<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Texas Rainmaker site has been hacked</title>
	<atom:link href="http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/</link>
	<description>Don&#039;t dis or dismiss this miss!</description>
	<lastBuildDate>Sun, 22 Nov 2009 02:23:12 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Phil</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596687</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Wed, 22 Nov 2006 07:05:59 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596687</guid>
		<description>Hi ST

Would you mind removing the comment by the link below.
http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596683

Thanks ST</description>
		<content:encoded><![CDATA[<p>Hi ST</p>
<p>Would you mind removing the comment by the link below.<br />
<a href="http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596683" rel="nofollow">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596683</a></p>
<p>Thanks ST</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596684</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Wed, 22 Nov 2006 07:03:39 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596684</guid>
		<description>Jason, Yes I would say what they did was childs play compared to professional hackers, I know all about the chmod command. It&#039;s a unix version of DOS&#039;s old ATTRIB command. In DOS the command to do that would have been ATTRIB +R wp-config.php which sets the file to read only and does not allow it to be written to, in unix there are combinations where like you said can be allowed to be written to by system administrators but not by users.

Anyone with a third grade level knowledge of how system files are set could have done that.</description>
		<content:encoded><![CDATA[<p>Jason, Yes I would say what they did was childs play compared to professional hackers, I know all about the chmod command. It&#8217;s a unix version of DOS&#8217;s old ATTRIB command. In DOS the command to do that would have been ATTRIB +R wp-config.php which sets the file to read only and does not allow it to be written to, in unix there are combinations where like you said can be allowed to be written to by system administrators but not by users.</p>
<p>Anyone with a third grade level knowledge of how system files are set could have done that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596683</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Wed, 22 Nov 2006 07:03:17 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596683</guid>
		<description>Jason, Yes I would say what they did was childs play compared to professional hackers, I know all about the chmod command. It&#039;s a unix version of DOS&#039;s old ATTRIB command. In DOS the command to do that would have been ATTRIB +R wp-config.php which sets the file to read only and does not allow it to be written to, in unix there are combinations where like you said can be allowed to be written to by system administrators but not by users.

Anyone with a thrird grade level knowledge of how system files are set could have done that.</description>
		<content:encoded><![CDATA[<p>Jason, Yes I would say what they did was childs play compared to professional hackers, I know all about the chmod command. It&#8217;s a unix version of DOS&#8217;s old ATTRIB command. In DOS the command to do that would have been ATTRIB +R wp-config.php which sets the file to read only and does not allow it to be written to, in unix there are combinations where like you said can be allowed to be written to by system administrators but not by users.</p>
<p>Anyone with a thrird grade level knowledge of how system files are set could have done that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TexasRainmaker</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596574</link>
		<dc:creator>TexasRainmaker</dc:creator>
		<pubDate>Wed, 22 Nov 2006 03:02:42 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596574</guid>
		<description>Thanks, ST, for posting the warning.  The site is back up (with my response to those who did it).  It was very amateur and unfortunately, very preventable.

For those using Wordpress, here&#039;s the issue (and the fix):  It appears that my wp-config.php file was overwritten the script hackers.  It appears that the permissions set on the wp-config.php file were set to &quot;chmod 666&quot;, which makes that file writeable.  PHP files should be set to &quot;chmod 644&quot; so that they are not writeable by the public.

Again, thanks for posting the warning as I couldn&#039;t reach out to visitors while the site was down.

