<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: die die die.</title>
	<atom:link href="http://spoken-for.org/archives/2008/08/18/2260/feed/" rel="self" type="application/rss+xml" />
	<link>http://spoken-for.org/archives/2008/08/18/2260/</link>
	<description>hmmm... what?</description>
	<lastBuildDate>Mon, 30 Jan 2012 02:01:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Val</title>
		<link>http://spoken-for.org/archives/2008/08/18/2260/comment-page-1/#comment-511021</link>
		<dc:creator>Val</dc:creator>
		<pubDate>Sun, 24 Aug 2008 22:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://spoken-for.org/?p=2260#comment-511021</guid>
		<description>Heh!  Well I know that no one is going to recommend me someone who&#039;s given them bad service and that all things can change given time, so I would never hold a recommendation gone bad against you.  :)

But yeah, Westhost has been great with this hacking mess.  What ended up happening after my initial post here was that it turned out that the hacker either got back in or had another backdoor and deleted everything as far as my files and some configuration stuff.  Westhost then took my account offline to try and locate the exact problem and then I ended up talking to one of the guys directly on the phone.  He&#039;d asked if it was ok if he could call me.  So he explained it a bit more and at that point, they were bringing things back up and they restored all my files and said that it was a waiting game, had to see if there was another back door.  He&#039;d personally been going through, like, every file, though, to make sure they were clean.  The processes that were apparently running were coming from a CLEAN WordPress install that I&#039;d done the day before in case that person&#039;s account was not updated/was not clean.  It was in the wp-includes folder and was named to appear that it was a WP file.  The IP address trying to access that file was 64.229.176.4 which is curiously similar to one of the ones trying to DoS me last month which was 64.229.225.34 (the other trying to DoS was 219.129.239.147).  I&#039;ve contacted the abuse department at Bell Canada but have yet to receive even a canned response.

Which reminds me... it&#039;s been so long since we talked about IP blocking that I guess I don&#039;t remember a lot of how it&#039;s done.  I can do IP filtering by the server level (I guess, that&#039;s how I thought they explained it to me) and they blocked both of those 64... IPs.  But... if it&#039;s a DSL user all they really have to do is turn off their modem for a bit and it will pick a new IP right?  So how far should one block? 64.229.* ??

So, anyway, he said after restoring everything that it was pretty much a waiting game to see if they had another backdoor yet and that they were keeping close watch.  That was mid-Thursday so, so far so good.</description>
		<content:encoded><![CDATA[<p>Heh!  Well I know that no one is going to recommend me someone who&#8217;s given them bad service and that all things can change given time, so I would never hold a recommendation gone bad against you.  :)</p>
<p>But yeah, Westhost has been great with this hacking mess.  What ended up happening after my initial post here was that it turned out that the hacker either got back in or had another backdoor and deleted everything as far as my files and some configuration stuff.  Westhost then took my account offline to try and locate the exact problem and then I ended up talking to one of the guys directly on the phone.  He&#8217;d asked if it was ok if he could call me.  So he explained it a bit more and at that point, they were bringing things back up and they restored all my files and said that it was a waiting game, had to see if there was another back door.  He&#8217;d personally been going through, like, every file, though, to make sure they were clean.  The processes that were apparently running were coming from a CLEAN WordPress install that I&#8217;d done the day before in case that person&#8217;s account was not updated/was not clean.  It was in the wp-includes folder and was named to appear that it was a WP file.  The IP address trying to access that file was 64.229.176.4 which is curiously similar to one of the ones trying to DoS me last month which was 64.229.225.34 (the other trying to DoS was 219.129.239.147).  I&#8217;ve contacted the abuse department at Bell Canada but have yet to receive even a canned response.</p>
<p>Which reminds me&#8230; it&#8217;s been so long since we talked about IP blocking that I guess I don&#8217;t remember a lot of how it&#8217;s done.  I can do IP filtering by the server level (I guess, that&#8217;s how I thought they explained it to me) and they blocked both of those 64&#8230; IPs.  But&#8230; if it&#8217;s a DSL user all they really have to do is turn off their modem for a bit and it will pick a new IP right?  So how far should one block? 64.229.* ??</p>
<p>So, anyway, he said after restoring everything that it was pretty much a waiting game to see if they had another backdoor yet and that they were keeping close watch.  That was mid-Thursday so, so far so good.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Owen</title>
		<link>http://spoken-for.org/archives/2008/08/18/2260/comment-page-1/#comment-510776</link>
		<dc:creator>Owen</dc:creator>
		<pubDate>Sun, 24 Aug 2008 13:51:01 +0000</pubDate>
		<guid isPermaLink="false">http://spoken-for.org/?p=2260#comment-510776</guid>
		<description>I get nervous about recommending hosts because when things like this happen inevitably you get some of the blame.  But in this case I&#039;ll just say, &quot;See???&quot;  ;)</description>
		<content:encoded><![CDATA[<p>I get nervous about recommending hosts because when things like this happen inevitably you get some of the blame.  But in this case I&#8217;ll just say, &#8220;See???&#8221;  ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Val</title>
		<link>http://spoken-for.org/archives/2008/08/18/2260/comment-page-1/#comment-510497</link>
		<dc:creator>Val</dc:creator>
		<pubDate>Sun, 24 Aug 2008 02:11:08 +0000</pubDate>
		<guid isPermaLink="false">http://spoken-for.org/?p=2260#comment-510497</guid>
		<description>Actually, this post was from before things went &lt;i&gt;really&lt;/i&gt; bad, lol.  But I have been too tired/busy to make any updates :)</description>
		<content:encoded><![CDATA[<p>Actually, this post was from before things went <i>really</i> bad, lol.  But I have been too tired/busy to make any updates :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vixx</title>
		<link>http://spoken-for.org/archives/2008/08/18/2260/comment-page-1/#comment-510389</link>
		<dc:creator>Vixx</dc:creator>
		<pubDate>Sat, 23 Aug 2008 18:26:21 +0000</pubDate>
		<guid isPermaLink="false">http://spoken-for.org/?p=2260#comment-510389</guid>
		<description>Soooo relieved everything&#039;s back to normal!

V xx</description>
		<content:encoded><![CDATA[<p>Soooo relieved everything&#8217;s back to normal!</p>
<p>V xx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajemi</title>
		<link>http://spoken-for.org/archives/2008/08/18/2260/comment-page-1/#comment-509017</link>
		<dc:creator>Ajemi</dc:creator>
		<pubDate>Thu, 21 Aug 2008 19:32:52 +0000</pubDate>
		<guid isPermaLink="false">http://spoken-for.org/?p=2260#comment-509017</guid>
		<description>When did you switch from Site5? I can&#039;t wait to switch from them when my contract is up.</description>
		<content:encoded><![CDATA[<p>When did you switch from Site5? I can&#8217;t wait to switch from them when my contract is up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amber</title>
		<link>http://spoken-for.org/archives/2008/08/18/2260/comment-page-1/#comment-507992</link>
		<dc:creator>Amber</dc:creator>
		<pubDate>Mon, 18 Aug 2008 21:50:35 +0000</pubDate>
		<guid isPermaLink="false">http://spoken-for.org/?p=2260#comment-507992</guid>
		<description>I&#039;m glad your host got things fixed. That was really awesome of them!</description>
		<content:encoded><![CDATA[<p>I&#8217;m glad your host got things fixed. That was really awesome of them!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

