<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DUQCSHc7eCp7ImA9WhRUGUo.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252</id><updated>2012-01-30T18:36:09.900-08:00</updated><category term="TDL4" /><category term="MS09-022" /><category term="CVE-2011-3192" /><category term="Duqu" /><category term="sms" /><category term="SMB" /><category term="news" /><category term="SQL Injection" /><category term="DigiNotar" /><category term="vulnerability" /><category term="malware" /><category term="onlyhomeclips.com" /><category term="DefCon" /><category term="adobe" /><category term="McAfee" /><category term="Windows" /><category term="Apple" /><category term="RSA" /><category term="malicious site" /><category term="scams" /><category term="MS09-005" /><category term="MS08-069" /><category term="TLS 1.2" /><category term="MS09-023" /><category term="spam" /><category term="celebrity" /><category term="Scanner" /><category term="CVE-2010-3654" /><category term="freebsd" /><category term="Regtool" /><category term="Apache" /><category term="Zombies" /><category term="Spyware Secure" /><category term="N0ise Bot" /><category term="wget" /><category term="fraud" /><category term="Morto" /><category term="malicious" /><category term="CVE-2010-2568" /><category term="Browser Guard" /><category term="MSN" /><category term="NYTimes.com" /><category term="TLS 1.1" /><category term="MMS" /><category term="MS09-024" /><category term="autorun" /><category term="RealPlayer" /><category term="Bogus" /><category term="Friendster" /><category term="pdf" /><category term="Microsoft Security Essentials" /><category term="CVE-2011-4317" /><category term="Hi5" /><category term="Firefox" /><category term="mayalondon" /><category term="PDF Stream Dumper" /><category term="Conficker" /><category term="savearmor" /><category term="Jailbreakme" /><category term="compromised" /><category term="websecurity" /><category term="MS09-025" /><category term="GDI+" /><category term="MS08-067" /><category term="Vista" /><category term="nc.exe" /><category term="Microsoft" /><category term="Patrick Swayze" /><category term="Script Fragmentation" /><category term="CVE-2010-3971" /><category term="iframe" /><category term="Browser Defender" /><category term="Vmware" /><category term="MS09-026" /><category term="Safeboot" /><category term="MS09-003" /><category term="Tutorial" /><category term="Firefox 7" /><category term="MS08-078" /><category term="Trendmicro" /><category term="Oracle" /><category term="PE" /><category term="battlenet" /><category term="CVE-2009-2979" /><category term="deobfuscate" /><category term="porn" /><category term="ix7.htm" /><category term="excel" /><category term="IRC" /><category term="POPULAR" /><category term="MS09-002" /><category term="Lxlabs" /><category term="CVE-2010-0188" /><category term="Security Response" /><category term="SSL" /><category term="CSRF" /><category term="suspicious" /><category term="Facebook" /><category term="BarCode" /><category term="PoC" /><category term="Wow" /><category term="virustotal" /><category term="brainwash" /><category term="Exploit Shield" /><category term="WordPress" /><category term="IIS 5.0" /><category term="MS09-027" /><category term="lifehacker" /><category term="Exploit" /><category term="alexa" /><category term="Antivir Premium" /><category term="FreShow" /><category term="0Day" /><category term="DHL" /><category term="Google" /><category term="Microsoft Patch Tuesday" /><category term="ITunes" /><category term="PHP" /><category term="phishing" /><category term="acrobat" /><category term="LuckySploit" /><category term="Google Chrome" /><category term="SearchWiki" /><category term="Memory Corruption" /><category term="paypal" /><category term="Linux" /><category term="twitter" /><category term="Web Security" /><category term="Tools" /><category term="DoS" /><category term="Ubuntu" /><category term="CVE-2009-4324" /><category term="Patches" /><category term="Tips and Tricks" /><category term="Drive-By-Downloads" /><category term="FIESTA" /><category term="VirusRemover2008" /><category term="MS09-004" /><category term="Secure Electronic Payment System" /><category term="Pdf exploit" /><category term="SSReader Ultra Star Reader" /><category term="Kaspersky" /><category term="zbot" /><category term="ATM" /><category term="DNS" /><category term="DUmete.exe" /><category term="MDAC" /><category term="websense" /><category term="whitepaper" /><category term="windows 7" /><category term="iphone" /><category term="Rootkit" /><category term="F-Secure" /><category term="mywot" /><category term="ActiveX" /><category term="CVE-2010-1297" /><category term="Browser;websecurity" /><category term="LinkedIn" /><category term="anti-phishing" /><category term="GFI" /><category term="eval()" /><category term="CVE-2010-1885" /><category term="Microsoft Security Advisory (2286198)" /><category term="IE7" /><category term="Survey Scam" /><category term="counterfeit" /><category term="MS09-047" /><category term="Gmail" /><category term="sophos" /><category term="XML" /><category term="ASCII85Decode" /><category term="blizzard" /><category term="Media Player" /><category term="hacker" /><category term="Pac-Man" /><category term="DirectShow" /><category term="BankOfAmerica" /><category term="email scam" /><category term="a0v.org" /><category term="MPEG2" /><category term="hacked" /><category term="Mebroot" /><category term="ThreatExpert" /><category term="Security News" /><category term="IE8" /><category term="Actns/Swif.T" /><category term="hsbc" /><category term="DDos" /><category term="astalavista" /><category term="MS09-001" /><category term="Trojan" /><category term="Clickjacking" /><category term="Hardy" /><category term="FlateDecode" /><category term="getIcon" /><category term="JavaScript" /><category term="acer" /><category term="XSS" /><category term="Toolbars" /><category term="MS09-019" /><category term="Robtex" /><category term="HTML entity" /><category term="HyperVM" /><category term="SecurID" /><category term="weight loss" /><category term="Malzilla" /><category term="skype" /><category term="ord()" /><category term="youtube" /><category term="spidermonkey" /><category term="MS09-018" /><category term="webromi" /><category term="Security" /><category term="Hotmail" /><category term="replica" /><category term="MS09-020" /><category term="python" /><category term="malwares" /><category term="cut" /><category term="Obfuscation" /><category term="ecard" /><category term="Own3d" /><category term="Android" /><category term="jsunpack" /><category term="Yahoo" /><category term="Pharmaceutic" /><category term="malaysia today" /><category term="phpAdmin" /><category term="Cheapware" /><category term="/ASCIIHexDecode" /><category term="research" /><category term="milw0rm" /><category term="OWA" /><category term="Nobel" /><category term="Ms09-014" /><category term="valentine" /><category term="Stuxnet" /><category term="971778" /><category term="Java" /><category term="OWC10.Spreadsheet" /><category term="VLC" /><category term="CVE-2011-2105" /><category term="Office Snapshot Viewer" /><category term="flash exploit" /><category term="BDATuningModelMPEG2TuneReques" /><category term="OLEDB32.dll" /><category term="antivirus" /><category term="Bitdefender" /><category term="rogue" /><category term="cloud-malware" /><category term="SEO" /><category term="fireshark" /><category term="Penetration" /><category term="monkeywrench" /><category term="Cross-Zone Scripting" /><category term="Zeus" /><category term="Heap Spray" /><category term="malaysiakini.com" /><category term="defaced" /><category term="Botnet" /><category term="IE" /><category term="fakecodec" /><category term="article" /><category term="TLS" /><category term="MS09-021" /><title>Web2Secure: Web Security Blog</title><subtitle type="html">We are non-funded group of security enthusiast who contributes and updates to community with latest security treats. Use and handle whatever links shared within website could be harmful to your systems with own risks. Feel free to use the contents for commercial or non-commercial purposes. We're very appreciating if using our useful information’s to your website by referring back to this original website. Donation or clicking on ads is most welcome to continue maintains costs for this website.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.web2secure.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.web2secure.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>470</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/WebSecurityWeblog" /><feedburner:info uri="websecurityweblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by/2.0/" /><feedburner:emailServiceId>WebSecurityWeblog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;CkAMQn0yfCp7ImA9WhRUFk8.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-686630364133159427</id><published>2012-01-26T15:33:00.000-08:00</published><updated>2012-01-26T15:33:03.394-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-26T15:33:03.394-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="compromised" /><category scheme="http://www.blogger.com/atom/ns#" term="Security News" /><category scheme="http://www.blogger.com/atom/ns#" term="websense" /><category scheme="http://www.blogger.com/atom/ns#" term="Google Chrome" /><title>Searching for Google Chrome can lead to malicious content</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Searching "Google Chrome" in Google search engine will end with potential malicious infection. This alert has been reported at &lt;a href="http://community.websense.com/blogs/securitylabs/archive/2012/01/23/search-for-google-chrome-leads-to-compromised-chrome-plugin-forum.aspx"&gt;Websense&lt;/a&gt; &amp;nbsp;Researcher.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-euB0mduVBOI/TyHiWxZnAGI/AAAAAAAABJQ/CLTV4PFZxuU/s1600/chrome-pl-compromise.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-euB0mduVBOI/TyHiWxZnAGI/AAAAAAAABJQ/CLTV4PFZxuU/s320/chrome-pl-compromise.jpg" width="279" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
According from founding,&amp;nbsp;The domain (&lt;i&gt;chromeplugins.com&lt;/i&gt;) has been registered in 2008, indicating that the website - an unofficial Google Chrome plugin forum - is legitimate. This website was compromised with fake AdSense "show_ads.js".&lt;br /&gt;
&lt;br /&gt;
Fake&amp;nbsp;"show_ads.js"&amp;nbsp;host in&amp;nbsp;pagead2.googlesynd&lt;u&gt;l&lt;/u&gt;cation.com". -&amp;nbsp;pagead2.googlesyndlcation.com/pagead/show_ads.js&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-686630364133159427?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Elqe6LSRIx0yJdHDsKeqJONyOGE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Elqe6LSRIx0yJdHDsKeqJONyOGE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Elqe6LSRIx0yJdHDsKeqJONyOGE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Elqe6LSRIx0yJdHDsKeqJONyOGE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/-CmS_AMJJKY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/686630364133159427/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=686630364133159427" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/686630364133159427?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/686630364133159427?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/-CmS_AMJJKY/searching-for-google-chrome-can-lead-to.html" title="Searching for Google Chrome can lead to malicious content" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-euB0mduVBOI/TyHiWxZnAGI/AAAAAAAABJQ/CLTV4PFZxuU/s72-c/chrome-pl-compromise.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2012/01/searching-for-google-chrome-can-lead-to.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0ADQngyeCp7ImA9WhRVEkk.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5667485246847839225</id><published>2012-01-10T18:42:00.000-08:00</published><updated>2012-01-10T18:42:53.690-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-10T18:42:53.690-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft Patch Tuesday" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><title>Microsoft Patch Tuesday - January 2012</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
Microsoft today released first batch of patches to fix their products security flaws for January 2012. Micorsoft released seven security bulletins addressing eight vulnerabilitis in Windows. Vulnerabilities in Windows Media rated as Critical severity. The remaining rated as Important.&lt;br /&gt;
&lt;br /&gt;
Summary of Microsof of January releases can be found at &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan"&gt;http://technet.microsoft.com/en-us/security/bulletin/ms12-jan&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-001"&gt;MS12-001&lt;/a&gt;: Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615)&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.This patch counter &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0001"&gt;CVE-2012-0001&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-002"&gt;MS12-002&lt;/a&gt;: Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. This patch counter &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0009"&gt;CVE-2012-0009&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-003"&gt;MS12-003&lt;/a&gt;: Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
This security update resolves one privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. All supported editions of Windows 7 and Windows Server 2008 R2 are not affected by this vulnerability. This could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application.This patch counter &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0005"&gt;CVE-2012-0005&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-004"&gt;MS12-004&lt;/a&gt;: Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This patch counter &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0003"&gt;CVE-2012-0003&lt;/a&gt; and &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0004"&gt;CVE-2012-0004&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&amp;nbsp;&lt;a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-005"&gt;MS12-005&lt;/a&gt;: Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. This patch counter &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0013"&gt;CVE-2012-0013&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&amp;nbsp;&lt;a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-006"&gt;MS12-006&lt;/a&gt; Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected. This patch counter &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389"&gt;CVE-2011-3389&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&amp;nbsp;&lt;a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-007"&gt;MS12-007&lt;/a&gt;: Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker’s user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.This patch counter &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0007"&gt;CVE-2012-0007&lt;/a&gt;.&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5667485246847839225?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/l844mrv3l5M4mHjS50w1yh7Uv_4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/l844mrv3l5M4mHjS50w1yh7Uv_4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/l844mrv3l5M4mHjS50w1yh7Uv_4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/l844mrv3l5M4mHjS50w1yh7Uv_4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/6J_xWfbBxZ8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5667485246847839225/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5667485246847839225" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5667485246847839225?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5667485246847839225?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/6J_xWfbBxZ8/microsoft-patch-tuesday-january-2012.html" title="Microsoft Patch Tuesday - January 2012" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2012/01/microsoft-patch-tuesday-january-2012.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAESHg_eip7ImA9WhRXFEU.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-7696481654315886053</id><published>2011-12-20T07:48:00.000-08:00</published><updated>2011-12-21T07:51:49.642-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-21T07:51:49.642-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Bogus" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><category scheme="http://www.blogger.com/atom/ns#" term="suspicious" /><title>Suspicious and Spam Link 20-Dec-2011</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
