<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SEO Expert &#38; Social Media Expert, Mobile &#38; Business App Developers - Austin &#187; Wordpress</title>
	<atom:link href="http://www.mattrauch.com/tag/wordpress/feed" rel="self" type="application/rss+xml" />
	<link>http://www.mattrauch.com</link>
	<description>Matt Rauch is an SEO Expert &#38; Social Media Expert in Austin, Texas</description>
	<lastBuildDate>Wed, 08 Feb 2012 00:34:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>ALERT: WordPress Attack Spreading Fast &#8211; Upgrade NOW!</title>
		<link>http://www.mattrauch.com/old-wordpress-versions-under-attack.php</link>
		<comments>http://www.mattrauch.com/old-wordpress-versions-under-attack.php#comments</comments>
		<pubDate>Sat, 05 Sep 2009 21:18:19 +0000</pubDate>
		<dc:creator>Rauch</dc:creator>
				<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[Wordpress Attack]]></category>
		<category><![CDATA[Wordpress Attack Spreading Fast]]></category>
		<category><![CDATA[Wordpress Security]]></category>
		<category><![CDATA[Wordpress Vulnerability]]></category>

		<guid isPermaLink="false">http://www.mattrauch.com/?p=532</guid>
		<description><![CDATA[WordPress developers are reporting (announced by "Lorelle on WordPress") there is an ongoing 'attack' on older versions (prior to release 2.8.4) of the WordPress blog software. The number of sites hit by this is multiplying by the hour, so protect your WordPress blog immediately and UPDATE NOW!!!]]></description>
			<content:encoded><![CDATA[<p>WordPress developers are reporting (announced by &#8220;<a href="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/" target="_blank">Lorelle on WordPress</a>&#8220;) there is an ongoing &#8216;attack&#8217; on older versions (prior to release 2.8.4) of the WordPress blog software. The number of sites hit by this is multiplying by the hour, so protect your WordPress blog immediately and <strong>UPDATE NOW!!!</strong></p>
<p><strong><span style="text-decoration: underline;">Special Note:</span> This Alert is for self-hosted WordPress installations.WordPress.com blogs are not impacted as they are up-to-date.</strong></p>
<p>Lorelle Writes:</p>
<p><em>***Update your WordPress blog before you continue reading this post. That&#8217;s how critical this issue is.</em></p>
<p>There are two clues that your WordPress site has been attacked.</p>
<ul>
<li>There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&#038;(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&#038;%/. The keywords are &#8220;eval&#8221; and &#8220;base64_decode.&#8221;</li>
<li>The 2nd clue is that a &#8220;back door&#8221; has been created by a &#8220;hidden Administrator&#8221;. Check site users for an &#8220;Administrator (2)&#8221; listing or some other name you don&#8217;t recognize. If one has been created, it is highly unlikely that you will be able to access the account.</li>
</ul>
<p><strong>For those already affected, it is being reported that you will need to:</strong></p>
<ol>
<li>Export all your content with the built-in XML WordPress exporter.</li>
<li>Remove your WordPress installation completely (saving only images and general files)</li>
<li>DO NOT EXPORT YOUR DATABASE! Exporting the database will result in exporting and transfer of the hacked code.</li>
<li>Reinstall WordPress adding the &#8220;clean&#8221; backup of your WordPress Theme</li>
<li>Re-import your content using the XML export file.</li>
</ol>
<p>And again, take care to keep your export limited to the post content, comments and Pages, not the entire database. Sincethe hack goes all the way into the database, exporting your DB will result in exporting the hacked code as well.</p>
<p>If you have further questions or concerns, check <a href="http://wordpress.org/support/" target="_blank">WordPress.com</a>, the community is there to help.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mattrauch.com/old-wordpress-versions-under-attack.php/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

