<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dwayne Coots &#187; security</title>
	<atom:link href="http://dwaynecoots.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://dwaynecoots.com</link>
	<description>Renaissance Biological Organism</description>
	<lastBuildDate>Thu, 19 Aug 2010 13:26:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>FTP Exploit &#8211; Back Door to Your Website</title>
		<link>http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/</link>
		<comments>http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/#comments</comments>
		<pubDate>Sun, 04 Oct 2009 16:24:22 +0000</pubDate>
		<dc:creator>Dwayne</dc:creator>
				<category><![CDATA[Tech Channel]]></category>
		<category><![CDATA[free information]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware prevention]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webmaster resources]]></category>
		<category><![CDATA[webmaster security]]></category>

		<guid isPermaLink="false">http://dwaynecoots.com/?p=50</guid>
		<description><![CDATA[Recently a client reported the heder.php exploit had infected their website. They needed help with the cleanup, so we got them back online, but they had questions like, &#8220;How did these files get onto my site?&#8221; First understand that heder.php is just one type of site trojan. There are many flavors of this type of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fftp-exploit-back-door-to-your-website%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fftp-exploit-back-door-to-your-website%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Recently a client reported the heder.php exploit had infected their website. They needed help with the cleanup, so we got them back online, but they had questions like, &#8220;How did these files get onto my site?&#8221;</p>
<p>First understand that heder.php is just one type of site trojan. There are many flavors of this type of site exploit and they have some things in common, so it might be worth a blog post to cover them.</p>
<p>These kinds of exploits compromise your hosting account. Then they  install malicious code into your html pages. They also add some entries to your htaccess file to redirect incoming traffic to the payload. Usually the payload is a version of the same exploit so the code can spread to the next victim.</p>
<p>So now we know how you get it&#8230; Basically, this exploit is usually dropped onto your machine when you visit an infected website. It will overwrite a Microsoft ActiveX file on your machine &#8212; which is how it hides from your antivirus. (Yes as usual it&#8217;s a Micro$oft exploit).</p>
<p>So what does it do?</p>
<p>In the background it scans for usernames and passwords. If it finds them it steals then and uploads them to the hackers. If it finds FTP credentials it uses those to upload itself to your websites and inject some code into your home page and write some backdoor ssh access files into your server space.  This is how it spreads &#8211; once it is on your website, anyone who lands on it gets the new code and the process starts attacking their machine.</p>
<p>I have anti-virus software so I&#8217;m safe right?</p>
<p>Nyet! Most Antivirus software cannot find it because it is more like spyware. Also it hits your machine via php and javascript code and those are functions your web browser uses all the time &#8212; so a firewall is useless to prevent this. Since it hacks an activex helper it hides really well from scanners.</p>
<p>Okay so why do people do this crap? Why me? What do they get out of it?</p>
<p>The hackers make money by retrieving your other credentials (usernames and passwords to banking sites, credit cards etc&#8230;) as well as personal info (your SSN, address, phone numbers, etc) and then it uploads them to a public board in encrypted form that only the original programmers have the decrypt key to. So all your data is uploaded to a public forum and the hackers pull these files daily and decrypt them. Then they:</p>
<ul>
<li>Sell your email address to spammers</li>
<li>Sell your personal info to identity thieves</li>
<li>Sell your credit card details to fraudsters</li>
<li>Share your exploited ftp details with partners who now have write-privilege to install other payloads to your website&#8230;</li>
<li>Then they post teaser code to boards to help other hackers develop better code.</li>
</ul>
<p>As a webmaster you should always keep a close eye on your security &#8212; particularly ftp credentials. FileZilla is one popular ftp client that is taking a big hit because it stores your credentials in unencrypted format. So if you manage 10 websites for clients and use FileZilla for FTP &#8211; you could be at real risk. FilaZilla is an excellent Windows FTP client, but please do not store your passwords in it. (Uncheck the &#8220;Save Password&#8221; box in the FTP profiles and keep a separate encrypted list of site credentials.)</p>
<p>Hope this helps&#8230;</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-shr">
<ul class="socials">
		<li class="shr-100zakladok">
			<a href="http://www.100zakladok.ru/save/?bmurl=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;bmtitle=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to 100 bookmarks">Add this to 100 bookmarks</a>
