<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" > <channel><title>Comments for Brett Terpstra</title> <atom:link href="http://brettterpstra.com/comments/feed/" rel="self" type="application/rss+xml" /><link>http://brettterpstra.com</link> <description>Elegant solutions to complex problems.</description> <lastBuildDate>Sun, 01 Aug 2010 00:41:52 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=2413</generator> <item><title>Comment on Notes on cleaning up the MediaTemple hack (JohnnyA) by Dan</title><link>http://brettterpstra.com/2010/07/24/notes-on-cleaning-up-the-mediatemple-hack-johnnya/comment-page-1/#comment-853</link> <dc:creator>Dan</dc:creator> <pubDate>Sun, 01 Aug 2010 00:41:52 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=823#comment-853</guid> <description>&lt;p&gt;I have 5 sites I manage on Media Temple each with their own account and a wordpress install with version 3.0.  All were compromised with the JohnnyA malware attack.&lt;/p&gt;&lt;p&gt;This appears to be more and more related to Media Temple&#039;s lack of ACL rather than a wordpress exploit.  However, it greatly disappoints me that they have failed to come forth and admit they &quot;screwed up&quot;...again.&lt;/p&gt;&lt;p&gt;I found the offending rootkit exploit located in folders nested deep without anything in common to the locations with other sites I manage.  You can add these file names to the list:&lt;/p&gt;&lt;p&gt;chmod.php fopen.php mkdir.php&lt;/p&gt;&lt;p&gt;Still the only way to locate and eradicate the exploit is to use the following &quot;grep&quot; commands with the above mentioned string both for the javascript and php rootkit.&lt;/p&gt;&lt;p&gt;grep -R &quot;document.write(unescape&quot; *&lt;/p&gt;&lt;p&gt;grep -iR --include &quot;*.php&quot; &quot;[a-zA-Z0-9&#092;/&#092;+]&#092;{255,&#092;}&quot; *&lt;/p&gt;&lt;p&gt;After you&#039;re done make sure to send a nice note to Media Temple demanding a years free hosting for the trouble...it wasn&#039;t too long ago we all had the hassle of changing our MySQL passwords due to a lack of security measure by Media Temple as well.&lt;/p&gt; </description> <content:encoded><![CDATA[<p>I have 5 sites I manage on Media Temple each with their own account and a wordpress install with version 3.0.  All were compromised with the JohnnyA malware attack.</p><p>This appears to be more and more related to Media Temple’s lack of ACL rather than a wordpress exploit.  However, it greatly disappoints me that they have failed to come forth and admit they “screwed up”…again.</p><p>I found the offending rootkit exploit located in folders nested deep without anything in common to the locations with other sites I manage.  You can add these file names to the list:</p><p>chmod.php fopen.php mkdir.php</p><p>Still the only way to locate and eradicate the exploit is to use the following “grep” commands with the above mentioned string both for the javascript and php rootkit.</p><p>grep –R “document.write(unescape” *</p><p>grep –iR –include “*.php” “[a-zA-Z0-9\/\+]\{255,\}” *</p><p>After you’re done make sure to send a nice note to Media Temple demanding a years free hosting for the trouble…it wasn’t too long ago we all had the hassle of changing our MySQL passwords due to a lack of security measure by Media Temple as well.</p>]]></content:encoded> </item> <item><title>Comment on Single-keystroke Instapaper in Google Reader by LagaV</title><link>http://brettterpstra.com/2010/07/28/single-keystroke-instapaper-in-google-reader/comment-page-1/#comment-847</link> <dc:creator>LagaV</dc:creator> <pubDate>Sat, 31 Jul 2010 16:55:16 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=836#comment-847</guid> <description>&lt;p&gt;Great tool. I would love to have similar functionality to transfer stuff directly from Google Reader or Instapaper into Evernote....(preferably using the reduced content provided by Safari Reader)&lt;/p&gt; </description> <content:encoded><![CDATA[<p>Great tool. I would love to have similar functionality to transfer stuff directly from Google Reader or Instapaper into Evernote.…(preferably using the reduced content provided by Safari Reader)</p>]]></content:encoded> </item> <item><title>Comment on Safari Reader Antique hack by Xiaohung.