<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gilbert Verdian - I Secure Enterprises &#187; hacking</title>
	<atom:link href="http://www.gilbertverdian.com/security/category/security/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gilbertverdian.com/security</link>
	<description>talking about security, from the front line</description>
	<lastBuildDate>Sun, 08 Nov 2009 10:52:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Get Hacked, Get Sued, Go Out of Business</title>
		<link>http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/</link>
		<comments>http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/#comments</comments>
		<pubDate>Tue, 04 Mar 2008 17:33:43 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/</guid>
		<description><![CDATA[I just received the following email from ecademy.com.  It is an unfortunate tale of the site being hacked, the customer database stolen, the company being sued and as a result of the verdict and legal expenses they have decided to shut down.  Dear members, clients and guests of our portal,Over the last few years our portal [...]]]></description>
			<content:encoded><![CDATA[<p><span class="Apple-style-span" style="font-family: Helvetica; font-size: 12px; line-height: normal">I just received the following email from ecademy.com.  It is an unfortunate tale of the site being hacked, the customer database stolen, the company being sued and as a result of the verdict and legal expenses they have decided to shut down. </span><br />
<blockquote> Dear members, clients and guests of our portal,<br />Over the last few years our portal has helped you to organize your business, find new partners and increase sales.However, all good things end. Many of you know that we have experienced legal problems over the last year. Our competitors from other social networks are trying to take over our client base.<br />Our website has been hacked and our database was stolen. After that we were taken to court because of identity theft.Unfortunately, legal expenses and unfavorable court verdict with following closure of our bank accounts will lead to closure of our website. All paying members will receive refund starting from March 14th.<br />Please check attached file for legal information in regards to your account.</p>
<p>Best regards,</p>
<p>The Ecademy TeamEcademy &#8211; The Social Network for Business People<br />Company Registration:3651083 VAT:718 0377 36 </p></blockquote>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internal Facebook Phishing or Worm?</title>
		<link>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/</link>
		<comments>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 00:03:09 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[virus, worms & malware]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/</guid>
		<description><![CDATA[Seems one of my facebook contacts&#8217; account was compromised either by phishing or key logging&#8230; &#8220;he&#8221; had posted the following URL onto my wall h11p://www.facebook.com.profile.php.id.371233.cn He also had the following from another user on his wall &#8220;lol i cant believe these pics got posted&#8230;.its going to be BADDDD when her boyfriend sees these- h11p://www.facebook.com.profile.php.id.371233.cn&#8221; Of [...]]]></description>
			<content:encoded><![CDATA[<p>Seems one of my facebook contacts&#8217; account was compromised either by phishing or key logging&#8230; &#8220;he&#8221; had posted the following URL onto my wall</p>
<p>h11p://www.facebook.com.profile.php.id.371233.cn</p>
<p>He also had the  following from another user on his wall</p>
<p>&#8220;lol i cant believe these pics got posted&#8230;.its going to be BADDDD when her boyfriend sees these- <a href="h11p://www.facebook.com.profile.php.id.371233.cn/" target="_blank" rel="nofollow"><span>h11p://www.facebook.com.pr</span><wbr></wbr><span class="word_break"></span>ofile.php.id.371233.cn</a>&#8221;</p>
<p>Of course, the guilty domain is 371233.cn&#8230; a whois doesn&#8217;t reveal much..</p>
<p>whois 371233.cn<br />
Domain Name: 371233.cn<br />