121.11.80.161&lt;br /&gt;
&lt;br /&gt;
adobe-reader-2012.com&lt;br /&gt;
official-reader-upgrade.com&lt;br /&gt;
online-direct-tv.com&lt;br /&gt;
pay4yourdomain.com&lt;br /&gt;
pdf-adobe-2012.com&lt;br /&gt;
sslgateway-signup.com&lt;br /&gt;
official-reader-upgrade.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
209.112.247.144&lt;br /&gt;
&lt;br /&gt;
mail.e4.net&lt;br /&gt;
mail.oceansideurc.org&lt;br /&gt;
mail.onsolidrock.org&lt;br /&gt;
mail.whyibelieve.org&lt;br /&gt;
onsolidrock.org&lt;br /&gt;
preferredresources.info&lt;br /&gt;
raq53.dnssys.com&lt;br /&gt;
real-player-superpass.com&lt;br /&gt;
strategicdeviance.com&lt;br /&gt;
whyibelieve.org&lt;br /&gt;
www.basket-lady.com&lt;br /&gt;
www-adobe-reader.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
194.28.158.153&lt;br /&gt;
&lt;br /&gt;
secure.signup-page.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
85.234.236.21&lt;br /&gt;
&lt;br /&gt;
adobe-acrobat.org&lt;br /&gt;
adobe-reader.es&lt;br /&gt;
adobe-reader.nl&lt;br /&gt;
adobe-reader8.com&lt;br /&gt;
dividendpagina.nl&lt;br /&gt;
hobbydoos.nl&lt;br /&gt;
wolhemel.com&lt;br /&gt;
www.dividendpagina.nl&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
46.105.150.218&lt;br /&gt;
&lt;br /&gt;
adobe-reader.softlate.com&lt;br /&gt;
softlate.com&lt;br /&gt;
softlatedownloads.com&lt;br /&gt;
www.softlate.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-ZxISnR4jN0Q/TvIATFvt5BI/AAAAAAAABI4/0Nmo47Q-FFw/s1600/signup-page.com.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://3.bp.blogspot.com/-ZxISnR4jN0Q/TvIATFvt5BI/AAAAAAAABI4/0Nmo47Q-FFw/s320/signup-page.com.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-IJNPrvxxpIc/TvIAVt_7eJI/AAAAAAAABJA/ZgiHVSEIe6Q/s1600/www-adobe-reader.com.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://3.bp.blogspot.com/-IJNPrvxxpIc/TvIAVt_7eJI/AAAAAAAABJA/ZgiHVSEIe6Q/s320/www-adobe-reader.com.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-NWgMAPzCZME/TvIAW4saXpI/AAAAAAAABJI/vKtktZLYS5I/s1600/www-adobe-reader.com1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://3.bp.blogspot.com/-NWgMAPzCZME/TvIAW4saXpI/AAAAAAAABJI/vKtktZLYS5I/s320/www-adobe-reader.com1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-7696481654315886053?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/mSk7cpCiXIxzpt6CQRpmW_Xcd0M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mSk7cpCiXIxzpt6CQRpmW_Xcd0M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/mSk7cpCiXIxzpt6CQRpmW_Xcd0M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mSk7cpCiXIxzpt6CQRpmW_Xcd0M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/UK25VJYEJvc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/7696481654315886053/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=7696481654315886053" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7696481654315886053?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7696481654315886053?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/UK25VJYEJvc/suspicious-and-spam-link-20-dec-2011.html" title="Suspicious and Spam Link 20-Dec-2011" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-ZxISnR4jN0Q/TvIATFvt5BI/AAAAAAAABI4/0Nmo47Q-FFw/s72-c/signup-page.com.PNG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/12/suspicious-and-spam-link-20-dec-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUCQHw_cCp7ImA9WhRRGU4.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-7761814509212963748</id><published>2011-12-03T10:04:00.001-08:00</published><updated>2011-12-03T10:17:41.248-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-03T10:17:41.248-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="0Day" /><category scheme="http://www.blogger.com/atom/ns#" term="Security News" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Yahoo" /><title>New Yahoo Messenger 0-Day Exploit Hijacks User's Status Update</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
Malware spread via Yahoo Instant Messenger has been around for years. Infection, though, has been limited by the fact that it requires some interaction with the user.&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
Not anymore.&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
A newly discovered&amp;nbsp;exploit&amp;nbsp;in version 11.x of the Messenger client (including the freshly-released 11.5.0.152-us) allows a remote attacker to arbitrarily change the status message of virtually any Yahoo Messenger user that runs the vulnerable version.&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
&lt;strong&gt;How does it work?&lt;/strong&gt;&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
The status message change occurs when an attacker simulates sending a file to a user. This action manipulates the $InlineAction parameter (responsible for the way the Messenger form displays the accept or deny the transfer) in order to load an iFrame which, when loaded, swaps the status message for the attacker's custom text. This status may also include a dubious link. This iFrame is sent as a regular message and comes from another Yahoo Instant Messenger user, even if the user is not in the victim’s contact list.&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
&lt;a href="http://www.malwarecity.com/blog/new-yahoo-messenger-0-day-exploit-hijacks-users-status-update-1229.html"&gt;Read Full More Here&lt;/a&gt;.&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-yolCQvAR7c8/Ttpnpx30zrI/AAAAAAAABIw/E1rA6iizL7I/s1600/yahoo-messenger.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-yolCQvAR7c8/Ttpnpx30zrI/AAAAAAAABIw/E1rA6iizL7I/s1600/yahoo-messenger.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="background-color: white; color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 14px; text-align: -webkit-auto;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-7761814509212963748?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/X9DRCko8L1CPoY0NWQMqJySXBe4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/X9DRCko8L1CPoY0NWQMqJySXBe4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/X9DRCko8L1CPoY0NWQMqJySXBe4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/X9DRCko8L1CPoY0NWQMqJySXBe4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/L3B_mm6RMSc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/7761814509212963748/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=7761814509212963748" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7761814509212963748?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7761814509212963748?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/L3B_mm6RMSc/new-yahoo-messenger-0-day-exploit.html" title="New Yahoo Messenger 0-Day Exploit Hijacks User's Status Update" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-yolCQvAR7c8/Ttpnpx30zrI/AAAAAAAABIw/E1rA6iizL7I/s72-c/yahoo-messenger.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/12/new-yahoo-messenger-0-day-exploit.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAESHk8eCp7ImA9WhRRE08.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-6843692197853104687</id><published>2011-11-26T07:40:00.001-08:00</published><updated>2011-11-26T07:51:49.770-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-26T07:51:49.770-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CVE-2011-4317" /><category scheme="http://www.blogger.com/atom/ns#" term="PoC" /><category scheme="http://www.blogger.com/atom/ns#" term="Apache" /><title>Apache HTTP Server Reverse Proxy - CVE-2011-4317</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Engineer from Qualys Security Labs discovered&amp;nbsp;vulnerability in Apache HTTP Server Reverse Proxy/Rewrite URL Validation during creating vulnerability signature for&amp;nbsp;CVE-2011-3368.&lt;br /&gt;
&lt;br /&gt;
The weakness is caused due to the mod_proxy module, when configured in reverse proxy mode, incorrectly processing certain web requests. This can be exploited to send requests to an unintended server behind the proxy via a specially crafted URL.&lt;br /&gt;
&lt;br /&gt;
Full Details with PoC&lt;br /&gt;
&lt;a href="https://community.qualys.com/blogs/securitylabs/2011/11/23/apache-reverse-proxy-bypass-issue"&gt;https://community.qualys.com/blogs/securitylabs/2011/11/23/apache-reverse-proxy-bypass-issue&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
WorkAround:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-collapse: collapse; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #4b4b4b; font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: 17px; list-style-image: initial; list-style-position: initial; list-style-type: none; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;
Apache has not yet released a patch for this issue. Until a patch is release, configuring the reverse proxy rules correctly will prevent this issue from occurring. For example, in the above case, if the reverse proxy rules are configured as follows, the proof of concept will not work.&lt;/div&gt;
&lt;div style="-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-collapse: collapse; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #4b4b4b; font-family: Arial, Helvetica, sans-serif; font-size: 13px; height: 8pt; line-height: 17px; list-style-image: initial; list-style-position: initial; list-style-type: none; min-height: 8pt; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;pre class="jive-pre" style="-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; background-attachment: initial; background-clip: initial; background-color: white; background-image: url(https://community.qualys.com/4.5.5/images/jive-bg-pre.gif); background-origin: initial; background-repeat: repeat repeat; border-bottom-color: rgb(238, 238, 238); border-bottom-style: solid; border-bottom-width: 1px; border-collapse: collapse; border-color: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 2px; border-right-color: rgb(238, 238, 238); border-right-style: solid; border-right-width: 1px; border-style: initial; border-top-color: rgb(238, 238, 238); border-top-style: solid; border-top-width: 1px; color: #4b4b4b; font-size: 1.2em; line-height: 17px; list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 10px; margin-left: 20px; margin-right: 20px; margin-top: 10px; outline-color: initial; outline-style: initial; outline-width: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 10px; padding-left: 10px; padding-right: 10px; padding-top: 10px; width: auto;"&gt;&lt;code class="jive-code" style="-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-collapse: collapse; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-size: 1em; list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;RewriteRule ^(.*) http://10.40.2.159/$1
ProxyPassMatch ^(.*) http://10.40.2.159/$1&lt;/code&gt;&lt;/pre&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-6843692197853104687?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/MpZCkzGW4PbMx5tTISUxVlOIFYc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MpZCkzGW4PbMx5tTISUxVlOIFYc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/MpZCkzGW4PbMx5tTISUxVlOIFYc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MpZCkzGW4PbMx5tTISUxVlOIFYc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/e_xHyfOv8Yc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/6843692197853104687/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=6843692197853104687" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6843692197853104687?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6843692197853104687?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/e_xHyfOv8Yc/apache-http-server-reverse-proxy-cve.html" title="Apache HTTP Server Reverse Proxy - CVE-2011-4317" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.web2secure.com/2011/11/apache-http-server-reverse-proxy-cve.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQCQ386eip7ImA9WhdaEE0.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-8138867766092727272</id><published>2011-10-18T23:55:00.000-07:00</published><updated>2011-10-18T23:56:02.112-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-18T23:56:02.112-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Stuxnet" /><category scheme="http://www.blogger.com/atom/ns#" term="Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Duqu" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><title>Next Stuxnet : Duqu</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
Researchers obtained new type of Stuxnet new virus called "Duqu". This remote acces Trojan (RAT) does not contain any code related to industrail control systems. The threat does not self-replicate.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;
Our telemetry shows the threat was highly targeted toward a limited number of organizations for their specific assets.Duqu uses HTTP and HTTPS to communicate with a command-and-control (C&amp;amp;C) server that at the time of writing is still operational. The attackers were able to download additional executables through the C&amp;amp;C server, including an infostealer that can perform actions such as enumerating the network, recording keystrokes, and gathering system information. The information is logged to a lightly encrypted and compressed local file, which then must be exfiltrated out.&lt;br /&gt;&lt;b&gt;Key points:&lt;/b&gt;&lt;br /&gt;• &amp;nbsp; &amp;nbsp;Executables using the Stuxnet source code have been discovered. They appear to have been developed since the last Stuxnet file was recovered.&lt;br /&gt;• &amp;nbsp; &amp;nbsp;The executables are designed to capture information such as keystrokes and system information.&lt;br /&gt;• &amp;nbsp; &amp;nbsp;Current analysis shows no code related to industrial control systems, exploits, or self-replication.&lt;br /&gt;• &amp;nbsp; &amp;nbsp;The executables have been found in a limited number of organizations, including those involved in the manufacturing of industrial control systems.&lt;br /&gt;• &amp;nbsp; &amp;nbsp;The exfiltrated data may be used to enable a future Stuxnet-like attack.&lt;/blockquote&gt;
&lt;br /&gt;
Reference:&lt;br /&gt;
&lt;br /&gt;
W32.Duqu: The Precursor to the Next Stuxnet &lt;a href="http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet"&gt;http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;
McAfee said that the Duqu worm has been identified in "professional, targeted attacks" against CAs in parts of Europe, the Middle East, Asia and Africa. The researchers speculate that a digital certificate belonging to the firm C-Media, based in Taipei, was not stolen, but forged by a compromised CA.&lt;br /&gt;The McAfee analysis fills in some details omitted from a longer analysis released by Symantec Corp on Tuesday. That research declined to name the kind of firm targeted by the worm, but provided a detailed analysis of the Duqu code, which bears a close resemblance to Stuxnet, with shared code used for the injection attack and several encryption keys and techniques that were used in Stuxnet.&lt;br /&gt;Like Symantec's report, the analysis from McAfee says that it knows of only a few infections linked to Duqu, and says the worm doesn't appear to be designed to attack industrial control systems, as Stuxnet was.&amp;nbsp;&lt;/blockquote&gt;
&lt;br /&gt;
Reference:&lt;br /&gt;
The Day of the Golden Jackal – The Next Tale in the Stuxnet Files: Duqu&lt;br /&gt;
&lt;a href="https://blogs.mcafee.com/mcafee-labs/the-day-of-the-golden-jackal-%E2%80%93-further-tales-of-the-stuxnet-file"&gt;https://blogs.mcafee.com/mcafee-labs/the-day-of-the-golden-jackal-%E2%80%93-further-tales-of-the-stuxnet-file&lt;/a&gt;s&lt;br /&gt;
&lt;br /&gt;
&lt;span class="rss:item"&gt;Another Cyber Security company, F-Secure Security Labs also posted related "Duqu" on its websites.&lt;/span&gt;&lt;br /&gt;
&lt;span class="rss:item"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;blockquote&gt;
&lt;span class="rss:item"&gt;Unlike Stuxnet, the new backdoor, known as &lt;span style="font-weight: bold;"&gt;Duqu&lt;/span&gt;,
 does not target automation or PLC gear. Instead, it's used for 
reconnaissance. Duqu collects various types of information from infected
 systems for a future attack. It's possible we'll eventually see a new 
attack targeting PLC systems, based on the information gathered by Duqu.&lt;/span&gt;&lt;span class="rss:item"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="rss:item"&gt;The
