<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Neutralizing a Trojan.JS.Redirector.cq SQL injection on your WordPress blog</title>
	<atom:link href="http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/</link>
	<description></description>
	<lastBuildDate>Thu, 29 Dec 2011 18:01:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Nathan Hangen - Digital Emperor</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-484</link>
		<dc:creator>Nathan Hangen - Digital Emperor</dc:creator>
		<pubDate>Fri, 30 Jul 2010 19:30:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-484</guid>
		<description>Thank you! Kept getting kicked out of phpMyadmin, but their support helped me out. Thank god.</description>
		<content:encoded><![CDATA[<p>Thank you! Kept getting kicked out of phpMyadmin, but their support helped me out. Thank god.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yauhui</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-481</link>
		<dc:creator>yauhui</dc:creator>
		<pubDate>Fri, 30 Jul 2010 05:28:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-481</guid>
		<description>SQL injects usually do not affect the WordPress files. Your case seems more like a WordPress trojan. If you can, check through your WordPress users in PHPMyAdmin.

Else, have a chat with your host to diagnose the issue.</description>
		<content:encoded><![CDATA[<p>SQL injects usually do not affect the WordPress files. Your case seems more like a WordPress trojan. If you can, check through your WordPress users in PHPMyAdmin.</p>
<p>Else, have a chat with your host to diagnose the issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudio</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-479</link>
		<dc:creator>Claudio</dc:creator>
		<pubDate>Thu, 29 Jul 2010 22:13:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-479</guid>
		<description>Now I can see that exact same line  on every post I try to edit...

Isn´t under any posts/pages yet, but it´s making me nervous to see this clearly lurking around

Now I´ll try to figure out how to kick his a$$ before manage any post</description>
		<content:encoded><![CDATA[<p>Now I can see that exact same line  on every post I try to edit&#8230;</p>
<p>Isn´t under any posts/pages yet, but it´s making me nervous to see this clearly lurking around</p>
<p>Now I´ll try to figure out how to kick his a$$ before manage any post</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bRIAN</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-477</link>
		<dc:creator>bRIAN</dc:creator>
		<pubDate>Thu, 29 Jul 2010 21:03:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-477</guid>
		<description>I had this too!!!
I realized it at 6:30AM. I did the same steps before you were maybe even awake.

That didn&#039;t completely solve the issue. After the fix I was getting errors, 500 errors, database not found errors and other badness.

What I did may have been drastic, i&#039;m not sure.

After I changed the password and removed the DB stuff I did the following...

1) copy all plugins to a backup directory
2) re-installed wordpress fresh via FTP
3) restored from yesterdays database backup
4) re-installed all plugins from the wordpress repository

Wordpress 3

The reason for all the fresh files is because, I&#039;m speculating, that the malware inserted itself somewhere in javascript or php and was re-infecting or causing some other badness. my apache log was showing errors, cant remember exactly what, its the error you get when php is malformed.</description>
		<content:encoded><![CDATA[<p>I had this too!!!<br />
I realized it at 6:30AM. I did the same steps before you were maybe even awake.</p>
<p>That didn&#8217;t completely solve the issue. After the fix I was getting errors, 500 errors, database not found errors and other badness.</p>
<p>What I did may have been drastic, i&#8217;m not sure.</p>
<p>After I changed the password and removed the DB stuff I did the following&#8230;</p>
<p>1) copy all plugins to a backup directory<br />
2) re-installed wordpress fresh via FTP<br />
3) restored from yesterdays database backup<br />
4) re-installed all plugins from the wordpress repository</p>
<p>WordPress 3</p>
<p>The reason for all the fresh files is because, I&#8217;m speculating, that the malware inserted itself somewhere in javascript or php and was re-infecting or causing some other badness. my apache log was showing errors, cant remember exactly what, its the error you get when php is malformed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention the yauhuinator: Neutralizing a Trojan.JS.Redirector.cq SQL injection on your WordPress blog #tutorial #wordpress -- Topsy.com</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-476</link>
		<dc:creator>Tweets that mention the yauhuinator: Neutralizing a Trojan.JS.Redirector.cq SQL injection on your WordPress blog #tutorial #wordpress -- Topsy.com</dc:creator>
		<pubDate>Thu, 29 Jul 2010 20:32:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-476</guid>
		<description>[...] This post was mentioned on Twitter by yauhui, eightfalls and eightfalls, codesketch. codesketch said: @mediatemple just found that our site was hit with an SQL injection attack (same thing that they explain here http://bit.ly/dcJREA.) Help? [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by yauhui, eightfalls and eightfalls, codesketch. codesketch said: @mediatemple just found that our site was hit with an SQL injection attack (same thing that they explain here <a href="http://bit.ly/dcJREA" rel="nofollow">http://bit.ly/dcJREA</a>.) Help? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Olson</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-475</link>
		<dc:creator>Mark Olson</dc:creator>
		<pubDate>Thu, 29 Jul 2010 20:22:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-475</guid>
		<description>Thanks for posting the tutorial ... much appreciated!</description>
		<content:encoded><![CDATA[<p>Thanks for posting the tutorial &#8230; much appreciated!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yauhui</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-472</link>
		<dc:creator>yauhui</dc:creator>
		<pubDate>Thu, 29 Jul 2010 14:04:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-472</guid>
		<description>This tutorial shows how to remove an existing injection, not prevent a future injection. That I have not figured out how yet. The password change is just a precautionary measure.</description>
		<content:encoded><![CDATA[<p>This tutorial shows how to remove an existing injection, not prevent a future injection. That I have not figured out how yet. The password change is just a precautionary measure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Melvin.F</title>
		<link>http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-471</link>
		<dc:creator>Melvin.F</dc:creator>
		<pubDate>Thu, 29 Jul 2010 13:35:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.yauhuinator.com/2010/07/neutralizing-a-trojan-js-redirector-cq-sql-injection-on-your-wordpress-blog/#comment-471</guid>
		<description>So just by deleting the URL thus eliminating the possibility of future injections? SQL injections do not need to even know your DB password.</description>
		<content:encoded><![CDATA[<p>So just by deleting the URL thus eliminating the possibility of future injections? SQL injections do not need to even know your DB password.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Database Caching 1/3 queries in 1.154 seconds using disk: basic
Object Caching 422/423 objects using disk: basic

Served from: www.yauhuinator.com @ 2012-02-07 07:48:21 -->