		</li>
		<li class="shr-bebo">
			<a href="http://www.bebo.com/c/share?Url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;Title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on Bebo">Share this on Bebo</a>
		</li>
		<li class="shr-bitacoras">
			<a href="http://bitacoras.com/anotaciones/http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Submit this to Bitacoras">Submit this to Bitacoras</a>
		</li>
		<li class="shr-blinklist">
			<a href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;Title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on Blinklist">Share this on Blinklist</a>
		</li>
		<li class="shr-blogengage">
			<a href="http://www.blogengage.com/submit.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Engage with this article!">Engage with this article!</a>
		</li>
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;n=FTP+Exploit+-+Back+Door+to+Your+Website&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-blogmarks">
			<a href="http://blogmarks.net/my/new.php?mini=1&amp;simple=1&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Mark this on BlogMarks">Mark this on BlogMarks</a>
		</li>
		<li class="shr-bobrdobr">
			<a href="http://bobrdobr.ru/addext.html?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on BobrDobr">Share this on BobrDobr</a>
		</li>
		<li class="shr-bonzobox">
			<a href="http://bonzobox.com/toolbar/add?pop=1&amp;u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;t=FTP+Exploit+-+Back+Door+to+Your+Website&amp;d=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Add this to BonzoBox">Add this to BonzoBox</a>
		</li>
		<li class="shr-box">
			<a href="https://www.box.net/api/1.0/import?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;name=FTP+Exploit+-+Back+Door+to+Your+Website&amp;description=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20&amp;import_as=link" rel="nofollow" class="external" title="Add this link to Box.net">Add this link to Box.net</a>
		</li>
		<li class="shr-bzzster">
			<a href="javascript:var%20s=document.createElement('script');s.src='http://www.buzzster.com/javascripts/bzz_adv.js';s.type='text/javascript';void(document.getElementsByTagName('head')[0].appendChild(s));" rel="nofollow" title="Share this via Buzzster!">Share this via Buzzster!</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-current">
			<a href="http://current.com/clipper.htm?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Post this to Current">Post this to Current</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-designbump">
			<a href="http://designbump.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;body=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Bump this on DesignBump">Bump this on DesignBump</a>
		</li>
		<li class="shr-designfloat">
			<a href="http://www.designfloat.com/submit.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Submit this to DesignFloat">Submit this to DesignFloat</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;desc=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-dzone">
			<a href="http://www.dzone.com/links/add.html?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;description=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Add this to DZone">Add this to DZone</a>
		</li>
		<li class="shr-ekudos">
			<a href="http://www.ekudos.nl/artikel/nieuw?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;desc=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Submit this to eKudos">Submit this to eKudos</a>
		</li>
		<li class="shr-evernote">
			<a href="http://www.evernote.com/clip.action?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Clip this to Evernote">Clip this to Evernote</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;t=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-faqpal">
			<a href="http://www.faqpal.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Submit this to FAQpal">Submit this to FAQpal</a>
		</li>
		<li class="shr-friendfeed">
			<a href="http://www.friendfeed.com/share?title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;link=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
		<li class="shr-fwisp">
			<a href="http://fwisp.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Share this on Fwisp">Share this on Fwisp</a>
		</li>
		<li class="shr-globalgrind">
			<a href="http://globalgrind.com/submission/submit.aspx?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;type=Article&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Grind this! on Global Grind">Grind this! on Global Grind</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=FTP+Exploit+-+Back+Door+to+Your+Website&amp;body=Link: http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;srcUrl=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;srcTitle=FTP+Exploit+-+Back+Door+to+Your+Website&amp;snippet=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;t=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hatena">
			<a href="http://b.hatena.ne.jp/add?mode=confirm&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Bookmarks this on Hatena Bookmarks">Bookmarks this on Hatena Bookmarks</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=FTP+Exploit+-+Back+Door+to+Your+Website&amp;body=Link: http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-hyves">