 code similarities between Duqu and Stuxnet are obvious. Duqu's kernel 
driver (JMINET7.SYS) is actually so similar to Stuxnet's driver 
(MRXCLS.SYS) that our back-end systems actually thought it's Stuxnet:&lt;/span&gt;&lt;/blockquote&gt;
&lt;span class="rss:item"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="rss:item"&gt;Reference:&lt;/span&gt;&lt;br /&gt;
&lt;span class="rss:item"&gt;Duqu - Stuxnet 2&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://www.f-secure.com/weblog/archives/00002255.html"&gt;http://www.f-secure.com/weblog/archives/00002255.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Additional Detail about "Duqu" by Symantec can be obtained here [&lt;a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet.pdf"&gt;PDF&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-8138867766092727272?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xs3AxXGLyKXTuZaLLtsXhz4L3w0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xs3AxXGLyKXTuZaLLtsXhz4L3w0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xs3AxXGLyKXTuZaLLtsXhz4L3w0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xs3AxXGLyKXTuZaLLtsXhz4L3w0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/M4K-LZoGmLw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/8138867766092727272/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=8138867766092727272" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8138867766092727272?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8138867766092727272?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/M4K-LZoGmLw/next-stuxnet-duqu.html" title="Next Stuxnet : Duqu" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/10/next-stuxnet-duqu.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQERns9eSp7ImA9WhdbFU0.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-3698063252699027779</id><published>2011-10-13T05:01:00.000-07:00</published><updated>2011-10-13T05:01:47.561-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-13T05:01:47.561-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="Security News" /><category scheme="http://www.blogger.com/atom/ns#" term="DefCon" /><title>DefCon 19 DVD now online download</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
For those who missed the presentation/talk session during DefCon 19, DefCon so kind to post DEF CON 19 DVD content media in 2 iso images.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-yCjOaF5zlYw/TpbSsD46EoI/AAAAAAAABIo/XF0foQT_YRY/s1600/events-defcon2010.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-yCjOaF5zlYw/TpbSsD46EoI/AAAAAAAABIo/XF0foQT_YRY/s1600/events-defcon2010.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Download them at the following links. :)&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Verdana, FreeSans, sans-serif; font-size: 13px; line-height: 22px;"&gt;&lt;a href="https://media.defcon.org/dc-19/defcon-19-dvd-original.iso" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #999999; font-size: 13px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;" title="DEF CON 19 DVD - original"&gt;https://media.defcon.org/dc-19/defcon-19-dvd-original.iso&lt;/a&gt;&amp;nbsp;(~1.6 GB)&lt;br /&gt;&lt;a href="https://media.defcon.org/dc-19/defcon-19-dvd-updated.iso" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #999999; font-size: 13px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;" title="DEF CON 19 DVD - updated"&gt;https://media.defcon.org/dc-19/defcon-19-dvd-updated.iso&lt;/a&gt;&amp;nbsp;(~1.7 GB)&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-3698063252699027779?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tppYBORz-5gtSi90i5OzpN8HLd0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tppYBORz-5gtSi90i5OzpN8HLd0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tppYBORz-5gtSi90i5OzpN8HLd0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tppYBORz-5gtSi90i5OzpN8HLd0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/x5q5RWep98g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/3698063252699027779/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=3698063252699027779" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3698063252699027779?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3698063252699027779?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/x5q5RWep98g/defcon-19-dvd-now-online-download.html" title="DefCon 19 DVD now online download" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-yCjOaF5zlYw/TpbSsD46EoI/AAAAAAAABIo/XF0foQT_YRY/s72-c/events-defcon2010.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/10/defcon-19-dvd-now-online-download.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUEFQX06eSp7ImA9WhdbFE0.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-1168512515775633695</id><published>2011-10-12T01:20:00.000-07:00</published><updated>2011-10-12T01:20:10.311-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-12T01:20:10.311-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="email scam" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><category scheme="http://www.blogger.com/atom/ns#" term="blizzard" /><title>Blizzard Phishing Emails Scam 12-Oct-11</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 18px;"&gt;Host names&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 18px;"&gt;neighbor for&lt;/span&gt;173.234.243.61&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
517ks.com&lt;br /&gt;
admin-wow.net&lt;br /&gt;
anshan521.com&lt;br /&gt;
at853.com&lt;br /&gt;
at853.net&lt;br /&gt;
catuba.org&lt;br /&gt;
game-10086.com&lt;br /&gt;
host64.yydns.net&lt;br /&gt;
newsletteraccount.net&lt;br /&gt;
us.battle.net.worldofwarcraft.com.admin-war.net&lt;br /&gt;
wouting.net&lt;br /&gt;
www.admin-wow.net&lt;br /&gt;
www.at853.com&lt;br /&gt;
www.at853.net&lt;br /&gt;
www.blizzard-battle.net&lt;br /&gt;
us.battle.net.en.iqzl.co.cc&lt;br /&gt;
www.blizzardnet-en.co.cc&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 18px;"&gt;Host names neighbor for&amp;nbsp;&lt;/span&gt;10.10.10.10&lt;br /&gt;
&lt;br /&gt;
2a.72hg.com&lt;br /&gt;
2a.bigboynetworks.com&lt;br /&gt;
3dyyzb.com&lt;br /&gt;
abbsza.com&lt;br /&gt;
abbza.info&lt;br /&gt;
abbza.org&lt;br /&gt;
abbza.us&lt;br /&gt;
abbzaonline.com&lt;br /&gt;
ad.ath.bielsko.pl&lt;br /&gt;
adams.plus.ru&lt;br /&gt;
agecs.com&lt;br /&gt;
agetresa.com&lt;br /&gt;
alainze.no-ip.biz&lt;br /&gt;
aq0.softex.ru&lt;br /&gt;
arai.owner.linuxmaster.co.cc&lt;br /&gt;
arg.hopto.org&lt;br /&gt;
bacha.chutiya.co.cc&lt;br /&gt;
bcsmcs.co.cc&lt;br /&gt;
bhagyashree.co.cc&lt;br /&gt;
bharwa.ghashti.ka.bacha.chutiya.co.cc&lt;br /&gt;
bilik.cn&lt;br /&gt;
brokerdirect.com&lt;br /&gt;
bugzilla.allenpress.com&lt;br /&gt;
cafeislam.co.cc&lt;br /&gt;
calre1.com&lt;br /&gt;
cannaiolo.sytes.net&lt;br /&gt;
changewccc.com&lt;br /&gt;
changhesd.com&lt;br /&gt;
chutiya.co.cc&lt;br /&gt;
chuyenthamkin.co.cc&lt;br /&gt;
cobalt1.myftp.org&lt;br /&gt;
core-rs1.thdo.ncuk.net&lt;br /&gt;
dalla.kunjer.bharwa.ghashti.ka.bacha.chutiya.co.cc&lt;br /&gt;
dena.razi.ac.ir&lt;br /&gt;
dj-dj.no-ip.org&lt;br /&gt;
drive-megawheels.net&lt;br /&gt;
erouterzone.net&lt;br /&gt;
estrim.ru&lt;br /&gt;
etali.de&lt;br /&gt;
evanj8.co.cc&lt;br /&gt;
exe.redirectme.net&lt;br /&gt;
exicorp.co.cc&lt;br /&gt;
facebook.co.cc&lt;br /&gt;
fendermfg.com&lt;br /&gt;
figo.servecounterstrike.com&lt;br /&gt;
financialbg.com&lt;br /&gt;
flowby.no-ip.org&lt;br /&gt;
fsxforum.co.cc&lt;br /&gt;
ftp.lainnet.lv&lt;br /&gt;
fuchme.com&lt;br /&gt;
fuchyou.com&lt;br /&gt;
gdk-vpn.co.cc&lt;br /&gt;
ghashti.ka.bacha.chutiya.co.cc&lt;br /&gt;
globalsit.com&lt;br /&gt;
golestanroad.net&lt;br /&gt;
gombel.co.cc&lt;br /&gt;
guapunye.nick.arai.owner.linuxmaster.co.cc&lt;br /&gt;
hot.k1ss.co.cc&lt;br /&gt;
igratatin.co.cc&lt;br /&gt;
ikutsukaakuisa.co.cc&lt;br /&gt;
infotechpro.info&lt;br /&gt;
innogroup-online.net&lt;br /&gt;
invalid.blueocean.com&lt;br /&gt;
itquan.org&lt;br /&gt;
jabbus.co.cc&lt;br /&gt;
jeff-dunham.co.cc&lt;br /&gt;
jiitnameserver.jiit.ac.in&lt;br /&gt;
k1ss.co.cc&lt;br /&gt;
ka.bacha.chutiya.co.cc&lt;br /&gt;
kawasakibusiness.com&lt;br /&gt;
kunjer.bharwa.ghashti.ka.bacha.chutiya.co.cc&lt;br /&gt;
lastfile.co.cc&lt;br /&gt;
limsadiane.co.cc&lt;br /&gt;
lincolncarlton.com&lt;br /&gt;
linuxmaster.co.cc&lt;br /&gt;
lootparty.com&lt;br /&gt;
lovemei.myftp.org&lt;br /&gt;
mail.72ym.com&lt;br /&gt;
mail.abbsza.com&lt;br /&gt;
mail.abbza.biz&lt;br /&gt;
mail.abbza.info&lt;br /&gt;
mail.abbza.org&lt;br /&gt;
mail.abbza.us&lt;br /&gt;
mail.abbzaonline.com&lt;br /&gt;
mail.behindtheblackboard.com&lt;br /&gt;
mail.environmentalhealthinc.com&lt;br /&gt;
mail.event-marketing-group.com&lt;br /&gt;
mail.fireservicetanks.com&lt;br /&gt;
mail.holowesko.net&lt;br /&gt;
mail.holoweskofund.com&lt;br /&gt;
mail.holoweskofund.net&lt;br /&gt;
mail.holoweskofunds.net&lt;br /&gt;
mail.holoweskoglobalfund.net&lt;br /&gt;
mail.holoweskoglobalfunds.com&lt;br /&gt;
mail.holoweskoglobalfunds.net&lt;br /&gt;
mail.i-you.net&lt;br /&gt;
mail.landmarkdistribution.com&lt;br /&gt;
mail.lap-service-bolsward.nl&lt;br /&gt;
mail.lsfsa.com&lt;br /&gt;
mail.markholowesko.com&lt;br /&gt;
mail.markholowesko.net&lt;br /&gt;
mail.mind-fullonline.com&lt;br /&gt;
mail.modularwheelchairramps.com&lt;br /&gt;
mail.stylebagno.it&lt;br /&gt;
mail.tomcatrecords.net&lt;br /&gt;
mail.transport2000-office.org.uk&lt;br /&gt;
mail.updatepaypals.com&lt;br /&gt;
mail1.test.argenta.be&lt;br /&gt;
mailnotifications.com&lt;br /&gt;
mdrdsp01.es.wh.verio.net&lt;br /&gt;
meirite.com&lt;br /&gt;
merlot.organicvintners.com&lt;br /&gt;
michaelwanderson.net&lt;br /&gt;
mobitech-forums.co.cc&lt;br /&gt;
moccainside.co.cc&lt;br /&gt;
morte.servebeer.com&lt;br /&gt;
mossurf.co.cc&lt;br /&gt;
mx.bgns.net&lt;br /&gt;
mx.yuxiaosuo.com&lt;br /&gt;
mx1.citadis-avignon.com&lt;br /&gt;
mx1.djangocom.net&lt;br /&gt;
mx1.nievre-amenagement.net&lt;br /&gt;
mx1.semaeb.net&lt;br /&gt;
mx1.semerap.net&lt;br /&gt;
mx2.alpine-isolation.net&lt;br /&gt;
mx2.djangocom.net&lt;br /&gt;
mx2.lacamiciaealtrivizi.com&lt;br /&gt;
mx2.modulgraficaonline.com&lt;br /&gt;
mx2.nievre-amenagement.net&lt;br /&gt;
mx2.relliance-partenaires.net&lt;br /&gt;
mx2.semaeb.net&lt;br /&gt;
mx2.semerap.net&lt;br /&gt;
mx2.spazzicatering.com&lt;br /&gt;
mycandeo.com&lt;br /&gt;
mycubaweb.com&lt;br /&gt;
neoclic-pro.com&lt;br /&gt;
nicejewishguys.com&lt;br /&gt;
nick.arai.owner.linuxmaster.co.cc&lt;br /&gt;
nj025.net&lt;br /&gt;
nomail.rasputin.de&lt;br /&gt;
nowhere.cais.net&lt;br /&gt;
null.fsrmail.com&lt;br /&gt;
ny1core01.erouterzone.net&lt;br /&gt;
organicvintners.com&lt;br /&gt;
otginsott.net&lt;br /&gt;
owner.linuxmaster.co.cc&lt;br /&gt;
pacar.yang.sangat.perhatian.co.cc&lt;br /&gt;
parsfr01.fr.wh.verio.net&lt;br /&gt;
pati.servebeer.com&lt;br /&gt;
perely.co.cc&lt;br /&gt;
perhatian.co.cc&lt;br /&gt;
philyves.net&lt;br /&gt;
picallo.co.cc&lt;br /&gt;
pprox.co.cc&lt;br /&gt;
primarydns.jalindia.co.in&lt;br /&gt;
proxy808.co.cc&lt;br /&gt;
prueba.etb.net.co&lt;br /&gt;
qqo9.com&lt;br /&gt;
rauchit.com&lt;br /&gt;
redbox.by&lt;br /&gt;
rocker.redirectme.net&lt;br /&gt;
romeodelta.net&lt;br /&gt;
sangat.perhatian.co.cc&lt;br /&gt;
sarek.com&lt;br /&gt;
securehostserver.com&lt;br /&gt;
serviziaziendali.net&lt;br /&gt;
shellinfo.no-ip.info&lt;br /&gt;
sith.ad.ath.bielsko.pl&lt;br /&gt;
smkn8mlg.co.cc&lt;br /&gt;
spousta.com&lt;br /&gt;
srv.cat&lt;br /&gt;
sushi.tdlab.ca&lt;br /&gt;
tdlab.ca&lt;br /&gt;
the-hirsts.net&lt;br /&gt;
torrentmovies.co.cc&lt;br /&gt;
tw2.no-ip.info&lt;br /&gt;
v-link.co.cc&lt;br /&gt;
vosmmscom.co.cc&lt;br /&gt;
vpn.net1.cc&lt;br /&gt;
w3.vmhome.com&lt;br /&gt;
wag-bill-smtp.waggonerstrucking.com&lt;br /&gt;
waggonerstrucking.com&lt;br /&gt;
wcccsucks.com&lt;br /&gt;
web44.co.cc&lt;br /&gt;
wow3.co.cc&lt;br /&gt;
www.chuyenthamkin.co.cc&lt;br /&gt;
www.etali.de&lt;br /&gt;
www.blizzard.car-fear.co.cc&lt;br /&gt;
www.facebook.co.cc&lt;br /&gt;
www.gcts.bh&lt;br /&gt;
www.retaj.com.bh&lt;br /&gt;
www.securehostserver.com&lt;br /&gt;
www.torrentmovies.co.cc&lt;br /&gt;
www.tu888.cn&lt;br /&gt;
xn--ferienwohnungen-rgen-5ec.net (ferienwohnungen-rügen.net)&lt;br /&gt;
xserve.carlton.sg&lt;br /&gt;
yang.sangat.perhatian.co.cc&lt;br /&gt;
yrphone.com&lt;br /&gt;
yuanmu.net&lt;br /&gt;
yzscale.com&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 18px;"&gt;Host names neighbor for:&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
112.175.243.21&lt;/div&gt;
&lt;div&gt;
112.175.243.22&lt;/div&gt;
&lt;div&gt;
112.175.243.24&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
10.lucasribeiro.co.cc&lt;/div&gt;
&lt;div&gt;
18cn.co.cc&lt;/div&gt;
&lt;div&gt;
24.10.lucasribeiro.co.cc&lt;/div&gt;
&lt;div&gt;
3adalat.co.cc&lt;/div&gt;
&lt;div&gt;
440amg.co.cc&lt;/div&gt;
&lt;div&gt;
airtelfun.co.cc&lt;/div&gt;
&lt;div&gt;
alynwap.co.cc&lt;/div&gt;
&lt;div&gt;
ambady.co.cc&lt;/div&gt;
&lt;div&gt;
anisomnia.co.cc&lt;/div&gt;
&lt;div&gt;
araup.co.cc&lt;/div&gt;
&lt;div&gt;
arteportugal.co.cc&lt;/div&gt;
&lt;div&gt;
articleinfo.co.cc&lt;/div&gt;
&lt;div&gt;
aspirincardio.co.cc&lt;/div&gt;
&lt;div&gt;
astrazeneca.co.cc&lt;/div&gt;
&lt;div&gt;
baby.d0ll.co.cc&lt;/div&gt;
&lt;div&gt;
baithuctap.co.cc&lt;/div&gt;
&lt;div&gt;
bangkok-hotels.co.cc&lt;/div&gt;
&lt;div&gt;
bayer-ah.co.cc&lt;/div&gt;
&lt;div&gt;
bayeraspirin.co.cc&lt;/div&gt;
&lt;div&gt;
bayerfull.co.cc&lt;/div&gt;
&lt;div&gt;
bayerhealthcare.co.cc&lt;/div&gt;
&lt;div&gt;
bayeryoungenvoy.co.cc&lt;/div&gt;
&lt;div&gt;
best-warez.co.cc&lt;/div&gt;
&lt;div&gt;
bestmusic4u.co.cc&lt;/div&gt;
&lt;div&gt;
blizzarwar.co.cc&lt;/div&gt;
&lt;div&gt;
bokepmurah.co.cc&lt;/div&gt;
&lt;div&gt;
campingalhassan.co.cc&lt;/div&gt;
&lt;div&gt;
cardio-bayer.co.cc&lt;/div&gt;
&lt;div&gt;
carolebayersager.co.cc&lt;/div&gt;
&lt;div&gt;
cbm64.co.cc&lt;/div&gt;
&lt;div&gt;
cbm64.strangled.net&lt;/div&gt;
&lt;div&gt;
cclmail.co.cc&lt;/div&gt;
&lt;div&gt;
chitthumyar.co.cc&lt;/div&gt;
&lt;div&gt;
cialislevitrasalesviagra.co.cc&lt;/div&gt;
&lt;div&gt;
cimahi.co.cc&lt;/div&gt;
&lt;div&gt;
coctail-host.co.cc&lt;/div&gt;
&lt;div&gt;
cyberwhitestar.co.cc&lt;/div&gt;
&lt;div&gt;
d0ll.co.cc&lt;/div&gt;
&lt;div&gt;
davidsaw.co.cc&lt;/div&gt;
&lt;div&gt;
diane-patenaude.co.cc&lt;/div&gt;
&lt;div&gt;
diane.co.cc&lt;/div&gt;
&lt;div&gt;
dianearbus.co.cc&lt;/div&gt;
&lt;div&gt;
dianebishtv.co.cc&lt;/div&gt;
&lt;div&gt;
dianekruger.co.cc&lt;/div&gt;
&lt;div&gt;
dianelanenude.co.cc&lt;/div&gt;
&lt;div&gt;
dianelovesbob-net.co.cc&lt;/div&gt;
&lt;div&gt;
dianestanley.co.cc&lt;/div&gt;
&lt;div&gt;
dianeturton.co.cc&lt;/div&gt;
&lt;div&gt;
dogs4u.co.cc&lt;/div&gt;
&lt;div&gt;
drocink.co.cc&lt;/div&gt;
&lt;div&gt;
ekoi.co.cc&lt;/div&gt;
&lt;div&gt;
englishpremierleague.co.cc&lt;/div&gt;
&lt;div&gt;
es-krim.co.cc&lt;/div&gt;
&lt;div&gt;
f.co.cc&lt;/div&gt;
&lt;div&gt;
femalelife.co.cc&lt;/div&gt;
&lt;div&gt;
filmesgratis.co.cc&lt;/div&gt;
&lt;div&gt;
folos.co.cc&lt;/div&gt;
&lt;div&gt;
friendster-music.co.cc&lt;/div&gt;
&lt;div&gt;
fullmusick.co.cc&lt;/div&gt;
&lt;div&gt;
gamebazaar.co.cc&lt;/div&gt;
&lt;div&gt;
getarticles.co.cc&lt;/div&gt;
&lt;div&gt;
gocthethao.co.cc&lt;/div&gt;
&lt;div&gt;
gudangrahasia.co.cc&lt;/div&gt;
&lt;div&gt;
h-pe.co.cc&lt;/div&gt;
&lt;div&gt;
hdytaufik.co.cc&lt;/div&gt;
&lt;div&gt;
hesitate.with.malaysian-hackers.co.cc&lt;/div&gt;
&lt;div&gt;
hk.co.cc&lt;/div&gt;
&lt;div&gt;
ibintechs.co.cc&lt;/div&gt;
&lt;div&gt;
ilavalai.co.cc&lt;/div&gt;
&lt;div&gt;
islamarket.co.cc&lt;/div&gt;
&lt;div&gt;
jammaah-mig33.co.cc&lt;/div&gt;
&lt;div&gt;
kecoakwap.co.cc&lt;/div&gt;
&lt;div&gt;
kn4h.co.cc&lt;/div&gt;
&lt;div&gt;
kutopersada.co.cc&lt;/div&gt;
&lt;div&gt;
lanxess-europe.co.cc&lt;/div&gt;
&lt;div&gt;
lanxess.co.cc&lt;/div&gt;
&lt;div&gt;
law4u.co.cc&lt;/div&gt;
&lt;div&gt;
leechouse.co.cc&lt;/div&gt;
&lt;div&gt;
lenadianejennings-blogspot.co.cc&lt;/div&gt;
&lt;div&gt;
levitravardenafilhcl.co.cc&lt;/div&gt;
&lt;div&gt;
ljcbraga.co.cc&lt;/div&gt;
&lt;div&gt;
look.sexy.with.baby.d0ll.co.cc&lt;/div&gt;
&lt;div&gt;
mail.chitthumyar.co.cc&lt;/div&gt;
&lt;div&gt;
mail.co.cc&lt;/div&gt;
&lt;div&gt;
mail.kecoakwap.co.cc&lt;/div&gt;
&lt;div&gt;
mail.name-server.co.cc&lt;/div&gt;
&lt;div&gt;
mail.pvpdestiny.co.cc&lt;/div&gt;
&lt;div&gt;
malaysian-hackers.co.cc&lt;/div&gt;
&lt;div&gt;
marshadianearnold.co.cc&lt;/div&gt;
&lt;div&gt;
mastigalaxy.co.cc&lt;/div&gt;
&lt;div&gt;
maturecunt.veronichka.co.cc&lt;/div&gt;
&lt;div&gt;
mayanks.co.cc&lt;/div&gt;
&lt;div&gt;
me.hot.k1ss.co.cc&lt;/div&gt;
&lt;div&gt;
melupakanmu.co.cc&lt;/div&gt;
&lt;div&gt;
mobifriendz4m.co.cc&lt;/div&gt;
&lt;div&gt;
