<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	  <title>Ask MetaFilter questions tagged with hacked</title>
      <link>http://ask.metafilter.com/tags/hacked</link>
      <description>Questions tagged with 'hacked' at Ask MetaFilter.</description>
	  <pubDate>Mon, 11 May 2009 17:34:27 -0800</pubDate> <lastBuildDate>Mon, 11 May 2009 17:34:27 -0800</lastBuildDate>

      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>	  
	<item>
	<title>They HaX0r3D my PHP!</title>
	<link>http://ask.metafilter.com/121846/They%2DHaX0r3D%2Dmy%2DPHP</link>	
	<description>I discovered that my DreamHost account appears to have been &quot;hacked&quot;. What does this PHP code do and what&apos;s a good way to get rid of it? When I was playing around with my websites tonight I noticed tons of PHP files that weren&apos;t there before. &lt;a href=&quot;http://pastebin.com/m61ae0fc7&quot;&gt;This link&lt;/a&gt; is an example of one of the files that I found.&lt;br&gt;
&lt;br&gt;
In general, it appears that it takes any file matching *.(php|html|phps), renames it to &lt;em&gt;filename&lt;/em&gt;&lt;b&gt;&amp;lt;random alpha in A-Za-z&amp;gt;&lt;/b&gt;.php and sticks something similar to the above-linked PHP doc in it.&lt;br&gt;
&lt;br&gt;
I notified Dreamhost of the problem, hoping that they could dig through my backups and let me know when these files were created, but I&apos;m not holding my breath.&lt;br&gt;
&lt;br&gt;
1. Has anyone seen these before? They&apos;re quite hard to search Google for since it&apos;s almost completely random data.&lt;br&gt;
2. What does it do? I&apos;m assuming it&apos;s some sort of bot net drone code of some sort.&lt;br&gt;
3. It appears to have only created copies of files that are accessible from a Google search. e.g. I have a few &quot;private&quot; web pages that have obscure directory names that only I know. These files were not modified (but are clearly read/writeable with PHP).&lt;br&gt;
4. How do I clean it up nicely? I don&apos;t see any modifications to existing files, so I think I can just delete the files that were created. File sizes, names, etc. are all different.&lt;br&gt;
&lt;br&gt;
Thanks in advance!&lt;br&gt;
&lt;small&gt;Sorry for the meta-question. I&apos;d be able to narrow it down to one more specific question if I could Google it.&lt;/small&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.121846</guid>
	<pubDate>Mon, 11 May 2009 17:34:27 -0800</pubDate>
	<category>dreamhost</category>
	<category>hacked</category>
	<category>php</category>
	<category>server</category>
	<dc:creator>yellowbkpk</dc:creator>
	</item>
	<item>
	<title>Can I use htaccess to deny certain non-existent directories to avoid going through my Drupal site?</title>
	<link>http://ask.metafilter.com/110599/Can%2DI%2Duse%2Dhtaccess%2Dto%2Ddeny%2Dcertain%2Dnonexistent%2Ddirectories%2Dto%2Davoid%2Dgoing%2Dthrough%2Dmy%2DDrupal%2Dsite</link>	
	<description>Can I use htaccess to deny certain non-existent directories in order to avoid going through my Drupal site (which requires connecting to my database)? My Drupal site was hacked, though my content was not touched (which is why it went unnoticed for a while).  I eventually noticed and cleaned up several extra directories that had had thousands of subdirectories with spammer linking content.  The whole site is fresh and fixed but now I am getting a huge amount of 404 errors from all over the world, with people trying to access these old spam directories.  In Drupal, each time this happens, the 404 page is generated and the 404 error is logged, which means accessing the database, which means my database is straining just to issue all of these 404 denials.&lt;br&gt;
&lt;br&gt;
I just want a simple apache 404 page instead (but only for these spammer urls!).&lt;br&gt;
&lt;br&gt;
The former pages and subdirectories were all contained within three base directories (I&apos;ll call them spam1, spam2, spam3), and so I would like to use htaccess to simply deny any request for (e.g.):&lt;br&gt;
&lt;br&gt;
mysite.com/spam1/&lt;br&gt;
mysite.com/spam1/item34/spam.php&lt;br&gt;
mysite.com/spam2/item23/item5/anotherspam.php&lt;br&gt;
...&lt;br&gt;
&lt;br&gt;
And any other permutation.&lt;br&gt;
&lt;br&gt;
I don&apos;t know how to do this when the directories don&apos;t actually exist.  That is, I can recreate an empty folder called &quot;spam1&quot; and deny mysite.com/spam1/ requests with Apache, but this wouldn&apos;t deny any of the thousands of subdirectories -- as I said, Drupal steps in and takes over the 404 duties when the directory does not exist.&lt;br&gt;
&lt;br&gt;
Is there some way to do the kind of denial I want, to pre-empt Drupal and the database connections?  I do not control the server so htaccess may be my most powerful option.&lt;br&gt;
&lt;br&gt;
(Otherwise, maybe I have to reconfigure Drupal in some way?)</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.110599</guid>
