<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My site was hacked! Invisible iframe to Chinese malware site</title>
	<atom:link href="http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=my-site-was-hacked-invisible-iframe-to-chinese-malware-site</link>
	<description>Its not always where you are, but where you want to go, and getting there.</description>
	<lastBuildDate>Tue, 07 Feb 2012 07:53:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: mike</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-13247</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Fri, 10 Dec 2010 14:21:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-13247</guid>
		<description>true, well maybe its not in China, but somewhere in the world then!!!  but hey, they may be exporters!  those aren&#039;t doing so good</description>
		<content:encoded><![CDATA[<p>true, well maybe its not in China, but somewhere in the world then!!!  but hey, they may be exporters!  those aren&#8217;t doing so good</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andrew</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-13245</link>
		<dc:creator>andrew</dc:creator>
		<pubDate>Fri, 10 Dec 2010 13:57:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-13245</guid>
		<description>What tough economy? There is no economic crisis in China. :)</description>
		<content:encoded><![CDATA[<p>What tough economy? There is no economic crisis in China. <img src='http://blog.michaelmichelini.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-6434</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Mon, 01 Mar 2010 13:34:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-6434</guid>
		<description>SSH and SCP are the way to go for remote communications unless you can VPN in.  SCP is a powerful command line tool, and there are some graphical versions out there as well I&#039;m sure. Also, enforcing strong passwords is a good idea.  If your server isn&#039;t secure, a strong password doesn&#039;t matter though...</description>
		<content:encoded><![CDATA[<p>SSH and SCP are the way to go for remote communications unless you can VPN in.  SCP is a powerful command line tool, and there are some graphical versions out there as well I&#8217;m sure. Also, enforcing strong passwords is a good idea.  If your server isn&#8217;t secure, a strong password doesn&#8217;t matter though&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matthias-Müller</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-1634</link>
		<dc:creator>Matthias-Müller</dc:creator>
		<pubDate>Mon, 24 Aug 2009 20:35:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-1634</guid>
		<description>Damn, that sound&#039;s so easy if you think about it.</description>
		<content:encoded><![CDATA[<p>Damn, that sound&#8217;s so easy if you think about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vijay</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-447</link>
		<dc:creator>vijay</dc:creator>
		<pubDate>Fri, 10 Jul 2009 07:49:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-447</guid>
		<description>Thank for the Great Feedback. I was suffering with the malware for our client&#039;s website. These malwares cause lot of problem for the website.
We need to thoroughly clean the malware before loading to the server. Otherwise the malware scripts getting loaded every time after we upload our back up files into the server.</description>
		<content:encoded><![CDATA[<p>Thank for the Great Feedback. I was suffering with the malware for our client&#8217;s website. These malwares cause lot of problem for the website.<br />
We need to thoroughly clean the malware before loading to the server. Otherwise the malware scripts getting loaded every time after we upload our back up files into the server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-437</link>
		<dc:creator>Alan</dc:creator>
		<pubDate>Thu, 09 Jul 2009 09:36:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-437</guid>
		<description>Thanks for the advice, my site has been hacked three times in one month, I have followed all what the service provider said to follow and it still happened. What they never told me is what you mention above. I use a Mac so will have to search for some catchers for OS X.. Have been using Nortons, but from what I read its not worth it. Thanks again.</description>
		<content:encoded><![CDATA[<p>Thanks for the advice, my site has been hacked three times in one month, I have followed all what the service provider said to follow and it still happened. What they never told me is what you mention above. I use a Mac so will have to search for some catchers for OS X.. Have been using Nortons, but from what I read its not worth it. Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mike</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-187</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Tue, 16 Jun 2009 15:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-187</guid>
		<description>Thanks Thomas!
wow, such a quick response to my post. I really appreciate this great feedback and solution.  It is sad to see how others are profiting off all these small business owners and entrepreneurs hard work.</description>
		<content:encoded><![CDATA[<p>Thanks Thomas!<br />
wow, such a quick response to my post. I really appreciate this great feedback and solution.  It is sad to see how others are profiting off all these small business owners and entrepreneurs hard work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas J. Raef</title>
		<link>http://blog.michaelmichelini.com/2009/06/my-site-was-hacked-invisible-iframe-to-chinese-malware-site.html/comment-page-1#comment-175</link>
		<dc:creator>Thomas J. Raef</dc:creator>
		<pubDate>Sun, 14 Jun 2009 12:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.michaelmichelini.com/?p=776#comment-175</guid>
		<description>We&#039;ve been seeing a huge increase in the number of people having their websites &quot;hacked&quot;. One of the most common ways right now is by infecting a PC then &quot;sniffing&quot; for FTP traffic.

Think about it. How many people have websites these days? It seems like everyone.

So why not infect PCs then wait for when they upload to a website through a protocol that sends everything in plain text?

You see, FTP does not encrypt it&#039;s traffic. We created a YouTube video on how insecure FTP is: http://www.youtube.com/watch?v=oYI1kssrrbc

We&#039;ve been recommending a couple of things. First, use AVG or Avast along with Malwarebytes. These have been catching more viruses/trojans than many of the more popular anti-virus programs have.

Second, if you update a website or websites, ask your hosting provider about moving to either SFTP or FTPS. Both of these protocols encrypt their traffic making it nearly impossible to sniff for username and password.

Last, stop using an administrator account on your PC for everyday work. A virus/trojan/worm can usually only obtain the same rights as the currently logged in user. If the current user can install software, then so can the malware. If the current user cannot install software, then neither can the malware.

There you are 3 things to do to protect your website from getting hacked - and if you use the free versions of the anti-malware software we&#039;ve recommended, these 3 things cost you nothing!

I hope you found this information worth more than you paid for it.</description>
		<content:encoded><![CDATA[<p>We&#8217;ve been seeing a huge increase in the number of people having their websites &#8220;hacked&#8221;. One of the most common ways right now is by infecting a PC then &#8220;sniffing&#8221; for FTP traffic.</p>
<p>Think about it. How many people have websites these days? It seems like everyone.</p>
<p>So why not infect PCs then wait for when they upload to a website through a protocol that sends everything in plain text?</p>
<p>You see, FTP does not encrypt it&#8217;s traffic. We created a YouTube video on how insecure FTP is: <a href="http://www.youtube.com/watch?v=oYI1kssrrbc" rel="nofollow">http://www.youtube.com/watch?v=oYI1kssrrbc</a></p>
<p>We&#8217;ve been recommending a couple of things. First, use AVG or Avast along with Malwarebytes. These have been catching more viruses/trojans than many of the more popular anti-virus programs have.</p>
<p>Second, if you update a website or websites, ask your hosting provider about moving to either SFTP or FTPS. Both of these protocols encrypt their traffic making it nearly impossible to sniff for username and password.</p>
<p>Last, stop using an administrator account on your PC for everyday work. A virus/trojan/worm can usually only obtain the same rights as the currently logged in user. If the current user can install software, then so can the malware. If the current user cannot install software, then neither can the malware.</p>
<p>There you are 3 things to do to protect your website from getting hacked &#8211; and if you use the free versions of the anti-malware software we&#8217;ve recommended, these 3 things cost you nothing!</p>
<p>I hope you found this information worth more than you paid for it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

