<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Three tips to protect your WordPress installation</title>
	<atom:link href="http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/</link>
	<description>neat fun stuff</description>
	<lastBuildDate>Sat, 21 Nov 2009 05:33:38 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Kat Young</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-399885</link>
		<dc:creator>Kat Young</dc:creator>
		<pubDate>Mon, 05 Oct 2009 02:55:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-399885</guid>
		<description>I have had my blog hacked over and over. I will try to edit my .htaccess file thanks =)</description>
		<content:encoded><![CDATA[<p>I have had my blog hacked over and over. I will try to edit my .htaccess file thanks =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russell</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-385971</link>
		<dc:creator>Russell</dc:creator>
		<pubDate>Tue, 01 Sep 2009 13:43:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-385971</guid>
		<description>Hi Matt
Hope you doing great!
Our blog has been hacked. Im getting all these wierd backlinks to my blog on other blogs but they hidden.  My blog developer says &quot;What the script does, apparently, is create those URL&#039;s on their site (that are linking back to you).&quot;

Thought it would interest you. We are working with Godaddy to fix the problem..

Best</description>
		<content:encoded><![CDATA[<p>Hi Matt<br />
Hope you doing great!<br />
Our blog has been hacked. Im getting all these wierd backlinks to my blog on other blogs but they hidden.  My blog developer says &#8220;What the script does, apparently, is create those URL&#8217;s on their site (that are linking back to you).&#8221;</p>
<p>Thought it would interest you. We are working with Godaddy to fix the problem..</p>
<p>Best</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: doruman</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-384361</link>
		<dc:creator>doruman</dc:creator>
		<pubDate>Sat, 29 Aug 2009 17:26:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-384361</guid>
		<description>Even if this post has more than a year old, here are very useful informations for any WP blogger. Thank you very much Matt for all that you offer as free informations, not only as Google employer.

 Kind regards,
Doru</description>
		<content:encoded><![CDATA[<p>Even if this post has more than a year old, here are very useful informations for any WP blogger. Thank you very much Matt for all that you offer as free informations, not only as Google employer.</p>
<p> Kind regards,<br />
Doru</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Redbrickstock</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-379343</link>
		<dc:creator>Redbrickstock</dc:creator>
		<pubDate>Fri, 21 Aug 2009 00:37:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-379343</guid>
		<description>Will the .htaccess thing work for a class B address. eg. allow from 64.233.169. ?</description>
		<content:encoded><![CDATA[<p>Will the .htaccess thing work for a class B address. eg. allow from 64.233.169. ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rory Siems</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-364971</link>
		<dc:creator>Rory Siems</dc:creator>
		<pubDate>Fri, 24 Jul 2009 02:45:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-364971</guid>
		<description>Hi Matt,

we just spent the day fixing my friend&#039;s wordpress site that apparently had some passthru exploit from a site on a Chinese domain routed through a Russian IP.

We upgraded Wordpress to the latest version, we upgraded all of the plugins to the latest version. The web developer who set up the website claimed that the malicious code installed on the site was not from a Wordpress vulnerability, but rather from a brute force attack on the web host.

I still am not 100% sure that a dictionary attack or brute force attack guessed the password as it was pretty obscure. To be safe I did subscribe to the wordpress development feed. I like the idea of obscuring plugins from snoops too.</description>
		<content:encoded><![CDATA[<p>Hi Matt,</p>
<p>we just spent the day fixing my friend&#8217;s wordpress site that apparently had some passthru exploit from a site on a Chinese domain routed through a Russian IP.</p>
<p>We upgraded Wordpress to the latest version, we upgraded all of the plugins to the latest version. The web developer who set up the website claimed that the malicious code installed on the site was not from a Wordpress vulnerability, but rather from a brute force attack on the web host.</p>
<p>I still am not 100% sure that a dictionary attack or brute force attack guessed the password as it was pretty obscure. To be safe I did subscribe to the wordpress development feed. I like the idea of obscuring plugins from snoops too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ByREV</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-345857</link>
		<dc:creator>ByREV</dc:creator>
		<pubDate>Sat, 13 Jun 2009 23:20:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-345857</guid>
		<description>i use mysql random passwd, only localhost in mysal connect, strong admin passwd with  14+ chars/numbers, 777 perm only for cache and uploads folder

btw, for mysql injection search in your site with google this words: wellbutrin, adipex, adderall, xanax, carisoprodol ... ex: site:http ://your.site.com xanax 

more words here: http://www.mattcutts.com/blog/helping-hacked-sites/ after line &quot;The following is some example hidden text we found at&quot;</description>
		<content:encoded><![CDATA[<p>i use mysql random passwd, only localhost in mysal connect, strong admin passwd with  14+ chars/numbers, 777 perm only for cache and uploads folder</p>
<p>btw, for mysql injection search in your site with google this words: wellbutrin, adipex, adderall, xanax, carisoprodol &#8230; ex: site:http ://your.site.com xanax </p>
<p>more words here: <a href="http://www.mattcutts.com/blog/helping-hacked-sites/" rel="nofollow">http://www.mattcutts.com/blog/helping-hacked-sites/</a> after line &#8220;The following is some example hidden text we found at&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Vanderhurst</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-333282</link>
		<dc:creator>Richard Vanderhurst</dc:creator>
		<pubDate>Tue, 19 May 2009 10:48:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-333282</guid>
		<description>A big thanks to this post... I just applied this on my wordpress blogs. Thanks again!</description>
		<content:encoded><![CDATA[<p>A big thanks to this post&#8230; I just applied this on my wordpress blogs. Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abhimanyu</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-330496</link>
		<dc:creator>Abhimanyu</dc:creator>
		<pubDate>Sat, 02 May 2009 17:49:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-330496</guid>
		<description>Hi, the problem #2 is fixed now in wordpress as it do not show plugins listing. If you are on a dynamic IP, its good not to do #1 step. Although you can use Country IP range.

Abhimanyu
http://mwolk.com</description>
		<content:encoded><![CDATA[<p>Hi, the problem #2 is fixed now in wordpress as it do not show plugins listing. If you are on a dynamic IP, its good not to do #1 step. Although you can use Country IP range.</p>
<p>Abhimanyu<br />
<a href="http://mwolk.com" rel="nofollow">http://mwolk.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Connie</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-284136</link>
		<dc:creator>Connie</dc:creator>
		<pubDate>Sat, 21 Mar 2009 11:14:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-284136</guid>
		<description>Two Questions:
If you exclude IP addresses, how can you write to your blog when you are on the road?

What about the way that IP addresses change, as with some ISPs?

Thanks.</description>
		<content:encoded><![CDATA[<p>Two Questions:<br />
If you exclude IP addresses, how can you write to your blog when you are on the road?</p>
<p>What about the way that IP addresses change, as with some ISPs?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-238555</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Fri, 06 Feb 2009 22:26:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-238555</guid>
		<description>Its great to hear a few guys mentioning our tools over at http://blogsecurity.net. 

Check out our free online WordPress vulnerability scanner if you get a chance... a new version has just been released, although, it still needs a lot of work.

Cheers</description>
		<content:encoded><![CDATA[<p>Its great to hear a few guys mentioning our tools over at <a href="http://blogsecurity.net" rel="nofollow">http://blogsecurity.net</a>. </p>
<p>Check out our free online WordPress vulnerability scanner if you get a chance&#8230; a new version has just been released, although, it still needs a lot of work.</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
</channel>
</rss>
