<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Unmask Parasites. Blog. &#187; Tweet Week</title>
	<atom:link href="http://blog.unmaskparasites.com/category/tweet-week/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:20:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Tweet Week: July 19-25, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/07/25/tweet-week-july-19-25-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/07/25/tweet-week-july-19-25-2010/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 15:41:37 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[milestone]]></category>
		<category><![CDATA[Soholaunch]]></category>
		<category><![CDATA[vBulletin]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=657</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

July 21, 2010
[zdnet.com] Adobe adding &#8217;sandbox&#8217; to PDF Reader to ward off hacker attacks
[h-online.com] Mozilla releases Firefox &#38; Thunderbird security updates &#8211; 14 security issues addressed in FireFox update
July 22, 2010
[badwarebusters.org] There is a  malware attack that only affects [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-657"></span><br />
<span style="color: #888888;"><strong>July 21, 2010</strong></span></p>
<p style="padding-left: 30px;">[zdnet.com] <a href="http://www.zdnet.com/blog/security/adobe-adding-sandbox-to-pdf-reader-to-ward-off-hacker-attacks/6886">Adobe adding &#8217;sandbox&#8217; to PDF Reader to ward off hacker attacks</a></p>
<p style="padding-left: 30px;">[h-online.com] <a href="http://www.h-online.com/security/news/item/Mozilla-releases-Firefox-Thunderbird-security-updates-1042519.html">Mozilla releases Firefox &amp; Thunderbird security updates</a> &#8211; 14 security issues addressed in FireFox update</p>
<p><span style="color: #888888;"><strong>July 22, 2010</strong></span></p>
<p style="padding-left: 30px;">[badwarebusters.org] There is a  <a href="http://badwarebusters.org/main/itemview/19856">malware attack that only affects sites built with Soholaunch</a> (<a href="http://www.google.com/safebrowsing/diagnostic?site=karatepacan.co.cc/">affected sites</a> via Google diagnostics)</p>
<p style="padding-left: 30px;">Updated my <a href="http://blog.unmaskparasites.com/2009/12/18/list-of-gumblar-zombie-urls/">list of Gumblar zombie URLs</a> &#8211; now 1125 items</p>
<p><span style="color: #888888;"><strong>July 23, 2010</strong></span></p>
<p style="padding-left: 30px;">[milestone] <strong>750,000</strong> web pages checked by Unmask Parasites  <a rel="nofollow" href="http://www.unmaskparasites.com/" target="_blank">http://www.UnmaskParasites.com</a></p>
<p style="padding-left: 30px;">[h-online.com] <a href="http://www.h-online.com/security/news/item/vBulletin-divulges-MySQL-login-1044462.html">vBulletin divulges MySQL login</a> &#8211; version 3.8.6 is vulnerable</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/07/25/tweet-week-july-19-25-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweet Week: July 12-18, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/07/18/tweet-week-july-12-18-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/07/18/tweet-week-july-12-18-2010/#comments</comments>
		<pubDate>Sun, 18 Jul 2010 15:02:23 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[Image Search]]></category>
		<category><![CDATA[MediaTemple]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=655</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

July 12, 2010
A lot of WordPress blogs on RackSpace Cloud are still hacked
July 13, 2010
Someone promotes shoponline2011 site via Image search spam. Check Alexa traffic details
