<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Breaking News: WordPress Hacked with Zettapetta on DreamHost</title> <atom:link href="http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/feed/" rel="self" type="application/rss+xml" /><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/</link> <description>Securing WordPress tips, harden server vulnerabilities, WordPress Security Services, teleseminars, and how to secure WordPress from malicious hackers.</description> <lastBuildDate>Sat, 04 Feb 2012 08:38:41 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: Regina Smola</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-4676</link> <dc:creator>Regina Smola</dc:creator> <pubDate>Mon, 11 Jul 2011 16:31:13 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-4676</guid> <description>Thanks for your comment and questions. I use HostGator. Great 24/7 support and updated servers. You can save 25% off with coupon code: wpsecuritylock25.Also, check out my post on 10 Tips for Secure Hosting here:
http://www.wpsecuritylock.com/10-tips-for-secure-wordpress-hosting/</description> <content:encoded><![CDATA[<p>Thanks for your comment and questions. I use HostGator. Great 24/7 support and updated servers. You can save 25% off with coupon code: wpsecuritylock25.</p><p>Also, check out my post on 10 Tips for Secure Hosting here:<br
/> <a
href="http://www.wpsecuritylock.com/10-tips-for-secure-wordpress-hosting/" rel="nofollow">http://www.wpsecuritylock.com/10-tips-for-secure-wordpress-hosting/</a></p> ]]></content:encoded> </item> <item><title>By: keerthi</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-4665</link> <dc:creator>keerthi</dc:creator> <pubDate>Sat, 02 Jul 2011 13:15:33 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-4665</guid> <description>Hey regina,I have been using VPS Hosting from one of vendors I know and I feel that the after sales service is really bad with them. And also a couple of my wp sites got hacked recently and started showing that I am hosting some malware when I am just having static html content on my sites...So I am thinking of moving to Dreamhost but as u have said that they are prone to hacking can u suggest me any other hosting providers?Keerthi</description> <content:encoded><![CDATA[<p>Hey regina,</p><p>I have been using VPS Hosting from one of vendors I know and I feel that the after sales service is really bad with them. And also a couple of my wp sites got hacked recently and started showing that I am hosting some malware when I am just having static html content on my sites...So I am thinking of moving to Dreamhost but as u have said that they are prone to hacking can u suggest me any other hosting providers?</p><p>Keerthi</p> ]]></content:encoded> </item> <item><title>By: Regina Smola</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-4444</link> <dc:creator>Regina Smola</dc:creator> <pubDate>Wed, 04 May 2011 23:28:22 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-4444</guid> <description>Hi Steve,I did a scan on your website and you&#039;re dealing with two malware hacks, one is iframe malware and one is javascript malware. Be sure to change your passwords and WordPress secret keys and restore from a clean backup if you can.After your site is clean, the Google cache is going to stay on the net awhile. You have to wait until Google bot checks that page again before the clean one shows. You can find the last day cached in the top right corner.If you need help, please let me know. I also sent you an email with some further instructions. Good luck and stay safe.~ Regina</description> <content:encoded><![CDATA[<p>Hi Steve,</p><p>I did a scan on your website and you're dealing with two malware hacks, one is iframe malware and one is javascript malware. Be sure to change your passwords and WordPress secret keys and restore from a clean backup if you can.</p><p>After your site is clean, the Google cache is going to stay on the net awhile. You have to wait until Google bot checks that page again before the clean one shows. You can find the last day cached in the top right corner.</p><p>If you need help, please let me know. I also sent you an email with some further instructions. Good luck and stay safe.</p><p>~ Regina</p> ]]></content:encoded> </item> <item><title>By: Regina Smola</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-4421</link> <dc:creator>Regina Smola</dc:creator> <pubDate>Tue, 03 May 2011 21:01:02 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-4421</guid> <description>Steve,Yikes! Sorry to hear your site was hacked. Make sure you check the rest of your server for any other mystery directories/folders and files. Malicious hackers can leave them in many places.If you need help, please &lt;a href=&quot;http://www.wpsecuritylock.com/contact/&quot; rel=&quot;nofollow&quot;&gt;contact me&lt;/a&gt;.Stay secure,Regina Smola</description> <content:encoded><![CDATA[<p>Steve,</p><p>Yikes! Sorry to hear your site was hacked. Make sure you check the rest of your server for any other mystery directories/folders and files. Malicious hackers can leave them in many places.</p><p>If you need help, please <a
href="http://www.wpsecuritylock.com/contact/" rel="nofollow">contact me</a>.</p><p>Stay secure,</p><p>Regina Smola</p> ]]></content:encoded> </item> <item><title>By: steve</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-4417</link> <dc:creator>steve</dc:creator> <pubDate>Tue, 03 May 2011 05:46:10 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-4417</guid> <description>Today realised that google flagged my WP site &quot;this site may be compromised&quot;.
