<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Evolution of Hidden Iframes</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-6240</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 14 Dec 2009 23:44:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-6240</guid>
		<description>The easiest (and the most common) way is using &lt;a href=&quot;http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/&quot; rel=&quot;nofollow&quot;&gt;stolen FTP credentials&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>The easiest (and the most common) way is using <a href="http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/" rel="nofollow">stolen FTP credentials</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-6238</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 14 Dec 2009 23:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-6238</guid>
		<description>&quot;google analy&lt;b&gt;s&lt;/b&gt;tics&quot; is definitely malicious. Every domain that mimics Google Analytics is at least suspicious.</description>
		<content:encoded><![CDATA[<p>&#8220;google analy<b>s</b>tics&#8221; is definitely malicious. Every domain that mimics Google Analytics is at least suspicious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unknown</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-6232</link>
		<dc:creator>Unknown</dc:creator>
		<pubDate>Mon, 14 Dec 2009 16:44:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-6232</guid>
		<description>I want you to contact me because these does not make sense. How could someone hack with iframes?</description>
		<content:encoded><![CDATA[<p>I want you to contact me because these does not make sense. How could someone hack with iframes?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unknown</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-6231</link>
		<dc:creator>Unknown</dc:creator>
		<pubDate>Mon, 14 Dec 2009 16:43:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-6231</guid>
		<description>Are you saying that google analystics is a hacker? what do you mean.</description>
		<content:encoded><![CDATA[<p>Are you saying that google analystics is a hacker? what do you mean.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: london speed dating</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-5784</link>
		<dc:creator>london speed dating</dc:creator>
		<pubDate>Thu, 19 Nov 2009 09:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-5784</guid>
		<description>I didn&#039;t know that I was infected mootools, is tha
obfuscated JavaScript, but there was an iframe in the document and the destination was exploited.</description>
		<content:encoded><![CDATA[<p>I didn&#8217;t know that I was infected mootools, is tha<br />
obfuscated JavaScript, but there was an iframe in the document and the destination was exploited.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rafael</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-5731</link>
		<dc:creator>Rafael</dc:creator>
		<pubDate>Tue, 17 Nov 2009 12:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-5731</guid>
		<description>&quot;Malwarebytes&#039; Anti-Malware&quot;

People, this software is very nice to prevent your computer!

Bye!</description>
		<content:encoded><![CDATA[<p>&#8220;Malwarebytes&#8217; Anti-Malware&#8221;</p>
<p>People, this software is very nice to prevent your computer!</p>
<p>Bye!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: UnderForge of Lack » Blog Archive » 2009.10.29 木曜日</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-5089</link>
		<dc:creator>UnderForge of Lack » Blog Archive » 2009.10.29 木曜日</dc:creator>
		<pubDate>Thu, 29 Oct 2009 00:34:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-5089</guid>
		<description>[...]  ---------- iFrameインジェクションの進化  Evolution of Hidden Iframes  iframeを隠す手段としてよく使われているのが &lt;iframe src=&quot;hxxp://gumblar .cn/ [...]</description>
		<content:encoded><![CDATA[<p>[...]  &#8212;&#8212;&#8212;- iFrameインジェクションの進化  Evolution of Hidden Iframes  iframeを隠す手段としてよく使われているのが &lt;iframe src=&quot;hxxp://gumblar .cn/ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-5082</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 28 Oct 2009 21:42:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-5082</guid>
		<description>Thomas,

These are probably all main tricks for hiding existing iframes.

On the other hand, there are so many ways to inject hidden iframes on the fly using scripts, that one could write a book about it.</description>
		<content:encoded><![CDATA[<p>Thomas,</p>
<p>These are probably all main tricks for hiding existing iframes.</p>
<p>On the other hand, there are so many ways to inject hidden iframes on the fly using scripts, that one could write a book about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas J. Raef</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-5081</link>
		<dc:creator>Thomas J. Raef</dc:creator>
		<pubDate>Wed, 28 Oct 2009 21:28:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-5081</guid>
		<description>I&#039;m sure in your research you also see many different ways of obfuscating iframes as well.

Care to show some of those methods?</description>
		<content:encoded><![CDATA[<p>I&#8217;m sure in your research you also see many different ways of obfuscating iframes as well.</p>
<p>Care to show some of those methods?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/10/28/evolution-of-hidden-iframes/comment-page-1/#comment-5080</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 28 Oct 2009 21:27:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=361#comment-5080</guid>
		<description>&lt;em&gt;I&#039;ve removed the link from your code since the script is really malicious.&lt;/em&gt;

Dave,

Malicious scripts that inject hidden iframes is a whole new story. Much longer story than this one...</description>
		<content:encoded><![CDATA[<p><em>I&#8217;ve removed the link from your code since the script is really malicious.</em></p>
<p>Dave,</p>
<p>Malicious scripts that inject hidden iframes is a whole new story. Much longer story than this one&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