	<pubDate>Fri, 02 Jan 2009 12:12:00 -0800</pubDate>
	<category>drupal</category>
	<category>hacked</category>
	<category>htaccess</category>
	<category>resolved</category>
	<category>spammers</category>
	<dc:creator>kosmonaut</dc:creator>
	</item>
	<item>
	<title>SEO word salad pornography?</title>
	<link>http://ask.metafilter.com/109571/SEO%2Dword%2Dsalad%2Dpornography</link>	
	<description>What in the world is going on with this website (subject of a &lt;a href=&quot;http://ask.metafilter.com/109564/How-much-fat-in-these-cookies&quot;&gt;recent askme&lt;/a&gt;)?   Have a look at these google results: &lt;a href=&quot;http://www.google.com/search?q=site%3Acarolscookies.com+inurl%3Alocator&quot;&gt;site:carolscookies.com inurl:locator&lt;/a&gt;.  Is this an indication that the website&apos;s been hacked, or is this the kind of disgusting behavior that passes for SEO these days? I tried to google the site for nutrition information to answer the original question, but my query turned up all these pages.  Rather than derail the original thread, I&apos;m asking a fresh question.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.109571</guid>
	<pubDate>Thu, 18 Dec 2008 19:49:39 -0800</pubDate>
	<category>google</category>
	<category>hack</category>
	<category>hacked</category>
	<category>pagerank</category>
	<category>resolved</category>
	<category>seo</category>
	<category>snakeoil</category>
	<dc:creator>jepler</dc:creator>
	</item>
	<item>
	<title>They hacked our Joomla, help!</title>
	<link>http://ask.metafilter.com/100863/They%2Dhacked%2Dour%2DJoomla%2Dhelp</link>	
	<description>We&apos;ve been hacked!  We were just about to upgrade the Joomla version, and then we get &lt;a href=&quot;http://bluuweb.com/MIKE/JoomlaCapture.JPG&quot;&gt;this.&lt;/a&gt;  Looks to be a ransom page, but we obviously want to reverse the hack.  How do we do this? We can still access the administrative panel, but obviously our user/pass doesn&apos;t work.  They were able to manipulate the hole in the older version 1.0.x (I forget the exact version it was, and can&apos;t check now) so can we do this as well?  I don&apos;t want to publish the site name here, but if someone has valid reasons for requiring it, I can PM it.  &lt;br&gt;
&lt;br&gt;
Not sure what other info is relevant, but I will be watching all day so ask away.&lt;br&gt;
&lt;br&gt;
Thanks.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.100863</guid>
	<pubDate>Thu, 04 Sep 2008 00:43:42 -0800</pubDate>
	<category>cms</category>
	<category>dirtbags</category>
	<category>hacked</category>
	<category>hacker</category>
	<category>hackerz</category>
	<category>joomla</category>
	<category>ransom</category>
	<dc:creator>wile e</dc:creator>
	</item>
	<item>
	<title>Someone hacked my&#8230; something... somehow</title>
	<link>http://ask.metafilter.com/98388/Someone%2Dhacked%2Dmy%2Dsomething%2Dsomehow</link>	
	<description>What do you do when you think you&apos;ve been hacked, but don&apos;t know how? This morning, when I tried to check my gmail with my iPhone, I got an error that the username/password combination was wrong. I was connected to my home network at the time. I re-entered the password in the iPhone settings and tried check it again. I got the error that the connection to the server &#8220;imap.gmail.com&#8221; failed. Feeling funny, I went to my Macbook and changed my gmail password in the google account settings. &lt;br&gt;
&lt;br&gt;
At lunch, I checked gmail from my work PC and noticed a spam message that got through which I found strange since gmail has been very good lately at blocking spam. The spam was sent from my account. I know that it&#8217;s easy enough to spoof this, but I did check my sent mail and there it was. Someone sent the email from me, to me. The email subject was: &#8220;Anjelina Jolie Free Video&#8221;. The content was: &#8220;The password on archive anjelina&#8221;. There was an attachment: Angelina_Jolie.rar which I did not open. It was sent at 12:32 pm. I was definitely at my desk during that time.&lt;br&gt;
&lt;br&gt;
I quickly changed my password again, and I made sure the new one was very strong. But, what now? Check my home and work machines for keystroke programs? Check to see if my home network has been hacked? How would I go about doing this, anyway? I feel like I need to change all my passwords now &#8211; bank, social networks, etc. &#8211; but what if they are watching me&#8230; Right Now!?!</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.98388</guid>
	<pubDate>Tue, 05 Aug 2008 11:05:14 -0800</pubDate>
	<category>hacked</category>
	<category>keystroke</category>
	<category>passwords</category>
	<category>privacy</category>
	<category>security</category>
	<category>spam</category>
	<category>virus</category>
	<dc:creator>studentbaker</dc:creator>
	</item>
	<item>
