<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The &quot;onload if this&quot; website infection</title>
	<atom:link href="http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/feed/" rel="self" type="application/rss+xml" />
	<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/</link>
	<description>Website Security</description>
	<lastBuildDate>Mon, 23 Jan 2012 22:26:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: visitor</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-53</link>
		<dc:creator>visitor</dc:creator>
		<pubDate>Fri, 19 Mar 2010 06:41:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-53</guid>
		<description>Thanks for sharing this usefull information.
One site  I detected also as a virus:
xg1.es/images/gifimg. php (DON&quot;t follow this link!! but I post it here so that others can find it - so, be aware !!!!)</description>
		<content:encoded><![CDATA[<p>Thanks for sharing this usefull information.<br />
One site  I detected also as a virus:<br />
xg1.es/images/gifimg. php (DON&#8221;t follow this link!! but I post it here so that others can find it &#8211; so, be aware !!!!)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-52</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Mon, 01 Mar 2010 20:15:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-52</guid>
		<description>Tachyon,

What do you mean by &quot;a secure editor&quot;?

The infected won&#039;t infect your PC unless you open them up in a browser. If you open them up with Dreamweaver or whatever your editor is, you won&#039;t get infected.</description>
		<content:encoded><![CDATA[<p>Tachyon,</p>
<p>What do you mean by &#8220;a secure editor&#8221;?</p>
<p>The infected won&#8217;t infect your PC unless you open them up in a browser. If you open them up with Dreamweaver or whatever your editor is, you won&#8217;t get infected.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tachyon</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-51</link>
		<dc:creator>Tachyon</dc:creator>
		<pubDate>Thu, 11 Feb 2010 04:22:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-51</guid>
		<description>Nice read. Thanks for tips.
Domains I recently found where:
- fujikvl.ge/
- adsolutionindia.com/
- cumportal.com/

Does anyone know a secure editor who scan files on FTP-site (with regular expressions) so I don&#039;t have to download any possible infected files???

Thanks,
Tachyon</description>
		<content:encoded><![CDATA[<p>Nice read. Thanks for tips.<br />
Domains I recently found where:<br />
- fujikvl.ge/<br />
- adsolutionindia.com/<br />
- cumportal.com/</p>
<p>Does anyone know a secure editor who scan files on FTP-site (with regular expressions) so I don&#8217;t have to download any possible infected files???</p>
<p>Thanks,<br />
Tachyon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: peyman</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-50</link>
		<dc:creator>peyman</dc:creator>
		<pubDate>Mon, 07 Dec 2009 09:55:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-50</guid>
		<description>I found


Line 72:
Line 73:
Line 74:


our website designed by asp.net 2  (aspx and vbx)

could i couldn&#039;t find any eval(base64_decode
i need your help to solve this problem</description>
		<content:encoded><![CDATA[<p>I found</p>
<p>Line 72:<br />
Line 73:<br />
Line 74:</p>
<p>our website designed by asp.net 2  (aspx and vbx)</p>
<p>could i couldn&#8217;t find any eval(base64_decode<br />
i need your help to solve this problem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-49</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Mon, 23 Nov 2009 18:03:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-49</guid>
		<description>@Luc,

The hackers have been leaving all sorts of malicious remote control code on websites. But the common thread is the virus/trojan on a PC with FTP access to the site. Please, please have your PC checked and any other PC with FTP access to your sites.

When analyzing these infections you have to look for common denominators. In this case you have 5 sites, 4 on one server and 1 on another server. So I would look deeper for a common denominator - like the PCs being used for FTPing files to the 5 different sites.

Keep looking for the .php files with various base64_decoding strings. Also look for php files with &quot;echo (insert obfuscated javascript here)&quot;

Let me know if you need further help.

Are you comfortable with grep? There&#039;s an awesome program: grepWin that works great at cleaning websites.