ROID: 20071101s10001s02380333-cn<br />
Domain Status: ok<br />
Registrant Organization: 小问<br />
Registrant Name: 笑纹<br />
Administrative Email: 24@244.com<br />
Sponsoring Registrar: 北京新网互联科技有限公司<br />
Name Server:ns1.4980603.com<br />
Name Server:ns2.4980603.com<br />
Name Server:ns3.4980603.com<br />
Name Server:ns4.4980603.com<br />
Registration Date: 2007-11-01 23:30<br />
Expiration Date: 2008-11-01 23:30</p>
<p>Then the whois of the hosted server 4980603.com is</p>
<p>Domain Name&#8230;&#8230;&#8230;. 4980603.com<br />
Creation Date&#8230;&#8230;.. 2007-10-19 18:26:55<br />
Registration Date&#8230;. 2007-10-19 18:26:55<br />
Expiry Date&#8230;&#8230;&#8230;. 2008-10-19 18:26:55<br />
Organisation Name&#8230;. xiaowen<br />
Organisation Address. No.323 chang&#8217;an road<br />
Organisation Address.<br />
Organisation Address. Beijing<br />
Organisation Address. 100001<br />
Organisation Address. BJ<br />
Organisation Address. CN</p>
<p>Admin Name&#8230;&#8230;&#8230;.. top wen<br />
Admin Address&#8230;&#8230;.. No.323 chang&#8217;an road<br />
Admin Address&#8230;&#8230;..<br />
Admin Address&#8230;&#8230;.. Beijing<br />
Admin Address&#8230;&#8230;.. 100001<br />
Admin Address&#8230;&#8230;.. BJ<br />
Admin Address&#8230;&#8230;.. CN<br />
Admin Email&#8230;&#8230;&#8230;. 24@244.com<br />
Admin Phone&#8230;&#8230;&#8230;. +86.1034546677<br />
Admin Fax&#8230;&#8230;&#8230;&#8230; +86.1067688466</p>
<p>Tech Name&#8230;&#8230;&#8230;&#8230; top wen<br />
Tech Address&#8230;&#8230;&#8230; No.323 chang&#8217;an road<br />
Tech Address&#8230;&#8230;&#8230;<br />
Tech Address&#8230;&#8230;&#8230; Beijing<br />
Tech Address&#8230;&#8230;&#8230; 100001<br />
Tech Address&#8230;&#8230;&#8230; BJ<br />
Tech Address&#8230;&#8230;&#8230; CN<br />
Tech Email&#8230;&#8230;&#8230;.. 24@244.com<br />
Tech Phone&#8230;&#8230;&#8230;.. +86.1034546677<br />
Tech Fax&#8230;&#8230;&#8230;&#8230;. +86.1067688466</p>
<p>Bill Name&#8230;&#8230;&#8230;&#8230; top wen<br />
Bill Address&#8230;&#8230;&#8230; No.323 chang&#8217;an road<br />
Bill Address&#8230;&#8230;&#8230;<br />
Bill Address&#8230;&#8230;&#8230; Beijing<br />
Bill Address&#8230;&#8230;&#8230; 100001<br />
Bill Address&#8230;&#8230;&#8230; BJ<br />
Bill Address&#8230;&#8230;&#8230; CN<br />
Bill Email&#8230;&#8230;&#8230;.. 24@244.com<br />
Bill Phone&#8230;&#8230;&#8230;.. +86.1034546677<br />
Bill Fax&#8230;&#8230;&#8230;&#8230;. +86.1067688466<br />
Name Server&#8230;&#8230;&#8230;. ns4.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns3.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns2.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns1.4980603.com</p>
<p>The site looks quite convincing to the user, they haven&#8217;t updated the year to 2008 yet&#8230;</p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/facebook_phish.png" title="facebook_phish.png"><img src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/facebook_phish.png" alt="facebook_phish.png" height="155" width="435" /></a></p>
<p>The source of the site is basically the following form&#8230;</p>
<p>&lt;form method=&#8221;post&#8221; action=&#8221;login.php&#8221;&gt;&lt;div id=&#8221;loginform&#8221;&gt;&lt;div class=&#8221;form_row clearfix&#8221;&gt;&lt;label for=&#8221;email&#8221; id=&#8221;label_email&#8221;&gt;Email:&lt;/label&gt;&lt;input type=&#8221;text&#8221; class=&#8221;inputtext&#8221; id=&#8221;email&#8221; name=&#8221;email&#8221; /&gt;&lt;/div&gt;&lt;div class=&#8221;form_row clearfix&#8221;&gt;&lt;label for=&#8221;pass&#8221; id=&#8221;label_pass&#8221;&gt;Password:&lt;/label&gt;&lt;input type=&#8221;password&#8221; class=&#8221;inputpassword&#8221; id=&#8221;pass&#8221; name=&#8221;pass&#8221; value=&#8221;" /&gt;&lt;/div&gt;&lt;label class=&#8221;persistent&#8221;&gt;&lt;input type=&#8221;checkbox&#8221; class=&#8221;inputcheckbox&#8221; onclick=&#8221;document.getElementById(&#8220;persistent_notification&#8221;).style.display=this.checked?&#8221;block&#8221;:&#8221;none&#8221;;&#8221; id=&#8221;persistent&#8221; name=&#8221;persistent&#8221; value=&#8221;1&#8243; /&gt;&lt;span&gt;Remember me&lt;/span&gt;&lt;/label&gt;&lt;div style=&#8221;display: none&#8221; id=&#8221;persistent_notification&#8221;&gt;&lt;div class=&#8221;status&#8221;&gt;&lt;h2&gt;&lt;span id=status_title&gt;By selecting &#8220;remember me&#8221; you will stay logged into this computer until you click logout. If this is a public computer please do not use this feature.&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;<br />
