<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Is sp2fucked shut down or not?&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Is-sp2fucked-shut-down-or-not-11904374</link>
<description></description>
<language>en</language>
<pubDate>Tue, 18 Jun 2013 20:46:50 EDT</pubDate>
<lastBuildDate>Tue, 18 Jun 2013 20:46:50 EDT</lastBuildDate>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11945083</link>
<description><![CDATA[anon posted : About 90% of the browsing world<br>&raquo;<A HREF="http://regfreeze.freeserverhost.com/" >regfreeze.freeserverhost.com/</A> ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11945083</guid>
<pubDate>Wed, 24 Nov 2004 04:43:50 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11935925</link>
<description><![CDATA[TeMerc posted : Little bit more on CNET:<br>&raquo;<A HREF="http://news.com.com/Attackers+strike+using+Web+ads/2100-7349_3-5463323.html?tag=nl" >news.com.com/Attackers+strike+us&middot;&middot;&middot;l?tag=nl</A><br><SMALL>--<br>Remember............You can NEVER be OVERPROTECTED!!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11935925</guid>
<pubDate>Tue, 23 Nov 2004 02:52:53 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11934071</link>
<description><![CDATA[Indy Sabre posted :  <div class="bquote"><SMALL>said by <a href="/profile/890688" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=890688');">TerryMiller</a>:</SMALL><BR><BR>As long as the user doesn't have permission to install applications. </DIV>Terry, thanks for the answer, that is what I thought. <br><br>BTW, I made the jump to installing a HOSTS file. Thanks for your helpful answers!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11934071</guid>
<pubDate>Mon, 22 Nov 2004 22:21:33 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11933835</link>
<description><![CDATA[TerryMiller posted :  <div class="bquote"><SMALL>said by <a href="/profile/882570" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=882570');">Indy Sabre</a>:</SMALL><br><br>Would surfing in IE on a limited user account in W2000 likely prevent damage from these exploits?<br> </DIV>As long as the user doesn't have permission to install applications.<br><SMALL>--<br> <A HREF="http://millfam.org"> My family site</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11933835</guid>
<pubDate>Mon, 22 Nov 2004 22:00:57 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11933165</link>
<description><![CDATA[Indy Sabre posted : Would surfing in IE on a limited user account in W2000 likely prevent damage from these exploits?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11933165</guid>
<pubDate>Mon, 22 Nov 2004 20:59:10 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11933004</link>
<description><![CDATA[jig posted : this is at least partially done with some of the content filtering boxes out there. what i've seen is that they contact an offsite service that checks the web address against a list and returns a 'grade' that labels the site as childsafe, adult, hate, etc. if the device is set to allow that subset, then the client can connect directly. <br><br>problem is, of course, that only the most recent requests are cached. so if the offsite service goes down or is otherwise unreachable, the protection isn't there anymore. and i don't think most of the offsite services would allow their entire list to be locally cached..<br><br>and i don't know how these offsite services deal with any kind of litgation over whether or not a site is labeled correctly. <br><br>i suppose it would be interesting if a hardware manufacturer sold a product that had some general ability to upload what is in effect a hosts file. general enough so that they couldn't get sued over someones site getting put into one of the various lists and uploaded to the router. and upgradeable memory. that would be enough, but the next step would be to have various sets of lists that could be applied to subnets in various combinations.<br><br>the more i think about it though, most of the appliances that have even the beginning of the right kinds of resources already cost as much as the cheapest dell, which has more than enough umph to do all the above AND much more.<br><br>still, i'd buy an appliance that did everything above for $300 or less. appliance = something without moving parts (no fan or hard drive).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11933004</guid>
<pubDate>Mon, 22 Nov 2004 20:44:22 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11932168</link>
<description><![CDATA[claudeo posted : I'd really like to find a single purpose, inexpensive appliance that could subscribe to a blacklist and automatically block access from my home network (maybe sit between the NAT/router and the modem). I know I can build one using Linux, but I don't have the time. Also I don't have time to learn how to make the ipchain or similar rules dynamically updatable from a "plain" blacklist updated continuously from a trusted source. <br><br>Nothing smart, nothing elegant,no smart rules, pure brute force. Simpler than messing around with hosts files (which BTW doesn't work well with Win2K where a big hosts file just seems to kill performance). And yes, I know, woe to whoever is accidentally listed--this is why it has to be updating continuously. It should also update continuously so that phishing sites can be listed as soon as they are detected, not days or weeks after they've been taken down.<br><br>I bet by now there are hundreds of thousands of people and small companies who would gladly pay $50-$100 for such a gadget, along with a $1/month subscription to the update service. Hint hint.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11932168</guid>
<pubDate>Mon, 22 Nov 2004 19:32:28 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11931482</link>
<description><![CDATA[eburger68 posted : Hi All:<br><br>An article in appeared in The Register today about this exploit:<br><br>http://www.theregister.co.uk/2004/11/22/apache_hijack_serves_iframe_exploit/<br><br>Best,<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11931482</guid>