Let me know...</description>
		<content:encoded><![CDATA[<p>@Luc,</p>
<p>The hackers have been leaving all sorts of malicious remote control code on websites. But the common thread is the virus/trojan on a PC with FTP access to the site. Please, please have your PC checked and any other PC with FTP access to your sites.</p>
<p>When analyzing these infections you have to look for common denominators. In this case you have 5 sites, 4 on one server and 1 on another server. So I would look deeper for a common denominator &#8211; like the PCs being used for FTPing files to the 5 different sites.</p>
<p>Keep looking for the .php files with various base64_decoding strings. Also look for php files with &#8220;echo (insert obfuscated javascript here)&#8221;</p>
<p>Let me know if you need further help.</p>
<p>Are you comfortable with grep? There&#8217;s an awesome program: grepWin that works great at cleaning websites.</p>
<p>Let me know&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luc</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-48</link>
		<dc:creator>Luc</dc:creator>
		<pubDate>Mon, 23 Nov 2009 16:36:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-48</guid>
		<description>I&#039;ve found this on 5 of my sites today, along with a few new commonalities (although not between every site, just 1 or 2 on each);

1) A file called &quot;mailtest.php&quot; was created on the root a some base64_decode string
2) Where timthumb.php (a popular image resizing script) was being used, new, randomly named directories had been created (presumably to test the attack)
3) 14 lines of document write script tags at the bottom of pages, linking to starktourism.com and ssmgulf.com
4) A file called chat.pl in a cgi-bin

4 of the 5 sites were all on the same server (and the 5th externally hosted with a completely different host), so I&#039;m hoping that it&#039;s a server vulnerability, rather than my PC (which is part of a larger, protected nextwork) that&#039;s been compromised.

The newest one I found was only attacked yesterday (22nd Nov), so there might be a new wave of attacks gearing up...</description>
		<content:encoded><![CDATA[<p>I&#8217;ve found this on 5 of my sites today, along with a few new commonalities (although not between every site, just 1 or 2 on each);</p>
<p>1) A file called &#8220;mailtest.php&#8221; was created on the root a some base64_decode string<br />
2) Where timthumb.php (a popular image resizing script) was being used, new, randomly named directories had been created (presumably to test the attack)<br />
3) 14 lines of document write script tags at the bottom of pages, linking to starktourism.com and ssmgulf.com<br />
4) A file called chat.pl in a cgi-bin</p>
<p>4 of the 5 sites were all on the same server (and the 5th externally hosted with a completely different host), so I&#8217;m hoping that it&#8217;s a server vulnerability, rather than my PC (which is part of a larger, protected nextwork) that&#8217;s been compromised.</p>
<p>The newest one I found was only attacked yesterday (22nd Nov), so there might be a new wave of attacks gearing up&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: miramis</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-47</link>
		<dc:creator>miramis</dc:creator>
		<pubDate>Fri, 20 Nov 2009 17:28:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-47</guid>
		<description>Thank you for all information.
I found
http://biocasa-inmobiliaria.com/images/start-ES.php
classicholidays.co.in/
freddyboy1.se/
thepascoedifference.com/
leuchtmittel-welt.com/</description>
		<content:encoded><![CDATA[<p>Thank you for all information.<br />
I found<br />
<a href="http://biocasa-inmobiliaria.com/images/start-ES.php" rel="nofollow">http://biocasa-inmobiliaria.com/images/start-ES.php</a><br />
classicholidays.co.in/<br />
freddyboy1.se/<br />
thepascoedifference.com/<br />
leuchtmittel-welt.com/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: b h</title>
		<link>http://wewatchyourwebsite.com/wordpress/2009/11/the-onload-if-this-website-infection/#comment-46</link>
		<dc:creator>b h</dc:creator>
		<pubDate>Sat, 14 Nov 2009 08:49:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.wewatchyourwebsite.com/wordpress/?p=278#comment-46</guid>
		<description>I found http://starktourism.com/flash/mt_global.php as a script that was injected into the HTML using eval</description>
		<content:encoded><![CDATA[<p>I found <a href="http://starktourism.com/flash/mt_global.php" rel="nofollow">http://starktourism.com/flash/mt_global.php</a> as a script that was injected into the HTML using eval</p>
]]></content:encoded>
	</item>
</channel>
</rss>

