<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: An Open Note to WordPress Spammers &amp; Hackers</title>
	<atom:link href="http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/</link>
	<description>News, reviews and technology blues!</description>
	<lastBuildDate>Thu, 11 Mar 2010 15:00:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Debbie Mahler</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-663</link>
		<dc:creator>Debbie Mahler</dc:creator>
		<pubDate>Tue, 09 Feb 2010 17:04:58 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-663</guid>
		<description>Michael, If you cannot login to your FTP, you need to start your process by contacting your web host company. Explain what happened and get them to reset your account. That&#039;s where you start.</description>
		<content:encoded><![CDATA[<p>Michael, If you cannot login to your FTP, you need to start your process by contacting your web host company. Explain what happened and get them to reset your account. That&#8217;s where you start.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael REMY</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-659</link>
		<dc:creator>Michael REMY</dc:creator>
		<pubDate>Sun, 07 Feb 2010 20:58:03 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-659</guid>
		<description>hi !

you can add this email &quot;makilovitalcamader@gmail.com&quot; to your hacker list ! 
my wordpress has been subscribe and (i guess) hacked! 
i can&#039;t manage to login in my usual ftp account to alter my website !

any help please !</description>
		<content:encoded><![CDATA[<p>hi !</p>
<p>you can add this email &#8220;makilovitalcamader@gmail.com&#8221; to your hacker list !<br />
my wordpress has been subscribe and (i guess) hacked!<br />
i can&#8217;t manage to login in my usual ftp account to alter my website !</p>
<p>any help please !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexandra Wolfe</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-612</link>
		<dc:creator>Alexandra Wolfe</dc:creator>
		<pubDate>Sat, 02 Jan 2010 19:38:58 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-612</guid>
		<description>Thank you for this. I&#039;ve started a list of my own having found several &quot;hacker&quot; email addresses and registrations on our web site. We have disabled registration for the moment in the hope of combating them.</description>
		<content:encoded><![CDATA[<p>Thank you for this. I&#8217;ve started a list of my own having found several &#8220;hacker&#8221; email addresses and registrations on our web site. We have disabled registration for the moment in the hope of combating them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WP Hacker's At It Again! &#124; Technical Tidbits</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-551</link>
		<dc:creator>WP Hacker's At It Again! &#124; Technical Tidbits</dc:creator>
		<pubDate>Tue, 27 Oct 2009 21:51:24 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-551</guid>
		<description>[...] you&#8217;ve been following our blog tracking the WordPress suspicious subscribers starting with, An Open Note to WordPress Spammers &amp; Hackers, and then, Adding to the WP Hacking Post, you&#8217;ll know many people are listing suspicious [...]</description>
		<content:encoded><![CDATA[<p>[...] you&#8217;ve been following our blog tracking the WordPress suspicious subscribers starting with, An Open Note to WordPress Spammers &amp; Hackers, and then, Adding to the WP Hacking Post, you&#8217;ll know many people are listing suspicious [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Debbie Mahler</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-549</link>
		<dc:creator>Debbie Mahler</dc:creator>
		<pubDate>Fri, 23 Oct 2009 15:07:59 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-549</guid>
		<description>Thanks for all that information! And I&#039;m so happy you found the file and the database entry! Great advice. I appreciate you commenting and letting everyone know how to check for this.</description>
		<content:encoded><![CDATA[<p>Thanks for all that information! And I&#8217;m so happy you found the file and the database entry! Great advice. I appreciate you commenting and letting everyone know how to check for this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: O'Ryan</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-546</link>
		<dc:creator>O'Ryan</dc:creator>
		<pubDate>Tue, 13 Oct 2009 19:49:41 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-546</guid>
		<description>oops i meant i found the PHP file in my 2009/09 directory. my mind has too many numbers floating around right now. lol</description>
		<content:encoded><![CDATA[<p>oops i meant i found the PHP file in my 2009/09 directory. my mind has too many numbers floating around right now. lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: O'Ryan</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-545</link>
		<dc:creator>O'Ryan</dc:creator>
		<pubDate>Tue, 13 Oct 2009 19:42:15 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-545</guid>
		<description>Hey firstly thanks for posting this. Helped me narrow down a few suspicious &quot;subscribers&quot; 

I was perusing my uploads folder via FTP and noticed in my 2009/02/ directory there was a php file there that i did not put there. the file was &quot;963991.php&quot; (filled with some base 64 gibberish)so immediately i knew something was up. i updated my WP to the current version and then logged into myPHPadmin to check out my DB user tables. and sure enough there was a user with no email or any other credentials in there. that did not show up in the WP dashboard. so they are able to cause mass damage if they can upload a php file and add admin users.

