<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: osCommerce v2.2 Website Infections</title>
	<atom:link href="http://wewatchyourwebsite.com/wordpress/2010/07/oscommerce-v2-2-website-infections/feed/" rel="self" type="application/rss+xml" />
	<link>http://wewatchyourwebsite.com/wordpress/2010/07/oscommerce-v2-2-website-infections/</link>
	<description>Website Security</description>
	<lastBuildDate>Mon, 16 Apr 2012 17:46:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: admin</title>
		<link>http://wewatchyourwebsite.com/wordpress/2010/07/oscommerce-v2-2-website-infections/#comment-86</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Mon, 30 Aug 2010 14:19:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=372#comment-86</guid>
		<description>If you wouldn&#039;t mind, for the benefit of our readers, what specifically do you look for in your raw server logs?

And should our readers look for these raw server logs?

Are you on a shared server?

Please provide details, if you would.</description>
		<content:encoded><![CDATA[<p>If you wouldn&#8217;t mind, for the benefit of our readers, what specifically do you look for in your raw server logs?</p>
<p>And should our readers look for these raw server logs?</p>
<p>Are you on a shared server?</p>
<p>Please provide details, if you would.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mommaroodles</title>
		<link>http://wewatchyourwebsite.com/wordpress/2010/07/oscommerce-v2-2-website-infections/#comment-83</link>
		<dc:creator>mommaroodles</dc:creator>
		<pubDate>Sat, 28 Aug 2010 20:55:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=372#comment-83</guid>
		<description>You could just remove the file_manger and related code from the site - its not all that necessary anyway and no one used it to edit files anyway - well not to my knowledge.

There is also .htaccess file which can be used - I find banning entire countries also quite effective, reading your raw server log files tell you a lot. I try to ready them at least once a week,  preferably every 2 days or so.</description>
		<content:encoded><![CDATA[<p>You could just remove the file_manger and related code from the site &#8211; its not all that necessary anyway and no one used it to edit files anyway &#8211; well not to my knowledge.</p>
<p>There is also .htaccess file which can be used &#8211; I find banning entire countries also quite effective, reading your raw server log files tell you a lot. I try to ready them at least once a week,  preferably every 2 days or so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://wewatchyourwebsite.com/wordpress/2010/07/oscommerce-v2-2-website-infections/#comment-63</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 06 Jul 2010 16:21:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=372#comment-63</guid>
		<description>Thank you. Sometimes the inconvenience of double login, can pay for itself in added security. Nice tip.</description>
		<content:encoded><![CDATA[<p>Thank you. Sometimes the inconvenience of double login, can pay for itself in added security. Nice tip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andras Virag</title>
		<link>http://wewatchyourwebsite.com/wordpress/2010/07/oscommerce-v2-2-website-infections/#comment-62</link>
		<dc:creator>Andras Virag</dc:creator>
		<pubDate>Tue, 06 Jul 2010 14:31:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=372#comment-62</guid>
		<description>For the file disclosure vulnerability you can secure the admin folder with htpasswd. It works. Yeah, double login, but at least it&#039;s a workaround.
Other than that it&#039;s a good find I wasn&#039;t aware myself. Thank you!</description>
		<content:encoded><![CDATA[<p>For the file disclosure vulnerability you can secure the admin folder with htpasswd. It works. Yeah, double login, but at least it&#8217;s a workaround.<br />
Other than that it&#8217;s a good find I wasn&#8217;t aware myself. Thank you!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

