<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: nihaorr1]]></title>
    <link>http://securityratty.com/tag/nihaorr1</link>
    <description></description>
    <pubDate>Wed, 23 Apr 2008 06:13:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Malware Domains Used in the SQL Injection Attacks]]></title>
      <link>http://securityratty.com/article/006fb71c4d155504d8f571646aa4cc66</link>
      <guid>http://securityratty.com/article/006fb71c4d155504d8f571646aa4cc66</guid>
      <description><![CDATA[Whereas the value of these malicious domains lies in the historical preservation of evidence, as long as hundreds of thousands of sites continue operating with outdated and unpatched web applications,...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SDNbuXtDXEI/AAAAAAAABuo/BrBwggomVvM/s1600-h/shadowserver_SQL_injection_attacks.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SDNbuXtDXEI/AAAAAAAABuo/BrBwggomVvM/s200/shadowserver_SQL_injection_attacks.JPG" alt="" id="BLOGGER_PHOTO_ID_5202602846738144322" border="0" /></a>Whereas the value of these malicious domains lies in the historical preservation of evidence, as long as hundreds of thousands of sites continue operating with outdated and unpatched web applications, the list is prone to grow on a daily basis, thanks to copycats and the <a href="http://blogs.zdnet.com/security/?p=1122">Asprox botnet</a>. The Shadowserver Foundation's <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080514">list of malicious domains used in the SQL injection attacks</a> :<br /><br /><span style="font-weight: bold;">nihaorr1.com</span> <span style="font-weight: bold;"><br />free.hostpinoy.info</span><br /><span style="font-weight: bold;">xprmn4u.info</span><br /><span style="font-weight: bold;">nmidahena.com</span><br /><span style="font-weight: bold;">winzipices.cn</span><br /><span style="font-weight: bold;">sb.5252.ws</span> <span style="font-weight: bold;"><br />aspder.com</span><br /><span style="font-weight: bold;">11910.net</span><br /><span style="font-weight: bold;">bbs.jueduizuan.com</span> <span style="font-weight: bold;"><br />bluell.cn</span><br /><span style="font-weight: bold;">2117966.net</span><br /><span style="font-weight: bold;">s.see9.us</span><br /><span style="font-weight: bold;">xvgaoke.cn</span><br /><span style="font-weight: bold;">1.hao929.cn</span><br /><span style="font-weight: bold;">414151.com</span> <span style="font-weight: bold;"><br />cc.18dd.net</span><br /><span style="font-weight: bold;">kisswow.com.cn</span><br /><span style="font-weight: bold;">urkb.net</span><br /><span style="font-weight: bold;">c.uc8010.com</span><br /><span style="font-weight: bold;">rnmb.net</span><br /><span style="font-weight: bold;">ririwow.cn</span><br /><span style="font-weight: bold;">killwow1.cn</span><br /><span style="font-weight: bold;">qiqigm.com</span><br /><span style="font-weight: bold;">wowgm1.cn</span><br /><span style="font-weight: bold;">wowyeye.cn</span><br /><span style="font-weight: bold;">9i5t.cn</span><br /><span style="font-weight: bold;">computershello.cn</span><br /><span style="font-weight: bold;">z008.net</span><br /><span style="font-weight: bold;">b15.3322.org</span><br /><span style="font-weight: bold;">direct84.com</span><br /><span style="font-weight: bold;">caocaowow.cn</span><br /><span style="font-weight: bold;">qiuxuegm.com</span><br /><span style="font-weight: bold;">firestnamestea.cn</span><br /><span style="font-weight: bold;">qiqi111.cn</span><br /><span style="font-weight: bold;">banner82.com</span> <span style="font-weight: bold;">s<br />meisp.cn</span><br /><span style="font-weight: bold;">okey123.cn</span><br /><span style="font-weight: bold;">b.kaobt.cn</span><br /><span style="font-weight: bold;">nihao112.com</span><br /><span style="font-weight: bold;">al.99.vc</span><br /><span style="font-weight: bold;">aidushu.net</span> <span style="font-weight: bold;"><br />chliyi.com</span><br /><span style="font-weight: bold;">free.edivid.info</span><br /><span style="font-weight: bold;">52-o.cn</span> <span style="font-weight: bold;"><br />actualization.cn</span><br /><span style="font-weight: bold;">d39.6600.org</span><br /><span style="font-weight: bold;">h28.8800.org</span><br /><span style="font-weight: bold;">ucmal.com</span><br /><span style="font-weight: bold;">t.uc8010.com</span> <span style="font-weight: bold;"><br />dota11.cn</span><br /><span style="font-weight: bold;">bc0.cn</span><br /><span style="font-weight: bold;">adword71.com</span> <span style="font-weight: bold;"><br />killpp.cn</span><br /><span style="font-weight: bold;">w11.6600.org</span><br /><span style="font-weight: bold;">usuc.us</span><br /><span style="font-weight: bold;">msshamof.com</span> <span style="font-weight: bold;"><br />newasp.com.cn</span><br /><span style="font-weight: bold;">wowgm2.cn</span><br /><span style="font-weight: bold;">mm.jsjwh.com.cn</span><br /><span style="font-weight: bold;">17ge.cn</span><br /><span style="font-weight: bold;">adword72.com</span> <span style="font-weight: bold;"><br />117275.cn</span><br /><span style="font-weight: bold;">vb008.cn</span><br /><span style="font-weight: bold;">wow112.cn</span><br /><span style="font-weight: bold;">nihaoel3.com</span><br /><br />Some new additions that I'm tracking :<br /><br /><span style="font-weight: bold;">a.13175.com</span><br /><span style="font-weight: bold;">r.you30.cn</span><br /><span style="font-weight: bold;">d39.6600.org</span><br /><span style="font-weight: bold;">001yl.com</span><br /><span style="font-weight: bold;">free.edivid.info</span><br /><span style="font-weight: bold;">aaa.1l1l1l.Com/error/404.html</span><br /><span style="font-weight: bold;">cc.buhaoyishi.com/one/hao5.htm?015</span><br /><span style="font-weight: bold;">aaa.77xxmm.cn/new858.htm?075</span> <span style="font-weight: bold;"><br />llSging.com/ww/new05.htm?075</span> <span style="font-weight: bold;"><br />shIjIedIyI.net/one/hao8.htm?005</span><br /><span style="font-weight: bold;">congtouzaIlaI.net/one/hao8.htm?005</span><br /><span style="font-weight: bold;">aa.llsging.com/ww/new05.hTm?075</span><br /><br />The rough number of SQL injected sites is around 1.5 million pages, in reality the number is much bigger, and there are several ongoing campaigns injecting obfuscated characters making it a bit more time consuming to track down. Who's behind these attacks? Besides <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">the automation courtesy of botnets</a>, the short answer is everyone with a decent SQL injector, and <a href="http://ddanchev.blogspot.com/2007/05/google-hacking-for-vulnerabilities.html">today's SQL injectors have a built-in reconnaissance capabilities</a>, like this one which I assessed in a previous post.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=awmrQH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=awmrQH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7U1K5H"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7U1K5H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kjtVCh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kjtVCh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0wivlh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0wivlh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b7mJQH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b7mJQH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=v0Ar2H"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=v0Ar2H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rABKgh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rABKgh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/295841225" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 22 May 2008 04:49:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/decent sql injector">decent sql injector</category>
      <category domain="http://securityratty.com/tag/htm">htm</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/malicious domains lies">malicious domains lies</category>
      <category domain="http://securityratty.com/tag/malicious domains">malicious domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/295841225/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</source>
    </item>
    <item>
      <title><![CDATA[Redmondmag...I told you so!]]></title>
      <link>http://securityratty.com/article/86c5246bb43764de7badda595a9e2b02</link>
      <guid>http://securityratty.com/article/86c5246bb43764de7badda595a9e2b02</guid>
      <description><![CDATA[There is no more egregious an act of negligence committed by online vendors and businesses than ignoring notifications of vulnerabilities found in their applications
So when Dancho Danchev pointed out...]]></description>
