<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Blog PermaLinks Hacked by &#8220;ElijahHastings65&#8243;!</title>
	<atom:link href="http://blog.nachotech.com/?feed=rss2&#038;p=125" rel="self" type="application/rss+xml" />
	<link>http://blog.nachotech.com/?p=125</link>
	<description>Tech tidbits that have crunch!</description>
	<lastBuildDate>Sun, 13 Jun 2010 19:19:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: star config web design sydney</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-1758</link>
		<dc:creator>star config web design sydney</dc:creator>
		<pubDate>Sat, 16 Jan 2010 09:02:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-1758</guid>
		<description>i had problems as well with accounting hiding when they hack ed web site, thank you for explaining us how to do it, especially i like you shoewd us codes in your article. Thank you.</description>
		<content:encoded><![CDATA[<p>i had problems as well with accounting hiding when they hack ed web site, thank you for explaining us how to do it, especially i like you shoewd us codes in your article. Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Attack: How to protect your blog when you don't know MySQL from My Little Pony &#124; Corporate Blogger &#124; Business Blogging, Web 2.0 &#38; Social Media Marketing for SMEs</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-685</link>
		<dc:creator>WordPress Attack: How to protect your blog when you don't know MySQL from My Little Pony &#124; Corporate Blogger &#124; Business Blogging, Web 2.0 &#38; Social Media Marketing for SMEs</dc:creator>
		<pubDate>Wed, 11 Nov 2009 20:40:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-685</guid>
		<description>[...] With that Users page open in Firefox, I followed the advice given in this excellent Nachotech post: I went to the View tab at the top of the page and selected Page Source, which pops up all the [...]</description>
		<content:encoded><![CDATA[<p>[...] With that Users page open in Firefox, I followed the advice given in this excellent Nachotech post: I went to the View tab at the top of the page and selected Page Source, which pops up all the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bman</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-210</link>
		<dc:creator>Bman</dc:creator>
		<pubDate>Mon, 28 Sep 2009 02:05:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-210</guid>
		<description>Hi - thanks for taking the time to report on this! It looks as though the malicious script (or whatever it is) is a bit more seriously entrenched in the installation I am attempting to fix. When I try to view source my antivirus program gets all bent out of shape about threats. I also cannot download the user-edit.php file for the same reason (won&#039;t allow me to do so for security reasons).
I WAS able to see the name of the evil admin (even though it vanishes from view very quickly) by first figuring out which page it was listed on (this site has many many subscribers, so I needed to dig through to find it), then I visited the page and took a screenshot right away. Sure enough, there was the bad admin username listed in the screenshot. I tried your approach with linking directly to that users edit page but it did not work.

You mentioned PhPMyAdmin - could I manually remove the user using that program or will I encounter the same issues?
Any assistance you can provide will be greatly appreciated!

Thanks
B</description>
		<content:encoded><![CDATA[<p>Hi &#8211; thanks for taking the time to report on this! It looks as though the malicious script (or whatever it is) is a bit more seriously entrenched in the installation I am attempting to fix. When I try to view source my antivirus program gets all bent out of shape about threats. I also cannot download the user-edit.php file for the same reason (won&#8217;t allow me to do so for security reasons).<br />
I WAS able to see the name of the evil admin (even though it vanishes from view very quickly) by first figuring out which page it was listed on (this site has many many subscribers, so I needed to dig through to find it), then I visited the page and took a screenshot right away. Sure enough, there was the bad admin username listed in the screenshot. I tried your approach with linking directly to that users edit page but it did not work.</p>
<p>You mentioned PhPMyAdmin &#8211; could I manually remove the user using that program or will I encounter the same issues?<br />
Any assistance you can provide will be greatly appreciated!</p>
<p>Thanks<br />
B</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Verme ataca Wordpress.</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-50</link>
		<dc:creator>Verme ataca Wordpress.</dc:creator>
		<pubDate>Tue, 15 Sep 2009 00:19:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-50</guid>
		<description>[...] http://blog.nachotech.com/?p=125 [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.nachotech.com/?p=125" rel="nofollow">http://blog.nachotech.com/?p=125</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iggy</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-33</link>
		<dc:creator>iggy</dc:creator>
		<pubDate>Sat, 12 Sep 2009 15:42:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-33</guid>
		<description>Hi Jason - thanks for your comment.  Sorry to hear your site was attacked too.  In my case, I was still able to log into wp-admin, so I didn&#039;t have to resort to other measures.  My hosting provider (GoDaddy) uses myphpadmin, not cpanel, so I&#039;m not familiar with cpanel.  If you do have access to cpanel, however, you should be able to use it to either change the administrator password, or create a new administrator user, which should then allow you to use wp-admin.  Here&#039;s a couple links that might help you get started:  &lt;a href=&quot;http://codex.wordpress.org/Using_cPanel&quot; rel=&quot;nofollow&quot;&gt;Using cPanel&lt;/a&gt; and &lt;a href=&quot;http://docs.cpanel.net/twiki/bin/view/AllDocumentation/AllFAQ/CPanelFAQ&quot; rel=&quot;nofollow&quot;&gt;CPanel FAQ&lt;/a&gt;.

I would also suggest that you contact your hosting provider for assistance.  They may be able to restore your Wordpress site and DB to a recent backup.