<pubDate>Mon, 22 Nov 2004 18:27:16 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11929176</link>
<description><![CDATA[bobince posted : > Is this being caused by unscrupulous companies intentionaly serving these exploits [...] Or is it unscrupulous individuals that are infecting blameless companies<br><br>In the case of the sp2f*cked/sp2admin/etc. exploits, seems to be "both". Some 'affiliates' are putting the exploits on their own dodgy properties, whilst some are apparently r00ting other webservers to inject the iframes.<br><br>culverj:<br><br>> Most/all of the domains originally identified as exploiting this vulnerability have been taken down.<br><br>Absolutely not. Some of the most widely-publicised URLs have been removed, and a bogus 'deactivated' message put up on the main sp2f*cked root page, but most of the other URLs we've seen used by these exploits are still very much active.<br><br>Similar sites (CWS havens) have been known for months and have not been taken down. We are dealing with rogue ISPs here.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11929176</guid>
<pubDate>Mon, 22 Nov 2004 14:24:19 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11929101</link>
<description><![CDATA[Bubba posted :   <div class="bquote"><SMALL>said by <a href="/profile/659356" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=659356');">ctrip</a>:</SMALL><BR><BR><BR>Could someone answer a simple question for me? Is this being caused by unscrupulous companies intentionaly serving these exploits from their webservers to the unwary visitors?</DIV>If I'm understanding your question as it relates to the beginning of this thread....I believe the answer is in Eric's first post ?<br><br> <div class="bquote"><SMALL>said by  eburger68 <A HREF="/useremail/u/378696"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A><br>It appears that a group of hackers (perhaps even a criminal gang) is hacking web servers all over the Net and installing root kits that dynamically inject code into the pages served from the compromised web servers. The injected code effectively serves as a "front door" to a number of different pages at these domains:</DIV>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11929101</guid>
<pubDate>Mon, 22 Nov 2004 14:13:39 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11929011</link>
<description><![CDATA[SolarPup posted : Whoa... he's the guy that hosts my colocate... wham bang!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11929011</guid>
<pubDate>Mon, 22 Nov 2004 14:01:18 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928897</link>
<description><![CDATA[ctrip posted : Could someone answer a simple question for me? Is this being caused by unscrupulous companies intentionaly serving these exploits from their webservers to the unwary visitors?<br><br>Or is it unscrupulous individuals that are infecting blameless companies who happen to be running Apache webservers?<br><SMALL>--<br>I actually voted for John Kerry...<br><br>before I voted against him.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928897</guid>
<pubDate>Mon, 22 Nov 2004 13:45:16 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928806</link>
<description><![CDATA[suzi5 posted : To find out where the domain is hosted and the pages are being served, the nameserver info is needed.<br><br>Name:    ns1.sp2fucked.biz<br>Address:  69.50.168.146<br><br>Name:    ns2.sp2fucked.biz<br>Address:  69.50.168.147<br><br>The IP lookup for those nameservers shows they are hosted by this company:<br><br>OrgName:    Atrivo <br>OrgID:      ATRIV<br>Address:    200 Paul Avenue<br>City:       San Francisco<br>StateProv:  CA<br>PostalCode: 94124<br>Country:    US<br><br>NetRange:   <B>69.50.160.0 - 69.50.191.255</B> <br>CIDR:       69.50.160.0/19 <br>NetName:    ATRIVOTECHNOLOGIES<br>NetHandle:  NET-69-50-160-0-1<br>Parent:     NET-69-0-0-0-0<br>NetType:    Direct Allocation<br>NameServer: MAIL.ATRIVO.COM<br>NameServer: PAVEL.ATRIVO.COM<br>Comment:    <br>Comment:            ## Comments listed here will appear in ARIN's WHOIS database.<br>RegDate:    2003-06-04<br>Updated:    2003-08-21<br><br>NOCHandle: EKA4-ARIN<br>NOCName:   Kacperski, Emil <br>NOCPhone:  +1-925-550-3947<br>NOCEmail:  abuse@atrivo.com <br><br><B>OrgAbuseHandle: ABUSE658-ARIN<br>OrgAbuseName:   Abuse Department <br>OrgAbusePhone:  +1-925-550-3947<br>OrgAbuseEmail:  abuse@atrivo.com</B><br><br>OrgNOCHandle: NETWO601-ARIN<br>OrgNOCName:   Network Operations <br>OrgNOCPhone:  +1-925-550-3947<br>OrgNOCEmail:  noc@atrivo.com<br><br>OrgTechHandle: EKA4-ARIN<br>OrgTechName:   Kacperski, Emil <br>OrgTechPhone:  +1-925-550-3947<br>OrgTechEmail:  abuse@atrivo.com<br><br>A Google search for Atrivo and Atrivotechnologies does *not* put the company in a good light:<br><br>&raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=UTF-8&q=Atrivo" >www.google.com/search?sourceid=n&middot;&middot;&middot;q=Atrivo</A><br><br>&raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=UTF-8&q=Atrivotechnologies" >www.google.com/search?sourceid=n&middot;&middot;&middot;nologies</A><br><br>Atrivotechnologies is listed on a number of spam block lists, among other things.  <br><br>The owner, Emil Kacperski, is reportedly a 26 year old in California.  He posts at &raquo;<A HREF="http://webhostingtalk.com/" >webhostingtalk.com/</A> forums using the name "goose".  (The forum seems to be down at the moment).  From what I read there, he and Atrivo are well regarded on that forum, but Google search results for the name Emil Kacperski paint a different picture of him and it's not pretty.<br><br>&raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=UTF-8&q=%22emil+Kacperski%22" >www.google.com/search?sourceid=n&middot;&middot;&middot;erski%22</A><br><br>Emails to the abuse department at Atrivo might be in order.<br><br>(edited to correct grammar)<br><SMALL>--<br>aka Suzi, Spyware Warrior</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928806</guid>