&lt;/div&gt;&lt;div id=&#8221;buttons&#8221; class=&#8221;form_row clearfix&#8221;&gt;&lt;label&gt;&lt;/label&gt;&lt;input type=&#8221;submit&#8221; value=&#8221;Login&#8221; name=&#8221;login&#8221; id=&#8221;login&#8221; onclick=&#8221;this.disabled=true; this.form.submit();&#8221; class=&#8221;inputsubmit&#8221; /&gt; or &lt;strong&gt;&lt;a id=reg_btn_link  href=&#8221;https://www.facebook.com/r.php?&#8221; &gt;Sign up for Facebook&lt;/a&gt; &lt;/strong&gt;&lt;/div&gt;&lt;p class=&#8221;reset_password form_row&#8221;&gt;&lt;label&gt;&lt;/label&gt;&lt;a href=&#8221;http://www.facebook.com/reset.php&#8221;&gt;Forgot your password?&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;/form&gt;</p>
<p>There&#8217;s also a reference to an internal IP&#8230;</p>
<p>&lt;span title=&#8221;10.1.227.120&#8243;&gt;20&lt;/span&gt;&lt;span title=&#8221;19192216&#8243;&gt;07&lt;/span&gt;</p>
<p>Anyone else seen this?</p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Root DNS Servers DDoS</title>
		<link>http://www.gilbertverdian.com/security/2007/02/root-dns-servers-ddos/</link>
		<comments>http://www.gilbertverdian.com/security/2007/02/root-dns-servers-ddos/#comments</comments>
		<pubDate>Wed, 07 Feb 2007 19:52:22 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2007/02/root-dns-servers-ddos/</guid>
		<description><![CDATA[Noticed something funny happening yesterday with DNS, it was only for a short amount of time, but it occurred on 3 different systems. For example when I went to google.com, it was redirected to a sedo.com search page. My first thought was that google had not renewed their domain in time which happened with their [...]]]></description>
			<content:encoded><![CDATA[<p> Noticed something funny happening yesterday with DNS, it was only for a short amount of time, but it occurred on 3 different systems. For example when I went to google.com, it<br />
   was redirected to a sedo.com search page. My first thought was that google had not renewed their domain in time which happened with their google.de domain. Thinking nothing of<br />
   it, after a couple of minutes the symptoms were gone, until today.                                                                                                                   </p>
<p>   My security feeds today had numerous stories about the root dns servers being hacked. There have been a couple of cases going back to the 80&#8242;s written about in<br />
   Clifford Stoll&#8217;s book, the Cuckoo&#8217;s Egg where hackers targeted the root servers. These servers are seen as trophy win, you get into these, you get into the backbone of the<br />
   internet, hence its alluring appeal. Naturally these servers need to be as secure as possible. Recently, Sun were commissioned to install Solaris 10 for the ISC F-ROOT server<br />
   f.root-servers.net (192.5.5.241).                                                                                                                                                    </p>
<p>   The attack against the servers was a DDoS (Distributed Denial of Service), this consists of using thousands of zombie machines sending hundred of thousands of requests to try to<br />
   overwhelm them and deny it from delivering the service it is designed to deliver. In this instance, the servers stood up against the attack.                                         </p>
<p>   Just another day in the internet. </p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2007/02/root-dns-servers-ddos/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2007/02/root-dns-servers-ddos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
