<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Beladen &#8211; Elusive Web Server Exploit. (information for site owners and hosting providers)</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:13:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-7238</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 02 May 2010 17:52:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-7238</guid>
		<description>It&#039;s not beladen. It doesn&#039;t affect all .php file. With beladen, usually no files are affected at all.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not beladen. It doesn&#8217;t affect all .php file. With beladen, usually no files are affected at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bobby sandhu</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-7226</link>
		<dc:creator>bobby sandhu</dc:creator>
		<pubDate>Sat, 01 May 2010 10:43:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-7226</guid>
		<description>Im using godaddy&#039;s shared hosting and my site has got affected twice in 10 days. The infection targets all .php files and adds an encrypted code to the first line. 

I restored my site using local end backup. Changed all CHMOD permissions to read only. The FTP passwords are iron tough. Still, it came back. Im not sure if its beladen or something new. I can provide screenshots if needed.

Im very sure that its  aserver based issue and im seriously considering moving to a new hosting provider. Can you suggest which is the safest and most co-operative hosting provider. 

Regards
Bobby</description>
		<content:encoded><![CDATA[<p>Im using godaddy&#8217;s shared hosting and my site has got affected twice in 10 days. The infection targets all .php files and adds an encrypted code to the first line. </p>
<p>I restored my site using local end backup. Changed all CHMOD permissions to read only. The FTP passwords are iron tough. Still, it came back. Im not sure if its beladen or something new. I can provide screenshots if needed.</p>
<p>Im very sure that its  aserver based issue and im seriously considering moving to a new hosting provider. Can you suggest which is the safest and most co-operative hosting provider. </p>
<p>Regards<br />
Bobby</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-6751</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 12 Feb 2010 10:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-6751</guid>
		<description>I also received this exploit from adwstat.com/lib/, the hidden iframe was from space.com.  I&#039;ve got a copy of the malicious iframe if that is of use or interest.

Thank you for the article, very helpful.

Kind Regards</description>
		<content:encoded><![CDATA[<p>I also received this exploit from adwstat.com/lib/, the hidden iframe was from space.com.  I&#8217;ve got a copy of the malicious iframe if that is of use or interest.</p>
<p>Thank you for the article, very helpful.</p>
<p>Kind Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A. Upchurch</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-6723</link>
		<dc:creator>A. Upchurch</dc:creator>
		<pubDate>Sat, 06 Feb 2010 01:04:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-6723</guid>
		<description>i don&#039;t have a website. But i did get this  Exploit JavaScript obfuscation threat block from AVG. the file name is adwstat.com/lib/
i could not find any info on AVG on it or what to do about it. I&#039;m not sure i understand what all you guys are doing about it or what i can do about it. any info would be gratefully appreciated.</description>
		<content:encoded><![CDATA[<p>i don&#8217;t have a website. But i did get this  Exploit JavaScript obfuscation threat block from AVG. the file name is adwstat.com/lib/<br />
i could not find any info on AVG on it or what to do about it. I&#8217;m not sure i understand what all you guys are doing about it or what i can do about it. any info would be gratefully appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David H</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-4813</link>
		<dc:creator>David H</dc:creator>
		<pubDate>Mon, 19 Oct 2009 00:28:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-4813</guid>
		<description>The majority of the recommendations and the article seem to be ignoring the fact that if a server is serving up random code instead of what was requested, the server has been root compromised; it&#039;s not just something as innocent and dismissible as oh a site on the server has some php file hiding somewhere and we&#039;re all good if we delete it.

Before a php script can take the place of a child apache process, listen on port 80 and answer queries, the server needs to be hacked; the parent apache process running as root spawns the child processes, it&#039;s not going to randomly spawn someone&#039;s php file instead.  If the server has been hacked, then running a bunch of commands to find things running is pointless as none of the utilities can be trusted, so who knows if what&#039;s being reported has any relevance.  Their output will most likely have been modified to hide the fact that processes that should not be there are running, or maybe they show you some bogus apache-owned process so you can kill it and think you&#039;ve eliminated the issue.

If this problem does occur, all the server binaries should be compared to a known-good system after first replacing the ssh daemon and the commands needed to do the comparison such as md5sum and rsync if you sync up with your read-only known good system, etc.</description>
		<content:encoded><![CDATA[<p>The majority of the recommendations and the article seem to be ignoring the fact that if a server is serving up random code instead of what was requested, the server has been root compromised; it&#8217;s not just something as innocent and dismissible as oh a site on the server has some php file hiding somewhere and we&#8217;re all good if we delete it.</p>
<p>Before a php script can take the place of a child apache process, listen on port 80 and answer queries, the server needs to be hacked; the parent apache process running as root spawns the child processes, it&#8217;s not going to randomly spawn someone&#8217;s php file instead.  If the server has been hacked, then running a bunch of commands to find things running is pointless as none of the utilities can be trusted, so who knows if what&#8217;s being reported has any relevance.  Their output will most likely have been modified to hide the fact that processes that should not be there are running, or maybe they show you some bogus apache-owned process so you can kill it and think you&#8217;ve eliminated the issue.</p>
<p>If this problem does occur, all the server binaries should be compared to a known-good system after first replacing the ssh daemon and the commands needed to do the comparison such as md5sum and rsync if you sync up with your read-only known good system, etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-3887</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Thu, 17 Sep 2009 09:15:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-3887</guid>
		<description>Hi Ben,