	<title>Mr. All-knowing Super-hacker/psychologist Mefite, I need your help securing our IRC conversations...</title>
	<link>http://ask.metafilter.com/96809/Mr%2DAllknowing%2DSuperhackerpsychologist%2DMefite%2DI%2Dneed%2Dyour%2Dhelp%2Dsecuring%2Dour%2DIRC%2Dconversations</link>	
	<description>Some really important info was leaked from our private IRC channel on our own server. Luckily, it was something that most people wouldn&apos;t believe without real proof, which the leaker didn&apos;t really have. So we&apos;re glad to have not been in a real shit-hit-the-fan situation yet. Can you find the weak link, or atleast offer suggestions on how to stop this from happening again? A little bit of info about our setup... We own our own dedicated server which runs a public IRCD (UnrealIRCD latest stable version if you&apos;re curious). On this network, we have our own invite-only private channel which only about 10-14 people have access to. The channel is +i and +k with a large enough key that cannot be bruteforced. On top of that, we use &lt;a href=&quot;http://fish.sekure.us&quot;&gt;FiSH encryption (blowfish)&lt;/a&gt; inside the channel. The key for the channel is exchanged/given to others after initiating a PM session which is also blowfish encrypted after a Diffie-Hellman 1080 key-exchange. So we&apos;re pretty sure that our encryption key hasn&apos;t been sniffed at any point. Plus, even having the dedicated server rootkitted/trojanned wouldn&apos;t compromise our encrypted talk since it&apos;s only forwarding encrypted packets. All of us connect using one of the two clients - mirc and xchat.&lt;br&gt;
&lt;br&gt;
The only way to get something from this channel that I can think of is either someone leaking the info by mistake or on purpose, or people with trojans or keyloggers. We&apos;re pretty sure none of us are infected after running multiple scans for rootkits, viruses/trojans and checking outgoing/incoming connections and processes. But it obviously cannot be ruled out since none of the tools are 100% trustworthy when it comes to detection. About someone leaking info from here, well, I&apos;d like to think it&apos;s impossible. All of us have been a part of this channel for upwards of a year now, would trust each other, and have had access to a lot more important stuff than what was leaked. If someone wanted to make a profit off it, they could have done so quite a long time ago... Again, not ruling it out, but if there is another explanation for this leak, I&apos;d put my faith in it being that one instead of the theory of a leaker.&lt;br&gt;
&lt;br&gt;
The info was posted on a bunch of public forums. We&apos;re friends with the admins of all those public forums and had access to the poster&apos;s ip. Unfortunately, all of them were known TOR ips, so we cannot really find out who it was.&lt;br&gt;
&lt;br&gt;
So, super-hacker mefites, find our weak link, and offer me suggestions on how I/we can make it even more secure. If you&apos;re a super psychologist (or is it psychiatrist?), you can even offer suggestions on how I could find the leaker by observing behavior patterns. Thanks!&lt;br&gt;
&lt;br&gt;
anonymous throwaway mail for this question: mefitempmailacc@gmail.com</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.96809</guid>
	<pubDate>Wed, 16 Jul 2008 23:47:24 -0800</pubDate>
	<category>encryption</category>
	<category>hacked</category>
	<category>irc</category>
	<category>ircd</category>
	<category>rootkit</category>
	<category>trojan</category>
	<dc:creator>Anonymous</dc:creator>
	</item>
	<item>
	<title>What happened with my cell phone Saturday night?</title>
	<link>http://ask.metafilter.com/95416/What%2Dhappened%2Dwith%2Dmy%2Dcell%2Dphone%2DSaturday%2Dnight</link>	
	<description>Did someone hack my cell phone or somehow use my number?  Do I need to worry about my phone being compromised or something?  Someone left a voicemail for my friend and there&apos;s no outgoing call on my phone nor would anyone have had access to it (it was at my house, we were asleep.)  When I checked my phone log, I found that a few minutes earlier I had a missed call from someone who does not have my number and denies having called me. Both of these calls happened just after 2:30am saturday night/sunday morning.  Our entire social group was at a party Saturday night including the girl who got a message from me and the guy who I have a missed call from.  My girlfriend and I went home around midnight.  My phone was locked in our car while we were at the bar, and was in a semi-private room (although anyone could have access to it) while at the earlier event.&lt;br&gt;
&lt;br&gt;
The girl&apos;s voicemail message says starts out &quot;I&apos;m calling you from [palegirl]&apos;s phone...&quot; and goes on to talk about how &quot;I know you&apos;ve never liked me but I don&apos;t know why!&quot; drama-drama.  It&apos;s a female voice that we can&apos;t identify, but they used nicknames and clearly are members of our social group.&lt;br&gt;