mobile4m.co.cc&lt;/div&gt;
&lt;div&gt;
moneysukh.co.cc&lt;/div&gt;
&lt;div&gt;
mp3.co.cc&lt;/div&gt;
&lt;div&gt;
my-exploit.co.cc&lt;/div&gt;
&lt;div&gt;
name-server.co.cc&lt;/div&gt;
&lt;div&gt;
nanangs.co.cc&lt;/div&gt;
&lt;div&gt;
navanblog.co.cc&lt;/div&gt;
&lt;div&gt;
nestle-gifts.co.cc&lt;/div&gt;
&lt;div&gt;
nestle-icecream.co.cc&lt;/div&gt;
&lt;div&gt;
nestle-waters.co.cc&lt;/div&gt;
&lt;div&gt;
nestle.co.cc&lt;/div&gt;
&lt;div&gt;
newskhitpyaing.co.cc&lt;/div&gt;
&lt;div&gt;
ns1.bangkok-hotels.co.cc&lt;/div&gt;
&lt;div&gt;
osamax.co.cc&lt;/div&gt;
&lt;div&gt;
outerxcircle.co.cc&lt;/div&gt;
&lt;div&gt;
p2p101.co.cc&lt;/div&gt;
&lt;div&gt;
pernah.melupakanmu.co.cc&lt;/div&gt;
&lt;div&gt;
pkfc.co.cc&lt;/div&gt;
&lt;div&gt;
pvpdestiny.co.cc&lt;/div&gt;
&lt;div&gt;
r-o-o-t.co.cc&lt;/div&gt;
&lt;div&gt;
radiowahrheit.co.cc&lt;/div&gt;
&lt;div&gt;
rafaelius.co.cc&lt;/div&gt;
&lt;div&gt;
rapiddown.co.cc&lt;/div&gt;
&lt;div&gt;
rawbeen.co.cc&lt;/div&gt;
&lt;div&gt;
realoiltd.co.cc&lt;/div&gt;
&lt;div&gt;
richardwalean.co.cc&lt;/div&gt;
&lt;div&gt;
rumbayan.co.cc&lt;/div&gt;
&lt;div&gt;
salon-net.co.cc&lt;/div&gt;
&lt;div&gt;
saurav.co.cc&lt;/div&gt;
&lt;div&gt;
sawa7.co.cc&lt;/div&gt;
&lt;div&gt;
sexy.with.baby.d0ll.co.cc&lt;/div&gt;
&lt;div&gt;
shibukg.co.cc&lt;/div&gt;
&lt;div&gt;
smppanderman.co.cc&lt;/div&gt;
&lt;div&gt;
stylweb.co.cc&lt;/div&gt;
&lt;div&gt;
sweet-memoriez.co.cc&lt;/div&gt;
&lt;div&gt;
sweetlady.co.cc&lt;/div&gt;
&lt;div&gt;
techcenter-lanxess.co.cc&lt;/div&gt;
&lt;div&gt;
thebayerfamily-blogspot.co.cc&lt;/div&gt;
&lt;div&gt;
uatu.co.cc&lt;/div&gt;
&lt;div&gt;
undernet-mafia.co.cc&lt;/div&gt;
&lt;div&gt;
veronichka.co.cc&lt;/div&gt;
&lt;div&gt;
viancom.co.cc&lt;/div&gt;
&lt;div&gt;
viuu.co.cc&lt;/div&gt;
&lt;div&gt;
vlrb.co.cc&lt;/div&gt;
&lt;div&gt;
walean.co.cc&lt;/div&gt;
&lt;div&gt;
webkontes.co.cc&lt;/div&gt;
&lt;div&gt;
williambayer.co.cc&lt;/div&gt;
&lt;div&gt;
wiredtree.co.cc&lt;/div&gt;
&lt;div&gt;
with.baby.d0ll.co.cc&lt;/div&gt;
&lt;div&gt;
with.malaysian-hackers.co.cc&lt;/div&gt;
&lt;div&gt;
woman-fucking-animals.veronichka.co.cc&lt;/div&gt;
&lt;div&gt;
www.18cn.co.cc&lt;/div&gt;
&lt;div&gt;
www.3adalat.co.cc&lt;/div&gt;
&lt;div&gt;
www.araup.co.cc&lt;/div&gt;
&lt;div&gt;
www.astrazeneca.co.cc&lt;/div&gt;
&lt;div&gt;
www.bayer-ah.co.cc&lt;/div&gt;
&lt;div&gt;
www.bayerfull.co.cc&lt;/div&gt;
&lt;div&gt;
www.bokepmurah.co.cc&lt;/div&gt;
&lt;div&gt;
www.cardio-bayer.co.cc&lt;/div&gt;
&lt;div&gt;
www.cialislevitrasalesviagra.co.cc&lt;/div&gt;
&lt;div&gt;
www.diane-patenaude.co.cc&lt;/div&gt;
&lt;div&gt;
www.dianebishtv.co.cc&lt;/div&gt;
&lt;div&gt;
www.femalelife.co.cc&lt;/div&gt;
&lt;div&gt;
www.folos.co.cc&lt;/div&gt;
&lt;div&gt;
www.freetemplates4u.co.cc&lt;/div&gt;
&lt;div&gt;
www.gocthethao.co.cc&lt;/div&gt;
&lt;div&gt;
www.jawamark.co.cc&lt;/div&gt;
&lt;div&gt;
www.kolah-ghermezi.co.cc&lt;/div&gt;
&lt;div&gt;
www.la-videoteca.co.cc&lt;/div&gt;
&lt;div&gt;
www.lanxess-europe.co.cc&lt;/div&gt;
&lt;div&gt;
www.metrovid.co.cc&lt;/div&gt;
&lt;div&gt;
www.nestle-gifts.co.cc&lt;/div&gt;
&lt;div&gt;
www.nestle.co.cc&lt;/div&gt;
&lt;div&gt;
www.outerxcircle.co.cc&lt;/div&gt;
&lt;div&gt;
www.p2p101.co.cc&lt;/div&gt;
&lt;div&gt;
www.sawa7.co.cc&lt;/div&gt;
&lt;div&gt;
www.techcenter-lanxess.co.cc&lt;/div&gt;
&lt;div&gt;
yahgoo.co.cc&lt;/div&gt;
&lt;div&gt;
yasmindavidds.co.cc&lt;/div&gt;
&lt;div&gt;
ycmi-med.co.cc&lt;/div&gt;
&lt;div&gt;
yduocantho.co.cc&lt;/div&gt;
&lt;div&gt;
zipwaves.co.cc&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 18px;"&gt;Host names neighbor for:&amp;nbsp;&lt;/span&gt;58.218.209.113&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
163rfg.com&lt;/div&gt;
&lt;div&gt;
baiduaic.com&lt;/div&gt;
&lt;div&gt;
baiduawj.com&lt;/div&gt;
&lt;div&gt;
baidubcv.com&lt;/div&gt;
&lt;div&gt;
baiducbx.com&lt;/div&gt;
&lt;div&gt;
baiduccd.com&lt;/div&gt;
&lt;div&gt;
baiduccf.com&lt;/div&gt;
&lt;div&gt;
baiducdd.com&lt;/div&gt;
&lt;div&gt;
baiduce4.com&lt;/div&gt;
&lt;div&gt;
baiduchs.com&lt;/div&gt;
&lt;div&gt;
baiducls.com&lt;/div&gt;
&lt;div&gt;
baiduclz.com&lt;/div&gt;
&lt;div&gt;
baiducuu.com&lt;/div&gt;
&lt;div&gt;
baiducxz.com&lt;/div&gt;
&lt;div&gt;
baidud4r.com&lt;/div&gt;
&lt;div&gt;
baidudc3.com&lt;/div&gt;
&lt;div&gt;
baiduddp.com&lt;/div&gt;
&lt;div&gt;
baidudjf.com&lt;/div&gt;
&lt;div&gt;
baiduduu.com&lt;/div&gt;
&lt;div&gt;
baidugal.com&lt;/div&gt;
&lt;div&gt;
baidugcb.com&lt;/div&gt;
&lt;div&gt;
baidugcd.com&lt;/div&gt;
&lt;div&gt;
baidugcx.com&lt;/div&gt;
&lt;div&gt;
baidugdj.com&lt;/div&gt;
&lt;div&gt;
baidugfc.com&lt;/div&gt;
&lt;div&gt;
baiduggs.com&lt;/div&gt;
&lt;div&gt;
baidugiu.com&lt;/div&gt;
&lt;div&gt;
baidugsd.com&lt;/div&gt;
&lt;div&gt;
baidugxs.com&lt;/div&gt;
&lt;div&gt;
baiduhjc.com&lt;/div&gt;
&lt;div&gt;
baiduhus.com&lt;/div&gt;
&lt;div&gt;
baidujdf.com&lt;/div&gt;
&lt;div&gt;
baidujhf.com&lt;/div&gt;
&lt;div&gt;
baidujk4.com&lt;/div&gt;
&lt;div&gt;
baidujkl.com&lt;/div&gt;
&lt;div&gt;
baidujus.com&lt;/div&gt;
&lt;div&gt;
baidujvc.com&lt;/div&gt;
&lt;div&gt;
baidukch.com&lt;/div&gt;
&lt;div&gt;
baidukjd.com&lt;/div&gt;
&lt;div&gt;
baidukjs.com&lt;/div&gt;
&lt;div&gt;
baidukkh.com&lt;/div&gt;
&lt;div&gt;
baiduks2.com&lt;/div&gt;
&lt;div&gt;
baidul08.com&lt;/div&gt;
&lt;div&gt;
baidul90.com&lt;/div&gt;
&lt;div&gt;
baidulal.com&lt;/div&gt;
&lt;div&gt;
baidulcm.com&lt;/div&gt;
&lt;div&gt;
baidulka.com&lt;/div&gt;
&lt;div&gt;
baidulkd.com&lt;/div&gt;
&lt;div&gt;
baidulks.com&lt;/div&gt;
&lt;div&gt;
baidulo0.com&lt;/div&gt;
&lt;div&gt;
baiduloc.com&lt;/div&gt;
&lt;div&gt;
baidulos.com&lt;/div&gt;
&lt;div&gt;
baidulpa.com&lt;/div&gt;
&lt;div&gt;
baidulsc.com&lt;/div&gt;
&lt;div&gt;
baidulss.com&lt;/div&gt;
&lt;div&gt;
baidumch.com&lt;/div&gt;
&lt;div&gt;
baidumcn.com&lt;/div&gt;
&lt;div&gt;
baidumls.com&lt;/div&gt;
&lt;div&gt;
baidummd.com&lt;/div&gt;
&lt;div&gt;
baidumnf.com&lt;/div&gt;
&lt;div&gt;
baidumnv.com&lt;/div&gt;
&lt;div&gt;
baidumnx.com&lt;/div&gt;
&lt;div&gt;
baidumqw.com&lt;/div&gt;
&lt;div&gt;
baidunbd.com&lt;/div&gt;
&lt;div&gt;
baiduncb.com&lt;/div&gt;
&lt;div&gt;
baiduohg.com&lt;/div&gt;
&lt;div&gt;
baiduoic.com&lt;/div&gt;
&lt;div&gt;
baiduoiu.com&lt;/div&gt;
&lt;div&gt;
baiduols.com&lt;/div&gt;
&lt;div&gt;
baiduosc.com&lt;/div&gt;
&lt;div&gt;
baidupbv.com&lt;/div&gt;
&lt;div&gt;
baidupdo.com&lt;/div&gt;
&lt;div&gt;
baidupju.com&lt;/div&gt;
&lt;div&gt;
baidupoc.com&lt;/div&gt;
&lt;div&gt;
baidupom.com&lt;/div&gt;
&lt;div&gt;
baidupsd.com&lt;/div&gt;
&lt;div&gt;
baidupwp.com&lt;/div&gt;
&lt;div&gt;
baiduqos.com&lt;/div&gt;
&lt;div&gt;
baiduqpx.com&lt;/div&gt;
&lt;div&gt;
baiduqw2.com&lt;/div&gt;
&lt;div&gt;
baiduree.com&lt;/div&gt;
&lt;div&gt;
baiduret.com&lt;/div&gt;
&lt;div&gt;
baidurew.com&lt;/div&gt;
&lt;div&gt;
baidurfg.com&lt;/div&gt;
&lt;div&gt;
baidurfh.com&lt;/div&gt;
&lt;div&gt;
baidurhg.com&lt;/div&gt;
&lt;div&gt;
baidurjg.com&lt;/div&gt;
&lt;div&gt;
baidurre.com&lt;/div&gt;
&lt;div&gt;
baidurrt.com&lt;/div&gt;
&lt;div&gt;
baidurwe.com&lt;/div&gt;
&lt;div&gt;
baidurwq.com&lt;/div&gt;
&lt;div&gt;
baiduscs.com&lt;/div&gt;
&lt;div&gt;
baidussd.com&lt;/div&gt;
&lt;div&gt;
baidusw1.com&lt;/div&gt;
&lt;div&gt;
baiduswt.com&lt;/div&gt;
&lt;div&gt;
baidutcs.com&lt;/div&gt;
&lt;div&gt;
baidutdc.com&lt;/div&gt;
&lt;div&gt;
baidutec.com&lt;/div&gt;
&lt;div&gt;
baidutes.com&lt;/div&gt;
&lt;div&gt;
baidutet.com&lt;/div&gt;
&lt;div&gt;
baidutew.com&lt;/div&gt;
&lt;div&gt;
baidutfg.com&lt;/div&gt;
&lt;div&gt;
baidutrb.com&lt;/div&gt;
&lt;div&gt;
baidutre.com&lt;/div&gt;
&lt;div&gt;
baidutrg.com&lt;/div&gt;
&lt;div&gt;
baidutsd.com&lt;/div&gt;
&lt;div&gt;
baiduttr.com&lt;/div&gt;
&lt;div&gt;
baidutvc.com&lt;/div&gt;
&lt;div&gt;
baidutvf.com&lt;/div&gt;
&lt;div&gt;
baidutvk.com&lt;/div&gt;
&lt;div&gt;
baiduuim.com&lt;/div&gt;
&lt;div&gt;
baiduuys.com&lt;/div&gt;
&lt;div&gt;
baiduuyt.com&lt;/div&gt;
&lt;div&gt;
baiduwex.com&lt;/div&gt;
&lt;div&gt;
baiduwlc.com&lt;/div&gt;
&lt;div&gt;
baiduwwe.com&lt;/div&gt;
&lt;div&gt;
baiduxah.com&lt;/div&gt;
&lt;div&gt;
baiduxsl.com&lt;/div&gt;
&lt;div&gt;
baiduxzs.com&lt;/div&gt;
&lt;div&gt;
baiduycd.com&lt;/div&gt;
&lt;div&gt;
baiduycm.com&lt;/div&gt;
&lt;div&gt;
baiduycs.com&lt;/div&gt;
&lt;div&gt;
baiduydp.com&lt;/div&gt;
&lt;div&gt;
baiduyew.com&lt;/div&gt;
&lt;div&gt;
baiduygl.com&lt;/div&gt;
&lt;div&gt;
baiduyjk.com&lt;/div&gt;
&lt;div&gt;
baiduyms.com&lt;/div&gt;
&lt;div&gt;
baiduytc.com&lt;/div&gt;
&lt;div&gt;
baiduyte.com&lt;/div&gt;
&lt;div&gt;
baiduytr.com&lt;/div&gt;
&lt;div&gt;
baiduytv.com&lt;/div&gt;
&lt;div&gt;
baiduytw.com&lt;/div&gt;
&lt;div&gt;
baiduywe.com&lt;/div&gt;
&lt;div&gt;
baiduyxb.com&lt;/div&gt;
&lt;div&gt;
baiduyxz.com&lt;/div&gt;
&lt;div&gt;
baiduzxc.com&lt;/div&gt;
&lt;div&gt;
google2fv.com&lt;/div&gt;
&lt;div&gt;
google6u7.com&lt;/div&gt;
&lt;div&gt;
googledsv.com&lt;/div&gt;
&lt;div&gt;
googlefct.com&lt;/div&gt;
&lt;div&gt;
googlemis.com&lt;/div&gt;
&lt;div&gt;
laotuw.com&lt;/div&gt;
&lt;div&gt;
sohuhju.com&lt;/div&gt;
&lt;div&gt;
sohus45.com&lt;/div&gt;
&lt;div&gt;
sohusde.com&lt;/div&gt;
&lt;div&gt;
sohusw4.com&lt;/div&gt;
&lt;div&gt;
www.163dcf.com&lt;/div&gt;
&lt;div&gt;
www.163lou.com&lt;/div&gt;
&lt;div&gt;
www.163qw8.com&lt;/div&gt;
&lt;div&gt;
www.163rfg.com&lt;/div&gt;
&lt;div&gt;
www.baidubcv.com&lt;/div&gt;
&lt;div&gt;
www.baidudg3.com&lt;/div&gt;
&lt;div&gt;
www.baiduhus.com&lt;/div&gt;
&lt;div&gt;
www.baidumls.com&lt;/div&gt;
&lt;div&gt;
www.baiduree.com&lt;/div&gt;
&lt;div&gt;
www.baidutdc.com&lt;/div&gt;
&lt;div&gt;
www.googledsv.com&lt;/div&gt;
&lt;div&gt;
www.laotuwang.com&lt;/div&gt;
&lt;div&gt;
www.sohusde.com&lt;/div&gt;
&lt;div&gt;
www.yahooui0.com&lt;/div&gt;
&lt;div&gt;
www.yahoozsw.com&lt;/div&gt;
&lt;div&gt;
yahooidd.com&lt;/div&gt;
&lt;div&gt;
yahoomkl.com&lt;/div&gt;
&lt;div&gt;
yahoowaq.com&lt;/div&gt;
&lt;div&gt;
yahooyao.com&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-1168512515775633695?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Xa-lkHrFWAtv75uADLZ_w8k-9uo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Xa-lkHrFWAtv75uADLZ_w8k-9uo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Xa-lkHrFWAtv75uADLZ_w8k-9uo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Xa-lkHrFWAtv75uADLZ_w8k-9uo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/8mYsixabkSQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/1168512515775633695/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=1168512515775633695" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1168512515775633695?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1168512515775633695?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/8mYsixabkSQ/blizzard-phishing-emails-scam-12-oct-11.html" title="Blizzard Phishing Emails Scam 12-Oct-11" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/10/blizzard-phishing-emails-scam-12-oct-11.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUUBSX4-cCp7ImA9WhdbE0o.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2203143473120383217</id><published>2011-10-11T16:53:00.000-07:00</published><updated>2011-10-11T16:54:18.058-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-11T16:54:18.058-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft Patch Tuesday" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Response" /><category scheme="http://www.blogger.com/atom/ns#" term="Patches" /><title>Microsoft Patch Tuesday - October 2011</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Microsoft Tuesday patch release for october consists of 8 bulletins. 2 of bulletins are rated &amp;nbsp;"Critical" and remaining issue are rated "Important". Six of issues could cause Remode Code Execution, one for Denial of Service and Elevation of Privilege.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkId=227075"&gt;MS11-078&lt;/a&gt; - Critical &amp;nbsp;- Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2604930)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkID=226382"&gt;MS11-081&lt;/a&gt; - Critical - Cumulative Security Update for Internet Explorer (2586448)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkId=221538"&gt;MS11-075&lt;/a&gt; - Important - Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution (2623699)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkId=227073"&gt;MS11-076&lt;/a&gt; - Important - Vulnerability in Windows Media Center Could Allow Remote Code Execution (2604926)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkId=225915"&gt;MS11-077&lt;/a&gt; - Important - Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkId=217472"&gt;MS11-079&lt;/a&gt; - Important - Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution (2544641)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkId=227486"&gt;MS11-080&lt;/a&gt; - Important - Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://go.microsoft.com/fwlink/?LinkId=228596"&gt;MS11-082&lt;/a&gt; - Important &amp;nbsp;- Vulnerabilities in Host Integration Server Could Allow Denial of Service (2607670)&lt;br /&gt;
&lt;br /&gt;
Microsoft’s summary of the October releases can be found here:&lt;br /&gt;
	&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-oct"&gt;http://technet.microsoft.com/en-us/security/bulletin/ms11-oct&lt;/a&gt;&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2203143473120383217?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/kEbrZNl5dHjgYSjD7Bbu8s8tPJA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kEbrZNl5dHjgYSjD7Bbu8s8tPJA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/kEbrZNl5dHjgYSjD7Bbu8s8tPJA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kEbrZNl5dHjgYSjD7Bbu8s8tPJA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/N556OLU3qJc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2203143473120383217/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2203143473120383217" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2203143473120383217?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2203143473120383217?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/N556OLU3qJc/microsoft-patch-tuesday-october-2011.html" title="Microsoft Patch Tuesday - October 2011" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/10/microsoft-patch-tuesday-october-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUMBSHwyfSp7ImA9WhdUFkg.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-3206251615651925178</id><published>2011-10-03T07:50:00.000-07:00</published><updated>2011-10-03T07:50:59.295-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-03T07:50:59.295-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><category scheme="http://www.blogger.com/atom/ns#" term="suspicious" /><title>Suspicious and Spam Link 3-Oct-2011</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
Hostnames neighbor for 112.216.242.125&lt;br /&gt;
&lt;br /&gt;
actbus.ru&lt;br /&gt;
actpot.ru&lt;br /&gt;
admin.actmud.ru&lt;br /&gt;
admin.againstboard.com&lt;br /&gt;
admin.ampzoo.ru&lt;br /&gt;
admin.bitblood.com&lt;br /&gt;
admin.botfox.ru&lt;br /&gt;
admin.bridgefinger.com&lt;br /&gt;
admin.channel3online.com&lt;br /&gt;
admin.cupelf.ru&lt;br /&gt;
admin.fadbed.ru&lt;br /&gt;
admin.fatpenisphoto.ru&lt;br /&gt;
admin.fightgrey.com&lt;br /&gt;
admin.gaprip.ru&lt;br /&gt;
admin.hatdot.ru&lt;br /&gt;
admin.legtie.ru&lt;br /&gt;
admin.matfox.ru&lt;br /&gt;
admin.matlip.ru&lt;br /&gt;
admin.mictie.ru&lt;br /&gt;
admin.mixrag.ru&lt;br /&gt;
admin.padwit.ru&lt;br /&gt;
admin.paltag.ru&lt;br /&gt;
admin.pawbin.ru&lt;br /&gt;
admin.podyak.ru&lt;br /&gt;
admin.pupgas.ru&lt;br /&gt;
admin.ragaxe.ru&lt;br /&gt;
admin.tagray.ru&lt;br /&gt;
admin.tarkid.ru&lt;br /&gt;
admin.tinpet.ru&lt;br /&gt;
admin.wigelf.ru&lt;br /&gt;
admin.zipfad.ru&lt;br /&gt;
ahtryte.ru&lt;br /&gt;
alecat.ru&lt;br /&gt;
allpup.ru&lt;br /&gt;
ampyak.ru&lt;br /&gt;
anthat.ru&lt;br /&gt;
armlaw.ru&lt;br /&gt;
ashpit.ru&lt;br /&gt;
batgas.ru&lt;br /&gt;
baypan.ru&lt;br /&gt;
bedamp.ru&lt;br /&gt;
bedego.ru&lt;br /&gt;
bluebroken.com&lt;br /&gt;
bodybrass.com&lt;br /&gt;
bodyfeeble.com&lt;br /&gt;
boggas.ru&lt;br /&gt;
bogpod.ru&lt;br /&gt;
boilingfertile.com&lt;br /&gt;
boyrag.ru&lt;br /&gt;
boyson.ru&lt;br /&gt;
brothermonth.com&lt;br /&gt;
bugear.ru&lt;br /&gt;
bunsum.ru&lt;br /&gt;
busdot.ru&lt;br /&gt;
cangun.ru&lt;br /&gt;
cantax.ru&lt;br /&gt;
caryou.ru&lt;br /&gt;
certainegg.com&lt;br /&gt;
channel3online.com&lt;br /&gt;
chinblood.com&lt;br /&gt;
chincontrol.com&lt;br /&gt;
copyafter.com&lt;br /&gt;
coughengine.com&lt;br /&gt;
cowguy.ru&lt;br /&gt;
cupact.ru&lt;br /&gt;
cupcar.ru&lt;br /&gt;
dadnet.ru&lt;br /&gt;
dadtoe.ru&lt;br /&gt;
demandvalues.ru&lt;br /&gt;
