<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">

<channel>
	<title>Aaron Mentele, Charisma 18</title>
	
	<link>http://aaronmentele.com</link>
	<description>Charisma 18 is the personal blog of Aaron Mentele, web developer and partner at Electric Pulp</description>
	<pubDate>Mon, 14 Jul 2008 02:35:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/charisma18/full" type="application/rss+xml" /><item>
		<title>Dance</title>
		<link>http://aaronmentele.com/2008/07/13/dance/</link>
		<comments>http://aaronmentele.com/2008/07/13/dance/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 02:35:59 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[travel]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=518</guid>
		<description><![CDATA[Some day, I&#8217;d like to travel extensively. (And not because I&#8217;m in a witness protection program.) Until then, I&#8217;ll settle to watch this guy.
]]></description>
			<content:encoded><![CDATA[<p>Some day, I&#8217;d like to travel extensively. (And not because I&#8217;m in a witness protection program.) Until then, <a href="http://www.youtube.com/watch?v=zlfKdbWwruY">I&#8217;ll settle to watch this guy</a>.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/334709404" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/07/13/dance/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Five men will die this year as a result of fireworks (and other pretty statistics)</title>
		<link>http://aaronmentele.com/2008/07/01/dying-as-a-result-of/</link>
		<comments>http://aaronmentele.com/2008/07/01/dying-as-a-result-of/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 14:18:43 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[design]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=517</guid>
		<description><![CDATA[Your chances of dying, designed to hang on your wall.
]]></description>
			<content:encoded><![CDATA[<p>Your chances of dying, <a href="http://blog.2modern.com/2008/07/scary-man-forma.html">designed to hang on your wall</a>.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/324076673" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/07/01/dying-as-a-result-of/feed/</wfw:commentRss>
		</item>
		<item>
		<title>My new muse</title>
		<link>http://aaronmentele.com/2008/06/30/my-new-muse/</link>
		<comments>http://aaronmentele.com/2008/06/30/my-new-muse/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 04:49:47 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[design]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=516</guid>
		<description><![CDATA[Design inspiration offers no RSS feed. Deal with it.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.graphic-exchange.com">Design inspiration offers no RSS feed.</a> Deal with it.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/323778037" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/30/my-new-muse/feed/</wfw:commentRss>
		</item>
		<item>
		<title>hackz0red!</title>
		<link>http://aaronmentele.com/2008/06/30/hackz0red/</link>
		<comments>http://aaronmentele.com/2008/06/30/hackz0red/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 14:10:25 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Geek]]></category>

