<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Malware on Hijacked Subdomains. New Trend?</title>
	<atom:link href="http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jayson Feidler</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-10490</link>
		<dc:creator>Jayson Feidler</dc:creator>
		<pubDate>Wed, 10 Nov 2010 19:26:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-10490</guid>
		<description>Isn&#039;t this a rather old method that hackers have been doing for a while now? I have found several reputable sites that host malware because either the webmaster did not update the infrastructure such as a wordpress install, or the hacker has basically taken control of the site inserting his scripts. 

Google is now starting to weed out these sites and not list them on search results.</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t this a rather old method that hackers have been doing for a while now? I have found several reputable sites that host malware because either the webmaster did not update the infrastructure such as a wordpress install, or the hacker has basically taken control of the site inserting his scripts. </p>
<p>Google is now starting to weed out these sites and not list them on search results.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phishing &#8211; Alive and kicking &#124; Naked Security</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-9929</link>
		<dc:creator>Phishing &#8211; Alive and kicking &#124; Naked Security</dc:creator>
		<pubDate>Mon, 25 Oct 2010 01:28:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-9929</guid>
		<description>[...] by a hijacked DNS server for a French construction company. This may be related to other reports of sub-domains being used to mask scam sites off of otherwise reputable domain names. The last four phishes I investigated have all referenced [...]</description>
		<content:encoded><![CDATA[<p>[...] by a hijacked DNS server for a French construction company. This may be related to other reports of sub-domains being used to mask scam sites off of otherwise reputable domain names. The last four phishes I investigated have all referenced [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-8959</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Fri, 03 Sep 2010 19:28:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-8959</guid>
		<description>It&#039;s good that you consider alternatives, however in this particular case we are not talking about WordPress (all types of sites are getting infected), and we have confirmed infection vector (via FTP).</description>
		<content:encoded><![CDATA[<p>It&#8217;s good that you consider alternatives, however in this particular case we are not talking about WordPress (all types of sites are getting infected), and we have confirmed infection vector (via FTP).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ruben</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-8878</link>
		<dc:creator>Ruben</dc:creator>
		<pubDate>Wed, 01 Sep 2010 06:43:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-8878</guid>
		<description>The answer may seem obvious but it aint necessarily so. What if your Wordpress site has been infected by an SQL injection attack which has compromised the database and your tables and files have base64 encoded scripting inserted into them. Those three steps won&#039;t help much...</description>
		<content:encoded><![CDATA[<p>The answer may seem obvious but it aint necessarily so. What if your Wordpress site has been infected by an SQL injection attack which has compromised the database and your tables and files have base64 encoded scripting inserted into them. Those three steps won&#8217;t help much&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-8624</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 04 Aug 2010 20:01:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-8624</guid>
		<description>Do you mean &lt;strong&gt;0 bytes&lt;/strong&gt; by empty? 

Note, sometimes hackers add several screens of blank lines before the actual code. This way files may look empty when you open them in a text editor/viewer and don&#039;t pay attention to the scroolbar (or there is no scrollbar in case of terminal editors like &lt;em&gt;vi&lt;/em&gt; or &lt;em&gt;nano&lt;/em&gt;)</description>
		<content:encoded><![CDATA[<p>Do you mean <strong>0 bytes</strong> by empty? </p>
<p>Note, sometimes hackers add several screens of blank lines before the actual code. This way files may look empty when you open them in a text editor/viewer and don&#8217;t pay attention to the scroolbar (or there is no scrollbar in case of terminal editors like <em>vi</em> or <em>nano</em>)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-8621</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 03 Aug 2010 20:32:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-8621</guid>
		<description>I have 2 websites with a 302 redirect to electnate.com 

I scanned the websites and didn&#039;t find any inserted code.  I checked the .htaccess files but they are empty even though they shouldn&#039;t be. So I changed the file name in httpd.cong from .htaccess to .testing this way Apache would ignore any .htacess files and see what happaned. After ding this I ran the unmaskparasites tool again and it no longer found the 302 redirect for the sites but now I&#039;m confused. 

It seems that 302 redirect rule for electnate would then have to be in one of the .htaccess files that I had Apache ignore but, the .htaccess files are empty.

If I don&#039;t have the .htaccess files then my websites don&#039;t work properly and if I do have them somehow there is a hidden 302 redirect.

Why are my .htaccess files mysteriously empty?  

I checked the entire server from root down, one directory at a time (it took hours) and there are no other .htaccess files other than the ones in public_html for each site but why are they empty and how come I can&#039;t see the content?</description>
		<content:encoded><![CDATA[<p>I have 2 websites with a 302 redirect to electnate.com </p>
<p>I scanned the websites and didn&#8217;t find any inserted code.  I checked the .htaccess files but they are empty even though they shouldn&#8217;t be. So I changed the file name in httpd.cong from .htaccess to .testing this way Apache would ignore any .htacess files and see what happaned. After ding this I ran the unmaskparasites tool again and it no longer found the 302 redirect for the sites but now I&#8217;m confused. </p>
<p>It seems that 302 redirect rule for electnate would then have to be in one of the .htaccess files that I had Apache ignore but, the .htaccess files are empty.</p>
<p>If I don&#8217;t have the .htaccess files then my websites don&#8217;t work properly and if I do have them somehow there is a hidden 302 redirect.</p>
<p>Why are my .htaccess files mysteriously empty?  </p>
<p>I checked the entire server from root down, one directory at a time (it took hours) and there are no other .htaccess files other than the ones in public_html for each site but why are they empty and how come I can&#8217;t see the content?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-8571</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 25 Jul 2010 15:00:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-8571</guid>
		<description>Dan,

