<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Yeap I got defaced</title>
	<atom:link href="http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/</link>
	<description>Skills to Pay the Bills</description>
	<lastBuildDate>Thu, 09 Feb 2012 05:45:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Want Links? Have Your Site Hacked! &#124; Xuru</title>
		<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/#comment-45206</link>
		<dc:creator>Want Links? Have Your Site Hacked! &#124; Xuru</dc:creator>
		<pubDate>Tue, 25 Dec 2007 22:54:37 +0000</pubDate>
		<guid isPermaLink="false">http://new.shoemoney.com/?p=332#comment-45206</guid>
		<description>[...] Written by Jeremy Luebke on October 12, 2006 &#8211; 8:29 pm -  Jeremy Shoemoney woke up to a big surprise. I feel for him. It happens to the best of us. I&#8217;m glad he was able to get everything back up [...]</description>
		<content:encoded><![CDATA[<p>[...] Written by Jeremy Luebke on October 12, 2006 &#8211; 8:29 pm &#8211;  Jeremy Shoemoney woke up to a big surprise. I feel for him. It happens to the best of us. I&#8217;m glad he was able to get everything back up [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: coop</title>
		<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/#comment-5713</link>
		<dc:creator>coop</dc:creator>
		<pubDate>Wed, 11 Apr 2007 06:11:13 +0000</pubDate>
		<guid isPermaLink="false">http://new.shoemoney.com/?p=332#comment-5713</guid>
		<description>dam... i didnt know there was that big of a vulnerability in phpbb</description>
		<content:encoded><![CDATA[<p>dam&#8230; i didnt know there was that big of a vulnerability in phpbb</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Mothner</title>
		<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/#comment-5712</link>
		<dc:creator>Mike Mothner</dc:creator>
		<pubDate>Fri, 30 Mar 2007 23:57:10 +0000</pubDate>
		<guid isPermaLink="false">http://new.shoemoney.com/?p=332#comment-5712</guid>
		<description>I guess looking at it positively, it&#039;s an honor to be worth defacing!</description>
		<content:encoded><![CDATA[<p>I guess looking at it positively, it&#8217;s an honor to be worth defacing!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; From Shoemoney.com - Yeap I got defaced - Best AdSense News</title>
		<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/#comment-5711</link>
		<dc:creator>&#187; From Shoemoney.com - Yeap I got defaced - Best AdSense News</dc:creator>
		<pubDate>Fri, 27 Oct 2006 01:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://new.shoemoney.com/?p=332#comment-5711</guid>
		<description>[...] inbetween 7am and 10am this morning the website looked like this: As soon as I saw it had been defaced I took the server off line (about 10am). Imaged it then had the drive reimaged with a fresh clean OS. Then I started to restore from tape backup. While restoring I went through the old logs [&#8230;] Read more&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] inbetween 7am and 10am this morning the website looked like this: As soon as I saw it had been defaced I took the server off line (about 10am). Imaged it then had the drive reimaged with a fresh clean OS. Then I started to restore from tape backup. While restoring I went through the old logs [&#8230;] Read more&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Overvold</title>
		<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/#comment-5710</link>
		<dc:creator>Richard Overvold</dc:creator>
		<pubDate>Mon, 23 Oct 2006 20:54:34 +0000</pubDate>
		<guid isPermaLink="false">http://new.shoemoney.com/?p=332#comment-5710</guid>
		<description>Man, I heard he showed a defaced site to get attention. This true Shoe? ;)</description>
		<content:encoded><![CDATA[<p>Man, I heard he showed a defaced site to get attention. This true Shoe? <img src='http://www.shoemoney.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zeeshan</title>
		<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/#comment-5709</link>
		<dc:creator>Zeeshan</dc:creator>
		<pubDate>Wed, 18 Oct 2006 20:37:45 +0000</pubDate>
		<guid isPermaLink="false">http://new.shoemoney.com/?p=332#comment-5709</guid>
		<description>This type of attack could have been contained to only that specific Web site (your friends&#039;) if PHP was executed in such a fashion that it had to adhere to a non-Apache user and group.

Often people run PHP via mod_php and therefore scripts inherit the UID/GUID of Apache, which is very unsafe, causing one script to be faulty and have all of the remaining sites get affected or have their private contents easily read (say database login information in a PHP configuration script).

You can apply a patch to suexec to execute the PHP under CGI mode to get back security, or if you wish to get security and performance, use FastCGI, which exceeds the performance of mod_php while giving back application safety.

View http://www.fastcgi.com/mod_fastcgi/docs/mod_fastcgi.html for more information. Lighttpd, an alternative to Apache, has native support to run PHP via FastCGI and can be found at http://www.lighttpd.net/ .

Good luck.</description>
		<content:encoded><![CDATA[<p>This type of attack could have been contained to only that specific Web site (your friends&#8217;) if PHP was executed in such a fashion that it had to adhere to a non-Apache user and group.</p>
<p>Often people run PHP via mod_php and therefore scripts inherit the UID/GUID of Apache, which is very unsafe, causing one script to be faulty and have all of the remaining sites get affected or have their private contents easily read (say database login information in a PHP configuration script).</p>
<p>You can apply a patch to suexec to execute the PHP under CGI mode to get back security, or if you wish to get security and performance, use FastCGI, which exceeds the performance of mod_php while giving back application safety.</p>
<p>View <a href="http://www.fastcgi.com/mod_fastcgi/docs/mod_fastcgi.html" rel="nofollow">http://www.fastcgi.com/mod_fastcgi/docs/mod_fastcgi.html</a> for more information. Lighttpd, an alternative to Apache, has native support to run PHP via FastCGI and can be found at <a href="http://www.lighttpd.net/" rel="nofollow">http://www.lighttpd.net/</a> .</p>
<p>Good luck.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Shoemoney defaced</title>
		<link>http://www.shoemoney.com/2006/10/12/yeap-i-got-defaced/#comment-5708</link>
		<dc:creator>&#187; Shoemoney defaced</dc:creator>
		<pubDate>Wed, 18 Oct 2006 14:20:26 +0000</pubDate>
		<guid isPermaLink="false">http://new.shoemoney.com/?p=332#comment-5708</guid>
		<description>[...] The attacker exploited a known phpbb2 vulnerability, running on a website Shoemoney was hosting for a friend, as Shoe is commenting the situation on shoemoney.com. Fortunately the attacker just replaced the index-page. You may take a look on this defacement screenshot of Shoemoney´s Blog taken by visitors [...]</description>
		<content:encoded><![CDATA[<p>[...] The attacker exploited a known phpbb2 vulnerability, running on a website Shoemoney was hosting for a friend, as Shoe is commenting the situation on shoemoney.com. Fortunately the attacker just replaced the index-page. You may take a look on this defacement screenshot of Shoemoney´s Blog taken by visitors [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

