<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feed.xaviermedia.com/~d/styles/atom10full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feed.xaviermedia.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" xml:lang="en" xml:base="http://antivirus.xaviermedia.com/wp-atom.php">
	<title type="text">The Antivirus blog</title>
	<subtitle type="text">How to protect yourself from viruses, malware and scumware</subtitle>

	<updated>2008-05-11T14:24:30Z</updated>
	<generator uri="http://wordpress.org/" version="2.5.1">WordPress</generator>

	<link rel="alternate" type="text/html" href="http://antivirus.xaviermedia.com" />
	<id>http://antivirus.xaviermedia.com/feed/atom/</id>
	

			<link rel="self" href="http://feed.xaviermedia.com/AntivirusBlog" type="application/atom+xml" /><feedburner:emailServiceId>1788243</feedburner:emailServiceId><feedburner:feedburnerHostname>http://www.feedburner.com</feedburner:feedburnerHostname><entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[More SQL injections]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/288078741/" />
		<id>http://antivirus.xaviermedia.com/?p=13</id>
		<updated>2008-05-11T14:24:30Z</updated>
		<published>2008-05-11T14:24:30Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="SQL" /><category scheme="http://antivirus.xaviermedia.com" term="phpBB" />		<summary type="html"><![CDATA[The sites effected by the last SQL injection wave haven&#8217;t recovered until it&#8217;s time for the next attack of SQL injections  
Once again it looks like it&#8217;s older version of phpbb that got injected by JS_SMALL.QT (discovered by Advanced Threats Research Program Manager Ivan Macalintal). Unfortunately if you&#8217;re going to use phpBB you have [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/05/11/more-sql-injections/">&lt;p&gt;The sites effected by &lt;a rel="nofollow" href="http://blog.trendmicro.com/a-very-convoluted-chinese-gaming-info-stealing-campaign/" target="_blank"&gt;the last SQL injection wave&lt;/a&gt; haven&amp;#8217;t recovered until it&amp;#8217;s time for the next attack of SQL injections &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /&gt; &lt;/p&gt;
&lt;p&gt;Once again it looks like it&amp;#8217;s older version of phpbb that got injected by &lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS_SMALL.QT"&gt;JS_SMALL.QT&lt;/a&gt; (discovered by Advanced Threats Research Program Manager &lt;em&gt;&lt;strong&gt;Ivan Macalintal&lt;/strong&gt;&lt;/em&gt;). Unfortunately if you&amp;#8217;re going to use phpBB you have to make sure you upgrade after they&amp;#8217;ve released yet another security fix (which they tend to to often sometimes &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /&gt; ).&lt;/p&gt;
&lt;p&gt;Visitors to a compromised site got redirected a couple of times to other sites and then will see a popup asking to install an ActiveX Object.&lt;/p&gt;
&lt;p&gt;When the ActiveX Object gets installed these trojans also gets installed on the victims computer:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;TROJ_DNSCHANG.CS&lt;/li&gt;
&lt;li&gt;TROJ_ALUREON.AE&lt;/li&gt;
&lt;li&gt;TROJ_ALUREON.AH&lt;/li&gt;
&lt;li&gt;TROJ_ALUREON.AI&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;According to Trend Micro these trojans are evil:&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;These types of Trojans are known for changing an affected system’s local DNS and Internet browser settings, thus making the system vulnerable for &lt;em&gt;even more&lt;/em&gt; potential threats.&lt;/p&gt;
&lt;p&gt;Read more at &lt;a rel="nofollow" href="http://blog.trendmicro.com/more-than-a-half-a-million-web-sites-compromised/" target="_blank"&gt;Trend Micro&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/288078741" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/05/11/more-sql-injections/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/05/11/more-sql-injections/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/05/11/more-sql-injections/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Google Adwords phishing attempt]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/281636955/" />
		<id>http://antivirus.xaviermedia.com/?p=12</id>
		<updated>2008-05-01T19:31:37Z</updated>
		<published>2008-05-01T19:31:37Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="Google" />		<summary type="html"><![CDATA[I just got an email from Google informing me of possible phishing attempts and that I should be &#8220;on my watch&#8221; for suspicious emails appearing to be from Google. Here&#8217;s the email I got (I removed @ from the email addresses):