      <content:encoded><![CDATA[There is no more egregious an act of negligence committed by online vendors and businesses than ignoring notifications of vulnerabilities found in their applications. <br />So when <a href="http://ddanchev.blogspot.com/">Dancho Danchev</a> <a href="http://blogs.zdnet.com/security/?p=1118">pointed out</a> that <a href="http://redmondmag.com/">Redmond Magazine</a> had been SQL injected by Chinese Hacktivists, I was both appalled, yet not surprised.<br />On <span style="font-weight:bold;">January 29th, 2008</span> I informed <a href="http://www.1105media.com/">1105 Media</a>, the parent company of the <a href="http://redmondmediagroup.com/">Redmond Media Group</a>, of multiple XSS vulnerabilities in various properties they maintain, including EntMag.com and AdtMag.com, as well as Redmondmag.com.<br /><br />From my email:<br /><span style="font-style:italic;">"I’d like to advise you of XSS vulnerabilities in the search code used by all Redmond Media Group websites.<br />This is most easily validated by pasting a simple script alert generator in the search form. <br />These vulnerabilities were disclosed by XSSed.com in February and July of 2007.<br /><a href="http://www.xssed.com/mirror/20073/">http://www.xssed.com/mirror/20073/</a><br /><a href="http://www.xssed.com/mirror/13305/">http://www.xssed.com/mirror/13305/</a><br />These vulnerability be exploited by malicious people to conduct XSS attacks and it could further lead to reputation and PR issues for the Redmond Media Group."</span><br /><br />Not only did they flatly ignore me, and they guys from <a href="http://www.xssed.com/">XSSed.com</a> who'd notified then in <span style="font-weight:bold;">FEBRUARY and JULY 2007!</span>, but all these vulnerabilities still exist, including Redmondmag.com. You could definitely say that these issues have led to "reputation and PR issues for the Redmond Media Group." <br />Doh! I told you so!<br />It goes without saying that if you are vulnerable to XSS, you have a significantly higher likelihood of being vulnerable to SQLi.<br />Redmondmag.com was also victimized by the 2nd wave of mass SQL injection attacks that dropped in <span style="font-style:italic;">nihaorr1.com/1.js</span>. <br /><br />Regarding current vulnerabilities, observe the following:<br /><a href="http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=http://search.redmondmag.com/search.asp&cmd=search&SearchForm=%%SearchForm%%&index=C:\dtSearch\rmg\red_all&sort=Date&srcrequest=%22%3E%3CSCRIPT%3Ealert('XSS_Alert')%3C/SCRIPT%3E&submit1=Search"><span style="font-style:italic;">http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=http://search.redmondmag.com/search.asp&cmd=search&SearchForm=%%SearchForm%%&index=C:\dtSearch\rmg\red_all&sort=Date&srcrequest=%22%3E%3CSCRIPT%3Ealert('XSS_Alert')%3C/SCRIPT%3E&submit1=Search">http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=<br />http://search.redmondmag.com/search.asp&cmd=search&SearchForm=%%SearchForm%%&<br />index=C:\dtSearch\rmg\red_all&sort=Date&<br />srcrequest=(Insert JavaScript here)&submit1=Search</span></a><br /><br />Props, as always, to Whiteacid's XSS Assistant and POST forwarder.<br />But behold, what do we see, but <span style="font-style:italic;">index=C:\dtSearch\rmg\red_all</span>.<br />Well, now we know you use <a href="http://www.dtsearch.com/">dtSearch</a> on the C: of your Windows server (no surprise there ;-)).<br /><br />Common people, fix your sites!<br />You have been found guilty of the following charges:<br />1) Vulnerable to SQLi<br />2) Vulnerable to XSS<br />3) Internal file disclosure<br />4) Flagrant negligence with regard to secure coding best practices<br />50 Flagrant disregard fo information submitted to you by the information security community.<br /><span style="font-weight:bold;">1105 Media and the Redmond Media Group, you have failed your readers, your visitors, your customers, and yourselves, and you should be ashamed.</span><br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/05/redmondmagi-told-you-so.html&title=Redmondmag%20...%20I%20told%20you%20so! " title="Redmondmag...I told you so! del.icio.us">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/05/redmondmagi-told-you-so.html" title="Redmondmag...I told you so! ">digg</a>]]></content:encoded>
      <pubDate>Sun, 18 May 2008 08:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/current vulnerabilities">current vulnerabilities</category>
      <category domain="http://securityratty.com/tag/multiple xss vulnerabilities">multiple xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss target">xss target</category>
      <category domain="http://securityratty.com/tag/xss assistant">xss assistant</category>
      <category domain="http://securityratty.com/tag/redmond media">redmond media</category>
      <category domain="http://securityratty.com/tag/xss alert">xss alert</category>
      <source url="http://holisticinfosec.blogspot.com/2008/05/redmondmagi-told-you-so.html">Redmondmag...I told you so!</source>
    </item>
    <item>
      <title><![CDATA[The United Nations Serving Malware]]></title>
      <link>http://securityratty.com/article/d1d822ed6374f6c7f294fed616ac7d76</link>