Good luck,
Iggy</description>
		<content:encoded><![CDATA[<p>Hi Jason &#8211; thanks for your comment.  Sorry to hear your site was attacked too.  In my case, I was still able to log into wp-admin, so I didn&#8217;t have to resort to other measures.  My hosting provider (GoDaddy) uses myphpadmin, not cpanel, so I&#8217;m not familiar with cpanel.  If you do have access to cpanel, however, you should be able to use it to either change the administrator password, or create a new administrator user, which should then allow you to use wp-admin.  Here&#8217;s a couple links that might help you get started:  <a href="http://codex.wordpress.org/Using_cPanel" rel="nofollow">Using cPanel</a> and <a href="http://docs.cpanel.net/twiki/bin/view/AllDocumentation/AllFAQ/CPanelFAQ" rel="nofollow">CPanel FAQ</a>.</p>
<p>I would also suggest that you contact your hosting provider for assistance.  They may be able to restore your Wordpress site and DB to a recent backup.</p>
<p>Good luck,<br />
Iggy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-30</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Fri, 11 Sep 2009 23:38:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-30</guid>
		<description>This a$$**** has got me to! I&#039;m new and my site is screwed up. My permalinks are messed up and I can&#039;t log into wp admin. How do I do this through the cpanel? I&#039;m scared that I will mess the site up worse. I look forward to hearing from you. Thank you for your time.
                            Jason</description>
		<content:encoded><![CDATA[<p>This a$$**** has got me to! I&#8217;m new and my site is screwed up. My permalinks are messed up and I can&#8217;t log into wp admin. How do I do this through the cpanel? I&#8217;m scared that I will mess the site up worse. I look forward to hearing from you. Thank you for your time.<br />
                            Jason</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iggy</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-29</link>
		<dc:creator>iggy</dc:creator>
		<pubDate>Thu, 10 Sep 2009 04:05:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-29</guid>
		<description>cavpres - As an example, if your blog is normally accessed as http://www.myblog.com/, abd the user id you want to edit is &quot;5&quot;, then you would put &quot;http://www.myblog.com/wp-admin/user-edit.php?user_id=5&quot; into the browser&#039;s Location/Address/URL field.

If that takes you to a login page, then go ahead and log in.  You do need to be logged into your Wordpress blog as an Administrator to be able to edit the users.  If you are not taken to an &quot;Edit User&quot; page eventually, then perhaps your Wordpress installation is non-standard.  Are you hosting your blog at your own domain, or with Wordpress.com?

Also, what is the bogus user name?  I am wondering if all the hacks were with the same username.  Good luck!</description>
		<content:encoded><![CDATA[<p>cavpres &#8211; As an example, if your blog is normally accessed as <a href="http://www.myblog.com/" rel="nofollow">http://www.myblog.com/</a>, abd the user id you want to edit is &#8220;5&#8243;, then you would put &#8220;http://www.myblog.com/wp-admin/user-edit.php?user_id=5&#8243; into the browser&#8217;s Location/Address/URL field.</p>
<p>If that takes you to a login page, then go ahead and log in.  You do need to be logged into your Wordpress blog as an Administrator to be able to edit the users.  If you are not taken to an &#8220;Edit User&#8221; page eventually, then perhaps your Wordpress installation is non-standard.  Are you hosting your blog at your own domain, or with Wordpress.com?</p>
<p>Also, what is the bogus user name?  I am wondering if all the hacks were with the same username.  Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cavpres</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-28</link>
		<dc:creator>cavpres</dc:creator>
		<pubDate>Thu, 10 Sep 2009 01:43:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-28</guid>
		<description>Iggy,

Thanks, but I must be very dumb because I still cannot figure it out. Where do I put the URL, in my browser bar? Because when I do that it takes me to the login page for my blog. I saw two users in the view source code, 1 (which I think is me) and 5 (the bogus user) and I can also see a user name for this user as well. But I&#039;m not being taken to any page to edit the info. Thanks again.</description>
		<content:encoded><![CDATA[<p>Iggy,</p>
<p>Thanks, but I must be very dumb because I still cannot figure it out. Where do I put the URL, in my browser bar? Because when I do that it takes me to the login page for my blog. I saw two users in the view source code, 1 (which I think is me) and 5 (the bogus user) and I can also see a user name for this user as well. But I&#8217;m not being taken to any page to edit the info. Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iggy</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-23</link>
		<dc:creator>iggy</dc:creator>
		<pubDate>Wed, 09 Sep 2009 13:16:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-23</guid>
		<description>cavpres - thanks for your comment.  I had an error in the URL due to my own upgrade of Wordpress.  I&#039;ve corrected that and also explained things a bit better.  Please read the &quot;How To Find And Delete&quot; section again and let me know if it works for you now.

Thanks,
Iggy</description>
		<content:encoded><![CDATA[<p>cavpres &#8211; thanks for your comment.  I had an error in the URL due to my own upgrade of Wordpress.  I&#8217;ve corrected that and also explained things a bit better.  Please read the &#8220;How To Find And Delete&#8221; section again and let me know if it works for you now.</p>
<p>Thanks,<br />
Iggy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Look for IT over here</title>
		<link>http://blog.nachotech.com/?p=125&#038;cpage=1#comment-21</link>
		<dc:creator>Look for IT over here</dc:creator>
		<pubDate>Wed, 09 Sep 2009 10:08:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nachotech.com/?p=125#comment-21</guid>
		<description>[...] thanks to the guys at NachoTech. The post there helped me sort out and fix my WP issues with a minimal loss of data.   Share and [...]</description>
		<content:encoded><![CDATA[<p>[...] thanks to the guys at NachoTech. The post there helped me sort out and fix my WP issues with a minimal loss of data.   Share and [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