			<a href="http://www.hyves.nl/profilemanage/add/tips/?name=FTP+Exploit+-+Back+Door+to+Your+Website&amp;text=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20+-+http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;rating=5" rel="nofollow" class="external" title="Share this on Hyves">Share this on Hyves</a>
		</li>
		<li class="shr-identica">
			<a href="http://identi.ca//index.php?action=newnotice&amp;status_textarea=Reading:+&quot;FTP+Exploit+-+Back+Door+to+Your+Website&quot;+-+from+http://b2l.me/apsue4" rel="nofollow" class="external" title="Post this to Identica">Post this to Identica</a>
		</li>
		<li class="shr-izeby">
			<a href="http://izeby.com/submit.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Add this to Izeby">Add this to Izeby</a>
		</li>
		<li class="shr-jumptags">
			<a href="http://www.jumptags.com/add/?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Submit this link to JumpTags">Submit this link to JumpTags</a>
		</li>
		<li class="shr-kaevur">
			<a href="http://kaevur.com/submit.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Share this on Kaevur">Share this on Kaevur</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;summary=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20&amp;source=Dwayne Coots" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22FTP%20Exploit%20-%20Back%20Door%20to%20Your%20Website%22&amp;body=Link: http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-memoryru">
			<a href="http://memori.ru/link/?sm=1&amp;u_data[url]=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;u_data[name]=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to Memory.ru">Add this to Memory.ru</a>
		</li>
		<li class="shr-meneame">
			<a href="http://meneame.net/submit.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Submit this to Meneame">Submit this to Meneame</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;bm_description=FTP+Exploit+-+Back+Door+to+Your+Website&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-moemesto">
			<a href="http://moemesto.ru/post.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to MyPlace">Add this to MyPlace</a>
		</li>
		<li class="shr-mylinkvault">
			<a href="http://www.mylinkvault.com/link-page.php?u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;n=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Store this link on MyLinkVault">Store this link on MyLinkVault</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;t=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-n4g">
			<a href="http://www.n4g.com/tips.aspx?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Submit tip to N4G">Submit tip to N4G</a>
		</li>
		<li class="shr-netvibes">
			<a href="http://www.netvibes.com/share?title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Submit this to Netvibes">Submit this to Netvibes</a>
		</li>
		<li class="shr-netvouz">
			<a href="http://www.netvouz.com/action/submitBookmark?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;popup=no" rel="nofollow" class="external" title="Submit this to Netvouz">Submit this to Netvouz</a>
		</li>
		<li class="shr-newsvine">
			<a href="http://www.newsvine.com/_tools/seed&amp;save?u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;h=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Seed this on Newsvine">Seed this on Newsvine</a>
		</li>
		<li class="shr-ning">
			<a href="http://bookmarks.ning.com/addItem.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;T=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to Ning">Add this to Ning</a>
		</li>
		<li class="shr-nujij">
			<a href="http://nujij.nl/jij.lynkx?t=FTP+Exploit+-+Back+Door+to+Your+Website&amp;u=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;b=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Submit this to NUjij">Submit this to NUjij</a>
		</li>
		<li class="shr-oknotizie">
			<a href="http://oknotizie.virgilio.it/post?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on OkNotizie">Share this on OkNotizie</a>
		</li>
		<li class="shr-orkut">
			<a href="http://promote.orkut.com/preview?nt=orkut.com&amp;tt=FTP+Exploit+-+Back+Door+to+Your+Website&amp;du=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;cn=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Promote this on Orkut">Promote this on Orkut</a>
		</li>
		<li class="shr-pfbuzz">
			<a href="http://pfbuzz.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on PFBuzz">Share this on PFBuzz</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;body=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.plaxo.com/?share_link=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=FTP+Exploit+-+Back+Door+to+Your+Website+-+http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-posterous">
			<a href="http://posterous.com/share?linkto=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;selection=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Post this to Posterous">Post this to Posterous</a>
		</li>
		<li class="shr-printfriendly">
			<a href="http://www.printfriendly.com/print?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Send this page to Print Friendly">Send this page to Print Friendly</a>
