<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>felix ker&#039;s blog &#187; blog</title>
	<atom:link href="http://felixker.com/category/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://felixker.com</link>
	<description>Codes, Life, Love, Media, Money, Tips &#38; Tricks, Web 2.0 &#38; all</description>
	<lastBuildDate>Thu, 29 Jul 2010 10:29:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>felixker.com shifted!</title>
		<link>http://felixker.com/web-hosting/felixkercom-shifted/</link>
		<comments>http://felixker.com/web-hosting/felixkercom-shifted/#comments</comments>
		<pubDate>Mon, 16 Jun 2008 08:20:43 +0000</pubDate>
		<dc:creator>Felix Ker</dc:creator>
				<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[migration]]></category>

		<guid isPermaLink="false">http://felixker.com/web-hosting/felixkercom-shifted/</guid>
		<description><![CDATA[After blogging about my previous web host being slow, I&#8217;ve subscribed for another web hosting package for this blog to run smoothly. For the past few days, I&#8217;ve been working on this blog to ensure that the web hosting migration will be smooth. Migration is now done for felixker.com and from now till June next [...]


Related posts:<ol><li><a href='http://felixker.com/technology/felixkercom-hacked-defaced-and-how-to-prevent-hacking/' rel='bookmark' title='Permanent Link: felixker.com hacked &amp; defaced and how to prevent hacking'>felixker.com hacked &amp; defaced and how to prevent hacking</a></li>
<li><a href='http://felixker.com/events/9-things-i-did-online-in-2007/' rel='bookmark' title='Permanent Link: 9 Things I did ONLINE in 2007'>9 Things I did ONLINE in 2007</a></li>
<li><a href='http://felixker.com/daily-rants/funny-conversations-on-msn/' rel='bookmark' title='Permanent Link: Funny conversations on MSN'>Funny conversations on MSN</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>After <a href="http://felixker.com/web-hosting/web-hosting-for-blog-required/" class="liinternal">blogging about my previous web host being slow</a>, I&#8217;ve subscribed for another web hosting package for this blog to run smoothly. For the past few days, I&#8217;ve been working on this blog to ensure that the web hosting migration will be smooth.</p>
<p>Migration is now done for felixker.com and from now till June next year, this blog will be hosted with <a href="http://frro.net" rel="nofollow" class="liexternal">FRRO</a>. </p>
<p><em>Do comment and let me know if anything here isn&#8217;t working well. And also, don&#8217;t forget to tell me how you feel about this blog.</em></p>
<p>---<br />Related Articles at felix ker&#039;s blog:<ul><li><a href="http://felixker.com/feature/fauzi-pingsg-dont-bully-ahwei/" rel="bookmark" title="Permanent Link: Fauzi @ Ping.SG : Don&#8217;t bully Ahwei">Fauzi @ Ping.SG : Don&#8217;t bully Ahwei</a></li><li><a href="http://felixker.com/just-for-fun/felixkercom-blog-for-sale/" rel="bookmark" title="Permanent Link: felixker.com &#8211; Blog for sale">felixker.com &#8211; Blog for sale</a></li><li><a href="http://felixker.com/technology/felixkercom-hacked-defaced-and-how-to-prevent-hacking/" rel="bookmark" title="Permanent Link: felixker.com hacked &amp; defaced and how to prevent hacking">felixker.com hacked &amp; defaced and how to prevent hacking</a></li></ul></p><br />

<p>Related posts:<ol><li><a href='http://felixker.com/technology/felixkercom-hacked-defaced-and-how-to-prevent-hacking/' rel='bookmark' title='Permanent Link: felixker.com hacked &amp; defaced and how to prevent hacking'>felixker.com hacked &amp; defaced and how to prevent hacking</a></li>
<li><a href='http://felixker.com/events/9-things-i-did-online-in-2007/' rel='bookmark' title='Permanent Link: 9 Things I did ONLINE in 2007'>9 Things I did ONLINE in 2007</a></li>
<li><a href='http://felixker.com/daily-rants/funny-conversations-on-msn/' rel='bookmark' title='Permanent Link: Funny conversations on MSN'>Funny conversations on MSN</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://felixker.com/web-hosting/felixkercom-shifted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>felixker.com hacked &amp; defaced and how to prevent hacking</title>
		<link>http://felixker.com/technology/felixkercom-hacked-defaced-and-how-to-prevent-hacking/</link>
		<comments>http://felixker.com/technology/felixkercom-hacked-defaced-and-how-to-prevent-hacking/#comments</comments>
		<pubDate>Sat, 14 Jun 2008 03:40:21 +0000</pubDate>
		<dc:creator>Felix Ker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[blog]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Read on to find out how I got hacked and eventually defaced and what I did to recover &#38; protect my website. I was surprised one evening (last year) when I came online and found my blog defaced by hackers. I still remember the page being very simple having big headers &#8220;h4ck3d by xxxxx&#8221;. Let&#8217;s [...]