</title><link>http://brettterpstra.com/2010/06/12/safari-reader-antique-hack/comment-page-1/#comment-842</link> <dc:creator>Xiaohung.</dc:creator> <pubDate>Sat, 31 Jul 2010 12:15:28 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=562#comment-842</guid> <description>&lt;p&gt;Hello,I come here for the first time. Nice to meet you too.. &amp;Your avatar(that at your blog) is really~~~ OK,It&#039;s a good skin for Safari reader. Love it! Thx~~&lt;/p&gt; </description> <content:encoded><![CDATA[<p>Hello,I come here for the first time. Nice to meet you too.. &amp;Your avatar(that at your blog) is really~~~ OK,It’s a good skin for Safari reader. Love it! Thx~~</p>]]></content:encoded> </item> <item><title>Comment on Notes on cleaning up the MediaTemple hack (JohnnyA) by theFlashBlog &#187; Details Of The JohnnyA MediaTemple Hack</title><link>http://brettterpstra.com/2010/07/24/notes-on-cleaning-up-the-mediatemple-hack-johnnya/comment-page-1/#comment-836</link> <dc:creator>theFlashBlog &#187; Details Of The JohnnyA MediaTemple Hack</dc:creator> <pubDate>Sat, 31 Jul 2010 04:11:34 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=823#comment-836</guid> <description>&lt;p&gt;[...] much searching and with the help of this blog post, I have found the rootkit that is used to do the damage. If you have been hacked you will find some [...]&lt;/p&gt; </description> <content:encoded><![CDATA[<p>[…] much searching and with the help of this blog post, I have found the rootkit that is used to do the damage. If you have been hacked you will find some […]</p>]]></content:encoded> </item> <item><title>Comment on TabLinks Safari Extension by Robert Spencer</title><link>http://brettterpstra.com/2010/06/18/tablinks-safari-extension/comment-page-1/#comment-832</link> <dc:creator>Robert Spencer</dc:creator> <pubDate>Fri, 30 Jul 2010 19:33:05 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=641#comment-832</guid> <description>&lt;p&gt;I&#039;ve just tested again and it works now. Seems like all that was needed was a total restart of Safari. Apologies for the noise, I should have tested for that to before reporting a problem. In my defence I was mislead by extensions.apple.com saying that there was &quot;no need to restart Safari&quot;.&lt;/p&gt;&lt;p&gt;That you for this great extension. I&#039;m quite chuffed with it. :-)&lt;/p&gt; </description> <content:encoded><![CDATA[<p>I’ve just tested again and it works now. Seems like all that was needed was a total restart of Safari. Apologies for the noise, I should have tested for that to before reporting a problem. In my defence I was mislead by extensions.apple.com saying that there was “no need to restart Safari”.</p><p>That you for this great extension. I’m quite chuffed with it. :-)</p>]]></content:encoded> </item> <item><title>Comment on Single-keystroke Instapaper in Google Reader by Google Reader an Instapaper per Tastendruck - surfgarden</title><link>http://brettterpstra.com/2010/07/28/single-keystroke-instapaper-in-google-reader/comment-page-1/#comment-826</link> <dc:creator>Google Reader an Instapaper per Tastendruck - surfgarden</dc:creator> <pubDate>Fri, 30 Jul 2010 14:44:55 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=836#comment-826</guid> <description>&lt;p&gt;[...] wirklich praktische Erweiterung für Safari ist GReader Instapaper: Ist es installiert, braucht es nur einen Tastendruck – wie z.B. “i” – um den [...]&lt;/p&gt; </description> <content:encoded><![CDATA[<p>[…] wirklich praktische Erweiterung für Safari ist GReader Instapaper: Ist es installiert, braucht es nur einen Tastendruck – wie z.B. “i” – um den […]</p>]]></content:encoded> </item> <item><title>Comment on Make amazing coffee without the hassle by Scott Jangro</title><link>http://brettterpstra.com/2010/07/24/make-amazing-coffee-without-the-hassle/comment-page-1/#comment-816</link> <dc:creator>Scott Jangro</dc:creator> <pubDate>Fri, 30 Jul 2010 06:33:46 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=816#comment-816</guid> <description>&lt;p&gt;That&#039;s interesting that the aeropress (which I&#039;ve never tried) is optimal at such a low temperature.  Convention says that 195-200 degrees is best for brewing coffee.&lt;/p&gt;&lt;p&gt;My favorite way to make coffee is with a syphon pot.  It is a bit more involved than the aeropress but it makes the cleanest cup that you&#039;ll ever taste.