<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Twitter API Still Attracts Hackers</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:13:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-7670</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 02 Jun 2010 21:48:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-7670</guid>
		<description>I don&#039;t follow this attack now. 

It worked for a few months.  If I come across a new working algorithm, I&#039;ll publish the update.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t follow this attack now. </p>
<p>It worked for a few months.  If I come across a new working algorithm, I&#8217;ll publish the update.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cyb3rd0lph1n</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-7642</link>
		<dc:creator>cyb3rd0lph1n</dc:creator>
		<pubDate>Tue, 01 Jun 2010 10:06:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-7642</guid>
		<description>Domain generation algorithm seems to have changed at the beginning of May 2010. Any news/info on this ?</description>
		<content:encoded><![CDATA[<p>Domain generation algorithm seems to have changed at the beginning of May 2010. Any news/info on this ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-6176</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Thu, 10 Dec 2009 21:12:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-6176</guid>
		<description>I doubt that the malware itself works with twitter.</description>
		<content:encoded><![CDATA[<p>I doubt that the malware itself works with twitter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J.R. Murray</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-6174</link>
		<dc:creator>J.R. Murray</dc:creator>
		<pubDate>Thu, 10 Dec 2009 19:15:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-6174</guid>
		<description>Sorry, I was referring to Torpig malware itself.  I have searched and not been able to determine this.  Thanks again.</description>
		<content:encoded><![CDATA[<p>Sorry, I was referring to Torpig malware itself.  I have searched and not been able to determine this.  Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-6171</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Thu, 10 Dec 2009 18:27:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-6171</guid>
		<description>The script works in a browser. So it uses the browser&#039;s settings.</description>
		<content:encoded><![CDATA[<p>The script works in a browser. So it uses the browser&#8217;s settings.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J.R. Murray</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-6168</link>
		<dc:creator>J.R. Murray</dc:creator>
		<pubDate>Thu, 10 Dec 2009 15:14:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-6168</guid>
		<description>Denis,

Thanks for the great work.

Do you know if any of this malware is proxy-aware?  For example, will it use a proxy server if one is configured on the host with Internet Explorer to access search.twitter.com?</description>
		<content:encoded><![CDATA[<p>Denis,</p>
<p>Thanks for the great work.</p>
<p>Do you know if any of this malware is proxy-aware?  For example, will it use a proxy server if one is configured on the host with Internet Explorer to access search.twitter.com?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas J. Raef</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-6158</link>
		<dc:creator>Thomas J. Raef</dc:creator>
		<pubDate>Thu, 10 Dec 2009 01:32:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-6158</guid>
		<description>Denis,

I&#039;ve some other code that uses this type of strategy, however it starts with:

$a=&quot;Z6fpZ3dZ22Z2524aZ253dZ2522dw...&quot;

Slightly different but it is still using the Twitter API. I have decoded this part:

&lt;code&gt; &lt;/code&gt;

Let me know if you&#039;d like the file, although you probably already have it. :)

Nice job on the write-up.</description>
		<content:encoded><![CDATA[<p>Denis,</p>
<p>I&#8217;ve some other code that uses this type of strategy, however it starts with:</p>
<p>$a=&#8221;Z6fpZ3dZ22Z2524aZ253dZ2522dw&#8230;&#8221;</p>
<p>Slightly different but it is still using the Twitter API. I have decoded this part:</p>
<p><code> </code></p>
<p>Let me know if you&#8217;d like the file, although you probably already have it. :)</p>
<p>Nice job on the write-up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Twitter API Still Attracts Hackers &#124; Unmask Parasites. Blog. -- Topsy.com</title>
		<link>http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers/comment-page-1/#comment-6150</link>
		<dc:creator>Tweets that mention Twitter API Still Attracts Hackers &#124; Unmask Parasites. Blog. -- Topsy.com</dc:creator>
		<pubDate>Wed, 09 Dec 2009 18:24:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=445#comment-6150</guid>
		<description>[...] This post was mentioned on Twitter by Denis, ak1010 and Malware Domain List, Old Mac Donald. Old Mac Donald said: Twitter API Still Attracts Hackers &#124; Unmask Parasites. Blog.: As of December 2009, hackers more intensively use Twitter http://url4.eu/u6XF [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Denis, ak1010 and Malware Domain List, Old Mac Donald. Old Mac Donald said: Twitter API Still Attracts Hackers | Unmask Parasites. Blog.: As of December 2009, hackers more intensively use Twitter <a href="http://url4.eu/u6XF" rel="nofollow">http://url4.eu/u6XF</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.192 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-07-29 21:21:54 -->