<pubDate>Mon, 22 Nov 2004 13:35:08 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928799</link>
<description><![CDATA[paranoidxe posted : Internet Explorer has simply become a browser that has more holes than a cheese grater. My freakin mother that does nothing more than browse the internet and read her email (doesn't download anything) has become infected by 4 different spyware programs using exploits from IE. This is EVEN with the latest patches from microsoft.<br><br>The real failure here is Microsoft, they have let everyone down with lack of security in their internet explorer program. Maybe it is high time they get off their asses and sandbox internet explorer from the windows interface, I knew eventually the intergation of IE would be a HUGE mistake.<br><br>I am sick of the argument for internet explorer fans, it can BE secure. Why would I waste my time trying to configure internet explorer to be "secure" through trial and error, when I can switch to a healthy alternative like Kmeleon, Mozilla, Firefox, Opera, etc. that are secure out of the box.<br><br>The other argument, Internet Explorer is FASTER! Sure it might be slightly faster, but the time wasted clearing the scumware off your machine through the holes in it is much more time consuming/difficult than waiting 1 or 2 seconds longer for a page to load. Since when does SPEED rule over SECURITY? come on now.<br><br>These are exploits that Microsoft seems to have refused to fix, because a lot of these exploits have been around for awhile now. It seems like to me that microsoft takes longer and longer to release patches for internet explorer when they should be putting them out much quicker.<br><SMALL>--<br>- paranoidxe (textsource.org)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928799</guid>
<pubDate>Mon, 22 Nov 2004 13:34:07 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928387</link>
<description><![CDATA[Dirtyping posted : Dammit! Now I find this thread. I am still completely Windows 2000 patched and I ended up getting infected.  The only day this week I used IE I got infected. (I always use Firefox)<br><br>&raquo;<A HREF="/forum/remark,11925878~mode=flat">IDS CPU/Memory usage</A><br><br>That will teach me not to ever run IE again or forget to update my Blackice signatures.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928387</guid>
<pubDate>Mon, 22 Nov 2004 12:40:36 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928298</link>
<description><![CDATA[TeMerc posted : Well, it seems CNET picked up the article from the Register:<br>&raquo;<A HREF="http://news.com.com/2001-9373_3-0.html?tag=nefd.xtra" >news.com.com/2001-9373_3-0.html?&middot;&middot;&middot;efd.xtra</A><br><br>Maybe now it will get even more ink.<br><br>Bump:D<br><SMALL>--<br>Remember............You can NEVER be OVERPROTECTED!!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11928298</guid>
<pubDate>Mon, 22 Nov 2004 12:29:46 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11923278</link>
<description><![CDATA[Doctor Four posted : It is getting worse out there, and has gotten so since the<br>first RPC worms started coming out. Now an unpatched system<br>can get infected in less than a minute after being connected<br>to the Internet.<br><br>As for the Reg's adserver being infected by Bofra, I was <br>on their site yesterday during the time frame they mentioned,<br>but since Falk-AG's URLs are all in my hosts file, the site<br>was prevented from fetching the infected code. And I was<br>running Mozilla anyway.<br><br>But I think I'll be very careful about what sites I visit<br>from my workstation, which while protected, may not offer<br>the same degree as Mozilla (it uses IE w/no popup blocker.)<br><SMALL>--<br>"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11923278</guid>
<pubDate>Sun, 21 Nov 2004 19:56:01 EDT</pubDate>
</item>

<item>
<title>Bofra exploit hits The Register</title>
<link>http://www.dslreports.com/forum/Bofra-exploit-hits-The-Register-11923127</link>
<description><![CDATA[groundling posted :  21st November 2004<br>Important notice Early on Saturday morning some banner advertising served for The Register by third party ad serving company Falk AG became infected with the Bofra/IFrame exploit. The Register suspended ad serving by this company on discovery of the problem.<br><br>If you may have visited The Register between 6am and 12.30pm GMT on Saturday, Nov 20 using any Windows platform bar XP SP2 we strongly advise you to check your machine with up to date anti-virus software<br><br>http://www.theregister.co.uk/2004/11/21/register_adserver_attack/]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Bofra-exploit-hits-The-Register-11923127</guid>
<pubDate>Sun, 21 Nov 2004 19:37:46 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11922530</link>
<description><![CDATA[SolarPup posted : Interesting Whois Output:<br><br>Request: sp2fucked.biz<br>whois server for *.biz is whois.neulevel.biz ...<br>connected to whois.neulevel.biz [209.173.53.169:43] ...<br>Domain Name:                                 SP2FUCKED.BIZ<br>Domain ID:                                   D7921805-BIZ<br>Sponsoring Registrar:                        DIRECT INFORMATION PVT. LTD., (D.