Can you and Chris put together some kind of lesson for the rest of us? Sort of a "watch out for this kind of thing" that we can learn from?<div><br></div><div>(I found the second one before you got it pulled from SVN; so at least I can look at it in the meantime.)</div>
<div><br></div><div>Chip<br><br><div class="gmail_quote">On Fri, Sep 3, 2010 at 8:56 AM, Otto <span dir="ltr"><<a href="mailto:otto@ottodestruct.com">otto@ottodestruct.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
Actually, I went ahead and removed them from SVN because we don't need<br>
malware of that sort in there.<br>
<br>
But if you want a copy, I did save the bad functions.php file, just<br>
for examination later. We may be able to detect this sort of thing in<br>
the uploader and prevent it from uploading.<br>
<font color="#888888"><br>
-Otto<br>
</font><div><div></div><div class="h5"><br>
<br>
<br>
On Fri, Sep 3, 2010 at 8:50 AM, Chip Bennett <<a href="mailto:chip@chipbennett.net">chip@chipbennett.net</a>> wrote:<br>
> I'll have to take a look at those tickets.<br>
> Good learning opportunity for the reviewers? (Or an example of why security<br>
> gurus are needed, for a security-review stage of the process?)<br>
> Chip<br>
><br>
> On Fri, Sep 3, 2010 at 8:45 AM, Otto <<a href="mailto:otto@ottodestruct.com">otto@ottodestruct.com</a>> wrote:<br>
>><br>
>> Never mind. I see it. It's in the functions.php file, disguised. Clever.<br>
>><br>
>> -Otto<br>
>><br>
>><br>
>><br>
>> On Fri, Sep 3, 2010 at 8:42 AM, Otto <<a href="mailto:otto@ottodestruct.com">otto@ottodestruct.com</a>> wrote:<br>
>> > I'm looking at it now.. Where's the worm? Not finding it.<br>
>> ><br>
>> > -Otto<br>
>> ><br>
>> ><br>
>> ><br>
>> > On Fri, Sep 3, 2010 at 8:07 AM, Chris <<a href="mailto:chris@thematic4you.com">chris@thematic4you.com</a>> wrote:<br>
>> >> Tickets #870 and #873<br>
>> >><br>
>> >><br>
>> >><br>
>> >> Von: <a href="mailto:theme-reviewers-bounces@lists.wordpress.org">theme-reviewers-bounces@lists.wordpress.org</a><br>
>> >> [mailto:<a href="mailto:theme-reviewers-bounces@lists.wordpress.org">theme-reviewers-bounces@lists.wordpress.org</a>] Im Auftrag von<br>
>> >> Edward<br>
>> >> Caissie<br>
>> >> Gesendet: Freitag, 3. September 2010 14:47<br>
>> >><br>
>> >> An: <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
>> >> Betreff: Re: [theme-reviewers] Emergency Call<br>
>> >><br>
>> >><br>
>> >><br>
>> >> SVN is a forever land ... without intervention by a "System Admin" as<br>
>> >> far as<br>
>> >> I know.<br>
>> >><br>
>> >> We can keep it out of Extend/Themes easy enough but beyond that we do<br>
>> >> not<br>
>> >> have much control.<br>
>> >><br>
>> >> What tickets/themes are you refering to?<br>
>> >><br>
>> >><br>
>> >> Cais.<br>
>> >><br>
>> >> On Fri, Sep 3, 2010 at 7:08 AM, Chris <<a href="mailto:chris@thematic4you.com">chris@thematic4you.com</a>> wrote:<br>
>> >><br>
>> >> Indeed .. infecting all installed themes of a blog.<br>
>> >><br>
>> >><br>
>> >><br>
>> >> Von: <a href="mailto:theme-reviewers-bounces@lists.wordpress.org">theme-reviewers-bounces@lists.wordpress.org</a><br>
>> >> [mailto:<a href="mailto:theme-reviewers-bounces@lists.wordpress.org">theme-reviewers-bounces@lists.wordpress.org</a>] Im Auftrag von<br>
>> >> Philip<br>
>> >> M. Hofer (Frumph)<br>
>> >> Gesendet: Freitag, 3. September 2010 13:00<br>
