<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Media Temple/WordPress hacked</title>
	<atom:link href="http://jeffreybarke.net/2009/11/media-templewordpress-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/</link>
	<description></description>
	<lastBuildDate>Mon, 06 Sep 2010 10:00:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Sam</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-2155</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Tue, 24 Aug 2010 02:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-2155</guid>
		<description>I think it is due to the &#039;special source&#039; that GS uses

I don&#039;t think it would affect the DV in same way (but long time since I had a DV account)

Also pixelkitty I get a warning that your site is infected with &quot;pheonix exploit kit&quot;.  I had never heard of this before and googling it it appears to be a kit to assist in analyizing incoming traffic

AVG is warning me about the pixelkitty site

defo a MT GS issue not isolated to wp - it has happened a few times since also</description>
		<content:encoded><![CDATA[<p>I think it is due to the &#8216;special source&#8217; that GS uses</p>
<p>I don&#8217;t think it would affect the DV in same way (but long time since I had a DV account)</p>
<p>Also pixelkitty I get a warning that your site is infected with &#8220;pheonix exploit kit&#8221;.  I had never heard of this before and googling it it appears to be a kit to assist in analyizing incoming traffic</p>
<p>AVG is warning me about the pixelkitty site</p>
<p>defo a MT GS issue not isolated to wp &#8211; it has happened a few times since also</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-972</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Sat, 19 Dec 2009 21:16:39 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-972</guid>
		<description>I got a call from a client this morning saying their Drupal site was down.  After finding the problem and this post the issue is exactly the same as what&#039;s posted above.

The scary thing is that I am on a DV server.  Don&#039;t think that this is just a GS issue.

Just about to contact mediaTemple.  I&#039;ll post back if I find out anything extra.</description>
		<content:encoded><![CDATA[<p>I got a call from a client this morning saying their Drupal site was down.  After finding the problem and this post the issue is exactly the same as what&#8217;s posted above.</p>
<p>The scary thing is that I am on a DV server.  Don&#8217;t think that this is just a GS issue.</p>
<p>Just about to contact mediaTemple.  I&#8217;ll post back if I find out anything extra.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joly</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-954</link>
		<dc:creator>Joly</dc:creator>
		<pubDate>Wed, 09 Dec 2009 08:02:26 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-954</guid>
		<description>Hi Jeff!

It seems to me that this is very similar to what went on at DH just about a year ago, if I&#039;m not mistaken!</description>
		<content:encoded><![CDATA[<p>Hi Jeff!</p>
<p>It seems to me that this is very similar to what went on at DH just about a year ago, if I&#8217;m not mistaken!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JeffreyBarke.net » Blog Archive » Media Temple/WordPress hacked Medical just to Me</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-943</link>
		<dc:creator>JeffreyBarke.net » Blog Archive » Media Temple/WordPress hacked Medical just to Me</dc:creator>
		<pubDate>Thu, 03 Dec 2009 12:58:34 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-943</guid>
		<description>[...] post:  JeffreyBarke.net » Blog Archive » Media Temple/WordPress hacked          By admin &#124; category: media temple &#124; tags: account, kyle-the-invincible, media temple, [...]</description>
		<content:encoded><![CDATA[<p>[...] post:  JeffreyBarke.net » Blog Archive » Media Temple/WordPress hacked          By admin | category: media temple | tags: account, kyle-the-invincible, media temple, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Byrd</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-937</link>
		<dc:creator>Dan Byrd</dc:creator>
		<pubDate>Wed, 02 Dec 2009 19:06:21 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-937</guid>
		<description>All my sites hosted with Media Temple were compromised.  Both .htaccess and index.php files modified in Joomla or wordpress directories - different accounts.  The interesting thing about this is that the perpetrators were able to access the admin control as well and turn on SSH and create a separate admin user.  Media Temple surely got caught with their pants down due to lack of security.  Who ever crashed this party surely isn&#039;t interested in a reality show - unless their name is Kevin Mitnick.</description>
		<content:encoded><![CDATA[<p>All my sites hosted with Media Temple were compromised.  Both .htaccess and index.php files modified in Joomla or wordpress directories &#8211; different accounts.  The interesting thing about this is that the perpetrators were able to access the admin control as well and turn on SSH and create a separate admin user.  Media Temple surely got caught with their pants down due to lack of security.  Who ever crashed this party surely isn&#8217;t interested in a reality show &#8211; unless their name is Kevin Mitnick.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jmcvearry</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-934</link>
		<dc:creator>jmcvearry</dc:creator>
		<pubDate>Tue, 01 Dec 2009 00:28:08 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-934</guid>
		<description>(mt) Media Temple just posted a new update on the spam injection issue with some new info and progress updates.

