<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: I Was Hacked&#8230; Or Wormed?</title>
	<atom:link href="http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/feed/" rel="self" type="application/rss+xml" />
	<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/</link>
	<description>Unwrapping the Mysteries of Life!</description>
	<lastBuildDate>Tue, 27 Jul 2010 14:38:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: Heather Vale</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-4177</link>
		<dc:creator>Heather Vale</dc:creator>
		<pubDate>Sat, 13 Sep 2008 04:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-4177</guid>
		<description>Here&#039;s an update that was supplied by &quot;BlueSquares&quot; at the Warrior Forum... 

From Slashdot:

&quot;A tool that automatically steals IDs of non-encrypted sessions and breaks into Google Mail accounts has been presented at the Defcon hackers&#039; conference in Las Vegas. Last week, Google introduced a new feature in Gmail that allows users to permanently switch on SSL and use it for every action involving Gmail, not just authentication. Users who did not turn it on now have a serious reason to do so, as Mike Perry, the reverse engineer from San Francisco who developed the hacking tool, is planning to release it in two weeks.&quot;

The solution is to set Permanent SSL in Gmail

   1. Sign in to Gmail.
   2. Click Settings at the top of any Gmail page.
   3. Set &#039;Browser Connection&#039; to &#039;Always use https.&#039;
   4. Click Save Changes.
   5. Reload Gmail.</description>
		<content:encoded><![CDATA[<p>Here&#8217;s an update that was supplied by &#8220;BlueSquares&#8221; at the Warrior Forum&#8230; </p>
<p>From Slashdot:</p>
<p>&#8220;A tool that automatically steals IDs of non-encrypted sessions and breaks into Google Mail accounts has been presented at the Defcon hackers&#8217; conference in Las Vegas. Last week, Google introduced a new feature in Gmail that allows users to permanently switch on SSL and use it for every action involving Gmail, not just authentication. Users who did not turn it on now have a serious reason to do so, as Mike Perry, the reverse engineer from San Francisco who developed the hacking tool, is planning to release it in two weeks.&#8221;</p>
<p>The solution is to set Permanent SSL in Gmail</p>
<p>   1. Sign in to Gmail.<br />
   2. Click Settings at the top of any Gmail page.<br />
   3. Set &#8216;Browser Connection&#8217; to &#8216;Always use https.&#8217;<br />
   4. Click Save Changes.<br />
   5. Reload Gmail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eddie</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-4132</link>
		<dc:creator>Eddie</dc:creator>
		<pubDate>Mon, 08 Sep 2008 09:21:51 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-4132</guid>
		<description>Hi Heather,

Thank you for the kind words, it&#039;s good to talk to someone who had the same problem.

I&#039;ve been doing some extensive research the past two days and read some very strange and scary things.

I don&#039;t know if I can use my email address in the future, most likely not. What remains is some fear and distrust.

I also don&#039;t know if I stay with gmail, maybe I&#039;ll switch to the allegedly more secure google apps.

Or I&#039;ll abandon it completely... like so many others throughout the net.

Thanks,
Eddie</description>
		<content:encoded><![CDATA[<p>Hi Heather,</p>
<p>Thank you for the kind words, it&#8217;s good to talk to someone who had the same problem.</p>
<p>I&#8217;ve been doing some extensive research the past two days and read some very strange and scary things.</p>
<p>I don&#8217;t know if I can use my email address in the future, most likely not. What remains is some fear and distrust.</p>
<p>I also don&#8217;t know if I stay with gmail, maybe I&#8217;ll switch to the allegedly more secure google apps.</p>
<p>Or I&#8217;ll abandon it completely&#8230; like so many others throughout the net.</p>
<p>Thanks,<br />
Eddie</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heather Vale</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-4125</link>
		<dc:creator>Heather Vale</dc:creator>
		<pubDate>Sun, 07 Sep 2008 07:37:49 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-4125</guid>
		<description>Hey Eddie,

Try sending a damage control email to everyone it was sent to... you can see their addresses on the email in the trash bin, and you can apologize, and explain that someone hacked into your account but you&#039;ve now changed the password, and at least some of them (the important ones) will understand.

I think hackers have tools that we can&#039;t even guess at... it&#039;s not just them randomly trying easy passwords, or knowing if we have one we use a lot -- they can do it by analyzing keystrokes sometimes, and I&#039;m sure there are a ton more ways they get access that it&#039;s really hard to anticipate and prevent.

Changing the password should work for awhile, anyhow -- maybe it&#039;s good to regularly change it up?

cheers
Heather</description>
		<content:encoded><![CDATA[<p>Hey Eddie,</p>
<p>Try sending a damage control email to everyone it was sent to&#8230; you can see their addresses on the email in the trash bin, and you can apologize, and explain that someone hacked into your account but you&#8217;ve now changed the password, and at least some of them (the important ones) will understand.</p>
<p>I think hackers have tools that we can&#8217;t even guess at&#8230; it&#8217;s not just them randomly trying easy passwords, or knowing if we have one we use a lot &#8212; they can do it by analyzing keystrokes sometimes, and I&#8217;m sure there are a ton more ways they get access that it&#8217;s really hard to anticipate and prevent.</p>
<p>Changing the password should work for awhile, anyhow &#8212; maybe it&#8217;s good to regularly change it up?</p>
<p>cheers<br />
Heather</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eddie</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-4124</link>
		<dc:creator>Eddie</dc:creator>
		<pubDate>Sun, 07 Sep 2008 07:29:59 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-4124</guid>
		<description>Yes, I also think that it was a person because they not only deleted the sent messages (found them in the trash bin) but also a few others that came as a reaction to the spam-mail.

