<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Malware on Hijacked Subdomains. Part 2.</title>
	<atom:link href="http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Hanson</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-9586</link>
		<dc:creator>Hanson</dc:creator>
		<pubDate>Sun, 10 Oct 2010 05:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-9586</guid>
		<description>Recently my domain was hacked through the appending of the .htaccess file on Godaddy.   It would redirect the browser to a .ru site if it&#039;s referred by google, facebook, twitter, those popular search engines.  So I did a force rewrite on the .htaccess, but once or twice a week the file&#039;s permission gets changed and the .htaccess file is appended with those redirecting codes again.  

And what is really weird is that if I make my .htaccess empty, it would redirect the those referred link directly to .ru site again.

I contacted Godaddy several times with their online support and all I get is generic support.  It seems as if the shared hosting server that I&#039;m on is infected.  I have requested FTP log and there isn&#039;t any log during the time the file was changed

What other file could cause the site to redirect other than the .htacess?  I have removed all files in the root directory and leave with just one index.php file.  It still redirect me to outside server if I change my .htaccess file to blank.</description>
		<content:encoded><![CDATA[<p>Recently my domain was hacked through the appending of the .htaccess file on Godaddy.   It would redirect the browser to a .ru site if it&#8217;s referred by google, facebook, twitter, those popular search engines.  So I did a force rewrite on the .htaccess, but once or twice a week the file&#8217;s permission gets changed and the .htaccess file is appended with those redirecting codes again.  </p>
<p>And what is really weird is that if I make my .htaccess empty, it would redirect the those referred link directly to .ru site again.</p>
<p>I contacted Godaddy several times with their online support and all I get is generic support.  It seems as if the shared hosting server that I&#8217;m on is infected.  I have requested FTP log and there isn&#8217;t any log during the time the file was changed</p>
<p>What other file could cause the site to redirect other than the .htacess?  I have removed all files in the root directory and leave with just one index.php file.  It still redirect me to outside server if I change my .htaccess file to blank.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yeahbabyyeah</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-9275</link>
		<dc:creator>yeahbabyyeah</dc:creator>
		<pubDate>Tue, 21 Sep 2010 16:13:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-9275</guid>
		<description>it was 

alienradar. ru/ keystroke.js

not alienware. ru

my mistake- sorry</description>
		<content:encoded><![CDATA[<p>it was </p>
<p>alienradar. ru/ keystroke.js</p>
<p>not alienware. ru</p>
<p>my mistake- sorry</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yeahbabyyeah</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-9274</link>
		<dc:creator>yeahbabyyeah</dc:creator>
		<pubDate>Tue, 21 Sep 2010 16:12:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-9274</guid>
		<description>Got hit as well. 

no subdomains

addonrock. ru/ keystroke.js
alienware. ru/ keystroke.js

they changed all *.js, all *.php, all *.htm files with this script

websites which were infected were hosted by 1and1 in Germany (1und1.de)</description>
		<content:encoded><![CDATA[<p>Got hit as well. </p>
<p>no subdomains</p>
<p>addonrock. ru/ keystroke.js<br />
alienware. ru/ keystroke.js</p>
<p>they changed all *.js, all *.php, all *.htm files with this script</p>
<p>websites which were infected were hosted by 1and1 in Germany (1und1.de)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jj-momscashblog</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-8608</link>
		<dc:creator>jj-momscashblog</dc:creator>
		<pubDate>Mon, 02 Aug 2010 03:18:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-8608</guid>
		<description>My blog has been hit with the &quot;this site may be harmful if you are on it&quot; so many times within the past months that I&#039;ve lost track. Each time I go through the whole deal that is required of us to perform. This time however I  had help with someone who knows more about tech-stuff than I do, and we found a correlation between HostGator vs. THEPLANET and the malware hit site. It seems that THEPLANET is a server for HG which in turns causes problems for anyone who has HG as their hosting co. Do you know any info. regarding this,we went to StopBadware.org and found out about this relationship. I would appreciate it if you could explain it in an easy way for some of us to wrap our heads around. Thanks so much, JJ</description>
		<content:encoded><![CDATA[<p>My blog has been hit with the &#8220;this site may be harmful if you are on it&#8221; so many times within the past months that I&#8217;ve lost track. Each time I go through the whole deal that is required of us to perform. This time however I  had help with someone who knows more about tech-stuff than I do, and we found a correlation between HostGator vs. THEPLANET and the malware hit site. It seems that THEPLANET is a server for HG which in turns causes problems for anyone who has HG as their hosting co. Do you know any info. regarding this,we went to StopBadware.org and found out about this relationship. I would appreciate it if you could explain it in an easy way for some of us to wrap our heads around. Thanks so much, JJ</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: StopBadware - Hijacked subdomains still serving malware</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-8577</link>
		<dc:creator>StopBadware - Hijacked subdomains still serving malware</dc:creator>
		<pubDate>Mon, 26 Jul 2010 20:58:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-8577</guid>
		<description>[...] by Oliver Day Mon, 26 Jul 2010 20:43:41 GMT  Last month the Unmask Parasites blog wrote about attacks using hijacked sudomains of legitimate websites to serve badware. &#160;At the [...]</description>
		<content:encoded><![CDATA[<p>[...] by Oliver Day Mon, 26 Jul 2010 20:43:41 GMT  Last month the Unmask Parasites blog wrote about attacks using hijacked sudomains of legitimate websites to serve badware. &nbsp;At the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-8364</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 14 Jul 2010 15:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-8364</guid>
		<description>They don&#039;t resort to only hijacked subdomains. They also use their own domains (as they did before the subdomains).