July 15, 2010
Just found an #nginx site that redirects search traffic  to scareware sites. [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-655"></span><br />
<span style="color: #888888;"><strong>July 12, 2010</strong></span></p>
<p style="padding-left: 30px;">A lot of WordPress blogs on RackSpace Cloud are still hacked</p>
<p><span style="color: #888888;"><strong>July 13, 2010</strong></span></p>
<p style="padding-left: 30px;">Someone promotes shoponline2011 site via <a href="http://www.google.com/support/forum/p/Web+Search/thread?tid=75123e892497b576&amp;hl=en">Image search spam</a>. Check <a href="http://www.alexa.com/siteinfo/shoponline2011.com">Alexa traffic details</a></p>
<p><span style="color: #888888;"><strong>July 15, 2010</strong></span></p>
<p style="padding-left: 30px;">Just found an <a title="#nginx" rel="nofollow" href="http://twitter.com/search?q=%23nginx">#nginx</a> site that redirects search traffic  to scareware sites. Previously, such hacks were limited to Apache (mainly)</p>
<p style="padding-left: 30px;">@<a rel="nofollow" href="http://twitter.com/baldown">baldown</a> Good point. I forgot about this config where nginx is just a reverse proxy for Apache. Thanks.</p>
<p><span style="color: #888888;"><strong>July 16, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://weblog.mediatemple.net/weblog/category/system-incidents/1404-wordpress-redirect-exploit/">WordPress Redirect Exploit</a> (on MediaTemple)  and suggested <a href="http://wiki.mediatemple.net/w/WordPress_Redirect_Exploit">clean-up</a> (redirect to <em>qooglesearch .com</em>)</p>
<p style="padding-left: 30px;">If <a rel="nofollow" href="http://www.unmaskparasites.com/" target="_blank">http://www.UnmaskParasites.com</a> reports script from &#8220;ae.awaue .com&#8221; for your WP blog, <a href="http://wiki.mediatemple.net/w/WordPress_Redirect_Exploit">check this</a></p>
<p style="padding-left: 30px;">[netcraft.com] <a href="http://news.netcraft.com/archives/2010/07/15/firefox-security-test-add-on-was-backdoored.html">Firefox security test add-on was backdoored</a></p>
<p><span style="color: #888888;"><strong>July 17, 2010</strong></span></p>
<p style="padding-left: 30px;">[forbes.com] <a href="http://blogs.forbes.com/firewall/2010/07/13/millions-of-home-routers-vulnerable-to-web-hack/">&#8220;Millions&#8221; Of Home Routers Vulnerable To Web Hack</a></p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/gcluley">gcluley</a>: Video and <a href="http://www.sophos.com/blogs/chetw/g/2010/07/16/windows-day-attack-works-windows-systems/">detailed analysis of new zero-day Windows .LNK shortcut vulnerability</a> (via @<a rel="nofollow" href="http://twitter.com/ChetWisniewski">ChetWisniewski</a>)</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/07/18/tweet-week-july-12-18-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweet Week: June 27 &#8211; July 4, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/07/04/tweet-week-june-27-july-4-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/07/04/tweet-week-june-27-july-4-2010/#comments</comments>
		<pubDate>Sun, 04 Jul 2010 19:42:24 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[SQL-injection]]></category>
		<category><![CDATA[WayBackMachine]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=654</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

June 28, 2010
added some more hijacked subdomains (rogue DNS  records of legitimate domains) &#8211; it&#8217;s definitely a trend
Updated my list of Gumblar zombie URLs &#8211; now 1,000+ items. Analysis will follow soon.
