<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: defacers]]></title>
    <link>http://securityratty.com/tag/defacers</link>
    <description></description>
    <pubDate>Tue, 01 Apr 2008 02:25:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Monetizing Compromised Web Sites]]></title>
      <link>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</link>
      <guid>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</guid>
      <description><![CDATA[Despite that pure patriotic hacktivism is still alive and kicking, compromised sites are largely getting monetized these days, starting from hosting blackhat SEO junk pages, to redirecting to live...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/CA2dvGI0DL0/s1600-h/Municipal_de_Amparo.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/k2bP_iz48tA/s200-R/Municipal_de_Amparo.png" style="border: 0pt none ;" /></a>Despite that pure patriotic hacktivism is still alive and kicking, <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">compromised sites are largely getting monetized</a> these days, starting from hosting blackhat SEO junk pages, to redirecting to live exploit URLs and fake codecs where revenue is earned through their participation in an affiliate business model.<br />
<br />
With The Africa Middle Market Fund's site monetized by web site defacers who defaced it "in between" the blackhat SEO infrastructure they were hosting internally, in this I'll comment on the currently compromised and redirection to a fake porn sites, Camara Municipal de Amparo (<b>camaraamparo.sp.gov.br/r.html</b>). Basically, it's homepage is heavily linking to the Zlob variant (<b>camaraamparo.sp.gov.br/ video.exe</b>) in between loading an IFRAME to <b>61.162.230.12/ index.php</b>. As always, upon uploading their redirector, they've build enough confidence into their new hosting provider that the link to the redirector was instantly spammed across the web. The site is so heavily linking to the internal redirector itself, that upon clicking on the majority of links the user will inevitably come across it.<br />
<br />
Speaking of fake porn sites redirecting to Zlob variants, here are the very latest additions spammed across the web through blackhat SEO practices :<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/ZDNLECdRM1U/s1600-h/fake_porn_sites_zlob.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/TIqQ0wE9bQM/s200-R/fake_porn_sites_zlob.JPG" style="border: 0pt none ;" /></a><b>just-tube .com<br />
mypornmovies .net<br />
moms-galls .net<br />
porntubefilms .com<br />
porntubedot .com<br />
hot-porntube .com<br />
landmovieblog .com<br />
sexvidtube .com<br />
freelifevideo .com<br />
getyourfreemovie .com<br />
iubat .com<br />
sweetyjoly .com<br />
hardbizarre .com<br />
freeworldvideo .net<br />
hot-porntube .net<br />
qualitymovies .net<br />
porntube1con .net<br />
video-info .net<br />
videocityblog .com<br />
fuckedolder&nbsp; .com<br />
highpro1 .com<br />
max-graf.com .pl<br />
grandsupertds .info<br />
hot-porn-tube .net<br />
hot-porntube .com<br />
terryschulz .com<br />
show-sextube .com<br />
qualitymovies .net<br />
clubvideos .net</b><br />
<br />
No matter the high profile site that's been exploited in order to participate in such malicious operations, for the time being, crunching out new domain names and using the hosting services of the well known ISPs neglecting their removal, seems to be the tactic of choice. The long tail of SQL injected sites is however, clearly replacing the plain simple blackhat SEO web spamming, so that traffic to these rogue sites is driven through redirection of the the traffic from legitimate sites.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cEyKTJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cEyKTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qsdYjJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qsdYjJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVongj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVongj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4DJmRj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4DJmRj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=al8bCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=al8bCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nrE7PJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nrE7PJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TCjewj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TCjewj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/334911319" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 23:26:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/rogue sites">rogue sites</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/web site defacers">web site defacers</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/profile site">profile site</category>
      <category domain="http://securityratty.com/tag/redirector">redirector</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/334911319/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Web Site Defacements]]></title>
      <link>http://securityratty.com/article/9c0b522d99880bbb79d7258c5f16975f</link>
      <guid>http://securityratty.com/article/9c0b522d99880bbb79d7258c5f16975f</guid>
