<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WMF vulnerability</title>
	<atom:link href="http://www.mattcutts.com/blog/wmf-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattcutts.com/blog/wmf-vulnerability/</link>
	<description>neat fun stuff</description>
	<lastBuildDate>Sat, 21 Nov 2009 05:33:38 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: john</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-103819</link>
		<dc:creator>john</dc:creator>
		<pubDate>Fri, 04 May 2007 04:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-103819</guid>
		<description>Additional info:

According to: (which I found via Google)
http://snort.iatp.by/acid/acid_qry_alert.php?submit=%236-(2-507)&amp;sort_order=
the code leads to a page on this site: (which has a GPR = 5)
http://www.red.by

What is the point of this?
How can this code be of any use against email spamming as suggested above?</description>
		<content:encoded><![CDATA[<p>Additional info:</p>
<p>According to: (which I found via Google)<br />
<a href="http://snort.iatp.by/acid/acid_qry_alert.php?submit=%236-(2-507)&amp;sort_order=" rel="nofollow">http://snort.iatp.by/acid/acid_qry_alert.php?submit=%236-(2-507)&amp;sort_order=</a><br />
the code leads to a page on this site: (which has a GPR = 5)<br />
<a href="http://www.red.by" rel="nofollow">http://www.red.by</a></p>
<p>What is the point of this?<br />
How can this code be of any use against email spamming as suggested above?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-93564</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Fri, 12 Jan 2007 05:46:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-93564</guid>
		<description>Funny enough for the past couple weeks I&#039;ve been searching for a good 
mathematics site to update my limited math&#039;s skills.

Thanks,sosmath.com looks to be jus what the doctor ordered.
Its funny how sometimes you find exactly what youre looking for
in the most unlikely of places.</description>
		<content:encoded><![CDATA[<p>Funny enough for the past couple weeks I&#8217;ve been searching for a good<br />
mathematics site to update my limited math&#8217;s skills.</p>
<p>Thanks,sosmath.com looks to be jus what the doctor ordered.<br />
Its funny how sometimes you find exactly what youre looking for<br />
in the most unlikely of places.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IncrediBILL</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-93522</link>
		<dc:creator>IncrediBILL</dc:creator>
		<pubDate>Thu, 11 Jan 2007 22:08:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-93522</guid>
		<description>I&#039;m mildly amused that many of the people responding to this thread think the only sites that have these types of scripts in them are those &quot;bad sites&quot; from the &quot;other side of the web&quot;.

Hate to burst all your bubbles (not really) but many of the sites with these scripts in them have been breached, or the &lt;a href=&quot;http://incredibill.blogspot.com/2007/01/multiple-shared-servers-hacked-at.html&quot; rel=&quot;nofollow&quot;&gt;entire shared server has been breached&lt;/a&gt;. Hundreds of innocent sites infected and nothing is being done about it by anyone.</description>
		<content:encoded><![CDATA[<p>I&#8217;m mildly amused that many of the people responding to this thread think the only sites that have these types of scripts in them are those &#8220;bad sites&#8221; from the &#8220;other side of the web&#8221;.</p>
<p>Hate to burst all your bubbles (not really) but many of the sites with these scripts in them have been breached, or the <a href="http://incredibill.blogspot.com/2007/01/multiple-shared-servers-hacked-at.html" rel="nofollow">entire shared server has been breached</a>. Hundreds of innocent sites infected and nothing is being done about it by anyone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: queenli</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-25306</link>
		<dc:creator>queenli</dc:creator>
		<pubDate>Mon, 08 May 2006 01:27:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-25306</guid>
		<description>ABC Amber Image Converter , The software supports a batch conversion, a run from command line, more than 50 languages and comes with an embedded viewer. Batch conversion ability allows you to convert a unlimited number of images at a time.

http://www.yaodownload.com/video-design/imagecompression/abc-image-converter_imagecompression.htm</description>
		<content:encoded><![CDATA[<p>ABC Amber Image Converter , The software supports a batch conversion, a run from command line, more than 50 languages and comes with an embedded viewer. Batch conversion ability allows you to convert a unlimited number of images at a time.</p>
<p><a href="http://www.yaodownload.com/video-design/imagecompression/abc-image-converter_imagecompression.htm" rel="nofollow">http://www.yaodownload.com/video-design/imagecompression/abc-image-converter_imagecompression.htm</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike C.</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-10999</link>
		<dc:creator>Mike C.</dc:creator>
		<pubDate>Mon, 23 Jan 2006 16:26:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-10999</guid>
		<description>RE the SOSMath disappearance: I don&#039;t see how those two pages shown (the ones with ads) are violations of the webmaster guidelines.  Perhaps I&#039;ve not read it carefully enough.  What part of the guidelines cover this particular offense?

What scares me (as a webmaster for a small group of web sites) is that I will unknowingly commit an error of this kind..