Another SQL injection attack against ASP(.NET)  sites. [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-654"></span><br />
<span style="color: #888888;"><strong>June 28, 2010</strong></span></p>
<p style="padding-left: 30px;">added some <a href="http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/#comment-8096">more hijacked subdomains</a> (rogue DNS  records of legitimate domains) &#8211; it&#8217;s definitely a trend</p>
<p style="padding-left: 30px;">Updated my <a href="http://blog.unmaskparasites.com/2009/12/18/list-of-gumblar-zombie-urls/">list of Gumblar zombie URLs</a> &#8211; now 1,000+ items. <a href="http://blog.unmaskparasites.com/2010/06/29/analysis-of-gumblar-zombie-urls/">Analysis</a> will follow soon.</p>
<p style="padding-left: 30px;">Another <a href="http://www.google.com/support/forum/p/Webmasters/thread?tid=3983e5fa6c001976&amp;hl=en&amp;fid=3983e5fa6c00197600048a173873bed1">SQL injection attack against ASP(.NET)  sites</a>. &#8211; thousands of  affected sites.</p>
<p style="padding-left: 30px;">@<a rel="nofollow" href="http://twitter.com/peterkruse">peterkruse</a> told  me that SQL injection attack was Asprox. Indeed, M86 Security described  this very attack <a href="http://www.m86security.com/labs/i/Another-round-of-Asprox-SQL-injection-attacks,trace.1366~.asp">here</a></p>
<p><span style="color: #888888;"><strong>June 29, 2010</strong></span></p>
<p style="padding-left: 30px;">via @<a rel="nofollow" href="http://twitter.com/briankrebs">briankrebs</a> :  There&#8217;s a <a href="http://krebsonsecurity.com/2010/06/security-update-for-adobe-acrobat-reader/">critical security update for Adobe Reader</a> &#8211; but the update process is  somewhat &#8220;tricky&#8221;</p>
<p style="padding-left: 30px;">[h-online.com] <a href="http://www.h-online.com/security/news/item/Google-integrates-safe-PDF-viewer-in-Chrome-1030640.html">Google integrates safe PDF viewer  in Chrome</a> &#8211; Adobe Reader  may become unneeded one day</p>
<p><span style="color: #888888;"><strong>June 30, 2010</strong></span></p>
<p style="padding-left: 30px;">just decoded a malicious PHP code. It had <strong>20</strong> !!!  levels of obfuscation!!! What an overkill and waste of CPU!</p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/mattcutts">mattcutts</a>:  <a href="http://www.mattcutts.com/blog/webspam-projects-in-2010/">Webspam projects in 2010?</a> &#8211; what projects do you think Google webspam should work on in 2010+?</p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/JohnMu">JohnMu</a>: Loving the  new <a rel="nofollow" href="http://waybackmachine.org/" target="_blank">http://waybackmachine.org/</a> &#8212; try it  out with one of your old sites :)</p>
<p><span style="color: #888888;"><strong>July 1, 2010</strong></span></p>
<p style="padding-left: 30px;">[blog] <a href="http://blog.unmaskparasites.com/2010/07/01/happy-2nd-birthday-unmask-parasites/">Happy 2nd Birthday, Unmask Parasites!</a> <a rel="nofollow" href="http://bit.ly/a7Sc3m" target="_blank"></a> + comparison of the 1st and the  2nd years. Steady growth :)</p>
<p style="padding-left: 30px;">[h-online.com] <a href="http://www.h-online.com/security/news/item/Trojan-attacks-now-almost-solely-from-legitimate-websites-1031631.html">Trojan attacks now almost solely  from legitimate websites </a>- only 1%  of threats come from adult sites</p>
<p><span style="color: #888888;"><strong>July 2, 2010</strong></span></p>
<p style="padding-left: 30px;">[securityweek.com] <a href="http://www.securityweek.com/new-tool-reveals-internet-passwords">New Tool Reveals Internet  Passwords</a> &#8211; trojans can  use such tricks too. Do you save passwords in IE?</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/07/04/tweet-week-june-27-july-4-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tweet Week: June 21-27, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/06/27/tweet-week-june-21-27-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/06/27/tweet-week-june-21-27-2010/#comments</comments>
		<pubDate>Sun, 27 Jun 2010 20:43:06 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[RackSpace]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=647</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

June 22, 2010
RT @mattcutts: New  webmaster video: How do you protect your blog from hackers? &#8211; mostly about WordPress
June 24, 2010
[h-online.com] Firefox 3.6.4 adds crash  protection, fixes vulnerabilities &#8211; not all vulnerabilities are fixed though
[status.mosso.com] Status update from [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-647"></span><br />
