{"id":319,"date":"2012-01-27T16:58:30","date_gmt":"2012-01-27T16:58:30","guid":{"rendered":"http:\/\/gusclass.com\/blog\/?p=319"},"modified":"2012-01-27T19:02:51","modified_gmt":"2012-01-27T19:02:51","slug":"blog-attack","status":"publish","type":"post","link":"http:\/\/gusclass.com\/blog\/2012\/01\/27\/blog-attack\/","title":{"rendered":"Blog attack!"},"content":{"rendered":"<p>My blog went down for about 36 hours this week.\u00a0 A hacker exploited a friend&#8217;s blog that I&#8217;m\u00a0hosting.\u00a0My host, 1&amp;1, took down all my hosted sites without notice.\u00a0 At first, I freaked out.\u00a0 I mean, who does this?\u00a0 Who takes down a whole host because of an attack? Then, I remembered that I pay about $6 \/ month and well, what do you expect for cheap hosting?\u00a0 Also, it&#8217;s probably better that the attack was stopped rather than just let it go longer than necessary. I would have appreciated a faster response but I&#8217;m not going to be losing sleep over it because everything came back functional.\u00a0 Now&#8217;s probably a good time to backup though in case this happens again.<\/p>\n<p>Now for the fun part \ud83d\ude42\u00a0 How was the site hacked?\u00a0 1&amp;1 sent me the details:<\/p>\n<p style=\"padding-left: 30px;\">1.1\u00a0 The hackers processed the attack through a security leak in your software &#8211; TimThumb<\/p>\n<p style=\"padding-left: 30px;\">They misused at least the following modules or files of this software:<\/p>\n<p style=\"padding-left: 30px;\">[path].\/wp-content\/themes\/premiumnews\/thumb.php<\/p>\n<p style=\"padding-left: 30px;\">1.2\u00a0 Via this security leak, the hackers have uploaded the following malicious files to your webspace:<\/p>\n<p style=\"padding-left: 30px;\">[path]\/3rdparty\/API\/api.php [path]\/3rdparty\/API\/api.php [path]\/wp-content\/themes\/premiumnews\/cache\/external_25b63d0508d2d6374ebc92c12e309517.php [path]\/wp-content\/uploads\/2011\/07\/catalog\/* [path]wp-content\/uploads\/_cache_t1hw1hza.php [path]wp-content\/uploads\/_cache_xvh2mwac.php [path]\/wp-content\/uploads\/sm5vs7.php [path]\/wp-content\/uploads\/sm6vm1.php [path]\/wp-content\/uploads\/edw.php [path]wp-content\/uploads\/r2mo2.html [path]\/wp-content\/uploads\/r2lm3.html [path]\/wp-content\/uploads\/htaccess<\/p>\n<p>So there you have it.\u00a0 Exploited a WordPress image thumbnail plugin, then uploaded a spam script, and then locked out the directory with an htaccess file.\u00a0 Let&#8217;s take a look at what the scripts do \ud83d\ude42\u00a0 I don&#8217;t have time this morning but soon!<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>My blog went down for about 36 hours this week.\u00a0 A hacker exploited a friend&#8217;s blog that I&#8217;m\u00a0hosting.\u00a0My host, 1&amp;1, took down all my hosted sites without notice.\u00a0 At first, I freaked out.\u00a0 I mean, who does this?\u00a0 Who takes&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[72,11,44,1],"tags":[288,43,284],"amp_validity":null,"amp_enabled":true,"_links":{"self":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts\/319"}],"collection":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/comments?post=319"}],"version-history":[{"count":5,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts\/319\/revisions"}],"predecessor-version":[{"id":323,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts\/319\/revisions\/323"}],"wp:attachment":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/media?parent=319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/categories?post=319"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/tags?post=319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}