check it out here:
http://weblog.mediatemple.net/weblog/category/system-incidents/1026-gs-security-advisory/</description>
		<content:encoded><![CDATA[<p>(mt) Media Temple just posted a new update on the spam injection issue with some new info and progress updates.</p>
<p>check it out here:<br />
<a href="http://weblog.mediatemple.net/weblog/category/system-incidents/1026-gs-security-advisory/" rel="nofollow">http://weblog.mediatemple.net/weblog/category/system-incidents/1026-gs-security-advisory/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MediaTemple index.php Analysis &#8211; bundyxc.com</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-930</link>
		<dc:creator>MediaTemple index.php Analysis &#8211; bundyxc.com</dc:creator>
		<pubDate>Sun, 29 Nov 2009 21:30:10 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-930</guid>
		<description>[...] passwords were stolen. In addition, many codes were added to people&#8217;s files. According to Jeffrey Barke, there were codes injected in index.php, and while there were codes injected in other parts of the [...]</description>
		<content:encoded><![CDATA[<p>[...] passwords were stolen. In addition, many codes were added to people&#8217;s files. According to Jeffrey Barke, there were codes injected in index.php, and while there were codes injected in other parts of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeffrey Barke</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-928</link>
		<dc:creator>Jeffrey Barke</dc:creator>
		<pubDate>Sun, 29 Nov 2009 16:37:11 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-928</guid>
		<description>&lt;p&gt;Thanks for the link, Matt. It&#039;s definitely worth following and reading.&lt;/p&gt;
&lt;p&gt;According to Media Temple, aaron, they&#039;re &quot;not certain this exploit is directly related to the way we were storing passwords,&quot; which &lt;em&gt;do&lt;/em&gt; appear to be stored in plain text. But I agree with you&#8212;if the passwords were not stored as one-way hashes, it was poor security.&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>Thanks for the link, Matt. It&#0039;s definitely worth following and reading.</p>
<p>According to Media Temple, aaron, they&#0039;re &#0034;not certain this exploit is directly related to the way we were storing passwords,&#0034; which <em>do</em> appear to be stored in plain text. But I agree with you&#8212;if the passwords were not stored as one-way hashes, it was poor security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fabbrication.net :: Blog</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-2/#comment-918</link>
		<dc:creator>fabbrication.net :: Blog</dc:creator>
		<pubDate>Fri, 27 Nov 2009 07:49:55 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-918</guid>
		<description>[...] the extent of the security breach.  My understanding of the incident, (as also blogged here and here), is that someone got ahold of many of the admin passwords for Grid Service (GS) accounts and thus [...]</description>
		<content:encoded><![CDATA[<p>[...] the extent of the security breach.  My understanding of the incident, (as also blogged here and here), is that someone got ahold of many of the admin passwords for Grid Service (GS) accounts and thus [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aaron</title>
		<link>http://jeffreybarke.net/2009/11/media-templewordpress-hacked/comment-page-1/#comment-917</link>
		<dc:creator>aaron</dc:creator>
		<pubDate>Fri, 27 Nov 2009 02:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://jeffreybarke.net/?p=1294#comment-917</guid>
		<description>Me too.  Mediatemple did not fess up to the vulnerability but after they reset my passwords without my permission (then proceeded to have two hours of downtime so I couldn&#039;t reset my password), I figured it had to be their problem.

Also, when I called in, they asked me for my password, and they said OK quickly enough to let me know the support guy was looking at a plain text version of my password (he couldn&#039;t have typed it in to check that quickly).  This means they don&#039;t store a one-way hash of the password, but the actual password.  This is poor, poor security IMHO.

I&#039;d like a year of paid hosting or an upgrade to DV for the hassle.  All my sites were affected and trying to pick through which files were affected and which were not is a royal PITA.</description>
		<content:encoded><![CDATA[<p>Me too.  Mediatemple did not fess up to the vulnerability but after they reset my passwords without my permission (then proceeded to have two hours of downtime so I couldn&#8217;t reset my password), I figured it had to be their problem.</p>
<p>Also, when I called in, they asked me for my password, and they said OK quickly enough to let me know the support guy was looking at a plain text version of my password (he couldn&#8217;t have typed it in to check that quickly).  This means they don&#8217;t store a one-way hash of the password, but the actual password.  This is poor, poor security IMHO.</p>
<p>I&#8217;d like a year of paid hosting or an upgrade to DV for the hassle.  All my sites were affected and trying to pick through which files were affected and which were not is a royal PITA.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