<span style="color: #888888;"><strong>June 22, 2010</strong></span></p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/mattcutts">mattcutts</a>: New  webmaster video: <a href="http://www.youtube.com/watch?v=gwAlEf-AbCU">How do you protect your blog from hackers?</a> &#8211; mostly about WordPress</p>
<p><span style="color: #888888;"><strong>June 24, 2010</strong></span></p>
<p style="padding-left: 30px;">[h-online.com] <a href="http://www.h-online.com/security/news/item/Firefox-3-6-4-adds-crash-protection-fixes-vulnerabilities-Update-1027586.html">Firefox 3.6.4 adds crash  protection, fixes vulnerabilities</a> &#8211; not all vulnerabilities are fixed though</p>
<p style="padding-left: 30px;">[status.mosso.com] <a href="http://status.mosso.com/2010/06/current-investigation-of-security-incident.html">Status update</a> from RackSpace on  the recent attack against WordPress sites<a rel="nofollow" href="http://bit.ly/bc0omf" target="_blank"></a></p>
<p><span style="color: #888888;"><strong>June 25, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://wordpress.org/development/2010/06/thelonious/"></a>[h-online.com] <a href="http://www.h-online.com/security/news/item/Adobe-brings-forward-security-update-for-Reader-1029200.html">Adobe brings forward security  update for Reader</a> &#8211; to be  available on June 29</p>
<p><span style="color: #888888;"><strong>June 27, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://cloudsites.rackspacecloud.com/index.php/File_Permissions#Cloud_Sites_Scenarios"></a>[status.mosso.com] <a href="http://status.mosso.com/2010/06/current-investigation-of-security-incident-update.html">new status update</a> from RackSpace on their recent security incident</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/06/27/tweet-week-june-21-27-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tweet Week: June 14-20, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/06/21/tweet-week-june-14-20-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/06/21/tweet-week-june-14-20-2010/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 08:57:34 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[RackSpace]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=645</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

June 14, 2010
RT @briankrebs: A  security heads-up for Microsoft XP users 
June 15, 2010
More on RackSpace case: Backdoor scripts in  WordPress mySql tables via @mvandemar
RT @briankrebs:  Keylogger posts stolen data for world to see at pastebin.com
updated my [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-645"></span><br />
<span style="color: #888888;"><strong>June 14, 2010</strong></span></p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/briankrebs">briankrebs</a>: <a href="http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/">A  security heads-up for Microsoft XP users</a> <a rel="nofollow" href="http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/" target="_blank"></a></p>
<p><span style="color: #888888;"><strong>June 15, 2010</strong></span></p>
<p style="padding-left: 30px;">More on RackSpace case: <a href="http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/">Backdoor scripts in  WordPress mySql tables</a> via @<a rel="nofollow" href="http://twitter.com/mvandemar">mvandemar</a></p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/briankrebs">briankrebs</a>: <a href="http://krebsonsecurity.com/2010/06/cloud-keyloggers/"> Keylogger posts stolen data for world to see at pastebin.com</a></p>
<p style="padding-left: 30px;">updated my post about RackSpace with<a href="http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/#update1"> info about  the backdoor script in wp_options table</a></p>
<p><span style="color: #888888;"><strong>June 17, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://wordpress.org/development/2010/06/thelonious/">WordPress 3.0 has just been released</a>.  Is your blog ready for this  major update?</p>
<p><span style="color: #888888;"><strong>June 18, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://cloudsites.rackspacecloud.com/index.php/File_Permissions#Cloud_Sites_Scenarios">secure file and directory permissions on RackSpace  Cloud</a> &#8211; <span style="color: #333333;"><strong>600</strong></span> and <span style="color: #333333;"><strong>700</strong></span> are almost always the best choice</p>
<p style="padding-left: 30px;">[wordpress.org] My summary of the <a href="http://wordpress.org/support/topic/405684/page/2#post-1557998">RackSpace  WordPress issue</a></p>
<p><span style="color: #888888;"><strong>June 19, 2010</strong></span></p>