At Google, we take the safety of our users very seriously, and we work hard [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/05/01/google-adwords-phishing-attempt/">&lt;p&gt;I just got an email from Google informing me of possible phishing attempts and that I should be &amp;#8220;on my watch&amp;#8221; for suspicious emails appearing to be from Google. Here&amp;#8217;s the email I got (I removed @ from the email addresses):&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;At Google, we take the safety of our users very seriously, and we work hard to  ensure that your accounts are secure. As part of those efforts, we recently  compiled some tips on our blog to help protect you from &amp;#8220;phishing,&amp;#8221; which is an  attempt to fraudulently collect passwords, credit card numbers, and other  sensitive information: &lt;a href="http://googleblog.blogspot.com/2008/04/how-to-avoid-getting-hooked.html"&gt;http://googleblog.blogspot.com/2008/04/how-to-avoid-getting-hooked.html&lt;/a&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;This  information is important because any online account can be targeted by phishers,  including online advertising accounts.&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;There are reports of phishing  attempts that falsely appear to be from adwords-noreply (a) google.com. These  fraudulent emails ask users to update their billing information, take action on  a disapproved ad, edit their account, or accept new AdWords terms and  conditions. Please remember that Google&amp;#8217;s AdWords team will never send an  unsolicited message asking for your password or other sensitive information by  email or through a link.&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;If you need to change your account information,  such as your billing details or your password, always sign in to your AdWords  account from the main AdWords login page at &lt;a href="https://adwords.google.com/"&gt;https://adwords.google.com&lt;/a&gt; and make the  changes directly within your account.&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;We&amp;#8217;ve included more information  below on how to avoid phishing.  If you have any questions, please don&amp;#8217;t  hesitate to contact us at adwords-support (a) google.com.&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;Sincerely,&lt;br /&gt;
The  Google AdWords Team&lt;/p&gt;
&lt;p&gt;As always it&amp;#8217;s important to make sure your logging in at the correct site (in this case google.com).&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/281636955" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/05/01/google-adwords-phishing-attempt/#comments" thr:count="1" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/05/01/google-adwords-phishing-attempt/feed/atom/" thr:count="1" />
		<thr:total>1</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/05/01/google-adwords-phishing-attempt/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Security fix for Wordpress]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/278118163/" />
		<id>http://antivirus.xaviermedia.com/?p=11</id>
		<updated>2008-04-26T07:02:29Z</updated>
		<published>2008-04-26T07:00:01Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="Wordpress" />		<summary type="html"><![CDATA[Most of us have just upgraded to Wordpress 2.5 when it&#8217;s now time for another upgrade. This time it&#8217;s a more urgent upgrade since it includes a security fix and about 70 bug fixes:
We recommend everyone update immediately, particularly if your blog has open registration. The vulnerability is not public but it will be shortly.
My [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/04/26/security-fix-for-wordpress/">&lt;p&gt;Most of us have just upgraded to Wordpress 2.5 when it&amp;#8217;s now time for another upgrade. This time it&amp;#8217;s a more urgent upgrade since it includes a security fix and about 70 bug fixes:&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;We recommend everyone update immediately, particularly if your blog has open registration. The vulnerability is not public but it will be shortly.&lt;/p&gt;
&lt;p&gt;My guess is that this security fix is related to &lt;a href="http://antivirus.xaviermedia.com/2008/03/21/check-your-wordpress-installation/" target="_self"&gt;this post&lt;/a&gt;, but that&amp;#8217;s just my guess.&lt;/p&gt;
&lt;p&gt;Read more in the &lt;a href="http://wordpress.org/development/2008/04/wordpress-251/" target="_blank"&gt;Wordpress blog&lt;/a&gt; or go directly to the &lt;a href="http://wordpress.org/download/" target="_blank"&gt;download page&lt;/a&gt; to get the latest version.&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/278118163" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/04/26/security-fix-for-wordpress/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/04/26/security-fix-for-wordpress/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/04/26/security-fix-for-wordpress/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Hosting companies watch out!]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/274123190/" />
		<id>http://antivirus.xaviermedia.com/?p=10</id>
		<updated>2008-04-20T15:32:26Z</updated>
		<published>2008-04-20T15:32:26Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="IIS" /><category scheme="http://antivirus.xaviermedia.com" term="SQL" />		<summary type="html"><![CDATA[Now all hosting companies offering IIS and SQL Server on Windows XP, 2003, Vista, and Server 2008 must watch out for a vulnerability allowing local users to raise his privilege level.
