<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Themocracy WordPress Themes &#187; malware</title>
	<atom:link href="http://themocracy.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://themocracy.com</link>
	<description>WordPress Theme Design</description>
	<lastBuildDate>Thu, 18 Aug 2011 07:34:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>WordPress and Gumblar &#8211; a significant problem</title>
		<link>http://themocracy.com/2009/11/wordpress-and-gumblar-a-significant-problem/</link>
		<comments>http://themocracy.com/2009/11/wordpress-and-gumblar-a-significant-problem/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 17:48:34 +0000</pubDate>
		<dc:creator>Lisa</dc:creator>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://themocracy.com/?p=199</guid>
		<description><![CDATA[You&#8217;ve got a problem &#8211; all your WordPress pages show an error message something like this Fatal error: Cannot redeclare xfm() (previously declared in /path/to/site/index.php(1) : eval()&#8217;d code:1) in /xxx/yyy/site/wp-config.php(1) : eval()&#8217;d code on line 1 the eval()&#8217;d code is the significant part. So you have a look &#8211; and you&#8217;ve got a whole heap [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fthemocracy.com%2F2009%2F11%2Fwordpress-and-gumblar-a-significant-problem%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fthemocracy.com%2F2009%2F11%2Fwordpress-and-gumblar-a-significant-problem%2F" height="61" width="51" /></a></div><p><img class="alignright size-full wp-image-200" title="virus sign" src="http://themocracy.com/wp-content/uploads/2009/11/virus-sign.jpg" alt="virus sign" width="175" height="157" />You&#8217;ve got a problem &#8211; all your WordPress pages show an error message something like this</p>
<p>Fatal error: Cannot redeclare xfm() (previously declared in /path/to/site/index.php(1) : eval()&#8217;d code:1)<br />
in /xxx/yyy/site/wp-config.php(1) : eval()&#8217;d code on line 1</p>
<p>the <strong>eval()&#8217;d code</strong> is the significant part.</p>
<p>So you have a look &#8211; and you&#8217;ve got a whole heap of rubbish in all php files that starts off something like</p>
<p><strong>eval(base64_decode(&#8216;aWYoIWlzc2V0K</strong>&#8230;.</p>
<p>You might also hunt around for any files helpfully named <strong>exploit.php</strong></p>
<p>You&#8217;ve caught Gumblar &#8211; which is an unpleasant business that attacks any PHP driven application, WordPress, Joomla, e-commerce applications, anything.<br />
<span id="more-199"></span><br />
Its main purpose seems to be to redirect Google search results &#8211; results that were yours will start heading off somewhere else. It may also grab sensitive information from compromised machines, and target your site visitors with attacks on PDF and Flash Player vulnerabilities to plant malware on their PCs.</p>
<p>1. First thing, remove all the infected files and replace them &#8211; you have got a clean copy of your site sitting on your desktop&#8230;? You should do, and probably will after this&#8230; If not, the quickest way is to make sure that all your /wp-content folder is clean,  then download the latest version of WordPress and do an update on the way.</p>
<p>2. Change your FTP access details &#8211; and that doesn&#8217;t mean, if you&#8217;re a developer, changing them and then sending the new details to all interested parties by unencrypted email. Use a text message&#8230; it&#8217;s about the best use for a text message I&#8217;ve ever found.</p>
<p>3. Change your wp-config password details &#8211; obviously.</p>
<p>4. Check through your file/folder permissions, CHMOD etc &#8211; if you&#8217;ve somehow got folders at 777 that shouldn&#8217;t be, you need to sort this now. But this can be a tricky one. Depending on server configuration, image uploads may require varying permissions &#8211; check out <a href="http://codex.wordpress.org/Hardening_WordPress">Hardening WordPress</a> on the subject &#8211; and if you are still unsure, get someone who does some sysadmin to have a look</p>
<p>If there&#8217;s any updates in this area, do comment and we will also include any other info as it becomes available.</p>
]]></content:encoded>
			<wfw:commentRss>http://themocracy.com/2009/11/wordpress-and-gumblar-a-significant-problem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

