<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Magento sites hacked</title>
	<atom:link href="http://activecodeline.com/magento-sites-hacked/feed" rel="self" type="application/rss+xml" />
	<link>http://activecodeline.com/magento-sites-hacked</link>
	<description>Blog site of Branko Ajzele, web application developer.</description>
	<lastBuildDate>Tue, 07 Sep 2010 11:26:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: meph137</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-4369</link>
		<dc:creator>meph137</dc:creator>
		<pubDate>Thu, 15 Oct 2009 21:52:15 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-4369</guid>
		<description>Nice job for letting everyone know about this. That is one nasty bug, especially being as it attempted to send personal data elsewhere without being detected, ouch! :(

@colin - we have also seen an iframe-injecting nasty before. As you metioned, it broke Magento which was great, however it was nowhere near as serious as sending card data - it just attempted to spread itself.

It also sniffed FTP passwords from what we could gather. It was contracted due to a vulnerability in Adobe PDF reader on one of our machines and then it spread to others who visited any sites.

If magento is vulnerable to anything, it certainly seems wise to not 777 everything, something I have personally decided not to do. Glad I did :)</description>
		<content:encoded><![CDATA[<p>Nice job for letting everyone know about this. That is one nasty bug, especially being as it attempted to send personal data elsewhere without being detected, ouch! <img src='http://activecodeline.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>@colin &#8211; we have also seen an iframe-injecting nasty before. As you metioned, it broke Magento which was great, however it was nowhere near as serious as sending card data &#8211; it just attempted to spread itself.</p>
<p>It also sniffed FTP passwords from what we could gather. It was contracted due to a vulnerability in Adobe PDF reader on one of our machines and then it spread to others who visited any sites.</p>
<p>If magento is vulnerable to anything, it certainly seems wise to not 777 everything, something I have personally decided not to do. Glad I did <img src='http://activecodeline.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meph137</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-5679</link>
		<dc:creator>meph137</dc:creator>
		<pubDate>Thu, 15 Oct 2009 21:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-5679</guid>
		<description>Nice job for letting everyone know about this. That is one nasty bug, especially being as it attempted to send personal data elsewhere without being detected, ouch! :(

@colin - we have also seen an iframe-injecting nasty before. As you metioned, it broke Magento which was great, however it was nowhere near as serious as sending card data - it just attempted to spread itself.

It also sniffed FTP passwords from what we could gather. It was contracted due to a vulnerability in Adobe PDF reader on one of our machines and then it spread to others who visited any sites.

If magento is vulnerable to anything, it certainly seems wise to not 777 everything, something I have personally decided not to do. Glad I did :)</description>
		<content:encoded><![CDATA[<p>Nice job for letting everyone know about this. That is one nasty bug, especially being as it attempted to send personal data elsewhere without being detected, ouch! <img src='http://activecodeline.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>@colin &#8211; we have also seen an iframe-injecting nasty before. As you metioned, it broke Magento which was great, however it was nowhere near as serious as sending card data &#8211; it just attempted to spread itself.</p>
<p>It also sniffed FTP passwords from what we could gather. It was contracted due to a vulnerability in Adobe PDF reader on one of our machines and then it spread to others who visited any sites.</p>
<p>If magento is vulnerable to anything, it certainly seems wise to not 777 everything, something I have personally decided not to do. Glad I did <img src='http://activecodeline.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-4356</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sat, 10 Oct 2009 11:16:24 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-4356</guid>
		<description>Hello Branko,

You mentioned mentioned in your comments a manual patch... do you have any further information on this?

Reason I ask is that I have a magento website still on 1.3.0.0, I&#039;m hesitent to upgrade due to past issues I have had with the auto upgrading process... any information or instructions on manual patching would be fantastic - maybe another blog post for it? 