<p style="padding-left: 30px;">[wordpress.org] some <a href="http://wordpress.org/support/topic/405684/page/2#post-1559680">new details about the  RackSpace WordPress issue</a> <a rel="nofollow" href="http://bit.ly/90AODz" target="_blank"></a></p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/06/21/tweet-week-june-14-20-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweet Week: May 31 &#8211; June 6, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/06/06/tweet-week-may-31-june-6-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/06/06/tweet-week-may-31-june-6-2010/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 12:46:51 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[hotlinking]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[milestone]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=636</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

May 31, 2010
[milestone] Just approved 1,000th comment on my  blog http://blog.unmaskparasites.com
[fbi.gov] “Scareware” Fraud Scheme That Caused  $100 Million in Losses to Internet Victims Worldwide
June 1, 2010
Updated my list of Gumblar zombie URLs &#8211; now 835 items. And the [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-636"></span><br />
<span style="color: #888888;"><strong>May 31, 2010</strong></span></p>
<p style="padding-left: 30px;">[milestone] Just approved <span style="color: #333333;"><strong>1,000</strong></span>th comment on my  blog <a rel="nofollow" href="http://blog.unmaskparasites.com/" target="_blank">http://blog.unmaskparasites.com</a></p>
<p style="padding-left: 30px;">[fbi.gov] <a href="http://chicago.fbi.gov/dojpressrel/pressrel10/cg052710.htm">“Scareware” Fraud Scheme That Caused  $100 Million in Losses</a> to Internet Victims Worldwide</p>
<p><span style="color: #888888;"><strong>June 1, 2010</strong></span></p>
<p style="padding-left: 30px;">Updated my <a href="http://blog.unmaskparasites.com/2009/12/18/list-of-gumblar-zombie-urls/">list of Gumblar zombie URLs</a> &#8211; now 835 items. And the <a href="http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/">list  of hijacked subdomains</a> <a rel="nofollow" href="http://bit.ly/bBdzNZ" target="_blank"></a></p>
<p><span style="color: #888888;"><strong>June 3, 2010</strong></span></p>
<p style="padding-left: 30px;">reddit discussion on <a href="http://www.reddit.com/r/PHP/comments/cahok/askphp_very_basic_security_question_on/">permissions of PHP files</a> <a rel="nofollow" href="http://bit.ly/d1mJp3" target="_blank"></a> &#8211; 644 or 600?</p>
<p style="padding-left: 30px;"><a href="http://www.h-online.com/security/news/item/Qubes-to-implement-Disposable-VMs-1014127.html">Disposable VMs in QubeOs</a> <a rel="nofollow" href="http://bit.ly/9tY16w" target="_blank"></a> &#8211; <a href="http://theinvisiblethings.blogspot.com/2010/06/disposable-vms.html">single-use single-purpose VMs  = improved security</a></p>
<p><span style="color: #888888;"><strong>June 4, 2010</strong></span></p>
<p style="padding-left: 30px;">Another <a href="http://www.google.com/support/forum/p/Webmasters/thread?tid=3929aaab2bc3254e&amp;hl=en">interesting discussion</a> about how Google  image search is actively abused by hot-linkers</p>
<p style="padding-left: 30px;">[zscaler.com] <a href="http://research.zscaler.com/2010/05/300-increase-in-malicious-jars.html">300% Increase In Malicious JARs</a> &#8211; make sure <a href="http://java.com/download/installed.jsp">Java on your PC is  up-to-date</a></p>
<p style="padding-left: 30px;">[zscaler.com] <a href="http://research.zscaler.com/2010/06/spam-seo-use-of-javaflash-leads-to-more.html">Spam SEO: Use of Java/Flash leads to  more dangerous exploits</a></p>
<p><span style="color: #888888;"><strong>June 5, 2010</strong></span></p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/briankrebs">briankrebs</a>:  Adobe warns that hackers are targeting a <a href="http://krebsonsecurity.com/2010/06/adobe-warns-of-critical-flaw-in-flash-acrobat-reader/">previously unknown flaw in  Flash Player, Reader and Acrobat</a></p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/06/06/tweet-week-may-31-june-6-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweet Week: May 24-30, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/05/30/tweet-week-may-24-30-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/05/30/tweet-week-may-24-30-2010/#comments</comments>
		<pubDate>Sun, 30 May 2010 22:02:50 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[bidvertizer]]></category>
		<category><![CDATA[Eleonore]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=632</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

May 24, 2010
via @briankrebs Revisiting the Eleonore Exploit Kit &#8211; new stats on browser vulnerabilities
May 26, 2010
Updated my list of Gumblar zombie URLs &#8211; now 785 items
May 27, 2010