I would definitely recommend to any one with these &quot;subscribers&quot; to check your user tables. and your upload directories (specifically September&#039;s)then remove anything un-authorized.</description>
		<content:encoded><![CDATA[<p>Hey firstly thanks for posting this. Helped me narrow down a few suspicious &#8220;subscribers&#8221; </p>
<p>I was perusing my uploads folder via FTP and noticed in my 2009/02/ directory there was a php file there that i did not put there. the file was &#8220;963991.php&#8221; (filled with some base 64 gibberish)so immediately i knew something was up. i updated my WP to the current version and then logged into myPHPadmin to check out my DB user tables. and sure enough there was a user with no email or any other credentials in there. that did not show up in the WP dashboard. so they are able to cause mass damage if they can upload a php file and add admin users.</p>
<p>I would definitely recommend to any one with these &#8220;subscribers&#8221; to check your user tables. and your upload directories (specifically September&#8217;s)then remove anything un-authorized.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-534</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Fri, 18 Sep 2009 19:59:42 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-534</guid>
		<description>Thank you so much for leting me know this especially about Username: Andrianq
E-mail: pulvillarrac@gmail.com  

I noticed a bunch of minor irregularities on my blog. I have now shut down all subscribers- I make my money from people that find my site from the search engine anyway.

I have now bookmarked your site and will try to give it a plug in an applicable Blog. Thanks Again. You are the Man!</description>
		<content:encoded><![CDATA[<p>Thank you so much for leting me know this especially about Username: Andrianq<br />
E-mail: <a href="mailto:pulvillarrac@gmail.com">pulvillarrac@gmail.com</a>  </p>
<p>I noticed a bunch of minor irregularities on my blog. I have now shut down all subscribers- I make my money from people that find my site from the search engine anyway.</p>
<p>I have now bookmarked your site and will try to give it a plug in an applicable Blog. Thanks Again. You are the Man!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Bartmann</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-533</link>
		<dc:creator>Bill Bartmann</dc:creator>
		<pubDate>Fri, 18 Sep 2009 15:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-533</guid>
		<description>Hey good stuff...keep up the good work!  I read a lot of blogs on a daily basis and for the most part, people lack substance but, I just wanted to make a quick comment to say I&#039;m glad I found your blog.  Thanks,)

A definite great read...:)

&lt;a href=&quot;http://wiki.jfrog.org/confluence/display/~bill-bartmann&quot; rel=&quot;nofollow&quot;&gt;-Bill-Bartmann&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Hey good stuff&#8230;keep up the good work!  I read a lot of blogs on a daily basis and for the most part, people lack substance but, I just wanted to make a quick comment to say I&#8217;m glad I found your blog.  Thanks,)</p>
<p>A definite great read&#8230;:)</p>
<p><a href="http://wiki.jfrog.org/confluence/display/~bill-bartmann" rel="nofollow">-Bill-Bartmann</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manisha</title>
		<link>http://mice.org/blog/an-open-note-to-wordpress-spammers-hackers/comment-page-1/#comment-524</link>
		<dc:creator>Manisha</dc:creator>
		<pubDate>Wed, 09 Sep 2009 06:06:16 +0000</pubDate>
		<guid isPermaLink="false">http://mice.org/blog/?p=942#comment-524</guid>
		<description>Confirming the following:
Username: MikeWink
E-mail: bugbeemershonyhe@gmail.com
Signed up as subscriber on one of my WP blogs. 

The next day, there was a new user GayleRodger64 with no email address for just one day. This was followed by RogerRizo63, also with no email address but with admin privileges. That was when the js script was injected into the db and my permalinks started failing. (I have incremental backups of my database.)</description>
		<content:encoded><![CDATA[<p>Confirming the following:<br />
Username: MikeWink<br />
E-mail: <a href="mailto:bugbeemershonyhe@gmail.com">bugbeemershonyhe@gmail.com</a><br />
Signed up as subscriber on one of my WP blogs. </p>
<p>The next day, there was a new user GayleRodger64 with no email address for just one day. This was followed by RogerRizo63, also with no email address but with admin privileges. That was when the js script was injected into the db and my permalinks started failing. (I have incremental backups of my database.)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