Many thanks
James</description>
		<content:encoded><![CDATA[<p>Hello Branko,</p>
<p>You mentioned mentioned in your comments a manual patch&#8230; do you have any further information on this?</p>
<p>Reason I ask is that I have a magento website still on 1.3.0.0, I&#8217;m hesitent to upgrade due to past issues I have had with the auto upgrading process&#8230; any information or instructions on manual patching would be fantastic &#8211; maybe another blog post for it? </p>
<p>Many thanks<br />
James</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-5678</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sat, 10 Oct 2009 11:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-5678</guid>
		<description>Hello Branko,

You mentioned mentioned in your comments a manual patch... do you have any further information on this?

Reason I ask is that I have a magento website still on 1.3.0.0, I&#039;m hesitent to upgrade due to past issues I have had with the auto upgrading process... any information or instructions on manual patching would be fantastic - maybe another blog post for it? 

Many thanks
James</description>
		<content:encoded><![CDATA[<p>Hello Branko,</p>
<p>You mentioned mentioned in your comments a manual patch&#8230; do you have any further information on this?</p>
<p>Reason I ask is that I have a magento website still on 1.3.0.0, I&#8217;m hesitent to upgrade due to past issues I have had with the auto upgrading process&#8230; any information or instructions on manual patching would be fantastic &#8211; maybe another blog post for it? </p>
<p>Many thanks<br />
James</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: branko</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-4351</link>
		<dc:creator>branko</dc:creator>
		<pubDate>Fri, 09 Oct 2009 06:33:11 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-4351</guid>
		<description>@jonathan :)</description>
		<content:encoded><![CDATA[<p>@jonathan <img src='http://activecodeline.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: branko</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-5677</link>
		<dc:creator>branko</dc:creator>
		<pubDate>Fri, 09 Oct 2009 06:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-5677</guid>
		<description>@jonathan :)</description>
		<content:encoded><![CDATA[<p>@jonathan <img src='http://activecodeline.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jonathan</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-4350</link>
		<dc:creator>jonathan</dc:creator>
		<pubDate>Thu, 08 Oct 2009 23:06:19 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-4350</guid>
		<description>Thanks for telling everyone Branko, this is not cool. 

@Colin - What mask should we be using - 755? 

Thanks,
Jonathan</description>
		<content:encoded><![CDATA[<p>Thanks for telling everyone Branko, this is not cool. </p>
<p>@Colin &#8211; What mask should we be using &#8211; 755? </p>
<p>Thanks,<br />
Jonathan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jonathan</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-5676</link>
		<dc:creator>jonathan</dc:creator>
		<pubDate>Thu, 08 Oct 2009 23:06:00 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-5676</guid>
		<description>Thanks for telling everyone Branko, this is not cool. 

@Colin - What mask should we be using - 755? 

Thanks,
Jonathan</description>
		<content:encoded><![CDATA[<p>Thanks for telling everyone Branko, this is not cool. </p>
<p>@Colin &#8211; What mask should we be using &#8211; 755? </p>
<p>Thanks,<br />
Jonathan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lloyd</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-4340</link>
		<dc:creator>Lloyd</dc:creator>
		<pubDate>Mon, 05 Oct 2009 16:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-4340</guid>
		<description>I&#039;m just wondering why Varien does not tell anyone about this? Especially for people running community version on production servers...</description>
		<content:encoded><![CDATA[<p>I&#8217;m just wondering why Varien does not tell anyone about this? Especially for people running community version on production servers&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lloyd</title>
		<link>http://activecodeline.com/magento-sites-hacked/comment-page-1#comment-5675</link>
		<dc:creator>Lloyd</dc:creator>
		<pubDate>Mon, 05 Oct 2009 16:58:00 +0000</pubDate>
		<guid isPermaLink="false">http://activecodeline.com/?p=894#comment-5675</guid>
		<description>I&#039;m just wondering why Varien does not tell anyone about this? Especially for people running community version on production servers...</description>
		<content:encoded><![CDATA[<p>I&#8217;m just wondering why Varien does not tell anyone about this? Especially for people running community version on production servers&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
