<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Article Directories Hacked by z7faan-h4ck3r</title>
	<atom:link href="http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/feed/" rel="self" type="application/rss+xml" />
	<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/</link>
	<description></description>
	<lastBuildDate>Sun, 03 Apr 2011 15:22:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Michael</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-79</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sun, 03 Apr 2011 15:22:16 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-79</guid>
		<description>It\&#039;s the article directory that got hacked, not your site.  This dude preys on articledashboard sites.</description>
		<content:encoded><![CDATA[<p>It\&#8217;s the article directory that got hacked, not your site.  This dude preys on articledashboard sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gavin</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-73</link>
		<dc:creator>Gavin</dc:creator>
		<pubDate>Thu, 21 Oct 2010 10:15:14 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-73</guid>
		<description>Hi,
I just joined a website (travelarticles.org) trying to promote my company&#039;s website. To be honest and to put this in context, I am a computer novice. I then got a confirmation email from someone who goes by HaCkEd BY Z7FaaN H4Ck3R . Any thoughts on what I should do, any measures I should take to protect my site? Is my site in danger and has anyone else had a similar experience?

Cheers,
Gavin</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I just joined a website (travelarticles.org) trying to promote my company&#8217;s website. To be honest and to put this in context, I am a computer novice. I then got a confirmation email from someone who goes by HaCkEd BY Z7FaaN H4Ck3R . Any thoughts on what I should do, any measures I should take to protect my site? Is my site in danger and has anyone else had a similar experience?</p>
<p>Cheers,<br />
Gavin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Atherton</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-66</link>
		<dc:creator>Rob Atherton</dc:creator>
		<pubDate>Tue, 01 Jun 2010 21:46:38 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-66</guid>
		<description>My site just got hacked again but some Turkish lot this time.

I had a look at the two directories
/admintemplates
/templates

I sorted the files by date/time and it showed a number of files in each directory had been updated recently. I&#039;ve just FTP&#039;d over the correct versions of the individual files that were hacked and so far it seems to have work. Took me about 5 minutes to fix.</description>
		<content:encoded><![CDATA[<p>My site just got hacked again but some Turkish lot this time.</p>
<p>I had a look at the two directories<br />
/admintemplates<br />
/templates</p>
<p>I sorted the files by date/time and it showed a number of files in each directory had been updated recently. I&#8217;ve just FTP&#8217;d over the correct versions of the individual files that were hacked and so far it seems to have work. Took me about 5 minutes to fix.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darman</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-65</link>
		<dc:creator>Darman</dc:creator>
		<pubDate>Wed, 19 May 2010 04:44:47 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-65</guid>
		<description>I just do this against z7faan. 
1. Change password
2. Change Theme
3. Reinstall the previous theme.
It works.</description>
		<content:encoded><![CDATA[<p>I just do this against z7faan.<br />
1. Change password<br />
2. Change Theme<br />
3. Reinstall the previous theme.<br />
It works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darman</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-64</link>
		<dc:creator>Darman</dc:creator>
		<pubDate>Wed, 19 May 2010 01:57:35 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-64</guid>
		<description>I am a newbie. Yesterday one of my site has attacked by this z7faan-.... I have read the above comment and your (Rob) article, but I don&#039;t know what to do from the first. Anyone can help?
Thanks.</description>
		<content:encoded><![CDATA[<p>I am a newbie. Yesterday one of my site has attacked by this z7faan-&#8230;. I have read the above comment and your (Rob) article, but I don&#8217;t know what to do from the first. Anyone can help?<br />
Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linda</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-61</link>
		<dc:creator>Linda</dc:creator>
		<pubDate>Mon, 10 May 2010 13:00:18 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-61</guid>
		<description>I set up my Article Bot directory submission software over the weekend and spent about 10 hours manually entering pw/user names to hundreds of directories that didn&#039;t load in the auto signup process. I felt the time spent would be well worth it to be able to rapidly submit my articles. Finally submitted my first article last night and all was going well when about 10 directories away from the entire 300+ or so being submitted, the submission process seemed to stall. I couldn&#039;t get it to cancel or close out. So I closed out Article Bot and when I came back in not only were my user and company profiles all wiped away but so was my Ready status for the sites I&#039;d spent 10 hours already manually signing up for! And there was no record or trace of the article I just submitted. It was as if I&#039;d never yet used the software.

As I had attempted to close down the stalled submission box, my McAffee had also shot up a Trojan warning yet when I went into to check recent activity it showed nothing.

The guy at Article Bot says they aren&#039;t responsible for the directories who don&#039;t take proper security precautions but my other problems aren&#039;t the result of this assh##e hacker and I&#039;m pretty sure they are. Once I ran through the auto signup process again I&#039;m now left with having to re-submit to 300+ directories my pw/user name manually again. Of several that went through on the auto submit, I received at least a dozen by this assenine hacker in confirmation emails. When clicking on the confirm link I&#039;m taken to his page with the face of a ugly as hell goth character and some Beasts of Hell BS!