Microsoft stated in their advisory:
Hosting providers may be at increased risk from this elevation of privilege vulnerability.
But no explanation was provided.
Since IIS is a popular [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/04/20/hosting-companies-watch-out/">&lt;p&gt;Now all hosting companies offering IIS and SQL Server on Windows XP, 2003, Vista, and Server 2008 must watch out for a vulnerability allowing local users to raise his privilege level.&lt;/p&gt;
&lt;p&gt;Microsoft stated in their advisory:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Hosting providers may be at increased risk from this elevation of privilege vulnerability.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;But no explanation was provided.&lt;/p&gt;
&lt;p&gt;Since IIS is a popular platform for may web hosting companies we may see targetted attacks on hosting companies (and their clients web sites)  &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /&gt; . If you work for or run your own hosting company you may have to keep an eye on your SQL server.&lt;/p&gt;
&lt;p&gt;Read more at &lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/04/18/web-hosting-providers/" target="_blank"&gt;McAfee AVERT Labs Blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/274123190" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/04/20/hosting-companies-watch-out/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/04/20/hosting-companies-watch-out/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/04/20/hosting-companies-watch-out/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Wordpress 2.5 is out, upgrade today!]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/261411403/" />
		<id>http://antivirus.xaviermedia.com/2008/03/31/wordpress-25-is-out-upgrade-today/</id>
		<updated>2008-03-31T17:21:57Z</updated>
		<published>2008-03-31T17:21:57Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="Wordpress" />		<summary type="html"><![CDATA[The latest version of Wordpress is only a few days old when I noticed this urgent post in the TrendLabs blog regarding the old version of Wordpress (version 2.3.3 that is). It&#8217;s always important to upgrade your software, and this time it can really hurt your visitors and subscribers if you don&#8217;t  
This javascript [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/03/31/wordpress-25-is-out-upgrade-today/">&lt;p&gt;The latest version of Wordpress is only a few days old when I noticed &lt;a href="http://blog.trendmicro.com/wordpress-233-invaded-by-wily-javascript/" target="_blank"&gt;this urgent post&lt;/a&gt; in the TrendLabs blog regarding the old version of Wordpress (version 2.3.3 that is). It&amp;#8217;s always important to upgrade your software, and this time it can really hurt your visitors and subscribers if you don&amp;#8217;t &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /&gt; &lt;/p&gt;
&lt;p&gt;This javascript injection is createing a directory called &lt;em&gt;1&lt;/em&gt; in your &lt;em&gt;wp-content&lt;/em&gt; directory. So to find out if your blog has been hijacked you should search for a directory called that. This directory will be full of infected files containing links to other infected files &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /&gt;  so you need to remove them all if your blog has been infected.&lt;/p&gt;
&lt;p&gt;If you blog gets infected, then all your blog pages will be filled with links to other infected pages.&lt;/p&gt;
&lt;p&gt;TrendLabs is giving this advice to blog owners:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;As of this writing, a fix for this vulnerability has yet to be issued by WordPress. (You may, however, find this and this sites useful.) As a workaround, users may want to close their registration feature. Also, be wary of third-party plug-ins you install in your blog sites.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/261411403" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/03/31/wordpress-25-is-out-upgrade-today/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/03/31/wordpress-25-is-out-upgrade-today/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/03/31/wordpress-25-is-out-upgrade-today/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Manipulated ratings at eBay?]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/256889276/" />
		<id>http://antivirus.xaviermedia.com/2008/03/24/manipulated-ratings-at-ebay/</id>
		<updated>2008-03-24T07:09:48Z</updated>
		<published>2008-03-24T07:09:25Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="eBay" />		<summary type="html"><![CDATA[TrendMicro is this morning reporting about manipulated ratings at eBay.co.uk. The ratings at eBay show the users history using stars. The more stars (five is the maximum) a user got the more successful trades have been completed and the more trusted a user can be.
