<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: StorageMojo: hacked!</title>
	<atom:link href="http://storagemojo.com/2008/05/06/storagemojo-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/</link>
	<description>Data storage info &#38; analysis</description>
	<pubDate>Wed, 09 Jul 2008 12:31:52 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Joe Gunroy</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195592</link>
		<dc:creator>Joe Gunroy</dc:creator>
		<pubDate>Sat, 10 May 2008 01:44:54 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195592</guid>
		<description>Open source isn't the issue, per se, as all the commercial website applications have had (and will have) their fair share of exploits, too.  

Inexpensive hosting does require the extra effort of "going it alone." But, this is more an issue with trying to be your own webmaster than with the choice of platform. 

Robin, I'm willing to bet you're not done. Chances are that whomever hacked you probably didn't do it because of your passwords, but more likely through some other vulnerability. If they got full access to your webhost (i.e., root) I'd recommend a complete reinstall, followed by patching every known vulnerability and then a good round of server hardening. Yes, it's a lot of work. Yes, it's unfortunate that you need to know all this stuff to be a webmaster.  But, this is the path you have chosen.</description>
		<content:encoded><![CDATA[<p>Open source isn&#8217;t the issue, per se, as all the commercial website applications have had (and will have) their fair share of exploits, too.  </p>
<p>Inexpensive hosting does require the extra effort of &#8220;going it alone.&#8221; But, this is more an issue with trying to be your own webmaster than with the choice of platform. </p>
<p>Robin, I&#8217;m willing to bet you&#8217;re not done. Chances are that whomever hacked you probably didn&#8217;t do it because of your passwords, but more likely through some other vulnerability. If they got full access to your webhost (i.e., root) I&#8217;d recommend a complete reinstall, followed by patching every known vulnerability and then a good round of server hardening. Yes, it&#8217;s a lot of work. Yes, it&#8217;s unfortunate that you need to know all this stuff to be a webmaster.  But, this is the path you have chosen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xfer_rdy</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195588</link>
		<dc:creator>xfer_rdy</dc:creator>
		<pubDate>Fri, 09 May 2008 16:24:27 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195588</guid>
		<description>Isn't open source wonderful ?? 

Sorry to hear you've been hacked...  but hacking popular web sites, open source forums, and blog software is a hobby for too many. In part, that's why I took my site down. I didn't have the time to keep up with the spamming and hacking.  

This is good example of the problems with open source technology for business or professional purposes. "Its free isn't it" , well --- no, what's is your time worth... There are very few companies, at least under $300/mo,  that will ensure your web/blog/forum site will mitigate or correct hacking. 

good luck

x
------------------------------------------------
"Too much monkey business"
      -Chuck Berry</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t open source wonderful ?? </p>
<p>Sorry to hear you&#8217;ve been hacked&#8230;  but hacking popular web sites, open source forums, and blog software is a hobby for too many. In part, that&#8217;s why I took my site down. I didn&#8217;t have the time to keep up with the spamming and hacking.  </p>
<p>This is good example of the problems with open source technology for business or professional purposes. &#8220;Its free isn&#8217;t it&#8221; , well &#8212; no, what&#8217;s is your time worth&#8230; There are very few companies, at least under $300/mo,  that will ensure your web/blog/forum site will mitigate or correct hacking. </p>
<p>good luck</p>
<p>x<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
&#8220;Too much monkey business&#8221;<br />
      -Chuck Berry</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Margaret</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195559</link>
		<dc:creator>Margaret</dc:creator>
		<pubDate>Wed, 07 May 2008 18:15:18 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195559</guid>
		<description>Scary stuff! Bloggers have to be pretty vigilant these days. Thanks for the links. 
~Margaret</description>
		<content:encoded><![CDATA[<p>Scary stuff! Bloggers have to be pretty vigilant these days. Thanks for the links.<br />
~Margaret</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francis</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195558</link>
		<dc:creator>Francis</dc:creator>
		<pubDate>Wed, 07 May 2008 14:07:55 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195558</guid>
		<description>Dreamhost has one redeeming feature, they let you spit up your websites by users. Make sure you have a different user for each domain you host and if one is hacked the others are secure. I'd be using media temple (they are much faster and more reliable) if they offered that.</description>
		<content:encoded><![CDATA[<p>Dreamhost has one redeeming feature, they let you spit up your websites by users. Make sure you have a different user for each domain you host and if one is hacked the others are secure. I&#8217;d be using media temple (they are much faster and more reliable) if they offered that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pieter Thoma</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195557</link>
		<dc:creator>Pieter Thoma</dc:creator>
		<pubDate>Wed, 07 May 2008 09:16:10 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195557</guid>
		<description>There is a security test plugin for wordpress. A must have!

