<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Drunkjeans.com / Roundstorm.com Hack and how to get rid of it</title>
	<atom:link href="http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/</link>
	<description>Dedicated Wordpress Hosting and Support</description>
	<lastBuildDate>Tue, 31 Jan 2012 09:43:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: mortise lock</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-1000</link>
		<dc:creator>mortise lock</dc:creator>
		<pubDate>Tue, 30 Nov 2010 11:56:37 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-1000</guid>
		<description>we got (Pantscow.ru) infected our blog most of them on .js files.
sorry for your loss bro, [Search &quot;.ru&quot; (4255 hits in 1298 files)] its really a big deal. you should clean your PC first.</description>
		<content:encoded><![CDATA[<p>we got (Pantscow.ru) infected our blog most of them on .js files.<br />
sorry for your loss bro, [Search ".ru" (4255 hits in 1298 files)] its really a big deal. you should clean your PC first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-5/#comment-488</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Wed, 29 Sep 2010 16:22:21 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-488</guid>
		<description>WARNING: 
They dont hack your FTP or server directly (might be, but smaller chance). 
They infect the machine (probably with a .sys driver (try out bitdefender addon for FF)) that you used to upload your sites files to your webspace. 
If u stored your FTP credentials on it ... they connect to your webspace and alter the the index and js files. 
So beware, changing FTP PW is only working until you log on to your space again if u dont clean your machine first !!! </description>
		<content:encoded><![CDATA[<p>WARNING:<br />
They dont hack your FTP or server directly (might be, but smaller chance).<br />
They infect the machine (probably with a .sys driver (try out bitdefender addon for FF)) that you used to upload your sites files to your webspace.<br />
If u stored your FTP credentials on it &#8230; they connect to your webspace and alter the the index and js files.<br />
So beware, changing FTP PW is only working until you log on to your space again if u dont clean your machine first !!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-276</link>
		<dc:creator>John</dc:creator>
		<pubDate>Mon, 30 Aug 2010 10:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-276</guid>
		<description>Same here. They &quot;hacked&quot; our website i think through ftp and installed the above code. The url of the javascript doesn&#039;t exist and the funny thing is that google got it just before i could do something. (i found it straight away) 
Now i changed ftp password and changed also the infected files. (mostly .js files) and just one php file. </description>
		<content:encoded><![CDATA[<p>Same here. They &#8220;hacked&#8221; our website i think through ftp and installed the above code. The url of the javascript doesn&#8217;t exist and the funny thing is that google got it just before i could do something. (i found it straight away)</p>
<p>Now i changed ftp password and changed also the infected files. (mostly .js files) and just one php file.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edgar</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-283</link>
		<dc:creator>Edgar</dc:creator>
		<pubDate>Wed, 18 Aug 2010 02:39:19 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-283</guid>
		<description>we got it pretty bad 
 
inkrainbow.ru/quicktime.js 
 
pocketbloke.ru/QuickTime.js 
 
Search &quot;.ru&quot; (4255 hits in 1298 files) 
not all of them are the address but most are 
 </description>
		<content:encoded><![CDATA[<p>we got it pretty bad </p>
<p>inkrainbow.ru/quicktime.js </p>
<p>pocketbloke.ru/QuickTime.js </p>
<p>Search &quot;.ru&quot; (4255 hits in 1298 files)<br />
not all of them are the address but most are</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Back with a Vengeance: The Downtime is over!</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-222</link>
		<dc:creator>Back with a Vengeance: The Downtime is over!</dc:creator>
		<pubDate>Tue, 03 Aug 2010 12:17:39 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-222</guid>
		<description>[...] you will have noticed that this site has been down for the last few days weeks. Not good I know! A nasty hacker attack was responsible and I was just too busy getting everybody else&#8217;s project back up and running [...]</description>
		<content:encoded><![CDATA[<p>[...] you will have noticed that this site has been down for the last few days weeks. Not good I know! A nasty hacker attack was responsible and I was just too busy getting everybody else&#8217;s project back up and running [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adi</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-214</link>
		<dc:creator>adi</dc:creator>
		<pubDate>Sat, 31 Jul 2010 15:19:53 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-214</guid>
		<description>Same problem as above, several sites got infected and i use CentOS, Cpanel and FileZila.

I think we had a similar problem about 6/7 months a go where all our index files got infected. but since then i have move to a new saver but with the same company .</description>
		<content:encoded><![CDATA[<p>Same problem as above, several sites got infected and i use CentOS, Cpanel and FileZila.</p>
<p>I think we had a similar problem about 6/7 months a go where all our index files got infected. but since then i have move to a new saver but with the same company .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay Versluis</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-212</link>
		<dc:creator>Jay Versluis</dc:creator>
		<pubDate>Sat, 31 Jul 2010 13:31:09 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-212</guid>
		<description>@ Jeremy
What a pain... Good luck ;-)

