<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New WordPress Hack Inserts Hidden Text</title>
	<atom:link href="http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/</link>
	<description>Sports News - Tech Reviews - Entertainment - Life Tips for EveryJoe</description>
	<lastBuildDate>Thu, 03 Dec 2009 12:09:16 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Increase Search Engine Ranking</title>
		<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/comment-page-1/#comment-168960</link>
		<dc:creator>Increase Search Engine Ranking</dc:creator>
		<pubDate>Mon, 20 Jul 2009 18:12:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.techsideup.com/wordpress-hack-inserts-hidden-text/#comment-168960</guid>
		<description>I would highly recommend ASL (available at the GotRoot.com website). Say hi to Scott for me.

Pramudita,

If your hosting provider doesn&#039;t run mod_sec, then do you really think it&#039;s a good idea to be with them? (nothing personal Dreamhost, I am sure your security is fine). This should be addressed by your provider Pramudita, you shouldn&#039;t be even having to worry about it.

Go visit AtomicRocketTurtle.com and ask around for which providers are best suited for hosting your type of application. Always start your search for a provider based on what application you are going to run and then go from there.</description>
		<content:encoded><![CDATA[<p>I would highly recommend ASL (available at the GotRoot.com website). Say hi to Scott for me.</p>
<p>Pramudita,</p>
<p>If your hosting provider doesn&#8217;t run mod_sec, then do you really think it&#8217;s a good idea to be with them? (nothing personal Dreamhost, I am sure your security is fine). This should be addressed by your provider Pramudita, you shouldn&#8217;t be even having to worry about it.</p>
<p>Go visit AtomicRocketTurtle.com and ask around for which providers are best suited for hosting your type of application. Always start your search for a provider based on what application you are going to run and then go from there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Shinn</title>
		<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/comment-page-1/#comment-41429</link>
		<dc:creator>Michael Shinn</dc:creator>
		<pubDate>Mon, 19 May 2008 13:42:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.techsideup.com/wordpress-hack-inserts-hidden-text/#comment-41429</guid>
		<description>Hmmm... what do if you cant install and your system does not have mod_security installed...

I might be able to tweak this for mod_rewrite.  I&#039;ll have to do some experimenting later today to see what can be done with other tools.  In the mean time, see if you can encourage your ISP to install mod_security and I&#039;ll see what I can come up with for mod_rewrite.</description>
		<content:encoded><![CDATA[<p>Hmmm&#8230; what do if you cant install and your system does not have mod_security installed&#8230;</p>
<p>I might be able to tweak this for mod_rewrite.  I&#8217;ll have to do some experimenting later today to see what can be done with other tools.  In the mean time, see if you can encourage your ISP to install mod_security and I&#8217;ll see what I can come up with for mod_rewrite.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: erdal sahin</title>
		<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/comment-page-1/#comment-41430</link>
		<dc:creator>erdal sahin</dc:creator>
		<pubDate>Mon, 19 May 2008 08:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.techsideup.com/wordpress-hack-inserts-hidden-text/#comment-41430</guid>
		<description>thanks michael for sharing this article</description>
		<content:encoded><![CDATA[<p>thanks michael for sharing this article</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pramudita</title>
		<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/comment-page-1/#comment-41358</link>
		<dc:creator>Pramudita</dc:creator>
		<pubDate>Mon, 12 May 2008 17:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.techsideup.com/wordpress-hack-inserts-hidden-text/#comment-41358</guid>
		<description>Michael, how to use that rule for my wordpress blog  ?. I can&#039;t install mod_security on server (dreamhost)

Thank You</description>
		<content:encoded><![CDATA[<p>Michael, how to use that rule for my wordpress blog  ?. I can&#8217;t install mod_security on server (dreamhost)</p>
<p>Thank You</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Abundo</title>
		<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/comment-page-1/#comment-41459</link>
		<dc:creator>Mike Abundo</dc:creator>
		<pubDate>Fri, 25 Apr 2008 06:11:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.techsideup.com/wordpress-hack-inserts-hidden-text/#comment-41459</guid>
		<description>Awesome. Thanks, Michael! :)</description>
		<content:encoded><![CDATA[<p>Awesome. Thanks, Michael! :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Shinn</title>
		<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/comment-page-1/#comment-41456</link>
		<dc:creator>Michael Shinn</dc:creator>
		<pubDate>Thu, 24 Apr 2008 22:14:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.techsideup.com/wordpress-hack-inserts-hidden-text/#comment-41456</guid>
		<description>I&#039;ve written a modsecurity rule to help prevent this.  You can download it (and other rules) from the GotRoot Website, or you can just use this rule:

#Rule 300055:  Hidden spam links
#examples:
#
#overflow:auto;width:0;height:0
SecRule REQUEST_BODY&#124;ARGS &quot;&lt; ?font style ?= ?(position ?\: ?absolute&#124;overflow ?\: ?(?:hidden&#124;auto)).*(?:height&#124;width) ?(?:=&#124;\:) ?[0-9] ?(px&#124;\;)&quot; \
        &quot;t:replaceNulls,t:htmlEntityDecode,t:urlDecodeUni,t:compressWhiteSpace,t:lowercase,id:300056,rev:1,severity:2,msg:&#039;Spam: Hidden Text Exploit&#039;&quot;</description>
		<content:encoded><![CDATA[<p>I&#8217;ve written a modsecurity rule to help prevent this.  You can download it (and other rules) from the GotRoot Website, or you can just use this rule:</p>
<p>#Rule 300055:  Hidden spam links<br />
#examples:<br />
#<br />
#overflow:auto;width:0;height:0<br />
SecRule REQUEST_BODY|ARGS &#8220;&lt; ?font style ?= ?(position ?\: ?absolute|overflow ?\: ?(?:hidden|auto)).*(?:height|width) ?(?:=|\:) ?[0-9] ?(px|\;)&#8221; \<br />
        &#8220;t:replaceNulls,t:htmlEntityDecode,t:urlDecodeUni,t:compressWhiteSpace,t:lowercase,id:300056,rev:1,severity:2,msg:&#8217;Spam: Hidden Text Exploit&#8217;&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Hack Epidemic!</title>
		<link>http://www.everyjoe.com/articles/wordpress-hack-inserts-hidden-text-608/comment-page-1/#comment-41541</link>
		<dc:creator>WordPress Hack Epidemic!</dc:creator>
		<pubDate>Wed, 09 Apr 2008 07:31:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.techsideup.com/wordpress-hack-inserts-hidden-text/#comment-41541</guid>
		<description>[...] WordPress hidden text exploit I blogged earlier has exploded to epidemic proportions, hitting even big sites like ZDNet. The worst part: [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress hidden text exploit I blogged earlier has exploded to epidemic proportions, hitting even big sites like ZDNet. The worst part: [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