>> >> An: <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
>> >> Betreff: Re: [theme-reviewers] Emergency Call<br>
>> >><br>
>> >><br>
>> >><br>
>> >> Oh fricken lovely.<br>
>> >><br>
>> >> ----- Original Message -----<br>
>> >><br>
>> >> From: Chris<br>
>> >><br>
>> >> To: <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
>> >><br>
>> >> Sent: Friday, September 03, 2010 3:55 AM<br>
>> >><br>
>> >> Subject: [theme-reviewers] Emergency Call<br>
>> >><br>
>> >><br>
>> >><br>
>> >> Hi,<br>
>> >><br>
>> >><br>
>> >><br>
>> >> - who is able to remove / delete / nuke two themes from the<br>
>> >> SVN??<br>
>> >><br>
>> >> - Who is in charge of the the scripts running right after<br>
>> >> theme<br>
>> >> upload??<br>
>> >><br>
>> >><br>
>> >><br>
>> >> Had an encounter with not so clean themes .. the themes are rejected,<br>
>> >> but<br>
>> >> need to be removed from the SVN as soon as possible.<br>
>> >><br>
>> >><br>
>> >><br>
>> >> In addition I would like to see the upload script filtering for a not<br>
>> >> so<br>
>> >> nice wormy gift.<br>
>> >><br>
>> >><br>
>> >><br>
>> >> Thanks,<br>
>> >><br>
>> >><br>
>> >><br>
>> >> Chris<br>
>> >><br>
>> >><br>
>> >><br>
>> >><br>
>> >><br>
>> >><br>
>> >><br>
>> >> ________________________________<br>
>> >><br>
>> >> _______________________________________________<br>
>> >> theme-reviewers mailing list<br>
>> >> <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
>> >> <a href="http://lists.wordpress.org/mailman/listinfo/theme-reviewers" target="_blank">http://lists.wordpress.org/mailman/listinfo/theme-reviewers</a><br>
>> >><br>
>> >> _______________________________________________<br>
>> >> theme-reviewers mailing list<br>
>> >> <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
>> >> <a href="http://lists.wordpress.org/mailman/listinfo/theme-reviewers" target="_blank">http://lists.wordpress.org/mailman/listinfo/theme-reviewers</a><br>
>> >><br>
>> >><br>
>> >><br>
>> >> _______________________________________________<br>
>> >> theme-reviewers mailing list<br>
>> >> <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
>> >> <a href="http://lists.wordpress.org/mailman/listinfo/theme-reviewers" target="_blank">http://lists.wordpress.org/mailman/listinfo/theme-reviewers</a><br>
>> >><br>
>> >><br>
>> ><br>
>> _______________________________________________<br>
>> theme-reviewers mailing list<br>
>> <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
>> <a href="http://lists.wordpress.org/mailman/listinfo/theme-reviewers" target="_blank">http://lists.wordpress.org/mailman/listinfo/theme-reviewers</a><br>
><br>
><br>
> _______________________________________________<br>
> theme-reviewers mailing list<br>
> <a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
> <a href="http://lists.wordpress.org/mailman/listinfo/theme-reviewers" target="_blank">http://lists.wordpress.org/mailman/listinfo/theme-reviewers</a><br>
><br>
><br>
_______________________________________________<br>
theme-reviewers mailing list<br>
<a href="mailto:theme-reviewers@lists.wordpress.org">theme-reviewers@lists.wordpress.org</a><br>
<a href="http://lists.wordpress.org/mailman/listinfo/theme-reviewers" target="_blank">http://lists.wordpress.org/mailman/listinfo/theme-reviewers</a><br>
</div></div></blockquote></div><br></div>