This rises the question how did they get in?

I had a super easy pass that&#039;s true, but is it so easy to hack?

Anyway, I hope it doesn&#039;t happen again, for most of my contacts I&#039;m a spammer now :(.

Eddie</description>
		<content:encoded><![CDATA[<p>Yes, I also think that it was a person because they not only deleted the sent messages (found them in the trash bin) but also a few others that came as a reaction to the spam-mail.</p>
<p>This rises the question how did they get in?</p>
<p>I had a super easy pass that&#8217;s true, but is it so easy to hack?</p>
<p>Anyway, I hope it doesn&#8217;t happen again, for most of my contacts I&#8217;m a spammer now <img src='http://heathervale.com/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> .</p>
<p>Eddie</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heather Vale</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-4119</link>
		<dc:creator>Heather Vale</dc:creator>
		<pubDate>Sun, 07 Sep 2008 03:13:50 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-4119</guid>
		<description>Hi Eddie,

Yes, I know how you feel -- it was my business account too, which of course looks really bad!

I&#039;m thinking it was a person because:

1) after I changed my password, it didn&#039;t happen again, and
2) I ran numerous virus/worm/trojan removal programs, and they all came up blank.

Another weird thing happened that I only noticed yesterday (because I rarely look at the page in question anymore), but on my Success Unwrapped podcast page somebody changed ONE picture of ONE guest (out of over 60) to a picture of a guitar player in a cowboy hat.

I&#039;m figuring if somebody actually logged in, why would they bother doing just that?  So in that instance I&#039;m suspecting some kind of bot through the online program.

cheers
Heather</description>
		<content:encoded><![CDATA[<p>Hi Eddie,</p>
<p>Yes, I know how you feel &#8212; it was my business account too, which of course looks really bad!</p>
<p>I&#8217;m thinking it was a person because:</p>
<p>1) after I changed my password, it didn&#8217;t happen again, and<br />
2) I ran numerous virus/worm/trojan removal programs, and they all came up blank.</p>
<p>Another weird thing happened that I only noticed yesterday (because I rarely look at the page in question anymore), but on my Success Unwrapped podcast page somebody changed ONE picture of ONE guest (out of over 60) to a picture of a guitar player in a cowboy hat.</p>
<p>I&#8217;m figuring if somebody actually logged in, why would they bother doing just that?  So in that instance I&#8217;m suspecting some kind of bot through the online program.</p>
<p>cheers<br />
Heather</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eddie</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-4117</link>
		<dc:creator>Eddie</dc:creator>
		<pubDate>Sat, 06 Sep 2008 20:11:45 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-4117</guid>
		<description>Hi Heather,

The very same thing happened to me today.

Unfortunately it hit my business account. Needless to say that I&#039;m devastated. 

Have you found out more about the nature of the whole thing in the mean time? Was is a worm or a person?

Eddie</description>
		<content:encoded><![CDATA[<p>Hi Heather,</p>
<p>The very same thing happened to me today.</p>
<p>Unfortunately it hit my business account. Needless to say that I&#8217;m devastated. </p>
<p>Have you found out more about the nature of the whole thing in the mean time? Was is a worm or a person?</p>
<p>Eddie</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heather Vale</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-3987</link>
		<dc:creator>Heather Vale</dc:creator>
		<pubDate>Mon, 25 Aug 2008 22:57:15 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-3987</guid>
		<description>Hi Ross,

The forums are a little trickier, because they&#039;re so vast at this point that it would take too much time to constantly be manually checking for spam posts.

But feel free to let us know if you see any so we can delete them... just go to http://lwlworldwide.com/support

At least people likely won&#039;t get the idea that WE posted the porn in the forum; whereas when an email goes out from your account, it certainly does give the impression that the person it says it&#039;s from is the one that sent it.

cheers
Heather</description>
		<content:encoded><![CDATA[<p>Hi Ross,</p>
<p>The forums are a little trickier, because they&#8217;re so vast at this point that it would take too much time to constantly be manually checking for spam posts.</p>
<p>But feel free to let us know if you see any so we can delete them&#8230; just go to <a href="http://lwlworldwide.com/support" rel="nofollow">http://lwlworldwide.com/support</a></p>
<p>At least people likely won&#8217;t get the idea that WE posted the porn in the forum; whereas when an email goes out from your account, it certainly does give the impression that the person it says it&#8217;s from is the one that sent it.</p>
<p>cheers<br />
Heather</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross Craft</title>
		<link>http://heathervale.com/blog/2008/08/24/i-was-hacked-or-wormed/#comment-3983</link>
		<dc:creator>Ross Craft</dc:creator>
		<pubDate>Mon, 25 Aug 2008 19:47:34 +0000</pubDate>
		<guid isPermaLink="false">http://heathervale.com/blog/?p=171#comment-3983</guid>
		<description>Hello Heather
I think someone is giving you the business.  I was on your forum awhile ago and about halfway down the page it all turned to porno pictures.

I went on to other subjects and I can&#039;t remember which subject I was on when I saw it.  I was assuming you probably do a cleanup on a regular basis.  I was not offended but others could be.
Ross</description>
		<content:encoded><![CDATA[<p>Hello Heather<br />
I think someone is giving you the business.  I was on your forum awhile ago and about halfway down the page it all turned to porno pictures.</p>
<p>I went on to other subjects and I can&#8217;t remember which subject I was on when I saw it.  I was assuming you probably do a cleanup on a regular basis.  I was not offended but others could be.<br />
Ross</p>
]]></content:encoded>
	</item>
</channel>
</rss>