		<category><![CDATA[hacked]]></category>

		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=512</guid>
		<description><![CDATA[On Friday a client and co-conspirateur IM’ed about a Safe Browsing warning being thrown at visitors to his blog. The alert warned that accessing the site could result in malicious software being downloaded and installed without user consent. If that wasn’t a strong enough deterrent from visiting, anyone hitting the site with the shiny new [...]]]></description>
			<content:encoded><![CDATA[<p>On Friday a client and co-conspirateur IM’ed about a Safe Browsing warning being thrown at visitors to his blog. The alert warned that accessing the site could result in malicious software being downloaded and installed without user consent. If that wasn’t a strong enough deterrent from visiting, anyone hitting the site with the shiny new Firefox 3 browser saw the <strong>Reported Attack Site!</strong> banner.</p>
<p><img src="http://aaronmentele.com/wp-content/uploads/2008/06/attack-site-460-1.gif" alt="" title="attack-site-460" width="460" height="192" class="alignnone size-full wp-image-515" /></p>
<p>Without naming the blog (this is now under further investigation, so if you know the site, please don’t mention it in the comments, etc.), I’ll say it’s a popular, revenue-generating blog with a very respectable following and <a href="http://technorati.com">technorati</a> ranking.</p>
<p><a href="http://electricpulp.com">We</a> didn’t build the site but were familiar with its guts - we do a lot with similar blog software and had recently upgraded the site to <a href="http://wordpress.org/development/2008/04/wordpress-251/">WordPress 2.5.1</a>. The warning, though, was new to me. I don’t think we’ve ever had a client that got flagged by Google.</p>
<p>1. To make sure we knew what we were chasing, we verified the site and checked its status in the <a href="https://www.google.com/webmasters/tools/dashboard/">Google Webmaster Tools</a> dashboard. The site overview told us that day’s crawl found intermediary links to malware. The list of pages it encountered with the link included the front page, so the issue didn’t seem to be coming from a comment.</p>
<p>2. Viewing the generated source (consider this another endorsement of the <a href="http://chrispederick.com/work/web-developer/">Web Developer extension</a> for Firefox and Flock) <strong>showed a suspicious iframe being included just inside the body of any blog page</strong>. The source of that frame was an offsite link to a malware drop. In other words, the site had been hacked.</p>
<h3>What do you do if your site is hacked?</h3>
<p>3. I’m not the world’s best hack0r chaser. In fact, when I took off to find the source, I thought I was looking for a simple document.write or crazy hex string somewhere in the hundreds of files / thousands of database entries involved in making the site go.</p>
<p>I checked the wp-posts and wp-comments tables. I disabled the plugins. I turned off the javascript ad calls. All this assuming someone was leveraging a WordPress security hole or injecting code through an ad server. <strong>Incorrect.</strong></p>
<p>4. We downloaded all site files and did a local search on the project files starting inside the theme and moving outward. We didn’t find anything.</p>
<p>5. After talking a bit more to the site owner, we decided to just carpet bomb the javascript - remove all scripts on the live site that weren’t already checked. The iframe disappeared.</p>
<p>6. After going through each file manually, we found the hacked code buried inside a script that called Flash to handle some typography on the site. It could have been any where, but that script probably seemed about the least obvious place to attach it. And he / she was right. We missed the eval(unescape(&#8217;%64%&#8230;&#8217;)); on the first pass.</p>
<h3>How the hell did that get in there?</h3>
<p>7. It’s probably worth mentioning we didn’t have shell access to the server, and we had to ask the web host to send us the access log. When we got it, I was a bit surprised to see <strong>the hacker got in via SFTP</strong>. They had the password.</p>
<p>8. We changed the passwords to the site, the databases, and to WordPress. Then, 9. went through each file uploaded by the ip address the hacker used. <strong>A contact form needed to be re-written.</strong> Some WordPress includes were replaced. A few other files were trimmed. <strong>A robots.txt file had to be corrected.</strong></p>
<p>10. Now that the site was clean (we hope), we had to take care of the Safe Browsing flag at Google. <strong>We requested another review in the Webmaster Tools dashboard.</strong> It took about 10-15 hours, but the crawl came back clean and the warning was removed. That was early Sunday morning.</p>
<p>11. The next step is a fresh WordPress install (it’d be great if 2.6 came out of beta in the next day or so). This will remove any doubt that we missed anything nasty outside of the theme or content folders. The web host will need to get involved as well. I’m not sure what kind of monitoring is currently in place, but it can always be improved. All passwords on any related applications will need to be changed.</p>
<h3>What they were trying to do.</h3>
<p>I’ve seen plenty of malicious code injections. The beta launch of Truemors alone resulted in 3 or 4 different ways clever kids can drop some text into a site. But this one was nasty. Judging from everything we found, it’s pretty clear the perp’s were trying to nuke the site’s ranking in search engines in addition to everything else.</p>
<ol>
<li>The iframe sourcing malware was a blatant flag to Google.</li>
<li>An additional page was set up in an attempt to host malware. (another flag)</li>
<li>A contact form was hijacked.</li>
<li>A script was added to allow a quick password change. (to lock out the site owner.)</li>
<li>A robots.txt file was modified to disallow bots.</li>
</ol>
<p>That last bit (blocking search engine crawls with a robots.txt file) is pretty telling. And scary. Someone was really trying to damage the popularity of the blog, and, from what we can tell, this was just the start.</p>
<p>My point in writing this rather than just twittering a bunch of <strong>zomg</strong> blurts was to show how quickly someone with proper motivation can damage your livelihood.</p>
<p>In this case, the site owner didn’t have a dedicated team that could immediately correct the issue. He was able to call in a few favors, but it still took him about 36 hours to get turned around (including the review by Google). It could have been longer had <a href="http://www.mozilla.com/en-US/firefox/?from=getfirefox">Firefox 3</a> not shipped with browsing alerts turned on by default, and it definitely would have been worse had he not had a few pals familiar with his setup. (Not that I’d rank high on the list of heroes to call.)</p>
<p>The take away here is this: <strong>you need to lock down anything you rely on</strong>. Keep your passwords clean. Keep your software current. But, more importantly, make sure you have a few emergency contacts. And, pay attention to Google.</p>
<p>This could happen to you. Especially if you’re <em>kind of a big deal</em>.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/323269982" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/30/hackz0red/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Spinning tower</title>
		<link>http://aaronmentele.com/2008/06/25/spinning-tower/</link>
		<comments>http://aaronmentele.com/2008/06/25/spinning-tower/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 01:56:45 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[architecture]]></category>

