<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Something Funny in the State of Maine</title>
	<atom:link href="http://blog.picadesign.com/2009/06/something-funny-in-the-state-of-maine/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.picadesign.com/2009/06/something-funny-in-the-state-of-maine/</link>
	<description>A Graphic Discussion</description>
	<lastBuildDate>Tue, 13 Apr 2010 14:14:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<item>
		<title>By: Tim Shackelford</title>
		<link>http://blog.picadesign.com/2009/06/something-funny-in-the-state-of-maine/comment-page-1/#comment-60</link>
		<dc:creator>Tim Shackelford</dc:creator>
		<pubDate>Tue, 16 Jun 2009 15:03:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.picadesign.com/blog/?p=313#comment-60</guid>
		<description>Several of the sites that I dealt with recently were just plain HTML sites with no dynamic content and no CMS of any sort.  These were basic brochure sites.  

In this case it was just an infected PC running FTP software that was compromised.  This could even happen if a client using Contribute or similar site management software had their PC infected.  

I haven&#039;t heard yet if Macs have also been infected by this malware, but for now FTP info stored on my Mac seems to be safe despite sharing a network with the infected PC.</description>
		<content:encoded><![CDATA[<p>Several of the sites that I dealt with recently were just plain HTML sites with no dynamic content and no CMS of any sort.  These were basic brochure sites.  </p>
<p>In this case it was just an infected PC running FTP software that was compromised.  This could even happen if a client using Contribute or similar site management software had their PC infected.  </p>
<p>I haven&#8217;t heard yet if Macs have also been infected by this malware, but for now FTP info stored on my Mac seems to be safe despite sharing a network with the infected PC.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cait</title>
		<link>http://blog.picadesign.com/2009/06/something-funny-in-the-state-of-maine/comment-page-1/#comment-59</link>
		<dc:creator>Cait</dc:creator>
		<pubDate>Mon, 15 Jun 2009 14:21:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.picadesign.com/blog/?p=313#comment-59</guid>
		<description>Absolutely. It&#039;s essential to keep up to date with the software packages - open source ones particularly. But at least one of the ones I&#039;ve seen has been just html, and on a well protected local host.</description>
		<content:encoded><![CDATA[<p>Absolutely. It&#8217;s essential to keep up to date with the software packages &#8211; open source ones particularly. But at least one of the ones I&#8217;ve seen has been just html, and on a well protected local host.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin</title>
		<link>http://blog.picadesign.com/2009/06/something-funny-in-the-state-of-maine/comment-page-1/#comment-57</link>
		<dc:creator>Justin</dc:creator>
		<pubDate>Sat, 13 Jun 2009 16:20:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.picadesign.com/blog/?p=313#comment-57</guid>
		<description>I&#039;ve also found that sites that use older versions of software packages (WordPress, phpBB, etc.) tend to be very vulnerable to these kinds of attacks. It&#039;s important for someone - whether it&#039;s the site owner or a company that manages the site for a business - to keep that sort of software as up-to-date as possible!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve also found that sites that use older versions of software packages (WordPress, phpBB, etc.) tend to be very vulnerable to these kinds of attacks. It&#8217;s important for someone &#8211; whether it&#8217;s the site owner or a company that manages the site for a business &#8211; to keep that sort of software as up-to-date as possible!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cait</title>
		<link>http://blog.picadesign.com/2009/06/something-funny-in-the-state-of-maine/comment-page-1/#comment-56</link>
		<dc:creator>Cait</dc:creator>
		<pubDate>Fri, 12 Jun 2009 20:36:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.picadesign.com/blog/?p=313#comment-56</guid>
		<description>I&#039;m so glad you were able to figure out the source and clear it up. We&#039;ve seen the same issue on two other local sites that aren&#039;t ours, but are hosted locally. It would be interesting to know if the code on all is the same, and if they share hosting.</description>
		<content:encoded><![CDATA[<p>I&#8217;m so glad you were able to figure out the source and clear it up. We&#8217;ve seen the same issue on two other local sites that aren&#8217;t ours, but are hosted locally. It would be interesting to know if the code on all is the same, and if they share hosting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Shackelford</title>
		<link>http://blog.picadesign.com/2009/06/something-funny-in-the-state-of-maine/comment-page-1/#comment-55</link>
		<dc:creator>Tim Shackelford</dc:creator>
		<pubDate>Fri, 12 Jun 2009 14:44:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.picadesign.com/blog/?p=313#comment-55</guid>
		<description>I experienced 7 sites hacked with this same attack in the last couple of weeks. I believe I found the root.  A malware infected Windows PC that I wasn&#039;t even using for anything but streaming Hulu to a TV.  

This used to be a development computer so I had Dreamweaver on it and was using Dreamweaver to manage FTP connections to the sites I worked on.  Out of 9 FTP profiles in Dreamweaver, 7 were hacked, 1 did not have an index page, and 1 had switched hosting companies.  I&#039;m still not certain how the malware got on that machine in the first place, but I have a feeling it probably occurred when visiting an infected site prior to the site being flagged and the warning being displayed.

The drastic but recommended solution, reformat the PC, clean the code from the website (I had great success by doing a site-wide find on the term &quot;unescape&quot;), then be sure to change the FTP password for the infected site.

Hope this helps!</description>
		<content:encoded><![CDATA[<p>I experienced 7 sites hacked with this same attack in the last couple of weeks. I believe I found the root.  A malware infected Windows PC that I wasn&#8217;t even using for anything but streaming Hulu to a TV.  </p>
<p>This used to be a development computer so I had Dreamweaver on it and was using Dreamweaver to manage FTP connections to the sites I worked on.  Out of 9 FTP profiles in Dreamweaver, 7 were hacked, 1 did not have an index page, and 1 had switched hosting companies.  I&#8217;m still not certain how the malware got on that machine in the first place, but I have a feeling it probably occurred when visiting an infected site prior to the site being flagged and the warning being displayed.</p>
<p>The drastic but recommended solution, reformat the PC, clean the code from the website (I had great success by doing a site-wide find on the term &#8220;unescape&#8221;), then be sure to change the FTP password for the infected site.</p>
<p>Hope this helps!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