      <description><![CDATA[What used to be a harmless web site defacements back in the old school days, is today's ongoing monetization of defaced web sites, a logical development given the consolidation between different...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SFKBgjBBwkI/AAAAAAAAByo/TVBWvnlCxq8/s1600-h/africa_fund_defaced.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SFKBgjBBwkI/AAAAAAAAByo/TVBWvnlCxq8/s200/africa_fund_defaced.png" alt="" id="BLOGGER_PHOTO_ID_5211370114976432706" border="0" /></a>What used to be a harmless web site defacements back in the old school days, is today's ongoing monetization of defaced web sites, a logical development given the consolidation between different underground parties, evidence of which can be seen in the majority of incidents I've been analyzing recently.<br /><br /><a href="http://africammfund.com">The Africa Middle Market Fund</a>' site is the latest example of a web site defacer is abusing the access to the web server to generate and locally host blackhat SEO pages, which when once access only by searching for the keywords and consequently returning 404 if traffic isn't coming from a search engine, redirect to known rogue security software, in this case, the <a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">XP antivirus protection</a> (<span style="font-weight: bold;">securityscannersite.com</span>) which you must be familiar with if you were following the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">assessments</a> of the <a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">massive IFRAME</a> SEO <a href="http://ddanchev.blogspot.com/2008/03/more-cnet-sites-under-iframe-attack.html">poisoning attacks</a> that took place during March this year. More about the found :<br /><br />"<span style="font-style: italic;">The Africa Middle Market Fund is a private capital fund that invests in small and medium sized African businesses who need from $500,000 up to $2 million to grow and succeed to their full potential. We are a "double bottom-line" or "impact investment" fund, meaning that we care equally about financial performance and social benefit. We are for-profit and insist on our investees employing world standards of financial and business management to maximize their chances of success</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFKLPBOgSkI/AAAAAAAAByw/N8jiOnSohiw/s1600-h/africa_fund_blackhat_seo.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFKLPBOgSkI/AAAAAAAAByw/N8jiOnSohiw/s200/africa_fund_blackhat_seo.JPG" alt="" id="BLOGGER_PHOTO_ID_5211380808964655682" border="0" /></a>Most of the outgoing links from a sample of over 50 blackhat SEO pages at the site point to <span style="font-weight: bold;">23search.org</span>, which is an invitation-only affiliate based network for traffic exchange, connecting different malicious parties together :<br /><br />"<span style="font-style: italic;">What is this site? This site helps webmasters to earn money with their sites. How it works? Our program generate traffic from search engines and display advertising. What shell I do to start with you? Signup, get php file from member area, put file into your website directory, modify or create .htaccess in the same directory, and receive money!</span>"<br /><br />The session is then redirected to <span style="font-weight: bold;">drivemedirect.com/soft.php?aid=0195&amp;d=3&amp;product=XPA,</span> as well as to<span style="font-weight: bold;"> drivemedirect.com/soft.php?aid=0263&amp;d=2&amp;product=XPC </span>to ultimately redirect the user to<span style="font-weight: bold;"> online-xpcleaner.com/2/freescan.php?aid=880263<br /><br /></span>Moreover, the majority of blackhat SEO campaigns are also starting to apply evasive techniques to make it harder to analyze them. In this particular campaign for instance, only traffic comming from search engines would get the chance to see the SEO page due to the use of document.referrer tags. Here are some sample monitization practices from what I've seen between the lines of recently defaced sites :<br /><br />- installing web backdoors and reselling the access to phishers, spammers and malware authors who would have full control over the content, and can therefore do whatever they to with the web server<br /><br />- installing web based spamming tools that later on will be either used directly by the defacers, or access to the tools sold to those interested in using them<br /><br />- participating in an affiliate based blackhat SEO networks, where revenue coming of the victims w<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFKcYCaWu9I/AAAAAAAABy4/X2y_2cplAoE/s1600-h/africa_fund_blackhat_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFKcYCaWu9I/AAAAAAAABy4/X2y_2cplAoE/s200/africa_fund_blackhat_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5211399655599291346" border="0" /></a>ho installed the rogue software is shared among the defacer and the affiliate based network, which doesn't really care how and where is all the traffic coming from<br /><br />- forwarding the responsibility of hosting phishing pages to the legitimate site by hosting them locally in between sending the phishing emails again using the same host<br /><br />- selling the access by promoting it based on its page rank<br /><br />Web site defacements in times when <a href="http://blogs.zdnet.com/security/?p=1200">traffic suppliers are efficiently coordinating campaigns with traffic seekers</a>, will mature into a tool for providing malicious infrastructure on demand, just like botnets did. Then again, the endless possibilities provided by insecure web applications are already blurring the lines between web site defacements and SQL injections.