<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kaizeku Ban &#187; Owned</title>
	<atom:link href="http://blog.kaizeku.com/topics/owned/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kaizeku.com</link>
	<description>So many evil plans, so little time...</description>
	<pubDate>Wed, 27 Aug 2008 13:02:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Co-Founder of Mozilla Project</title>
		<link>http://blog.kaizeku.com/wordpress/blake-ross-hacked-wordpress-blackhat-spammer/</link>
		<comments>http://blog.kaizeku.com/wordpress/blake-ross-hacked-wordpress-blackhat-spammer/#comments</comments>
		<pubDate>Thu, 28 Feb 2008 19:46:07 +0000</pubDate>
		<dc:creator>ck</dc:creator>
		
		<category><![CDATA[Black Hat]]></category>

		<category><![CDATA[Owned]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[blackhat]]></category>

		<category><![CDATA[blake ross]]></category>

		<category><![CDATA[gehackt]]></category>

		<category><![CDATA[goro]]></category>

		<category><![CDATA[mozilla]]></category>

		<category><![CDATA[parasite hosting]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kaizeku.com/wordpress/blake-ross-hacked-wordpress-blackhat-spammer/</guid>
		<description><![CDATA[Blake Ross, the Co-Founder of Mozilla Project WordPress Blog&apos;s Hacked by Wordpress.net.in Blackhat Spammer.]]></description>
			<content:encoded><![CDATA[<p><span class="vcard"><img src='http://blog.kaizeku.com/wp-content/uploads/2008/03/blakeross-com-hack-by-blackhat.png' alt='blakeross-com-hack-by-blackhat.png' width='128' height='128' class="photo thumb- fl" longdesc='http://blog.kaizeku.com/wordpress/blake-ross-hacked-wordpress-blackhat-spammer/' /><a class="url fn microformat icn-r1" href="http://blakeross.com"><span class="given-name dc-name">Blake</span> <span class="family-name surname">Ross</span></a></span> WordPress blog is being run by <strong class="fw-">wordpress.net.in</strong> <a href="http://blog.kakkoi.net/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" class="exturl icn-r1">goro spam</a> injection.</p>
<h3>Who&apos;s Blake Ross</h3>
<p class="mgb-"><small>Excerpt from <a class="exturl icn-r1" href="http://en.wikipedia.org/wiki/Blake_Ross">wikipedia</a></small></p>
<blockquote class="mgt-"><p class="cite"><strong>Blake Aaron Ross</strong> is a software developer who is known for his work on the Mozilla web browser; in particular, he started the Mozilla Firefox project with Dave Hyatt, as well as the Spread Firefox project with Asa Dotzler while working as a contractor at the Mozilla Foundation.<span class="db">In 2005, he was nominated for Wired magazine&#8217;s top Rave Award, Renegade of the Year, opposite Larry Page, Sergey Brin and Jon Stewart. He was also a part of Rolling Stone magazine&#8217;s 2005 hot list.</span></p>
</blockquote>
<p><span id="more-128"></span><br />
<small class="rgb-hgray"><a href="http://en.wikipedia.org/wiki/Image:Blake_Ross_WIRED_cover.jpeg" class="exturl icn-r1">Image Source</a>, The cover for issue #13.02 (the February 2005 edition) of Wired magazine featuring Blake Ross holding a Firefox globe as part of the lead article, The Firefox Explosion, about the browser&#8217;s development history.</small></p>
<h3 class="cb mgb- mgt">HTML Source &#038; ScreenGrab</h3>
<ul class="xoxo exturl pdt">
<li><a class="inturl" type="text/plain" rel="nofollow robots-nofollow noarchive" title="blakeross.com wordpress 2.0.4 html sources text" href='http://blog.kaizeku.com/wp-content/uploads/2008/02/blakeross-com-022808source.txt' title='blakeross-com-022808source.txt' rev="site:upload-txt">blakeross-com-022808-source.txt</a></li>
<li><a href="http://chaos-kaizer.deviantart.com/art/blakeross-com-hacked-78643257">Screenshot taken on Feb 28th, 2008</a></li>
</ul>
<h2 class="mgt">WordPress Vulnerability</h2>
<ol class="xoxo">
<li>
<h4 class="mgb-">Outdated WordPress</h4>
<ul class="exturl">
<li>
<h4 class="title-">WordPress 2.0.4 Exploit &amp; Vulnerability</h4>
<ul>
<li>Blake&#8217;s is running on <a href="http://wordpress.org/development/2006/07/wordpress-204/" class="exturl icn-r1" title="WordPress Development Blog &raquo; WordPress 2.0.4 Security Release">WordPress 2.0.4</a> first release on Jul 29th, 2006.</li>
<li><a href="http://trac.wordpress.org/browser/branches/2.0/wp-content/plugins/wp-db-backup.php?rev=4226">wp-db-backup.php</a> directory traversal <a href="http://trac.wordpress.org/changeset/4226" class="exturl icn-r1">Rev.4226</a></li>
<li><a href="http://markjaquith.wordpress.com/2006/10/17/changes-in-wordpress-205/">Mark Jaquith on WordPress 2.0.5 Changelog</a></li>
</ul>
</li>
<li>&#181; <small title="Proxy Cached on Feb 28th 2008 via d95.com">Proxy Cached:</small> <a rel="nofollow robots-nofollow noarchive" href="/uri/ZDk1LmNvbS8yNDAx.curie,80,302" title="redirect to blakeross.com wordpress feed">blakeross.com WordPress Version (feed)</a></li>
</ul>
</li>
<li class="mgt">
<h3 class="mgb-">WordPress Core Directory &amp; Plugins Informations Leak</h3>
<ul class="exturl">
<li>
<h3 class="title-">View blakeross.com WordPress Core Directory Listing</h3>
<pre class="prebox dn">
Index of /wp-includes

