<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Divide and Conquer &#187; Open Source</title>
	<atom:link href="http://www.divideandconquer.se/tag/open-source/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.divideandconquer.se</link>
	<description>David's Software Development Blog</description>
	<lastBuildDate>Thu, 24 Jun 2010 13:47:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress crack attempt this morning!</title>
		<link>http://www.divideandconquer.se/2008/04/16/wordpress-crack-attempt-this-morning/</link>
		<comments>http://www.divideandconquer.se/2008/04/16/wordpress-crack-attempt-this-morning/#comments</comments>
		<pubDate>Wed, 16 Apr 2008 08:12:50 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://www.divideandconquer.se/2008/04/16/wordpress-crack-attempt-this-morning/</guid>
		<description><![CDATA[When I got to work and viewed this blog I noticed that Sidebar Widgets was disabled. I thought &#34;That&#8217;s weird!&#34;
When I tried to login to the administration interface I was told that my WordPress database needed upgrading. I thought &#34;That&#8217;s weird!&#34;
Some further investigation revealed that someone managed to upload a PHP script called ro8kfbsmag.txt (MD5 [...]]]></description>
			<content:encoded><![CDATA[<p>When I got to work and viewed this blog I noticed that <a href="http://svn.wp-plugins.org/widgets/trunk" title="Visit plugin homepage" onclick="pageTracker._trackPageview('/outgoing/svn.wp-plugins.org/widgets/trunk?referer=');">Sidebar Widgets</a> was disabled. I thought &quot;That&#8217;s weird!&quot;</p>
<p>When I tried to login to the administration interface I was told that my WordPress database needed upgrading. I thought &quot;That&#8217;s weird!&quot;</p>
<p>Some further investigation revealed that someone managed to upload a PHP script called ro8kfbsmag.txt (MD5 sum df3b74cd38c717d9d7bbf0cd1910baa1) to my /tmp directory. It starts like this:</p>
<p style="margin-left: 40px;"><code>&lt;?php<br />
/*Magic Include Shell by Mag icq 884888*/<br />
//TODO: &ntilde;&euml;&egrave;&ograve;&uuml; &ocirc;&agrave;&eacute;&euml;&icirc; &iacute;&agrave; &ntilde;&acirc;&icirc;&eacute; &ocirc;&ograve;&iuml; (!)<br />
$ver='2.1';<br />
if(isset($_GET[pisun233]))<br />
{</code></p>
<p>This gave me enough information too start googling. A must-read is <a href="http://blog.taragana.com/index.php/archive/detailed-post-mortem-of-a-website-hack-through-wordpress-how-to-protect-your-wordpress-blog-from-hacking/" rel="bookmark" title="Detailed Post-Mortem of a Website Hack Through WordPress &amp; How To Protect Your WordPress Blog From Hacking" onclick="pageTracker._trackPageview('/outgoing/blog.taragana.com/index.php/archive/detailed-post-mortem-of-a-website-hack-through-wordpress-how-to-protect-your-wordpress-blog-from-hacking/?referer=');"> Detailed Post-Mortem of a Website Hack Through WordPress &amp; How To Protect Your WordPress Blog From Hacking</a>, as it describes a very similar attack. There is also a support thread at wordpress.org: <a href="http://wordpress.org/support/topic/141041" target="_self" onclick="pageTracker._trackPageview('/outgoing/wordpress.org/support/topic/141041?referer=');">Weird and Dangerous : ro8kfbsmag.txt</a>.</p>
<p>The attack vector on my server looked like this, originating from 78.109.21.80 with HTTP/1.0 as protocol version and &quot;Opera&quot; as User-Agent. I wish I logged POST data!</p>
<p style="margin-left: 40px;">POST /wp-admin/options.php<br />
POST /wp-admin/upload.php<br />
POST /wp-admin/options.php<br />
POST /wp-admin/options.php<br />
POST /wp-admin/inline-uploading.php?post=-1&amp;action=upload<br />
POST /wp-admin/options.php<br />
POST /wp-admin/options.php<br />
POST /wp-admin/upload.php?style=inline&amp;tab=upload&amp;post_id=-1<br />
POST /wp-admin/upload.php?style=inline&amp;tab=upload&amp;post_id=-1<br />
POST /wp-admin/options.php<br />
POST /wp-admin/options.php<br />
GET /wp-admin/upgrade.php?step=1</p>