The manipulation works like this.  The unsuspecting user visits one [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/03/24/manipulated-ratings-at-ebay/">&lt;p&gt;TrendMicro is this morning reporting about &lt;a href="http://blog.trendmicro.com/ratings-manipulation-reaches-ebay/" target="_blank" rel=nofollow&gt;manipulated ratings at eBay.co.uk&lt;/a&gt;. The ratings at eBay show the users history using stars. The more stars (five is the maximum) a user got the more successful trades have been completed and the more trusted a user can be.&lt;/p&gt;
&lt;p&gt;The manipulation works like this.  The unsuspecting user visits one of the auction pages at eBay which contains an embed (and hidden) Shockwave file. The user is redirected to a .aspx file in Russia, which means that the user is doing business with someone he can&amp;#8217;t identify &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /&gt; . So be alert when you do business on eBay. &lt;strong&gt;Make sure you&amp;#8217;re still at the eBay site at all times!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/256889276" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/03/24/manipulated-ratings-at-ebay/#comments" thr:count="1" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/03/24/manipulated-ratings-at-ebay/feed/atom/" thr:count="1" />
		<thr:total>1</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/03/24/manipulated-ratings-at-ebay/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Check your Wordpress installation]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/255428038/" />
		<id>http://antivirus.xaviermedia.com/2008/03/21/check-your-wordpress-installation/</id>
		<updated>2008-03-21T09:50:25Z</updated>
		<published>2008-03-21T09:49:42Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="Wordpress" />		<summary type="html"><![CDATA[If you&#8217;re using Wordpress you should make sure that you&#8217;re using the latest version (at the moment 2.3.3) and that you&#8217;ve removed all the old files so no one can take advantage of a security leak in the old files. Shoemoney.com is reporting that people claim to have hidden links (or even iframes) injected into [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/03/21/check-your-wordpress-installation/">&lt;p&gt;If you&amp;#8217;re using Wordpress you should make sure that you&amp;#8217;re using the latest version (at the moment 2.3.3) and that you&amp;#8217;ve removed all the old files so no one can take advantage of a security leak in the old files. &lt;a href="http://www.shoemoney.com/2008/03/21/wordpress-233-hidden-links-injection-exploit-and-how-to-not-let-it-happen-to-you/" target="_blank"&gt;Shoemoney.com&lt;/a&gt; is reporting that people claim to have hidden links (or even iframes) injected into their latest installations of Wordpress.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.shoemoney.com/2008/03/21/wordpress-233-hidden-links-injection-exploit-and-how-to-not-let-it-happen-to-you/" target="_blank"&gt;Shoemoney.com&lt;/a&gt; says:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;First I want to say I have never seen any evidence of a fresh 2.3.3 install of Wordpress.&lt;/p&gt;
&lt;p&gt;The issue most likely comes from either a previous exploitable file still existing in your Wordpress install directory or from someone who has already hijacked your admin cookie. You see there were some wicked exploits in earlier versions that allowed people to hijack your admin cookie which authenticates you (keep me logged in).&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;So the advice is to always keep your installations up to date, change passwords regularly and to remove old files used in previous version of your installation. This is not only true for Word press, but for all installations on your server like for example phpBB.&lt;/p&gt;
&lt;p align="left"&gt;A good idea is also to keep a backup on your database at some other location then your current server. Wordpress got a few good plugins that can email your database to you on a daily basis, or if you can you should setup so your web server is sending a backup of your entire site to some remote FTP account.&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/255428038" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/03/21/check-your-wordpress-installation/#comments" thr:count="2" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/03/21/check-your-wordpress-installation/feed/atom/" thr:count="2" />
		<thr:total>2</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/03/21/check-your-wordpress-installation/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Make sure you upgrade your phpBB forums]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/253758110/" />
		<id>http://antivirus.xaviermedia.com/2008/03/18/make-sure-you-upgrade-your-phpbb-forums/</id>
		<updated>2008-03-21T09:50:36Z</updated>
		<published>2008-03-18T17:24:59Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="phpBB" />		<summary type="html"><![CDATA[Since a few days over 200 000 pages (most of them using phpBB) have been compromised with an exploit according to McAfee.