      <guid>http://securityratty.com/article/d1d822ed6374f6c7f294fed616ac7d76</guid>
      <description><![CDATA[Yet another massive SQL injection attack is making its rounds online, and this time without the SEO poisoning as an attack tactic , has managed to successfully infect the United Nations events page,...]]></description>
      <content:encoded><![CDATA[<div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA5b7NDpi2I/AAAAAAAABm4/XilLYHXJoSs/s1600-h/united_nations_malicious_injection.JPG"><img id="BLOGGER_PHOTO_ID_5192188493080136546" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SA5b7NDpi2I/AAAAAAAABm4/XilLYHXJoSs/s200/united_nations_malicious_injection.JPG" border="0" /></a>Yet another massive SQL injection attack is making its rounds online, and this time without the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">SEO poisoning as an attack tactic</a>, has managed to successfully infect the United Nations events page, which is now also marked as malware infected page, and with a reason since both the malicious URl and the injection are still active. <a href="http://securitylabs.websense.com/content/Alerts/3070.aspx">According to WebSense</a> :<br /><br />"<span style="font-style: italic;">This mass injection is remarkably similar to the attack we saw earlier this month. When a </span><span style="font-style: italic;">user browses to a compromised site, the injected JavaScript loads a file named 1.js which is ho</span><span style="font-style: italic;">sted on http://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing. There are further similarities too between the two mass attacks. Resident on the latest malici</span><span style="font-style: italic;">ous domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here. Mentioned in that diary entry is http://www.2117[removed].net. Our blog on that attack can be found here. It appears that same tool was used to orchestrate this attack too. </span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA5rltDpi6I/AAAAAAAABnQ/73aOsN1uYy0/s1600-h/another_massive_injection.JPG"><img id="BLOGGER_PHOTO_ID_5192205715898993570" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SA5rltDpi6I/AAAAAAAABnQ/73aOsN1uYy0/s200/another_massive_injection.JPG" border="0" /></a>Let's assess the malicious injection. <span style="font-weight: bold;">nihaorr1.com/ 1.js</span> (219.153.46.28) is attempting to load <span style="font-weight: bold;">nihaorr1.com/ 1.htm</span>, where several other internal exploit serving URLs and javascript obfuscations load through IFRAMES, such as :<br /><br /><span style="font-weight: bold;">nihaorr1.com/ Real.gif</span> <span style="font-weight: bold;"><br />niha</span><span style="font-weight: bold;">orr1.com/ Yahoo.php</span> <span style="font-weight: bold;"><br />nihaorr1.com/ cuteqq.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07055.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07033.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07018.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07004.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ajax.htm</span> <span style="font-weight: bold;"><br />nihaorr1</span><span style="font-weight: bold;">.com/ Ms06014.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Bfyy.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Lz.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Pps.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ XunLei.htm</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA5rwtDpi7I/AAAAAAAABnY/BGvEieF0v0s/s1600-h/another_massive_injection_2.JPG"><img id="BLOGGER_PHOTO_ID_5192205904877554610" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SA5rwtDpi7I/AAAAAAAABnY/BGvEieF0v0s/s200/another_massive_injection_2.JPG" border="0" /></a>and finally serve the malware, by also taking us out of the point and loading another malicious IFRAME farm at <span style="font-weight: bold;">gg.haoliuliang.net/one/ hao8.htm?036</span> (222.73.44.162) :<br /><br />Scanners Result: 18/<span id="porcentaje"><span style="color:red;"></span>32 (56.25%) :<br />W32/PWStealer1!Generic; PWS:Win32/Lineage.WI.dr<br /></span>File size: 24667 bytes<br />MD5...: 4b913be127d648373e511974351ff04e<br />SHA1..: 0ab703c93e3ad7c03d1aae5ea394d7db3b89bfd2<br /><span id="porcentaje"><br />Another internal IFRAME serving exploits is also loading at </span><span style="font-weight: bold;">haoliuliang.net</span>, <span style="font-weight: bold;">gg.haoliuliang.net/wmwm/ new.htm</span> where a new piece of malware is served :<br /><br />Scanners Result: 26/32 (81.25%)<br />Trojan-PSW.Win32.OnLineGames.ppu; Trojan.PSW.Win32.OnlineGames.GEN<br />File size: 7205 bytes<br />MD5...: af05c777700b338f428463e56f316a05<br />SHA1..: bd68f621ec6c9796afa8b766c6cf4167afbd4703<br /><br />As it appears, everyone's a victim of web application vulnerabilities discovered automatically, and either filtered based on high-page rank, or trying to take advantage of the long-tail of SQL injected sites to compensate for the lack of vulnerable high profile sites.