<p>Needless to say, I have restored a backup and taken certain precautions to prevent this from happening again.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.divideandconquer.se/2008/04/16/wordpress-crack-attempt-this-morning/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SourceForge.net Marketplace spam</title>
		<link>http://www.divideandconquer.se/2008/02/02/sourceforgenet-marketplace-spam/</link>
		<comments>http://www.divideandconquer.se/2008/02/02/sourceforgenet-marketplace-spam/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 09:11:04 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[SourceForge]]></category>

		<guid isPermaLink="false">http://www.divideandconquer.se/2008/02/02/sourceforgenet-marketplace-spam/</guid>
		<description><![CDATA[I&#8217;ve been a member of a number of SourceForge projects since 2001 and I can&#8217;t recall that I&#8217;ve had any previous complaints about their services to the Open Source community, but I&#8217;ve been getting &#8220;Turn your skills into cash at SourceForge.net Marketplace&#8221; mails for a while now and my annoyance keeps growing.  Some DNS [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been a member of a number of SourceForge projects since 2001 and I can&#8217;t recall that I&#8217;ve had any previous complaints about their services to the Open Source community, but I&#8217;ve been getting &#8220;Turn your skills into cash at SourceForge.net Marketplace&#8221; mails for a while now and my annoyance keeps growing.  Some DNS checks on marketplace.sourceforge.net shows that a company called ExactTarget  is running the business. I previously tried to change my e-mail address in their &#8220;Profile Center&#8221; to me@privacy.net but on Thursday I got another of the mails. This time I think I managed to unsubscribe. Unsurprisingly, I&#8217;m <a href="http://www.cod3r.com/2008/02/sourceforge-spam/" onclick="pageTracker._trackPageview('/outgoing/www.cod3r.com/2008/02/sourceforge-spam/?referer=');">not the only one annoyed</a> by this venture from SourceForge.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.divideandconquer.se/2008/02/02/sourceforgenet-marketplace-spam/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Web design and SimpleSidebar</title>
		<link>http://www.divideandconquer.se/2008/01/26/web-design-and-simplesidebar/</link>
		<comments>http://www.divideandconquer.se/2008/01/26/web-design-and-simplesidebar/#comments</comments>
		<pubDate>Sat, 26 Jan 2008 08:32:08 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Projects]]></category>
		<category><![CDATA[Rails]]></category>
		<category><![CDATA[The Project]]></category>

		<guid isPermaLink="false">http://www.divideandconquer.se/2008/01/26/web-design-and-simplesidebar/</guid>
		<description><![CDATA[I found a suitable initial web design for The Project at Open Source Web Design.  That&#8217;s a really great site!
Now I&#8217;m learning about layouts in Ruby on Rails. As suggested in the Midnight Oil blog (Beds are burning?) article SimpleSidebar &#8211; If you have sidebars, you need this plugin I now use SimpleSidebar in [...]]]></description>
			<content:encoded><![CDATA[<p>I found a suitable initial web design for <a href="/the-project/">The Project</a> at <a href="http://www.oswd.org/" onclick="pageTracker._trackPageview('/outgoing/www.oswd.org/?referer=');">Open Source Web Design</a>.  That&#8217;s a really great site!</p>
<p>Now I&#8217;m learning about layouts in Ruby on Rails. As suggested in the Midnight Oil blog (Beds are burning?) article <a href="http://blog.aisleten.com/2007/06/03/simplesidebar-if-you-have-sidebars-you-need-this-plugin/" onclick="pageTracker._trackPageview('/outgoing/blog.aisleten.com/2007/06/03/simplesidebar-if-you-have-sidebars-you-need-this-plugin/?referer=');">SimpleSidebar &#8211; If you have sidebars, you need this plugin</a> I now use SimpleSidebar in <a href="/the-project/">The Project</a>. At first it didn&#8217;t work at all, but updating config.plugins in config/environment.rb was an easy solution! :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.divideandconquer.se/2008/01/26/web-design-and-simplesidebar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
