<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog De Manila &#187; blog hacked</title>
	<atom:link href="http://www.blogdemanila.com/tag/blog-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blogdemanila.com</link>
	<description>Helping other people blog smartly!</description>
	<lastBuildDate>Tue, 31 Jan 2012 09:14:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>My Wife&#8217;s Blog Was Hacked</title>
		<link>http://www.blogdemanila.com/my-wifes-blog-was-hacked/</link>
		<comments>http://www.blogdemanila.com/my-wifes-blog-was-hacked/#comments</comments>
		<pubDate>Mon, 23 Feb 2009 04:38:38 +0000</pubDate>
		<dc:creator>eric</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Search Engine]]></category>
		<category><![CDATA[SEO]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[blog hacked]]></category>

		<guid isPermaLink="false">http://www.blogdemanila.com/?p=236</guid>
		<description><![CDATA[Don&#8217;t Panic As I&#8217;ve mentioned in my January Top Entrecard Dropper&#8217;s post, my wife&#8217;s blog including the forum was hacked. I was promoting the site to one of my friend in Singapore when I noticed the main page was showing a different page. Being a technical guy, I did not panic but I was so [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.blogdemanila.com%2Fmy-wifes-blog-was-hacked%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.blogdemanila.com%2Fmy-wifes-blog-was-hacked%2F&amp;source=blogdemanila&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="aligncenter" title="Pinay Mom Hacked" src="http://pinaymom.org/images/pm_hacked.jpg" alt="" width="302" height="330" /></p>
<p><strong>Don&#8217;t Panic</strong></p>
<p>As I&#8217;ve mentioned in my January Top Entrecard Dropper&#8217;s post, my <a href="http://pinaymom.org/forum/" target="_blank">wife&#8217;s blog</a> including the <a href="http://pinaymom.org/forum/" target="_blank">forum</a> was hacked. I was promoting the site to one of my friend in Singapore when I noticed the main page was showing a different page. Being a technical guy, I did not panic but I was so concerned about the data of the site, most specially the forum. And to top it all, I don&#8217;t want to face  the ire of my wife if she learns about the hacking.</p>
<p><strong>Report to the Authority</strong></p>
<p>I have no recourse but to report  what happened to her blog. To my surprised, <span id="more-236"></span>I did not hear any &#8220;furious winds&#8221; from her.</p>
<p><strong>First Step: Damage Assessment</strong></p>
<p>The moment I&#8217;ve learned about the hacking incidence, I immediately called our webhost provider if they can do something about it. They replied that they have encountered the same problem before and they recommended to upgrade the WordPress version that <a href="http://pinaymom.org/forum/" target="_blank">PinayMom</a> are using.</p>
<p>I downloaded the latest WordPress 2.7. from WordPress.org and  strictly followed to the letter the instructions on upgrading WordPress.  I deleted everything except for the wp-content folder , that&#8217;s the where the plugins and themes folders are located, and I was extra careful to preserve wp-config.php as well.</p>
<p>Unfortunately, the trick didn&#8217;t work. After the supposed &#8220;upgrade&#8221;, the problem still remained. The &#8220;hacked&#8221; pages is still being shown on the blog and on the forum main page. I could not even login to the wp-admin page!</p>
<p><strong>Check Other Criminal Profiles</strong></p>
<p>I turned to Mr. Google to find the same pattern of hacking, but Mr. G did not return any helpful solutions. It seems my wife&#8217;s site was the first victim of this group of hackers.</p>
<p>I even checked some of the entry on the MySQL database, if there were inserts or new table that were created  but I could not find any trace.</p>
<p>After 2 or 3 more sleepless nights, I decided to delete everything, including the plugins, themes and all the root pages except wp-config.php which I know contains the database configurations of the site. Lo and behold, the hack was still there even if I uploaded a new copy of WordPress 2.7.</p>
<p><strong>Still Clueless</strong></p>
<p>I was clueless on what to do.</p>
<p>Finally, I decided to put everything offline. I was determined to create a new database. I copied wp-config.php locally and just change the content on it to reflect the new database configuration that I was about to create.</p>
<p><strong>Crime Scene Evidence</strong></p>
<p>And to my surprised, when I opened wp-config.php, I noticed the content was changed. It was totally altered! Not only it was modified, but the wordpress database configuration was all gone! What the &#8230;.!</p>
<p>Boom! Gotcha!</p>
<p>The hackers hacked the the wp-config.php file. Their fingerprints was all over the crime scene. They&#8217;ve totally messed up the file. Below is the image of the crime scene.</p>
<p><strong>Scene 1:<br />
</strong><img class="aligncenter" title="Pinay Mom Hacked Scene1" src="http://pinaymom.org/images/hacked1.jpg" alt="" width="517" height="128" /><strong>Scene 2:</strong></p>
<p><img class="aligncenter" title="Pinay Mom Hacked Scene 2" src="http://pinaymom.org/images/hacked2.jpg" alt="" width="846" height="401" /></p>
<p>The hackers knew what file they needed to hack in order to be undetected, far from the radar sight, knowing that a user won&#8217;t change or delete the wp-config.file. As you can see, I was so careful not to touch wp-config.php file. Aside from the wp-content folders, wp-config.php is the last file that you wouldn&#8217;t suspect the hackers will use to do their dirty job.</p>
<p><strong>Recovery: Solutions</strong></p>
<p>And this is where the good backup works! Good thing, I have a local copy of this file on my hard disk.</p>
<p>Not only I upgraded the wordpress to 2.7.1., I am now regularly backing up all my blogs. So I suggest to all bloggers and website owners not to take the backup lightly.</p>
<p>Blogging is fun but don&#8217;t let the hackers destroy your work. Keep your blog in top and working condition!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blogdemanila.com/my-wifes-blog-was-hacked/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
	</channel>
</rss>