&lt;br&gt;
The missed call I got is from my current girlfriend&apos;s ex-boyfriend.  My girlfriend recognized his number when we were investigating the voicemail my friend got.  He was at the party too.  He and I aren&apos;t friends, and my gf and I don&apos;t even know if he knows the nature of our relationship.  My girlfriend called him today and asked him if he called me and he denies it and she believes him.  &lt;br&gt;
&lt;br&gt;
We think someone is messing around with us.  Is this possible?&lt;br&gt;
&lt;br&gt;
It&apos;s a true fact that no one made a call from my phone to leave my friend that voicemail, but her phone shows my phone number as the received call, and the voicemailer explicitly says she&apos;s calling from my phone.&lt;br&gt;
&lt;br&gt;
Do I need to change my number and or get a new phone or anything else?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.95416</guid>
	<pubDate>Mon, 30 Jun 2008 14:05:33 -0800</pubDate>
	<category>cellphone</category>
	<category>hacked</category>
	<dc:creator>palegirl</dc:creator>
	</item>
	<item>
	<title>The website got hacked. What now?</title>
	<link>http://ask.metafilter.com/92773/The%2Dwebsite%2Dgot%2Dhacked%2DWhat%2Dnow</link>	
	<description>A website I programmed got hacked. Credit card numbers were compromised. What do I do now? I found the security hole and plugged it up, but at least one or two credit cards have already been stolen. There are a few hundred orders (less than 300) in the system. According to the error logs there were hits to the backend from the UK and Africa.&lt;br&gt;
&lt;br&gt;
Obviously, I will recommend that all of the customers be notified. I don&apos;t suppose there&apos;s any way to do this in a classy manner that won&apos;t make our client look bad.&lt;br&gt;
&lt;br&gt;
The worst of all is that the client will obviously suffer -- who knows how many of their customers will stop buying from them -- when it was not their fault. I feel like there is nothing I can do to resolve this problem...it&apos;s like a nightmare I can&apos;t wake up from. Please, please help.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.92773</guid>
	<pubDate>Fri, 30 May 2008 08:57:14 -0800</pubDate>
	<category>creditcards</category>
	<category>hacked</category>
	<category>website</category>
	<dc:creator>Anonymous</dc:creator>
	</item>
	<item>
	<title>Why&apos;d my reliable mac crash so violently?</title>
	<link>http://ask.metafilter.com/91514/Whyd%2Dmy%2Dreliable%2Dmac%2Dcrash%2Dso%2Dviolently</link>	
	<description>My 15&quot; Powerbook from 2003, running OS X.3, just froze up and demanded that I restart my computer. Why? The screen grayed out and a message popped up telling me to restart my computer in English, German and a couple of other languages, in front of a graphic of the apple power logo.&lt;br&gt;
&lt;br&gt;
Was it some kind of kernel crash? I&apos;ve gone through my logs and don&apos;t see anything out of the ordinary.&lt;br&gt;
&lt;br&gt;
I&apos;ve never seen anything like this. Has my computer been hacked, or was it just running so long that a serious crash was bound to happen? (Disclosure: I&apos;ve been using OS9 support recently.)</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.91514</guid>
	<pubDate>Thu, 15 May 2008 15:31:31 -0800</pubDate>
	<category>cracked</category>
	<category>crash</category>
	<category>forcedrestart</category>
	<category>hacked</category>
	<category>Mac</category>
	<category>OSX</category>
	<category>restart</category>
	<dc:creator>thecaddy</dc:creator>
	</item>
	<item>
	<title>Yahoo Email Hacked! Help!</title>
	<link>http://ask.metafilter.com/90901/Yahoo%2DEmail%2DHacked%2DHelp</link>	
	<description>My Yahoo! email was hacked. What can I do? My Yahoo! email address was hacked and now I can&apos;t get in. They sent email to my friends and family saying I was stranded in Canada and that I needed money. Obviously, this isn&apos;t true. The hacker has changed my acct information and I cannot retrieve or change my password thru yahoo&apos;s forgot password mechanism. What can I do? Who can I contact? Is there some one I can call at Yahoo? I searched their help pages and cannot find any info related to my situation.&lt;br&gt;
&lt;br&gt;
I need to get this acct back, as it is tied to my flickr and countless other online accts!&lt;br&gt;
&lt;br&gt;
Please help. Thanks.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.90901</guid>
	<pubDate>Thu, 08 May 2008 11:09:02 -0800</pubDate>
	<category>email</category>
	<category>hacked</category>
	<category>hijacked</category>
	<category>yahoo</category>
	<dc:creator>blueplasticfish</dc:creator>
	</item>
	<item>
	<title>hacked again</title>
	<link>http://ask.metafilter.com/90639/hacked%2Dagain</link>	