Well, it&#039;s back up and clean as a whistle.</description>
		<content:encoded><![CDATA[<p>Thanks, ST, for posting the warning.  The site is back up (with my response to those who did it).  It was very amateur and unfortunately, very preventable.</p>
<p>For those using Wordpress, here&#8217;s the issue (and the fix):  It appears that my wp-config.php file was overwritten the script hackers.  It appears that the permissions set on the wp-config.php file were set to &#8220;chmod 666&#8243;, which makes that file writeable.  PHP files should be set to &#8220;chmod 644&#8243; so that they are not writeable by the public.</p>
<p>Again, thanks for posting the warning as I couldn&#8217;t reach out to visitors while the site was down.</p>
<p>Well, it&#8217;s back up and clean as a whistle.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596539</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Wed, 22 Nov 2006 01:05:36 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596539</guid>
		<description>Hey ST that is good news that Jason&#039;s site is back up and running. It probably wasn&#039;t too bad, you know you and the other bloggers should always keep your information backed up on your own hard drives in case of a situation like that so that you can restore it easily.</description>
		<content:encoded><![CDATA[<p>Hey ST that is good news that Jason&#8217;s site is back up and running. It probably wasn&#8217;t too bad, you know you and the other bloggers should always keep your information backed up on your own hard drives in case of a situation like that so that you can restore it easily.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sister Toldjah</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596477</link>
		<dc:creator>Sister Toldjah</dc:creator>
		<pubDate>Tue, 21 Nov 2006 22:58:48 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596477</guid>
		<description>No worries, Phil - I&#039;m steering clear.</description>
		<content:encoded><![CDATA[<p>No worries, Phil &#8211; I&#8217;m steering clear.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Night Rider</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596430</link>
		<dc:creator>Night Rider</dc:creator>
		<pubDate>Tue, 21 Nov 2006 21:57:35 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596430</guid>
		<description>ST

Just be careful and warn as many as possible not to go to his site until he has given you the go ahead.</description>
		<content:encoded><![CDATA[<p>ST</p>
<p>Just be careful and warn as many as possible not to go to his site until he has given you the go ahead.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596423</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Tue, 21 Nov 2006 21:41:18 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596423</guid>
		<description>ST, Stix is basically correct, meaning that if it&#039;s an older virus, the Anti-Virus program might catch it, how ever if it&#039;s a fresh newly written virus, the Anti-Virus program will not stop it, in which case those who Write Anti-Virus programs will have to see the strain of that virus first in order to combat that virus, to write code to destroy it or keep it from launching it&#039;s nastyness on everyone else.

Still best bet is not to go near his site and let him deal with it, he will write you I&#039;m sure when he gets it fixed.</description>
		<content:encoded><![CDATA[<p>ST, Stix is basically correct, meaning that if it&#8217;s an older virus, the Anti-Virus program might catch it, how ever if it&#8217;s a fresh newly written virus, the Anti-Virus program will not stop it, in which case those who Write Anti-Virus programs will have to see the strain of that virus first in order to combat that virus, to write code to destroy it or keep it from launching it&#8217;s nastyness on everyone else.</p>
<p>Still best bet is not to go near his site and let him deal with it, he will write you I&#8217;m sure when he gets it fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sister Toldjah</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596422</link>
		<dc:creator>Sister Toldjah</dc:creator>
		<pubDate>Tue, 21 Nov 2006 21:37:06 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596422</guid>
		<description>Thanks for the info, guys.</description>
		<content:encoded><![CDATA[<p>Thanks for the info, guys.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596419</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Tue, 21 Nov 2006 21:32:44 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596419</guid>
		<description>ST, how that works is that when you load a page into ram, then that is where the virus can litterally be written to right either a hard file to the hard drive or a litteral file to the hard drive.  A hard file is one that is encoded directly to the hard drive but doesn&#039;t show up as a file.  It is all in code like what the ( FAT ) table looks like.  The FAT stands for File Allocation Table which is a code on your hard drive. That takes a lot of brillant coding to do that, and the other is the litteral file which looks just like any other kind of file but may be set with the hidden and system attributes so that you wouldn&#039;t see it. Sort of how the MSDOS.SYS and the other file systems files that do not appear. To a normal directory listing.  A litteral file writing to the hard drive doesn&#039;t require as much brilliants to do that, but can be just as severe.

Multitude of Viruses can be either triggered to do severe damage to the hard ware of the system, ie.. Like the one back in the early 90&#039;s that was called the Disk-killer which litterally dragged the hard drive heads accross the platters of the hard drive to nothing more than a hinderance or nusience.