<br /><br /><strong>Related posts:</strong><br /><a href="http://ddanchev.blogspot.com/2008/04/unicef-too-iframe-injected-and-seo.html">UNICEF Too IFRAME Injected and SEO Poisoned</a><br /><a href="http://ddanchev.blogspot.com/2008/03/embedded-malware-at-bloggies-awards.html">Embedded Malware at Bloggies Awards Site</a><br /><a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">Embedding Malicious IFRAMEs Through Stolen FTP Accounts</a><br /><a href="http://ddanchev.blogspot.com/2008/02/yet-another-massive-embedded-malware.html">Yet Another Massive Embedded Malware Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/12/mdac-activex-code-execution-exploit.html">MDAC ActiveX Code Execution Exploit Still in the Wild</a><br /><a href="http://ddanchev.blogspot.com/2008/01/malware-serving-exploits-embedded-sites.html">Malware Serving Exploits Embedded Sites as Usual</a><br /><a href="http://ddanchev.blogspot.com/2008/01/massive-realplayer-exploit-embedded.html">Massive RealPlayer Exploit Embedded Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in London Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/08/bank-of-india-serving-malware.html">Bank of India Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/09/us-consulate-st-petersburg-serving.html">U.S Consulate St. Petersburg Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/01/dutch-embassy-in-moscow-serving-malware.html">The Dutch Embassy in Moscow Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/uks-feta-serving-malware.html">U.K's FETA Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/anti-malware-vendors-site-serving.html">Anti-Malware Vendor's Site Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/new-media-malware-gang-part-three.html">The New Media Malware Gang - Part Three</a><br /><a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html">The New Media Malware Gang - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">The New Media Malware Gang</a><br /><a href="http://ddanchev.blogspot.com/2007/10/portfolio-of-malware-embedded-magazines.html">A Portfolio of Malware Embedded Magazines</a><br /><a href="http://ddanchev.blogspot.com/2007/11/another-massive-embedded-malware-attack.html">Another Massive Embedded Malware Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere.html">I See Alive IFRAMEs Everywhere</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere-part-two.html">I See Alive IFRAMEs Everywhere - Part Two</a></div><br /><div> </div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h2szloG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h2szloG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Jh8d9YG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Jh8d9YG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TZyIhPg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TZyIhPg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DQqL6Mg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DQqL6Mg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tPC4aNG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tPC4aNG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nWuC8GG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nWuC8GG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3djJeCg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3djJeCg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/276225903" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 06:13:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <category domain="http://securityratty.com/tag/anti-malware vendor">anti-malware vendor</category>
      <category domain="http://securityratty.com/tag/media malware gang">media malware gang</category>
      <category domain="http://securityratty.com/tag/htm">htm</category>
      <category domain="http://securityratty.com/tag/nihaorr1">nihaorr1</category>
      <category domain="http://securityratty.com/tag/load nihaorr1">load nihaorr1</category>
      <category domain="http://securityratty.com/tag/attack tactic">attack tactic</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/276225903/united-nations-serving-malware.html">The United Nations Serving Malware</source>
    </item>
  </channel>
</rss>
