<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Support Forum - Topic: Choices site was hacked - known vulnerability?</title>
		<link>http://www.kriesi.at/support/topic/choices-site-was-hacked-known-vulnerability</link>
		<description>Support Forum - Topic: Choices site was hacked - known vulnerability?</description>
		<language>en-US</language>
		<pubDate>Sun, 26 May 2013 00:43:16 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.kriesi.at/support/search.php</link>
		</textInput>
		<atom:link href="http://www.kriesi.at/support/rss/topic/choices-site-was-hacked-known-vulnerability" rel="self" type="application/rss+xml" />

		<item>
			<title>songbyanon on "Choices site was hacked - known vulnerability?"</title>
			<link>http://www.kriesi.at/support/topic/choices-site-was-hacked-known-vulnerability#post-84453</link>
			<pubDate>Sun, 18 Nov 2012 13:42:58 +0000</pubDate>
			<dc:creator>songbyanon</dc:creator>
			<guid isPermaLink="false">84453@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Great, thanks for the quick reply.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Dude on "Choices site was hacked - known vulnerability?"</title>
			<link>http://www.kriesi.at/support/topic/choices-site-was-hacked-known-vulnerability#post-84448</link>
			<pubDate>Sun, 18 Nov 2012 12:42:00 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">84448@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi! &#60;/p&#62;
&#60;p&#62; Yes, Choices version 1.6 fixes the security issue: &#60;a href=&#34;http://themeforest.net/item/choices-responsive-business-and-portfolio/2536338&#34; rel=&#34;nofollow&#34;&#62;http://themeforest.net/item/choices-responsive-business-and-portfolio/2536338&#60;/a&#62;&#60;br /&#62;
Please download the latest version from themeforest.net. &#60;/p&#62;
&#60;p&#62; Best regards,&#60;br /&#62;
Peter
&#60;/p&#62;</description>
		</item>
		<item>
			<title>songbyanon on "Choices site was hacked - known vulnerability?"</title>
			<link>http://www.kriesi.at/support/topic/choices-site-was-hacked-known-vulnerability#post-84440</link>
			<pubDate>Sun, 18 Nov 2012 08:10:19 +0000</pubDate>
			<dc:creator>songbyanon</dc:creator>
			<guid isPermaLink="false">84440@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hello,&#60;/p&#62;
&#60;p&#62;One of my sites using the Choices theme was recently hacked - I believe using a UTF-7 exploit with XSS (though I could be wrong about that).  The hackers basically defaced all the pages by editing the head section on each of the pages.  This resulted in a load of errors like this being displayed on each of the pages:-&#60;/p&#62;
&#60;p&#62;Warning: html_entity_decode() [function.html-entity-decode]: charset `UTF-7' not supported, assuming iso-8859-1 in &#38;lt;URL&#38;gt;/choices/framework/php/function-set-avia-backend.php on line XXX&#60;/p&#62;
&#60;p&#62;From my little understanding of this, I thought this sort of hack was only possible when you don't explicitly declare which charset you are using.  In the theme I see the charset is defined as:-&#60;/p&#62;
&#60;p&#62;&#38;lt;meta charset=&#34;&#38;lt;?php bloginfo( 'charset' ); ?&#38;gt;&#34; /&#38;gt;&#60;/p&#62;
&#60;p&#62;...which seems pretty standard.  &#60;/p&#62;
&#60;p&#62;Any idea how they managed to do this and/or what I can do to prevent it from happening again?  Incidentally, if you do a google search for the error message, you'll see a lot of sites using your themes that have been hacked in the same way (with file function-set-avia-backend.php).&#60;/p&#62;
&#60;p&#62;Thanks in advance
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