	<description>Site hacked again 4 years later. I need some advice. So about 4 years I asked this &lt;a href=&quot;http://ask.metafilter.com/10198/&quot;&gt;question&lt;/a&gt;. Nothing much happened to my site then other than a index.html file was created which defaced my site. &lt;br&gt;
Then today I get a not too official email from paypal telling me my site has been compromised. The email looked weird and had a url in it within my site. I open a new tab hand type the url and it exists. &lt;br&gt;
I ssh into my site ls -alt to find most recent changes. I had not done anything in 2008 so it was really obvious what was new and modified. So I clean up the mess and change login info.&lt;br&gt;
I renamed and moved the new files so I could look at them and find r57shell was used. mail logs have tons of out going. &lt;br&gt;
The oldest file that was changed was from end of Jan 08. My logs only go back to mid March, so I can not see what got through. I had changed my old code to ignore variables with www or http. I do have awstats which I perused through pages/urls to see if anything in Jan stuck out. Nothing did. &lt;br&gt;
I&apos;m going to redo the site completely, but wonder how they got in.&lt;br&gt;
And paypal/ebay asked me to help by giving them any logs that might help them.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.90639</guid>
	<pubDate>Mon, 05 May 2008 20:43:45 -0800</pubDate>
	<category>hacked</category>
	<category>php</category>
	<category>resolved</category>
	<dc:creator>sailormouth</dc:creator>
	</item>
	<item>
	<title>My blog has become a playground for filthy pornmongers!</title>
	<link>http://ask.metafilter.com/88549/My%2Dblog%2Dhas%2Dbecome%2Da%2Dplayground%2Dfor%2Dfilthy%2Dpornmongers</link>	
	<description>How can I restore my totally disgustingly porn-hacked Wordpress blog to its former pristine state? Ugh. My Wordpress blog, hosted by phpwebhosting, has been invaded by the grossest spammer on earth. &lt;br&gt;
&lt;br&gt;
Every individual post has been altered, with hundreds of lines unspeakably filthy links, enclosed in div tags. &lt;br&gt;
&lt;br&gt;
In addition, comments are continuously being posted to every post, which appear to be coming from me (the blog name as the commenter). &lt;br&gt;
&lt;br&gt;
I am locked out Wordpress, insofar as I cannot edit posts, post new ones, or make any security changes (I tried turning off comments, putting my spam blockers at their highest security levels, etc. &lt;br&gt;
&lt;br&gt;
I have been using MarsEdit (as once recommended to me by AskMe users--thank you!) to make new posts and go in to each post and delete the horrifying spam. But there are hundreds if not thousands of posts.&lt;br&gt;
&lt;br&gt;
1. Help!&lt;br&gt;
2. Is there a way to batch edit all the affected posts? It seems that there are a handful every 10 or 12 or so that have not been touched.&lt;br&gt;
3. How do I get back into Wordpress and regain control of my blog?&lt;br&gt;
4. Has this happened before? What is going on?&lt;br&gt;
&lt;br&gt;
I am using Wordpress 2.04 but cannot update. I emailed the abuse line of the spammer&apos;s IP address but that won&apos;t help me with the situation on my end, but might get the spammer(s) to stop the madness.&lt;br&gt;
&lt;br&gt;
Thank you so much. &lt;br&gt;
&lt;br&gt;
Is there anything I can do? I contacted Wordpress &amp;amp; phpwebhosting and posted on the Wordpress support forums.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.88549</guid>
	<pubDate>Fri, 11 Apr 2008 12:54:37 -0800</pubDate>
	<category>blog</category>
	<category>comments</category>
	<category>hacked</category>
	<category>lockedout</category>
	<category>wordpress</category>
	<dc:creator>Drohan</dc:creator>
	</item>
	<item>
	<title>Great, just what I needed... a hot HTML injection.</title>
	<link>http://ask.metafilter.com/80535/Great%2Djust%2Dwhat%2DI%2Dneeded%2Da%2Dhot%2DHTML%2Dinjection</link>	
	<description>Pages on my website are getting strange javascript, iframes, &amp;amp; links placed in them... This isn&apos;t affecting the other sites I host... what&apos;s going on? I have several websites I host from a reseller account, though I don&apos;t actually sell any of my space. Most of the sites are just placeholder pages or projects I started and never finished, so they sit alone and unloved most of the time.&lt;br&gt;
&lt;br&gt;
Looking around online, I see things about &quot;Injected&quot; Links, and of course the incident with Al Gore&apos;s site. But, how is this happening? It doesn&apos;t seem to affect the pages that are updated via Moveable Type and it doesn&apos;t seem to affect the sites &quot;under&quot; the main one. &lt;br&gt;
&lt;br&gt;
I uploaded an HTML file on Monday afternoon for a friend and by Tuesday morning when he went to save it, it had an iframe injected into it.&lt;br&gt;
&lt;br&gt;
Please note that this doesn&apos;t appear to be a Movable Type problem, as these are files that seem least likely to have the iframe or random links.&lt;br&gt;
&lt;br&gt;
