<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Mass Attack Underway</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2008/03/12/another-mass-attack-underway/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway</link>
	<description></description>
	<lastBuildDate>Sat, 12 May 2012 04:55:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Website headers simple</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-203513</link>
		<dc:creator>Website headers simple</dc:creator>
		<pubDate>Tue, 07 Feb 2012 11:10:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-203513</guid>
		<description>A comprehensive  quantity of  scientific studies are  put into  seo services  by  pros  since these  goods  will be the  power  with regard to  web site traffic. rUnning  headers, game titles, and the  website ...</description>
		<content:encoded><![CDATA[<p>A comprehensive  quantity of  scientific studies are  put into  seo services  by  pros  since these  goods  will be the  power  with regard to  web site traffic. rUnning  headers, game titles, and the  website &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maeven</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15168</link>
		<dc:creator>Maeven</dc:creator>
		<pubDate>Wed, 19 Mar 2008 20:08:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15168</guid>
		<description>So, how can an ordinary user recognize if their computer is infected with this virus/trojan?  Is there a file name we should be looking for in the Task Manager or elsewhere?</description>
		<content:encoded><![CDATA[<p>So, how can an ordinary user recognize if their computer is infected with this virus/trojan?  Is there a file name we should be looking for in the Task Manager or elsewhere?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aa'ed Alqarta</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15167</link>
		<dc:creator>Aa'ed Alqarta</dc:creator>
		<pubDate>Tue, 18 Mar 2008 20:47:56 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15167</guid>
		<description>System admins should be ready to prevent their clients from getting exploited and redirected to those malicious domains.

check here: http://extremesecurity.blogspot.com/2008/03/iframe-attacks-actions-to-be-taken.html</description>
		<content:encoded><![CDATA[<p>System admins should be ready to prevent their clients from getting exploited and redirected to those malicious domains.</p>
<p>check here: http://extremesecurity.blogspot.com/2008/03/iframe-attacks-actions-to-be-taken.html</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Schmugar</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15166</link>
		<dc:creator>Craig Schmugar</dc:creator>
		<pubDate>Tue, 18 Mar 2008 16:52:54 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15166</guid>
		<description>Blind SQL injection was used to attack ASP applications.  The vulnerability is in the coding of the applications and improper sanitization of input parameters.

More details are available here:
http://blogs.technet.com/neilcar/archive/2008/03/15/anatomy-of-a-sql-injection-incident-part-2-meat.aspx</description>
		<content:encoded><![CDATA[<p>Blind SQL injection was used to attack ASP applications.  The vulnerability is in the coding of the applications and improper sanitization of input parameters.</p>
<p>More details are available here:<br />
http://blogs.technet.com/neilcar/archive/2008/03/15/anatomy-of-a-sql-injection-incident-part-2-meat.aspx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eric</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15165</link>
		<dc:creator>eric</dc:creator>
		<pubDate>Tue, 18 Mar 2008 05:06:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15165</guid>
		<description>So is it a common web server software that is being hacked, apache, iss what have you?</description>
		<content:encoded><![CDATA[<p>So is it a common web server software that is being hacked, apache, iss what have you?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan de Kruyf</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15164</link>
		<dc:creator>Jan de Kruyf</dc:creator>
		<pubDate>Sat, 15 Mar 2008 11:17:40 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15164</guid>
		<description>#  Bas Groot Says:
March 14th, 2008 at 12:19 am

How did they break into the website? If it is automated, it must be a widely spread exploit that is worth reporting.
----------------------------------------------------------------

It is automated, it comes from europe, holland and france the last time I checked, and it is indeed aimed at certain routers. There was a general discussion about 3 years back on the net.
From my analysis they request a specific file on this router &quot;/cgi-bin/firmwarecfg&quot; if they are the first running it then it leaves the whole system wide open since they have access to all info in the router or something like that. In any case complaints to my provider or the provider from whose network some of the attacks originate have not been answered whatsoever.

Peace

Jan de Kruyf.</description>
		<content:encoded><![CDATA[<p>#  Bas Groot Says:<br />
March 14th, 2008 at 12:19 am</p>
<p>How did they break into the website? If it is automated, it must be a widely spread exploit that is worth reporting.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>It is automated, it comes from europe, holland and france the last time I checked, and it is indeed aimed at certain routers. There was a general discussion about 3 years back on the net.<br />
From my analysis they request a specific file on this router &#8220;/cgi-bin/firmwarecfg&#8221; if they are the first running it then it leaves the whole system wide open since they have access to all info in the router or something like that. In any case complaints to my provider or the provider from whose network some of the attacks originate have not been answered whatsoever.</p>
<p>Peace</p>
<p>Jan de Kruyf.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Schmugar</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15163</link>
		<dc:creator>Craig Schmugar</dc:creator>
		<pubDate>Fri, 14 Mar 2008 19:25:02 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15163</guid>
		<description>There&#039;s not much to see...the drive by can cause IE to hang, and the payload doesn&#039;t display anything.</description>
		<content:encoded><![CDATA[<p>There&#8217;s not much to see&#8230;the drive by can cause IE to hang, and the payload doesn&#8217;t display anything.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: curious</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15162</link>
		<dc:creator>curious</dc:creator>
		<pubDate>Fri, 14 Mar 2008 18:28:38 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15162</guid>
		<description>could mcafee show us a video demo of this attack in action, similar to the video for the phpBB hack?

Thanks.</description>
		<content:encoded><![CDATA[<p>could mcafee show us a video demo of this attack in action, similar to the video for the phpBB hack?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Toralv Dirro</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15161</link>
		<dc:creator>Toralv Dirro</dc:creator>
		<pubDate>Fri, 14 Mar 2008 12:28:06 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15161</guid>
		<description>That is an attempt to exploit a 3 year old vulnerability found in some DSL routers if remote management is enabled and is very likely not related to the Mass Hack Attacks.


cheers,
Toralv</description>
		<content:encoded><![CDATA[<p>That is an attempt to exploit a 3 year old vulnerability found in some DSL routers if remote management is enabled and is very likely not related to the Mass Hack Attacks.</p>
<p>cheers,<br />
Toralv</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bas Groot</title>
		<link>http://blogs.mcafee.com/mcafee-labs/another-mass-attack-underway/comment-page-1#comment-15160</link>
		<dc:creator>Bas Groot</dc:creator>
		<pubDate>Fri, 14 Mar 2008 08:19:58 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.mcafee.com/2008/03/12/another-mass-attack-underway/#comment-15160</guid>
		<description>How did they break into the website? If it is automated, it must be a widely spread exploit that is worth reporting.</description>
		<content:encoded><![CDATA[<p>How did they break into the website? If it is automated, it must be a widely spread exploit that is worth reporting.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