Again, each of them point to 5 different IPs where they set up reverse proxies

&lt;code&gt;
pantscow .ru.		78	IN	A	94.23.34.93
pantscow .ru.		78	IN	A	87.98.136.164
pantscow .ru.		78	IN	A	94.23.231.140
pantscow .ru.		78	IN	A	94.23.240.219
pantscow .ru.		78	IN	A	91.121.184.181
&lt;/code&gt;

hxxp://&lt;strong&gt;pansolo .ru&lt;/strong&gt;/Web_Host.js

hxxp://&lt;strong&gt;greatrow .ru&lt;/strong&gt;/End_User.js

hxxp://&lt;strong&gt;nuttypiano .com&lt;/strong&gt;/LAN.js
&lt;code&gt;nuttypiano .com.		66	IN	A	91.121.61.207
nuttypiano .com.		66	IN	A	91.121.135.109
nuttypiano .com.		66	IN	A	94.32.66.150
nuttypiano .com.		66	IN	A	213.165.91.101
nuttypiano .com.		66	IN	A	82.103.129.152&lt;/code&gt;

hxxp://&lt;strong&gt;addonrock .ru&lt;/strong&gt;/Emulation.js
&lt;code&gt;addonrock .ru.		83	IN	A	212.57.179.29
addonrock .ru.		83	IN	A	66.241.102.159
addonrock .ru.		83	IN	A	66.241.102.166
addonrock .ru.		83	IN	A	85.90.233.171
addonrock .ru.		83	IN	A	89.39.203.134&lt;/code&gt;

hxxp://&lt;strong&gt;subbell .ru&lt;/strong&gt;/LIFO.js
&lt;code&gt;subbell .ru.		432	IN	A	94.23.202.33
subbell .ru.		432	IN	A	109.168.126.54
subbell .ru.		432	IN	A	195.2.139.31
subbell .ru.		432	IN	A	88.191.96.7
subbell .ru.		432	IN	A	88.208.234.222&lt;/code&gt;

&lt;code&gt;idealdesk .ru.		432	IN	A	94.23.60.106
idealdesk .ru.		432	IN	A	178.32.5.232
idealdesk .ru.		432	IN	A	188.165.192.106
idealdesk .ru.		432	IN	A	91.121.96.212
idealdesk .ru.		432	IN	A	94.23.24.90&lt;/code&gt;

&lt;code&gt;farbaby .ru.		432	IN	A	88.191.96.7
farbaby .ru.		432	IN	A	88.208.234.222
farbaby .ru.		432	IN	A	94.23.202.33
farbaby .ru.		432	IN	A	109.168.126.54
farbaby .ru.		432	IN	A	195.2.139.31&lt;/code&gt;

hxxp://&lt;strong&gt;dullplane .ru&lt;/strong&gt;/Webmaster.js
&lt;code&gt;dullplane .ru.		344	IN	A	94.23.202.33
dullplane .ru.		344	IN	A	216.66.78.137
dullplane .ru.		344	IN	A	88.191.96.7
dullplane .ru.		344	IN	A	88.208.234.222
dullplane .ru.		344	IN	A	93.157.232.64&lt;/code&gt;