@Alex79
Sounds serious. See if you can get in touch with your hosting provider. If they can&#039;t help you, sign up with me and &lt;a href=&quot;http://wpguru.co.uk/hosting/&quot; rel=&quot;nofollow&quot;&gt;get excellent hosting with Wordpress pre-installed&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>@ Jeremy<br />
What a pain&#8230; Good luck <img src='http://wpguru.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>@Alex79<br />
Sounds serious. See if you can get in touch with your hosting provider. If they can&#8217;t help you, sign up with me and <a href="http://wpguru.co.uk/hosting/" rel="nofollow">get excellent hosting with WordPress pre-installed</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ALEX79</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-209</link>
		<dc:creator>ALEX79</dc:creator>
		<pubDate>Sat, 31 Jul 2010 09:25:28 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-209</guid>
		<description>MY SITE HAS BEN     hacked by * Malepad.ru

document.write(&#039;&#039;)
I CLEAN THE FILES ITS WORK SOME TIME BUT  NOW I KANT LOGHIN IN MY WORDPRESS CONTROL PANEL  GIVE ERROR 500 INTERNAL SERVER ERROR END MY SITE GIVE ERROR 500 INTERNAL SERVER ERROR ..I DELET EVERYTHING DATABASE EVERYTHING..BUT  I KANT INSTAL A NEW  FRESH WORDPRESS ..IN  ME 500 INTERNAL SERVER ERROR!!
PLISS HELPPP</description>
		<content:encoded><![CDATA[<p>MY SITE HAS BEN     hacked by * Malepad.ru</p>
<p>document.write(&#8221;)<br />
I CLEAN THE FILES ITS WORK SOME TIME BUT  NOW I KANT LOGHIN IN MY WORDPRESS CONTROL PANEL  GIVE ERROR 500 INTERNAL SERVER ERROR END MY SITE GIVE ERROR 500 INTERNAL SERVER ERROR ..I DELET EVERYTHING DATABASE EVERYTHING..BUT  I KANT INSTAL A NEW  FRESH WORDPRESS ..IN  ME 500 INTERNAL SERVER ERROR!!<br />
PLISS HELPPP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-4/#comment-207</link>
		<dc:creator>Jeremy</dc:creator>
		<pubDate>Fri, 30 Jul 2010 16:15:00 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-207</guid>
		<description>Also hacked. We had the malepad.ru in all our js files. We don&#039;t use filezilla. Since the DB&#039;s seem unaffected and based on comments above I&#039;m leaning towards FTP breach. Obviously we&#039;ve changed all the FTP passwords. Off to fix all the js files now....</description>
		<content:encoded><![CDATA[<p>Also hacked. We had the malepad.ru in all our js files. We don&#8217;t use filezilla. Since the DB&#8217;s seem unaffected and based on comments above I&#8217;m leaning towards FTP breach. Obviously we&#8217;ve changed all the FTP passwords. Off to fix all the js files now&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Roundstorm Virus/Trojan Information &#124;</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-3/#comment-204</link>
		<dc:creator>The Roundstorm Virus/Trojan Information &#124;</dc:creator>
		<pubDate>Thu, 29 Jul 2010 18:28:23 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-204</guid>
		<description>[...] few days later and I managed to find a blog that was discussing the virus, and also talking about the different forms/variations it came [...]</description>
		<content:encoded><![CDATA[<p>[...] few days later and I managed to find a blog that was discussing the virus, and also talking about the different forms/variations it came [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Olly</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-3/#comment-203</link>
		<dc:creator>Olly</dc:creator>
		<pubDate>Thu, 29 Jul 2010 17:50:39 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-203</guid>
		<description>http://forum.filezilla-project.org/viewtopic.php?f=1&amp;t=11003&amp;start=0

FYI

A search for filezilla, password, hack finds LOTS of stuff about it.

We had 3 accounts hacked on our server, however we cant work out how these three particular acocunts got owned.

I have filezilla on mine, and that could explain 2 of them, but the one other 1 is a mystery.

My mate uses filezilla, but only has HIS account saved.

The only explanation is that we both had/have a virus.

Im scanning every computer in the office with Malware Bytes.. Not found anything on mine yet tho!</description>
		<content:encoded><![CDATA[<p><a href="http://forum.filezilla-project.org/viewtopic.php?f=1&#038;t=11003&#038;start=0" rel="nofollow">http://forum.filezilla-project.org/viewtopic.php?f=1&#038;t=11003&#038;start=0</a></p>
<p>FYI</p>
<p>A search for filezilla, password, hack finds LOTS of stuff about it.</p>
<p>We had 3 accounts hacked on our server, however we cant work out how these three particular acocunts got owned.</p>
<p>I have filezilla on mine, and that could explain 2 of them, but the one other 1 is a mystery.</p>
<p>My mate uses filezilla, but only has HIS account saved.</p>
<p>The only explanation is that we both had/have a virus.</p>
<p>Im scanning every computer in the office with Malware Bytes.. Not found anything on mine yet tho!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay Versluis</title>
		<link>http://wpguru.co.uk/2010/07/the-drunkjeans-com-wordpress-hack-and-how-to-get-rid-of-it/comment-page-3/#comment-202</link>
		<dc:creator>Jay Versluis</dc:creator>
		<pubDate>Thu, 29 Jul 2010 17:38:19 +0000</pubDate>
		<guid isPermaLink="false">http://wpguru.co.uk/?p=460#comment-202</guid>
		<description>Yes I use Filezilla... and I also believe it&#039;s happening via FTP. Since I&#039;ve changed all the FTP passwords, the files are OK (although a certain IP address has tried to gain access into EVERY account).

Superb call Olly, that may well be how they got their hands on the passwords: FileZilla.

Hands up everybody who has their site hacked AND uses FileZilla.</description>
		<content:encoded><![CDATA[<p>Yes I use Filezilla&#8230; and I also believe it&#8217;s happening via FTP. Since I&#8217;ve changed all the FTP passwords, the files are OK (although a certain IP address has tried to gain access into EVERY account).</p>
<p>Superb call Olly, that may well be how they got their hands on the passwords: FileZilla.</p>
<p>Hands up everybody who has their site hacked AND uses FileZilla.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