<br>A. DIRECTI.COM)<br>Sponsoring Registrar IANA ID:                303<br>Domain Status:                               clientDeleteProhibited<br>Domain Status:                               clientTransferProhibited<br>Domain Status:                               clientUpdateProhibited<br>Registrant ID:                               DI_937571<br>Registrant Name:                             John Miller<br>Registrant Organization:                     Liber Inc<br>Registrant Address1:                         135/2 Washington str<br>Registrant City:                             Limasson<br>Registrant Postal Code:                      06432<br>Registrant Country:                          Cyprus<br>Registrant Country Code:                     CY<br>Registrant Phone Number:                     +944.8735673<br>Registrant Email:                            support@coolsearch.biz<br>Administrative Contact ID:                   DI_937571<br>Administrative Contact Name:                 John Miller<br>Administrative Contact Organization:         Liber Inc<br>Administrative Contact Address1:             135/2 Washington str<br>Administrative Contact City:                 Limasson<br>Administrative Contact Postal Code:          06432<br>Administrative Contact Country:              Cyprus<br>Administrative Contact Country Code:         CY<br>Administrative Contact Phone Number:         +944.8735673<br>Administrative Contact Email:                support@coolsearch.biz<br>Billing Contact ID:                          DI_937571<br>Billing Contact Name:                        John Miller<br>Billing Contact Organization:                Liber Inc<br>Billing Contact Address1:                    135/2 Washington str<br>Billing Contact City:                        Limasson<br>Billing Contact Postal Code:                 06432<br>Billing Contact Country:                     Cyprus<br>Billing Contact Country Code:                CY<br>Billing Contact Phone Number:                +944.8735673<br>Billing Contact Email:                       support@coolsearch.biz<br>Technical Contact ID:                        DI_937571<br>Technical Contact Name:                      John Miller<br>Technical Contact Organization:              Liber Inc<br>Technical Contact Address1:                  135/2 Washington str<br>Technical Contact City:                      Limasson<br>Technical Contact Postal Code:               06432<br>Technical Contact Country:                   Cyprus<br>Technical Contact Country Code:              CY<br>Technical Contact Phone Number:              +944.8735673<br>Technical Contact Email:                     support@coolsearch.biz<br>Name Server:                                 NS1.SP2FUCKED.BIZ<br>Name Server:                                 NS2.SP2FUCKED.BIZ<br>Created by Registrar:                        DIRECT INFORMATION PVT. LTD., (D.<br>A. DIRECTI.COM)<br>Last Updated by Registrar:                   DIRECT INFORMATION PVT. LTD., (D.<br>A. DIRECTI.COM)<br>Domain Registration Date:                    Sat Oct 09 17:54:48 GMT 2004<br>Domain Expiration Date:                      Sat Oct 08 23:59:59 GMT 2005<br>Domain Last Updated Date:                    Tue Nov 16 23:03:13 GMT 2004<br><br>>>>> Whois database was last updated on: Sun Nov 21 23:24:33 GMT 2004 <br><br>Here's what Symantec speaks of it:<br><br>Scan type:  Realtime Protection Scan<br>Event:  Virus Found!<br>Virus name: MHTMLRedir.Exploit<br>File:  C:\Documents and Settings\userid.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\VR1NRTW4\adv65[1].htm<br>Location:  Quarantine<br>Computer:  PEGASUS<br>User:  casey<br>Action taken:  Clean failed : Quarantine succeeded : Access denied<br>Date found: Sun Nov 21 16:21:54 2004]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11922530</guid>
<pubDate>Sun, 21 Nov 2004 18:25:29 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921860</link>
<description><![CDATA[Bobby_Peru posted : Hi  BillBigus <A HREF="/useremail/u/890049"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, well that is not good at all! Unfortunately, I do not know.  The prevention I was addressing was on the surfing end, not the web server itself. Hopefully someone will come along that is able to address this, short of trying to simply turn off all 3ed Party Objects served to a site's users until this calms down - which actually might be the safest route, but which might entail lost revenue and contractual complications on a commercial site.<br><SMALL>--<br>**~~<A HREF="/faq/8428">Infected/Hijacked? FAQ</A>~~~<A HREF="/faq/8463">Protect/Secure Your Box/Data FAQ</A>~~~<A HREF="/faq/security">Security Forum FAQs</A>~~**</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921860</guid>
<pubDate>Sun, 21 Nov 2004 16:38:33 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921788</link>
<description><![CDATA[MagMan posted : Nice info Thanks;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921788</guid>
<pubDate>Sun, 21 Nov 2004 16:29:55 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921742</link>
<description><![CDATA[Bobby_Peru posted :  <div class="bquote"><SMALL>said by <a href="/profile/229657" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=229657');">Formeister</a>:</SMALL><br><br> I couldn't get on to any of those sites and I was wondering if it's just because I use the latest Hosts file from this forum </DIV> From earlier posts in this thread, it appears that  hpguru <A HREF="/useremail/u/615773"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s/IE-SYPAD would stop you from getting on the sites, even if they were still active.<br><SMALL>--<br>**~~<A HREF="/faq/8428">Infected/Hijacked? FAQ</A>~~~<A HREF="/faq/8463">Protect/Secure Your Box/Data FAQ</A>~~~<A HREF="/faq/security">Security Forum FAQs</A>~~**</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921742</guid>
<pubDate>Sun, 21 Nov 2004 16:23:13 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921589</link>
<description><![CDATA[Mei Guo Ren posted : Most/all of the domains originally identified as exploiting this vulnerability have been taken down.  I think if you look around there are some sites that demonstrate the IFRAME buffer overflow vulnerability without actually hosing your system.<br><br>As for the great unwashed masses, I'm cleaning 4-5 PCs a month for friends and family.  A friend who used to be in the PC OEM business (aka, Mom & Pop) now makes his living cleaning up Windows computers, and he's working six days a week, 12 hours a day.  Better money than he ever made as a screwdriver shop.<br><br>The average user doesn't have Windows autoupdate turned on.  They don't on AV software, or they do (only because it came from the OEM with a trial subscription) but they let the subscription lapse and don't even realize they are surfing naked.  They have been conditioned by IE to believe that annoying popups are "normal."  