hxxp://&lt;strong&gt;youngarea .ru&lt;/strong&gt;/AGP.js
&lt;code&gt;youngarea .ru.		395	IN	A	88.191.96.7
youngarea .ru.		395	IN	A	88.208.234.222
youngarea .ru.		395	IN	A	93.157.232.64
youngarea .ru.		395	IN	A	94.23.202.33
youngarea .ru.		395	IN	A	216.66.78.137&lt;/code&gt;

hxxp://&lt;strong&gt;hugejar .com&lt;/strong&gt;:8080/Bandwidth.js
hxxp://&lt;strong&gt;trapbarf .ru&lt;/strong&gt;/IM.js

hxxp://&lt;strong&gt;shelfmurder .ru&lt;/strong&gt;/QWERTY.js
hxxp://&lt;strong&gt;cutboss .ru&lt;/strong&gt;/RADCAB.js

hxxp://&lt;strong&gt;riotassistance .ru&lt;/strong&gt;/Template.js
&lt;code&gt;riotassistance.ru.	395	IN	A	217.195.160.74
riotassistance .ru.	395	IN	A	77.37.21.166
riotassistance .ru.	395	IN	A	77.235.44.94
riotassistance .ru.	395	IN	A	88.191.47.83
riotassistance .ru.	395	IN	A	93.157.232.64&lt;/code&gt;

hxxp://&lt;strong&gt;pocketbloke .ru&lt;/strong&gt;/Tebibyte.js
&lt;code&gt;pocketbloke .ru.		344	IN	A	77.235.44.94
pocketbloke .ru.		344	IN	A	88.191.47.83
pocketbloke .ru.		344	IN	A	93.157.232.64
pocketbloke .ru.		344	IN	A	217.195.160.74
pocketbloke .ru.		344	IN	A	77.37.21.166&lt;/code&gt;

hxxp://&lt;strong&gt;hairyartist .ru&lt;/strong&gt;/JPEG.js
&lt;code&gt;hairyartist .ru.		432	IN	A	97.107.132.41
hairyartist .ru.		432	IN	A	188.40.58.19
hairyartist .ru.		432	IN	A	85.120.34.244
hairyartist .ru.		432	IN	A	88.191.47.83
hairyartist .ru.		432	IN	A	89.19.5.116&lt;/code&gt;

hxxp://obscurewax .ru/Scroll_Wheel.js
&lt;code&gt;
obscurewax .ru.		388	IN	A	217.151.230.10
obscurewax .ru.		388	IN	A	188.40.58.19
obscurewax .ru.		388	IN	A	88.191.47.83
obscurewax .ru.		388	IN	A	85.120.34.244
obscurewax .ru.		388	IN	A	212.176.115.141
&lt;/code&gt;

Another variant: hxxp://roundstorm .com:8080/Megabyte.js
&lt;code&gt;
roundstorm .com.		432	IN	A	91.121.162.65
roundstorm .com.		432	IN	A	194.24.228.81
roundstorm .com.		432	IN	A	213.175.207.140
roundstorm .com.		432	IN	A	62.212.132.226
roundstorm .com.		432	IN	A	88.84.145.36
&lt;/code&gt;

&lt;code&gt;serfinworld.com.	900	IN	A	201.233.32.161
serfinworld.com.	900	IN	A	71.205.41.75
serfinworld.com.	900	IN	A	70.66.77.227
serfinworld.com.	900	IN	A	173.30.189.230
serfinworld.com.	900	IN	A	71.192.136.228&lt;/code&gt;

&lt;code&gt;profincorp.com.		900	IN	A	71.192.136.228
profincorp.com.		900	IN	A	70.66.77.227
profincorp.com.		900	IN	A	173.30.189.230
profincorp.com.		900	IN	A	201.233.32.161
profincorp.com.		900	IN	A	71.205.41.75&lt;/code&gt;

