<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for s3c-watch</title>
	<atom:link href="http://s3cwatch.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://s3cwatch.wordpress.com</link>
	<description>security watch</description>
	<lastBuildDate>Fri, 27 Feb 2009 18:07:44 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on deabak.com/z.js by Tina</title>
		<link>http://s3cwatch.wordpress.com/2009/02/26/deabakcomzjs/#comment-142</link>
		<dc:creator>Tina</dc:creator>
		<pubDate>Fri, 27 Feb 2009 18:07:44 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=152#comment-142</guid>
		<description>Thanks for your response. I have a question, is there any way the hacker can find out all files in the directory? I&#039;ve put the code to prevent URL injection, but I have some hidden files which can only be accessed by registered user does not have the protection. So I wonder hacker might found those pages and attack it from there.</description>
		<content:encoded><![CDATA[<p>Thanks for your response. I have a question, is there any way the hacker can find out all files in the directory? I&#8217;ve put the code to prevent URL injection, but I have some hidden files which can only be accessed by registered user does not have the protection. So I wonder hacker might found those pages and attack it from there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on deabak.com/z.js by s3cu</title>
		<link>http://s3cwatch.wordpress.com/2009/02/26/deabakcomzjs/#comment-141</link>
		<dc:creator>s3cu</dc:creator>
		<pubDate>Fri, 27 Feb 2009 14:38:49 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=152#comment-141</guid>
		<description>sanitize and validate all data passed through URL, cookies and post data.</description>
		<content:encoded><![CDATA[<p>sanitize and validate all data passed through URL, cookies and post data.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on deabak.com/z.js by Tina</title>
		<link>http://s3cwatch.wordpress.com/2009/02/26/deabakcomzjs/#comment-140</link>
		<dc:creator>Tina</dc:creator>
		<pubDate>Thu, 26 Feb 2009 19:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=152#comment-140</guid>
		<description>Hi, I just got this SQL injection to my database today. Can you tell me how do they inject this script? I&#039;ve put code in to all variables passing through URL. But I still got this. If you can help, that&#039;ll be great! 

Thanks in advance. 

Tina</description>
		<content:encoded><![CDATA[<p>Hi, I just got this SQL injection to my database today. Can you tell me how do they inject this script? I&#8217;ve put code in to all variables passing through URL. But I still got this. If you can help, that&#8217;ll be great! </p>
<p>Thanks in advance. </p>
<p>Tina</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on IE 0-day exploit by s3cu</title>
		<link>http://s3cwatch.wordpress.com/2008/12/12/ie-0-day-exploit/#comment-129</link>
		<dc:creator>s3cu</dc:creator>
		<pubDate>Thu, 18 Dec 2008 15:49:49 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=124#comment-129</guid>
		<description>The patch to the IE vulnerability is already released - http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx

If you are still procrastinating, maybe this report about IE exploit via Word doc may change your mind - http://www.avertlabs.com/research/blog/index.php/2008/12/17/ie-7-exploit-reloaded-the-new-face-of-drive-by-attacks-using-doc-files/</description>
		<content:encoded><![CDATA[<p>The patch to the IE vulnerability is already released &#8211; <a href="http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx" rel="nofollow">http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx</a></p>
<p>If you are still procrastinating, maybe this report about IE exploit via Word doc may change your mind &#8211; <a href="http://www.avertlabs.com/research/blog/index.php/2008/12/17/ie-7-exploit-reloaded-the-new-face-of-drive-by-attacks-using-doc-files/" rel="nofollow">http://www.avertlabs.com/research/blog/index.php/2008/12/17/ie-7-exploit-reloaded-the-new-face-of-drive-by-attacks-using-doc-files/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on cbp7t.cn by Ilion</title>
		<link>http://s3cwatch.wordpress.com/2008/10/21/cbp7tcn/#comment-121</link>
		<dc:creator>Ilion</dc:creator>
		<pubDate>Tue, 21 Oct 2008 08:35:07 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=108#comment-121</guid>
		<description>Other domains:
batyu.cn
chshun.cn
dae3.cn
empty1.cn
empty52.cn
hap1.cn
kan31ni.cn
kao17.cn 
log5it.cn
meto1.cn
pcca4.cn
sfz22.cn
showwo2.cn</description>
		<content:encoded><![CDATA[<p>Other domains:<br />
batyu.cn<br />
chshun.cn<br />
dae3.cn<br />
empty1.cn<br />
empty52.cn<br />
hap1.cn<br />
kan31ni.cn<br />
kao17.cn<br />
log5it.cn<br />
meto1.cn<br />
pcca4.cn<br />
sfz22.cn<br />
showwo2.cn</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on www.ok2bstr8.com/index_13.html by s3cu</title>
		<link>http://s3cwatch.wordpress.com/2008/09/11/wwwok2bstr8comindex_13html/#comment-107</link>
		<dc:creator>s3cu</dc:creator>
		<pubDate>Fri, 12 Sep 2008 17:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=86#comment-107</guid>
		<description>first, strip html entities off the &quot;index.cgi?script&quot; content.