I&#039;ve noticed these new sites as well. The malicious redirects a similar to the &lt;a href=&quot;http://blog.unmaskparasites.com/2009/07/23/goscanpark-13-facts-about-malicious-server-wide-meta-redirects/&quot; rel=&quot;nofollow&quot;&gt;Goscanpark attack&lt;/a&gt; (a new version of the same attack)

Thanks for sharing search commands.</description>
		<content:encoded><![CDATA[<p>Hi Ben,</p>
<p>I&#8217;ve noticed these new sites as well. The malicious redirects a similar to the <a href="http://blog.unmaskparasites.com/2009/07/23/goscanpark-13-facts-about-malicious-server-wide-meta-redirects/" rel="nofollow">Goscanpark attack</a> (a new version of the same attack)</p>
<p>Thanks for sharing search commands.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-3826</link>
		<dc:creator>Ben</dc:creator>
		<pubDate>Wed, 16 Sep 2009 23:35:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-3826</guid>
		<description>Also used the following search and found another file!:

find . -iname &#039;*php&#039; &#124; xargs grep &#039;\$_POST\[\&quot;p\&quot;\]&#039; -sl

Again, as mentioned in the article - word wrap wasn&#039;t on in Joe so it looked legit - a search for the term revealed the code way off to the right...</description>
		<content:encoded><![CDATA[<p>Also used the following search and found another file!:</p>
<p>find . -iname &#8216;*php&#8217; | xargs grep &#8216;\$_POST\[\"p\"\]&#8216; -sl</p>
<p>Again, as mentioned in the article &#8211; word wrap wasn&#8217;t on in Joe so it looked legit &#8211; a search for the term revealed the code way off to the right&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-3824</link>
		<dc:creator>Ben</dc:creator>
		<pubDate>Wed, 16 Sep 2009 22:01:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-3824</guid>
		<description>Hi,

Just thought I&#039;d leave a note here thanking you immensely for providing this information.  It aided me in catching the offending file (a file named the same as an image but with php on the end).  I performed the following search in the root of the vhosts directory:

find . -iname &#039;*php&#039; &#124; xargs grep &#039;Instant Zero&#039; -sl

This showed the offending file which I could remove and notify the account holder to &quot;get a real password&quot;.

I also thought I&#039;d share that I saw totally different URLs - my sites were being redirected to:

indianapolis-sales .com
best-virus-scanner5 .com

The rest of the article still fitted (I never did see the processes running however).

Thanks again,
Ben.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Just thought I&#8217;d leave a note here thanking you immensely for providing this information.  It aided me in catching the offending file (a file named the same as an image but with php on the end).  I performed the following search in the root of the vhosts directory:</p>
<p>find . -iname &#8216;*php&#8217; | xargs grep &#8216;Instant Zero&#8217; -sl</p>
<p>This showed the offending file which I could remove and notify the account holder to &#8220;get a real password&#8221;.</p>
<p>I also thought I&#8217;d share that I saw totally different URLs &#8211; my sites were being redirected to:</p>
<p>indianapolis-sales .com<br />
best-virus-scanner5 .com</p>
<p>The rest of the article still fitted (I never did see the processes running however).</p>
<p>Thanks again,<br />
Ben.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: declare.james</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-1526</link>
		<dc:creator>declare.james</dc:creator>
		<pubDate>Tue, 30 Jun 2009 15:22:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-1526</guid>
		<description>Denis,

Just Posted up steps to take to try to prevent attacks like Gumblar, Martuz and Nine-Ball.

http://blog.igothacked.com/2009/06/steps-to-prevent-gumblar-martuz-nine.html</description>
		<content:encoded><![CDATA[<p>Denis,</p>
<p>Just Posted up steps to take to try to prevent attacks like Gumblar, Martuz and Nine-Ball.</p>
<p><a href="http://blog.igothacked.com/2009/06/steps-to-prevent-gumblar-martuz-nine.html" rel="nofollow">http://blog.igothacked.com/2009/06/steps-to-prevent-gumblar-martuz-nine.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Estadd</title>
		<link>http://blog.unmaskparasites.com/2009/06/18/beladen-elusive-web-server-exploit/comment-page-1/#comment-1484</link>
		<dc:creator>Estadd</dc:creator>
		<pubDate>Fri, 19 Jun 2009 14:04:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=225#comment-1484</guid>
		<description>Google? No! Not that for me!
The most unreliable and damaging agent 
for website monitoring - see my earlier posts here. Many have already quit it, not just me. 

Please develop unmaskparasite to such extent that it does better than those and becomes the best. You can !!!</description>
		<content:encoded><![CDATA[<p>Google? No! Not that for me!<br />
The most unreliable and damaging agent<br />
for website monitoring &#8211; see my earlier posts here. Many have already quit it, not just me. </p>
<p>Please develop unmaskparasite to such extent that it does better than those and becomes the best. You can !!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