dogjar.ru&lt;br /&gt;
dogpit.ru&lt;br /&gt;
dotpod.ru&lt;br /&gt;
dyedog.ru&lt;br /&gt;
eggant.ru&lt;br /&gt;
egoair.ru&lt;br /&gt;
egodye.ru&lt;br /&gt;
elfbay.ru&lt;br /&gt;
enlargemypenisnatural.ru&lt;br /&gt;
enlargemypeniss.com&lt;br /&gt;
eyerib.ru&lt;br /&gt;
eyeute.ru&lt;br /&gt;
fabboy.ru&lt;br /&gt;
fadgap.ru&lt;br /&gt;
fadpaw.ru&lt;br /&gt;
fangap.ru&lt;br /&gt;
fanrow.ru&lt;br /&gt;
fantea.ru&lt;br /&gt;
fashionwit.ru&lt;br /&gt;
fatpenisphoto.ru&lt;br /&gt;
flowerbody.com&lt;br /&gt;
foxpup.ru&lt;br /&gt;
foxzit.ru&lt;br /&gt;
fungin.ru&lt;br /&gt;
galhog.ru&lt;br /&gt;
gaplab.ru&lt;br /&gt;
gaspup.ru&lt;br /&gt;
getitbigz.com&lt;br /&gt;
gindad.ru&lt;br /&gt;
grainlanguage.com&lt;br /&gt;
gunbog.ru&lt;br /&gt;
gundew.ru&lt;br /&gt;
gunyou.ru&lt;br /&gt;
gutice.ru&lt;br /&gt;
guypub.ru&lt;br /&gt;
hitpeg.ru&lt;br /&gt;
icehog.ru&lt;br /&gt;
inkion.ru&lt;br /&gt;
ionpit.ru&lt;br /&gt;
jarsax.ru&lt;br /&gt;
jarsun.ru&lt;br /&gt;
jellygoat.com&lt;br /&gt;
kidaxe.ru&lt;br /&gt;
labtin.ru&lt;br /&gt;
landchin.com&lt;br /&gt;
languageawake.com&lt;br /&gt;
languagefeeble.com&lt;br /&gt;
legfox.ru&lt;br /&gt;
maprib.ru&lt;br /&gt;
medialine3.com&lt;br /&gt;
mefox.ru&lt;br /&gt;
mekey.ru&lt;br /&gt;
menjar.ru&lt;br /&gt;
mickid.ru&lt;br /&gt;
miczit.ru&lt;br /&gt;
mixmat.ru&lt;br /&gt;
momcar.ru&lt;br /&gt;
mudcar.ru&lt;br /&gt;
mudpad.ru&lt;br /&gt;
mumtow.ru&lt;br /&gt;
mumute.ru&lt;br /&gt;
nutamp.ru&lt;br /&gt;
nuteye.ru&lt;br /&gt;
nutgas.ru&lt;br /&gt;
oilmom.ru&lt;br /&gt;
oldyak.ru&lt;br /&gt;
padink.ru&lt;br /&gt;
padmix.ru&lt;br /&gt;
paldad.ru&lt;br /&gt;
paltag.ru&lt;br /&gt;
panwar.ru&lt;br /&gt;
pawego.ru&lt;br /&gt;
pawtv.ru&lt;br /&gt;
pawyou.ru&lt;br /&gt;
pegcan.ru&lt;br /&gt;
penislargechat.ru&lt;br /&gt;
penislargebrain.ru&lt;br /&gt;
penislargeforex.ru&lt;br /&gt;
penislargegreen.ru&lt;br /&gt;
penislargeproperty.ru&lt;br /&gt;
petbay.ru&lt;br /&gt;
piespa.ru&lt;br /&gt;
pigegg.ru&lt;br /&gt;
pitbed.ru&lt;br /&gt;
pitegg.ru&lt;br /&gt;
podspa.ru&lt;br /&gt;
pubmix.ru&lt;br /&gt;
puppub.ru&lt;br /&gt;
raptap.ru&lt;br /&gt;
replicaswatchcash.ru&lt;br /&gt;
replicaswatchcloud.ru&lt;br /&gt;
replicaswatchclub.ru&lt;br /&gt;
replicaswatchdog.ru&lt;br /&gt;
replicaswatchfish.ru&lt;br /&gt;
replicawatch4you.com&lt;br /&gt;
ribale.ru&lt;br /&gt;
rimpub.ru&lt;br /&gt;
ripwax.ru&lt;br /&gt;
rowpen.ru&lt;br /&gt;
rowpup.ru&lt;br /&gt;
saxegg.ru&lt;br /&gt;
saxelf.ru&lt;br /&gt;
saxeye.ru&lt;br /&gt;
seebun.ru&lt;br /&gt;
skysum.ru&lt;br /&gt;
slimmonth.com&lt;br /&gt;
soddot.ru&lt;br /&gt;
sodjar.ru&lt;br /&gt;
sodleg.ru&lt;br /&gt;
sodtap.ru&lt;br /&gt;
sodtea.ru&lt;br /&gt;
sonbar.ru&lt;br /&gt;
sonlip.ru&lt;br /&gt;
sontax.ru&lt;br /&gt;
sumbus.ru&lt;br /&gt;
tablip.ru&lt;br /&gt;
tabmud.ru&lt;br /&gt;
tabpit.ru&lt;br /&gt;
tagbox.ru&lt;br /&gt;
taghog.ru&lt;br /&gt;
tapute.ru&lt;br /&gt;
tarbat.ru&lt;br /&gt;
tarwit.ru&lt;br /&gt;
taxwit.ru&lt;br /&gt;
teaspa.ru&lt;br /&gt;
tiebag.ru&lt;br /&gt;
tinpie.ru&lt;br /&gt;
tipwit.ru&lt;br /&gt;
toekid.ru&lt;br /&gt;
tubweb.ru&lt;br /&gt;
ukolfyg.ru&lt;br /&gt;
usefax.ru&lt;br /&gt;
vadeixr.ru&lt;br /&gt;
waxsax.ru&lt;br /&gt;
webtar.ru&lt;br /&gt;
wigweb.ru&lt;br /&gt;
world3newz.com&lt;br /&gt;
yaktab.ru&lt;br /&gt;
zenwit.ru&lt;br /&gt;
zitcow.ru&lt;br /&gt;
zitlab.ru&lt;br /&gt;
zooyou.ru&lt;br /&gt;
&lt;br /&gt;
Hostnames neighbor for 200.63.45.11&lt;br /&gt;
&lt;br /&gt;
accesspharmacy.ru&lt;br /&gt;
buymedicines.ru&lt;br /&gt;
compu-pharmacy.ru&lt;br /&gt;
compupharmacy.ru&lt;br /&gt;
connect-pharmacy.ru&lt;br /&gt;
connectpharmacy.ru&lt;br /&gt;
cyber-medicines.ru&lt;br /&gt;
cyberpharmacy.ru&lt;br /&gt;
deeperwinnings.com&lt;br /&gt;
direct-medsshop.ru&lt;br /&gt;
direct-pharmacy.ru&lt;br /&gt;
directpharmacy.ru&lt;br /&gt;
directrxhere.ru&lt;br /&gt;
domain-pharmacy.ru&lt;br /&gt;
e-card-greeting.com&lt;br /&gt;
e-cards-fast.ru&lt;br /&gt;
ecard2011.ru&lt;br /&gt;
ez-pharmacy.ru&lt;br /&gt;
ezmedicines.ru&lt;br /&gt;
ezpharmacy.ru&lt;br /&gt;
faster-ecard.ru&lt;br /&gt;
hiddendate.com&lt;br /&gt;
hotmedicines.ru&lt;br /&gt;
hotpharmacy.ru&lt;br /&gt;
internet-pharmacy.ru&lt;br /&gt;
internetpharmacy.ru&lt;br /&gt;
mail.rxfromhome.com&lt;br /&gt;
mega-pharmacy.ru&lt;br /&gt;
megapharmacy.ru&lt;br /&gt;
new-ecard.ru&lt;br /&gt;
paylessrx.ru&lt;br /&gt;
propharmacy.ru&lt;br /&gt;
shop-medsdirect.ru&lt;br /&gt;
uptodowner.com&lt;br /&gt;
usatermlifequoter.com&lt;br /&gt;
www.direct-medsshop.ru&lt;br /&gt;
www.e-cards-fast.ru&lt;br /&gt;
www.megapharmacy.ru&lt;br /&gt;
www.shop-medsdirect.ru&lt;br /&gt;
www.special-e-card4you.com&lt;br /&gt;
your-ecard-here.ru&lt;br /&gt;
yourlifequotesterm.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Hostnames neighbor for 31.11.43.24&lt;br /&gt;
&lt;br /&gt;
admin.pillcorrectpharmacyrx.net&lt;br /&gt;
admin.pillsvx.net&lt;br /&gt;
admin.sussuhlywn.com&lt;br /&gt;
admin.suyquylfe.net&lt;br /&gt;
admin.tabdiet.com&lt;br /&gt;
admin.tabdrugstoretablets.net&lt;br /&gt;
admin.tabhealthospital.com&lt;br /&gt;
admin.tabletcvs.com&lt;br /&gt;
admin.tabletshealthdrugstoreguide.net&lt;br /&gt;
admin.tabletspharmacytabs.net&lt;br /&gt;
admin.tabletspillsmercola.com&lt;br /&gt;
admin.tabletsspecialtypharmacymeds.com&lt;br /&gt;
admin.tablettorontorxmeds.ru&lt;br /&gt;
admin.tabpause.com&lt;br /&gt;
admin.tabstabletspharmacy.ru&lt;br /&gt;
admin.taxlnesslevitra.com&lt;br /&gt;
admin.taxtrapharmacy.com&lt;br /&gt;
admin.taxtrarx.com&lt;br /&gt;
admin.tevasviagra.com&lt;br /&gt;
admin.thepurplepills.ru&lt;br /&gt;
admin.thijgobqux.com&lt;br /&gt;
admin.totalpharmacyrx.ru&lt;br /&gt;
admin.touchpadiet.com&lt;br /&gt;
admin.treatmentsdrugstorepharmacy.net&lt;br /&gt;
admin.treatmentspharmacytablets.net&lt;br /&gt;
admin.trenomdys.com&lt;br /&gt;
admin.uhlyjywke.com&lt;br /&gt;
admin.veczedfeyd.com&lt;br /&gt;
admin.veczedfeyd.net&lt;br /&gt;
admin.viagrapatients.com&lt;br /&gt;
admin.vmedall.com&lt;br /&gt;
admin.walgreenspharmacyrxmeds.com&lt;br /&gt;
admin.welnesshealthcare.com&lt;br /&gt;
admin.welnesslevitrainc.com&lt;br /&gt;
admin.welnessmedical.com&lt;br /&gt;
admin.welnessmedicare.com&lt;br /&gt;
admin.wikihealthospital.com&lt;br /&gt;
admin.wikimedicare.com&lt;br /&gt;
admin.wikiovercharge.com&lt;br /&gt;
admin.workoutwelnessdiet.com&lt;br /&gt;
admin.wyjterqus.com&lt;br /&gt;
admin.xumcoycdead.net&lt;br /&gt;
admin.yofgeptu.com&lt;br /&gt;
admin.zagbevgoqe.com&lt;br /&gt;
mail.pillsvx.net&lt;br /&gt;
mail.rxbiological.com&lt;br /&gt;
mail.sussuhlywn.com&lt;br /&gt;
mail.tabdiet.com&lt;br /&gt;
mail.tabdrugstoretablets.net&lt;br /&gt;
mail.tabhealthospital.com&lt;br /&gt;
mail.tabletcvs.com&lt;br /&gt;
mail.tabletpharmacyhealthmedicare.com&lt;br /&gt;
mail.tabletshealthdrugstoreguide.net&lt;br /&gt;
mail.tabletsleepingpillsdrugstore.com&lt;br /&gt;
mail.tabletsleepingpillsdrugstore.net&lt;br /&gt;
mail.tabletspharmacytabs.net&lt;br /&gt;
mail.tabletspillsmercola.com&lt;br /&gt;
mail.tabletsspecialtypharmacymeds.com&lt;br /&gt;
mail.tabpause.com&lt;br /&gt;
mail.tabstabletspharmacy.ru&lt;br /&gt;
mail.taxlnesslevitra.com&lt;br /&gt;
mail.taxtrapharmacy.com&lt;br /&gt;
mail.taxtrarx.com&lt;br /&gt;
mail.totalpharmacyrx.ru&lt;br /&gt;
mail.touchpadiet.com&lt;br /&gt;
mail.treatmentspharmacytablets.net&lt;br /&gt;
mail.uhlyjywke.com&lt;br /&gt;
mail.veczedfeyd.net&lt;br /&gt;
mail.viagrapatients.com&lt;br /&gt;
mail.walgreenspharmacyrxmeds.com&lt;br /&gt;
mail.welnesshealthcare.com&lt;br /&gt;
mail.welnesslevitrainc.com&lt;br /&gt;
mail.welnessmedical.com&lt;br /&gt;
mail.welnessmedicare.com&lt;br /&gt;
mail.wikihealthospital.com&lt;br /&gt;
mail.wikimedicare.com&lt;br /&gt;
mail.wikiovercharge.com&lt;br /&gt;
mail.wineherbalmeds.com&lt;br /&gt;
mail.workoutwelnessdiet.com&lt;br /&gt;
mail.xmedonline365.net&lt;br /&gt;
mail.xuhtuivtict.com&lt;br /&gt;
mail.xumcoycdead.net&lt;br /&gt;
ns1.qufkadzolv.com&lt;br /&gt;
ns1.realmed-plus.net&lt;br /&gt;
ns1.sussuhlywn.com&lt;br /&gt;
ns1.suyquylfe.net&lt;br /&gt;
ns1.trenomdys.com&lt;br /&gt;
ns1.twozefukl.com&lt;br /&gt;
ns1.uhlyjywke.com&lt;br /&gt;
ns1.veczedfeyd.com&lt;br /&gt;
ns1.veczedfeyd.net&lt;br /&gt;
ns1.vmedall.com&lt;br /&gt;
ns1.xuhtuivtict.com&lt;br /&gt;
ns1.yajpoxwes.com&lt;br /&gt;
ns1.zagbevgoqe.com&lt;br /&gt;
ns2.pillsvx.net&lt;br /&gt;
ns2.sussuhlywn.com&lt;br /&gt;
ns2.suyquylfe.net&lt;br /&gt;
ns2.trenomdys.com&lt;br /&gt;
ns2.vmedall.com&lt;br /&gt;
ns2.wyjterqus.com&lt;br /&gt;
ns2.xmedonline365.net&lt;br /&gt;
ns2.xuhtuivtict.com&lt;br /&gt;
ns2.xumcoycdead.net&lt;br /&gt;
ns2.zagbevgoqe.com&lt;br /&gt;
pillscifi.com&lt;br /&gt;
prescriptioncounterpunch.com&lt;br /&gt;
ratsed.com&lt;br /&gt;
rxgenericsdrug.com&lt;br /&gt;
tabhealthospital.com&lt;br /&gt;
tabletcanadandroid.com&lt;br /&gt;
tabletmedsomma.net&lt;br /&gt;
tabletprecisionpharmacyrx.net&lt;br /&gt;
tabletrxdrugstoreomma.net&lt;br /&gt;
tabletsmedshealth.com&lt;br /&gt;
tabletsmedshealthcare.net&lt;br /&gt;
tabletsmedshealthnook.net&lt;br /&gt;
tabletspharmacytabs.net&lt;br /&gt;
tabletspillsexpress.com&lt;br /&gt;
tabletspillshealth.com&lt;br /&gt;
tabletsrxmedsomma.net&lt;br /&gt;
tablettorontorxmeds.ru&lt;br /&gt;
taxlnesslevitra.com&lt;br /&gt;
taxtrarx.com&lt;br /&gt;
techbuypills.ru&lt;br /&gt;
techmedicinepills.ru&lt;br /&gt;
techhealth.ru&lt;br /&gt;
tlezuidce.com&lt;br /&gt;
tradhyvy.com&lt;br /&gt;
tradhyvy.net&lt;br /&gt;
tyqugilac.com&lt;br /&gt;
ufpfk.ru&lt;br /&gt;
unixmedsdrugstore.net&lt;br /&gt;
vasmiklet.com&lt;br /&gt;
veczedfeyd.net&lt;br /&gt;
vomiccalhe.com&lt;br /&gt;
vzaclulqumb.com&lt;br /&gt;
walgreenspillsdrugstore.net&lt;br /&gt;
wikigenerics.com&lt;br /&gt;
wikimedicalpatients.com&lt;br /&gt;
wikimedicare.com&lt;br /&gt;
wrimvysry.com&lt;br /&gt;
wrimvysry.net&lt;br /&gt;
www.svalopras.com&lt;br /&gt;
www.tabletsrxmedsomma.net&lt;br /&gt;
www.tnacj.ru&lt;br /&gt;
www.ugff.ru&lt;br /&gt;
www.ugfj.ru&lt;br /&gt;
www.umdgv.ru&lt;br /&gt;
www.upfzl.ru&lt;br /&gt;
www.wygpufli.com&lt;br /&gt;
www.vasmiklet.com&lt;br /&gt;
www.zudiqwolo.com&lt;br /&gt;
xarneidr.com&lt;br /&gt;
xopnymjurh.com&lt;br /&gt;
yajpoxwes.com&lt;br /&gt;
yavtiomy.com&lt;br /&gt;
yofgeptu.com&lt;br /&gt;
yogilqugja.com&lt;br /&gt;
yukeufmiti.com&lt;br /&gt;
zagbevgoqe.com&lt;br /&gt;
zdiafuyfqe.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Hostnames neighbor for 86.55.243.25&lt;br /&gt;
&lt;br /&gt;
amazingsize.ru&lt;br /&gt;
bigpenisll.ru&lt;br /&gt;
bigpenisrf.ru&lt;br /&gt;
bigpenissu.ru&lt;br /&gt;
bigpenisti.ru&lt;br /&gt;
bigsizeac.ru&lt;br /&gt;
bigsizehn.ru&lt;br /&gt;
buypenispass.ru&lt;br /&gt;
client25.zaininter.net&lt;br /&gt;
crisrays.ru&lt;br /&gt;
dlikdele.ru&lt;br /&gt;
dvovojzo.ru&lt;br /&gt;
extra-ordinary.ru&lt;br /&gt;
extraviagrow.com&lt;br /&gt;
gatecelest.ru&lt;br /&gt;
go-tomeeting.ru&lt;br /&gt;
growlong.ru&lt;br /&gt;
huge-manhood.ru&lt;br /&gt;
illusioniste.ru&lt;br /&gt;
importheavy.ru&lt;br /&gt;
inpantshardd.com&lt;br /&gt;
intensemedium.ru&lt;br /&gt;
joinfast.ru&lt;br /&gt;
life-mania.ru&lt;br /&gt;
mail.bebiggers.com&lt;br /&gt;
mail.bigsizehn.ru&lt;br /&gt;
mail.blwomenow.com&lt;br /&gt;
mail.buypenisface.ru&lt;br /&gt;
mail.cheapenlarger.com&lt;br /&gt;
mail.cheerspenis.com&lt;br /&gt;
mail.crisrays.ru&lt;br /&gt;
mail.dildobiger.com&lt;br /&gt;
mail.dlikdele.ru&lt;br /&gt;
mail.dvovojzo.ru&lt;br /&gt;
mail.extraviagrow.com&lt;br /&gt;
mail.growlong.ru&lt;br /&gt;
mail.growsfasts.com&lt;br /&gt;
mail.inchezlarged.com&lt;br /&gt;
mail.increasepenisplaty.ru&lt;br /&gt;
mail.increasepenisroan.ru&lt;br /&gt;
mail.joinfast.ru&lt;br /&gt;
mail.masterviagrow.com&lt;br /&gt;
mail.menlydicks.com&lt;br /&gt;
mail.minixmaxy.com&lt;br /&gt;
mail.mostgrow.com&lt;br /&gt;
mail.mynewsviagra.com&lt;br /&gt;
mail.newsviagrowerz.com&lt;br /&gt;
mail.penisgrowcare.ru&lt;br /&gt;
mail.penisgrowkids.ru&lt;br /&gt;
mail.penisgrowshopping.ru&lt;br /&gt;
mail.penisprosell.ru&lt;br /&gt;
mail.penisproteen.ru&lt;br /&gt;
mail.penisselect.com&lt;br /&gt;
mail.penissizeaverse.ru&lt;br /&gt;
mail.penissizeaxenic.ru&lt;br /&gt;
mail.penissizecosey.ru&lt;br /&gt;
mail.powerhuger.com&lt;br /&gt;
mail.rvolivec.ru&lt;br /&gt;
mail.rx-newsviagrows.com&lt;br /&gt;
mail.shopenlarge.com&lt;br /&gt;
mail.soldsviagrows.com&lt;br /&gt;
mail.stephuge.com&lt;br /&gt;
mail.superlarge.ru&lt;br /&gt;
mail.via-growth.com&lt;br /&gt;
mail.viagradrinker.com&lt;br /&gt;
mail.viagrasgrows.com&lt;br /&gt;
mail.viagrower.ru&lt;br /&gt;
mail.viagrowerz.com&lt;br /&gt;
mail.viagrowstore.com&lt;br /&gt;
mail.voukluci.ru&lt;br /&gt;
mail.vzpodska.ru&lt;br /&gt;
mail.wondershuge.com&lt;br /&gt;
mail.wonderviagrow.com&lt;br /&gt;
mail.wowmonster.ru&lt;br /&gt;
mail.zlojzori.ru&lt;br /&gt;
manhoodbig.ru&lt;br /&gt;
menlydicks.com&lt;br /&gt;
minixmaxy.com&lt;br /&gt;
nightdeep.ru&lt;br /&gt;
penissizecosey.ru&lt;br /&gt;
root.bigsizehn.ru&lt;br /&gt;
root.dlikdele.ru&lt;br /&gt;
root.rvolivec.ru&lt;br /&gt;
rvolivec.ru&lt;br /&gt;
sexypenis.ru&lt;br /&gt;
stephuge.com&lt;br /&gt;
viagrowstore.com&lt;br /&gt;
voukluci.ru&lt;br /&gt;
vzpodska.ru&lt;br /&gt;
wonderviagrow.com&lt;br /&gt;
zlojzori.ru&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Hostnames neighbor for 86.55.243.28&lt;br /&gt;
&lt;br /&gt;
mail.couturewatches.ru&lt;br /&gt;
mail.luxury2shop.com&lt;br /&gt;
mail.newscouturee.com&lt;br /&gt;
mail.replicabuyme.com&lt;br /&gt;
mail.replicastoreshop.ru&lt;br /&gt;
mail.richcoutures.com&lt;br /&gt;
mail.toperect.ru&lt;br /&gt;
mail.watchforless.info&lt;br /&gt;
replicastorenet.ru&lt;br /&gt;
root.toperect.ru&lt;br /&gt;
toperect.ru&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-3206251615651925178?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KQd3NM5bZEws78370jY2TQW2pFE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KQd3NM5bZEws78370jY2TQW2pFE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KQd3NM5bZEws78370jY2TQW2pFE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KQd3NM5bZEws78370jY2TQW2pFE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/tkVO2IZt5XI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/3206251615651925178/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=3206251615651925178" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3206251615651925178?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3206251615651925178?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/tkVO2IZt5XI/suspicious-and-spam-3-oct-2011.html" title="Suspicious and Spam Link 3-Oct-2011" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/10/suspicious-and-spam-3-oct-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IMR3s8eSp7ImA9WhdUFkw.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-7625013286105429022</id><published>2011-10-02T20:13:00.000-07:00</published><updated>2011-10-02T20:13:06.571-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-02T20:13:06.571-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="malware" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="Zeus" /><title>Zeus Trojan in depth by TrustDefender Labs</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
TrustDefender Labs posted in-depth report for&amp;nbsp;“Zeus Trojan Update – New Variants based on leaked Zeus Source Code” by Alex Shipp / Andreas Baumhof.&lt;br /&gt;
&lt;br /&gt;
Three variants were released to improve malware within few weeks which consists ICE IX, Registry Storage Version and RC4 replaced with AES.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ************************************&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;

1 Introduction&lt;/h1&gt;
When the source code of the Zeus Trojan (v.2.0.9.8) leaked into the 
public in April this year, it was clear that this will have some serious
 implication for the security industry. At the time, there was 
speculation that this would result in a large amount of new variants, as
 malware writers got hold of the code and started work on their own 
versions.&lt;br /&gt;
After a period of silence, we have seen at least three new variants 
based on the leaked Zeus source code appearing within the last couple of
 weeks. None of the three variants modified the core of the Zeus code; 
all of them focused on AV evasion and making sure that security 
researchers/tools cannot easily decrypt the configuration files.&lt;br /&gt;
The configuration files define what a Zeus Trojan does, and are therefore the holy grail to each Trojan.&lt;br /&gt;
In this report, we look into great detail with respect to these new variants and what changes were introduced.&lt;br /&gt;
The Zeus Trojan is complicated, with more than 600 subroutines. 