&lt;/p&gt;&lt;p&gt;Maybe I&#039;ll pick up an aeropress as, Iike you, I&#039;ve switched to drinking tea more during the day. I&#039;ve heard good things about it elsewhere.&lt;/p&gt; </description> <content:encoded><![CDATA[<p>That’s interesting that the aeropress (which I’ve never tried) is optimal at such a low temperature.  Convention says that 195–200 degrees is best for brewing coffee.</p><p>My favorite way to make coffee is with a syphon pot.  It is a bit more involved than the aeropress but it makes the cleanest cup that you’ll ever taste.</p><p>Maybe I’ll pick up an aeropress as, Iike you, I’ve switched to drinking tea more during the day. I’ve heard good things about it elsewhere.</p>]]></content:encoded> </item> <item><title>Comment on Notes on cleaning up the MediaTemple hack (JohnnyA) by Joshua</title><link>http://brettterpstra.com/2010/07/24/notes-on-cleaning-up-the-mediatemple-hack-johnnya/comment-page-1/#comment-813</link> <dc:creator>Joshua</dc:creator> <pubDate>Fri, 30 Jul 2010 02:50:22 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=823#comment-813</guid> <description>&lt;p&gt;I had PHP files added throughout my file structure on almost every site hosted with (mt).  I ended up finding them using instructions found here: http://www.uhleeka.com/blog/2010/07/johnnya-wordpress-malware-on-mediatemple/&lt;/p&gt;&lt;p&gt;Because of the way the hack works he recommended searching for a string longer than 255 characters.&lt;/p&gt;&lt;p&gt;&lt;code&gt;grep -iR --include &quot;*.php&quot; &quot;[a-zA-Z0-9\/\+]\{255,\}&quot; *&lt;/code&gt;&lt;/p&gt; </description> <content:encoded><![CDATA[<p>I had PHP files added throughout my file structure on almost every site hosted with (mt).  I ended up finding them using instructions found here: <a href="http://www.uhleeka.com/blog/2010/07/johnnya-wordpress-malware-on-mediatemple/" rel="nofollow">http://www.uhleeka.com/blog/2010/07/johnnya-wordpress-malware-on-mediatemple/</a></p><p>Because of the way the hack works he recommended searching for a string longer than 255 characters.</p><p><code>grep -iR --include "*.php" "[a-zA-Z0-9\/\+]\{255,\}" *</code></p>]]></content:encoded> </item> <item><title>Comment on TabLinks Safari Extension by Brett</title><link>http://brettterpstra.com/2010/06/18/tablinks-safari-extension/comment-page-1/#comment-807</link> <dc:creator>Brett</dc:creator> <pubDate>Thu, 29 Jul 2010 22:43:59 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=641#comment-807</guid> <description>&lt;p&gt;I&#039;ll need to know more about how you&#039;re using it to figure out why it&#039;s not working for you. It has to be run in a tab which has a page loaded in it, but beyond that, it really should function in almost any case. Do you have a template set in the preferences (there&#039;s one loaded by default)?&lt;/p&gt; </description> <content:encoded><![CDATA[<p>I’ll need to know more about how you’re using it to figure out why it’s not working for you. It has to be run in a tab which has a page loaded in it, but beyond that, it really should function in almost any case. Do you have a template set in the preferences (there’s one loaded by default)?</p>]]></content:encoded> </item> <item><title>Comment on TabLinks Safari Extension by Robert Spencer</title><link>http://brettterpstra.com/2010/06/18/tablinks-safari-extension/comment-page-1/#comment-805</link> <dc:creator>Robert Spencer</dc:creator> <pubDate>Thu, 29 Jul 2010 22:34:56 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=641#comment-805</guid> <description>&lt;p&gt;I think it&#039;s a beautiful idea, I installed it from extensions.apple.com and then came here to read up more about it. Unfortunately after repeated testing I&#039;ve come to the conclusion that it does nothing. Maybe it&#039;s bust, but I don&#039;t get anything like in your screen-shot. I even tried uninstalling, downloaded the zip file from here and tested again. Nothing. Using Safari 5.0.1 (5533.17.8).&lt;/p&gt; </description> <content:encoded><![CDATA[<p>I think it’s a beautiful idea, I installed it from extensions.apple.com and then came here to read up more about it. Unfortunately after repeated testing I’ve come to the conclusion that it does nothing. Maybe it’s bust, but I don’t get anything like in your screen-shot. I even tried uninstalling, downloaded the zip file from here and tested again. Nothing. Using Safari 5.0.1 (5533.17.8).