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br /><a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br /><a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br /><a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br /><a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br /><div><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a></div> <div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div> <div><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a></div> <a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2008/05/blackhat-seo-campaign-at-millennium.html">Blackhat SEO Campaign at The Millennium Challenge Corporation</a><br /><a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">Massive IFRAME SEO Poisoning Attack Continuing</a><br /><a href="http://ddanchev.blogspot.com/2008/02/massive-blackhat-seo-targeting-blogspot.html">Massive  Blackhat SEO Targeting Blogspot</a><br /><a href="http://ddanchev.blogspot.com/2008/01/invisible-blackhat-seo-campaign.html">The  Invisible Blackhat SEO Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/01/attack-of-seo-bots-on-edu-domain.html">Attack  of the SEO Bots on the .EDU Domain</a><br /><a href="http://ddanchev.blogspot.com/2007/11/p0rngov-ongoing-blackhat-seo-operation.html">p0rn.gov  - The Ongoing Blackhat SEO Operation</a><br /><a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign.html">The Continuing .Gov Blackat SEO Campaign</a><br /><a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign_25.html">The Continuing .Gov Blackhat SEO Campaign - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/10/compromised-sites-serving-malware-and.html">Compromised Sites Serving Malware and Spam</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NKDexI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NKDexI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hZINeI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hZINeI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3PrFbi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3PrFbi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nDo4mi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nDo4mi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jT9iqI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jT9iqI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YLiNQI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YLiNQI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sAhmSi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sAhmSi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/311270173" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 07:54:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/web site defacements">web site defacements</category>
      <category domain="http://securityratty.com/tag/site helps webmasters">site helps webmasters</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/traffic exchange">traffic exchange</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/traffic suppliers">traffic suppliers</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/311270173/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</source>
    </item>
    <item>
      <title><![CDATA[Phishing Tactics Evolving]]></title>
      <link>http://securityratty.com/article/30ee59a46d8acb7f8fa8466791f3491d</link>
      <guid>http://securityratty.com/article/30ee59a46d8acb7f8fa8466791f3491d</guid>
      <description><![CDATA[Malware authors, phishers and spammers have been actively consolidating for the past couple of years, and until they figure out to to vertically integrate and limit the participation of other pa rties...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SAwAZhnVfUI/AAAAAAAABl4/OMpqebw9CrM/s1600-h/malware_infected_host_phishing.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SAwAZhnVfUI/AAAAAAAABl4/OMpqebw9CrM/s200/malware_infected_host_phishing.jpg" alt="" id="BLOGGER_PHOTO_ID_5191524908971425090" border="0" /></a><a href="http://ddanchev.blogspot.com/2007/12/phishers-spammers-and-malware-authors.html">Malware authors, phishers and spammers have been actively consolidating</a> for the past couple of years, and until they figure out to to vertically integrate and limit the participation of other pa<a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">rties in their activities, this development will continue to remain so. Malware infected hosts are not getting used as stepping stones</a> these days, for <a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT</a> or <a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">cyber espionage</a> purposes, but also, for sending and hosting phishing pages, a tactic in which I'm seeing an increased interest as of recently.  Here are some example of recently spammed phishing campaigns hosting the phishing pages on end user's PCs :<br /><br />- <span style="font-weight: bold;">pool-71-116-244-232.lsanca.dsl-w.verizon.net</span><br />- <span style="font-weight: bold;">user-142o3ds.cable.mindspring.com</span>/online.lloydstsb.co.uk/customer.ibc/logon.html<br />- <span style="font-weight: bold;">user-142o3ds.cable.mindspring.com</span>/onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br />- <span style="font-weight: bold;">user-142o3ds.cable.mindspring.com</span>/halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin.aspsource=halifaxcouk<br />-<span style="font-weight: bold;"> stolnick-8marta-8b-r1-c1-45.ekb.unitline.ru</span>/halifax-online.co.uk/_mem_bin<br />- <span style="font-weight: bold;">zux006-052-125.adsl.green.c</span>h/onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br />- <span style="font-weight: bold;">rrcs-74-218-5-6.central.biz.rr.com</span>/webview/files//onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br />- <span style="font-weight: bold;">user-0c93qog.cable.mindspring.com</span>/onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br /><br />The second tactic that I've been researching for a while is that of remotely SQL injecting or remotely file including phishing pages on vulnerable sites, as for instance, someone's actively abusing vulnerable sites, which are apparently noticing this malicious activities and taking care of their web application vulnerabilities. Some recent examples include :<br /><br />- <span style="font-weight: bold;">kclmc.org</span>/components/www.halifax.co.uk/_mem_bin/FormsLogin.aspsource=halifaxcouk/Index.PHP<br />- <span style="font-weight: bold;">citrusfsc.org</span>/templates_c/www.halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin.aspsource=halifaxcouk/index.html<br />- <span style="font-weight: bold;">agentur-schneckenreither.com</span>/administrator/components/com_joomfish/help/www.halifax.co.uk/_mem_bin/formslogin.asp/index.php<br />-<span style="font-weight: bold;"> dziswesele.pl</span>/media/www.halifax.co.uk/_mem_bin/formslogin.asp/<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SAwF4xnVfVI/AAAAAAAABmA/5wNw0ziCkX0/s1600-h/equidi_hacked_phishing_hosting.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SAwF4xnVfVI/AAAAAAAABmA/5wNw0ziCkX0/s200/equidi_hacked_phishing_hosting.jpg" alt="" id="BLOGGER_PHOTO_ID_5191530943400475986" border="0" /></a>In November, 2007, I started making the connecting between a Turkish defacement group that wasn't just defacing the web sites it was coming across, but was also <a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere.html">hosting malware on the vulnerable sites</a> :<br /><br />"<span style="font-style: italic;">It gets even more interesting, as it appears that a Turkish defacer like the  ones </span><a style="font-style: italic;" href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">I  blogged about yesterday</a><span style="font-style: italic;"> is somehow connected with the group behind the  recent Possibility Media's Attack, and the Syrian Embassy Hack as some of his  IFRAMES are using the exact urls in the previous attacks.</span>"<br /><br />As of recently, I'm starting to see more such activity, with various defacing groups realizing that monetizing their defacements can indeed improve their revenue streams. For instance, <span style="font-weight: bold;">findaswap.co.uk/administrator/components/com_extplorer/www.Halifax.co.uk/_mem_bin/formslogin.asp/</span>was serving a phishing page, and was also recently <a href="http://www.turk-h.org/defacement/view/268495/findaswap.co.uk/modules">hacked by a Turkish defacement group</a>. Moreover, <span style="font-weight: bold;">equidi.com</span> which is currently defaced is also hosting the following phishing pages within its directory structure, namely, <span style="font-weight: bold;">equidi.com/New2008/Orange</span>; <span style="font-weight: bold;">equidi.com/New2008/www.bankofamerica.com</span>; <span style="font-weight: bold;">equidi.com/New2008/www.halifax.co.uk</span><br /><br />Why are all of these tactics so smart? Mainly because they forward the responsibility to the infected party, and I can reasonably argue that a phishing page hosted at a .biz or .info tld will get shut down faster than the one hosted at a home user's PC. As for the SQL injections, the RFI, and the consolidation between defacers and phishers if it's not defacers actually phishing for themselves, what we might witness anytime now is a vulnerable financial institutions web sites' hosting phishing page, or its web application vulnerabilities used against itself in a social engineering attempt.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UDiiO1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UDiiO1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VHJ21hG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VHJ21hG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCSx1Tg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCSx1Tg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NlLC6ug"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NlLC6ug" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6vWhX8G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6vWhX8G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=je1QVMG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=je1QVMG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1a1eW8g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1a1eW8g" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/274774878" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 07:18:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/halifax-online">halifax-online</category>
      <category domain="http://securityratty.com/tag/halifax">halifax</category>
      <category domain="http://securityratty.com/tag/mem binformslogin">mem binformslogin</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/user-142o3ds">user-142o3ds</category>
      <category domain="http://securityratty.com/tag/web application vulnerabilities">web application vulnerabilities</category>
      <category domain="http://securityratty.com/tag/mem binhalifax loginformslogin">mem binhalifax loginformslogin</category>
      <category domain="http://securityratty.com/tag/vulnerable sites">vulnerable sites</category>
      <category domain="http://securityratty.com/tag/turkish defacement">turkish defacement</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/274774878/phishing-tactics-evolving.html">Phishing Tactics Evolving</source>
