<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: My blog got hacked, probably at Blogworld Expo</title>
	<atom:link href="http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/</link>
	<description>Amy Gahran's news and musings on how we communicate in the online age.</description>
	<pubDate>Sun, 23 Nov 2008 17:04:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Murfreesboro Cabling</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1223876</link>
		<dc:creator>Murfreesboro Cabling</dc:creator>
		<pubDate>Sun, 12 Oct 2008 22:26:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1223876</guid>
		<description>Sorry to hear that your blog was hacked, this is a problem when you use someone else's software, you do not know how well the code is written.</description>
		<content:encoded><![CDATA[<p>Sorry to hear that your blog was hacked, this is a problem when you use someone else&#8217;s software, you do not know how well the code is written.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacker Forums</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1223859</link>
		<dc:creator>Hacker Forums</dc:creator>
		<pubDate>Tue, 07 Oct 2008 20:00:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1223859</guid>
		<description>Most all hacks are from people not upgrading their software.

If you don't make a ton of changes, just backup your template one time, then create or download a script to email you a database dumb every couple days.</description>
		<content:encoded><![CDATA[<p>Most all hacks are from people not upgrading their software.</p>
<p>If you don&#8217;t make a ton of changes, just backup your template one time, then create or download a script to email you a database dumb every couple days.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: contentious.com - Bluehost&#8217;s Bad Attitude: Customer Service 101</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1212034</link>
		<dc:creator>contentious.com - Bluehost&#8217;s Bad Attitude: Customer Service 101</dc:creator>
		<pubDate>Sat, 02 Feb 2008 17:59:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1212034</guid>
		<description>[...] were generally going OK with hosting both sites on my Bluehost account, until last November, when Contentious got hacked &#8212; someone sniffed my password when I logged on over open wifi and inserted spam into my blog. [...]</description>
		<content:encoded><![CDATA[<p>[...] were generally going OK with hosting both sites on my Bluehost account, until last November, when Contentious got hacked &#8212; someone sniffed my password when I logged on over open wifi and inserted spam into my blog. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chip Neville</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206656</link>
		<dc:creator>Chip Neville</dc:creator>
		<pubDate>Wed, 14 Nov 2007 02:51:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206656</guid>
		<description>This illustrates a critical security flaw in the design of Wordpress and most CMSs (Content Management Systems).  They do not provide secure https for logins, where passwords must be sent over the net, and administrative access.  Only Plone , and maybe some of the Java based systems, seem to provide this capability, but only by tearing your hair out first.  If Wordpress provided it transparently, you would have used it, and your password would not have been stolen.</description>
		<content:encoded><![CDATA[<p>This illustrates a critical security flaw in the design of Wordpress and most CMSs (Content Management Systems).  They do not provide secure https for logins, where passwords must be sent over the net, and administrative access.  Only Plone , and maybe some of the Java based systems, seem to provide this capability, but only by tearing your hair out first.  If Wordpress provided it transparently, you would have used it, and your password would not have been stolen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: contentious.com - This blog is still hacked, grrrrrrr&#8230;..</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206633</link>
		<dc:creator>contentious.com - This blog is still hacked, grrrrrrr&#8230;..</dc:creator>
		<pubDate>Tue, 13 Nov 2007 15:49:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206633</guid>
		<description>[...] in advance to my readers, but it appears my hacker woes are not yet [...]</description>
		<content:encoded><![CDATA[<p>[...] in advance to my readers, but it appears my hacker woes are not yet [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amy Gahran</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206587</link>
		<dc:creator>Amy Gahran</dc:creator>
		<pubDate>Mon, 12 Nov 2007 18:48:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206587</guid>
		<description>TDavid, Mark -- yes, I'm definitely looking into an EVDO connection. Thanks. But I still need a more secure solution in the meantime. It'll be a few weeks before I can pull that into place.

- Amy Gahran</description>
		<content:encoded><![CDATA[<p>TDavid, Mark &#8212; yes, I&#8217;m definitely looking into an EVDO connection. Thanks. But I still need a more secure solution in the meantime. It&#8217;ll be a few weeks before I can pull that into place.</p>
<p>- Amy Gahran</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Turner</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206579</link>
		<dc:creator>Jim Turner</dc:creator>
		<pubDate>Mon, 12 Nov 2007 17:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206579</guid>
		<description>Amy,

Looking back now, I may have also been hacked.  I was trying to post to my blog so I could show the audience in my presentation something, and suddenly I lost my blog's template.  I'll let you know when I find out what happens.  Perhaps at the next meetup.  Good luck!</description>
		<content:encoded><![CDATA[<p>Amy,</p>
<p>Looking back now, I may have also been hacked.  I was trying to post to my blog so I could show the audience in my presentation something, and suddenly I lost my blog&#8217;s template.  I&#8217;ll let you know when I find out what happens.  Perhaps at the next meetup.  Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Jaquith</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206578</link>
		<dc:creator>Mark Jaquith</dc:creator>
		<pubDate>Mon, 12 Nov 2007 17:16:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206578</guid>
		<description>Never, ever, transmit a plaintext password over unsecured WiFi.  Heck, probably not a good idea to do it over WEP'd WiFi either.

Solutions: HTTPS, VPN -- or just forget about the WiFi and get an EVDO card.  A few trips to Starbucks/hotels/conferences a month and it will pay for itself.</description>
		<content:encoded><![CDATA[<p>Never, ever, transmit a plaintext password over unsecured WiFi.  Heck, probably not a good idea to do it over WEP&#8217;d WiFi either.</p>
<p>Solutions: HTTPS, VPN &#8212; or just forget about the WiFi and get an EVDO card.  A few trips to Starbucks/hotels/conferences a month and it will pay for itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TDavid</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206577</link>
		<dc:creator>TDavid</dc:creator>
		<pubDate>Mon, 12 Nov 2007 17:11:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206577</guid>
		<description>Suggestion: get your own EVDO connection -- don't use conference WiFi which usually suck anyway.</description>
		<content:encoded><![CDATA[<p>Suggestion: get your own EVDO connection &#8212; don&#8217;t use conference WiFi which usually suck anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: contentious.com - Twitter actually can be useful</title>
		<link>http://www.contentious.com/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206574</link>
		<dc:creator>contentious.com - Twitter actually can be useful</dc:creator>
		<pubDate>Mon, 12 Nov 2007 16:55:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.contentious.com/archives/2007/11/11/my-blog-got-hacked-probably-at-blogworld-expo/#comment-1206574</guid>
		<description>[...] the weekend, I found Twitter useful when I learned that my blog was hacked by a spammer. As I rushed to understand what happened and what I needed to do to fix the problem, I [...]</description>
		<content:encoded><![CDATA[<p>[...] the weekend, I found Twitter useful when I learned that my blog was hacked by a spammer. As I rushed to understand what happened and what I needed to do to fix the problem, I [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
