<?xml version="1.0"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>Weblogtoolscollection News Topic: Hacker attack has broken thousands of WordPress blogs</title>
<link>http://weblogtoolscollection.com/news/</link>
<description>Weblogtoolscollection News Topic: Hacker attack has broken thousands of WordPress blogs</description>
<language>en</language>
<pubDate>Wed, 19 Jun 2013 12:05:07 +0000</pubDate>

<item>
<title>UseShots on "Hacker attack has broken thousands of WordPress blogs"</title>
<link>http://weblogtoolscollection.com/news/topic/hacker-attack-has-broken-thousands-of-wordpress-blogs#post-5726</link>
<pubDate>Fri, 06 Nov 2009 14:45:47 +0000</pubDate>
<dc:creator>UseShots</dc:creator>
<guid isPermaLink="false">5726@http://weblogtoolscollection.com/news/</guid>
<description>&#60;p&#62;Malware attack, known as Gumblar, targets PHP driven websites. It injects a backdoor script into various .php files on compromised sites.&#60;/p&#62;
&#60;p&#62;A bug in the backdoor script effectively breaks WordPress blogs that start to report the following error for every requested page (including admin interface)&#60;/p&#62;
&#60;p&#62;&#60;code&#62;&#60;strong&#62;Fatal error:&#60;/strong&#62; Cannot redeclare xfm() (previously declared in /path/to/site/index.php(1) : eval()'d code:1)&#60;br /&#62;
in &#60;strong&#62;/path/to/site/wp-config.php(1) : eval()'d code&#60;/strong&#62; on line 1&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;The name of the reported function changes from site to site but stays meaningless.&#60;/p&#62;
&#60;p&#62;The scope of the problem can be revealed by the following Google search that currently returns &#60;strong&#62;62,000&#60;/strong&#62; results: &#60;a href=&#34;http://www.google.com/search?hl=en&#38;#38;q=%22previously+declared+in%22+%22wp-config.php%22+eval+code+%22on+line+1%22&#34; rel=&#34;nofollow&#34;&#62;http://www.google.com/search?hl=en&#38;#38;q=%22previously+declared+in%22+%22wp-config.php%22+eval+code+%22on+line+1%22&#60;/a&#62;&#60;br /&#62;
Most results point to either compromised WordPress blogs or to posts about compromised WordPress blogs.&#60;/p&#62;
&#60;p&#62;More details and clean up instructions can be found here:&#60;br /&#62;
&#60;a href=&#34;http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/&#34; rel=&#34;nofollow&#34;&#62;http://blog.unmaskparasites.com/2009/11/04/gumblar-breaks-wordpress-blogs-and-other-complex-php-sites/&#60;/a&#62;
&#60;/p&#62;</description>
</item>

</channel>
</rss>