Rogue A-records don&#039;t apply to hacked sites. They apply to the sites where your webpages redirect to. In your case, &lt;b&gt;wiki&lt;/b&gt;.&lt;i&gt;natebennettfleming .com&lt;/i&gt; is an A-record of &lt;i&gt;natebennettfleming .com&lt;/i&gt;

&lt;i&gt;&gt;I checked every level up to the root &lt;/i&gt;

Did you check above the root?</description>
		<content:encoded><![CDATA[<p>Dan,</p>
<p>Rogue A-records don&#8217;t apply to hacked sites. They apply to the sites where your webpages redirect to. In your case, <b>wiki</b>.<i>natebennettfleming .com</i> is an A-record of <i>natebennettfleming .com</i></p>
<p><i>&gt;I checked every level up to the root </i></p>
<p>Did you check above the root?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-8565</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Sat, 24 Jul 2010 07:07:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-8565</guid>
		<description>- UPDATE - 

Ok so since I could not find the redirect rule in any .htaccess and didn&#039;t see an A-record I decided to: 

1) Back the site up by changing the directory&#039;s name since it was a addon domain.

2) Create a new/blank directory with the previous name.

3) Delete the addon domain from cPanel.  This is why I created a blank directory because otherwise cPanel might have a problem deleting a site that didn&#039;t have a directory found.

4) I readded the addon domain.

5) I deleted the directory that was automatically created when I added the addon domain again and then renamed the old directory that I previously named something else back to the original name.

That solved it!

Not sure how because their wasn&#039;t an A-Record before but if there was somewhere or somehow by doing the above I erased my DNS zone records and started fresh.  I never found any thing in .htaccess in fact I don&#039;t have an .htaccess file for this particular site so if anyone one else comes across this hopefully this will help.  

Best of luck :)</description>
		<content:encoded><![CDATA[<p>- UPDATE &#8211; </p>
<p>Ok so since I could not find the redirect rule in any .htaccess and didn&#8217;t see an A-record I decided to: </p>
<p>1) Back the site up by changing the directory&#8217;s name since it was a addon domain.</p>
<p>2) Create a new/blank directory with the previous name.</p>
<p>3) Delete the addon domain from cPanel.  This is why I created a blank directory because otherwise cPanel might have a problem deleting a site that didn&#8217;t have a directory found.</p>
<p>4) I readded the addon domain.</p>
<p>5) I deleted the directory that was automatically created when I added the addon domain again and then renamed the old directory that I previously named something else back to the original name.</p>
<p>That solved it!</p>
<p>Not sure how because their wasn&#8217;t an A-Record before but if there was somewhere or somehow by doing the above I erased my DNS zone records and started fresh.  I never found any thing in .htaccess in fact I don&#8217;t have an .htaccess file for this particular site so if anyone one else comes across this hopefully this will help.  </p>
<p>Best of luck :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-8563</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Sat, 24 Jul 2010 04:21:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-8563</guid>
		<description>Hmmm, I have the same problem but my website is in flash and I don&#039;t use an .htaccess file for this site since I don&#039;t need any rewrite rules.  When I visit my site as soon as I get to the home page my antivirus goes crazy and it looks like my sie is trying to redirect to wiki.natebennettfleming.com/main.php?e=r&amp;h=  which is on the list above.  

I checked the DNS zone for this domain in my hosting panel and there isn&#039;t an A record for any other IP other than my host&#039;s.  

Where else can I find where this may be inserted so that I can cure my site?

It&#039;s not in DNS zone as an A-record and it&#039;s not in .htaccess, I checked every level up to the root and I don&#039;t have any .htaccess for this site. 

Any help is appreciated.</description>
		<content:encoded><![CDATA[<p>Hmmm, I have the same problem but my website is in flash and I don&#8217;t use an .htaccess file for this site since I don&#8217;t need any rewrite rules.  When I visit my site as soon as I get to the home page my antivirus goes crazy and it looks like my sie is trying to redirect to wiki.natebennettfleming.com/main.php?e=r&amp;h=  which is on the list above.  </p>
<p>I checked the DNS zone for this domain in my hosting panel and there isn&#8217;t an A record for any other IP other than my host&#8217;s.  </p>
<p>Where else can I find where this may be inserted so that I can cure my site?</p>
<p>It&#8217;s not in DNS zone as an A-record and it&#8217;s not in .htaccess, I checked every level up to the root and I don&#8217;t have any .htaccess for this site. </p>
<p>Any help is appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/comment-page-1/#comment-7979</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Tue, 22 Jun 2010 13:57:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=628#comment-7979</guid>
		<description>Actually, while strong passwords are a really good practice, it doesn&#039;t matter how strong they are if &lt;a href=&quot;http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/&quot; rel=&quot;nofollow&quot;&gt;hackers can simply steal them&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>Actually, while strong passwords are a really good practice, it doesn&#8217;t matter how strong they are if <a href="http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/" rel="nofollow">hackers can simply steal them</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

