<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress, remv.php and You</title>
	<atom:link href="http://jasoncosper.com/wordpress-remvphp-and-you/feed/" rel="self" type="application/rss+xml" />
	<link>http://jasoncosper.com/wordpress-remvphp-and-you/</link>
	<description>Gentleman of fortune. Man of action.</description>
	<lastBuildDate>Fri, 24 Feb 2012 03:57:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-beta4-20717</generator>
	<item>
		<title>By: Juvy Barbosa</title>
		<link>http://jasoncosper.com/wordpress-remvphp-and-you/#comment-63675</link>
		<dc:creator>Juvy Barbosa</dc:creator>
		<pubDate>Mon, 19 Jan 2009 02:50:10 +0000</pubDate>
		<guid isPermaLink="false">http://jasoncosper.com/?p=439#comment-63675</guid>
		<description>That’s a great article, Jason and ought be required reading for anyone running a WordPress blog. It gave remote browser access to my entire directory tree, modify any file, seemed like it might be able to change modification times.

Regards
Juvy</description>
		<content:encoded><![CDATA[<p>That’s a great article, Jason and ought be required reading for anyone running a WordPress blog. It gave remote browser access to my entire directory tree, modify any file, seemed like it might be able to change modification times.</p>
<p>Regards<br />
Juvy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Laughlin</title>
		<link>http://jasoncosper.com/wordpress-remvphp-and-you/#comment-63598</link>
		<dc:creator>Laughlin</dc:creator>
		<pubDate>Thu, 18 Dec 2008 14:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://jasoncosper.com/?p=439#comment-63598</guid>
		<description>Got a message from google that my site was spamming. Found remv.php more or less by accident. Found out what it did by commenting out the line that checks to see if you are from the allowed list of IP addresses (near the beginning).
It gave remote browser access to my entire directory tree, modify any file, seemed like it might be able to change modification times.
So I look through every file (and there are a lot). Peppered through the directories are php scripts disguised as other things (eg picture.php.jpgg, right under picture.jpg).
Make sure you check your files!
Did the reinstall thing.</description>
		<content:encoded><![CDATA[<p>Got a message from google that my site was spamming. Found remv.php more or less by accident. Found out what it did by commenting out the line that checks to see if you are from the allowed list of IP addresses (near the beginning).<br />
It gave remote browser access to my entire directory tree, modify any file, seemed like it might be able to change modification times.<br />
So I look through every file (and there are a lot). Peppered through the directories are php scripts disguised as other things (eg picture.php.jpgg, right under picture.jpg).<br />
Make sure you check your files!<br />
Did the reinstall thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anders Saugstrup</title>
		<link>http://jasoncosper.com/wordpress-remvphp-and-you/#comment-63593</link>
		<dc:creator>Anders Saugstrup</dc:creator>
		<pubDate>Sat, 13 Dec 2008 08:47:16 +0000</pubDate>
		<guid isPermaLink="false">http://jasoncosper.com/?p=439#comment-63593</guid>
		<description>Good find!

I will warn the Danish audience. 

Any knowledge on what versions of Wordpress are safe from this hack?</description>
		<content:encoded><![CDATA[<p>Good find!</p>
<p>I will warn the Danish audience. </p>
<p>Any knowledge on what versions of WordPress are safe from this hack?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rlparker</title>
		<link>http://jasoncosper.com/wordpress-remvphp-and-you/#comment-63591</link>
		<dc:creator>rlparker</dc:creator>
		<pubDate>Thu, 11 Dec 2008 11:40:19 +0000</pubDate>
		<guid isPermaLink="false">http://jasoncosper.com/?p=439#comment-63591</guid>
		<description>That&#039;s a great article, Jason and ought be required reading for anyone running a WordPress blog. I&#039;ve linked it from a post on the DreamHost forums, in hopes others can benefit from it. Rock On!</description>
		<content:encoded><![CDATA[<p>That&#8217;s a great article, Jason and ought be required reading for anyone running a WordPress blog. I&#8217;ve linked it from a post on the DreamHost forums, in hopes others can benefit from it. Rock On!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