		<category><![CDATA[dubai]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=511</guid>
		<description><![CDATA[Each of its 80 floors will spin independently. This seems like a really bad idea. And yet&#8230;
]]></description>
			<content:encoded><![CDATA[<p><a href="http://news.bbc.co.uk/1/hi/world/middle_east/7472722.stm">Each of its 80 floors will spin independently.</a> This seems like a really bad idea. And yet&#8230;</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/320156218" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/25/spinning-tower/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Accidental panelist</title>
		<link>http://aaronmentele.com/2008/06/25/accidental-panelist/</link>
		<comments>http://aaronmentele.com/2008/06/25/accidental-panelist/#comments</comments>
		<pubDate>Wed, 25 Jun 2008 05:28:18 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[sxsw]]></category>

		<category><![CDATA[sxswi]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=510</guid>
		<description><![CDATA[This one time, Guy Kawasaki asked me to join a panel at SXSWi. True Stories From Social Media
]]></description>
			<content:encoded><![CDATA[<p>This one time, Guy Kawasaki asked me to join a panel at SXSWi. <a href="http://audio.sxsw.com/podcast/interactive/panels/2008/SXSW08.INT.20080310.TrueStoriesFromSocialMedia.mp3">True Stories From Social Media</a></p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/319438586" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/25/accidental-panelist/feed/</wfw:commentRss>
<enclosure url="http://audio.sxsw.com/podcast/interactive/panels/2008/SXSW08.INT.20080310.TrueStoriesFromSocialMedia.mp3" length="31864512" type="audio/mpeg" />
		</item>
		<item>
		<title>Bricks</title>
		<link>http://aaronmentele.com/2008/06/24/bricks/</link>
		<comments>http://aaronmentele.com/2008/06/24/bricks/#comments</comments>
		<pubDate>Tue, 24 Jun 2008 15:28:58 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=507</guid>
		<description><![CDATA[This guy likes Legos more than I do. (non permalink)
]]></description>
			<content:encoded><![CDATA[<p><a href="http://flickr.com/photos/kaminoan/sets/">This guy likes Legos more than I do.</a> (<a href="http://flickr.com/photos/kaminoan/page15/">non permalink</a>)</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/318967227" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/24/bricks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Spore</title>
		<link>http://aaronmentele.com/2008/06/17/spore/</link>
		<comments>http://aaronmentele.com/2008/06/17/spore/#comments</comments>
		<pubDate>Tue, 17 Jun 2008 16:55:16 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[gaming]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=506</guid>
		<description><![CDATA[If you&#8217;ve been on the Internet today, you probably already know the Spore Creature Creator is available and awesome. Consider this one more notice.
]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;ve been on the Internet today, you probably already know the <a href="http://www.spore.com/getSpore">Spore Creature Creator</a> is available and awesome. Consider this one more notice.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/313930514" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/17/spore/feed/</wfw:commentRss>
		</item>
		<item>
		<title>on the modern prowl</title>
		<link>http://aaronmentele.com/2008/06/16/on-the-modern-prowl/</link>
		<comments>http://aaronmentele.com/2008/06/16/on-the-modern-prowl/#comments</comments>
		<pubDate>Tue, 17 Jun 2008 04:13:37 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=502</guid>
		<description><![CDATA[Linda Hogan is a cougar. And, somehow, that news deserves video.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cnn.com/video/#/video/showbiz/2008/06/16/sbt.cougar.linda.hogan.cnn?iref=mpvideosview">Linda Hogan is a cougar</a>. And, somehow, that news deserves video.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/313519136" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/16/on-the-modern-prowl/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Contributing factors</title>
		<link>http://aaronmentele.com/2008/06/14/tim-russert/</link>
		<comments>http://aaronmentele.com/2008/06/14/tim-russert/#comments</comments>
		<pubDate>Sat, 14 Jun 2008 05:57:08 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Geek]]></category>