I found a folder labeled &quot;femur&quot; on my ftp. Inside were hundreds of html files of spam sites.
The folder was dated around mid April 2011 maybe it was the 16th. I deleted it.
If you have any helpful hints please let me know.</description> <content:encoded><![CDATA[<p>Today realised that google flagged my WP site "this site may be compromised".<br
/> I found a folder labeled "femur" on my ftp. Inside were hundreds of html files of spam sites.<br
/> The folder was dated around mid April 2011 maybe it was the 16th. I deleted it.<br
/> If you have any helpful hints please let me know.</p> ]]></content:encoded> </item> <item><title>By: Erin</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-1915</link> <dc:creator>Erin</dc:creator> <pubDate>Tue, 26 Oct 2010 03:10:32 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-1915</guid> <description>I have a WordPress site hosted with Dreamhost.  For months, it got infected w/ malicitious scripts on a daily basis.  Dreamhost basically said it&#039;s my fault or the fault of the software I use.  Everything I run is always up to date. Anyway, eventually the daily infections stopped, and I was clear for months. Then one day fairly recently (don&#039;t know when, sorry), they started again, always in the footer.php files (sometimes the header.php) of the /wp/wp-content/themes dir.I changed the prefix on all the tables via phpMyAdmin to something other than the wp_ default this weekend, but I was infected (and subsequently blocked by Google) yet again, though it turns out I missed ONE table.  Whether or not that was the culprit, I won&#039;t know until I make it a length of time with no infections.I&#039;m kind of at my wit&#039;s end with this. I don&#039;t know what to do if it doesn&#039;t work.Though it&#039;s noteworthy that the last-modified date/time does NOT change on the files when it happens, though the file size changes.  Unless I check the source on my site multiple times per day, I have no idea that my site&#039;s been compromised until someone tells me it&#039;s blocked.Do you have any suggestions?  I&#039;m desperate.Thank you,
Erin</description> <content:encoded><![CDATA[<p>I have a WordPress site hosted with Dreamhost.  For months, it got infected w/ malicitious scripts on a daily basis.  Dreamhost basically said it's my fault or the fault of the software I use.  Everything I run is always up to date. Anyway, eventually the daily infections stopped, and I was clear for months. Then one day fairly recently (don't know when, sorry), they started again, always in the footer.php files (sometimes the header.php) of the /wp/wp-content/themes dir.</p><p>I changed the prefix on all the tables via phpMyAdmin to something other than the wp_ default this weekend, but I was infected (and subsequently blocked by Google) yet again, though it turns out I missed ONE table.  Whether or not that was the culprit, I won't know until I make it a length of time with no infections.</p><p>I'm kind of at my wit's end with this. I don't know what to do if it doesn't work.</p><p>Though it's noteworthy that the last-modified date/time does NOT change on the files when it happens, though the file size changes.  Unless I check the source on my site multiple times per day, I have no idea that my site's been compromised until someone tells me it's blocked.</p><p>Do you have any suggestions?  I'm desperate.</p><p>Thank you,<br
/> Erin</p> ]]></content:encoded> </item> <item><title>By: Regina Smola</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-1875</link> <dc:creator>Regina Smola</dc:creator> <pubDate>Mon, 18 Oct 2010 16:35:39 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-1875</guid> <description>Hi nelsdrums,Sorry to hear your website was hacked. Was it done on 9/15/2010 or 10/15/2010?Were you able to get it fixed? Also, did you find out how they got into your site?</description> <content:encoded><![CDATA[<p>Hi nelsdrums,</p><p>Sorry to hear your website was hacked. Was it done on 9/15/2010 or 10/15/2010?</p><p>Were you able to get it fixed? Also, did you find out how they got into your site?