It would seem that the webserver is insecure. Is this something that is my own fault or is this the problem of my webhost? What can I do to stop/prevent/fix this?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.80535</guid>
	<pubDate>Tue, 08 Jan 2008 23:18:06 -0800</pubDate>
	<category>hacked</category>
	<category>hosting</category>
	<category>injectedlinks</category>
	<category>website</category>
	<dc:creator>aristan</dc:creator>
	</item>
	<item>
	<title>Help me snatch a hacker/spammer</title>
	<link>http://ask.metafilter.com/79859/Help%2Dme%2Dsnatch%2Da%2Dhackerspammer</link>	
	<description>My hotmail acct has been hacked/cracked and is being used to spam people including a few MeFites.  I&apos;m pissed and concerned.  Please hope me! I&apos;ve changed my password to something I think is pretty uncrackable but it&apos;s still happening.  &lt;br&gt;
&lt;br&gt;
Ultimately, I know, I should just use a g-mail acct.  But in the mean time, what can I do to investigate, complain and secure the info that exists there in my acct?&lt;br&gt;
&lt;br&gt;
It&apos;s also odd that at least one Mefite has been spammed who I&apos;ve never had contacted with hotmail.  So I believe that this might be MeFi related too.&lt;br&gt;
&lt;br&gt;
p.s.  Should I post a PSA to MeTa to let folks know that I&apos;m not spamming them?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.79859</guid>
	<pubDate>Mon, 31 Dec 2007 16:24:09 -0800</pubDate>
	<category>cracked</category>
	<category>hacked</category>
	<category>hotmail</category>
	<category>password</category>
	<category>spam</category>
	<dc:creator>snsranch</dc:creator>
	</item>
	<item>
	<title>Has my computer been hacked?</title>
	<link>http://ask.metafilter.com/66707/Has%2Dmy%2Dcomputer%2Dbeen%2Dhacked</link>	
	<description>There&apos;s a brand-new user account showing up on my Windows XP SP2 desktop.  Only thing is, I didn&apos;t create it, and nobody else has physical access to my machine. This just showed up a couple of days ago.  The account is called ASP.NET Machine A... (the ellipsis is part of the name).  It is a limited account, password protected.&lt;br&gt;
&lt;br&gt;
Has my computer been hacked?  If not, then what?&lt;br&gt;
&lt;br&gt;
I know I can just delete the account since I&apos;m an administrator.  But are there other steps I can/should take?  And what can I do to prevent this from happening again?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.66707</guid>
	<pubDate>Tue, 10 Jul 2007 20:29:34 -0800</pubDate>
	<category>account</category>
	<category>aspnet</category>
	<category>computer</category>
	<category>hacked</category>
	<category>windows</category>
	<dc:creator>number9dream</dc:creator>
	</item>
	<item>
	<title>Can an Oyster Card be hacked?</title>
	<link>http://ask.metafilter.com/65377/Can%2Dan%2DOyster%2DCard%2Dbe%2Dhacked</link>	
	<description>Can an Oyster Card be hacked? As i was leaving the tube yesterday a security guard scanned my oyster card with a handheld device just before I was about to scan out through the barrier.&lt;br&gt;
&lt;br&gt;
This made me wonder why?.. what was it his handheld scanner would show that the normal barrier scanner couldn&apos;t pickup. The only thing i could think of was that somehow oyster cards can be faked and he was checking the status of the card against the main central database.&lt;br&gt;
&lt;br&gt;
Oyster card?&lt;br&gt;
if your wondering what an oyster card is.. its a new contactles smartcard that you use instead of a normal ticket on the london underground. It uses Philips&apos; MIFARE Standard 1k chips provided by G&amp;amp;D and SchlumbergerSema. It is the same contactless smartcard as Touch &apos;n Go card in Malaysia which is mainly used for tollway fares.&lt;br&gt;
http://en.wikipedia.org/wiki/Oyster_card&lt;br&gt;
&lt;br&gt;
I found a MIFARE card writer on ebay.. could this do it?&lt;br&gt;
http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&amp;amp;item=250134169733&lt;br&gt;
&lt;br&gt;
So my question is..&lt;br&gt;
1.) can Oyster cards be hacked and faked?&lt;br&gt;
2.) How would it be done?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2007:site.65377</guid>
	<pubDate>Fri, 22 Jun 2007 06:45:17 -0800</pubDate>
	<category>card</category>
	<category>hacked</category>
	<category>MIFARE</category>
	<category>Oyster</category>
	<category>smartcard</category>
	<dc:creator>complience</dc:creator>
	</item>
	<item>
	<title>Can you help me translate my hacked website from Polish to English?</title>
	<link>http://ask.metafilter.com/50547/Can%2Dyou%2Dhelp%2Dme%2Dtranslate%2Dmy%2Dhacked%2Dwebsite%2Dfrom%2DPolish%2Dto%2DEnglish</link>	
	<description>Can you translate this short paragraph from Polish into English please?  It involves some &quot;L33t&quot; speak so it may be challenging. To make a long story short, my wordpress blog was hacked.  I just want to make sure it doesn&apos;t say anything about my family or anything threatening.&lt;br&gt;
