<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: mozgilla hack &#8211; index.* files corrupted</title>
	<atom:link href="http://blog.georgezamfir.com/mozgilla-hack-index-files-corrupted.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.georgezamfir.com/mozgilla-hack-index-files-corrupted.html</link>
	<description></description>
	<lastBuildDate>Mon, 14 Jun 2010 12:00:39 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ashleymsm</title>
		<link>http://blog.georgezamfir.com/mozgilla-hack-index-files-corrupted.html/comment-page-1#comment-515</link>
		<dc:creator>Ashleymsm</dc:creator>
		<pubDate>Mon, 14 Jun 2010 12:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.georgezamfir.com/?p=643#comment-515</guid>
		<description>Your site is like a blonde with a brain. I like it. All jokes apart, vrey informative post and equally impressive design.</description>
		<content:encoded><![CDATA[<p>Your site is like a blonde with a brain. I like it. All jokes apart, vrey informative post and equally impressive design.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Louboutin Shoes</title>
		<link>http://blog.georgezamfir.com/mozgilla-hack-index-files-corrupted.html/comment-page-1#comment-513</link>
		<dc:creator>Christian Louboutin Shoes</dc:creator>
		<pubDate>Fri, 04 Jun 2010 10:38:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.georgezamfir.com/?p=643#comment-513</guid>
		<description>Thank you for useful info. :-)</description>
		<content:encoded><![CDATA[<p>Thank you for useful info. <img src='http://blog.georgezamfir.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George</title>
		<link>http://blog.georgezamfir.com/mozgilla-hack-index-files-corrupted.html/comment-page-1#comment-485</link>
		<dc:creator>George</dc:creator>
		<pubDate>Thu, 05 Nov 2009 23:09:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.georgezamfir.com/?p=643#comment-485</guid>
		<description>Well, my index.* files didn&#039;t have any permissions ( e.g. ---------- 1 668 552 3669 Oct 30 18:16 index.php), if it were 777 it&#039;d have been easier for me to figure it out. But it had no permissions and I couldn&#039;t edit them... until I set my own permissions again. 

Anyhow, you&#039;re right in all other respects. Thanks for the info.</description>
		<content:encoded><![CDATA[<p>Well, my index.* files didn&#8217;t have any permissions ( e.g. &#8212;&#8212;&#8212;- 1 668 552 3669 Oct 30 18:16 index.php), if it were 777 it&#8217;d have been easier for me to figure it out. But it had no permissions and I couldn&#8217;t edit them&#8230; until I set my own permissions again. </p>
<p>Anyhow, you&#8217;re right in all other respects. Thanks for the info.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas J. Raef</title>
		<link>http://blog.georgezamfir.com/mozgilla-hack-index-files-corrupted.html/comment-page-1#comment-483</link>
		<dc:creator>Thomas J. Raef</dc:creator>
		<pubDate>Wed, 04 Nov 2009 22:48:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.georgezamfir.com/?p=643#comment-483</guid>
		<description>You may have found your files with the wrong permissions, but they were set that way by the hackers.

The way this works is that a PC with FTP access to a website gets a virus. I know, everyone has anti-virus software these days. However, anti-virus vendors are faced with 30,000 new viruses everyday so they started creating more generic signatures. These signatures are ill-prepared for the newer viruses that hackers claim are FUD (Fully Un Detectable).

These viruses steal FTP login credentials, send them to a server which carries out the website infection with valid FTP credentials. When &quot;they&quot; upload their infected files, the permissions are set to 777. This makes it easier for them to modify later on if you remove their work the first time.

So, without scanning all PCs with FTP access for viruses, the website is still vulnerable to re-infection.

First, change all FTP passwords. Then, because these viruses also know how to evade detection of the currently installed anti-virus software, it&#039;s recommended to use something different. Many have had good success with AVG, Avast or Avira. Select one of those and use it with Malwarebytes - on every PC with FTP access to the website.

Also, keep in mind that while your specific infection showed the mozgilla.ru domain, many other domains are used as well. The same infectious code, but a different domain.

I just thought I&#039;d share my experience in dealing with this for so many site owners.</description>
		<content:encoded><![CDATA[<p>You may have found your files with the wrong permissions, but they were set that way by the hackers.</p>
<p>The way this works is that a PC with FTP access to a website gets a virus. I know, everyone has anti-virus software these days. However, anti-virus vendors are faced with 30,000 new viruses everyday so they started creating more generic signatures. These signatures are ill-prepared for the newer viruses that hackers claim are FUD (Fully Un Detectable).</p>
<p>These viruses steal FTP login credentials, send them to a server which carries out the website infection with valid FTP credentials. When &#8220;they&#8221; upload their infected files, the permissions are set to 777. This makes it easier for them to modify later on if you remove their work the first time.</p>
<p>So, without scanning all PCs with FTP access for viruses, the website is still vulnerable to re-infection.</p>
<p>First, change all FTP passwords. Then, because these viruses also know how to evade detection of the currently installed anti-virus software, it&#8217;s recommended to use something different. Many have had good success with AVG, Avast or Avira. Select one of those and use it with Malwarebytes &#8211; on every PC with FTP access to the website.</p>
<p>Also, keep in mind that while your specific infection showed the mozgilla.ru domain, many other domains are used as well. The same infectious code, but a different domain.</p>
<p>I just thought I&#8217;d share my experience in dealing with this for so many site owners.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