Most of the time viruses can be delivered by going to a site because your system first puts all contents of that site into &quot;RAM&quot; and from there it can do what it was programed to do.  I had a friend of mine who had a older computer system he used to run viruses on just to see what it did to the computer.  So I had learned a lot about how viruses can effect a computer from him.  Most anoyance type virsues can do what is called multiply, meaning that either you will get coppies of that viruse file all over your hard drive or it can be programmed to be sent out to all your friends via email by watching for outgoing mime/smtp transmisions and it will attach itself by encoding directly in your email message to all the ones in your mail box.

The word embeded all that means is that the raw code of the virus is embeded in the code of the site, for example, take and view a email in it&#039;s raw format with either notepad or another text editor and you will see all kinds of strings of code in there and that is called mime encoding, now there is encoding in HTML XML and all the rest of the basic HTML format.

Also the embeding of the code of the virus does not have to follow with the code of the HTML for example it can be not in order, you might find the end of it towards the beginning of the HTML and the end of it some where in the middle.

Trust me better not go to the site to be safe.</description>
		<content:encoded><![CDATA[<p>ST, how that works is that when you load a page into ram, then that is where the virus can litterally be written to right either a hard file to the hard drive or a litteral file to the hard drive.  A hard file is one that is encoded directly to the hard drive but doesn&#8217;t show up as a file.  It is all in code like what the ( FAT ) table looks like.  The FAT stands for File Allocation Table which is a code on your hard drive. That takes a lot of brillant coding to do that, and the other is the litteral file which looks just like any other kind of file but may be set with the hidden and system attributes so that you wouldn&#8217;t see it. Sort of how the MSDOS.SYS and the other file systems files that do not appear. To a normal directory listing.  A litteral file writing to the hard drive doesn&#8217;t require as much brilliants to do that, but can be just as severe.</p>
<p>Multitude of Viruses can be either triggered to do severe damage to the hard ware of the system, ie.. Like the one back in the early 90&#8217;s that was called the Disk-killer which litterally dragged the hard drive heads accross the platters of the hard drive to nothing more than a hinderance or nusience.</p>
<p>Most of the time viruses can be delivered by going to a site because your system first puts all contents of that site into &#8220;RAM&#8221; and from there it can do what it was programed to do.  I had a friend of mine who had a older computer system he used to run viruses on just to see what it did to the computer.  So I had learned a lot about how viruses can effect a computer from him.  Most anoyance type virsues can do what is called multiply, meaning that either you will get coppies of that viruse file all over your hard drive or it can be programmed to be sent out to all your friends via email by watching for outgoing mime/smtp transmisions and it will attach itself by encoding directly in your email message to all the ones in your mail box.</p>
<p>The word embeded all that means is that the raw code of the virus is embeded in the code of the site, for example, take and view a email in it&#8217;s raw format with either notepad or another text editor and you will see all kinds of strings of code in there and that is called mime encoding, now there is encoding in HTML XML and all the rest of the basic HTML format.</p>
<p>Also the embeding of the code of the virus does not have to follow with the code of the HTML for example it can be not in order, you might find the end of it towards the beginning of the HTML and the end of it some where in the middle.</p>
<p>Trust me better not go to the site to be safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stix</title>
		<link>http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/comment-page-1/#comment-596407</link>
		<dc:creator>Stix</dc:creator>
		<pubDate>Tue, 21 Nov 2006 21:07:31 +0000</pubDate>
		<guid isPermaLink="false">http://sistertoldjah.com/archives/2006/11/21/the-texas-rainmaker-site-has-been-hacked/#comment-596407</guid>
		<description>It is embedded in the code on the web site.  And when someone visits it it downlaods it automatically to the visiting computer.  If you have a good anti-virus and firewall, it should catch it and not really do harm.  I would run a virus scan with your anti-virus just to be on the safe side.</description>
		<content:encoded><![CDATA[<p>It is embedded in the code on the web site.  And when someone visits it it downlaods it automatically to the visiting computer.  If you have a good anti-virus and firewall, it should catch it and not really do harm.  I would run a virus scan with your anti-virus just to be on the safe side.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