Their kids and spouses are using the computer for God knows what-- especially for AIM, where "autodownload files sent to me" is a default setting!  <br><br>Back in the good old days, the threat to your computer was sneakerware-- stuff on floppies and CDs.  Today, it's any website you visit, anyone on your "buddy" list, anyone who gets a mailer virus and has one of your email addresses in their address book, and whether there are unpatched OS or IE vulnerabilities already being used by malware.<br><br>As recently as two years ago, I didn't have any AV software.  I used a software firewall when I had dial up, and still use a router/fw with broadband.  And I never had a virus infection on any of the five PCs here, all but one running windows (my main WS has run Linux since 1998).  I know today that most computers are hosed to one extent or another by malware--and I'm not even counting tracking cookies.  If they are on the net, without a firewall, OS patches, and antivirus, I would bet that anyone with broadband is hosed, and even most dialup users are hosed.  With threats like the IFRAMEs exploit, even people with AV software, anti-spyware utilities, a firewall, and the system fully patched can get hosed just by visiting a website with banner ads.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921589</guid>
<pubDate>Sun, 21 Nov 2004 16:06:09 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921523</link>
<description><![CDATA[ironwalker posted : Thanx...missed it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921523</guid>
<pubDate>Sun, 21 Nov 2004 15:57:04 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921431</link>
<description><![CDATA[Formeister posted : I find this interesting and feel sorry for all non-geeks who put out good money to buy a computer and have it ruined because they lack the knowledge to combat these intrusions.  That said, does anyone have any links to other sites that actually will do what the author has shown?  On my computer, XP pro, patched but w/o SP 1 or 2 and no active firewall besides Windows, I couldn't get on to any of those sites and I was wondering if it's just because I use the latest Hosts file from this forum and Opera instead of IE or if it's because I don't hit the right porn sites.  Any way I'd like to try it in IE and see what happens (I'm a glutton for punishment).:D<br><br>Forgot to say to IM links rather than post. Tks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921431</guid>
<pubDate>Sun, 21 Nov 2004 15:42:15 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921057</link>
<description><![CDATA[TheJoker posted :  <div class="bquote"><SMALL>said by <a href="/profile/465004" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=465004');">ironwalker</a>:</SMALL><br><br>Does IESpyad block these?<br> </DIV>Already posted in the thread.  IE-SYPAD does indeed block all the sites listed in Eric's first post in this thread. To check to see if IE-SPYAD blocks a specific site, just open ie-ads.reg in Notepad, hit CTRL+F, and paste in the name of the site you want to check for.<br><SMALL>--<br>TheJoker</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11921057</guid>
<pubDate>Sun, 21 Nov 2004 14:38:11 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11920674</link>
<description><![CDATA[ironwalker posted : Someone have a sygate dat file People can import to block most of these sites?<br>Does IESpyad block these?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11920674</guid>
<pubDate>Sun, 21 Nov 2004 13:40:56 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11920507</link>
<description><![CDATA[BillBigus posted : OK <br>My server was done in the exact way that you describe.<br>However, the server management company insist that it was done by an individual in Texas, who just 'Happened" to guess my password...<br>First time !<br>Yeah right, I believe that (NOT)<br><br>so if I am correct, and my server people are lying to me and it had been hacked... <br>What would I be looking for to prove it, aside from the iframes injected into the pages themselves ? And also... What do i need to remove to stop it re-occurring ? Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11920507</guid>
<pubDate>Sun, 21 Nov 2004 13:17:09 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919732</link>
<description><![CDATA[Bobby_Peru posted :  <div class="bquote"><SMALL>said by <a href="/profile/1069643" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1069643');">Joe Stewart</a>:</SMALL><br><br>I've written up some more detail of some of the banner-ad IFRAME exploiters:<br><br>http://www.lurhq.com/iframeads.html<br><br>One of the banner services being abused to infect users is oas-central.realmedia.com.</DIV>Thanks Joe.  This sure seems to me to be a real solid reason to BLOCK the calling and downloading of such 3ed Party Objects!<br><SMALL>--<br>**~~<A HREF="/faq/8428">Infected/Hijacked? FAQ</A>~~~<A HREF="/faq/8463">Protect/Secure Your Box/Data FAQ</A>~~~<A HREF="/faq/security">Security Forum FAQs</A>~~**</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919732</guid>
<pubDate>Sun, 21 Nov 2004 11:11:03 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919694</link>
<description><![CDATA[Joe Stewart posted : I've written up some more detail of some of the banner-ad IFRAME exploiters:<br><br>http://www.lurhq.com/iframeads.html<br><br>One of the banner services being abused to infect users is oas-central.realmedia.com.<br><br>-Joe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919694</guid>
<pubDate>Sun, 21 Nov 2004 11:04:05 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919676</link>
<description><![CDATA[TA63 posted : But be careful at majorgeeks:<br>&raquo;<A HREF="/forum/remark,11724035~mode=flat">crappy ads at majorgeeks.com</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919676</guid>
<pubDate>Sun, 21 Nov 2004 10:59:40 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919650</link>