</p>]]></content:encoded> </item> <item><title>Comment on Instapaper Beyond for Fluid.app by Kacy Triolo</title><link>http://brettterpstra.com/2010/03/28/instapaper-beyond/comment-page-1/#comment-803</link> <dc:creator>Kacy Triolo</dc:creator> <pubDate>Thu, 29 Jul 2010 20:28:49 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=344#comment-803</guid> <description>&lt;p&gt;Awesome, ok if i link back to you?&lt;/p&gt; </description> <content:encoded><![CDATA[<p>Awesome, ok if i link back to you?</p>]]></content:encoded> </item> <item><title>Comment on Single-keystroke Instapaper in Google Reader by Brett</title><link>http://brettterpstra.com/2010/07/28/single-keystroke-instapaper-in-google-reader/comment-page-1/#comment-794</link> <dc:creator>Brett</dc:creator> <pubDate>Thu, 29 Jul 2010 13:58:33 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=836#comment-794</guid> <description>&lt;p&gt;Quite possibly a bug, I haven&#039;t tested it without a password yet.&lt;/p&gt; </description> <content:encoded><![CDATA[<p>Quite possibly a bug, I haven’t tested it without a password yet.</p>]]></content:encoded> </item> <item><title>Comment on A better System Service for Evernote clipping — with MultiMarkdown by Brett</title><link>http://brettterpstra.com/2010/03/06/a-better-os-x-system-service-for-evernote-notes-with-multimarkdown/comment-page-1/#comment-793</link> <dc:creator>Brett</dc:creator> <pubDate>Thu, 29 Jul 2010 13:57:00 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=302#comment-793</guid> <description>&lt;p&gt;That&#039;s easy enough. Let me know if you build it before I do :).&lt;/p&gt; </description> <content:encoded><![CDATA[<p>That’s easy enough. Let me know if you build it before I do :).</p>]]></content:encoded> </item> <item><title>Comment on Notes on cleaning up the MediaTemple hack (JohnnyA) by Brett</title><link>http://brettterpstra.com/2010/07/24/notes-on-cleaning-up-the-mediatemple-hack-johnnya/comment-page-1/#comment-792</link> <dc:creator>Brett</dc:creator> <pubDate>Thu, 29 Jul 2010 13:54:58 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=823#comment-792</guid> <description>&lt;p&gt;That&#039;s exactly where I found them in one install. I didn&#039;t list it verbatim as I didn&#039;t find them there in all installs and figured it was random.&lt;/p&gt; </description> <content:encoded><![CDATA[<p>That’s exactly where I found them in one install. I didn’t list it verbatim as I didn’t find them there in all installs and figured it was random.</p>]]></content:encoded> </item> <item><title>Comment on Notes on cleaning up the MediaTemple hack (JohnnyA) by Chris</title><link>http://brettterpstra.com/2010/07/24/notes-on-cleaning-up-the-mediatemple-hack-johnnya/comment-page-1/#comment-784</link> <dc:creator>Chris</dc:creator> <pubDate>Thu, 29 Jul 2010 04:41:41 +0000</pubDate> <guid isPermaLink="false">http://brettterpstra.com/?p=823#comment-784</guid> <description>&lt;p&gt;Did you notice any files added to the TinyMCE folder that&#039;s included in WordPress? I noticed that this folder path was the most common across all of the affected domains. This path in particular:&lt;/p&gt;&lt;p&gt;&lt;code&gt;(domain name)/html/wp-includes/js/tinymce/plugins/inlinepopups/skins/clearlooks2/img/&lt;/code&gt;&lt;/p&gt;&lt;p&gt;I wonder if that wasn&#039;t the point of entry, or if it&#039;s just a coincidence.&lt;/p&gt; </description> <content:encoded><![CDATA[<p>Did you notice any files added to the TinyMCE folder that’s included in WordPress? I noticed that this folder path was the most common across all of the affected domains. This path in particular:</p><p><code>(domain name)/html/wp-includes/js/tinymce/plugins/inlinepopups/skins/clearlooks2/img/</code></p><p>I wonder if that wasn’t the point of entry, or if it’s just a coincidence.</p>]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using xcache
Database Caching 15/45 queries in 0.076 seconds using xcache
Object Caching 424/770 objects using xcache
Content Delivery Network via Amazon Web Services: CloudFront: Amazon Web Services: S3: cdn.brettterpstra.com

Served from: brettterpstra.com @ 2010-08-01 03:35:22 -->