		</li>
		<li class="shr-propeller">
			<a href="http://www.propeller.com/submit/?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Submit this story to Propeller">Submit this story to Propeller</a>
		</li>
		<li class="shr-pusha">
			<a href="http://www.pusha.se/posta?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Push this on Pusha">Push this on Pusha</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-scriptstyle">
			<a href="http://scriptandstyle.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Submit this to Script &amp; Style">Submit this to Script &amp; Style</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-sphinn">
			<a href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Sphinn this on Sphinn">Sphinn this on Sphinn</a>
		</li>
		<li class="shr-springpad">
			<a href="http://springpadit.com/clip.action?body=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;format=microclip&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;isSelected=true" rel="nofollow" class="external" title="Spring this on SpringPad">Spring this on SpringPad</a>
		</li>
		<li class="shr-squidoo">
			<a href="http://www.squidoo.com/lensmaster/bookmark?http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Add to a lense on Squidoo">Add to a lense on Squidoo</a>
		</li>
		<li class="shr-strands">
			<a href="http://www.strands.com/tools/share/webpage?title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Submit this to Strands">Submit this to Strands</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-stumpedia">
			<a href="http://www.stumpedia.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to Stumpedia">Add this to Stumpedia</a>
		</li>
		<li class="shr-techmeme">
			<a href="http://twitter.com/home/?status=Tip+@Techmeme+http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/+&quot;FTP+Exploit+-+Back+Door+to+Your+Website&quot;&amp;source=shareaholic" rel="nofollow" class="external" title="Tip this to TechMeme">Tip this to TechMeme</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-tipd">
			<a href="http://tipd.com/submit.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Share this on Tipd">Share this on Tipd</a>
		</li>
		<li class="shr-tomuse">
			<a href="mailto:tips@tomuse.com?subject=New+tip+submitted+via+the+SexyBookmarks+Plugin%21&amp;body=Link: http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/ %0D%0A%0D%0A Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Suggest this article to ToMuse">Suggest this article to ToMuse</a>
		</li>
		<li class="shr-tumblr">
			<a href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fftp-exploit-back-door-to-your-website%2F&amp;t=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on Tumblr">Share this on Tumblr</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=FTP+Exploit+-+Back+Door+to+Your+Website+-+http://b2l.me/apsue4&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-twittley">
			<a href="http://twittley.com/submit/?title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;url=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fftp-exploit-back-door-to-your-website%2F&amp;desc=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20&amp;pcat=Technology&amp;tags=" rel="nofollow" class="external" title="Submit this to Twittley">Submit this to Twittley</a>
		</li>
		<li class="shr-viadeo">
			<a href="http://www.viadeo.com/shareit/share/?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;urlaffiliate=31138" rel="nofollow" class="external" title="Share this on Viadeo">Share this on Viadeo</a>
		</li>
		<li class="shr-virb">
			<a href="http://virb.com/share?external&amp;v=2&amp;url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Share this on Virb">Share this on Virb</a>
		</li>
		<li class="shr-webblend">
			<a href="http://thewebblend.com/submit?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website&amp;body=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Blend this!">Blend this!</a>
		</li>
		<li class="shr-wykop">
			<a href="http://www.wykop.pl/dodaj?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to Wykop!">Add this to Wykop!</a>
		</li>
		<li class="shr-xerpi">
			<a href="http://www.xerpi.com/block/add_link_from_extension?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;title=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Save this to Xerpi">Save this to Xerpi</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;submitHeadline=FTP+Exploit+-+Back+Door+to+Your+Website&amp;submitSummary=Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=FTP+Exploit+-+Back+Door+to+Your+Website&amp;body=Link: http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Recently%20a%20client%20reported%20the%20heder.php%20exploit%20had%20infected%20their%20website.%20They%20needed%20help%20with%20the%20cleanup%2C%20so%20we%20got%20them%20back%20online%2C%20but%20they%20had%20questions%20like%2C%20%22How%20did%20these%20files%20get%20onto%20my%20site%3F%22%0D%0A%0D%0AFirst%20understand%20that%20heder.php%20is%20just%20one%20type%20of%20site%20trojan.%20There%20are%20many%20flavors%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
		<li class="shr-yandex">