    </item>
    <item>
      <title><![CDATA[China's CERT Annual Security Report - 2007]]></title>
      <link>http://securityratty.com/article/8eec1b2624eb89fa1310133e71a9abdb</link>
      <guid>http://securityratty.com/article/8eec1b2624eb89fa1310133e71a9abdb</guid>
      <description><![CDATA[Every coin has two sides, and while China has long embraced unrestricted warfare and people's information warfare for conducting cyber espionage, China's networked infrastructure is also under attack,...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SAvJARnVfPI/AAAAAAAABlQ/7XmltP8sxhc/s1600-h/CN_CERT_2007.jpg"><img id="BLOGGER_PHOTO_ID_5191464002040200434" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SAvJARnVfPI/AAAAAAAABlQ/7XmltP8sxhc/s200/CN_CERT_2007.jpg" border="0" /></a>Every coin has two sides, and while China has long embraced <a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">unrestricted warfare</a> and <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare</a> for conducting cyber espionage, China's networked infrastructure is also under attack, and is logically used as stepping stone to hit others country's infrastructures, thereby contributing to the possibility to engineer cyber warfare tensions.<br /><br /><div></div>A week ago, <a href="http://www.cert.org.cn/UserFiles/File/CNCERTCC2007AnnualReport_Chinese.pdf">China's CERT released their annual security report</a> (in Chinese for the time being), outlining the local threatscape with data indicating the increasing efficiency applied by Turkish web site defacement groups, in between the logical increases in spam/phishing and malware related incidents. Here's an excerpt from the report :<br /><br /><div>"<em>According CNCERT / CC monitoring found that in 2007 China's mainland are implanted into the host Trojans alarming increase in the number of IP is 22 times last year, the Trojans have become the largest Internet hazards. Underground black mature industrial chain for the production and the large number of Trojans wide dissemination provides a very convenient conditions, Trojan horses on the Internet led to the proliferation of a lot of personal information and the privacy of data theft, to the personal reputation and cause serious economic losses; In addition, the Trojans also increasingly being used to steal state secrets and secrets of the state and enterprises incalculable losses, the Chinese mainland are implanted into the Trojan Horse computer controlled source, the majority in China's Taiwan region, the phenomenon has been brought to the agency's attention. <strong>Zombie network is still the basic network attacks platform means and resources. 2007 CNCERT / CC sampling found to be infected with a zombie monitoring procedures inside and outside the mainframe amounted to 6.23 million, of which China's mainland has 3.62 million IP addresses were implanted zombie mainframe procedures, and more than 10,000 outside the control server to China Host mainland control.</strong> Zombie networks primarily be used launch denial of service (DdoS) attacks, send spam, spread malicious code, as well as theft of the infected host of sensitive information, issued by the zombie network flow, distributed DDOS attack is recognized in the world problems not only seriously affect the operation of the Internet business, but also a serious threat to China's Internet infrastructure in the safe operation. 2007 China's Internet domain name registration and the use of quantitative rapid growth, reaching 11.93 million, an annual growth rate of 190.4 percent, while hackers use of domain names has become a major tool. Use of domain names, the attackers could be flexible, hidden website linked to the implementation of large-scale horse zombie network control, network malicious activities such as counterfeiting. Fast-Flux domain names, such as dynamic analysis technologies, resulting in accordance with the IP to the attacks more difficult to trace and block; 2007 domain names which has been in use analytical services for the existence of security flaws, the public domain analysis of the server domain hijacking security incidents, a large number of users without knowing the circumstances of their fishing lure to the site or sites containing malicious code, such incidents very great danger. Therefore, the strengthening of the management of domain names and domain names analytic system's security protection is very important.</em>"</div><br />6.23 million botnet participating hosts according to their stats, where 3.62 million are Chinese IPs is a great example of how the Chinese Internet infrastructure's getting heavily abused by experienced malware and botnet masters, primarily taking advantage of what's old school social engineering, and outdated malware infection techniques, which undoubtedly will work given China's immature and inexperienced from a security perspective emerging Internet generation.<br /><div><br /></div><div><a href="http://bp1.blogger.com/_wICHhTiQmrA/SAvYUxnVfQI/AAAAAAAABlY/ZVoI70yVk68/s1600-h/chinese_defacer_nationalism.jpg"><img id="BLOGGER_PHOTO_ID_5191480846901935362" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SAvYUxnVfQI/AAAAAAAABlY/ZVoI70yVk68/s200/chinese_defacer_nationalism.jpg" border="0" /></a>Getting back to the globalization and efficiency of Turkish web site defacement groups' worldwide web application security audit, indicated in the report, according to China's CERT these are the top 10 defacers, where 7 are well known Turkish ones, and 3 are interestingly Chinese :</div><br />sinaritx - 1731 defacements<br /><div>1923turk - 1417 defacements</div>the freedom - 1156 defacements<br /><div>aLpTurkTegin - 1052 defacements</div>Mor0Ccan Islam Defenders Team - 864 defacements<br /><div>iskorpitx - 761 defacements</div>lucifercihan - 525 defacements<br /><br /><div></div>It's also interesting to see pro-democratic Chinese hackers attacking homeland networks.