<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Spyware and popups close to home</title>
	<link>http://lukewelling.com/2006/02/27/spyware-and-popups-close-to-home/</link>
	<description>Just another nerd's weblog</description>
	<pubDate>Wed,  7 Jan 2009 11:17:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Loren Wolsiffer</title>
		<link>http://lukewelling.com/2006/02/27/spyware-and-popups-close-to-home/#comment-6784</link>
		<dc:creator>Loren Wolsiffer</dc:creator>
		<pubDate>Fri, 23 Nov 2007 23:11:02 +0000</pubDate>
		<guid>http://lukewelling.com/2006/02/27/spyware-and-popups-close-to-home/#comment-6784</guid>
		<description>I got hit bad by this one, what happens is if a visitor to your site has a referer string from the search engines for certain keywords, they will not see your site as you intended, instead they will see a list of pay per click ads. 

I had literally hundreds of these files in deeply nested directories. I ended up writing the verminator.php and the vermicide.php scripts that would recursively go through an entire website and remove those files and look for the offending .htaccess file and remove the bad stuff and delete the .htaccess file if nothing else was in it, Some of my .htaccess files had passwords and modrewrite and 404 redirects so my script left the important stuff in the .htaccess and put them back the way they were.

They were trying to hide thier tracks and did not deface the site. The hacker and I were literally playing cat and mouse on the server. he would delete the log file but I got a copy just befor he did so.

I wrote my own tracking script and he was using netscape 3 and his ip was from pakistan I then got hundreds of emails with viruses form pakistan, the next day hundreds more from egypt.

I saw your post and had to respond since no one really documented what it does</description>
		<content:encoded><![CDATA[<p>I got hit bad by this one, what happens is if a visitor to your site has a referer string from the search engines for certain keywords, they will not see your site as you intended, instead they will see a list of pay per click ads. </p>
<p>I had literally hundreds of these files in deeply nested directories. I ended up writing the verminator.php and the vermicide.php scripts that would recursively go through an entire website and remove those files and look for the offending .htaccess file and remove the bad stuff and delete the .htaccess file if nothing else was in it, Some of my .htaccess files had passwords and modrewrite and 404 redirects so my script left the important stuff in the .htaccess and put them back the way they were.</p>
<p>They were trying to hide thier tracks and did not deface the site. The hacker and I were literally playing cat and mouse on the server. he would delete the log file but I got a copy just befor he did so.</p>
<p>I wrote my own tracking script and he was using netscape 3 and his ip was from pakistan I then got hundreds of emails with viruses form pakistan, the next day hundreds more from egypt.</p>
<p>I saw your post and had to respond since no one really documented what it does</p>
]]></content:encoded>
	</item>
</channel>
</rss>
