<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8539880144347728238.post9143230724205909839..comments</id><updated>2009-03-24T04:43:28.511-04:00</updated><title type='text'>Comments on Carnal0wnage Blog: cute...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://carnal0wnage.blogspot.com/feeds/9143230724205909839/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/9143230724205909839/comments/default'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/cute.html'/><author><name>CG</name><uri>http://www.blogger.com/profile/11061967917509053185</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-293005777224194001</id><published>2008-09-06T08:26:00.000-04:00</published><updated>2008-09-06T08:26:00.000-04:00</updated><title type='text'>I noticed the exact same string on my web site's l...</title><content type='html'>I noticed the exact same string on my web site's logs. I was actually looking at the logs at the time it happened with the "tail -f". I dropped the GET into the burp suite's decode tab and saw the .cn urls. Dropped those urls into Serversniff.net's File-Info tool and checked out each of the subsequently linked files one at a time just like you did. The thing that was my saving grace was a properly configured mod_security suite along with the excellent .htaccess file done by Ronald of 0x000000.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/9143230724205909839/comments/default/293005777224194001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/9143230724205909839/comments/default/293005777224194001'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/cute.html?showComment=1220703960000#c293005777224194001' title=''/><author><name>Mubix</name><uri>http://www.blogger.com/profile/08706151795678283675</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14654565360294860308'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.blogspot.com/2008/08/cute.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-9143230724205909839' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/9143230724205909839' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-7314020271931265005</id><published>2008-09-02T11:54:00.000-04:00</published><updated>2008-09-02T11:54:00.000-04:00</updated><title type='text'>This was the same injection string that was used o...</title><content type='html'>This was the same injection string that was used on the three sites that I did the I.R. for. &lt;BR/&gt;&lt;BR/&gt;The Asprox/Danmec bot was the source of the SQLi. I needed to use the same SQLi vector to clean the database. The #$%# database admin was MIA and none of the clients had access to the database. At least they eventually fixed the code in their sites.&lt;BR/&gt;&lt;BR/&gt;I'm not sure if this one is Asprox/Danmec though. The .js does not look to be one of the current ones in use by the bot. This looks to be linked to a Chinese malware site. &lt;BR/&gt;&lt;BR/&gt;/dean</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/9143230724205909839/comments/default/7314020271931265005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/9143230724205909839/comments/default/7314020271931265005'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/cute.html?showComment=1220370840000#c7314020271931265005' title=''/><author><name>dean</name><uri>http://www.blogger.com/profile/13744345182407258839</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08521767208495447043'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.blogspot.com/2008/08/cute.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-9143230724205909839' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/9143230724205909839' type='text/html'/></entry></feed>