<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>noCreativity.com &#187; bbClone</title>
	<atom:link href="http://nocreativity.com/blog/tag/bbclone/feed" rel="self" type="application/rss+xml" />
	<link>http://nocreativity.com</link>
	<description>The life and discoveries of a new media artist</description>
	<lastBuildDate>Sat, 07 Jan 2012 17:03:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>I lied</title>
		<link>http://nocreativity.com/blog/i-lied</link>
		<comments>http://nocreativity.com/blog/i-lied#comments</comments>
		<pubDate>Sat, 13 Feb 2010 17:36:14 +0000</pubDate>
		<dc:creator>Ronny</dc:creator>
				<category><![CDATA[Everything else]]></category>
		<category><![CDATA[bbClone]]></category>
		<category><![CDATA[hacked script]]></category>
		<category><![CDATA[rfi exploit]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[vps]]></category>

		<guid isPermaLink="false">http://nocreativity.com/blog/?p=894</guid>
		<description><![CDATA[I lied! I actually did! I lied when I told you everbody was going down. Because ever since I said so, the server has been up without going down at all. The server has been up for 3 days now, which is about 3 times longer as the longest uptime before that. I think it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="size-full wp-image-895 aligncenter" title="Picture 850" src="http://nocreativity.com/blog-engine/wp-content/uploads/2010/02/Picture-850.jpg" alt="" width="571" height="121" /></p>
<p>I lied! I actually did! I lied when I told you everbody was going down. Because ever since I said so, the server has been up without going down at all. The server has been up for 3 days now, which is about 3 times longer as the longest uptime before that.</p>
<p>I think it&#8217;s safe to assume that the issues have been resolved at this point. The question that many people might want to see answered: What was the cause of all this? A hacked script.</p>
<p><a href="http://www.bbclone.de/" target="_blank" target="_blank">BBclone</a> to be exact. BBclone is a great script to keep count of your statistics. It&#8217;s free, it&#8217;s PHP based (so it doesn&#8217;t matter whether your visitors have Javascript enabled or not), it can be included using .htaccess rules, it&#8217;s simple to use, etc. Basically it&#8217;s a good script to show you basic statistics of your website. However it&#8217;s vulnerable: People can access a modified script URL to include a personal (and probably hostile) scripts (RFI exploit).</p>
<p>That happened to a client of mine who ended up with a nasty script residing in the BBclone folder. That script added cron jobs that ran some other nasty stuff&#8230; Very uncool as you can tell from my unstable server.</p>
<p>I removed those cron jobs, got rid of the hostile files, deleted BBclone and did some other (minor) stuff&#8230; The server has been up ever since.</p>
<p>I want to thank everyone who helped out and suggested what to look for. It would&#8217;ve taken me ages to figure out those things myself. Seen as everything is running smoothly, I can get on with what I really wanted to do: New stuff!</p>
]]></content:encoded>
			<wfw:commentRss>http://nocreativity.com/blog/i-lied/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