<description><![CDATA[PentiumIII posted : Alternatively, people with SP1a can use this temporarily fix from Maxthon to patch the IFRAME vulnerability until the official patch is released by Microsoft http://www.majorgeeks.com/download.php?det=4412<br>It can be uninstall as well for those who are worry about conflicts with the future official patch.  It has worked flawlessly for myself so far to date.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919650</guid>
<pubDate>Sun, 21 Nov 2004 10:55:20 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919587</link>
<description><![CDATA[Bobby_Peru posted : Hi  KyeU <A HREF="/useremail/u/923463"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, would you post just the filters applicable to this exploit (Reg-Ex is ok, if existent), since AdBlock (WebWasher...) users might want to Add them to their existing filter set?  I have already added  b00gle.info    coolsearch.biz    newiframe.biz   pizdato.biz .  While these folks may presently just be attempting to exploit an IE vulnerability, any known areas were they operate might should be avoided, even by FF users.  Thanks!<br><SMALL>--<br>**~~<A HREF="/faq/8428">Infected/Hijacked? FAQ</A>~~~<A HREF="/faq/8463">Protect/Secure Your Box/Data FAQ</A>~~~<A HREF="/faq/security">Security Forum FAQs</A>~~**</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919587</guid>
<pubDate>Sun, 21 Nov 2004 10:43:59 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919076</link>
<description><![CDATA[illukka posted : just to bump :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11919076</guid>
<pubDate>Sun, 21 Nov 2004 08:19:56 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918625</link>
<description><![CDATA[Mele20 posted : I read that SANS diary earlier today. I'm still not going to install SP2. Microsoft will issue a patch for SP1. In the meantime, anyone with SP1 should use another browser. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918625</guid>
<pubDate>Sun, 21 Nov 2004 04:10:59 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918597</link>
<description><![CDATA[suzi5 posted :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Microsoft fully supports SP1 and will issue a patch for what ever exploit this is I'm sure. It sounds to me like you have to be rather naive to get this infection. You have to use IE (only the naive do that these days), and you have to do a bunch of suspicious clicks? That is what the naive do.<HR></BLOCKQUOTE><br><br>Well, I think most of us were naive at one time.  Being naive or not has nothing to do with it.  This is a dangerous exploit.  In fact, there has been some speculation that it's a prelude to a major distributed denial of service attack.  SANS is reporting on it.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Spy/Adware via Browser Vulnerabilities and Compromised Web Servers <br><br>Steve Friedl pointed us to the BroadbandReports discussion that documents a series of web server compromises that deliver spy/adware to victims that visit compromised sites. The victims are running a vulnerable browser. The information is still preliminary, but there are indications that the attackers are using an IFRAME vulnerability in Internet Explorer to deliver the payload. The web servers hosting the malicious code seem to be running Apache. <br><br>The BroadbandReports discussion of this incident:<br>http://www.broadbandreports.com/forum/remark,11904374 <br><br>A post to the Full-Disclosure list that may be related to this incident, referencing IFRAME and Apache (this link was posted on the BroadbandReports forum):<br>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/27857 <br><br>Information about the recent IFRAME vulnerability (no patch available at the moment; Windows XP SP2 systems not affected):<br>http://secunia.com/advisories/12959 <br><br>We don't have much information regarding this attack pattern to determine its scope. We'd love to hear from you if you can share with us logs, malware samples, or observations relevant to this incident. If server compromises are wide-spread, this incident is reminiscent of attacks on Web servers that distributed the Download.Ject trojan in June.<HR></BLOCKQUOTE><br><br>And the updates on the IFRAME vulnerabilities:<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Just to refresh everyone on the details. On October 24, a vulnerability was discovered in the IFRAME tags of Internet Explorer 6.0 affecting all Windows platforms except Windows XP SP2. This vulnerability can be exploited by going to a web-site that has malicious code. Currently, some high profile sites with banner ads are linking to servers that have the exploit and malicious code.<HR></BLOCKQUOTE><br><br>I traced the file which set off the exploit from one web page down through multiple nested IFRAMES embedded in web page on a forum.  <br><br>It also notes that machines with XP SP 2 are NOT vulnerable.  I've installed SP 2 on both my XP machines with no problems whatsoever.  <br><SMALL>--<br>aka Suzi, Spyware Warrior</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918597</guid>
<pubDate>Sun, 21 Nov 2004 03:58:24 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918511</link>
<description><![CDATA[Jeremy341 posted :  <div class="bquote"><SMALL>said by <a href="/profile/403861" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=403861');">Mele20</a>:</SMALL><br><br>you couldn't pay me to upgrade a Dell.</DIV>Well of the computers I have personally upgraded to SP2, 10 of them have been Dells.  I maintain that if you know what you're doing, the process will go well.  You will not convince me that's untrue, because I have never done a bad SP2 install.<br><SMALL>--<br>I do <B>not</B> trust Firefox.  Spread anything besides that horrid piece of crap.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918511</guid>
<pubDate>Sun, 21 Nov 2004 03:24:07 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918499</link>