 Name Last modified Size Description

[DIR] Parent Directory 25-Dec-2006 01:14 -
[ ] cache.php 03-Sep-2006 23:52 11k
[ ] capabilities.php 03-Sep-2006 23:52 11k
[ ] class-IXR.php 03-Sep-2006 23:52 27k
[ ] class-pop3.php 03-Sep-2006 23:52 21k
[ ] class-snoopy.php 03-Sep-2006 23:52 37k
[ ] classes.php 03-Sep-2006 23:52 51k
[ ] comment-functions.php 03-Sep-2006 23:52 31k
[ ] default-filters.php 03-Sep-2006 23:52 5k
[ ] feed-functions.php 03-Sep-2006 23:52 4k
[ ] functions-compat.php 03-Sep-2006 23:52 3k
[ ] functions-formatting..> 03-Sep-2006 23:53 34k
[ ] functions-post.php 03-Sep-2006 23:53 30k
[ ] functions.php 03-Sep-2006 23:53 71k
[ ] gettext.php 03-Sep-2006 23:53 11k
[DIR] images/ 03-Sep-2006 23:50 -
[DIR] js/ 03-Sep-2006 23:55 -
[ ] kses.php 03-Sep-2006 23:55 22k
[ ] links.php 03-Sep-2006 23:55 20k
[ ] locale.php 03-Sep-2006 23:55 3k
[ ] pluggable-functions.php 03-Sep-2006 23:55 17k
[ ] registration-functio..> 03-Sep-2006 23:55 4k
[ ] rss-functions.php 03-Sep-2006 23:55 21k
[ ] streams.php 03-Sep-2006 23:55 4k
[ ] template-functions-a..> 03-Sep-2006 23:55 5k
[ ] template-functions-c..> 03-Sep-2006 23:56 13k
[ ] template-functions-g..> 03-Sep-2006 23:56 21k
[ ] template-functions-l..> 03-Sep-2006 23:56 15k
[ ] template-functions-p..> 03-Sep-2006 23:56 15k
[ ] template-loader.php 03-Sep-2006 23:56 2k
[ ] vars.php 03-Sep-2006 23:56 3k
[ ] version.php 03-Sep-2006 23:56 1k
[ ] wp-db.php 03-Sep-2006 23:56 10k
[ ] wp-l10n.php 03-Sep-2006 23:56 2k 

Apache/1.3.39 Server at blakeross.com Port 80
</pre>
<p>&#181; <small title="Proxy Cached on Feb 28th 2008 via d95.com">Proxy Cached:</small> <a rel="nofollow robots-nofollow noarchive" href="/uri/ZDk1LmNvbS9mNGEx.curie,80,302" rev="site:redirect" title="redirect to blakeross.com wordpress core directory">http://blakeross.com/wp-includes/</a></li>
<li>
<h3 class="title-">View blakeross.com WordPress Plugins Directory Listing</h3>
<pre class="prebox dn">
Index of /wp-content/plugins

 Name Last modified Size Description

[DIR] Parent Directory 27-Sep-2006 22:27 -
[DIR] akismet/ 03-Sep-2006 23:52 -
[ ] hello.php 03-Sep-2006 23:52 2k
[ ] wp-db-backup.php 03-Sep-2006 23:52 30k 

Apache/1.3.39 Server at blakeross.com Port 80
</pre>
<p>&#181; <small title="Proxy Cached on Feb 28th 2008 via d95.com">Proxy Cached:</small> <a rel="nofollow robots-nofollow noarchive" href="/uri/ZDk1LmNvbS81NmQ3.curie,80,302" title="redirect to blakeross.com wordpress plugins directory">http://blakeross.com/wp-content/plugins</a>
</li>
</ul>
</li>
</ol>
<h3>Hardening Wordpress?</h3>
<p>There is <a class="google icn-l" href="http://www.google.com/search?hl=en&amp;q=%E2%80%9Cparent+directory%E2%80%9D+wp-content%2Fplugins%2F+-text+%E2%80%93php+-shtml+-md5+-md5sums">105,000 WordPress blogs</a> leaking their plugins informations for BotNet to scan.</p>
<h2>Blackhat SEO targeting High PR WordPress Blog</h2>
<p><strong class="fw-">Blake Ross</strong> is not alone, there is similar <abbr title="Parasite Host">Spamride</abbr> cases for the past few months. Below is are few &#8220;High PR WordPress Blogs&#8221; with similar issues.</p>
<h3 class="mgb-">Others Popular Victim</h3>
<ul class="xoxo exturl">
<li><a href="http://www.climatecrisis.net/blog/" title="Al Gore&apos;s Blog"> Al Gore&#8217;s Blog</a></li>
<li><a href="http://mattheaton.com">Bluehost Hostmonster CEO&#8217;s Blog</a></li>
<li>blog.indeed.com</li>
<li>thinkingphp.org</li>
<li>floaridablog.org</li>
</ul>]]></content:encoded>
			<wfw:commentRss>http://blog.kaizeku.com/wordpress/blake-ross-hacked-wordpress-blackhat-spammer/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
