<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Wordpress blog hacked with admin-ajax.php vulnerability</title>
	<atom:link href="http://www.neox.net/w/2008/05/16/wordpress-blog-hacked-with-admin-ajaxphp-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.neox.net/w/2008/05/16/wordpress-blog-hacked-with-admin-ajaxphp-vulnerability/</link>
	<description>Here are the freewares just the ones I like</description>
	<pubDate>Fri, 05 Sep 2008 15:32:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: HanaDaddy</title>
		<link>http://www.neox.net/w/2008/05/16/wordpress-blog-hacked-with-admin-ajaxphp-vulnerability/#comment-12340</link>
		<dc:creator>HanaDaddy</dc:creator>
		<pubDate>Mon, 30 Jun 2008 02:27:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.neox.net/w/?p=155#comment-12340</guid>
		<description>When you install Bad Behavior, it will block all the unverified access to admin pages which causes some of your plugins to fail. In that case, you should add your IP to the $bb2_whitelist_ip_ranges array of the &lt;code&gt;plugins/bad-behavior/bad-behavior/whitelist.inc.php&lt;/code&gt; file.</description>
		<content:encoded><![CDATA[<p>When you install Bad Behavior, it will block all the unverified access to admin pages which causes some of your plugins to fail. In that case, you should add your IP to the $bb2_whitelist_ip_ranges array of the <code>plugins/bad-behavior/bad-behavior/whitelist.inc.php</code> file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HanaDaddy</title>
		<link>http://www.neox.net/w/2008/05/16/wordpress-blog-hacked-with-admin-ajaxphp-vulnerability/#comment-12334</link>
		<dc:creator>HanaDaddy</dc:creator>
		<pubDate>Sun, 22 Jun 2008 23:33:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.neox.net/w/?p=155#comment-12334</guid>
		<description>Basically you will need to make a clean install. Then overwrite the wp-content with the previous folder.
Also highly recommend installing the &lt;a href='http://www.bad-behavior.ioerror.us/' rel="nofollow"&gt;Bad Behavior&lt;/a&gt; plugin. It blocks suspicious connection attempts to the admin pages.
And how would you know that you are successfully blocking the hacking attempts? You should monitor your Awstat ( or similar web log analysis software) results everyday. You should be able to find the admin-ajax.php entry in the Pages-URL section of the awtats statistics. If you don't, you are OK. But if you do find one, check the 'Entry' column. If this value is high, you should suspect that there are still hacking attempts occurring. </description>
		<content:encoded><![CDATA[<p>Basically you will need to make a clean install. Then overwrite the wp-content with the previous folder.<br />
Also highly recommend installing the <a href='http://www.bad-behavior.ioerror.us/' rel="nofollow">Bad Behavior</a> plugin. It blocks suspicious connection attempts to the admin pages.<br />
And how would you know that you are successfully blocking the hacking attempts? You should monitor your Awstat ( or similar web log analysis software) results everyday. You should be able to find the admin-ajax.php entry in the Pages-URL section of the awtats statistics. If you don&#8217;t, you are OK. But if you do find one, check the &#8216;Entry&#8217; column. If this value is high, you should suspect that there are still hacking attempts occurring.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Technology madness</title>
		<link>http://www.neox.net/w/2008/05/16/wordpress-blog-hacked-with-admin-ajaxphp-vulnerability/#comment-12333</link>
		<dc:creator>Technology madness</dc:creator>
		<pubDate>Sun, 22 Jun 2008 15:26:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.neox.net/w/?p=155#comment-12333</guid>
		<description>So, now after upgrade to 2.5.1, do you think your site is clean? I had a similar issue but not sure how to fix it. However, I do see wp-admin/admin-ajax.php accessed by someone. When I tried it to acess wp-admin/admin-ajax.php, it returns -1 value in browser. What does that mean? Do you think wordpress 2.5.1 is now secure?</description>
		<content:encoded><![CDATA[<p>So, now after upgrade to 2.5.1, do you think your site is clean? I had a similar issue but not sure how to fix it. However, I do see wp-admin/admin-ajax.php accessed by someone. When I tried it to acess wp-admin/admin-ajax.php, it returns -1 value in browser. What does that mean? Do you think wordpress 2.5.1 is now secure?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