-----------------------------------------------------------&lt;br&gt;
szczegolnie gorace pozdrowka dla &lt;strong&gt;KwIaTuSzk&apos;A=)&lt;/strong&gt; - ktora gdzies tam gleboko sie smuci... :* &lt;br&gt;
&lt;br&gt;
witam i pozdrawiam, przykro mi ze macie tak zle zabezpieczona strone ze daje sie zrobic cos takiego ale takie zycie :)&lt;br&gt;
&lt;br&gt;
Pozdrowka dla Kasi :*(szkoda ze nie caluje tak jak kiedys :(... ), cherry, ESPI (wymieniam tych co byli na czacie no i cos jesio &lt;mhihi&gt;)&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
ne0 3mam za Ciebie kciuki :)&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
respect 4: ETM T34M &lt;br&gt;
&lt;br&gt;
http://cssource.info/forum/style_images/1/logo4.gif&quot; &lt;br&gt;
&lt;br&gt;
&lt;strong&gt;own3d by dar0&lt;/strong&gt;&lt;/mhihi&gt;&lt;br&gt;
&lt;br&gt;
ps... badziewne te zdjecia na dole co nie? :D&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
----------------------------&lt;br&gt;
btw, I took out the link to the picture, as I don&apos;t want their servers seeing metafilter</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.50547</guid>
	<pubDate>Thu, 09 Nov 2006 12:33:09 -0800</pubDate>
	<category>hacked</category>
	<category>help</category>
	<category>polish</category>
	<category>translate</category>
	<dc:creator>allthewhile</dc:creator>
	</item>
	<item>
	<title>They changed my password and security question.</title>
	<link>http://ask.metafilter.com/47662/They%2Dchanged%2Dmy%2Dpassword%2Dand%2Dsecurity%2Dquestion</link>	
	<description>Any ideas on how to retaliate against someone who hacked into my email account and changed my password? Or should I even bother? I got into a quarrel with someone on another board. They had posted a nasty message on that board, and I replied to them directly (off board) asking them what the hell their problem was. They replied directly to me with some name-calling and obscenities. I told them to grow up. The next time I tried to log into my email, I found that both the password and the security question had been changed. &lt;br&gt;
&lt;br&gt;
A talented friend is going to help me hack back into my account (though I certainly won&#8217;t be using that account anymore). Now I&#8217;m wondering what, if anything, I should do about the person I believe is responsible. I don&#8217;t know for certain if this person actually did the hacking, obviously, but because of the tone of the emails, and the timing of the hacking, I strongly suspect they are.&lt;br&gt;
&lt;br&gt;
An added wrinkle is that originally I thought I was dealing with an adult. I&#8217;ve been thinking about the messages and the hacking itself, and I now wonder if I was actually dealing with a teenager, specifically a &lt;a href=&quot;http://www.urbandictionary.com/define.php?term=script+kiddie&quot;&gt;script kiddie&lt;/a&gt;. &lt;br&gt;
&lt;br&gt;
I don&#8217;t really want to hassle with someone who may be just a teenager, and honestly, I&#8217;ve got better things to do with my time.&lt;br&gt;
&lt;br&gt;
On the other hand, they hacked into my account and changed my password, and that ticks me off.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
So, any suggestions on how to teach the little snot a lesson &#8211; ideally something that would make them think twice before they pulled something like that again?&lt;br&gt;
&lt;br&gt;
Or should I just forget about it?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.47662</guid>
	<pubDate>Sun, 01 Oct 2006 17:11:07 -0800</pubDate>
	<category>email</category>
	<category>hacked</category>
	<category>password</category>
	<dc:creator>La Gata</dc:creator>
	</item>
	<item>
	<title>Wuz she hax0r3d?</title>
	<link>http://ask.metafilter.com/32063/Wuz%2Dshe%2Dhax0r3d</link>	
	<description>Wuz she hax0r3d?&lt;br&gt;Scenarios that explain this situation, please: Someone (not I) tries to connect to the &apos;Net on her AOHell account &amp;amp; gets an error message, the gist of which is &quot;Ain&apos;t gonna log you on; reppy5 is already logged on to your account at another location.&quot; reppy5 is &lt;em&gt;not&lt;/em&gt; one of the accounts/screen-names she has ever created. Has she been hacked? Used as a zombie? Hacked &lt;em&gt;by&lt;/em&gt; a zombie? A zombie for what, for spam? A few minutes later she logs onto the &apos;Net and DOES get online, she calls AOL and is told to change her password. That&apos;s all she is told &amp;amp; she can barely understand this much from the AOHell CSR. She asks them to investigate reppy5 &amp;amp; they tell her to e-mail the TOS-General. &lt;br&gt;
&lt;br&gt;
If she changed her password to something with letters (lower AND upper case) &amp;amp; numbers, it&apos;s not likely she&apos;ll be hacked again, right? Someone probably set up a program to run a random password generator on a list of confirmed usernames s/he got from AOL, got lucky with my friend, &amp;amp; now it&apos;s not likely to happen again? I&apos;m no Techno-God, I&apos;m just spex-you-lating.&lt;br&gt;