			<a href="http://zakladki.yandex.ru/userarea/links/addfromfav.asp?bAddLink_x=1&amp;lurl=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/&amp;lname=FTP+Exploit+-+Back+Door+to+Your+Website" rel="nofollow" class="external" title="Add this to Yandex.Bookmarks">Add this to Yandex.Bookmarks</a>
		</li>
		<li class="shr-zabox">
			<a href="http://www.zabox.net/submit.php?url=http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/" rel="nofollow" class="external" title="Box this on Zabox">Box this on Zabox</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://dwaynecoots.com/tech/ftp-exploit-back-door-to-your-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Site Hacked? What its All a Bot</title>
		<link>http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/</link>
		<comments>http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/#comments</comments>
		<pubDate>Sat, 23 Aug 2008 12:24:20 +0000</pubDate>
		<dc:creator>Dwayne</dc:creator>
				<category><![CDATA[Tech Channel]]></category>
		<category><![CDATA[Website Design Tips]]></category>
		<category><![CDATA[malware prevention]]></category>
		<category><![CDATA[referrer spam]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server stats]]></category>

		<guid isPermaLink="false">http://dwaynecoots.com/?p=10</guid>
		<description><![CDATA[A client recently reported some strange entries in their website statistics referrer logs. The entry was from a bot probe by a nasty outfit that is up to all sorts of evil malware stuff. The issue did raise a good questions about the security of sites and what even novice webmasters can and should do [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fsite-hacked-what-its-all-a-bot%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fsite-hacked-what-its-all-a-bot%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>A client recently reported some strange entries in their website statistics referrer logs. The entry was from a bot probe by a nasty outfit that is up to all sorts of evil malware stuff. The issue did raise a good questions about the security of sites and what even novice webmasters can and should do to protect themselves from site compromise.</p>
<p>Bot probes from a slimy outfits are common. Properly secured systems will block offending IPs but the attacking bots switch IPs all the time. This form of vulnerability probe or referrer spam is very common &#8212; just like email spam. We do everything we can to prevent it but that does not stop the evil bastards from trying&#8230; all the time.</p>
<p>This is why it is so important to have a strong password and to change it every few months. You should also look around in your site file structure frequently for things that don&#8217;t belong &#8212; like .c files or .exe files or even php files that you did not install. I recommend you check your site once a week for this kind of activity.</p>
<p>Remember, no matter how secure our servers are, your website is an open door to the world and malware developers have a powerful monetary interest in gaining control of your server resources to make money. The days of malicious teenagers gleefully scrambling your home page and laughing through a mouth full of hot pockets is long gone. Hacking websites to install malware is serious (and big) business.</p>
<p>So it&#8217;s also up to you as a webmaster to make sure you don&#8217;t let these demons in the door.</p>
<p>By the way. Take care which backlinks you click on while scanning your stats reports. That is one way referrer spam works. The malware developer creates an attack routine and embeds it in a web page. Then they deploy botnets to spider websites constantly &#8212; leaving nice little fake &#8216;visitor&#8217; entries in the log files and stats. Then if you click on the link to see who visited you the malware site hits your machine with a payload. Even though you may have a great antivirus / antimalware program, pages can be constructed in ways to overwhelm your computers resources and tie up your system as the payload is being installed.</p>
<p>It&#8217;s a jungle. And your website is part of the food chain.</p>
<p>As always we&#8217;re, <a title="At Your Servers Web Hosting" href="http://atyourservers.net/" target="_blank">At Your Servers</a></p>
<p>Dwayne</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-shr">
<ul class="socials">
		<li class="shr-100zakladok">
			<a href="http://www.100zakladok.ru/save/?bmurl=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;bmtitle=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to 100 bookmarks">Add this to 100 bookmarks</a>
		</li>
		<li class="shr-bebo">
			<a href="http://www.bebo.com/c/share?Url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;Title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on Bebo">Share this on Bebo</a>
		</li>
		<li class="shr-bitacoras">
			<a href="http://bitacoras.com/anotaciones/http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Submit this to Bitacoras">Submit this to Bitacoras</a>
		</li>
		<li class="shr-blinklist">
			<a href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;Title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on Blinklist">Share this on Blinklist</a>
		</li>
		<li class="shr-blogengage">