[4sysops.com] Scan your website for malware with  free tools &#8211; 4 [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-632"></span><br />
<span style="color: #888888;"><strong>May 24, 2010</strong></span></p>
<p style="padding-left: 30px;">via @<a rel="nofollow" href="http://twitter.com/briankrebs">briankrebs</a> <a href="http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/">Revisiting the Eleonore Exploit Kit</a> &#8211; new stats on browser vulnerabilities</p>
<p><span style="color: #888888;"><strong>May 26, 2010</strong></span></p>
<p style="padding-left: 30px;">Updated my <a href="http://blog.unmaskparasites.com/2009/12/18/list-of-gumblar-zombie-urls/">list of Gumblar zombie URLs</a> &#8211; now 785 items</p>
<p><span style="color: #888888;"><strong>May 27, 2010</strong></span></p>
<p style="padding-left: 30px;">[4sysops.com] <a href="http://4sysops.com/archives/scan-your-website-for-malware-with-free-tools/">Scan your website for malware with  free tools</a> &#8211; 4 tools  reviewed, including Unmask Parasites</p>
<p><span style="color: #888888;"><strong>May 28, 2010</strong></span></p>
<p style="padding-left: 30px;">There had been <a href="http://www.google.com/safebrowsing/diagnostic?site=bidvertiser.com/">malware problems with Bidvertiser</a> and sites using their ads <a href="http://www.google.com/support/forum/p/Webmasters/thread?tid=2351a1f26434b6ee&amp;hl=en">may  be blacklisted</a></p>
<p><span style="color: #888888;"><strong>May 30, 2010</strong></span></p>
<p style="padding-left: 30px;">[sophos.com] <a href="http://www.sophos.com/blogs/chetw/g/2010/05/27/phishing-alive-kicking/">Phishing &#8211; Alive and kicking</a> &#8211; hijacked DNS used by phishers</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/05/30/tweet-week-may-24-30-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweet Week: May 17-23, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/05/23/tweet-week-may-17-23-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/05/23/tweet-week-may-17-23-2010/#comments</comments>
		<pubDate>Sun, 23 May 2010 14:45:23 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[GoDaddy]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=630</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

May 17, 2010
Google Internet Stats &#8211; collection of the latest  industry facts and insights.
May 19, 2010
jnlcom.com&#8217;s adserver is infected with malware. If  you are running their ads the chances are your site is blacklisted by  Google.
May 22, [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-630"></span><br />
<span style="color: #888888;"><strong>May 17, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://www.google.co.uk/intl/en/landing/internetstats/">Google Internet Stats</a> &#8211; collection of the latest  industry facts and insights.</p>
<p><span style="color: #888888;"><strong>May 19, 2010</strong></span></p>
<p style="padding-left: 30px;">jnlcom.com&#8217;s adserver is infected with malware. If  you are running their ads the chances are your site is blacklisted by  Google.</p>
<p><span style="color: #888888;"><strong>May 22, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://tech.slashdot.org/story/10/05/22/1546215/Malware-on-Hijacked-Subdomains-a-New-Trend">Slashdot discussion</a> of my &#8220;<a href="http://blog.unmaskparasites.com/2010/05/22/malware-on-hijacked-subdomains-new-trend/">Malware on Hijacked  Subdomains, a New Trend?</a>&#8221; article &#8211; do you have anything to add?</p>
<p style="padding-left: 30px;">@<a rel="nofollow" href="http://twitter.com/nrathaus">nrathaus</a> At this  point none of the known rogue subdomains is blacklisted by Google. But  Norton <a href="http://safeweb.norton.com/report/show?name=lighthouseusa.net"> blocks whole domains</a></p>
<p style="padding-left: 30px;"><a href="https://www.godaddy.com/security/internet-security.aspx?isc=smtwsup">GoDaddy security tips</a> &#8211; account security,  anti-phishing, etc.</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/05/23/tweet-week-may-17-23-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweet Week: May 10-16, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/05/16/tweet-week-may-10-16-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/05/16/tweet-week-may-10-16-2010/#comments</comments>
		<pubDate>Sun, 16 May 2010 17:54:43 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[Drupal]]></category>
		<category><![CDATA[GoDaddy]]></category>
		<category><![CDATA[jarlsberg]]></category>
		<category><![CDATA[Moodle]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=623</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

May 10, 2010
Completed the Jarlsberg codelab from Google Code University.  Insightful. Found some alternative attack vectors.