Google really should try to find a way to communicate the nature of an offense to a webmaster - I know that G wants to prevent hacking the algo, but this is really bad - having a site drop out of G&#039;s index without the webmaster knowing what caused it is just scary.  And I would think it tends to build up animosity from webmasters who are not really trying to game the system.</description>
		<content:encoded><![CDATA[<p>RE the SOSMath disappearance: I don&#8217;t see how those two pages shown (the ones with ads) are violations of the webmaster guidelines.  Perhaps I&#8217;ve not read it carefully enough.  What part of the guidelines cover this particular offense?</p>
<p>What scares me (as a webmaster for a small group of web sites) is that I will unknowingly commit an error of this kind..</p>
<p>Google really should try to find a way to communicate the nature of an offense to a webmaster &#8211; I know that G wants to prevent hacking the algo, but this is really bad &#8211; having a site drop out of G&#8217;s index without the webmaster knowing what caused it is just scary.  And I would think it tends to build up animosity from webmasters who are not really trying to game the system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: M.A. Khamsi</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-9477</link>
		<dc:creator>M.A. Khamsi</dc:creator>
		<pubDate>Mon, 09 Jan 2006 06:31:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-9477</guid>
		<description>Hi,
I agree with Elizabeth that it was a poor marketing decision.  For more on this is ssue please go to:
 http://www.mattcutts.com/blog/directory-of-home-page-widgets/#comment-9299
By the way I am one of the three creators of SOSMATH.
Cheers,
Mohamed</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I agree with Elizabeth that it was a poor marketing decision.  For more on this is ssue please go to:<br />
 <a href="http://www.mattcutts.com/blog/directory-of-home-page-widgets/#comment-9299" rel="nofollow">http://www.mattcutts.com/blog/directory-of-home-page-widgets/#comment-9299</a><br />
By the way I am one of the three creators of SOSMATH.<br />
Cheers,<br />
Mohamed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elizabeth</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-8296</link>
		<dc:creator>Elizabeth</dc:creator>
		<pubDate>Wed, 04 Jan 2006 20:38:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-8296</guid>
		<description>Matt,

Thank you for the info. I agree that the &quot;payday loans&quot; pages, entirely off-topic for the site, could easily have lead to the entire site having been banned.

While it&#039;s disappointing that this otherwise-valuable educational site made such a poor marketing decision, it&#039;s reassuring to me personally, since I would never degrade my site in this manner. I&#039;d been concerned that my educational site might accidentally be banned, and now I know that I needn&#039;t be worried.

Thank you!</description>
		<content:encoded><![CDATA[<p>Matt,</p>
<p>Thank you for the info. I agree that the &#8220;payday loans&#8221; pages, entirely off-topic for the site, could easily have lead to the entire site having been banned.</p>
<p>While it&#8217;s disappointing that this otherwise-valuable educational site made such a poor marketing decision, it&#8217;s reassuring to me personally, since I would never degrade my site in this manner. I&#8217;d been concerned that my educational site might accidentally be banned, and now I know that I needn&#8217;t be worried.</p>
<p>Thank you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-8174</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 04 Jan 2006 07:29:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-8174</guid>
		<description>Elizabeth, check the most recent archive.org version of the sosmath.com home page. Here ya go:
http://web.archive.org/web/20050329015405/http://www.sosmath.com/

Note on the left-hand side at the bottom of the column:
&quot;Featured Loans:
Payday loans&quot;

then start clicking. I believe sosmath.com was selling text pages and link on its site.</description>
		<content:encoded><![CDATA[<p>Elizabeth, check the most recent archive.org version of the sosmath.com home page. Here ya go:<br />
<a href="http://web.archive.org/web/20050329015405/http://www.sosmath.com/" rel="nofollow">http://web.archive.org/web/20050329015405/http://www.sosmath.com/</a></p>
<p>Note on the left-hand side at the bottom of the column:<br />
&#8220;Featured Loans:<br />
Payday loans&#8221;</p>
<p>then start clicking. I believe sosmath.com was selling text pages and link on its site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-8162</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Wed, 04 Jan 2006 02:57:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-8162</guid>
		<description>Note that some software may re-register shimgvw.dll when it doesn&#039;t see it there, so another workaround is to both unregister it, as Matt described above, and then rename the file to maybe something like shimgvw.dll.dead</description>
		<content:encoded><![CDATA[<p>Note that some software may re-register shimgvw.dll when it doesn&#8217;t see it there, so another workaround is to both unregister it, as Matt described above, and then rename the file to maybe something like shimgvw.dll.dead</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.mattcutts.com/blog/wmf-vulnerability/#comment-8161</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 04 Jan 2006 02:19:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/?p=148#comment-8161</guid>
		<description>hi, a friend&#039;s website was hacked recently (hosted by ipowerweb). The hackers inserted an iframe at the top of the site&#039;s index.php. The iframe pointed to a wmf file with the exploit. The site - trust4free.ws(do not go to this site) is currently listed in Googles index.</description>
		<content:encoded><![CDATA[<p>hi, a friend&#8217;s website was hacked recently (hosted by ipowerweb). The hackers inserted an iframe at the top of the site&#8217;s index.php. The iframe pointed to a wmf file with the exploit. The site &#8211; trust4free.ws(do not go to this site) is currently listed in Googles index.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