			<a href="http://www.blogengage.com/submit.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Engage with this article!">Engage with this article!</a>
		</li>
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;n=Site+Hacked%3F+What+its+All+a+Bot&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-blogmarks">
			<a href="http://blogmarks.net/my/new.php?mini=1&amp;simple=1&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Mark this on BlogMarks">Mark this on BlogMarks</a>
		</li>
		<li class="shr-bobrdobr">
			<a href="http://bobrdobr.ru/addext.html?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on BobrDobr">Share this on BobrDobr</a>
		</li>
		<li class="shr-bonzobox">
			<a href="http://bonzobox.com/toolbar/add?pop=1&amp;u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;t=Site+Hacked%3F+What+its+All+a+Bot&amp;d=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Add this to BonzoBox">Add this to BonzoBox</a>
		</li>
		<li class="shr-box">
			<a href="https://www.box.net/api/1.0/import?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;name=Site+Hacked%3F+What+its+All+a+Bot&amp;description=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d&amp;import_as=link" rel="nofollow" class="external" title="Add this link to Box.net">Add this link to Box.net</a>
		</li>
		<li class="shr-bzzster">
			<a href="javascript:var%20s=document.createElement('script');s.src='http://www.buzzster.com/javascripts/bzz_adv.js';s.type='text/javascript';void(document.getElementsByTagName('head')[0].appendChild(s));" rel="nofollow" title="Share this via Buzzster!">Share this via Buzzster!</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-current">
			<a href="http://current.com/clipper.htm?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Post this to Current">Post this to Current</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-designbump">
			<a href="http://designbump.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;body=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Bump this on DesignBump">Bump this on DesignBump</a>
		</li>
		<li class="shr-designfloat">
			<a href="http://www.designfloat.com/submit.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Submit this to DesignFloat">Submit this to DesignFloat</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;desc=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-dzone">
			<a href="http://www.dzone.com/links/add.html?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;description=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Add this to DZone">Add this to DZone</a>
		</li>
		<li class="shr-ekudos">
			<a href="http://www.ekudos.nl/artikel/nieuw?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;desc=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Submit this to eKudos">Submit this to eKudos</a>
		</li>
		<li class="shr-evernote">
			<a href="http://www.evernote.com/clip.action?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Clip this to Evernote">Clip this to Evernote</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;t=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-faqpal">
			<a href="http://www.faqpal.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Submit this to FAQpal">Submit this to FAQpal</a>
		</li>
		<li class="shr-friendfeed">
			<a href="http://www.friendfeed.com/share?title=Site+Hacked%3F+What+its+All+a+Bot&amp;link=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
		<li class="shr-fwisp">
			<a href="http://fwisp.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Share this on Fwisp">Share this on Fwisp</a>
		</li>
		<li class="shr-globalgrind">
			<a href="http://globalgrind.com/submission/submit.aspx?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;type=Article&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Grind this! on Global Grind">Grind this! on Global Grind</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Site+Hacked%3F+What+its+All+a+Bot&amp;body=Link: http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;srcUrl=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;srcTitle=Site+Hacked%3F+What+its+All+a+Bot&amp;snippet=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;t=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hatena">
			<a href="http://b.hatena.ne.jp/add?mode=confirm&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Bookmarks this on Hatena Bookmarks">Bookmarks this on Hatena Bookmarks</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Site+Hacked%3F+What+its+All+a+Bot&amp;body=Link: http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-hyves">
			<a href="http://www.hyves.nl/profilemanage/add/tips/?name=Site+Hacked%3F+What+its+All+a+Bot&amp;text=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d+-+http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;rating=5" rel="nofollow" class="external" title="Share this on Hyves">Share this on Hyves</a>
		</li>
		<li class="shr-identica">
			<a href="http://identi.ca//index.php?action=newnotice&amp;status_textarea=Reading:+&quot;Site+Hacked%3F+What+its+All+a+Bot&quot;+-+from+http://b2l.me/apszfd" rel="nofollow" class="external" title="Post this to Identica">Post this to Identica</a>
		</li>
		<li class="shr-izeby">
