Got hacked, hence the weirdness around here the last couple of minutes. Luckily I subscribe to my own feed and happened to see that my last blog post was advertising some really hard core porn. I know you’ll be disappointed but thats not the direction this blog is taking.
What happened?
216.246.56.146 - - [12/Apr/2008:05:27:33 -0700] "GET /wp-admin/edit.php HTTP/1.0" 200 38723 "http://schulzone.org/wp-admin/edit.php" "Opera" 216.246.56.146 - - [12/Apr/2008:05:27:41 -0700] "GET /wp-admin/post.php?action=edit&post=1555 HTTP/1.0" 200 71189 "http://schulzone.org/wp-admin/edit.php" "Opera" 216.246.56.146 - - [12/Apr/2008:05:27:55 -0700] "POST /wp-admin/post.php HTTP/1.0" 200 455 "http://schulzone.org/upload.php?style=inline&tab=upload&post_id=-1" "Opera"
Thats a word press vulnerability. Upgrade your blogs people! The irritating thing is that dreamhost makes this really simple. I pushed a button and waited for 5 minutes to fix it. I run every other part of my online life through providers: Flickr, gmail, hosting, precisely so I don’t have to keep up with shit like this. I used to run everything myself, but it’s too much pain. Maybe a hosting my blog is the same way.
My first reaction on seeing those links was to defecate my pants, almost literally. I used public wireless to transmit the picture to that blog entry from chase ball park, and I thought at first my flickr/email got hacked. Either of which would be very very bad. But I thought about it and realized I was fine: Gmail communicates on secure ports and I didn’t log into anything on the web while I was there. So I combed through the log files and found the bits above.
Let this be a warning: Don’t use public wireless to access non encrypted secure information (which I didn’t, but was scared I had) and keep up with software upgrades.
btw: Chase would be a fantastic place to sniff packets. You’d make out like a bandit.