&lt;code&gt;diseasednoodle.ru.	432	IN	A	91.121.188.123
diseasednoodle.ru.	432	IN	A	188.165.95.133
diseasednoodle.ru.	432	IN	A	188.165.212.54
diseasednoodle.ru.	432	IN	A	87.98.147.134
diseasednoodle.ru.	432	IN	A	91.121.108.61&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>They don&#8217;t resort to only hijacked subdomains. They also use their own domains (as they did before the subdomains).</p>
<p>Again, each of them point to 5 different IPs where they set up reverse proxies</p>
<p><code><br />
pantscow .ru.		78	IN	A	94.23.34.93<br />
pantscow .ru.		78	IN	A	87.98.136.164<br />
pantscow .ru.		78	IN	A	94.23.231.140<br />
pantscow .ru.		78	IN	A	94.23.240.219<br />
pantscow .ru.		78	IN	A	91.121.184.181<br />
</code></p>
<p>hxxp://<strong>pansolo .ru</strong>/Web_Host.js</p>
<p>hxxp://<strong>greatrow .ru</strong>/End_User.js</p>
<p>hxxp://<strong>nuttypiano .com</strong>/LAN.js<br />
<code>nuttypiano .com.		66	IN	A	91.121.61.207<br />
nuttypiano .com.		66	IN	A	91.121.135.109<br />
nuttypiano .com.		66	IN	A	94.32.66.150<br />
nuttypiano .com.		66	IN	A	213.165.91.101<br />
nuttypiano .com.		66	IN	A	82.103.129.152</code></p>
<p>hxxp://<strong>addonrock .ru</strong>/Emulation.js<br />
<code>addonrock .ru.		83	IN	A	212.57.179.29<br />
addonrock .ru.		83	IN	A	66.241.102.159<br />
addonrock .ru.		83	IN	A	66.241.102.166<br />
addonrock .ru.		83	IN	A	85.90.233.171<br />
addonrock .ru.		83	IN	A	89.39.203.134</code></p>
<p>hxxp://<strong>subbell .ru</strong>/LIFO.js<br />
<code>subbell .ru.		432	IN	A	94.23.202.33<br />
subbell .ru.		432	IN	A	109.168.126.54<br />
subbell .ru.		432	IN	A	195.2.139.31<br />
subbell .ru.		432	IN	A	88.191.96.7<br />
subbell .ru.		432	IN	A	88.208.234.222</code></p>
<p><code>idealdesk .ru.		432	IN	A	94.23.60.106<br />
idealdesk .ru.		432	IN	A	178.32.5.232<br />
idealdesk .ru.		432	IN	A	188.165.192.106<br />
idealdesk .ru.		432	IN	A	91.121.96.212<br />
idealdesk .ru.		432	IN	A	94.23.24.90</code></p>
<p><code>farbaby .ru.		432	IN	A	88.191.96.7<br />
farbaby .ru.		432	IN	A	88.208.234.222<br />
farbaby .ru.		432	IN	A	94.23.202.33<br />
farbaby .ru.		432	IN	A	109.168.126.54<br />
farbaby .ru.		432	IN	A	195.2.139.31</code></p>
<p>hxxp://<strong>dullplane .ru</strong>/Webmaster.js<br />
<code>dullplane .ru.		344	IN	A	94.23.202.33<br />
dullplane .ru.		344	IN	A	216.66.78.137<br />
dullplane .ru.		344	IN	A	88.191.96.7<br />
dullplane .ru.		344	IN	A	88.208.234.222<br />
dullplane .ru.		344	IN	A	93.157.232.64</code></p>
<p>hxxp://<strong>youngarea .ru</strong>/AGP.js<br />
<code>youngarea .ru.		395	IN	A	88.191.96.7<br />
youngarea .ru.		395	IN	A	88.208.234.222<br />
youngarea .ru.		395	IN	A	93.157.232.64<br />
youngarea .ru.		395	IN	A	94.23.202.33<br />
youngarea .ru.		395	IN	A	216.66.78.137</code></p>
<p>hxxp://<strong>hugejar .com</strong>:8080/Bandwidth.js<br />
hxxp://<strong>trapbarf .ru</strong>/IM.js</p>
<p>hxxp://<strong>shelfmurder .ru</strong>/QWERTY.js<br />
hxxp://<strong>cutboss .ru</strong>/RADCAB.js</p>
<p>hxxp://<strong>riotassistance .ru</strong>/Template.js<br />
<code>riotassistance.ru.	395	IN	A	217.195.160.74<br />
riotassistance .ru.	395	IN	A	77.37.21.166<br />
riotassistance .ru.	395	IN	A	77.235.44.94<br />
riotassistance .ru.	395	IN	A	88.191.47.83<br />
riotassistance .ru.	395	IN	A	93.157.232.64</code></p>
<p>hxxp://<strong>pocketbloke .ru</strong>/Tebibyte.js<br />
<code>pocketbloke .ru.		344	IN	A	77.235.44.94<br />
pocketbloke .ru.		344	IN	A	88.191.47.83<br />
pocketbloke .ru.		344	IN	A	93.157.232.64<br />
pocketbloke .ru.		344	IN	A	217.195.160.74<br />
pocketbloke .ru.		344	IN	A	77.37.21.166</code></p>
<p>hxxp://<strong>hairyartist .ru</strong>/JPEG.js<br />
<code>hairyartist .ru.		432	IN	A	97.107.132.41<br />
hairyartist .ru.		432	IN	A	188.40.58.19<br />
hairyartist .ru.		432	IN	A	85.120.34.244<br />
hairyartist .ru.		432	IN	A	88.191.47.83<br />
hairyartist .ru.		432	IN	A	89.19.5.116</code></p>
<p>hxxp://obscurewax .ru/Scroll_Wheel.js<br />
<code><br />
obscurewax .ru.		388	IN	A	217.151.230.10<br />
obscurewax .ru.		388	IN	A	188.40.58.19<br />
obscurewax .ru.		388	IN	A	88.191.47.83<br />
obscurewax .ru.		388	IN	A	85.120.34.244<br />
obscurewax .ru.		388	IN	A	212.176.115.141<br />
</code></p>
<p>Another variant: hxxp://roundstorm .com:8080/Megabyte.js<br />
<code><br />
roundstorm .com.		432	IN	A	91.121.162.65<br />
roundstorm .com.		432	IN	A	194.24.228.81<br />
roundstorm .com.		432	IN	A	213.175.207.140<br />
roundstorm .com.		432	IN	A	62.212.132.226<br />
roundstorm .com.		432	IN	A	88.84.145.36<br />
</code></p>
<p><code>serfinworld.com.	900	IN	A	201.233.32.161<br />
serfinworld.com.	900	IN	A	71.205.41.75<br />
serfinworld.com.	900	IN	A	70.66.77.227<br />
serfinworld.com.	900	IN	A	173.30.189.230<br />
serfinworld.com.	900	IN	A	71.192.136.228</code></p>
<p><code>profincorp.com.		900	IN	A	71.192.136.228<br />
profincorp.com.		900	IN	A	70.66.77.227<br />
profincorp.com.		900	IN	A	173.30.189.230<br />
profincorp.com.		900	IN	A	201.233.32.161<br />
profincorp.com.		900	IN	A	71.205.41.75</code></p>
<p><code>diseasednoodle.ru.	432	IN	A	91.121.188.123<br />
diseasednoodle.ru.	432	IN	A	188.165.95.133<br />
diseasednoodle.ru.	432	IN	A	188.165.212.54<br />
diseasednoodle.ru.	432	IN	A	87.98.147.134<br />
diseasednoodle.ru.	432	IN	A	91.121.108.61</code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maarten</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-8359</link>
		<dc:creator>Maarten</dc:creator>
		<pubDate>Wed, 14 Jul 2010 08:20:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-8359</guid>
		<description>It might be a trend, i also had an infected site with the same kind of scripts inserted, this one pointed to 

