<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Attacks on OpenX v2.8.2 installations reported</title>
	<atom:link href="http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/</link>
	<description>Support, Consulting, and Training for OpenX Source ad server</description>
	<lastBuildDate>Thu, 03 Nov 2011 08:03:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Erik Geurts</title>
		<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/comment-page-1/#comment-183</link>
		<dc:creator>Erik Geurts</dc:creator>
		<pubDate>Wed, 14 Apr 2010 17:45:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.openxconsultant.com/?p=445#comment-183</guid>
		<description>Hi Will, Tait,

I&#039;m very sorry to hear that you&#039;ve been hit by this, as have been many others. I would like to recommend that you contact &lt;a href=&quot;http://www.beccati.com/&quot; rel=&quot;nofollow&quot;&gt;Matteo Beccati&lt;/a&gt;, he is almost certainly able to help you with the clean-up efforts.

Good luck, Erik Geurts</description>
		<content:encoded><![CDATA[<p>Hi Will, Tait,</p>
<p>I&#8217;m very sorry to hear that you&#8217;ve been hit by this, as have been many others. I would like to recommend that you contact <a href="http://www.beccati.com/" rel="nofollow">Matteo Beccati</a>, he is almost certainly able to help you with the clean-up efforts.</p>
<p>Good luck, Erik Geurts</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tait</title>
		<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/comment-page-1/#comment-182</link>
		<dc:creator>Tait</dc:creator>
		<pubDate>Wed, 14 Apr 2010 13:14:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.openxconsultant.com/?p=445#comment-182</guid>
		<description>Hey Erik,

Do you know what entries were made in the DB that caused the stats to not show up?

Thanks!</description>
		<content:encoded><![CDATA[<p>Hey Erik,</p>
<p>Do you know what entries were made in the DB that caused the stats to not show up?</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will Willis</title>
		<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/comment-page-1/#comment-181</link>
		<dc:creator>Will Willis</dc:creator>
		<pubDate>Tue, 13 Apr 2010 22:44:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.openxconsultant.com/?p=445#comment-181</guid>
		<description>I just found that I&#039;ve been hit with this attack.  I moved the install.php file out of www/admin/ and I deleted the new admin account.  Any idea how I can get my stats back?</description>
		<content:encoded><![CDATA[<p>I just found that I&#8217;ve been hit with this attack.  I moved the install.php file out of www/admin/ and I deleted the new admin account.  Any idea how I can get my stats back?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matteo Beccati</title>
		<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/comment-page-1/#comment-180</link>
		<dc:creator>Matteo Beccati</dc:creator>
		<pubDate>Tue, 13 Apr 2010 09:57:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.openxconsultant.com/?p=445#comment-180</guid>
		<description>I&#039;ve just reported the attacker IP address to the abuse account of the Italian ISP (Fastweb).

Quickly translated email follows:
&lt;cite&gt;
Hi,

I&#039;ve been contacted by many customers around the world to solve the issues caused by an attack exploiting a vulnerability of the popular open source ad server OpenX (www.openx.org).

The mass infection took place on Saturday April 10 between 1pm and 2pm Italian time and it was coming from an IP address belonging to your network: 62.101.68.213.

Here are some excerpts from web server logs that I verified myself:
&lt;code&gt;
62.101.68.213 - - [10/Apr/2010:07:46:56 -0400] &quot;GET /admin/index.php HTTP/1.1&quot; 200 1388 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:07:46:56 -0400] &quot;POST /admin/install.php HTTP/1.1&quot; 200 1529 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:07:46:57 -0400] &quot;POST /admin/index.php HTTP/1.1&quot; 200 1438 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:07:46:57 -0400] &quot;GET /admin/account-switch.php?account_id=1 HTTP/1.1&quot; 200 1378 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:07:46:58 -0400] &quot;POST /admin/plugin-index.php HTTP/1.1&quot; 200 1367 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
&lt;/code&gt;