Rather than examine the entire code for changes, this research just 
looks at the processes involved in obtaining a decoded configuration 
file. This is a useful benchmark for a researcher, because the 
information we are usually interested in are the sites under attack by 
any particular copy of Zeus, and any custom code used in those attacks. 
Both these pieces of information are contained in the configuration 
file, which is encrypted.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tidos-group.com/blog/?p=429"&gt;READ MORE HERE&lt;/a&gt;&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-7625013286105429022?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2_A-S-2ScxiwzZ-35IibQ9vozuY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2_A-S-2ScxiwzZ-35IibQ9vozuY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2_A-S-2ScxiwzZ-35IibQ9vozuY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2_A-S-2ScxiwzZ-35IibQ9vozuY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/ny1VaWOY5fw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/7625013286105429022/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=7625013286105429022" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7625013286105429022?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7625013286105429022?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/ny1VaWOY5fw/zeus-trojan-in-depth-by-trustdefender.html" title="Zeus Trojan in depth by TrustDefender Labs" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/10/zeus-trojan-in-depth-by-trustdefender.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMGRXo4fCp7ImA9WhdUE00.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5936678121932776207</id><published>2011-09-29T07:27:00.000-07:00</published><updated>2011-09-29T07:27:04.434-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-29T07:27:04.434-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DDos" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="0Day" /><category scheme="http://www.blogger.com/atom/ns#" term="CVE-2011-3192" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Apache" /><title>CVE-2011-3192 - Apache Killer DoS Vulnerability and Patch</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Byterange filter in Apache HTTP Server prior to HTTP Server 2.2.20 allow remote attackers to cause Denial of Service ( DoS ) which cause memory and CPU consumption , exploited in the wild in August 2011.&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
As patch for this vulnerability been released by Apache last week. Prior to official patch, there have solution was &lt;a href="http://www.infosecstuff.com/?p=754"&gt;suggested&lt;/a&gt; and discussed to mitigate this problem.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Official Mitigation by Apache (&lt;a href="https://httpd.apache.org/security/CVE-2011-3192.txt"&gt;https://httpd.apache.org/security/CVE-2011-3192.txt&lt;/a&gt;),&amp;nbsp;Web administrators who use Apache HTTP Server are advised to apply the patch as soon as possible.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
Mitigation:&lt;/div&gt;
&lt;div&gt;
===========&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
There are several immediate options to mitigate this issue until a full fix&lt;/div&gt;
&lt;div&gt;
is available. Below examples handle both the 'Range' and the legacy&lt;/div&gt;
&lt;div&gt;
'Request-Range' with various levels of care.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Note that 'Request-Range' is a legacy name dating back to Netscape Navigator&lt;/div&gt;
&lt;div&gt;
2-3 and MSIE 3. Depending on your user community - it is likely that you&lt;/div&gt;
&lt;div&gt;
can use option '3' safely for this older 'Request-Range'.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
0) Consult http://httpd.apache.org/security/CVE-2011-3192.txt for the most&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;recent information (as this is the final advisory).&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
1) Use SetEnvIf or mod_rewrite to detect a large number of ranges and then&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;either ignore the Range: header or reject the request.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;Option 1: (Apache 2.2, requires mod_setenvif and mod_headers)&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # Drop the Range header when more than 5 ranges.&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # CVE-2011-3192&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SetEnvIf Range (?:,.*?){5,5} bad-range=1&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RequestHeader unset Range env=bad-range&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # We always drop Request-Range; as this is a legacy&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # dating back to MSIE3 and Netscape 2 and 3.&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RequestHeader unset Request-Range&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # optional logging.&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CustomLog logs/range-CVE-2011-3192.log common env=bad-range&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;Above may not work for all configurations. In particular situations&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;mod_cache and (language) modules may act before the 'unset'&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;is executed upon during the 'fixup' phase.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;Option 2: (Pre 2.2, requires mod_rewrite and mod_headers)&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # Reject request when more than 5 ranges in the Range: header.&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # CVE-2011-3192&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RewriteEngine on&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RewriteCond %{HTTP:range} !(^bytes=[^,]+(,[^,]+){0,4}$|^$) [NC]&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RewriteRule .* - [F]&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # We always drop Request-Range; as this is a legacy&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # dating back to MSIE3 and Netscape 2 and 3.&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RequestHeader unset Request-Range&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;The number 5 is arbitrary. Several 10's should not be an issue and may be&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;required for sites which for example serve PDFs to very high end eReaders&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;or use things such complex http based video streaming.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;WARNING These directives need to be specified in every configured&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;vhost, or inherited from server context as described in:&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;http://httpd.apache.org/docs/current/mod/mod_rewrite.html#vhosts&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
2) Use mod_headers to completely dis-allow the use of Range headers:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RequestHeader unset Range&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;Note that this may break certain clients - such as those used for&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;e-Readers and progressive/http-streaming video.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;Furthermore to ignore the Netscape Navigator 2-3 and MSIE 3 specific&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;legacy header - add:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RequestHeader unset Request-Range&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;Unlike the commonly used 'Range' header - dropping the 'Request-Range'&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;is not likely to affect many clients.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
4) Deploy a Range header count module as a temporary stopgap measure.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;A stop-gap module which is runtime-configurable can be found at:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;http://people.apache.org/~fuankg/httpd/mod_rangecnt-improved/&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;A simpler stop-gap module which requires compile-time configuration&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp;is also available:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;http://people.apache.org/~dirkx/mod_rangecnt.c&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;pre&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;/pre&gt;
&lt;br /&gt;
Exploit:&lt;br /&gt;
For study and researching purpose, source code for this vulnerability can be obtained from "&lt;a href="http://seanp2k.com/2011/09/cve-2011-3192-apache-killer-exploit-in-ruby/"&gt;CVE-2011-3192 (“Apache Killer”) Exploit in Ruby&lt;/a&gt;", "&lt;a href="http://knowledge-republic.com/CRM/2011/09/apache-http-server-byte-range-dos-manual-check/"&gt;Apache HTTP Server Byte Range DoS Manual Check&lt;/a&gt;" and PoC for this exploit code by &lt;a href="http://www.exploit-db.com/exploits/17696/"&gt;Exploit-db.com&lt;/a&gt;

&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;pre&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;/pre&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5936678121932776207?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/J0Y7qeBxNZugblEN4OWPcmUUCmY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/J0Y7qeBxNZugblEN4OWPcmUUCmY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/J0Y7qeBxNZugblEN4OWPcmUUCmY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/J0Y7qeBxNZugblEN4OWPcmUUCmY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/I_EgiLYezV4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5936678121932776207/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5936678121932776207" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5936678121932776207?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5936678121932776207?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/I_EgiLYezV4/cve-2011-3192-apache-killer-dos.html" title="CVE-2011-3192 - Apache Killer DoS Vulnerability and Patch" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/cve-2011-3192-apache-killer-dos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkYCSHg9eyp7ImA9WhdUEUU.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2714573139782133203</id><published>2011-09-27T20:22:00.000-07:00</published><updated>2011-09-27T20:22:49.663-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-27T20:22:49.663-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="Firefox 7" /><category scheme="http://www.blogger.com/atom/ns#" term="Firefox" /><title>Mozilla Firefox 7 Released!</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
Mozilla, a global, non-profit organization dedicated to making the Web better, today released an update to Firefox for &lt;a href="http://www.mozilla.org/firefox/fx/"&gt;Windows, Mac and Linux&lt;/a&gt;. Mozilla Firefox provides a speedy Web browsing experience for users and new tools to help developers create faster websites and Web apps.&lt;br /&gt;
&lt;br /&gt;
Firefox manages memory more efficiently to deliver a nimble Web browsing experience. Users will notice Firefox is faster at opening new tabs, clicking on menu items and buttons on websites. Heavy Internet users will enjoy &lt;a href="http://hacks.mozilla.org/2011/09/firefox-7-is-lean-and-fast/"&gt;enhanced performance&lt;/a&gt; when lots of tabs are open and during long Web browsing sessions that last hours or even days.&lt;br /&gt;
&lt;br /&gt;
New tools in Firefox make it easier for developers to build snappy Web experiences for users. A new version of hardware-accelerated Canvas speeds up HTML5 animations and games in Firefox. This allows developers to build more compelling and interactive Web experiences like Angry Birds or Runfield.&lt;br /&gt;
&lt;br /&gt;
Firefox now supports the W3C navigation timing spec API so developers can measure page load time and website navigation against bandwidth speed, website traffic and other factors. This API allows developers to test user experiences remotely and easily and quickly optimize websites and Web apps for different types of users.&lt;br /&gt;
&lt;br /&gt;
To help improve future versions of Firefox, users can opt in to Telemetry. Telemetry is a tool built on Mozilla Privacy Principles that allows users to provide anonymous browser performance data in a private and secure way that they control.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New users can head to the Firefox 7 &lt;a href="http://www.mozilla.org/en-US/firefox/new/"&gt;download&lt;/a&gt; page (http://www.firefox.com/)&lt;br /&gt;
&lt;br /&gt;
Reference: &lt;a href="https://blog.mozilla.com/blog/2011/09/27/mozilla-firefox-significantly-reduces-memory-use-to-make-web-browsing-faster/"&gt;Mozilla Website&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2714573139782133203?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GH-_uRyCboJQxKpaUkIkttzs2XE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GH-_uRyCboJQxKpaUkIkttzs2XE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GH-_uRyCboJQxKpaUkIkttzs2XE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GH-_uRyCboJQxKpaUkIkttzs2XE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/Oudkau93DPM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2714573139782133203/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2714573139782133203" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2714573139782133203?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2714573139782133203?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/Oudkau93DPM/mozilla-firefox-7-released.html" title="Mozilla Firefox 7 Released!" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/mozilla-firefox-7-released.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ICQX07fCp7ImA9WhdUFkw.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5209968160174585404</id><published>2011-09-27T18:33:00.000-07:00</published><updated>2011-10-02T20:12:40.304-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-02T20:12:40.304-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="email scam" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><category scheme="http://www.blogger.com/atom/ns#" term="Wow" /><category scheme="http://www.blogger.com/atom/ns#" term="blizzard" /><title>Phishing Email Scams targets Blizzard WOW</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
Battle.net, the largest net gaming service, was launched by Blizzard in 1997. For years it has hosted online play for games like Diablo, Warcraft and Starcraft.&lt;br /&gt;
&lt;br /&gt;
Victims of the scam are sent an email purporting to be from Battle.net, requesting a confirmation of the user’s login information. Users are directed to a fake website designed to look like Battle.net, where they are asked to log in. From there, their information is presumably stolen.&lt;br /&gt;
&lt;br /&gt;
World of Warcraft’s popularity makes it a popular target for phishing scams. Blizzard recently announced that the game had 12 million players worldwide. Blizzard’s policy states that its employees will never request a player’s password.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
&lt;u&gt;Email Spam URL:&lt;/u&gt;&lt;br /&gt;
-hxxxp://www.newsletteraccount.net/login/en/login.html.asp?ref=https://us.battle.net/account/management/index.xml&amp;amp;app=bam&lt;br /&gt;
&lt;br /&gt;
-hxxxp://us-account.net/login/en/login.html.asp?ref=https://us.battle.net/account/management/index.xml&amp;amp;app=bam&lt;br /&gt;
&lt;br /&gt;
-hxxxp://us.battle.net.en.eg-wlk.in/login/en/login.html.asp?ref=https://us.battle.net/account/management/index.xml&amp;amp;app=bam&lt;br /&gt;
&lt;br /&gt;
-hxxxp://us.battle.net.wow-admin.net/&lt;br /&gt;
&lt;br /&gt;
-hxxxp://usadminaccount.in/&lt;br /&gt;
&lt;br /&gt;
-hxxxp://admin-wow.net/&lt;br /&gt;
&lt;br /&gt;
-hxxxp://www.admin-wow.net/&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-Cb2797P5tSk/ToHmDYVQDQI/AAAAAAAABHk/v07qnvSzxH0/s1600/blizzard1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="87" src="http://1.bp.blogspot.com/-Cb2797P5tSk/ToHmDYVQDQI/AAAAAAAABHk/v07qnvSzxH0/s320/blizzard1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Email Phishing format 1&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-Rn_T9y3NTtY/ToHmEgqPtNI/AAAAAAAABHo/O1UAeHEFV5Y/s1600/blizzard2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="181" src="http://3.bp.blogspot.com/-Rn_T9y3NTtY/ToHmEgqPtNI/AAAAAAAABHo/O1UAeHEFV5Y/s320/blizzard2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Email Phishing format 2&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-Yl4DPjW8z7Y/ToHmFOxf5vI/AAAAAAAABHs/i3VFj3EURl0/s1600/blizzard3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-Yl4DPjW8z7Y/ToHmFOxf5vI/AAAAAAAABHs/i3VFj3EURl0/s320/blizzard3.png" width="241" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Email Phishing format 3&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-MlzoHjeeC5c/ToHmFyp5bRI/AAAAAAAABHw/tL3U2Mk7YEU/s1600/blizzard4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-MlzoHjeeC5c/ToHmFyp5bRI/AAAAAAAABHw/tL3U2Mk7YEU/s320/blizzard4.png" width="311" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Email Phishing format 4&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-H1t7_QKW6n4/ToKG4sWDeMI/AAAAAAAABH4/uxPvlv4NUe4/s1600/fake-battlenet.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="151" src="http://4.bp.blogspot.com/-H1t7_QKW6n4/ToKG4sWDeMI/AAAAAAAABH4/uxPvlv4NUe4/s320/fake-battlenet.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Fake Battle.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
IP neighbor for newsletteraccount.net (173.234.243.61):&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
517ks.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
admin-wow.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
anshan521.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
at853.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
at853.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
catuba.org&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
game-10086.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
host64.yydns.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
newsletteraccount.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
wouting.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.at853.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.at853.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.blizzard-battle.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.dgut0769.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.jade-china.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.jn12315.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.newsletteraccount.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
IP neighbor for us.battle.net.en.eg-wlk.in (173.208.131.218):&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
18023.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
admin.zupingan.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
us.battle.net.en.eg-wlk.in&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
webmaster.zupingan.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
IP neighbor for usadminaccount.in (173.234.243.61):&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
517ks.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
admin-wow.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
anshan521.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
at853.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
at853.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
catuba.org&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
game-10086.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
host64.yydns.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
newsletteraccount.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
wouting.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.admin-wow.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.at853.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.at853.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.blizzard-battle.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.dgut0769.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.jade-china.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.jn12315.com&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
www.newsletteraccount.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
us.battle.net.worldofwarcraft.com.admin-war.net&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
us.battie.net.en.funshud.co.cc&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
IP neighbor for us.battle.net.wow-admin.net (173.208.131.221):&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
IP neighbor for usadminaccount.in (173.208.131.220):&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;b&gt;Updated: 2-Oct-11&lt;/b&gt;&lt;br /&gt;
hxxxp://us.battle.net.worldofwarcraft.com.admin-war.net/ &amp;nbsp;- IP Address:&amp;nbsp;173.234.243.61&lt;br /&gt;
hxxxp://us.battie.net.en.funshud.co.cc/ -&amp;nbsp;IP Address:&amp;nbsp;173.234.243.61&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5209968160174585404?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/E_-ulwOyG_dUCTxNkiL7S3ZjVfs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/E_-ulwOyG_dUCTxNkiL7S3ZjVfs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/E_-ulwOyG_dUCTxNkiL7S3ZjVfs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/E_-ulwOyG_dUCTxNkiL7S3ZjVfs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/PgwMhQUCqtY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5209968160174585404/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5209968160174585404" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5209968160174585404?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5209968160174585404?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/PgwMhQUCqtY/phishing-email-scams-targets-blizzard.html" title="Phishing Email Scams targets Blizzard WOW" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Cb2797P5tSk/ToHmDYVQDQI/AAAAAAAABHk/v07qnvSzxH0/s72-c/blizzard1.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/phishing-email-scams-targets-blizzard.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIMR305fip7ImA9WhdbFUg.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-4359028025450892969</id><published>2011-09-27T00:32:00.000-07:00</published><updated>2011-10-13T19:16:26.326-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-13T19:16:26.326-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="windows 7" /><category scheme="http://www.blogger.com/atom/ns#" term="TLS" /><category scheme="http://www.blogger.com/atom/ns#" term="IE" /><category scheme="http://www.blogger.com/atom/ns#" term="TLS 1.1" /><category scheme="http://www.blogger.com/atom/ns#" term="TLS 1.2" /><title>TLS 1.2 in Windows 7</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
There have few discussion about vulnerability in TLS ( Transport Layer Security ) v1.0 recently, there have security concern over TLS 1.0 when two researchers are demostrating their method "BEAST" to bypass and breaking an encrypted PalPal cookies during &lt;a href="http://us.generation-nt.com/redirect.html?url=B2hTIlMhUyQCbQV4DCxXIwB3VSQKIQRnATkHPwEkUj8Ddgd2US5ReFBqBCRdNQUpB2IGblAyVH0%3D"&gt;Ekoparty&lt;/a&gt;&amp;nbsp;conference. This topic also posted in &lt;a href="http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/"&gt;THE REGISTER&lt;/a&gt; - "Hackers break SSL encryption used by millions of sites - Beware of BEAST decrypting secret PayPal cookies"&lt;br /&gt;
