<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Malicious “Income” IFrames from .CN Domains</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sat, 20 Mar 2010 16:18:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: robert</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-6136</link>
		<dc:creator>robert</dc:creator>
		<pubDate>Tue, 08 Dec 2009 22:39:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-6136</guid>
		<description>You can make sure you have a proper firewall in front of your server which will may protect you from these sort of attacks...lock it right down and only open the ports your require. Also you can block domain&#039;s which can help</description>
		<content:encoded><![CDATA[<p>You can make sure you have a proper firewall in front of your server which will may protect you from these sort of attacks&#8230;lock it right down and only open the ports your require. Also you can block domain&#8217;s which can help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-4522</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 05 Oct 2009 09:28:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-4522</guid>
		<description>.gnome2 is a folder of the &lt;a href=&quot;http://www.gnome.org/&quot; rel=&quot;nofollow&quot;&gt;Gnome 2.x&lt;/a&gt; (desktop for Linux computers). However this desktop is not used on servers.

Check the owner of the folder and the creation date.</description>
		<content:encoded><![CDATA[<p>.gnome2 is a folder of the <a href="http://www.gnome.org/" rel="nofollow">Gnome 2.x</a> (desktop for Linux computers). However this desktop is not used on servers.</p>
<p>Check the owner of the folder and the creation date.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-4521</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 05 Oct 2009 09:24:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-4521</guid>
		<description>Everything is automated and done by thousands of infected user computers. By the way your computer is/was also infected and hacked some other sites.

I know this because these &lt;a href=&quot;http://blog.unmaskparasites.com/2009/09/17/quicksilver-malware-network/&quot; rel=&quot;nofollow&quot;&gt;iframes are injected&lt;/a&gt; when trojans &lt;a href=&quot;http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/&quot; rel=&quot;nofollow&quot;&gt;steal FTP credentials&lt;/a&gt; from infected computers.</description>
		<content:encoded><![CDATA[<p>Everything is automated and done by thousands of infected user computers. By the way your computer is/was also infected and hacked some other sites.</p>
<p>I know this because these <a href="http://blog.unmaskparasites.com/2009/09/17/quicksilver-malware-network/" rel="nofollow">iframes are injected</a> when trojans <a href="http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/" rel="nofollow">steal FTP credentials</a> from infected computers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thorir</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-4506</link>
		<dc:creator>thorir</dc:creator>
		<pubDate>Mon, 05 Oct 2009 01:08:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-4506</guid>
		<description>This is a site I did, It got hit pretty bad.. the &quot;virus&quot; comes again again, I have cleaned my own computer. But how can they change the html files so fast?.. just few hours later, the virus is back. Is it a javascript file? Or is something logging into the ftp and changing the files?</description>
		<content:encoded><![CDATA[<p>This is a site I did, It got hit pretty bad.. the &#8220;virus&#8221; comes again again, I have cleaned my own computer. But how can they change the html files so fast?.. just few hours later, the virus is back. Is it a javascript file? Or is something logging into the ftp and changing the files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: phil</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-4498</link>
		<dc:creator>phil</dc:creator>
		<pubDate>Sun, 04 Oct 2009 18:39:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-4498</guid>
		<description>Hi, last night a new folder turned up in the root of my ftp, named .gnome2, which is seemingly empty. I didnt put it there, the server guys didnt put it there, so I cant see what else it could be but some sort of hack/phising tactic.

Searching .gnome2 doesnt bring up much in the way of info on other cases, but it certianly does worry me and has had me reading up on security and malicious practices all day. 

Im not sure what to do here really, I will follow a few of your rec&#039;s, but if you have ever heard of this before please advise accordingly.

Thanks</description>
		<content:encoded><![CDATA[<p>Hi, last night a new folder turned up in the root of my ftp, named .gnome2, which is seemingly empty. I didnt put it there, the server guys didnt put it there, so I cant see what else it could be but some sort of hack/phising tactic.</p>
<p>Searching .gnome2 doesnt bring up much in the way of info on other cases, but it certianly does worry me and has had me reading up on security and malicious practices all day. </p>
<p>Im not sure what to do here really, I will follow a few of your rec&#8217;s, but if you have ever heard of this before please advise accordingly.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking: iFrames containing .cn domains / meta redirects &#124; Dimitri.eu</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-4089</link>
		<dc:creator>Hacking: iFrames containing .cn domains / meta redirects &#124; Dimitri.eu</dc:creator>
		<pubDate>Sat, 19 Sep 2009 13:03:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-4089</guid>
		<description>[...] http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/" rel="nofollow">http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: web security software</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-2880</link>
		<dc:creator>web security software</dc:creator>
		<pubDate>Thu, 10 Sep 2009 12:12:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-2880</guid>
		<description>Nice points you have made about web security. 
Thanks for the post, informative and inciteful, made me think more about web security.</description>
		<content:encoded><![CDATA[<p>Nice points you have made about web security.<br />
Thanks for the post, informative and inciteful, made me think more about web security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael G.</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-2/#comment-2421</link>
		<dc:creator>Michael G.</dc:creator>
		<pubDate>Mon, 07 Sep 2009 05:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-2421</guid>
		<description>One of my client site infect with iframe that redirect to this sites : 3b4 .ru/, q3e .in/, x3y .ru/, using port 8080.

Make sure you clean up all the files that infected ( .... ) and find suspicious javascript code that inject into index.html files on your site. Better not using frame anymore on your site.</description>
		<content:encoded><![CDATA[<p>One of my client site infect with iframe that redirect to this sites : 3b4 .ru/, q3e .in/, x3y .ru/, using port 8080.</p>
<p>Make sure you clean up all the files that infected ( &#8230;. ) and find suspicious javascript code that inject into index.html files on your site. Better not using frame anymore on your site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: metalpigs</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-1/#comment-2395</link>
		<dc:creator>metalpigs</dc:creator>
		<pubDate>Mon, 31 Aug 2009 10:23:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-2395</guid>
		<description>Thanks, great info... my other site had been infected by a malicious code (iframe), but cleaned already. You can also add this suspicious site:
hostads .cn</description>
		<content:encoded><![CDATA[<p>Thanks, great info&#8230; my other site had been infected by a malicious code (iframe), but cleaned already. You can also add this suspicious site:<br />
hostads .cn</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Internet Evolution - Jonathan Hochman - Nasty Malware Attack Targets Web Developers</title>
		<link>http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/comment-page-1/#comment-2249</link>
		<dc:creator>Internet Evolution - Jonathan Hochman - Nasty Malware Attack Targets Web Developers</dc:creator>
		<pubDate>Wed, 19 Aug 2009 14:58:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=151#comment-2249</guid>
		<description>[...] information about this attack is available in this blog on Unmask Parasites regarding Malicious &quot;Income&quot; IFrames from .CN [...]</description>
		<content:encoded><![CDATA[<p>[...] information about this attack is available in this blog on Unmask Parasites regarding Malicious &quot;Income&quot; IFrames from .CN [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
