<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Techie Gadgets &#187; wordpress upgrade</title>
	<atom:link href="http://techiegadgets.com/tag/wordpress-upgrade/feed/" rel="self" type="application/rss+xml" />
	<link>http://techiegadgets.com</link>
	<description>Cellphones, Laptops, Techie Gadgets</description>
	<lastBuildDate>Tue, 07 Sep 2010 03:36:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Removal from Google&#8217;s Index Due to Hacked Wordpress Plugin</title>
		<link>http://techiegadgets.com/removal-from-googles-index-due-to-hacked-wordpress-plugin/</link>
		<comments>http://techiegadgets.com/removal-from-googles-index-due-to-hacked-wordpress-plugin/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 06:39:54 +0000</pubDate>
		<dc:creator>Noemi</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[hacked wordpress]]></category>
		<category><![CDATA[hacked wordpress plugin]]></category>
		<category><![CDATA[wordpress upgrade]]></category>
		<category><![CDATA[wp super cache]]></category>

		<guid isPermaLink="false">http://techiegadgets.com/?p=949</guid>
		<description><![CDATA[It was nice of Google to inform me. I received this email on June 23

While we were indexing your webpages, we detected that some of your pages were using techniques that are outside our quality guidelines, which can be found here: http://www.google.com/support/webmasters/bin/answer.py?answer=35769&#038;hl=en. This appears to be because your site has been modified by a third [...]]]></description>
			<content:encoded><![CDATA[<p>It was nice of Google to inform me. I received this email on June 23</p>
<blockquote>
<p>While we were indexing your webpages, we detected that some of your pages were using techniques that are outside our quality guidelines, which can be found here: http://www.google.com/support/webmasters/bin/answer.py?answer=35769&#038;hl=en. This appears to be because your site has been modified by a third party. Typically, the offending party gains access to an insecure directory that has open permissions. Many times, they will upload files or modify existing ones, which then show up as spam in our index.<br />
We detected cloaking on your site and suspect this is the cause. For example at http://weddingbellsblog.com/ we found:<br />
fosamax cheap rx purchase fosamax in eastbay california cheapest generic fosamax online compare fosamax prices find how to use fosamax fosamax for sale cheap 250mg fosamax fosamax 250mg online</p>
<p>In order to preserve the quality of our search engine, pages from weddingbellsblog.com are scheduled to be removed temporarily from our search results for at least 30 days.</p></blockquote>
<p>However when I viewed the source file, I could not find anything. I also checked the templates. </p>
<p>When I typed cialis site:weddingbellsblog.com, 265 pages pertaining to the word came out. I clicked on a cache entry and lo and behold, I saw this on the header:<br />
<img src="http://techiegadgets.com/wp-content/uploads/2009/06/cloaking.jpg" alt="" title="cloaking" width="458" height="226" class="aligncenter size-full wp-image-950" /></p>
<p>A css code was injected to my template with the id=&#8217;reklama_css&#8217;</p>
<p>Hundreds of spam links. Checking the templates once more, I could not find anything suspicious. I upgraded to wordpress 2.8 and then got a new template.</p>
<p>Two days later, I still saw the same results. I upgraded the plugins this time. </p>
<p>Then I asked the help of the system administrator of my server (Good thing I own my server), and he found this<br />
<span id="more-949"></span></p>
<blockquote><p>we have checked your webroot files for inclusions. Tag with id=&#8217;reklama_css&#8217; was found in the following files:</p>
<p>./wp-content/gt-cache/ca/image.php: echo &#8220;&#8221;.$rmm1.&#8221;";<br />
./wp-content/gt-cache/gl/.default.php: echo &#8220;&#8221;.$rmm1.&#8221;";</p></blockquote>
<p>So, the <a href="http://wordpress.org/extend/plugins/wp-super-cache/">WP Super Cache</a> was the culprit. I had the old version. The current version was Version: 0.9.4.3.  One thing that surprised me is that the wp-content/cache folder was renamed to wp-content/g-cache. I instructed the tech guy to remove the g-cache folder because I didn&#8217;t have permissions to delete the folder.</p>
<p>Maybe the hacking was due to other factors other than a vulnerable wordpress plugin. It could have been a combination of an outdated wordpress, a writable folder and the vulnerability of wordpress plugin. It teaches me to always do regular upgrade.</p>
<p>Google is now processing my request for reconsideration.</p>
]]></content:encoded>
			<wfw:commentRss>http://techiegadgets.com/removal-from-googles-index-due-to-hacked-wordpress-plugin/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
