<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacked</title>
	<atom:link href="http://www.ausweblogs.com/users/rodneyfletcher/?feed=rss2&#038;p=4" rel="self" type="application/rss+xml" />
	<link>http://www.ausweblogs.com/users/rodneyfletcher/?p=4</link>
	<description>Technology, life &#038; living</description>
	<lastBuildDate>Sun, 05 Sep 2010 08:29:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Rodney</title>
		<link>http://www.ausweblogs.com/users/rodneyfletcher/?p=4&#038;cpage=1#comment-7</link>
		<dc:creator>Rodney</dc:creator>
		<pubDate>Tue, 29 Nov 2005 12:02:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.ausweblogs.com/users/rodneyfletcher/?p=4#comment-7</guid>
		<description>It&#039;s the most annoying thing in the world, isn&#039;t it? I was lucky like you and the payload of the rootkit was never fully executed. I was doubly lucky in that the server in question was due for retirement at the end of this year anyway and the replacement was already there to go. Still, did you have a look at my post on mod_security for apache?

Old news to many but if you&#039;re not playing with it - you should. The URL for the post is http://www.ausweblogs.com/users/rodneyfletcher/?p=6 (or the one about hacking the web server). It&#039;s really nice to know that anything that tries to fly ludicrous comments like &quot;wget&#039; etc through a URL is going to fail.</description>
		<content:encoded><![CDATA[<p>It&#8217;s the most annoying thing in the world, isn&#8217;t it? I was lucky like you and the payload of the rootkit was never fully executed. I was doubly lucky in that the server in question was due for retirement at the end of this year anyway and the replacement was already there to go. Still, did you have a look at my post on mod_security for apache?</p>
<p>Old news to many but if you&#8217;re not playing with it &#8211; you should. The URL for the post is <a href="http://www.ausweblogs.com/users/rodneyfletcher/?p=6" rel="nofollow">http://www.ausweblogs.com/users/rodneyfletcher/?p=6</a> (or the one about hacking the web server). It&#8217;s really nice to know that anything that tries to fly ludicrous comments like &#8220;wget&#8217; etc through a URL is going to fail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GreyDuck</title>
		<link>http://www.ausweblogs.com/users/rodneyfletcher/?p=4&#038;cpage=1#comment-6</link>
		<dc:creator>GreyDuck</dc:creator>
		<pubDate>Mon, 28 Nov 2005 22:16:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.ausweblogs.com/users/rodneyfletcher/?p=4#comment-6</guid>
		<description>Pain felt... I too ran across r0nin, though it was in the midst of an entirely different procedure (good thing I scrolled through the output of &#039;ps&#039;, eh?) and killed it dead. As near as I can tell, nothing else of badness has transpired, but I&#039;m going to have a long talk with one of the users I provide hosting for... argh.</description>
		<content:encoded><![CDATA[<p>Pain felt&#8230; I too ran across r0nin, though it was in the midst of an entirely different procedure (good thing I scrolled through the output of &#8216;ps&#8217;, eh?) and killed it dead. As near as I can tell, nothing else of badness has transpired, but I&#8217;m going to have a long talk with one of the users I provide hosting for&#8230; argh.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