&lt;code&gt;
62.101.68.213 - - [10/Apr/2010:04:47:17 -0700] &quot;GET /openx/www/admin/index.php HTTP/1.1&quot; 200 4420 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:04:47:21 -0700] &quot;POST /openx/www/admin/install.php HTTP/1.1&quot; 200 3688 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:04:47:23 -0700] &quot;POST /openx/www/admin/index.php HTTP/1.1&quot; 200 4410 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:04:47:26 -0700] &quot;GET /openx/www/admin/account-switch.php?account_id=1 HTTP/1.1&quot; 200 4263 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:04:47:29 -0700] &quot;POST /openx/www/admin/plugin-index.php HTTP/1.1&quot; 200 4248 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
62.101.68.213 - - [10/Apr/2010:04:47:32 -0700] &quot;GET /openx/plugins/bannerTypeHtml/oxHtml/genericHtml.delivery.php HTTP/1.1&quot; 200 175 &quot;-&quot; &quot;Mozilla/5.0 (Windows)&quot;
&lt;/code&gt;
&lt;/cite&gt;</description>
		<content:encoded><![CDATA[<p>I&#8217;ve just reported the attacker IP address to the abuse account of the Italian ISP (Fastweb).</p>
<p>Quickly translated email follows:<br />
<cite><br />
Hi,</p>
<p>I&#8217;ve been contacted by many customers around the world to solve the issues caused by an attack exploiting a vulnerability of the popular open source ad server OpenX (www.openx.org).</p>
<p>The mass infection took place on Saturday April 10 between 1pm and 2pm Italian time and it was coming from an IP address belonging to your network: 62.101.68.213.</p>
<p>Here are some excerpts from web server logs that I verified myself:<br />
<code><br />
62.101.68.213 - - [10/Apr/2010:07:46:56 -0400] "GET /admin/index.php HTTP/1.1" 200 1388 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:07:46:56 -0400] "POST /admin/install.php HTTP/1.1" 200 1529 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:07:46:57 -0400] "POST /admin/index.php HTTP/1.1" 200 1438 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:07:46:57 -0400] "GET /admin/account-switch.php?account_id=1 HTTP/1.1" 200 1378 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:07:46:58 -0400] "POST /admin/plugin-index.php HTTP/1.1" 200 1367 "-" "Mozilla/5.0 (Windows)"<br />
</code></p>
<p><code><br />
62.101.68.213 - - [10/Apr/2010:04:47:17 -0700] "GET /openx/www/admin/index.php HTTP/1.1" 200 4420 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:04:47:21 -0700] "POST /openx/www/admin/install.php HTTP/1.1" 200 3688 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:04:47:23 -0700] "POST /openx/www/admin/index.php HTTP/1.1" 200 4410 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:04:47:26 -0700] "GET /openx/www/admin/account-switch.php?account_id=1 HTTP/1.1" 200 4263 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:04:47:29 -0700] "POST /openx/www/admin/plugin-index.php HTTP/1.1" 200 4248 "-" "Mozilla/5.0 (Windows)"<br />
62.101.68.213 - - [10/Apr/2010:04:47:32 -0700] "GET /openx/plugins/bannerTypeHtml/oxHtml/genericHtml.delivery.php HTTP/1.1" 200 175 "-" "Mozilla/5.0 (Windows)"<br />
</code><br />
</cite></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Payne</title>
		<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/comment-page-1/#comment-179</link>
		<dc:creator>Craig Payne</dc:creator>
		<pubDate>Tue, 13 Apr 2010 09:38:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.openxconsultant.com/?p=445#comment-179</guid>
		<description>Erik

Thanks for staying on top of this. As you know I have been watching the forum posts and reports nervously about my installation. No problems yet.

CP</description>
		<content:encoded><![CDATA[<p>Erik</p>
<p>Thanks for staying on top of this. As you know I have been watching the forum posts and reports nervously about my installation. No problems yet.</p>
<p>CP</p>
]]></content:encoded>
	</item>
</channel>
</rss>

