<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Simianuprising.com now hopefully UN-hacked.</title>
	<atom:link href="http://simianuprising.com/2009/05/12/simianuprisingcom-now-hopefully-un-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://simianuprising.com/2009/05/12/simianuprisingcom-now-hopefully-un-hacked/</link>
	<description></description>
	<lastBuildDate>Sun, 07 Feb 2010 18:14:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: jeremyclarke</title>
		<link>http://simianuprising.com/2009/05/12/simianuprisingcom-now-hopefully-un-hacked/comment-page-1/#comment-99000</link>
		<dc:creator>jeremyclarke</dc:creator>
		<pubDate>Sun, 31 May 2009 15:58:09 +0000</pubDate>
		<guid isPermaLink="false">http://simianuprising.com/?p=720#comment-99000</guid>
		<description>@Steve: I would try to figure out when they first used their power on your site. In my experience they tend to use it right away. Did they edit any posts? In that case you could look at when it was edited. Check the modified dates on any plugin/theme/wp files they tampered with in FTP, that might give you hints about when they first got in (though be careful because they might have edited files then come back, in which case there could be old and new edits). 

Usually though if you have a database backup that&#039;s fairly recent you should try it out with fresh files. If you  change the account passwords and check all users then the real risk is really that they have files on your server, not access based on the database. 

If you meant the site files and that you can&#039;t be sure they are clean then you really just need to use whatever copy you have and look through every file. Replace all the wp ones, then go re-download any plugins and go through the recent uploads and make sure everything is what it seems to be (look at the photos).</description>
		<content:encoded><![CDATA[<p>@Steve: I would try to figure out when they first used their power on your site. In my experience they tend to use it right away. Did they edit any posts? In that case you could look at when it was edited. Check the modified dates on any plugin/theme/wp files they tampered with in FTP, that might give you hints about when they first got in (though be careful because they might have edited files then come back, in which case there could be old and new edits). </p>
<p>Usually though if you have a database backup that&#8217;s fairly recent you should try it out with fresh files. If you  change the account passwords and check all users then the real risk is really that they have files on your server, not access based on the database. </p>
<p>If you meant the site files and that you can&#8217;t be sure they are clean then you really just need to use whatever copy you have and look through every file. Replace all the wp ones, then go re-download any plugins and go through the recent uploads and make sure everything is what it seems to be (look at the photos).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://simianuprising.com/2009/05/12/simianuprisingcom-now-hopefully-un-hacked/comment-page-1/#comment-98999</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Sun, 31 May 2009 10:04:51 +0000</pubDate>
		<guid isPermaLink="false">http://simianuprising.com/?p=720#comment-98999</guid>
		<description>I saw your presentation at last years WordcampNewYork and I guess I didn&#039;t take the appropriate steps because a few of my sites have been hacked.

You mentioned restoring a pre-hacked version of the site.  How do you know how far back to go?  Couldn&#039;t it have been hacked months ago but abused recently.  

Any help you can provide would be greatly appreciated.</description>
		<content:encoded><![CDATA[<p>I saw your presentation at last years WordcampNewYork and I guess I didn&#8217;t take the appropriate steps because a few of my sites have been hacked.</p>
<p>You mentioned restoring a pre-hacked version of the site.  How do you know how far back to go?  Couldn&#8217;t it have been hacked months ago but abused recently.  </p>
<p>Any help you can provide would be greatly appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Blow</title>
		<link>http://simianuprising.com/2009/05/12/simianuprisingcom-now-hopefully-un-hacked/comment-page-1/#comment-98992</link>
		<dc:creator>Chris Blow</dc:creator>
		<pubDate>Tue, 19 May 2009 01:20:50 +0000</pubDate>
		<guid isPermaLink="false">http://simianuprising.com/?p=720#comment-98992</guid>
		<description>Thanks for a good scare. I manage probably a dozen wordpress installs and it&#039;s hard to keep them all up to date. For me the key is getting them under version control, so you can just &quot;svn up&quot; to the latest. Thanks especially for the tips on the Google recovery!</description>
		<content:encoded><![CDATA[<p>Thanks for a good scare. I manage probably a dozen wordpress installs and it&#8217;s hard to keep them all up to date. For me the key is getting them under version control, so you can just &#8220;svn up&#8221; to the latest. Thanks especially for the tips on the Google recovery!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Doran</title>
		<link>http://simianuprising.com/2009/05/12/simianuprisingcom-now-hopefully-un-hacked/comment-page-1/#comment-98990</link>
		<dc:creator>Jim Doran</dc:creator>
		<pubDate>Wed, 13 May 2009 02:21:37 +0000</pubDate>
		<guid isPermaLink="false">http://simianuprising.com/?p=720#comment-98990</guid>
		<description>Thanks for sharing this.</description>
		<content:encoded><![CDATA[<p>Thanks for sharing this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