May 11, 2010
[pcmech.com] Check If Your Website Has Been  Hijacked &#8211; about Unmask  Parasites
May 12, 2010
[h-online.com] XSS vulnerability fixed in Drupal  [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-623"></span><br />
<span style="color: #888888;"><strong>May 10, 2010</strong></span></p>
<p style="padding-left: 30px;">Completed the <a href="http://jarlsberg.appspot.com/">Jarlsberg codelab</a> from <a href="http://code.google.com/edu">Google Code University</a>.  Insightful. Found some alternative attack vectors.</p>
<p><span style="color: #888888;"><strong>May 11, 2010</strong></span></p>
<p style="padding-left: 30px;">[pcmech.com] <a href="http://www.pcmech.com/article/check-if-your-website-has-been-hijacked/">Check If Your Website Has Been  Hijacked</a> &#8211; about Unmask  Parasites</p>
<p><span style="color: #888888;"><strong>May 12, 2010</strong></span></p>
<p style="padding-left: 30px;">[h-online.com] <a href="http://www.h-online.com/security/news/item/XSS-vulnerability-fixed-in-Drupal-module-Update-998101.html">XSS vulnerability fixed in Drupal  module Context</a> &#8211; update if you  use it</p>
<p><span style="color: #888888;"><strong>May 15, 2010</strong></span></p>
<p style="padding-left: 30px;">RT @<a rel="nofollow" href="http://twitter.com/mattcutts">mattcutts</a>: Good  article at about the  <a href="http://smackdown.blogsblogsblogs.com/2010/05/13/hosting-with-godaddy-might-want-to-rethink-that-decision/">GoDaddy/WordPress hacking</a>. I fear it&#8217;ll get worse for people on lax  webhosts.</p>
<p style="padding-left: 30px;">Follow up on the <a href="http://smackdown.blogsblogsblogs.com/2010/05/14/godaddys-suggestion-for-the-cause-of-their-hacks-and-their-community-blog-can-you-smell-the-irony/">GoDaddy/WP security issue</a> by @<a rel="nofollow" href="http://twitter.com/mvandemar">mvandemar</a> &#8211; So who is using outdated WordPress?</p>
<p><span style="color: #888888;"><strong>May 16, 2010</strong></span></p>
<p style="padding-left: 30px;">see a lot of web spam on compromised Moodle  (e-learning) sites all over the world.</p>
<p style="padding-left: 30px;">[Moodle] Some examples: <a href="http://www.unmaskparasites.com/security-report/?page=moodle.ems-berufskolleg.de/c/9a7c-can-i-order-online-cialis.php">1</a> <a href="http://www.UnmaskParasites.com/security-report/?page=testwood.moodle.uk.net/c/0309b-buying-in-the-uk-levitra.php">2</a> <a href="http://www.unmaskparasites.com/security-report/?page=moodle.trinityhigh.com/c/4d65-buy-online-in-britain-nexium.php">3</a> (plus many many more) &#8211; check the redirects and the  highlighted keywords</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/05/16/tweet-week-may-10-16-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweet Week: May 3-9, 2010</title>
		<link>http://blog.unmaskparasites.com/2010/05/10/tweet-week-may-3-9-2010/</link>
		<comments>http://blog.unmaskparasites.com/2010/05/10/tweet-week-may-3-9-2010/#comments</comments>
		<pubDate>Mon, 10 May 2010 14:03:22 +0000</pubDate>
		<dc:creator>Denis</dc:creator>
				<category><![CDATA[Tweet Week]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[jarlsberg]]></category>
		<category><![CDATA[milestone]]></category>

		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=622</guid>
		<description><![CDATA[Selected short messages and links you might have missed if you don’t follow me on Twitter.

