<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: iFrame worms: goooogleadsence.biz, cutlot.cn, google-ana1yticz.com, mixante.cn and similar</title>
	<atom:link href="http://www.sulumitsretsambew.org/iframe-worms/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sulumitsretsambew.org/iframe-worms/</link>
	<description>Sulumits Retsambew is entry by Evil Science for NetBuilders seo contest.</description>
	<lastBuildDate>Wed, 30 Mar 2011 10:03:54 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: glass machinery</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-836</link>
		<dc:creator>glass machinery</dc:creator>
		<pubDate>Mon, 22 Feb 2010 08:29:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-836</guid>
		<description>Hmm I had the similar issue, but overwriting all wordpress files with newer ones fixed the thing.</description>
		<content:encoded><![CDATA[<p>Hmm I had the similar issue, but overwriting all wordpress files with newer ones fixed the thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-580</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Sun, 11 Oct 2009 10:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-580</guid>
		<description>Similar issue...  I use the tool Iframe.Attack to remove injection :

http://kawablog.com/scarabox/product.php?id_produit=1&amp;id_rub=2&amp;lng=en

Demo on youtube :
http://www.youtube.com/watch?v=XosRuSk_NFg

regards, Sam</description>
		<content:encoded><![CDATA[<p>Similar issue&#8230;  I use the tool Iframe.Attack to remove injection :</p>
<p><a href="http://kawablog.com/scarabox/product.php?id_produit=1&amp;id_rub=2&amp;lng=en" rel="nofollow">http://kawablog.com/scarabox/product.php?id_produit=1&amp;id_rub=2&amp;lng=en</a></p>
<p>Demo on youtube :<br />
<a href="http://www.youtube.com/watch?v=XosRuSk_NFg" rel="nofollow">http://www.youtube.com/watch?v=XosRuSk_NFg</a></p>
<p>regards, Sam</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mat</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-435</link>
		<dc:creator>Mat</dc:creator>
		<pubDate>Thu, 06 Aug 2009 17:03:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-435</guid>
		<description>Here is a great article on how to get rid of this virus
&lt;a href=&quot;http://www.qualitycodes.com/tutorial.php?articleid=29&quot; rel=&quot;nofollow&quot;&gt;http://www.qualitycodes.com/tutorial.php?articleid=29&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Here is a great article on how to get rid of this virus<br />
<a href="http://www.qualitycodes.com/tutorial.php?articleid=29" rel="nofollow">http://www.qualitycodes.com/tutorial.php?articleid=29</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-323</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Fri, 19 Jun 2009 07:02:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-323</guid>
		<description>Hmm I had the similar issue, but overwriting all wordpress files with newer ones fixed the thing.</description>
		<content:encoded><![CDATA[<p>Hmm I had the similar issue, but overwriting all wordpress files with newer ones fixed the thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oggy</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-321</link>
		<dc:creator>oggy</dc:creator>
		<pubDate>Fri, 19 Jun 2009 02:41:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-321</guid>
		<description>I cleaned up all the files infected in my wordpress...

The site looked great...  3 days later, got hacked again (definately not server side, I had made the necessary changes, the used ftp from filezilla for sure).

just changed FTP and cleaned files.

All looks good, except:

I log in to my admin in Wordpress and only the &quot;tools&quot; appears in the nav.  Can&#039;t write or edit posts.  Just dissappeared.  

went in through PHPmyAdmin to see if user still had admin access... apparently it does.

Made sure all wp-admin files were not infected, basically replaced them with a brand new wordpress download (same version 2.8), and still cannot access any other actions in dashboard logged in as admin other than &quot;tools&quot;.

