<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Julian Sula's Blog</title>
	<atom:link href="http://www.juliansula.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.juliansula.com/blog</link>
	<description>paintings, drawings, photography, fine art</description>
	<lastBuildDate>Wed, 07 Jul 2010 04:42:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Fanatical Support? What fanatical support&#8230;Rackspace sucks!</title>
		<link>http://www.juliansula.com/blog/fanatical-support-what-fanatical-support-rackspace-sucks/</link>
		<comments>http://www.juliansula.com/blog/fanatical-support-what-fanatical-support-rackspace-sucks/#comments</comments>
		<pubDate>Sat, 03 Jul 2010 06:51:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[application level security]]></category>
		<category><![CDATA[backup source]]></category>
		<category><![CDATA[cloudsites]]></category>
		<category><![CDATA[copy paste]]></category>
		<category><![CDATA[design compromises]]></category>
		<category><![CDATA[directory permissions]]></category>
		<category><![CDATA[exposures]]></category>
		<category><![CDATA[frustration]]></category>
		<category><![CDATA[live chat]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[rackspace]]></category>
		<category><![CDATA[rackspace compromised]]></category>
		<category><![CDATA[rackspace hacked]]></category>
		<category><![CDATA[rackspace sucks]]></category>
		<category><![CDATA[security team]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.juliansula.com/blog/?p=185</guid>
		<description><![CDATA[If you are considering signing up for Cloud Hosting with Rackspace I would urge you to seriously re-consider. After assisting a client with their website that is hosted with them on a cloud hosting account ($149/month w/ no shell access - you might as well get a cheap $5 shared hosting account if you will [...]]]></description>
			<content:encoded><![CDATA[<p>If you are considering signing up for Cloud Hosting with Rackspace I would urge you to seriously re-consider. After assisting a client with their website that is hosted with them on a cloud hosting account (<span style="color: #ff0000;"><strong>$149/month w/ no shell access</strong></span> -<strong><span style="text-decoration: underline;"> you might as well get a cheap $5 shared hosting account if you will get crappy support</span></strong>) and dealing with their so-called fanatical support I can tell you with the outmost certainty that their support is far from fanatical. Matt W the support tech on the live chat was unprofessional and slow to respond to my questions. I felt like I was pulling teeth. Their servers had been hit with a WordPress cloaking script effecting a lot of customers including mine, and troubleshooting and cleaning a server over FTP is nearly impossible.<br />
Here is a copy/paste BS answer from him:</p>
<blockquote><p>Matt W: I&#8217;m sorry that your site has potentially been compromised. We understand the frustration this causes and want you to rest assured that we are going to do everything within our capacity to help you out.<br />
Matt W: By design, compromises are normally attributed to insecure permissions and/or application level security vulnerabilities. The goal of our &#8220;Security Team&#8221; is to identify a few ways that your site may have become vulnerable and offer you a best practice approach for you to apply to your application to remedy the issue.<br />
Matt W: We recommend that you immediately take the following steps if you believe your website has been compromised:<br />
Matt W: 1. Change all passwords (please make sure you are using strong passwords)<br />
Matt W: 2. Backup the compromised data modify your directory and file permissions to ensure these exposures are corrected. If you need assistance setting your file and directory permissions, please do not hesitate to contact our Support Teams for assistance.<br />
Matt W: 3. Identify what has been compromised<br />
Matt W: 4. Find the vulnerability<br />
Matt W: 5. Restore your content from a known, trusted backup source<br />
Matt W: 6. Preventative/Counter Measures<br />
Matt W: Please visit the following page to obtain more detail on these steps:<br />
Matt W: http://cloudsites.rackspacecloud.com/index.php/Recovering_from_and_Dealing_with_a_Site_Compromise<br />
Julian: so what can you do to help<br />
Julian: I have taken those measures already<br />
Julian: since we do not have shell access I cant do any sys admin type stuff<br />
Julian: through FTP<br />
Julian: can&#8217;t tail trace or grep<br />
Julian: ?<br />
Matt W: Generally you can copy the compromised data, restore to a clean copy, and trace the compromised files locally to find the vulnerabilities. Another option is to use cron to run a scripted commands.<br />
Julian: I just replaced ALL the wordpress files with a fresh copy of the sofware and the problem STILL persists<br />
Julian: from my research a lot of your customers have been hit with this issue<br />
Julian: what level of support are you?<br />
Matt W: We are responsible for the security of the servers, however the security of your website and it&#8217;s contents is something that you are reliable for. As I stated, we can certainly assist you in determining what may be causing your site to continue getting hacked. However this is something that will take some time and investigation.</p></blockquote>
<p>Mind you it has been noted that this issue had been as a result of an insecure version of phpmyadmin running on their servers, so how is it our fault in the first place that our customer sites get hacked?<br />
As noted <a href="http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/">here</a> or <a href="http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html">here</a> or <a href="http://www.voiptechchat.com/tech/551/rackspace-wordpress-sites-under-attack/">here</a></p>
<p>I left the chat frustrated and disappointed. In the end a complete move away from the Rackspace Cloud was recommended to the client, and a VPS solution was recommended in its place for a fraction of the cost of a Rackspace account,  and with a lot more features and control. A big thumbs down for Rackspace and their &#8220;Fanatical&#8221; support claim they tout everywhere is just a marketing gimmick that just could not be further away from reality.</p>
<p><strong><span style="color: #ff0000;">**UPDATE</span></strong></p>
<p>After painfully manually looking at every singe file and line of code I discovered the following php include  being called from within the &#8216;main.php&#8217; file of the installed theme.</p>
<p>Looking at menu.is you guessed it, it was executing some nasty binary code.</p>
<p><code> </code></p>
<p>NOTE: If you are being hit with this cloaking hack first thing I would recommend you do is disable XML-RPC publishing. Then scan your header.php file for anything that should not be there. Usually at the very top of the code.</p>
<p>For those with no shell access (like the fore mentioned) you have to download ALL of your remote files locally (P.I.T.A.) and scan them locally.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.juliansula.com/blog/fanatical-support-what-fanatical-support-rackspace-sucks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Time Lapse Charcoal Drawing</title>
		<link>http://www.juliansula.com/blog/time-lapse-charcoal-drawing/</link>
		<comments>http://www.juliansula.com/blog/time-lapse-charcoal-drawing/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 16:56:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Drawing]]></category>
		<category><![CDATA[charcoal]]></category>
		<category><![CDATA[charcoal drawing]]></category>
		<category><![CDATA[time lapse]]></category>