			<a href="http://izeby.com/submit.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Add this to Izeby">Add this to Izeby</a>
		</li>
		<li class="shr-jumptags">
			<a href="http://www.jumptags.com/add/?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Submit this link to JumpTags">Submit this link to JumpTags</a>
		</li>
		<li class="shr-kaevur">
			<a href="http://kaevur.com/submit.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Share this on Kaevur">Share this on Kaevur</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;summary=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d&amp;source=Dwayne Coots" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Site%20Hacked%3F%20What%20its%20All%20a%20Bot%22&amp;body=Link: http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-memoryru">
			<a href="http://memori.ru/link/?sm=1&amp;u_data[url]=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;u_data[name]=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to Memory.ru">Add this to Memory.ru</a>
		</li>
		<li class="shr-meneame">
			<a href="http://meneame.net/submit.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Submit this to Meneame">Submit this to Meneame</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;bm_description=Site+Hacked%3F+What+its+All+a+Bot&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-moemesto">
			<a href="http://moemesto.ru/post.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to MyPlace">Add this to MyPlace</a>
		</li>
		<li class="shr-mylinkvault">
			<a href="http://www.mylinkvault.com/link-page.php?u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;n=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Store this link on MyLinkVault">Store this link on MyLinkVault</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;t=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-n4g">
			<a href="http://www.n4g.com/tips.aspx?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Submit tip to N4G">Submit tip to N4G</a>
		</li>
		<li class="shr-netvibes">
			<a href="http://www.netvibes.com/share?title=Site+Hacked%3F+What+its+All+a+Bot&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Submit this to Netvibes">Submit this to Netvibes</a>
		</li>
		<li class="shr-netvouz">
			<a href="http://www.netvouz.com/action/submitBookmark?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;popup=no" rel="nofollow" class="external" title="Submit this to Netvouz">Submit this to Netvouz</a>
		</li>
		<li class="shr-newsvine">
			<a href="http://www.newsvine.com/_tools/seed&amp;save?u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;h=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Seed this on Newsvine">Seed this on Newsvine</a>
		</li>
		<li class="shr-ning">
			<a href="http://bookmarks.ning.com/addItem.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;T=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to Ning">Add this to Ning</a>
		</li>
		<li class="shr-nujij">
			<a href="http://nujij.nl/jij.lynkx?t=Site+Hacked%3F+What+its+All+a+Bot&amp;u=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;b=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Submit this to NUjij">Submit this to NUjij</a>
		</li>
		<li class="shr-oknotizie">
			<a href="http://oknotizie.virgilio.it/post?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on OkNotizie">Share this on OkNotizie</a>
		</li>
		<li class="shr-orkut">
			<a href="http://promote.orkut.com/preview?nt=orkut.com&amp;tt=Site+Hacked%3F+What+its+All+a+Bot&amp;du=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;cn=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Promote this on Orkut">Promote this on Orkut</a>
		</li>
		<li class="shr-pfbuzz">
			<a href="http://pfbuzz.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on PFBuzz">Share this on PFBuzz</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;body=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.plaxo.com/?share_link=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Site+Hacked%3F+What+its+All+a+Bot+-+http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-posterous">
			<a href="http://posterous.com/share?linkto=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;selection=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Post this to Posterous">Post this to Posterous</a>
		</li>
		<li class="shr-printfriendly">
			<a href="http://www.printfriendly.com/print?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Send this page to Print Friendly">Send this page to Print Friendly</a>
		</li>
		<li class="shr-propeller">
			<a href="http://www.propeller.com/submit/?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Submit this story to Propeller">Submit this story to Propeller</a>
		</li>
		<li class="shr-pusha">
			<a href="http://www.pusha.se/posta?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Push this on Pusha">Push this on Pusha</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-scriptstyle">
			<a href="http://scriptandstyle.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Submit this to Script &amp; Style">Submit this to Script &amp; Style</a>
		</li>
		<li class="shr-slashdot">