http://wordpress.org/extend/plugins/wp-security-scan/</description>
		<content:encoded><![CDATA[<p>There is a security test plugin for wordpress. A must have!</p>
<p><a href="http://wordpress.org/extend/plugins/wp-security-scan/" rel="nofollow">http://wordpress.org/extend/plugins/wp-security-scan/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amit Gurdasani</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195556</link>
		<dc:creator>Amit Gurdasani</dc:creator>
		<pubDate>Wed, 07 May 2008 08:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195556</guid>
		<description>IF this is dedicated hosting or something like a Xen VPS: I'd advise you to take it offline, power it off, do a clean operating system install on your host, restore from known-good backup, harden said known-good system and then take it online.

The reason is that if the hackers ended up injecting code into the kernel, your view of the system might well be governed by said code -- their processes on the host may be hidden from view, providing a hidden, ready backdoor for them to come in again. In a nutshell, _you cannot trust the system_ unless you've rebuilt it with known-good components _from the bottom up_. And if you cannot trust what the system tells you, you cannot be certain that it's clean or secure.

If it's shared hosting, you generally don't have control over the operating system -- but shared hosts tend to harden their systems against this sort of thing anyway. The best you can do is to back up the _data_, remove everything, reinstall the CMS, vet the data and restore the databases and configuration for the CMS. That way you can be sure you haven't missed anything.</description>
		<content:encoded><![CDATA[<p>IF this is dedicated hosting or something like a Xen VPS: I&#8217;d advise you to take it offline, power it off, do a clean operating system install on your host, restore from known-good backup, harden said known-good system and then take it online.</p>
<p>The reason is that if the hackers ended up injecting code into the kernel, your view of the system might well be governed by said code &#8212; their processes on the host may be hidden from view, providing a hidden, ready backdoor for them to come in again. In a nutshell, _you cannot trust the system_ unless you&#8217;ve rebuilt it with known-good components _from the bottom up_. And if you cannot trust what the system tells you, you cannot be certain that it&#8217;s clean or secure.</p>
<p>If it&#8217;s shared hosting, you generally don&#8217;t have control over the operating system &#8212; but shared hosts tend to harden their systems against this sort of thing anyway. The best you can do is to back up the _data_, remove everything, reinstall the CMS, vet the data and restore the databases and configuration for the CMS. That way you can be sure you haven&#8217;t missed anything.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Riot Nrrrd™</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195555</link>
		<dc:creator>Riot Nrrrd™</dc:creator>
		<pubDate>Wed, 07 May 2008 02:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195555</guid>
		<description>"Language = ru, whatever that means."

As in RUssian.</description>
		<content:encoded><![CDATA[<p>&#8220;Language = ru, whatever that means.&#8221;</p>
<p>As in RUssian.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: phil</title>
		<link>http://storagemojo.com/2008/05/06/storagemojo-hacked/#comment-195554</link>
		<dc:creator>phil</dc:creator>
		<pubDate>Wed, 07 May 2008 02:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://storagemojo.com/?p=703#comment-195554</guid>
		<description>"Language=ru" mean Russian.</description>
		<content:encoded><![CDATA[<p>&#8220;Language=ru&#8221; mean Russian.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.439 seconds -->
