<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Support Forum - Tag: hacked - Recent Posts</title>
		<link>http://www.kriesi.at/support/tags/hacked</link>
		<description>Support Forum - Tag: hacked - Recent Posts</description>
		<language>en-US</language>
		<pubDate>Sun, 19 May 2013 06:26:42 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.kriesi.at/support/search.php</link>
		</textInput>
		<atom:link href="http://www.kriesi.at/support/rss/tags/hacked" rel="self" type="application/rss+xml" />

		<item>
			<title>Devin on "Avisio version 1.2.1 Theme hacked / defaced"</title>
			<link>http://www.kriesi.at/support/topic/avisio-version-121-theme-hacked-defaced#post-89569</link>
			<pubDate>Wed, 02 Jan 2013 15:57:10 +0000</pubDate>
			<dc:creator>Devin</dc:creator>
			<guid isPermaLink="false">89569@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi GT2000,&#60;/p&#62;
&#60;p&#62;I would suggest contacting your hosting provider and ask them to scan your account for vulnerabilities. As far as I know there has been no reported exploit with Avisio or any part of its files. Since Kriesi runs it on his MU install in the demo, I would expect his installation to be hit with something major very quickly if it was discovered.&#60;/p&#62;
&#60;p&#62;Regards,&#60;/p&#62;
&#60;p&#62;Devin
&#60;/p&#62;</description>
		</item>
		<item>
			<title>GT2000 on "Avisio version 1.2.1 Theme hacked / defaced"</title>
			<link>http://www.kriesi.at/support/topic/avisio-version-121-theme-hacked-defaced#post-89533</link>
			<pubDate>Wed, 02 Jan 2013 10:19:32 +0000</pubDate>
			<dc:creator>GT2000</dc:creator>
			<guid isPermaLink="false">89533@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi&#60;br /&#62;
My site with WP3.5 and Avisio 1.2.1 has been defaced (by indonesian hackers both times) twice within a week. It seems like the hacking has been done through the Avisio theme and not at the core WP. Can you please advise me what to do to prevent it to occur again. Is there an update to the theme?&#60;/p&#62;
&#60;p&#62;Kind regards
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Devin on "Serious issues in original CORONA theme files - hacked WP installation"</title>
			<link>http://www.kriesi.at/support/topic/serious-issues-in-original-corona-theme-files-hacked-wp-installation#post-89271</link>
			<pubDate>Fri, 21 Dec 2012 19:21:11 +0000</pubDate>
			<dc:creator>Devin</dc:creator>
			<guid isPermaLink="false">89271@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi colorit2,&#60;/p&#62;
&#60;p&#62;The dst_store is a file created by apple. Since Kriesi compiles and works on a Mac it gets added in. See: &#60;a href=&#34;http://en.wikipedia.org/wiki/.DS_Store&#34; rel=&#34;nofollow&#34;&#62;http://en.wikipedia.org/wiki/.DS_Store&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;There was a security fix in the most recent version of corona (1.4) so you should definitely download it and update. You can do so by re-downloading the theme from themeforest and then installing the theme in the same way you first installed it.&#60;/p&#62;
&#60;p&#62;Regards,&#60;/p&#62;
&#60;p&#62;Devin
&#60;/p&#62;</description>
		</item>
		<item>
			<title>colorit2 on "Serious issues in original CORONA theme files - hacked WP installation"</title>
			<link>http://www.kriesi.at/support/topic/serious-issues-in-original-corona-theme-files-hacked-wp-installation#post-89242</link>
			<pubDate>Fri, 21 Dec 2012 13:35:35 +0000</pubDate>
			<dc:creator>colorit2</dc:creator>
			<guid isPermaLink="false">89242@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Here is a PDF (600 kB) made with Fireshot of this theme check:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;https://www.dropbox.com/s/n0ug942le2z5kmk/ThemeCheck-Corona-Original.pdf&#34; rel=&#34;nofollow&#34;&#62;https://www.dropbox.com/s/n0ug942le2z5kmk/ThemeCheck-Corona-Original.pdf&#60;/a&#62;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>colorit2 on "Serious issues in original CORONA theme files - hacked WP installation"</title>
			<link>http://www.kriesi.at/support/topic/serious-issues-in-original-corona-theme-files-hacked-wp-installation#post-89240</link>
			<pubDate>Fri, 21 Dec 2012 13:29:31 +0000</pubDate>
			<dc:creator>colorit2</dc:creator>
			<guid isPermaLink="false">89240@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi,&#60;/p&#62;
&#60;p&#62;due to some security issues at my WP installation I have made beside other things a theme check with this plugin: &#60;a href=&#34;http://wordpress.org/extend/plugins/theme-check/&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/extend/plugins/theme-check/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;And there are obviously a lot of issues with CORONA; I'm mostly concerned about the red &#34;warnings&#34; like&#60;/p&#62;