			<a href="http://slashdot.org/bookmark.pl?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Submit this to SlashDot">Submit this to SlashDot</a>
		</li>
		<li class="shr-sphinn">
			<a href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Sphinn this on Sphinn">Sphinn this on Sphinn</a>
		</li>
		<li class="shr-springpad">
			<a href="http://springpadit.com/clip.action?body=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;format=microclip&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;isSelected=true" rel="nofollow" class="external" title="Spring this on SpringPad">Spring this on SpringPad</a>
		</li>
		<li class="shr-squidoo">
			<a href="http://www.squidoo.com/lensmaster/bookmark?http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Add to a lense on Squidoo">Add to a lense on Squidoo</a>
		</li>
		<li class="shr-strands">
			<a href="http://www.strands.com/tools/share/webpage?title=Site+Hacked%3F+What+its+All+a+Bot&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Submit this to Strands">Submit this to Strands</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-stumpedia">
			<a href="http://www.stumpedia.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to Stumpedia">Add this to Stumpedia</a>
		</li>
		<li class="shr-techmeme">
			<a href="http://twitter.com/home/?status=Tip+@Techmeme+http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/+&quot;Site+Hacked%3F+What+its+All+a+Bot&quot;&amp;source=shareaholic" rel="nofollow" class="external" title="Tip this to TechMeme">Tip this to TechMeme</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-tipd">
			<a href="http://tipd.com/submit.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Share this on Tipd">Share this on Tipd</a>
		</li>
		<li class="shr-tomuse">
			<a href="mailto:tips@tomuse.com?subject=New+tip+submitted+via+the+SexyBookmarks+Plugin%21&amp;body=Link: http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/ %0D%0A%0D%0A A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Suggest this article to ToMuse">Suggest this article to ToMuse</a>
		</li>
		<li class="shr-tumblr">
			<a href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fsite-hacked-what-its-all-a-bot%2F&amp;t=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on Tumblr">Share this on Tumblr</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Site+Hacked%3F+What+its+All+a+Bot+-+http://b2l.me/apszfd&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-twittley">
			<a href="http://twittley.com/submit/?title=Site+Hacked%3F+What+its+All+a+Bot&amp;url=http%3A%2F%2Fdwaynecoots.com%2Ftech%2Fsite-hacked-what-its-all-a-bot%2F&amp;desc=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d&amp;pcat=Technology&amp;tags=" rel="nofollow" class="external" title="Submit this to Twittley">Submit this to Twittley</a>
		</li>
		<li class="shr-viadeo">
			<a href="http://www.viadeo.com/shareit/share/?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;urlaffiliate=31138" rel="nofollow" class="external" title="Share this on Viadeo">Share this on Viadeo</a>
		</li>
		<li class="shr-virb">
			<a href="http://virb.com/share?external&amp;v=2&amp;url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Share this on Virb">Share this on Virb</a>
		</li>
		<li class="shr-webblend">
			<a href="http://thewebblend.com/submit?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot&amp;body=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Blend this!">Blend this!</a>
		</li>
		<li class="shr-wykop">
			<a href="http://www.wykop.pl/dodaj?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to Wykop!">Add this to Wykop!</a>
		</li>
		<li class="shr-xerpi">
			<a href="http://www.xerpi.com/block/add_link_from_extension?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;title=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Save this to Xerpi">Save this to Xerpi</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;submitHeadline=Site+Hacked%3F+What+its+All+a+Bot&amp;submitSummary=A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Site+Hacked%3F+What+its+All+a+Bot&amp;body=Link: http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20client%20recently%20reported%20some%20strange%20entries%20in%20their%20website%20statistics%20referrer%20logs.%20The%20entry%20was%20from%20a%20bot%20probe%20by%20a%20nasty%20outfit%20that%20is%20up%20to%20all%20sorts%20of%20evil%20malware%20stuff.%20The%20issue%20did%20raise%20a%20good%20questions%20about%20the%20security%20of%20sites%20and%20what%20even%20novice%20webmasters%20can%20and%20should%20d" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
		<li class="shr-yandex">
			<a href="http://zakladki.yandex.ru/userarea/links/addfromfav.asp?bAddLink_x=1&amp;lurl=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/&amp;lname=Site+Hacked%3F+What+its+All+a+Bot" rel="nofollow" class="external" title="Add this to Yandex.Bookmarks">Add this to Yandex.Bookmarks</a>
		</li>
		<li class="shr-zabox">
			<a href="http://www.zabox.net/submit.php?url=http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/" rel="nofollow" class="external" title="Box this on Zabox">Box this on Zabox</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://dwaynecoots.com/tech/site-hacked-what-its-all-a-bot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