second, create a stub file, stub.js, with the following contents:
function eval(a) {print(a);}
location = new Object();
location.href = &quot;http://92prt.ru/cgi-bin/index.cgi?script&quot;;
document= new Object();
document = {write:print};
navigator = new Object();
navigator.appMinorVersion = &quot;;SP2;&quot;
navigator.systemLanguage = &quot;en-us&quot;

then issue command &quot;js -f stub.js index.cgi\?script&quot;</description>
		<content:encoded><![CDATA[<p>first, strip html entities off the &#8220;index.cgi?script&#8221; content.</p>
<p>second, create a stub file, stub.js, with the following contents:<br />
function eval(a) {print(a);}<br />
location = new Object();<br />
location.href = &#8220;http://92prt.ru/cgi-bin/index.cgi?script&#8221;;<br />
document= new Object();<br />
document = {write:print};<br />
navigator = new Object();<br />
navigator.appMinorVersion = &#8220;;SP2;&#8221;<br />
navigator.systemLanguage = &#8220;en-us&#8221;</p>
<p>then issue command &#8220;js -f stub.js index.cgi\?script&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on www.ok2bstr8.com/index_13.html by RS</title>
		<link>http://s3cwatch.wordpress.com/2008/09/11/wwwok2bstr8comindex_13html/#comment-106</link>
		<dc:creator>RS</dc:creator>
		<pubDate>Fri, 12 Sep 2008 15:19:37 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=86#comment-106</guid>
		<description>Hello, wondering if you&#039;ve been able to decode the new script being used by asprox.  Sample @ http://92prt.ru/cgi-bin/index.cgi?script

I have not been able to do so using spider monkey wondering if you&#039;ve done some analysis on this before. 

Thanks,</description>
		<content:encoded><![CDATA[<p>Hello, wondering if you&#8217;ve been able to decode the new script being used by asprox.  Sample @ <a href="http://92prt.ru/cgi-bin/index.cgi?script" rel="nofollow">http://92prt.ru/cgi-bin/index.cgi?script</a></p>
<p>I have not been able to do so using spider monkey wondering if you&#8217;ve done some analysis on this before. </p>
<p>Thanks,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on cdm1djeni.com/cgi-bin/index.cgi?dx by s3cu</title>
		<link>http://s3cwatch.wordpress.com/2008/09/01/cdm1djenicomcgi-binindexcgidx/#comment-103</link>
		<dc:creator>s3cu</dc:creator>
		<pubDate>Mon, 08 Sep 2008 14:08:41 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=81#comment-103</guid>
		<description>Based on robtex lookup, the following domains share the same IP address:
cdm1djeni.com
daadhevif.com
den2djeni.com
dtd1eni.com
etcyght.com
eue2eni.com
gvryehght.com
hiepdjeni.com
jjgyght.com</description>
		<content:encoded><![CDATA[<p>Based on robtex lookup, the following domains share the same IP address:<br />
cdm1djeni.com<br />
daadhevif.com<br />
den2djeni.com<br />
dtd1eni.com<br />
etcyght.com<br />
eue2eni.com<br />
gvryehght.com<br />
hiepdjeni.com<br />
jjgyght.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on jjmaobuduo.3322.org/csrss/w.js by chris</title>
		<link>http://s3cwatch.wordpress.com/2008/08/06/jjmaobuduo3322orgcsrsswjs/#comment-95</link>
		<dc:creator>chris</dc:creator>
		<pubDate>Sun, 24 Aug 2008 23:52:02 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=57#comment-95</guid>
		<description>rondll32.exe will go out and grab ack.htm.
ack.htm downloads 4 executables:
beauty.exe
sss.exe
sl.exe
fengxiang.exe</description>
		<content:encoded><![CDATA[<p>rondll32.exe will go out and grab ack.htm.<br />
ack.htm downloads 4 executables:<br />
beauty.exe<br />
sss.exe<br />
sl.exe<br />
fengxiang.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on additional domains with hhr2ehght.com by hmm</title>
		<link>http://s3cwatch.wordpress.com/2008/08/18/additional-domains-with-hhr2ehghtcom/#comment-89</link>
		<dc:creator>hmm</dc:creator>
		<pubDate>Fri, 22 Aug 2008 21:24:20 +0000</pubDate>
		<guid isPermaLink="false">http://s3cwatch.wordpress.com/?p=75#comment-89</guid>
		<description>anyygfxes.com	 A 	74.50.108.226</description>
		<content:encoded><![CDATA[<p>anyygfxes.com	 A 	74.50.108.226</p>
]]></content:encoded>
	</item>
</channel>
</rss>