&lt;br /&gt;
This attack only works for communication encrypted with TLS 1.0 or less version. Currently there have two client browsers support TLS 1.2 which Opera and IE9 only.&lt;br /&gt;
&lt;br /&gt;
By Default, Windows 7 support TLS 1.1 and TLS 1.2 protocol. To enable the use of protocols that will not negotiated by default.Change the DWORD value data of the &lt;b&gt;DisabledByDefault&lt;/b&gt; value to 0x0 in each of the following registry keys under Protocols key.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&amp;nbsp; &amp;nbsp; SCHANNEL\Protocols\TLS 1.1\Client&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp; &amp;nbsp; SCHANNEL\Protocols\TLS 1.1\Server&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp; &amp;nbsp; SCHANNEL\Protocols\TLS 1.2\Client&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp; &amp;nbsp; SCHANNEL\Protocols\TLS 1.2\Server&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Those Subkey are located under "&lt;b&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL&lt;/b&gt; "&lt;br /&gt;
&lt;br /&gt;
Details about thoe to Restrict the Use of Certain Cryptographic Algorithms can be found from M&lt;a href="http://support.microsoft.com/kb/245030"&gt;icrosoft Support&lt;/a&gt;. http://support.microsoft.com/kb/245030&lt;br /&gt;
&lt;br /&gt;
To verify the changes, you may try to test it out on few&amp;nbsp;TLS interop servers in internet.&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;a href="http://www.mikestoolbox.org/"&gt;http://www.mikestoolbox.org&lt;/a&gt;&amp;nbsp;- Detect client browser TLS version.&lt;/li&gt;
&lt;li&gt;&lt;a href="http://tls.secg.org/"&gt;http://tls.secg.org/index1.php?action=preconnect&lt;/a&gt;&amp;nbsp;-&amp;nbsp;Certicom’s interop server which shows you details about the entire handshake.&lt;/li&gt;
&lt;li&gt;&lt;a href="http://tls.woodgrovebank.com/"&gt;http://tls.woodgrovebank.com&lt;/a&gt;&amp;nbsp;-&amp;nbsp;Microsoft’s TLS interop server&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Updated 13-Oct-2011:&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;Apple iOS 5 added support for TLS1.2&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-4359028025450892969?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qiOJG6rMJW11nOZfL5GixCsCYQw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qiOJG6rMJW11nOZfL5GixCsCYQw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qiOJG6rMJW11nOZfL5GixCsCYQw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qiOJG6rMJW11nOZfL5GixCsCYQw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/bjsifaCN6x4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/4359028025450892969/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=4359028025450892969" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/4359028025450892969?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/4359028025450892969?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/bjsifaCN6x4/tls-12-in-windows-7.html" title="TLS 1.2 in Windows 7" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/tls-12-in-windows-7.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYFRHwzfCp7ImA9WhdUEU0.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-7423070199340831189</id><published>2011-09-26T22:41:00.000-07:00</published><updated>2011-09-26T22:58:35.284-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-26T22:58:35.284-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="malware" /><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="pdf" /><category scheme="http://www.blogger.com/atom/ns#" term="Exploit" /><category scheme="http://www.blogger.com/atom/ns#" term="Pdf exploit" /><title>mysql.com javascript compromised with malicious code</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Few researchers from Armorize Malware Blog have found mysql.com was compromized with hosting malicious codes. The malicious code was injected to .js file which can be obtained from &lt;a href="http://snipt.net/armorize/mysqlcom-injection-point/?key=3a3468c8a3fb7d694a138351c94a5606#"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Basically the decoded script point to "hxxxp://falosfax.in" which will redirecting "302 protocol" to final exploiting websites "hxxxp://truruhfhqnviaosdpruejeslsuy.cx.cc/main.php". The&amp;nbsp;truruhfhqnviaosdpruejeslsuy.cx.cc exploiting client browers plugin like Adobe PDF, Flash, Java and executable malware file.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-4Tvf5MwztXc/ToFD1b-H-OI/AAAAAAAABHg/d8EKEaF99JA/s1600/decoded-malicious_code.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="mysql.com malicious code_remote.js" border="0" src="http://1.bp.blogspot.com/-4Tvf5MwztXc/ToFD1b-H-OI/AAAAAAAABHg/d8EKEaF99JA/s320/decoded-malicious_code.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Right now, the "s_code_remote.js" is clean after removing the code.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/-ouSRboH1LCY/ToFD0dIapeI/AAAAAAAABHc/78q0U-5RC0A/s1600/clean-js.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="mysql.com clean code_remote.js" border="0" src="http://4.bp.blogspot.com/-ouSRboH1LCY/ToFD0dIapeI/AAAAAAAABHc/78q0U-5RC0A/s320/clean-js.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blog.armorize.com/2011/09/mysqlcom-hacked-infecting-visitors-with.html"&gt;READ FULL HERE&lt;/a&gt;&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-7423070199340831189?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KDBOsa0UlRTL7KrbC9AGxJqN5v0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KDBOsa0UlRTL7KrbC9AGxJqN5v0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KDBOsa0UlRTL7KrbC9AGxJqN5v0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KDBOsa0UlRTL7KrbC9AGxJqN5v0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/BljOEvww0WE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/7423070199340831189/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=7423070199340831189" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7423070199340831189?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7423070199340831189?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/BljOEvww0WE/mysqlcom-javascript-compromised-with.html" title="mysql.com javascript compromised with malicious code" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-4Tvf5MwztXc/ToFD1b-H-OI/AAAAAAAABHg/d8EKEaF99JA/s72-c/decoded-malicious_code.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/mysqlcom-javascript-compromised-with.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUASX0-eCp7ImA9WhdUEE0.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-585538607840112908</id><published>2011-09-16T07:45:00.000-07:00</published><updated>2011-09-25T19:30:48.350-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-25T19:30:48.350-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Rootkit" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="webromi" /><title>Mebromi rootkit - BIOS Threat in wild</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Researcher from Webroot and Symantec posted about Mebromi rootkits findings. This is first ever BIOS rootkit Mebromi spread in wild. I am not sure how many of PC infected before the finding, I better switched to better OS. :)&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; **********************************&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are more and more known viruses that infect the MBR (Master Boot Record). Symantec Security Response has published a &lt;a href="http://www.symantec.com/connect/blogs/are-mbr-infections-back-fashion"&gt;blog&lt;/a&gt;&amp;nbsp;to demonstrate this trend last month. However, we seldom confront with one that infects the &lt;a href="http://en.wikipedia.org/wiki/BIOS"&gt;BIOS&lt;/a&gt;.
 One of them is the notorious CIH appeared in 1999, which infected the 
computer BIOS and thus harmed a huge number of computers at that time. 
Recently, we met a new threat named Trojan.Mebromi that can add 
malicious components into Award BIOS which allows the threat to take 
control of the system even before MBR.&lt;br /&gt;
The threat will drop a driver to %system%\drivers\bios.sys, then stop
 the beep service and replace %system%\beep.sys with the dropped one. 
After that it restarts beep service to load the dropped driver.&lt;br /&gt;
bios.sys is used to interact with BIOS such as get BIOS info, flash and backup BIOS.&lt;br /&gt;
&lt;br /&gt;
By using bios.sys, the threat will check whether the compromised 
computer is using Award BIOS. If so, it will save existing BIOS to 
c:\bios.bin and check whether it is already infected:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.symantec.com/connect/blogs/bios-threat-showing-again"&gt;READ FULL HERE&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*******************************&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In the past few weeks a Chinese security company called&amp;nbsp;&lt;strong&gt;&lt;a href="http://bbs.360.cn/4005462/251096134.html" target="_blank"&gt;Qihoo 360&lt;/a&gt;&lt;/strong&gt;
 blogged about a new BIOS rootkit hitting Chinese computers. This turned
 to be a very interesting discovery as it appears to be the first real 
malware targeting system BIOS&amp;nbsp;since a well-known proof of concept called
 &lt;strong&gt;IceLord&lt;/strong&gt; in 2007.&amp;nbsp;The malware is called &lt;strong&gt;Mebromi&lt;/strong&gt;
 and contains a bit of everything: a BIOS rootkit specifically targeting
 Award BIOS, a MBR rootkit, a kernel mode rootkit, a PE file infector 
and a Trojan downloader. At this time, Mebromi is not designed to infect
 64-bit operating system and it is not able to infect the system if run 
with limited privileges.&lt;br /&gt;
The infection starts with a small encrypted dropper that contains five crypted resource files: &lt;em&gt;hook.rom&lt;/em&gt;, &lt;em&gt;flash.dll&lt;/em&gt;, &lt;em&gt;cbrom.exe&lt;/em&gt;, &lt;em&gt;my.sys&lt;/em&gt;, &lt;em&gt;bios.sys&lt;/em&gt;. The goal of these files will be presented later in this analysis.&lt;br /&gt;
The infection is clearly focused on Chinese users, because the 
dropper is carefully checking if the system it’s going to infect is 
protected by Chinese security software &lt;strong&gt;Rising Antivirus&lt;/strong&gt; and &lt;strong&gt;Jiangmin KV Antivirus&lt;/strong&gt;.
 To gain access to the BIOS, the infection first needs to get loaded in 
kernel&amp;nbsp;mode so that it can handle with physical memory instead of 
virtual memory.&lt;br /&gt;
Many of you may&amp;nbsp;recall the old &lt;strong&gt;CIH/Chernobyl&lt;/strong&gt; 
infection, the infamous virus discovered in 1998 that was able to flash 
the motherboard BIOS, erasing it. Even CIH needed to gain kernel mode 
access to reach the BIOS, though at the time the virus was exploiting a 
privilege escalation bug in Windows 9x operating system which allowed it
 to overwrite the Interrupt Descriptor Table with its own payload from 
user mode, then triggering the overwritten interrupt handler and its 
malicious code is executed in kernel mode. Mebromi does not use such 
kind of privilege escalation trick anymore, it just needs to load its 
own kernel mode driver which will handle the BIOS infection. To do so, 
it uses two methods: it could either extract and load the flash.dll 
library which will load the bios.sys driver, or it stops the beep.sys 
service key, overwriting the beep.sys driver with its own bios.sys code,
 restart the service key and restore the original beep.sys code.&lt;br /&gt;
The bios.sys driver is the code which handle the BIOS infection. To 
read the BIOS code, it needs to map the physical memory located at 
physical memory address &lt;em&gt;0xF0000&lt;/em&gt;, this is where the BIOS ROM 
usually resides. Once read, the driver verifies if the BIOS ROM is Award
 BIOS, by checking the presence of the string: &lt;em&gt;$@AWDFLA&lt;/em&gt;. If found, the driver tries to locate the &lt;strong&gt;SMI port&lt;/strong&gt;&amp;nbsp;that will be used by the rootkit to flash the BIOS ROM.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blog.webroot.com/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/"&gt;READ FULL HERE&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-585538607840112908?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Pvn5pB6lOpUrJIuhVCznLXASANg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Pvn5pB6lOpUrJIuhVCznLXASANg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Pvn5pB6lOpUrJIuhVCznLXASANg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Pvn5pB6lOpUrJIuhVCznLXASANg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/JC1KnjtAnY8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/585538607840112908/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=585538607840112908" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/585538607840112908?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/585538607840112908?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/JC1KnjtAnY8/mebromi-rootkit-bios-threat-in-wild.html" title="Mebromi rootkit - BIOS Threat in wild" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/mebromi-rootkit-bios-threat-in-wild.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QCQXo-fip7ImA9WhdWFUg.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2903103521710706603</id><published>2011-09-09T02:09:00.000-07:00</published><updated>2011-09-09T02:09:20.456-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-09T02:09:20.456-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><category scheme="http://www.blogger.com/atom/ns#" term="suspicious" /><title>Suspicious link 9-Sep-2011</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
hxxxp://193.105.154.136/w.php?e=2&amp;amp;f=20&lt;br /&gt;
hxxxp://www.charlesandrecars.com/wp-content/zeus/ext.exe&lt;br /&gt;
hxxxp://gafs.at&lt;br /&gt;
&lt;br /&gt;
hxxxp://posterityn71.com&lt;br /&gt;
hxxxp://rifepfl61.com&lt;br /&gt;
hxxxp://torpormvp35.com&lt;br /&gt;
hxxxp://209.141.60.200&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2903103521710706603?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/CIe08CYLVW-pqJMV_4WQlC1OMHE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/CIe08CYLVW-pqJMV_4WQlC1OMHE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/CIe08CYLVW-pqJMV_4WQlC1OMHE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/CIe08CYLVW-pqJMV_4WQlC1OMHE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/Lj2Wv2vEi00" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2903103521710706603/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2903103521710706603" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2903103521710706603?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2903103521710706603?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/Lj2Wv2vEi00/suspicious-link-9-sep-2011.html" title="Suspicious link 9-Sep-2011" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/suspicious-link-9-sep-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUEDRX8_eip7ImA9WhdWE0g.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-1342108251041957332</id><published>2011-09-06T17:01:00.000-07:00</published><updated>2011-09-06T17:01:14.142-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-06T17:01:14.142-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="TDL4" /><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><title>TDL-4</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Joseph Mlodzianowski from &lt;a href="http://sub0day.com/?page_id=2"&gt;sub0day&lt;/a&gt;&amp;nbsp;had did great article about analysis new variant TDL-4 .It worth to read if you following TDL trends.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;******************************************&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;&lt;strong&gt;Attention… &lt;/strong&gt;&lt;/em&gt;&amp;nbsp;You no longer have to put up 
with google browser search hijacks, popups or annoying spam email.&amp;nbsp; The 
latest and greatest in trojan technology can use your computer to browse
 silently, visiting hundreds of websites per day earning the attacker 
thousands of dollars per day* (botnet).&amp;nbsp; Additionally, it is&amp;nbsp;capable of 
stealing&amp;nbsp;your&amp;nbsp;email, bank account and other passwords on your system as 
well&amp;nbsp;using your computer as a proxy, and&amp;nbsp;all with no intrusive popups.&lt;br /&gt;

This article will focus on the dissection and analysis of a&amp;nbsp;new 
TDL-4&amp;nbsp;”Variant” I believe I discovered. While performing the analysis, 
some interesting trends, data and methods the “underground” is using to 
evade detection and make money were uncovered.&lt;br /&gt;

If you’re new to TDL (TDSS variants) malware, or crimeware in 
general, I suggest several articles written by Sergey Golovanov from 
Kaspersky Lab that can be&amp;nbsp;found here: &lt;a href="http://www.securelist.com/en/userinfo/72"&gt;http://www.securelist.com/en/userinfo/72&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This Stealth trojan malware (TDL4.2) uses the victims computer to 
browse websites with out any signs. It doesn’t display the common 
browser redirects or annoying popups, which normally alert users to the 
fact that they are infected.&amp;nbsp;TDL-4 is detectable and can be removed by 
Kasperskys &lt;a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip"&gt;TDSS Killer&lt;/a&gt;, however, this variant&amp;nbsp;will download and update itself becoming undetectable. [At least for a while]&lt;br /&gt;

The malware is very sophisticated in that it utilizes custom 
encryption and has various methods in which it is capable of&amp;nbsp;avoiding 
detection. It contains a root kit that infects the boot sector allowing 
it&amp;nbsp;to load prior to other drivers, etc..&lt;br /&gt;

Proxy Service – In addition, this&amp;nbsp;variant&amp;nbsp;downloads and uses 
Socks.dll, which allows the victims system to be used&amp;nbsp;as a proxy server 
(AWM Proxy Client), the fine people at awmproxy-dot-com created&amp;nbsp;a 
convenient plug-in for firefox.&amp;nbsp; It appears, you can purchase their 
service and use the plug-in to browse anonymously using tdl infected 
systems.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://sub0day.com/?page_id=2"&gt;READ FULL HERE&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-1342108251041957332?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HnbhauU7XV0mxNsfcE3REOSnUVQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HnbhauU7XV0mxNsfcE3REOSnUVQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HnbhauU7XV0mxNsfcE3REOSnUVQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HnbhauU7XV0mxNsfcE3REOSnUVQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/De21KonZLVw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/1342108251041957332/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=1342108251041957332" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1342108251041957332?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1342108251041957332?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/De21KonZLVw/tdl-4.html" title="TDL-4" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/09/tdl-4.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMFRno9fyp7ImA9WhdXGE4.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-1254141655106111590</id><published>2011-08-31T17:53:00.000-07:00</published><updated>2011-08-31T17:53:37.467-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-31T17:53:37.467-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="websecurity" /><category scheme="http://www.blogger.com/atom/ns#" term="DNS" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="Morto" /><title>Morto worm sets a (DNS) record (Symantec)</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: helvetica, arial, clean, sans-serif; font-size: 13px; line-height: 19px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;There has been a lot of coverage of the recent RDP capable&amp;nbsp;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2011-082908-4116-99" style="color: #004bad; text-decoration: none;"&gt;W32.Morto&lt;/a&gt;&amp;nbsp;worm, but one of the more interesting aspects of the worm’s behavior appears to have been overlooked. Most malware that we have seen recently has some means of communication with a remote Command and Control (C&amp;amp;C) server. The actual vector of communication tends to vary between threats. For example,&amp;nbsp;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-070818-0630-99" style="color: #004bad; text-decoration: none;"&gt;W32.IRCBot&lt;/a&gt;&amp;nbsp;uses Internet Relay Chat channels whereas the recent high profile threat,&amp;nbsp;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2011-052413-1248-99" style="color: #004bad; text-decoration: none;"&gt;Trojan.Downbot&lt;/a&gt;, is capable of reading commands embedded in HTML pages and image files. W32.Morto has added another C&amp;amp;C communication vector by supplying remote commands through Domain Name System (&lt;a href="http://www.ietf.org/rfc/rfc1035.txt" style="color: #004bad; text-decoration: none;"&gt;DNS&lt;/a&gt;) records.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;DNS is primarily used to translate human readable URLs, such as “Symantec.com”, into numerical network identifiers (216.12.145.20). Every URL on the Internet is eventually resolved to an associated IP address using this system, typically using a&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/List_of_DNS_record_types" style="color: #004bad; text-decoration: none;"&gt;DNS A record&lt;/a&gt;&amp;nbsp;for IPv4. The A record is what we usually think of when we discuss DNS. These records map domain names to their associated IP addresses with a PTR record used for the inverse operation of IP to host. But DNS is not limited to these records types; there are a number of record types that have been defined in various RFCs over the years to address the changing needs of the system. The record type that W32.Morto uses for its communication protocol is the TXT record.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;The DNS TXT record type was originally used to allow human readable text to be stored with a DNS record and&lt;a href="http://tools.ietf.org/html/rfc1464" style="color: #004bad; text-decoration: none;"&gt;later&amp;nbsp;&lt;/a&gt;evolved to store machine useable data. To experiment with this, you can use the Microsoft nslookup.exe tool. By querying the TXT record type for “Symantec.com” you can retrieve the&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Sender_Policy_Framework" style="color: #004bad; text-decoration: none;"&gt;SPF&amp;nbsp;&lt;/a&gt;information associated with the Domain.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a href="http://www.symantec.com/connect/blogs/morto-worm-sets-dns-record"&gt;READ FULL HERE&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-1254141655106111590?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/09zeOrMO4mLfQXnUf9xhmiy2C64/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/09zeOrMO4mLfQXnUf9xhmiy2C64/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/09zeOrMO4mLfQXnUf9xhmiy2C64/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/09zeOrMO4mLfQXnUf9xhmiy2C64/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/j2RQh-s5Voc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/1254141655106111590/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=1254141655106111590" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1254141655106111590?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1254141655106111590?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/j2RQh-s5Voc/morto-worm-sets-dns-record-symantec.html" title="Morto worm sets a (DNS) record (Symantec)" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/08/morto-worm-sets-dns-record-symantec.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A04ARns6eip7ImA9WhdXF0s.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-8989055945788493318</id><published>2011-08-30T22:52:00.000-07:00</published><updated>2011-08-30T22:52:27.512-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-30T22:52:27.512-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SSL" /><category scheme="http://www.blogger.com/atom/ns#" term="DigiNotar" /><title>DigiNotar reports security incident</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;