		<guid isPermaLink="false">http://www.juliansula.com/blog/?p=179</guid>
		<description><![CDATA[Time Lapse Charcoal Drawing from Julian S. on Vimeo. Time lapse charcoal drawing.]]></description>
			<content:encoded><![CDATA[<p><object width="400" height="225"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=8452729&amp;server=vimeo.com&amp;show_title=0&amp;show_byline=0&amp;show_portrait=0&amp;color=636363&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=8452729&amp;server=vimeo.com&amp;show_title=0&amp;show_byline=0&amp;show_portrait=0&amp;color=636363&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="225"></embed></object>
<p><a href="http://vimeo.com/8452729">Time Lapse Charcoal Drawing</a> from <a href="http://vimeo.com/julians">Julian S.</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<p>Time lapse charcoal drawing.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.juliansula.com/blog/time-lapse-charcoal-drawing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Contemporary direction</title>
		<link>http://www.juliansula.com/blog/contemporary-direction/</link>
		<comments>http://www.juliansula.com/blog/contemporary-direction/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 06:43:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Acrylics]]></category>
		<category><![CDATA[Paintings]]></category>

		<guid isPermaLink="false">http://www.juliansula.com/blog/?p=171</guid>
		<description><![CDATA[I wanted to flirt with some abstract work and here are the results.]]></description>
			<content:encoded><![CDATA[<p>I wanted to flirt with some abstract work and here are the results.</p>
<p style="text-align: center; "><a style="text-decoration: none;" href="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8244.jpg" rel="lightbox[171]"><img class="aligncenter size-medium wp-image-172" title="IMG_8244" src="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8244-231x300.jpg" alt="IMG_8244" width="231" height="300" /></a></p>
<p style="text-align: center; "><a href="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8246.jpg" rel="lightbox[171]"><img class="aligncenter size-medium wp-image-174" title="IMG_8246" src="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8246-233x300.jpg" alt="IMG_8246" width="233" height="300" /></a></p>
<p style="text-align: center; "><a href="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8249.jpg" rel="lightbox[171]"><img class="aligncenter size-medium wp-image-173" title="IMG_8249" src="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8249-234x300.jpg" alt="IMG_8249" width="234" height="300" /></a></p>
<p style="text-align: center; "><a href="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8251.jpg" rel="lightbox[171]"><img class="aligncenter size-medium wp-image-175" title="IMG_8251" src="http://www.juliansula.com/blog/wp-content/uploads/2009/12/IMG_8251-300x232.jpg" alt="IMG_8251" width="300" height="232" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.juliansula.com/blog/contemporary-direction/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Portrait (close-up)</title>
		<link>http://www.juliansula.com/blog/portrait-close-up/</link>
		<comments>http://www.juliansula.com/blog/portrait-close-up/#comments</comments>
		<pubDate>Sun, 25 Oct 2009 17:06:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.juliansula.com/blog/?p=166</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a rel="lightbox" href="http://www.juliansula.com/blog/wp-content/uploads/2009/10/DSC05066.JPG"><img class="aligncenter size-medium wp-image-168" title="DSC05066" src="http://www.juliansula.com/blog/wp-content/uploads/2009/10/DSC05066-225x300.jpg" alt="DSC05066" width="225" height="300" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.juliansula.com/blog/portrait-close-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Portrait in progress</title>
		<link>http://www.juliansula.com/blog/portrait-in-progress/</link>
		<comments>http://www.juliansula.com/blog/portrait-in-progress/#comments</comments>
		<pubDate>Sun, 06 Sep 2009 14:34:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Acrylics]]></category>
		<category><![CDATA[Paintings]]></category>

		<guid isPermaLink="false">http://www.juliansula.com/blog/?p=158</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-medium wp-image-159" title="DSC05045" src="http://www.juliansula.com/blog/wp-content/uploads/2009/09/DSC05045-225x300.jpg" alt="DSC05045" width="225" height="300" /><img class="aligncenter size-medium wp-image-160" title="DSC05047" src="http://www.juliansula.com/blog/wp-content/uploads/2009/09/DSC05047-300x225.jpg" alt="DSC05047" width="300" height="225" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.juliansula.com/blog/portrait-in-progress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Acrylic Nude</title>
		<link>http://www.juliansula.com/blog/acrylic-nude/</link>
		<comments>http://www.juliansula.com/blog/acrylic-nude/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 22:42:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Acrylics]]></category>

		<guid isPermaLink="false">http://www.juliansula.com/blog/?p=149</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.juliansula.com/blog/wp-content/uploads/2009/08/IMG_7592.jpg" rel="lightbox[149]"><img class="size-full wp-image-150 aligncenter" title="IMG_7592" src="http://www.juliansula.com/blog/wp-content/uploads/2009/08/IMG_7592.jpg" alt="IMG_7592" width="407" height="323" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.juliansula.com/blog/acrylic-nude/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