&#60;p&#62;&#60;code&#62; ... base64_encode ... &#60;/code&#62;&#60;/p&#62;
&#60;p&#62;in avia-export-class.php for example, fopen, fclose, and why is there a &#60;strong&#62;hidden file/folder &#34;.ds_store&#34;&#60;/strong&#62;??&#60;br /&#62;
It is in the original CORONA files, freshly downloaded at Themeforest.&#60;/p&#62;
&#60;p&#62;What is there to do with all these issues concerning the security?&#60;br /&#62;
(my WP has been hacked by the &#34;pharma hack&#34; --&#38;gt; &#60;a href=&#34;http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php&#34; rel=&#34;nofollow&#34;&#62;http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;And this although I have installed Antivirus, Limit Login Attempts-plugin, several WP security plugins, using strong passwords, having no &#34;admin&#34; user, protecting wp-admin and wp-config.php with .htaccess and having the wp-config.php moved above the WP installation folder etc.&#60;/p&#62;
&#60;p&#62;So I'm currently checking all security vulnerabilities in my network - and therefor I'm worried about the &#34;theme check&#34; of CORONA.&#60;/p&#62;
&#60;p&#62;Any suggestions for this?&#60;br /&#62;
Thanks a lot!
&#60;/p&#62;</description>
		</item>
		<item>
			<title>James Morrison on "Footer hacked?"</title>
			<link>http://www.kriesi.at/support/topic/footer-hacked#post-2560</link>
			<pubDate>Wed, 11 Aug 2010 14:14:26 +0000</pubDate>
			<dc:creator>James Morrison</dc:creator>
			<guid isPermaLink="false">2560@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;If you figure out which plugin is adding the links and you want to continue using the plugin, edit the plugin file and remove the links.&#60;/p&#62;
&#60;p&#62;Some authors offer a &#34;premium&#34; version without links in the footer so it may be worth contacting them first to see if they have any guidelines on this.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>sparklyscotty on "Footer hacked?"</title>
			<link>http://www.kriesi.at/support/topic/footer-hacked#post-2502</link>
			<pubDate>Tue, 10 Aug 2010 16:27:36 +0000</pubDate>
			<dc:creator>sparklyscotty</dc:creator>
			<guid isPermaLink="false">2502@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Thanks so much!  I should have thought of that. Doh!  Will start deactivating and reactivating and see if I can find it.&#60;/p&#62;
&#60;p&#62;Angela
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Dude on "Footer hacked?"</title>
			<link>http://www.kriesi.at/support/topic/footer-hacked#post-2498</link>
			<pubDate>Tue, 10 Aug 2010 15:40:26 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">2498@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;I think the links are produced by the wp_footer() function. Have a look at this thread: &#60;a href=&#34;http://codex.wordpress.org/Plugin_API/Action_Reference/wp_footer&#34; rel=&#34;nofollow&#34;&#62;http://codex.wordpress.org/Plugin_API/Action_Reference/wp_footer&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;Something in your WP setup calls the wp_footer() and produces this code. I'm pretty sure it's a hacked plugin because a javascript file(wp-includes/js/jquery/jquery.form.js?ver=2.02m) from another plugin is called before this spam code.&#60;/p&#62;
&#60;p&#62;If it's located in the footer (hardcoded) you need to check your footer.php - but I don't think so because the spam links would disappear if you change the theme.&#60;/p&#62;
&#60;p&#62;The Dude
&#60;/p&#62;</description>
		</item>
		<item>
			<title>sparklyscotty on "Footer hacked?"</title>
			<link>http://www.kriesi.at/support/topic/footer-hacked#post-2495</link>
			<pubDate>Tue, 10 Aug 2010 15:17:20 +0000</pubDate>
			<dc:creator>sparklyscotty</dc:creator>
			<guid isPermaLink="false">2495@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi folks,  Someone seems to have hack my site, &#60;a href=&#34;http://www.weddingfashionfiles.com&#34; rel=&#34;nofollow&#34;&#62;http://www.weddingfashionfiles.com&#60;/a&#62;  (See those lovely arabic links on the right hand side??)  When I swap themes they appear below the footer area, so I think the guilty code must be in the footer?  If anyone has any suggestions, I would really appreciate it.  My Search and Destroy mission to find the code in my theme files has failed. :(&#60;/p&#62;
&#60;p&#62;Angela
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
