<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gilbert Verdian - I Secure Enterprises &#187; virus, worms &amp; malware</title>
	<atom:link href="http://www.gilbertverdian.com/security/category/security/virus-worms-malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gilbertverdian.com/security</link>
	<description>talking about security, from the front line</description>
	<lastBuildDate>Sun, 08 Nov 2009 10:52:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Internal Facebook Phishing or Worm?</title>
		<link>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/</link>
		<comments>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 00:03:09 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[virus, worms & malware]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/</guid>
		<description><![CDATA[Seems one of my facebook contacts&#8217; account was compromised either by phishing or key logging&#8230; &#8220;he&#8221; had posted the following URL onto my wall h11p://www.facebook.com.profile.php.id.371233.cn He also had the following from another user on his wall &#8220;lol i cant believe these pics got posted&#8230;.its going to be BADDDD when her boyfriend sees these- h11p://www.facebook.com.profile.php.id.371233.cn&#8221; Of [...]]]></description>
			<content:encoded><![CDATA[<p>Seems one of my facebook contacts&#8217; account was compromised either by phishing or key logging&#8230; &#8220;he&#8221; had posted the following URL onto my wall</p>
<p>h11p://www.facebook.com.profile.php.id.371233.cn</p>
<p>He also had the  following from another user on his wall</p>
<p>&#8220;lol i cant believe these pics got posted&#8230;.its going to be BADDDD when her boyfriend sees these- <a href="h11p://www.facebook.com.profile.php.id.371233.cn/" target="_blank" rel="nofollow"><span>h11p://www.facebook.com.pr</span><wbr></wbr><span class="word_break"></span>ofile.php.id.371233.cn</a>&#8221;</p>
<p>Of course, the guilty domain is 371233.cn&#8230; a whois doesn&#8217;t reveal much..</p>
<p>whois 371233.cn<br />
Domain Name: 371233.cn<br />
ROID: 20071101s10001s02380333-cn<br />
Domain Status: ok<br />
Registrant Organization: 小问<br />
Registrant Name: 笑纹<br />
Administrative Email: 24@244.com<br />
Sponsoring Registrar: 北京新网互联科技有限公司<br />
Name Server:ns1.4980603.com<br />
Name Server:ns2.4980603.com<br />
Name Server:ns3.4980603.com<br />
Name Server:ns4.4980603.com<br />
Registration Date: 2007-11-01 23:30<br />
Expiration Date: 2008-11-01 23:30</p>
<p>Then the whois of the hosted server 4980603.com is</p>
<p>Domain Name&#8230;&#8230;&#8230;. 4980603.com<br />
Creation Date&#8230;&#8230;.. 2007-10-19 18:26:55<br />
Registration Date&#8230;. 2007-10-19 18:26:55<br />
Expiry Date&#8230;&#8230;&#8230;. 2008-10-19 18:26:55<br />
Organisation Name&#8230;. xiaowen<br />
Organisation Address. No.323 chang&#8217;an road<br />
Organisation Address.<br />
Organisation Address. Beijing<br />
Organisation Address. 100001<br />
Organisation Address. BJ<br />
Organisation Address. CN</p>
<p>Admin Name&#8230;&#8230;&#8230;.. top wen<br />
Admin Address&#8230;&#8230;.. No.323 chang&#8217;an road<br />
Admin Address&#8230;&#8230;..<br />
Admin Address&#8230;&#8230;.. Beijing<br />
Admin Address&#8230;&#8230;.. 100001<br />
Admin Address&#8230;&#8230;.. BJ<br />
Admin Address&#8230;&#8230;.. CN<br />
Admin Email&#8230;&#8230;&#8230;. 24@244.com<br />
Admin Phone&#8230;&#8230;&#8230;. +86.1034546677<br />
Admin Fax&#8230;&#8230;&#8230;&#8230; +86.1067688466</p>
<p>Tech Name&#8230;&#8230;&#8230;&#8230; top wen<br />
Tech Address&#8230;&#8230;&#8230; No.323 chang&#8217;an road<br />
Tech Address&#8230;&#8230;&#8230;<br />
Tech Address&#8230;&#8230;&#8230; Beijing<br />
Tech Address&#8230;&#8230;&#8230; 100001<br />
Tech Address&#8230;&#8230;&#8230; BJ<br />