<br /><p><a href="http://bp2.blogger.com/_wICHhTiQmrA/SAvigBnVfRI/AAAAAAAABlg/Gt4kn7d3LN8/s1600-h/anti_cnn_dot_com.jpg"><img id="BLOGGER_PHOTO_ID_5191492035291741458" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SAvigBnVfRI/AAAAAAAABlg/Gt4kn7d3LN8/s200/anti_cnn_dot_com.jpg" border="0" /></a>Cyber warfare tensions engineering is only starting to take place, and state sponsored or perhaps even tolerated cyber espionage building capabilities in order for the state to later on acquire the already developed resources and capabilities in a cost-effective manner. However, <a href="http://bbs.gliet.edu.cn/bbs/index.php?s=40e077245937853cd6075b3d1cf365f2&amp;showtopic=157692&amp;st=0%EF%BF%BDentry2321659">considering</a> the <a href="http://www.upi.com/International_Security/Emerging_Threats/Analysis/2008/03/24/analysis_cyberattacks_on_tibet_groups/9260/print_view/">recent cyber attacks against "Free Tibet" movements</a>, as well as the <a href="http://asert.arbornetworks.com/2008/04/impending-cnncom-ddos/">DDoS attack attempts at CNN</a> due to <a href="http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/">CNN's coverage of Tibet</a>, Chinese cyber warriors continue demonstrating people's information warfare, and <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPs</a> by developing an <strong>anti-cnn.com</strong> (121.52.208.243) community, with some catchy altered images from the originals broadcasted worldwide, and with a special section to improve China's image across the world.</p>And logically, there's a <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">PSYOPs centered malware</a> released in the wild, a sample of which is basically embedding links to a non-existent domain, descriptive enough to point to <strong>TibetIsAPartOFChina.com</strong> :<br /><br /><p>%\CommonDocuments%\My Music\My Playlists\WWW.cgjSFGrz_TibetIsAPartOFChina.COM<br /></p><p>%CommonDocuments%\My Music\WWW.bimStzno_TibetIsAPartOFChina.COM<br /></p><p>%CommonDocuments%\My Videos\WWW.kUJs_TibetIsAPartOFChina.COM<br /></p><p>%CommonPrograms%\Accessories\Accessibility\WWW.RSulr_TibetIsAPartOFChina.COM<br /></p><p>%CommonPrograms%\Accessories\System Tools\WWW.aEGXBl_TibetIsAPartOFChina.COM</p>Now that's effective digital PSYOPs, isn't it? If you're visionary enough to tolerate the development of underground communities, whereas ensuring their nationalism level remain a priority for anything they do, you end up with a powerful cyber army whose every action perfectly fits with your political and military doctrine, without you even bothering to coordinate their efforts, thereby eliminating the need for a command and control structure.<br /><p>Related posts:</p><a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br /><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a><br /><a href="http://ddanchev.blogspot.com/2007/12/inside-chinese-underground-economy.html">Inside the Chinese Underground Economy</a><br /><a href="http://ddanchev.blogspot.com/2007/10/chinas-cyber-warriors-video.html">China's Cyber Warriors - Video</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GC5DiiG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GC5DiiG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Vz3Pf1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Vz3Pf1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GDo5aKg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GDo5aKg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dETNhLg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dETNhLg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7rxi57G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7rxi57G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZpzUMXG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZpzUMXG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ScAQiNg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ScAQiNg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/274516906" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 20 Apr 2008 22:34:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/internet infrastructure">internet infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese internet infrastructure">chinese internet infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/zombie network flow">zombie network flow</category>
      <category domain="http://securityratty.com/tag/zombie network">zombie network</category>
      <category domain="http://securityratty.com/tag/interestingly chinese">interestingly chinese</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese underground economy">chinese underground economy</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/274516906/chinas-cert-annual-security-report-2007.html">China's CERT Annual Security Report - 2007</source>
    </item>
    <item>
      <title><![CDATA[A Commercial Web Site Defacement Tool]]></title>
      <link>http://securityratty.com/article/0f040b157439766d42ede77d14a0a6fe</link>
      <guid>http://securityratty.com/article/0f040b157439766d42ede77d14a0a6fe</guid>