</p> ]]></content:encoded> </item> <item><title>By: nelsdrums</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-1873</link> <dc:creator>nelsdrums</dc:creator> <pubDate>Mon, 18 Oct 2010 03:30:17 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-1873</guid> <description>My Dreamhost site was hacked on 09-15-10 at 10:51 pm PST. Here&#039;s the code on every single PHP file of the WP 3.0.1 installation:  &quot;/**/ eval(base64_decode(&quot;aWYoZnVuY3RpbComment Edited by Regina Smola: We have copied the entire hacker code and shortened it to protect our readers.</description> <content:encoded><![CDATA[<p>My Dreamhost site was hacked on 09-15-10 at 10:51 pm PST. Here's the code on every single PHP file of the WP 3.0.1 installation:  "/**/ eval(base64_decode("aWYoZnVuY3Rpb</p><p>Comment Edited by Regina Smola: We have copied the entire hacker code and shortened it to protect our readers.</p> ]]></content:encoded> </item> <item><title>By: Abid</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-1835</link> <dc:creator>Abid</dc:creator> <pubDate>Sat, 09 Oct 2010 12:59:37 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-1835</guid> <description>Thank you,I had changed the passwords and contacted my host in order to retrieve the database backup. Anyways, with your and my hosts help I am able to get my blog back. It is cleaned now :)Regards,
Abid Sultan</description> <content:encoded><![CDATA[<p>Thank you,</p><p>I had changed the passwords and contacted my host in order to retrieve the database backup. Anyways, with your and my hosts help I am able to get my blog back. It is cleaned now <img
src='http://www.wpsecuritylock.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>Regards,<br
/> Abid Sultan</p> ]]></content:encoded> </item> <item><title>By: Regina Smola</title><link>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/comment-page-7/#comment-1833</link> <dc:creator>Regina Smola</dc:creator> <pubDate>Sat, 09 Oct 2010 00:15:08 +0000</pubDate> <guid
isPermaLink="false">http://www.wpsecuritylock.com/?p=2462#comment-1833</guid> <description>Yes, your WordPress site has been hacked by .HaCkEd By FoX HaCkEr. We know this because they&#039;ve left their hacker &quot;calling card&quot; all over your website. You can see that you&#039;re not alone. This hacker has hacked several other sites. Look at this &lt;a href=&quot;http://www.google.com/#sclient=psy&amp;hl=en&amp;q=%22.HaCkEd+By+FoX+HaCkEr%22&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=a29c82155c57878e&quot; rel=&quot;nofollow&quot;&gt;Google search result&lt;/a&gt;. Don&#039;t worry it&#039;s safe to click that link.According to my scans, right now there is no malware detected that can infect your computer. It looks like a partial defacement.Don&#039;t panic. It can be fixed.Please go and change all of your FTP passwords, all of your wp-admin passwords that have access to your &quot;Dashboard&quot; and change your Authentication Unique Keys and Salts in your wp-config.php file immediately.Do you have a backup of your website and database?</description> <content:encoded><![CDATA[<p>Yes, your WordPress site has been hacked by .HaCkEd By FoX HaCkEr. We know this because they've left their hacker "calling card" all over your website. You can see that you're not alone. This hacker has hacked several other sites. Look at this <a
href="http://www.google.com/#sclient=psy&amp;hl=en&amp;q=%22.HaCkEd+By+FoX+HaCkEr%22&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=a29c82155c57878e" rel="nofollow">Google search result</a>. Don't worry it's safe to click that link.</p><p>According to my scans, right now there is no malware detected that can infect your computer. It looks like a partial defacement.</p><p>Don't panic. It can be fixed.</p><p>Please go and change all of your FTP passwords, all of your wp-admin passwords that have access to your "Dashboard" and change your Authentication Unique Keys and Salts in your wp-config.php file immediately.</p><p>Do you have a backup of your website and database?</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 38/69 queries in 0.066 seconds using disk: basic

Served from: www.wpsecuritylock.com @ 2012-02-04 03:21:59 -->