hxxp://pantscow .ru:8080/OASIS.js

(no subdomain here!)

The infected site was not hosted by GoDaddy this time, but by a company named realhosting.nl. After changing the FTP password the site was infected again, so i guess someone found an exploit to gain access to their servers as well. I informed the hosting provider...</description>
		<content:encoded><![CDATA[<p>It might be a trend, i also had an infected site with the same kind of scripts inserted, this one pointed to </p>
<p>hxxp://pantscow .ru:8080/OASIS.js</p>
<p>(no subdomain here!)</p>
<p>The infected site was not hosted by GoDaddy this time, but by a company named realhosting.nl. After changing the FTP password the site was infected again, so i guess someone found an exploit to gain access to their servers as well. I informed the hosting provider&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-8340</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Mon, 12 Jul 2010 14:30:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-8340</guid>
		<description>Hi Denis,

This seems to be part this injection

http://www.sophos.com/blogs/sophoslabs/?p=10417

pob</description>
		<content:encoded><![CDATA[<p>Hi Denis,</p>
<p>This seems to be part this injection</p>
<p><a href="http://www.sophos.com/blogs/sophoslabs/?p=10417" rel="nofollow">http://www.sophos.com/blogs/sophoslabs/?p=10417</a></p>
<p>pob</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-8096</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Mon, 28 Jun 2010 09:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-8096</guid>
		<description>I find new hijacked subdomains almost every day so I decided to post them here:

&lt;b&gt;blog.locatejobs .org&lt;/b&gt;:8080/File.js
&lt;b&gt;dodo.busop .info&lt;/b&gt;:8080/Emoticon.js
&lt;b&gt;adoffy.alltuckedinathome .com&lt;/b&gt;:8080/LED.js
&lt;b&gt;dolgo.lulucabana .com&lt;/b&gt;:8080/Data.js
&lt;b&gt;soaoo.blog-salopes .com&lt;/b&gt;:8080/Access_Point.js
&lt;b&gt;asol.vmtechsolutions .biz&lt;/b&gt;:8080/File.js
&lt;b&gt;sokyoss.drelshazly .com&lt;/b&gt;:8080/E-commerce.js
&lt;b&gt;questtore.hermosayasociados .com&lt;/b&gt;:8080/Base_Station.js
&lt;b&gt;solk.seamscreative .info&lt;/b&gt;:8080/Undo.js
&lt;b&gt;sfofotky.iexam .info&lt;/b&gt;:8080/ODBC.js
&lt;b&gt;kolpo.gunterschaub .com&lt;/b&gt;:8080/Keywords.js
&lt;b&gt;dolfy.sedonahyperbarics .com&lt;/b&gt;:8080/File.js
&lt;b&gt;golaogp.islamicweightloss .com&lt;/b&gt;:8080/Real-Time.js
&lt;b&gt;asoosp.acilalisveris .com&lt;/b&gt;:8080/OASIS.js
&lt;b&gt;assol.metro-trading .net&lt;/b&gt;:8080/Link.js
&lt;b&gt;blog.nodisposable .com&lt;/b&gt;:8080/URL.js
&lt;b&gt;sogpaoiy.the-mlmpowercall .com&lt;/b&gt;/Zettabyte.js</description>
		<content:encoded><![CDATA[<p>I find new hijacked subdomains almost every day so I decided to post them here:</p>
<p><b>blog.locatejobs .org</b>:8080/File.js<br />
<b>dodo.busop .info</b>:8080/Emoticon.js<br />
<b>adoffy.alltuckedinathome .com</b>:8080/LED.js<br />
<b>dolgo.lulucabana .com</b>:8080/Data.js<br />
<b>soaoo.blog-salopes .com</b>:8080/Access_Point.js<br />
<b>asol.vmtechsolutions .biz</b>:8080/File.js<br />
<b>sokyoss.drelshazly .com</b>:8080/E-commerce.js<br />
<b>questtore.hermosayasociados .com</b>:8080/Base_Station.js<br />
<b>solk.seamscreative .info</b>:8080/Undo.js<br />
<b>sfofotky.iexam .info</b>:8080/ODBC.js<br />
<b>kolpo.gunterschaub .com</b>:8080/Keywords.js<br />
<b>dolfy.sedonahyperbarics .com</b>:8080/File.js<br />
<b>golaogp.islamicweightloss .com</b>:8080/Real-Time.js<br />
<b>asoosp.acilalisveris .com</b>:8080/OASIS.js<br />
<b>assol.metro-trading .net</b>:8080/Link.js<br />
<b>blog.nodisposable .com</b>:8080/URL.js<br />
<b>sogpaoiy.the-mlmpowercall .com</b>/Zettabyte.js</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/comment-page-1/#comment-7988</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 23 Jun 2010 15:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=639#comment-7988</guid>
		<description>I&#039;ve also found a new hijacked domain today:
&lt;strong&gt;iopap.upperdarby26 .com&lt;/strong&gt;

And I still think that it was a phishing attack that helped criminals get access to certain domains&#039; DNS records. There are many known GoDaddy phishing attacks (mainly via email spam). 

If it was some exploitable security hole in GoDaddy&#039;s domain management service, I&#039;m afraid, we would have seed much more hijacked subdomains and altogether stolen domain names.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve also found a new hijacked domain today:<br />
<strong>iopap.upperdarby26 .com</strong></p>
<p>And I still think that it was a phishing attack that helped criminals get access to certain domains&#8217; DNS records. There are many known GoDaddy phishing attacks (mainly via email spam). </p>
<p>If it was some exploitable security hole in GoDaddy&#8217;s domain management service, I&#8217;m afraid, we would have seed much more hijacked subdomains and altogether stolen domain names.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