<description><![CDATA[Mele20 posted :  <div class="bquote"><SMALL>said by <a href="/profile/126335" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=126335');">Jeremy341</a>:</SMALL><br><br> <div class="bquote"><SMALL>said by <a href="/profile/403861" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=403861');">Mele20</a>:</SMALL><br><br>I am not at all convinced that I need to install SP2 with all its headaches.</DIV>If you haven't installed it, how can you <B>know</B> it will cause headaches?  I have installed SP2 on many computers, and have never had a problem.<br> </DIV>Have you been following  Libra <A HREF="/useremail/u/854295"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> threads? We both have Dell Dimensions (I have the 8300 she has the 8400). After helping her for some time now, you couldn't pay me to upgrade a Dell. ;) Dell told her that upgrading her brand new 8400 Dimension to SP2 is what wrecked her computer. She has had a huge mess ever since. Dell took her back to SP1 and she has had problem after problem. Microsoft and Dell together can't even figure it all out.<br><br>Additionally, I have a scanner that cannot upgrade to SP2. It is using 98SE software on SP1a but that won't work on SP2. <br><br>Microsoft fully supports SP1 and will issue a patch for what ever exploit this is I'm sure. It sounds to me like you have to be rather naive to get this infection. You have to use IE (only the naive do that these days), and you have to do a bunch of suspicious clicks? That is what the naive do.<br><br> ctrip <A HREF="/useremail/u/659356"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> Of course XP Pro SP1 can be fully patched. I have all the patches and Microsoft supports SP1 for two more years and I will continue to get all patches. So don't say SP1 cannot be fully patched. That will be the case ONLY after Microsoft ceases supporting it. By that time I will either install SP2 (if I have not already done so) or have Longhorn. I have never said I will never install SP2. But I see no need to do so now and I would prefer to wait and install Longhorn instead (assuming Longhorn will be compatible with this hardware). If and when I decide SP2 is necessary then I will install it. I don't believe it is necessary at this time and this IE exploit doesn't convince me.<br><SMALL>--<br>The first and foremost function of our jurors is to protect private citizens from a tyrannical and intrusive government...Jurors are the last line of defense for liberty. Thomas Jefferson 1789</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918499</guid>
<pubDate>Sun, 21 Nov 2004 03:19:36 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918467</link>
<description><![CDATA[claudeo posted : The other thing is, teach anyone you support to use Alt-F4 on the keyboard rather than clicking anything on the window. I got one of those a few weeks back on which I looked at the source. Sure enough, the "Continue" and "No thanks" button were linking to the exact same thing. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918467</guid>
<pubDate>Sun, 21 Nov 2004 03:10:45 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918385</link>
<description><![CDATA[toddbs98 posted : Ok if a fully patched XP box isn't effected then this really isn't an exploit is it if the problems been fixed?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918385</guid>
<pubDate>Sun, 21 Nov 2004 02:45:51 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918167</link>
<description><![CDATA[KyeU posted : I've written some Proxomitron filters to remove the danger from "sp2f***ed.biz"<br><br>These are filters included in my "Browser Security Pack".<br>I've uploaded v4.25 to my site and the Prox-List Y! Group.<br><br>&raquo;<A HREF="http://www.kye-u.com/proxo/forums/index.php?showtopic=131&st=210&#entry3104" >www.kye-u.com/proxo/forums/index&middot;&middot;&middot;ntry3104</A><br>&raquo;<A HREF="http://www.kye-u.com/proxo/downloads.php?id=cfgpacks" >www.kye-u.com/proxo/downloads.ph&middot;&middot;&middot;cfgpacks</A><br>&raquo;<A HREF="http://groups.yahoo.com/group/prox-list/message/20178" >groups.yahoo.com/group/prox-list&middot;&middot;&middot;ge/20178</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11918167</guid>
<pubDate>Sun, 21 Nov 2004 01:56:57 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11917789</link>
<description><![CDATA[danball1976 posted : It happens to be affecting more websites than are listed.  At least two websites I regularly visit have this stealth attempting to install the stuff listed below.<br><br>Whats worse is that when it attempts to download, it will first put its own little page telling you that you must download it in order to view the website.<br><br>I did it once, but luckily, I have ZoneAlarm and told it to block access to whatever attempts to access the internet.  Also, I fought the download and deleted things that kept being downloaded.  When that was all over, I ran adaware, and deleted whatever else there was to delete, and then searched the registry to delete any more things.<br><br>The only thing to do is tell Internet Explorer to NOT download items that are from the company "CLICK HERE TO CONTINUE" and IE will block it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11917789</guid>
<pubDate>Sun, 21 Nov 2004 00:35:36 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11916533</link>
<description><![CDATA[ctrip posted :  <div class="bquote"><SMALL>said by <a href="/profile/403861" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=403861');">Mele20</a>:</SMALL><br><br> I haven't seen anyone say that SP1a (fully patched) with Proxo (latest JD5000 alpha extra/advanced filters) gets infected. So, I am not at all convinced that I need to install SP2 with all its headaches.<br> </DIV>SP1a cannot be fully patched because a fully patched XP machine would be SP2. But I wish you good luck in your daring and determined experiment of never updating your XP machine to protect yourself from exploits and vulnerabilities as they are discovered.<br><SMALL>--<br>I actually voted for John Kerry...before I voted against him.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11916533</guid>
<pubDate>Sat, 20 Nov 2004 21:35:10 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11916459</link>