Anyone think they know what the issue is?  I need help :P

Thx!</description>
		<content:encoded><![CDATA[<p>I cleaned up all the files infected in my wordpress&#8230;</p>
<p>The site looked great&#8230;  3 days later, got hacked again (definately not server side, I had made the necessary changes, the used ftp from filezilla for sure).</p>
<p>just changed FTP and cleaned files.</p>
<p>All looks good, except:</p>
<p>I log in to my admin in Wordpress and only the &#8220;tools&#8221; appears in the nav.  Can&#8217;t write or edit posts.  Just dissappeared.  </p>
<p>went in through PHPmyAdmin to see if user still had admin access&#8230; apparently it does.</p>
<p>Made sure all wp-admin files were not infected, basically replaced them with a brand new wordpress download (same version 2.8), and still cannot access any other actions in dashboard logged in as admin other than &#8220;tools&#8221;.</p>
<p>Anyone think they know what the issue is?  I need help <img src='http://www.sulumitsretsambew.org/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Thx!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: miklosz</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-303</link>
		<dc:creator>miklosz</dc:creator>
		<pubDate>Sun, 14 Jun 2009 15:51:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-303</guid>
		<description>I think this post and that one related said all...</description>
		<content:encoded><![CDATA[<p>I think this post and that one related said all&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-302</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Sun, 14 Jun 2009 15:45:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-302</guid>
		<description>It appears to be a PC virus that will read your FTP login information from various FTP programs like CuteFTP, FileZilla, etc.  I added a password to open CuteFTP ... Tools &gt; Global Options &gt; Security &gt; Encrypt Site Manager ... and haven&#039;t had an issue since.  I also upgraded my security on my PC with PC Tools Free Firewall, and added Avast along with AVG to make sure it doesn&#039;t happen again.  So far, so good.</description>
		<content:encoded><![CDATA[<p>It appears to be a PC virus that will read your FTP login information from various FTP programs like CuteFTP, FileZilla, etc.  I added a password to open CuteFTP &#8230; Tools &gt; Global Options &gt; Security &gt; Encrypt Site Manager &#8230; and haven&#8217;t had an issue since.  I also upgraded my security on my PC with PC Tools Free Firewall, and added Avast along with AVG to make sure it doesn&#8217;t happen again.  So far, so good.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-300</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sat, 13 Jun 2009 20:23:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-300</guid>
		<description>I have yet to determine if this is a PC virus or some kind of injection attack at the server, but it definitely uses FTP.
If you can, set your hosting to only allow FTP access on specific IP addresses or ranges.  At least this will prevent use of FTP to do the attack.
If you use CPanel/WHM and have full access, you can do this.  Otherwise you could ask your hosting provider to do so.</description>
		<content:encoded><![CDATA[<p>I have yet to determine if this is a PC virus or some kind of injection attack at the server, but it definitely uses FTP.<br />
If you can, set your hosting to only allow FTP access on specific IP addresses or ranges.  At least this will prevent use of FTP to do the attack.<br />
If you use CPanel/WHM and have full access, you can do this.  Otherwise you could ask your hosting provider to do so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-201</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 05 May 2009 15:36:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-201</guid>
		<description>check this post
I uploaded removal tool there

http://www.sulumitsretsambew.org/iframe-worms-xtrarobotzcom-superbetfaircn-lotmachinesguidecn/</description>
		<content:encoded><![CDATA[<p>check this post<br />
I uploaded removal tool there</p>
<p><a href="http://www.sulumitsretsambew.org/iframe-worms-xtrarobotzcom-superbetfaircn-lotmachinesguidecn/" rel="nofollow">http://www.sulumitsretsambew.org/iframe-worms-xtrarobotzcom-superbetfaircn-lotmachinesguidecn/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rahim</title>
		<link>http://www.sulumitsretsambew.org/iframe-worms/comment-page-1/#comment-200</link>
		<dc:creator>Rahim</dc:creator>
		<pubDate>Tue, 05 May 2009 12:59:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.sulumitsretsambew.org/?p=259#comment-200</guid>
		<description>Hey guys, 

I run a server, and unfortunately, it got infected by a virus (iframe)..I really don&#039;t know what I should do, since almost all my websites have been infected, and even the direct admin pages!!!! soo strange!

please can anyone help me here!

also, can you please update the rapidshare php cleaner, that link given is broken.

many thanks guys!

regards</description>
		<content:encoded><![CDATA[<p>Hey guys, </p>
<p>I run a server, and unfortunately, it got infected by a virus (iframe)..I really don&#8217;t know what I should do, since almost all my websites have been infected, and even the direct admin pages!!!! soo strange!</p>
<p>please can anyone help me here!</p>
<p>also, can you please update the rapidshare php cleaner, that link given is broken.</p>
<p>many thanks guys!</p>
<p>regards</p>
]]></content:encoded>
	</item>
</channel>
</rss>