May 3, 2010
New Unmask Parasites testimonials &#8211; Thanks!  If you like Unmask  Parasites, consider writing your testimonial too.
May 4, 2010
[hackademix.net] Bug in Ubuntu 10.04 Crashing Your  Desktop via Firefox, NoScript 
[milestone] 100,000 suspicious web pages detected  [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">Selected short messages and links you might have missed if you don’t <a href="http://twitter.com/unmaskparasites">follow me</a> on Twitter.</span></em></p>
<p><span id="more-622"></span><br />
<span style="color: #888888;"><strong>May 3, 2010</strong></span></p>
<p style="padding-left: 30px;"><a href="http://blog.unmaskparasites.com/contact/unmask-parasites-testimonials/#comment-7242">New Unmask Parasites testimonials</a> &#8211; Thanks!  If you like Unmask  Parasites, consider <a href="http://blog.unmaskparasites.com/contact/unmask-parasites-testimonials/#respond">writing your testimonial</a> too.</p>
<p><span style="color: #888888;"><strong>May 4, 2010</strong></span></p>
<p style="padding-left: 30px;">[hackademix.net] <a href="http://hackademix.net/2010/05/04/bug-in-ubuntu-1004-crashing-your-desktop-via-firefox-noscript/">Bug in Ubuntu 10.04 Crashing Your  Desktop via Firefox, NoScript</a> <a rel="nofollow" href="http://bit.ly/9bwSLq" target="_blank"></a></p>
<p style="padding-left: 30px;">[milestone] <span style="color: #333333;"><strong>100,000</strong></span> suspicious web pages detected  by Unmask Parasites <a rel="nofollow" href="http://www.unmaskparasites.com/" target="_blank">http://www.UnmaskParasites.com/</a></p>
<p style="padding-left: 30px;">Google Code University: <a href="http://jarlsberg.appspot.com/">Web Application Exploits  and Defenses</a></p>
<p><span style="color: #888888;"><strong>May 6, 2010</strong></span></p>
<p style="padding-left: 30px;">Google <a href="http://googlewebmastercentral.blogspot.com/2010/05/call-for-webspam-reports-in-thai.html">calls for for webspam reports in Thai,  Indonesian, Romanian, Czech and Farsi</a> <a rel="nofollow" href="http://bit.ly/aUY0fA" target="_blank"></a></p>
<p><span style="color: #888888;"><strong>May 7, 2010</strong></span></p>
<p style="padding-left: 30px;">Updated my<a href="http://blog.unmaskparasites.com/2009/12/18/list-of-gumblar-zombie-urls/"> list of Gumblar Zombie URLs</a> <a rel="nofollow" href="http://bit.ly/8Lz2u4" target="_blank"></a> &#8211; now <span style="color: #333333;"><strong>725</strong></span> items</p>
<p>If you want more real-time experience, you can follow <a href="http://twitter.com/unmaskparasites">@UnmaskParasites</a> on Twitter.</p>
<p><span style="color: #888888;"><strong>Related posts:</strong></span></p>
<ul>
<li> <a href="http://blog.unmaskparasites.com/category/tweet-week/">Previous Tweet Weeks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.unmaskparasites.com/2010/05/10/tweet-week-may-3-9-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