What pathetic lives these losers have to have to get their jollies out of causing hard working people such grief. If I could get my hands on this creep I&#039;d kill him and I DO mean that!!!

Linda</description>
		<content:encoded><![CDATA[<p>I set up my Article Bot directory submission software over the weekend and spent about 10 hours manually entering pw/user names to hundreds of directories that didn&#8217;t load in the auto signup process. I felt the time spent would be well worth it to be able to rapidly submit my articles. Finally submitted my first article last night and all was going well when about 10 directories away from the entire 300+ or so being submitted, the submission process seemed to stall. I couldn&#8217;t get it to cancel or close out. So I closed out Article Bot and when I came back in not only were my user and company profiles all wiped away but so was my Ready status for the sites I&#8217;d spent 10 hours already manually signing up for! And there was no record or trace of the article I just submitted. It was as if I&#8217;d never yet used the software.</p>
<p>As I had attempted to close down the stalled submission box, my McAffee had also shot up a Trojan warning yet when I went into to check recent activity it showed nothing.</p>
<p>The guy at Article Bot says they aren&#8217;t responsible for the directories who don&#8217;t take proper security precautions but my other problems aren&#8217;t the result of this assh##e hacker and I&#8217;m pretty sure they are. Once I ran through the auto signup process again I&#8217;m now left with having to re-submit to 300+ directories my pw/user name manually again. Of several that went through on the auto submit, I received at least a dozen by this assenine hacker in confirmation emails. When clicking on the confirm link I&#8217;m taken to his page with the face of a ugly as hell goth character and some Beasts of Hell BS!</p>
<p>What pathetic lives these losers have to have to get their jollies out of causing hard working people such grief. If I could get my hands on this creep I&#8217;d kill him and I DO mean that!!!</p>
<p>Linda</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: michael</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-60</link>
		<dc:creator>michael</dc:creator>
		<pubDate>Sun, 09 May 2010 19:57:33 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-60</guid>
		<description>ok here is the script for your mysql update:

update admin
set password = &#039;21232f297a57a5a743894a0e4a801fc3&#039;
where adminid = [your admin id]

sets the password to &#039;admin&#039;</description>
		<content:encoded><![CDATA[<p>ok here is the script for your mysql update:</p>
<p>update admin<br />
set password = &#8217;21232f297a57a5a743894a0e4a801fc3&#8242;<br />
where adminid = [your admin id]</p>
<p>sets the password to &#8216;admin&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: michael</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-59</link>
		<dc:creator>michael</dc:creator>
		<pubDate>Sun, 09 May 2010 19:38:50 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-59</guid>
		<description>I forgot my admin password.  I remember seeing an encrypted string somewhere on the net that reset the password via a db entry. And then I could go into the app and provide a new on.  Anyone know what that was?</description>
		<content:encoded><![CDATA[<p>I forgot my admin password.  I remember seeing an encrypted string somewhere on the net that reset the password via a db entry. And then I could go into the app and provide a new on.  Anyone know what that was?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Carlson</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-58</link>
		<dc:creator>David Carlson</dc:creator>
		<pubDate>Wed, 28 Apr 2010 20:57:58 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-58</guid>
		<description>Pardon my French, but these guys are f---ing assholes.
About 2 weeks ago, our wordpress module was compromised so we couldn&#039;t access it. Then today they put their obnoxious bloody skull logo on the site. I am still trying to clean it off, but their seems to be something embedded in the site that is redirecting the website to a different page. Hopefully I can just disable the site while I try to reconstruct it... and yes, I have already changed my password.</description>
		<content:encoded><![CDATA[<p>Pardon my French, but these guys are f&#8212;ing assholes.<br />
About 2 weeks ago, our wordpress module was compromised so we couldn&#8217;t access it. Then today they put their obnoxious bloody skull logo on the site. I am still trying to clean it off, but their seems to be something embedded in the site that is redirecting the website to a different page. Hopefully I can just disable the site while I try to reconstruct it&#8230; and yes, I have already changed my password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://robatherton.com/183/article-directories-hacked-by-z7faan-h4ck3r/comment-page-1/#comment-57</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 23 Apr 2010 22:18:47 +0000</pubDate>
		<guid isPermaLink="false">http://robatherton.com/?p=183#comment-57</guid>
		<description>Search your entire remote (webhost) directory for mshell.php. There may be several of them.

Also look for a folder called g2data, this will guide you to the place where they set up on your hosting account.

Anonymous</description>
		<content:encoded><![CDATA[<p>Search your entire remote (webhost) directory for mshell.php. There may be several of them.</p>
<p>Also look for a folder called g2data, this will guide you to the place where they set up on your hosting account.</p>
<p>Anonymous</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Database Caching 2/17 queries in 0.008 seconds using disk: basic
Object Caching 394/398 objects using disk: basic

Served from: robatherton.com @ 2012-02-08 03:17:56 -->