&lt;br&gt;
Various scenarios? Whahappened? She wants to e-mail reppy5--should she?&lt;br&gt;
&lt;br&gt;
Thanks, youse technorati ;-)&lt;br&gt;
&lt;small&gt;BTW, I only added &quot;britney spears&quot; to the list of tags on this post because anybody searching MeFi for info on Britney &lt;em&gt;deserves&lt;/em&gt; to be misdirected ;-)&lt;/small&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.32063</guid>
	<pubDate>Fri, 03 Feb 2006 20:16:28 -0800</pubDate>
	<category>aol</category>
	<category>computers</category>
	<category>hack</category>
	<category>hacked</category>
	<category>internet</category>
	<category>net</category>
	<category>spam</category>
	<category>zombie</category>
	<dc:creator>Shane</dc:creator>
	</item>
	<item>
	<title>Am I hacked? What now?</title>
	<link>http://ask.metafilter.com/30037/Am%2DI%2Dhacked%2DWhat%2Dnow</link>	
	<description>If you ran a Debian server and one day noticed that telnet and apt-get were segfaulting, how would you proceed? I&apos;m one of two admins on this server, and neither of us has made any changes in the last couple of months. This morning I noticed telnet and apt-get were wonky. Nothing unusual in the syslogs. It seems likely that someone has done something malicious.&lt;br&gt;
&lt;br&gt;
How would you proceed from here?&lt;br&gt;
&lt;br&gt;
jojopizza@askme:~$ telnet yahoo.com 80 &lt;br&gt;
Segmentation fault&lt;br&gt;
jojopizza@askme:~$ sudo apt-get update&lt;br&gt;
Segmentation fault&lt;br&gt;
jojopizza@askme:~$</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.30037</guid>
	<pubDate>Mon, 02 Jan 2006 14:37:53 -0800</pubDate>
	<category>hacked</category>
	<category>linux</category>
	<category>security</category>
	<category>server</category>
	<dc:creator>jojopizza</dc:creator>
	</item>
	<item>
	<title>XP lite?</title>
	<link>http://ask.metafilter.com/29049/XP%2Dlite</link>	
	<description>Has anyone used one of the hacked windows XP-lite distros? The ones that remove unnecessary stuff and leave you with a faster machine? a- how stable are they, can you use them for resource intensive apps like photoshop, autocad, etc.? b- do they support non-english keyboards? c- is the performance gain worth the hassle of finding and installing them? Yes, I know that they&apos;re illegal in some countries. Let&apos;s say I have a merely academic interest.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2005:site.29049</guid>
	<pubDate>Wed, 14 Dec 2005 11:46:39 -0800</pubDate>
	<category>hacked</category>
	<category>lite</category>
	<category>windows</category>
	<category>xp</category>
	<dc:creator>signal</dc:creator>
	</item>
	<item>
	<title>What do I do after a PHP site break-in?</title>
	<link>http://ask.metafilter.com/10198/What%2Ddo%2DI%2Ddo%2Dafter%2Da%2DPHP%2Dsite%2Dbreakin</link>	
	<description>A couple months ago my site was lightly hacked. It happened again on a site for a friend of my father, possibly not as lightly. --&amp;gt; The weakness in both cases for piss poor php coding. I had written the code a few years ago w/o thinking about vulnerability. Basically I had an index page and then index2.php (I know real original) for everything else. Content of other pages were loaded when the filename was passed in the querystring. &lt;br&gt;
One site passed the entire filename. The other site appended the extension on the file. &lt;br&gt;
Well some Brazilian haxors passed their url to a &quot;jpg&quot; with command line commands. Viola they can dink around some. Everything they did is in the logs. &lt;br&gt;
On my site they only wrote an index.html file after trying to get up in the server (unsuccessfully) to get to some config info. I deleted the file, rewrote my php code, and went on with my life. &lt;br&gt;
Well on the other site some files were loaded. &lt;br&gt;
Files include: f3, kmod, mremap, r0nin, telnetd, ptrace, tfmaster, some perl, C, eggdrop (tar), and psyBNC (tar). It mostly seems like they were setting up IRC stuff.&lt;br&gt;
I took all of their files/dirs and moved them. Changed all login info. I reworked my php to close the obvious hole.&lt;br&gt;
So after all of that backstory here is my question: What specifics should I look for in their trail (cmds in logs and actual files) to see if they were able to compromise anything serious?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2004:site.10198</guid>
	<pubDate>Tue, 14 Sep 2004 22:02:08 -0800</pubDate>
	<category>hack</category>
	<category>hacked</category>
	<category>hacking</category>
	<category>informationsecurity</category>
	<category>php</category>
	<category>resolved</category>
	<category>server</category>
	<category>web</category>
	<category>webdesign</category>
	<dc:creator>sailormouth</dc:creator>
	</item>
	
	</channel>
</rss>

