<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>NIS 2009 Found This... What is it? in Security</title>
<link>http://www.dslreports.com/forum/r21306810</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 09:58:05 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 09:58:05 EDT</lastBuildDate>

<item>
<title>Re: NIS 2009 Found This... What is it?</title>
<link>http://www.dslreports.com/forum/remark,21309490</link>
<description><![CDATA[<A HREF="/useremail/u/1019407"><b>owlyn</b></A> : <div class="bquote"><small>said by  therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Looks like this, <A HREF="http://www.castlecops.com/p1114767-Niranhadas_com.html">Niranhadas.com</a>.<br> </div>Okay, I visited the link, but I don't know what the information ther means. It was obviously a code snippet, but iu don't know what it does. Looks like it wants to cause a buffer overflow, and then install a (malware?)helper to Adobe reader? Just a guess...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21309490</guid>
<pubDate>Wed, 22 Oct 2008 16:40:55 EDT</pubDate>
</item>

<item>
<title>Re: NIS 2009 Found This... What is it?</title>
<link>http://www.dslreports.com/forum/remark,21309171</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Looks like this, <A HREF="http://www.castlecops.com/p1114767-Niranhadas_com.html">Niranhadas.com</a>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21309171</guid>
<pubDate>Wed, 22 Oct 2008 15:34:51 EDT</pubDate>
</item>

<item>
<title>Re: NIS 2009 Found This... What is it?</title>
<link>http://www.dslreports.com/forum/remark,21307791</link>
<description><![CDATA[<A HREF="/useremail/u/1019407"><b>owlyn</b></A> : Thanks. I checked the whois on it before posting, but I still wasn't sure. I sure hope my Trend Micro software was protecting me prior to the NIS install...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21307791</guid>
<pubDate>Wed, 22 Oct 2008 11:15:23 EDT</pubDate>
</item>

<item>
<title>Re: NIS 2009 Found This... What is it?</title>
<link>http://www.dslreports.com/forum/remark,21307749</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : SnapShot Viewer ActiveX? That sure sounds like a social engineering ploy to get a trojan installed (such as Zlob).<br><br>I wouldn't call it a FP.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21307749</guid>
<pubDate>Wed, 22 Oct 2008 11:07:44 EDT</pubDate>
</item>

<item>
<title>Re: NIS 2009 Found This... What is it?</title>
<link>http://www.dslreports.com/forum/remark,21306861</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : NIS states that wsxhost.net was the webpage you were visiting<br><br>WHO IS INFO<br>Result for wsxhost.net<br>--> /usr/local/bin/fwhois wsxhost.net@whois.internic.net<br>[whois.internic.net]<br><br>Whois Server Version 2.0<br><br>Domain names in the .com and .net domains can now be registered<br><br>   Domain Name: WSXHOST.NET<br>   Registrar: REGTIME LTD.<br>   Whois Server: whois.regtime.net<br>   Referral URL: &raquo;<A HREF="http://www.webnames.ru" >www.webnames.ru</A><br>   Name Server: NS1.NAMESELF.COM<br>   Name Server: NS2.NAMESELF.COM<br>   Status: ok<br>   Updated Date: 19-sep-2008<br>   Creation Date: 19-sep-2008<br>   Expiration Date: 19-sep-2009<br><br>The Registry database contains ONLY .COM, .NET, .EDU domains and<br>--> /usr/local/bin/fwhois wsxhost.net@whois.regtime.net<br>[www.regtime.net]<br>% RegTime.net WHOIS server<br><br>Domain name: wsxhost.net<br><br>Name servers:<br>   ns1.nameself.com<br>   ns2.nameself.com<br><br>Registrar: RegTime.net Limited<br><b>Creation date: 2008-09-19</b><br>Expiration date: 2009-09-19<br><br>Registrant:<br>   Rey<br>   Email: palfreycrossvw@gmail.com<br>   Organization: Cross Co<br>   Address: 228 WIECKING CTR<br>   City: MANKATO<br>   State: MN<br>   ZIP: 56001<br>   Country: US<br>   Phone: +1.5073891822<br>   Fax: +1.5073891822<br>Administrative Contact:<br>   Rey<br>   Email: palfreycrossvw@gmail.com<br>   Organization: Cross Co<br>   Address: 228 WIECKING CTR<br>   City: MANKATO<br>   State: MN<br>   ZIP: 56001<br>   Country: US<br>   Phone: +1.5073891822<br>   Fax: +1.5073891822<br>Technical Contact:<br>   Rey<br>   Email: palfreycrossvw@gmail.com<br>   Organization: Cross Co<br>   Address: 228 WIECKING CTR<br>   City: MANKATO<br>   State: MN<br>   ZIP: 56001<br>   Country: US<br>   Phone: +1.5073891822<br>   Fax: +1.5073891822<br>Billing Contact:<br>   Rey<br>   Email: palfreycrossvw@gmail.com<br>   Organization: Cross Co<br>   Address: 228 WIECKING CTR<br>   City: MANKATO<br>   State: MN<br>   ZIP: 56001<br>   Country: US<br>   Phone: +1.5073891822<br>   Fax: +1.5073891822<br><br>Domain name registered recently using IP name servers in HongKong for registrants in Minnesota thru a Russian registrar service -- IMO I would thank NIS.  Doesn't sound kosher :)<br><small>--<br>Proud Member of <A HREF="http://asap.maddoktor2.com">ASAP</a><br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21306861</guid>
<pubDate>Wed, 22 Oct 2008 07:14:14 EDT</pubDate>
</item>

<item>
<title>Re: NIS 2009 Found This... What is it?</title>
<link>http://www.dslreports.com/forum/remark,21306833</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Here is some info about that IP<br>&raquo;<A HREF="http://www.dshield.org/ipinfo.html?ip=58.65.234.9" >www.dshield.org/ipinfo.html?ip=58.65.234.9</A><br>Hostname:  58-65-234-9.myrdns.com <br><br>ISP in HongKong<br><br>I wouldn't call it a false positive unless you were unable to view a web page correctly that may have contained something from this IP.<br><br>NIS blocked it so if you didn't notice a web page loading properly hosted in HongKong I wouldn't worry  NIS did its job :)<br><small>--<br>Proud Member of <A HREF="http://asap.maddoktor2.com">ASAP</a><br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21306833</guid>
<pubDate>Wed, 22 Oct 2008 06:59:06 EDT</pubDate>
</item>

<item>
<title>NIS 2009 Found This... What is it?</title>
<link>http://www.dslreports.com/forum/remark,21306810</link>
<description><![CDATA[<A HREF="/useremail/u/1019407"><b>owlyn</b></A> : What is this attack? Looks like an FP to me, but I'm not really sure...<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21306810?c=1361899&ret=L2ZvcnVtL3IyMTMwNjgxMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="92755 bytes" WIDTH=600 HEIGHT=429 SRC="/r0/download/1361899.thumb600~ebda222403e942890fcb4407ab6ded32/nis.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21306810</guid>
<pubDate>Wed, 22 Oct 2008 06:41:49 EDT</pubDate>
</item>

</channel>
</rss>