<description><![CDATA[Jeremy341 posted :  <div class="bquote"><SMALL>said by <a href="/profile/403861" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=403861');">Mele20</a>:</SMALL><br><br>I am not at all convinced that I need to install SP2 with all its headaches.</DIV>If you haven't installed it, how can you <B>know</B> it will cause headaches?  I have installed SP2 on many computers, and have never had a problem.<br><SMALL>--<br>I do <B>not</B> trust Firefox.  Spread anything besides that horrid piece of crap.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11916459</guid>
<pubDate>Sat, 20 Nov 2004 21:24:27 EDT</pubDate>
</item>

<item>
<title>Re: video recording method</title>
<link>http://www.dslreports.com/forum/Re-video-recording-method-11916449</link>
<description><![CDATA[jig posted :  <div class="bquote"><SMALL>said by Ben Edelman:</SMALL><BR><BR>I use Windows Media Encoder, free from &raquo;<A HREF="http://www.microsoft.com/windowsmedia" >www.microsoft.com/windowsmedia</A> .  It generally does a good job.  Sometimes my test machine gets so badly infected that the encoder crashes, though.  I doubt that MS ever tested the encoder under such conditions, or designed it to cope with such conditions.<br> </DIV>thans much, it works really well, at least on a fastish computer.<br><br>also, consider this another vote for you to subscribe here..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-video-recording-method-11916449</guid>
<pubDate>Sat, 20 Nov 2004 21:23:23 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11916345</link>
<description><![CDATA[Mele20 posted :  <div class="bquote"><SMALL>said by <a href="/profile/465004" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=465004');">ironwalker</a>:</SMALL><br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>toddbs98, the exploits I tested were not successful in harming a fully patched version of XP, at least not in my testing. My tests show an unpatched XP installation.<br><br><HR></BLOCKQUOTE><br><br>Now,hopefully, all those that didnt/wont/uninstalled sp2 will now seee why its a much needed resource.<br>Thanx Ben<br> </DIV>I haven't seen anyone say that SP1a (fully patched) with Proxo (latest JD5000 alpha extra/advanced filters) gets infected. So, I am not at all convinced that I need to install SP2 with all its headaches. I very seldom use IE anyhow. <br><SMALL>--<br>The first and foremost function of our jurors is to protect private citizens from a tyrannical and intrusive government...Jurors are the last line of defense for liberty. Thomas Jefferson 1789</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11916345</guid>
<pubDate>Sat, 20 Nov 2004 21:07:52 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11915971</link>
<description><![CDATA[JollyStomper posted :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Those pages use several security exploits to stealth install a variety of different software packages on users' PCs, all without any warning whatsoever. Several other domains are used in that installation/exploit process, including:<br><br>69.50.168.147<br>195.178.160.30<br>213.159.117.133<br>b00gle.info <br>coolsearch.biz<br>newiframe.biz<br>pizdato.biz<br><HR></BLOCKQUOTE><br><br>Thanks for all the info, Eric.  All blocked at the firewall level now.<br><br>js<br><SMALL>--<br>"As I was sayin' buster, this planet ain't big enough for the two of us so... OFF YA GO!"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11915971</guid>
<pubDate>Sat, 20 Nov 2004 20:15:21 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11914885</link>
<description><![CDATA[jonkman posted : You're right. I said fully patched, I should have said XP SP1 with all patches, but not SP2.<br><br>We work on that assumption in work and on bleeding snort generally. There are still such a large number of apps that SP2 breaks we work to keep SP1 secure.<br><br>Although the new vulns in SP2 are getting it caught up with SP1 for open issues. :)<br><br>Thanks for pointing that out, I'll correct my post on the bleedingsnort site as well.<br><br>Matt]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11914885</guid>
<pubDate>Sat, 20 Nov 2004 17:35:10 EDT</pubDate>
</item>

<item>
<title>Re: Effect of patches; testing methods</title>
<link>http://www.dslreports.com/forum/Re-Effect-of-patches-testing-methods-11914411</link>
<description><![CDATA[Nerdtalker posted :  <div class="bquote"><SMALL>said by Ben Edelman:</SMALL><br><br>Nerdtalker, yes, I was using a vmware test environment for the tests shown in the video.  Vmware makes it much easier to run these kinds of tests.<br> </DIV>Thanks!<br><br>So this un-patched XP installation was essentially SP1?<br><br>Thanks again Ben for elaborating on all this.<br><SMALL>--<br>Touch a thistle timidly, and it pricks you; grasp it boldly, and its spines crumble. -William S. Halsey<BR><BR>I'm testing Gmail's spam filters, fill it up: Broadbandreports1@gmail.com<BR>Spam to date: 548</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Effect-of-patches-testing-methods-11914411</guid>
<pubDate>Sat, 20 Nov 2004 16:32:05 EDT</pubDate>
</item>

<item>
<title>Re: News: Major Exploit Underway...</title>
<link>http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11913839</link>
<description><![CDATA[ironwalker posted :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>toddbs98, the exploits I tested were not successful in harming a fully patched version of XP, at least not in my testing. My tests show an unpatched XP installation.<br><br><HR></BLOCKQUOTE><br><br>Now,hopefully, all those that didnt/wont/uninstalled sp2 will now seee why its a much needed resource.<br>Thanx Ben<br><SMALL>--<br>"LIVE FREE OR DIE"www.Theforumz.com ---- www.ownt.com--<A HREF="http://www.dslreports.com/forum/ftth">Fiber Optics</A> is the future of high-speed internet access. Stop by the <A HREF="http://www.dslreports.com/forum/ftth">BBR Fiber Optic</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-News-Major-Exploit-Underway-11913839</guid>
<pubDate>Sat, 20 Nov 2004 15:19:05 EDT</pubDate>
</item>

</channel>
</rss>