Tech Address&#8230;&#8230;&#8230; CN<br />
Tech Email&#8230;&#8230;&#8230;.. 24@244.com<br />
Tech Phone&#8230;&#8230;&#8230;.. +86.1034546677<br />
Tech Fax&#8230;&#8230;&#8230;&#8230;. +86.1067688466</p>
<p>Bill Name&#8230;&#8230;&#8230;&#8230; top wen<br />
Bill Address&#8230;&#8230;&#8230; No.323 chang&#8217;an road<br />
Bill Address&#8230;&#8230;&#8230;<br />
Bill Address&#8230;&#8230;&#8230; Beijing<br />
Bill Address&#8230;&#8230;&#8230; 100001<br />
Bill Address&#8230;&#8230;&#8230; BJ<br />
Bill Address&#8230;&#8230;&#8230; CN<br />
Bill Email&#8230;&#8230;&#8230;.. 24@244.com<br />
Bill Phone&#8230;&#8230;&#8230;.. +86.1034546677<br />
Bill Fax&#8230;&#8230;&#8230;&#8230;. +86.1067688466<br />
Name Server&#8230;&#8230;&#8230;. ns4.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns3.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns2.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns1.4980603.com</p>
<p>The site looks quite convincing to the user, they haven&#8217;t updated the year to 2008 yet&#8230;</p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/facebook_phish.png" title="facebook_phish.png"><img src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/facebook_phish.png" alt="facebook_phish.png" height="155" width="435" /></a></p>
<p>The source of the site is basically the following form&#8230;</p>
<p>&lt;form method=&#8221;post&#8221; action=&#8221;login.php&#8221;&gt;&lt;div id=&#8221;loginform&#8221;&gt;&lt;div class=&#8221;form_row clearfix&#8221;&gt;&lt;label for=&#8221;email&#8221; id=&#8221;label_email&#8221;&gt;Email:&lt;/label&gt;&lt;input type=&#8221;text&#8221; class=&#8221;inputtext&#8221; id=&#8221;email&#8221; name=&#8221;email&#8221; /&gt;&lt;/div&gt;&lt;div class=&#8221;form_row clearfix&#8221;&gt;&lt;label for=&#8221;pass&#8221; id=&#8221;label_pass&#8221;&gt;Password:&lt;/label&gt;&lt;input type=&#8221;password&#8221; class=&#8221;inputpassword&#8221; id=&#8221;pass&#8221; name=&#8221;pass&#8221; value=&#8221;" /&gt;&lt;/div&gt;&lt;label class=&#8221;persistent&#8221;&gt;&lt;input type=&#8221;checkbox&#8221; class=&#8221;inputcheckbox&#8221; onclick=&#8221;document.getElementById(&#8220;persistent_notification&#8221;).style.display=this.checked?&#8221;block&#8221;:&#8221;none&#8221;;&#8221; id=&#8221;persistent&#8221; name=&#8221;persistent&#8221; value=&#8221;1&#8243; /&gt;&lt;span&gt;Remember me&lt;/span&gt;&lt;/label&gt;&lt;div style=&#8221;display: none&#8221; id=&#8221;persistent_notification&#8221;&gt;&lt;div class=&#8221;status&#8221;&gt;&lt;h2&gt;&lt;span id=status_title&gt;By selecting &#8220;remember me&#8221; you will stay logged into this computer until you click logout. If this is a public computer please do not use this feature.&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;<br />
&lt;/div&gt;&lt;div id=&#8221;buttons&#8221; class=&#8221;form_row clearfix&#8221;&gt;&lt;label&gt;&lt;/label&gt;&lt;input type=&#8221;submit&#8221; value=&#8221;Login&#8221; name=&#8221;login&#8221; id=&#8221;login&#8221; onclick=&#8221;this.disabled=true; this.form.submit();&#8221; class=&#8221;inputsubmit&#8221; /&gt; or &lt;strong&gt;&lt;a id=reg_btn_link  href=&#8221;https://www.facebook.com/r.php?&#8221; &gt;Sign up for Facebook&lt;/a&gt; &lt;/strong&gt;&lt;/div&gt;&lt;p class=&#8221;reset_password form_row&#8221;&gt;&lt;label&gt;&lt;/label&gt;&lt;a href=&#8221;http://www.facebook.com/reset.php&#8221;&gt;Forgot your password?&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;/form&gt;</p>
<p>There&#8217;s also a reference to an internal IP&#8230;</p>
<p>&lt;span title=&#8221;10.1.227.120&#8243;&gt;20&lt;/span&gt;&lt;span title=&#8221;19192216&#8243;&gt;07&lt;/span&gt;</p>
<p>Anyone else seen this?</p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
