<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Righty-oh! &#187; security</title>
	<atom:link href="http://www.righty-oh.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.righty-oh.com</link>
	<description>tips &#38; tools for busy site owners</description>
	<lastBuildDate>Sun, 15 Aug 2010 01:06:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Zen Cart Hacked &#8211; Rebuilding</title>
		<link>http://www.righty-oh.com/2010/07/zen-cart-hacked-rebuilding/</link>
		<comments>http://www.righty-oh.com/2010/07/zen-cart-hacked-rebuilding/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 22:01:52 +0000</pubDate>
		<dc:creator>C Rand-Thompson</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[bluehost]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[site]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[Zen Cart]]></category>

		<guid isPermaLink="false">http://www.righty-oh.com/?p=1209</guid>
		<description><![CDATA[At this point, in the story, the whole blooming hosting account and all associated sites have been made unavailable to the public (which is nice from a &#8220;do no harm&#8221; point of view), and it is apparent that both wordpress and zen cart were hacked, though on two separate domains&#8211;same hosting account. I thought perhaps [...]]]></description>
			<content:encoded><![CDATA[<p>At this point, in the story, the whole blooming hosting account and all associated sites have been made unavailable to the public (which is nice from a &#8220;do no harm&#8221; point of view), and it is apparent that both wordpress and zen cart were hacked, though on two separate domains&#8211;same hosting account.</p>
<p>I thought perhaps you&#8217;d like to know the names of a couple of the files used convert my sleepy little natural body care site into a phishing site feared and hated by Google, PayPal, BlueHost and phishing-site-cops.  They are easily found on the web, and you can even buy your own version!  I got mine &#8220;free&#8221;, but at some cost.</p>
<p>The two most dreaded files seem to be: update.paypal, and update.bofa/Unauthorized%20Verification%20Form.htm.  Update.paypal is a deal, at $20.   I guess Hackers have to make a living too, and without them a whole lot of internet security folk would be out of a job.</p>
<p>Other people it seems have had great experiences with BlueHost being helpful after their site was hacked, I&#8217;m not feeling the love.  But, so much of &#8220;Support&#8221; depends on who you get.  I particularly love the admonition to keep my finger always over the &#8220;update&#8221; button, while being blocked from updating the sites!  Not that the info on how to pro-actively secure a site wasn&#8217;t entertaining following a hack.  It seemed a little like being shown proper flossing techniques while getting fitted for dentures.  A bit late, and this is the time for drastic measures, not preventive steps.</p>
<p>Thinking it over, I think I&#8217;ll secure my as yet unaffected site, then begin the scorched earth cleaning and rebuilding process.  Here are some useful links for information on securing and/or rebuilding your MySQL / PHP driven site:</p>
<p><a rel="bookmark" href="http://thecartblog.com/2009/10/14/my-zen-cart-was-hacked-now-what/" target="_blank">My Zen Cart was hacked – now what?</a></p>
<p><a style="color: #006dad; text-decoration: none;" title="10 Ways To Secure Your WordPress Install" rel="bookmark" href="http://www.hackosis.com/10-ways-to-secure-your-wordpress-install/" target="_blank">10 Ways To Secure Your WordPress Install</a></p>
<p><em>The links below may require a BlueHost account:</em></p>
<p><a href="http://helpdesk.bluehost.com/index.php/kb/article/000570" target="_blank">Google Flagged My Site as Malware</a></p>
<p><a href="http://helpdesk.bluehost.com/index.php/kb/article/000511" target="_blank">What can I do to increase my Site Security while hosting with Bluehost?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.righty-oh.com/2010/07/zen-cart-hacked-rebuilding/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