		<category><![CDATA["Tim Russert"]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=505</guid>
		<description><![CDATA[58 is too young to exit by way of a disease that names stress as a contributing factor. We should all check our own.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.msnbc.msn.com/id/25145431/">58</a> is too young to exit by way of a disease that names stress as a contributing factor. We should all check our own.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/313571440" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/14/tim-russert/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Sue Teller Mashes It Up</title>
		<link>http://aaronmentele.com/2008/06/13/sue-teller-mashes-it-up/</link>
		<comments>http://aaronmentele.com/2008/06/13/sue-teller-mashes-it-up/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 14:57:55 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[ads]]></category>

		<category><![CDATA[music]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=501</guid>
		<description><![CDATA[It&#8217;s an ad, but that won&#8217;t stop me from linking to Sue Teller mashing it up.
]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s an ad, but that won&#8217;t stop me from linking to <a href="http://youtube.com/watch?v=A4uyN5rQbbU">Sue Teller mashing it up</a>.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/311203631" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/13/sue-teller-mashes-it-up/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mac or PC?</title>
		<link>http://aaronmentele.com/2008/06/11/mac-or-pc/</link>
		<comments>http://aaronmentele.com/2008/06/11/mac-or-pc/#comments</comments>
		<pubDate>Thu, 12 Jun 2008 02:00:33 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[politics]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=500</guid>
		<description><![CDATA[Republican candidates were asked a simple question: Mac or PC? I like John McCain&#8217;s answer best.
]]></description>
			<content:encoded><![CDATA[<p>Republican candidates were asked a simple question: Mac or PC? I like<a href="http://www.huffingtonpost.com/2008/06/11/mccain-admits-he-doesnt-k_n_106478.html"> John McCain&#8217;s answer</a> best.</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/310080516" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/11/mac-or-pc/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Democratic race in 8 minutes</title>
		<link>http://aaronmentele.com/2008/06/10/democratic-race-in-8-minutes/</link>
		<comments>http://aaronmentele.com/2008/06/10/democratic-race-in-8-minutes/#comments</comments>
		<pubDate>Tue, 10 Jun 2008 14:59:29 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[politics]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=499</guid>
		<description><![CDATA[The democratic race in 8 minutes.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://slatev.com/player.html?id=1593347006">The democratic race in 8 minutes.</a></p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/308892649" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/10/democratic-race-in-8-minutes/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Escape From Corporate America</title>
		<link>http://aaronmentele.com/2008/06/09/escape-from-corporate-america/</link>
		<comments>http://aaronmentele.com/2008/06/09/escape-from-corporate-america/#comments</comments>
		<pubDate>Tue, 10 Jun 2008 04:14:01 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[books]]></category>

		<category><![CDATA[surveys]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=498</guid>
		<description><![CDATA[Escape from corporate America.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.guykawasaki.com/2008/06/how-to-escape-c.html">Escape from corporate America.</a></p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/308535861" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/09/escape-from-corporate-america/feed/</wfw:commentRss>
		</item>
		<item>
		<title>dirty car art</title>
		<link>http://aaronmentele.com/2008/06/08/dirty-car-art/</link>
		<comments>http://aaronmentele.com/2008/06/08/dirty-car-art/#comments</comments>
		<pubDate>Sun, 08 Jun 2008 16:34:51 +0000</pubDate>
		<dc:creator>Aaron Mentele</dc:creator>
		
		<category><![CDATA[Asides]]></category>

		<category><![CDATA[art]]></category>

		<guid isPermaLink="false">http://aaronmentele.com/?p=497</guid>
		<description><![CDATA[What can you say about dirty car art? How about awesome?
]]></description>
			<content:encoded><![CDATA[<p>What can you say about <a href="http://www.dirtycarart.com/gallery/">dirty car art</a>? How about <em>awesome</em>?</p>
<img src="http://feeds.feedburner.com/~r/charisma18/full/~4/307433598" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://aaronmentele.com/2008/06/08/dirty-car-art/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