Related posts:<ol><li><a href='http://felixker.com/technology/how-to-know-when-your-facebook-is-hacked/' rel='bookmark' title='Permanent Link: How to know when your Facebook is hacked'>How to know when your Facebook is hacked</a></li>
<li><a href='http://felixker.com/web-hosting/felixkercom-shifted/' rel='bookmark' title='Permanent Link: felixker.com shifted!'>felixker.com shifted!</a></li>
<li><a href='http://felixker.com/daily-rants/blogwebsite-links-updated/' rel='bookmark' title='Permanent Link: Blog/Website links updated'>Blog/Website links updated</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Read on to find out how I got hacked and eventually defaced and what I did to recover &amp; protect my website.</p>
<p>I was surprised one evening (last year) when I came online and found my blog defaced by hackers. I still remember the page being very simple having big headers &#8220;h4ck3d by xxxxx&#8221;. Let&#8217;s not name anyone in this scene okay.</p>
<p>When I googled my own site, even Google&#8217;s Cache shows the hacker&#8217;s page. My page must&#8217;ve been hacked the night before when I didn&#8217;t come online.</p>
<p><strong>How felixker.com got hacked?</strong></p>
<p>As I&#8217;m on a shared hosting environment, there were other sites that had security flaws that enabled the hacker to enter through the vulnerability. That was all I know when I told my provider I got hacked, as I wasn&#8217;t the only one reporting the issue.</p>
<p>Next, I went into Plesk (Hosting Control Panel) to check Apache&#8217;s logs for suspicious activity. This was when I found out that the hacker got in through a neighbouring site (on the same host) and <strong>placed a php backdoor script in my site</strong>. Next, he renamed my index.php to index2.php and placed his own index file (that contained those hacked messages).</p>
<p>I looked up the IP address (on apnic.net) I saw along with the access records and identified that the IP belonged to Indonesia. Not surprising at all.</p>
<p><strong>How I recovered my blog?</strong></p>
<p>I don&#8217;t have much files inside my public folder, so all I got to do was to browse around my folders through FTP and identify those files I didn&#8217;t add. After that, delete all them to prevent the hackers from being able to access my site through the backdoor.</p>
<p>Other than that, I set all folders I don&#8217;t need to <strong>644</strong> permission.</p>
<p><strong>Hacked second time!</strong></p>
<p>I thought I was smart by removing all the files and no one could use the backdoor to play pranks. I was wrong.</p>
<p>The hacker went back to the main site that could be exploited, replaced the backdoor file on a different folder and put back the same hacked message.</p>
<p>I had to contact support regarding this to have them help out. They took down the affected sites and removed the exploits before putting the sites online again.</p>
<p><strong>Preven</strong><strong>tion</strong></p>
<p>I shall share some prevention tips whether you&#8217;re on shared or dedicated environment.</p>
<ol>
<li><strong>Update your softwares regularly!</strong> There shouldn&#8217;t be much issues with Apache/PHP these days, but it&#8217;s still wise your provider updates the software into the latest stable build.</li>
<li><strong>Make sure you&#8217;re not running out-of-date PHP softwares!</strong> If you&#8217;re using any CMS programs, check the program site regularly for updates and tips on security. It&#8217;ll do you good in the long run. You&#8217;re likely to encounter less bugs too.</li>
<li><strong>CHMOD folders and files to 644 when not needed to modify/create files. </strong>Unless your programs need to create files inside any folders, don&#8217;t leave them as 777. 644 is always safest. FTP into your host now to change the permissions. Don&#8217;t invite unwanted files.</li>
<li><strong>Secure your passwords</strong>. That could be the weakest link. When your login details are too easy, e.g username:admin password:password. Its always wise to use a password with 8 or more characters and should be alpha-numerical!</li>
</ol>
<p>You can also attend a <strong><a href="http://eccouncilacademy.org/main/index.php?option=com_content&amp;task=blogsection&amp;id=11&amp;Itemid=147" rel="nofollow" class="liexternal">Complimentary Workshop on Cybersecurity</a></strong> if you&#8217;re interested to learn more about security..</p>
<p>There are many tips, but I can only think of 4. <strong>What can you share with me with regards to hacking and prevention? </strong></p>
<p>---<br />Related Articles at felix ker&#039;s blog:<ul><li><a href="http://felixker.com/feature/fauzi-pingsg-dont-bully-ahwei/" rel="bookmark" title="Permanent Link: Fauzi @ Ping.SG : Don&#8217;t bully Ahwei">Fauzi @ Ping.SG : Don&#8217;t bully Ahwei</a></li><li><a href="http://felixker.com/interesting-articles/awesome-business-model/" rel="bookmark" title="Permanent Link: Awesome Business Model">Awesome Business Model</a></li><li><a href="http://felixker.com/programming/sql-server-management-studio-2008-saving-changes-is-not-permitted-solution/" rel="bookmark" title="Permanent Link: SQL Server Management Studio 2008: Saving changes is not permitted (Solution)">SQL Server Management Studio 2008: Saving changes is not permitted (Solution)</a></li><li><a href="http://felixker.com/web-hosting/felixkercom-shifted/" rel="bookmark" title="Permanent Link: felixker.com shifted!">felixker.com shifted!</a></li><li><a href="http://felixker.com/interesting-articles/lets-all-wear-white-undergarments/" rel="bookmark" title="Permanent Link: Lets all wear white undergarments">Lets all wear white undergarments</a></li></ul></p><br />

<p>Related posts:<ol><li><a href='http://felixker.com/technology/how-to-know-when-your-facebook-is-hacked/' rel='bookmark' title='Permanent Link: How to know when your Facebook is hacked'>How to know when your Facebook is hacked</a></li>
<li><a href='http://felixker.com/web-hosting/felixkercom-shifted/' rel='bookmark' title='Permanent Link: felixker.com shifted!'>felixker.com shifted!</a></li>
<li><a href='http://felixker.com/daily-rants/blogwebsite-links-updated/' rel='bookmark' title='Permanent Link: Blog/Website links updated'>Blog/Website links updated</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://felixker.com/technology/felixkercom-hacked-defaced-and-how-to-prevent-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk (feed is rejected)
Page Caching using disk (enhanced) (user agent is rejected)
Database Caching 48/125 queries in 0.991 seconds using disk
Content Delivery Network via cdn.felixker.com

Served from: felixker.com @ 2010-07-31 00:50:35 -->