Topic which related to DigiNotar's SSL rouge certification were widely discuss and posted in Web post, twitter and other channel as well. DigiNotar finally officially released public announcement to clarify the incident.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; *************************************&lt;br /&gt;
&lt;br /&gt;
VASCO Data Security International, Inc. (Nasdaq: VDSI; www.vasco.com) today comments on DigiNotar’s reported security incident. DigiNotar is a wholly owned subsidiary of VASCO.&lt;br /&gt;
&lt;br /&gt;
On July 19th 2011, DigiNotar detected an intrusion into its Certificate Authority (CA) infrastructure, which resulted in the fraudulent issuance of public key certificate requests for a number of domains, including Google.com.&lt;br /&gt;
Once it detected the intrusion, DigiNotar has acted in accordance with all relevant rules and procedures.&lt;br /&gt;
At that time, an external security audit concluded that all fraudulently issued certificates were revoked. Recently, it was discovered that at least one fraudulent certificate had not been revoked at the time. &amp;nbsp;After being notified by Dutch government organization Govcert, DigiNotar took immediate action and revoked the fraudulent certificate.&lt;br /&gt;
&lt;br /&gt;
The attack was targeted solely at DigiNotar's Certificate Authority infrastructure for issuing SSL and EVSSL certificates. No other certificate types were issued or compromised. DigiNotar stresses the fact that the vast majority of its business, including his Dutch government business (PKIOverheid) was completely unaffected by the attack.&lt;br /&gt;
&lt;br /&gt;
The company will take every possible precaution to secure its SSL and EVSSL certificate offering, including temporarily suspending the sale of its SSL and EVSSL certificate offerings. The company will only restart its SSL and EVSSL certificate activities after thorough additional security audits by third party organizations.&lt;br /&gt;
&lt;br /&gt;
DigiNotar actively looks for quick and effective solutions for its existing (EV)SSL customers. The company expects to have a solution for its entire customer base before the end of this business week. DigiNotar expects that the cost of this action will be minimal.&lt;br /&gt;
&lt;br /&gt;
The incident at DigiNotar has no consequences whatsoever for VASCO's core authentication technology. The technological infrastructures of VASCO and DigiNotar are completely separated, meaning that there is no risk for infection of VASCO’s strong authentication business.&lt;br /&gt;
&lt;br /&gt;
VASCO expects the impact of the breach of DigiNotar’s SSL and EVSSL business to be minimal. Through the first six months of 2011, revenue from the SSL and EVSSL business was less than Euro 100,000.&lt;br /&gt;
VASCO does not expect that the DigiNotar security incident will have a significant impact on the company’s future revenue or business plans.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx"&gt;READ FULL HERE&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-8989055945788493318?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_vyFdx9wc_-JKXH3zWin2drri4Y/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_vyFdx9wc_-JKXH3zWin2drri4Y/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_vyFdx9wc_-JKXH3zWin2drri4Y/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_vyFdx9wc_-JKXH3zWin2drri4Y/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/4RJt18DXZO0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/8989055945788493318/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=8989055945788493318" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8989055945788493318?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8989055945788493318?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/4RJt18DXZO0/diginotar-reports-security-incident.html" title="DigiNotar reports security incident" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/08/diginotar-reports-security-incident.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkEMQnk4eSp7ImA9WhdXFE8.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-3165277803224446450</id><published>2011-08-26T22:58:00.000-07:00</published><updated>2011-08-26T22:58:03.731-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-26T22:58:03.731-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="sophos" /><category scheme="http://www.blogger.com/atom/ns#" term="Apple" /><title>Apple iCloud phishing attacks</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;No surprise if Apple iCloud become of the phishing target by hacker. Below is the post by Sophos about Apple iCloud phishing attacks in details.&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; **************************&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 16px; line-height: 16px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;When a Naked Security reader forwarded us a suspicious email he received today, it served as a healthy reminder for all computer users to be on their guard against phishing attacks.&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;The email claims to come from Apple, and appears to have targeted our correspondent because he is a user of Apple's MobileMe service.&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Apple is planning to shut down its MobileMe service in mid-2012, as it is readying its new iCloud service (which will store music, photos, calendars, documents etc in 'the cloud' and wirelessly push them to all of your devices).&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Understandably, a lot of MobileMe users are interested in how they will migrate to iCloud and this is the issue that the phishing email uses as bait.&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;img alt="iCloud phishing email" src="http://sophosnews.files.wordpress.com/2011/08/icloud-phish.jpg?w=640" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 3px; max-width: 500px; padding-bottom: 5px; padding-left: 5px; padding-right: 10px; padding-top: 0px; vertical-align: baseline;" title="iCloud phishing email" /&gt;&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;strong style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-weight: bold; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Subject:&lt;/strong&gt;&lt;/div&gt;&lt;blockquote style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; margin-bottom: 1em; margin-left: 40px; margin-right: 40px; margin-top: 1em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Welcome to iCLOUD&lt;/tt&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;strong style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-weight: bold; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Message body:&lt;/strong&gt;&lt;/div&gt;&lt;blockquote style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; margin-bottom: 1em; margin-left: 40px; margin-right: 40px; margin-top: 1em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Important information for MobileMe members.&lt;/tt&gt;&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Dear MobileMe member,&lt;/tt&gt;&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Please sign up for iCloud and click the submit botton, you'll be able to keep your old&lt;br /&gt;
email address and move your mail, contacts, calendars, and bookmarks to the new service.&lt;/tt&gt;&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Your subscription will be automatically extended through July 31, 2012, at no additional charge.&lt;br /&gt;
After that date, MobileMe will no longer be available.&lt;/tt&gt;&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Click here to update iCLOUD&lt;/tt&gt;&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Sincerely,&lt;/tt&gt;&lt;/div&gt;&lt;div style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; line-height: normal; margin-bottom: 10px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;tt style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: courier, monospace; font-size: 14px; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;The Apple store Team&lt;/tt&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;br /&gt;
&lt;a href="http://nakedsecurity.sophos.com/2011/08/26/welcome-to-apple-icloud-phishing-attacks/"&gt;READ MORE HERE&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-3165277803224446450?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/sYV8104rVSPIyIjyxPZkMdX79i4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sYV8104rVSPIyIjyxPZkMdX79i4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/sYV8104rVSPIyIjyxPZkMdX79i4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sYV8104rVSPIyIjyxPZkMdX79i4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/C8CdXi0TvVo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/3165277803224446450/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=3165277803224446450" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3165277803224446450?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3165277803224446450?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/C8CdXi0TvVo/apple-icloud-phishing-attacks.html" title="Apple iCloud phishing attacks" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.web2secure.com/2011/08/apple-icloud-phishing-attacks.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIDQX8-eip7ImA9WhdXFE8.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-1466993744412144861</id><published>2011-08-26T22:39:00.000-07:00</published><updated>2011-08-26T22:39:30.152-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-26T22:39:30.152-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CVE-2011-3192" /><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Apache" /><title>Apache Web Server Vulnerable CVE-2011-3192</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;Apache Software Foundation announced their Apache Web Server (Httpd) vulnerable (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3192"&gt;CVE-2011-3192)&lt;/a&gt; to attack. According to &lt;a href="http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3C20110824161640.122D387DD@minotaur.apache.org%3E"&gt;source&lt;/a&gt;, the attack can be done remotely and with a modest number of requests can&amp;nbsp;cause very significant memory and CPU usage on the server. Patch to fix vulnerability is expected to release by another 46 Hours.&lt;br /&gt;
&lt;br /&gt;
Luckily, there have mitigation steps are in place to counter the attack while waiting for patch to fix the vulnerable Httpd.&lt;br /&gt;
&lt;br /&gt;
Mitigation Steps:&lt;br /&gt;
&lt;br /&gt;
1) Use SetEnvIf or mod_rewrite to detect a large number of ranges and then&lt;br /&gt;
&amp;nbsp; &amp;nbsp;either ignore the Range: header or reject the request.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;Option 1: (Apache 2.0 and 2.2)&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # Drop the Range header when more than 5 ranges.&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # CVE-2011-3192&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SetEnvIf Range (,.*?){5,} bad-range=1&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RequestHeader unset Range env=bad-range&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # optional logging.&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CustomLog logs/range-CVE-2011-3192.log common env=bad-range&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;Option 2: (Also for Apache 1.3)&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # Reject request when more than 5 ranges in the Range: header.&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # CVE-2011-3192&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RewriteEngine on&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RewriteCond %{HTTP:range} !(^bytes=[^,]+(,[^,]+){0,4}$|^$)&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RewriteRule .* - [F]&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;The number 5 is arbitrary. Several 10's should not be an issue and may be&lt;br /&gt;
&amp;nbsp; &amp;nbsp;required for sites which for example serve PDFs to very high end eReaders&lt;br /&gt;
&amp;nbsp; &amp;nbsp;or use things such complex http based video streaming.&lt;br /&gt;
&lt;br /&gt;
2) Limit the size of the request field to a few hundred bytes. Note that while&lt;br /&gt;
&amp;nbsp; &amp;nbsp;this keeps the offending Range header short - it may break other headers;&lt;br /&gt;
&amp;nbsp; &amp;nbsp;such as sizeable cookies or security fields.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; LimitRequestFieldSize 200&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;Note that as the attack evolves in the field you are likely to have&lt;br /&gt;
&amp;nbsp; &amp;nbsp;to further limit this and/or impose other LimitRequestFields limits.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;See: &lt;a href="http://httpd.apache.org/docs/2.2/mod/core.html#limitrequestfieldsize"&gt;http://httpd.apache.org/docs/2.2/mod/core.html#limitrequestfieldsize&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
3) Use mod_headers to completely dis-allow the use of Range headers:&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RequestHeader unset Range&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;Note that this may break certain clients - such as those used for&lt;br /&gt;
&amp;nbsp; &amp;nbsp;e-Readers and progressive/http-streaming video.&lt;br /&gt;
&lt;br /&gt;
4) Deploy a Range header count module as a temporary stopgap measure:&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://people.apache.org/~dirkx/mod_rangecnt.c"&gt;http://people.apache.org/~dirkx/mod_rangecnt.c&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;Precompiled binaries for some platforms are available at:&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;&lt;a href="http://people.apache.org/~dirkx/BINARIES.txt"&gt;http://people.apache.org/~dirkx/BINARIES.txt&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
5) Apply any of the current patches under discussion - such as:&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp;&lt;a href="http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g@mail.gmail.com%3e"&gt;http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g@mail.gmail.com%3e&lt;/a&gt;&lt;br /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Another latest research from Netcraft about &lt;a href="http://news.netcraft.com/archives/2011/08/05/august-2011-web-server-survey-3.html"&gt;Web Server Survey,&lt;/a&gt; it indicates Apache Web Server still dominate compare to other Web Server (like ngix, Microsoft, Google). It also potentially leaving up&amp;nbsp;65.86% Apache Web Server vulnerable (CVE-2011-3192)&amp;nbsp;to DoS attack.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-1466993744412144861?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qKttk0pMYKtx0ONr_07PehYsHMk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qKttk0pMYKtx0ONr_07PehYsHMk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qKttk0pMYKtx0ONr_07PehYsHMk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qKttk0pMYKtx0ONr_07PehYsHMk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/y4w1BHRaXEE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/1466993744412144861/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=1466993744412144861" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1466993744412144861?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/1466993744412144861?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/y4w1BHRaXEE/apache-web-server-vulnerable-cve-2011.html" title="Apache Web Server Vulnerable CVE-2011-3192" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.web2secure.com/2011/08/apache-web-server-vulnerable-cve-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEQHQHwycCp7ImA9WhdXFE8.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-709568973101208604</id><published>2011-08-26T22:18:00.000-07:00</published><updated>2011-08-26T22:18:51.298-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-26T22:18:51.298-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="GFI" /><title>Facebook Makes a Move Toward Security</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, sans-serif; font-size: x-small; line-height: 19px;"&gt;Facebook recently&amp;nbsp;&lt;a href="https://www.facebook.com/safety/attachment/Guide%20to%20Facebook%20Security.pdf" style="color: #ff9900; text-decoration: none;"&gt;published a guide for it's users on how to secure their online accounts&lt;/a&gt;from anything that threatens one's&amp;nbsp;&lt;i&gt;Facebook&lt;/i&gt;&amp;nbsp;security. Among those covered are Wall, Chat, and Comment spams, weak passwords, fake applications, and account hacking. Personally, I'm quite happy that&amp;nbsp;&lt;i&gt;Facebook&lt;/i&gt;&amp;nbsp;is actually doing something that concerns user security, despite it being quite late come to think about it. Still, better to have something than nothing.&lt;br /&gt;
&lt;br /&gt;
The document guide contains practical tips and cases to illustrate the gravity of the attack if ignored. It also has some great, agreeable points that make it a good reference anyone can recommend to their friends and family who are on&amp;nbsp;&lt;i&gt;Facebook&lt;/i&gt;. Feel free to download&amp;nbsp;&lt;a href="https://www.facebook.com/safety/attachment/Guide%20to%20Facebook%20Security.pdf" style="color: #ff9900; text-decoration: none;"&gt;here&lt;/a&gt;&amp;nbsp;and distribute.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, sans-serif; font-size: x-small; line-height: 19px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, sans-serif; font-size: x-small; line-height: 19px;"&gt;&lt;a href="http://sunbeltblog.blogspot.com/2011/08/facebook-makes-move-toward-security.html"&gt;READ MORE HERE&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-709568973101208604?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/wuPaKp3RURC4bMRb4JpXwJYqUxo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wuPaKp3RURC4bMRb4JpXwJYqUxo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/wuPaKp3RURC4bMRb4JpXwJYqUxo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wuPaKp3RURC4bMRb4JpXwJYqUxo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/EyYlUbwj1fk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/709568973101208604/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=709568973101208604" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/709568973101208604?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/709568973101208604?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/EyYlUbwj1fk/facebook-makes-move-toward-security.html" title="Facebook Makes a Move Toward Security" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.web2secure.com/2011/08/facebook-makes-move-toward-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04DR3k5fSp7ImA9WhdXFE8.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5969529657408645922</id><published>2011-08-26T22:12:00.000-07:00</published><updated>2011-08-26T22:12:56.725-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-26T22:12:56.725-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="SEO" /><category scheme="http://www.blogger.com/atom/ns#" term="websense" /><title>Follow Me Not - Microblog SEO Study (Websense)</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;span&gt;&lt;span&gt;With the release of&lt;/span&gt;&amp;nbsp;Social Web Control,&amp;nbsp;&lt;/span&gt;&lt;span&gt;Websense Security Labs&lt;span&gt;&lt;span&gt;™&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;nbsp;looks  at the growing trend&amp;nbsp;of how you can optimize your popularity ranking on  social Web sites&amp;nbsp;such as Twitter and Sina's Weibo.&lt;/span&gt;&lt;br /&gt;
&lt;span&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
Marketeers are heavily tuning social Web sites for Search Engine  Optimization (SEO) in a similar way&amp;nbsp;to standard Web sites, where SEO is  still the primary source of information traffic. In parallel,  cyber-criminals also use BlackHat SEO to spread malware. A high social  Web ranking&amp;nbsp;is becoming an important tool to&amp;nbsp;receive constant exposure  and get messages out to the desired target audiences, hence the race  from both personal and business microblog users to boost their  recognition. To attract or to be featured on microblog platforms, you  need a very large follower base in a very short time.&lt;br /&gt;
&lt;br /&gt;
Weibo.com, being one of the largest microblog platforms in China with  over 200 million users,&amp;nbsp;attracted a different kind of user. Seeing  potentially unlimited business opportunities, many users were spoofing  as&amp;nbsp;famous companies and celebrities to publish false messages to the  public.&amp;nbsp;Weibo recently enforced true identity verification as identify  theft became an increased problem. To counter this, ranking  "smoke-screen" services are popping up,&amp;nbsp;leading to&amp;nbsp;the idea to "Shua  Fen": purchase followers. The screenshot below shows 2 Weibo accounts  with avatars advertising services for "Microblog, get thousands of  followers", and "Paid Followers and get verified".&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://community.websense.com/blogs/securitylabs/archive/2011/08/24/FollowMeNot.aspx"&gt;READ MORE HERE&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5969529657408645922?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/dLd-txNrDJcW_wcg90IpjU-tFXY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dLd-txNrDJcW_wcg90IpjU-tFXY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/dLd-txNrDJcW_wcg90IpjU-tFXY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dLd-txNrDJcW_wcg90IpjU-tFXY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WebSecurityWeblog/~4/Cl3oQq3vqTU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5969529657408645922/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5969529657408645922" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5969529657408645922?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5969529657408645922?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/Cl3oQq3vqTU/follow-me-not-microblog-seo-study.html" title="Follow Me Not - Microblog SEO Study (Websense)" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="27" height="32" src="http://2.bp.blogspot.com/-zpdfz0MxO5U/ToUcNsyY8iI/AAAAAAAABIE/95SMjBkDH1g/s220/ULquiorra.png" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.web2secure.com/2011/08/follow-me-not-microblog-seo-study.html</feedburner:origLink></entry></feed>

