<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Spam in my feed&#8230; Ugh&#8230;</title>
	<atom:link href="http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/</link>
	<description>Amy Gahran's news and musings on how we communicate in the online age.</description>
	<pubDate>Sun, 23 Nov 2008 16:43:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Wordpress &#38; Spam at Journal of Crisology</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1215358</link>
		<dc:creator>Wordpress &#38; Spam at Journal of Crisology</dc:creator>
		<pubDate>Tue, 04 Mar 2008 18:52:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1215358</guid>
		<description>[...] browsing for reasons it appears I&#8217;m not the only one: this blog feed reported the same problem already November 7th last year. And indeed, I&#8217;ll have to [...]</description>
		<content:encoded><![CDATA[<p>[...] browsing for reasons it appears I&#8217;m not the only one: this blog feed reported the same problem already November 7th last year. And indeed, I&#8217;ll have to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: contentious.com - Spammer with a sense of humor</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206575</link>
		<dc:creator>contentious.com - Spammer with a sense of humor</dc:creator>
		<pubDate>Mon, 12 Nov 2007 17:02:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206575</guid>
		<description>[...] just found in my Wordpress moderation queue this comment, submitted in response to my post about my blog being [...]</description>
		<content:encoded><![CDATA[<p>[...] just found in my Wordpress moderation queue this comment, submitted in response to my post about my blog being [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: contentious.com - My blog got hacked, probably at Blogworld Expo</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206496</link>
		<dc:creator>contentious.com - My blog got hacked, probably at Blogworld Expo</dc:creator>
		<pubDate>Sun, 11 Nov 2007 17:23:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206496</guid>
		<description>[...] Yesterday I posted about how a reader let me know that a huge chunk of spam had shown up in a post I made from Blogworld Expo in Las Vegas. As I investigated this further with the help of readers (especially Mihai Parparita) and my colleague Justin Crawford, I learned that someone had gained access to my Wordpress installation (most likely by stealing my password) and inserted spam directly into my post. This problem appears to have started only very recently &#8212; while I was at Blogworld, on the conference wifi network. [...]</description>
		<content:encoded><![CDATA[<p>[...] Yesterday I posted about how a reader let me know that a huge chunk of spam had shown up in a post I made from Blogworld Expo in Las Vegas. As I investigated this further with the help of readers (especially Mihai Parparita) and my colleague Justin Crawford, I learned that someone had gained access to my Wordpress installation (most likely by stealing my password) and inserted spam directly into my post. This problem appears to have started only very recently &#8212; while I was at Blogworld, on the conference wifi network. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amy Gahran</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206451</link>
		<dc:creator>Amy Gahran</dc:creator>
		<pubDate>Sat, 10 Nov 2007 22:10:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206451</guid>
		<description>Neil -- yes, come to think of it, I noticed that comments were set as closed on that post! I manually re-opened them when I saw it, and I figured I had just accidentally closed them. But it's possible that could be related to this bug.

I'm waiting to hear from my geek-on-call about the wordpress upgrade. But if he can't do it right now, I appreciate your offer of help, and I'll let you know.

Thanks,

- Amy</description>
		<content:encoded><![CDATA[<p>Neil &#8212; yes, come to think of it, I noticed that comments were set as closed on that post! I manually re-opened them when I saw it, and I figured I had just accidentally closed them. But it&#8217;s possible that could be related to this bug.</p>
<p>I&#8217;m waiting to hear from my geek-on-call about the wordpress upgrade. But if he can&#8217;t do it right now, I appreciate your offer of help, and I&#8217;ll let you know.</p>
<p>Thanks,</p>
<p>- Amy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neil Ford</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206450</link>
		<dc:creator>Neil Ford</dc:creator>
		<pubDate>Sat, 10 Nov 2007 22:04:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206450</guid>
		<description>I tried posting a comment to your Blog World post (recommending a bag) but when I hit post it said comments were closed. I just thought you'd closed comments. This would have been shortly after the post hit Google Reader for me as I had my unread count down to nothing yesterday.

If you need a hand with the upgrade, let me know.

- Neil.</description>
		<content:encoded><![CDATA[<p>I tried posting a comment to your Blog World post (recommending a bag) but when I hit post it said comments were closed. I just thought you&#8217;d closed comments. This would have been shortly after the post hit Google Reader for me as I had my unread count down to nothing yesterday.</p>
<p>If you need a hand with the upgrade, let me know.</p>
<p>- Neil.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: contentious.com - Why blogging conferences is so damn hard</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206449</link>
		<dc:creator>contentious.com - Why blogging conferences is so damn hard</dc:creator>
		<pubDate>Sat, 10 Nov 2007 21:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206449</guid>
		<description>[...] reader, you may see a big block of spam below. Sorry about that &#8212; my blog has been hacked. I&#8217;m working to fix it.) [...]</description>
		<content:encoded><![CDATA[<p>[...] reader, you may see a big block of spam below. Sorry about that &#8212; my blog has been hacked. I&#8217;m working to fix it.) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amy Gahran</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206448</link>
		<dc:creator>Amy Gahran</dc:creator>
		<pubDate>Sat, 10 Nov 2007 21:35:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206448</guid>
		<description>Another update:

Via Twitter, my friend Karoli (who blogs at &lt;a href="http://www.drumsnwhistles.com/" rel="nofollow"&gt;Drums n Whistles&lt;/a&gt;) noted that she suffered a similar hack a couple of years ago. The problem came from a Wordpress security hole. Info about it here:

http://snipurl.com/1tft7

Thanks, Karoli! I'll look into it. I'm currently on Wordpress 2.1.2, but the lasest stable release is 2.3.1. I'll arrange an upgrade.</description>
		<content:encoded><![CDATA[<p>Another update:</p>
<p>Via Twitter, my friend Karoli (who blogs at <a href="http://www.drumsnwhistles.com/" rel="nofollow">Drums n Whistles</a>) noted that she suffered a similar hack a couple of years ago. The problem came from a Wordpress security hole. Info about it here:</p>
<p><a href="http://snipurl.com/1tft7" rel="nofollow">http://snipurl.com/1tft7</a></p>
<p>Thanks, Karoli! I&#8217;ll look into it. I&#8217;m currently on Wordpress 2.1.2, but the lasest stable release is 2.3.1. I&#8217;ll arrange an upgrade.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mihai Parparita</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206447</link>
		<dc:creator>Mihai Parparita</dc:creator>
		<pubDate>Sat, 10 Nov 2007 20:44:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206447</guid>
		<description>It looks like the spam is in the original post too, you just can't see it. However, if you do a view source and search for "viagra", you will see (I've replaced angle brackets with square brackets to make sure the HTML is not interpreted):

[p][font style="overflow: hidden; position: absolute; height: 0pt; width: 0pt"][br /]
alternative impotence natural viagra [a href="http://www.industry.ucsb.edu/technology/blog/wp-includes/js/tinymce/themes/advanced/images/xp/1/index.html"]viagra[/a] viagra overdose[br /]
free sample viagra uk [a href="http://www.industry.ucsb.edu/technology/blog/wp-includes/js/tinymce/themes/advanced/images/xp/1/buy-viagra.html"]buy viagra[/a] viagra patent[br /]

I'm guessing you can see this in WordPress's post editor too. The CSS that's applied is stripped by wed-based aggregators, which is why this is visible there. Desktop aggregators tend to leave CSS alone (since they have fewer security concerns), thus you don't see it there.</description>
		<content:encoded><![CDATA[<p>It looks like the spam is in the original post too, you just can&#8217;t see it. However, if you do a view source and search for &#8220;viagra&#8221;, you will see (I&#8217;ve replaced angle brackets with square brackets to make sure the HTML is not interpreted):</p>
<p>[p][font style="overflow: hidden; position: absolute; height: 0pt; width: 0pt"][br /]<br />
alternative impotence natural viagra [a href="http://www.industry.ucsb.edu/technology/blog/wp-includes/js/tinymce/themes/advanced/images/xp/1/index.html"]viagra[/a] viagra overdose[br /]<br />
free sample viagra uk [a href="http://www.industry.ucsb.edu/technology/blog/wp-includes/js/tinymce/themes/advanced/images/xp/1/buy-viagra.html"]buy viagra[/a] viagra patent[br /]</p>
<p>I&#8217;m guessing you can see this in WordPress&#8217;s post editor too. The CSS that&#8217;s applied is stripped by wed-based aggregators, which is why this is visible there. Desktop aggregators tend to leave CSS alone (since they have fewer security concerns), thus you don&#8217;t see it there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amy Gahran</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206446</link>
		<dc:creator>Amy Gahran</dc:creator>
		<pubDate>Sat, 10 Nov 2007 20:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206446</guid>
		<description>Mihai -- thanks for helping me figure this out. The odd thing is, I can see the spam only in web-based feed readers (bloglines and Google Reader). It doesn't show up at all in Newsfire or Safari.

I'll need some help diagnosing and fixing this, but I've got some people I can call to help.

Just when I was hoping to take the day off....   Sigh....

- Amy Gahran</description>
		<content:encoded><![CDATA[<p>Mihai &#8212; thanks for helping me figure this out. The odd thing is, I can see the spam only in web-based feed readers (bloglines and Google Reader). It doesn&#8217;t show up at all in Newsfire or Safari.</p>
<p>I&#8217;ll need some help diagnosing and fixing this, but I&#8217;ve got some people I can call to help.</p>
<p>Just when I was hoping to take the day off&#8230;.   Sigh&#8230;.</p>
<p>- Amy Gahran</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mihai Parparita</title>
		<link>http://www.contentious.com/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206444</link>
		<dc:creator>Mihai Parparita</dc:creator>
		<pubDate>Sat, 10 Nov 2007 20:02:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/10/spam-in-my-bloglines-feed-ugh/#comment-1206444</guid>
		<description>It looks like the same viagra spam ended up in the feed data that was crawled (and cached) by Google Reader:

http://www.google.com/reader/view/feed/http://feeds.feedburner.com/Contentious

The fact that both Reader and Bloglines have the same data makes it less likely that it's a bug in Bloglines. I'm guessing that your blog was somehow hacked. When looking at your feed:

http://feeds.feedburner.com/Contentious

I see the viagra links in there too.</description>
		<content:encoded><![CDATA[<p>It looks like the same viagra spam ended up in the feed data that was crawled (and cached) by Google Reader:</p>
<p><a href="http://www.google.com/reader/view/feed/http://feeds.feedburner.com/Contentious" rel="nofollow">http://www.google.com/reader/view/feed/http://feeds.feedburner.com/Contentious</a></p>
<p>The fact that both Reader and Bloglines have the same data makes it less likely that it&#8217;s a bug in Bloglines. I&#8217;m guessing that your blog was somehow hacked. When looking at your feed:</p>
<p><a href="http://feeds.feedburner.com/Contentious" rel="nofollow">http://feeds.feedburner.com/Contentious</a></p>
<p>I see the viagra links in there too.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