This video will show you how it looks like on the users side:

March 2008 - Mass Hack Demo  from Schmooog on Vimeo.If you got a forum using phpBB you have to make sure [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/03/18/make-sure-you-upgrade-your-phpbb-forums/">&lt;p&gt;Since a few days over 200 000 pages (most of them using phpBB) have been compromised with an exploit according to McAfee.&lt;/p&gt;
&lt;p&gt;This video will show you how it looks like on the users side:&lt;br /&gt;
&lt;object type="application/x-shockwave-flash" data="http://www.vimeo.com/moogaloop.swf?clip_id=781981&amp;amp;server=www.vimeo.com&amp;amp;fullscreen=1&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=" height="298" width="400"&gt;&lt;/object&gt;&lt;param name="quality" value="best"&gt;&lt;/param&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;/param&gt;&lt;param name="scale" value="showAll"&gt;&lt;/param&gt;&lt;param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=781981&amp;amp;server=www.vimeo.com&amp;amp;fullscreen=1&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color="&gt;&lt;/param&gt;
&lt;a href="http://www.vimeo.com/781981/l:embed_781981" rel="nofollow"&gt;March 2008 - Mass Hack Demo &lt;/a&gt; from &lt;a href="http://www.vimeo.com/user400518/l:embed_781981" rel="nofollow"&gt;Schmooog&lt;/a&gt; on &lt;a href="http://vimeo.com/l:embed_781981" rel="nofollow"&gt;Vimeo&lt;/a&gt;.If you got a forum using phpBB you have to make sure you&amp;#8217;re using the latest version. Back in 2004 another mass hack of phpBB occurred &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /&gt; so this is not the first (and absolutely not the last time) the users of phpBB forums learn the hard way how important backups are.&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/253758110" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/03/18/make-sure-you-upgrade-your-phpbb-forums/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/03/18/make-sure-you-upgrade-your-phpbb-forums/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/03/18/make-sure-you-upgrade-your-phpbb-forums/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Andreas from Xavier Media</name>
					</author>
		<title type="html"><![CDATA[Welcome to the antivirus blog]]></title>
		<link rel="alternate" type="text/html" href="http://feed.xaviermedia.com/~r/AntivirusBlog/~3/251968914/" />
		<id>http://antivirus.xaviermedia.com/2008/03/15/welcome-to-the-antivirus-blog/</id>
		<updated>2008-03-15T13:49:25Z</updated>
		<published>2008-03-15T13:49:25Z</published>
		<category scheme="http://antivirus.xaviermedia.com" term="News" />		<summary type="html"><![CDATA[Welcome to the latest blog from Xavier Media about antivirus softwares, latest virus threats and how to protect you and your computer from scumware, trojans and other malware.
The virus map found on the main page is constantly updated with the latest threats you need to look our for. You can also &#8220;zoom in&#8221; on your [...]]]></summary>
		<content type="html" xml:base="http://antivirus.xaviermedia.com/2008/03/15/welcome-to-the-antivirus-blog/">&lt;p&gt;Welcome to the latest blog from Xavier Media about antivirus softwares, latest virus threats and how to protect you and your computer from scumware, trojans and other malware.&lt;/p&gt;
&lt;p&gt;The virus map found on the &lt;a href="http://antivirus.xaviermedia.com/"&gt;main page&lt;/a&gt; is constantly updated with the latest threats you need to look our for. You can also &amp;#8220;zoom in&amp;#8221; on your region to see what&amp;#8217;s going on in your part of the world.&lt;/p&gt;
&lt;p style="text-align: center"&gt;&lt;img src="http://antivirus.xaviermedia.com/blog/wp-content/uploads/2008/03/virusmap.PNG" alt="The virus map" /&gt;&lt;/p&gt;
&lt;p&gt;Thanks to our friends at Trend Micro you can also scan your computer for viruses completely free by visiting &lt;a href="http://housecall.trendmicro.com/" target="_blank" rel="nofollow"&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;More features and articles on how to protect yourself will be added shortly and I really hope that you like the new and improved antivirus page from Xavier Media &lt;img src='http://antivirus.xaviermedia.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /&gt; .&lt;/p&gt;
&lt;p&gt;Post from: &lt;a href="http://antivirus.xaviermedia.com/"&gt;The Antivirus blog&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://feed.xaviermedia.com/~r/AntivirusBlog/~4/251968914" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://antivirus.xaviermedia.com/2008/03/15/welcome-to-the-antivirus-blog/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://antivirus.xaviermedia.com/2008/03/15/welcome-to-the-antivirus-blog/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://antivirus.xaviermedia.com/2008/03/15/welcome-to-the-antivirus-blog/</feedburner:origLink></entry>
	</feed><!-- Dynamic Page Served (once) in 0.275 seconds --><!-- Cached page served by WP-Cache -->