      <description><![CDATA[On the look for creative approaches to cash out of selling commodity tools and services, malicious parties within the underground economy continue applying basic market approaches to further...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R_ILjF281GI/AAAAAAAABhA/F4F6BLQoEyw/s1600-h/defacer1.jpg"><img id="BLOGGER_PHOTO_ID_5184218818552845410" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R_ILjF281GI/AAAAAAAABhA/F4F6BLQoEyw/s200/defacer1.jpg" border="0" /></a>On the look for creative approaches to cash out of selling commodity tools and services, malicious parties within the underground economy continue applying basic market approaches to further commercialize what was once a tax free area. <a href="http://ddanchev.blogspot.com/2007/08/commercial-click-fraud-tool.html">Commercial click fraud tools</a>, <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming</a> services and <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">fast-fluxing on demand</a>, <a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">botnets and DDoS attacks</a> as <a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">a service</a>, <a href="http://ddanchev.blogspot.com/2007/12/shark-malware-new-versions-coming.html">malware pitched as a remote access tool</a> with limited functionality to prompt the user to buy the full version, malware crypting as a service, and the very latest indication for this trend is the availability of commercial <a href="http://photos1.blogger.com/blogger/1933/1779/1600/dtool-1.0.png">web site defacement tools</a>.<br /><div></div><div> </div><div><br />There's a common misunderstanding regarding web site defacement tools, namely that of a defacer on purposely targeting a specific domain. That's at least the way it used to be, before defacers started embracing the efficiency model, namely deface anyone, anywhere, than parse the successful defacements logs, come across a high profile site and make sure the entire defacers community knows that they've defaced it - well at least their automated web sites defacement tools did <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">in a combination with</a> remotely included <a href="http://ddanchev.blogspot.com/2007/04/compilation-of-web-backdoors.html">web backdoors</a>.</div><br /><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/R_IT91281HI/AAAAAAAABhI/H3TQz-LnVXw/s1600-h/zoneh_reporter_defacer.jpg"><img id="BLOGGER_PHOTO_ID_5184228074207368306" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R_IT91281HI/AAAAAAAABhI/H3TQz-LnVXw/s200/zoneh_reporter_defacer.jpg" border="0" /></a>This particular commercial web site defacement tool's main differentiation factor compared to others is it's efficiency centered functionability, namely it has a <a href="http://www.zone-h.org/">built-in Zone-H defacement archive submission</a>. Moreover, within the functions changelog we see :</div><br /><div></div><div>"<em>Choose number of perm folder to check it and go another site with out load all perm it cause to deface with more speed; Working back proxy and cache servers; Get Connect back with php in all servers that safe mode is Off ( with out need any command same as system() ; Auto Detect Open Command</em>"</div><div> </div><div><br />It is such kind of commercialization approaches of commodity goods that increase the market valuation of the underground economy in general, one thing for sure though - while certain parties are messing up with entry barriers making it damn easy to launch a phishing or a malware attack, others are trying to prove themselves as aspiring entrepreneurs. In the long-term, I'd rather we have defacers deface than consolidate with phishers, spammers and malware authors for the purpose of malware embedded attacks, hosting and sending of scams, a development that is slowly starting to take place despite my wishful thinking.</div><div> </div><div><strong><br />Related posts:</strong></div><div><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3JhlpTG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3JhlpTG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jvBR1FG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jvBR1FG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GEVnLDg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GEVnLDg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2lDIY3g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2lDIY3g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P00L5lG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P00L5lG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hnH6tNG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hnH6tNG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WMKKNjg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WMKKNjg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/261895820" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Apr 2008 02:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <category domain="http://securityratty.com/tag/approaches">approaches</category>
      <category domain="http://securityratty.com/tag/defacers">defacers</category>
      <category domain="http://securityratty.com/tag/creative approaches">creative approaches</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/entire defacers community">entire defacers community</category>
      <category domain="http://securityratty.com/tag/defacers deface">defacers deface</category>
      <category domain="http://securityratty.com/tag/deface">deface</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/261895820/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</source>
    </item>
  </channel>
</rss>
