<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Servage hacked: Exploit-Iframe (Trojan) Infection</title>
	<atom:link href="http://www.proxyutza.com/exploit-iframe-trojan-infection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/</link>
	<description>About all sorth of things: PHP, Hacks, Scripts, Servers, Linux, Technology, News, Trends</description>
	<lastBuildDate>Fri, 27 Aug 2010 06:34:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Chris</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5971</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 21 Apr 2010 11:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5971</guid>
		<description>Well just hours after I posted this, it seems Servage is down and so is the email.
Or so I thought.
Doing a traceroute it seems they are up and running absolutely fine from everywhere... except my office IP!
I assume they have blocked out of spite due to my earlier comments, has anyone else experienced this sort of action?</description>
		<content:encoded><![CDATA[<p>Well just hours after I posted this, it seems Servage is down and so is the email.<br />
Or so I thought.<br />
Doing a traceroute it seems they are up and running absolutely fine from everywhere&#8230; except my office IP!<br />
I assume they have blocked out of spite due to my earlier comments, has anyone else experienced this sort of action?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lawrence</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5970</link>
		<dc:creator>Lawrence</dc:creator>
		<pubDate>Tue, 20 Apr 2010 16:58:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5970</guid>
		<description>Servage hosts many Porn sites, I&#039;m not an expert but it seems Servage seems particularly, prone to such attacks. I closed my account with them many moons ago, mainly due to their banal, and patronising CS. They are obviously making way too much money to care about posters such as yourself and many 100&#039;s  of others, yes they are very complacent. Depending on the content I find 1 and 1 has grown into s more, well much more scripts, also much more control over individual choices regarding a shared hosting account than a few years ago. They are reliable, CS is A1, not cheap (unless your have an address in the US), but you get what you pay for as our grandparents always remind us of lol.</description>
		<content:encoded><![CDATA[<p>Servage hosts many Porn sites, I&#8217;m not an expert but it seems Servage seems particularly, prone to such attacks. I closed my account with them many moons ago, mainly due to their banal, and patronising CS. They are obviously making way too much money to care about posters such as yourself and many 100&#8242;s  of others, yes they are very complacent. Depending on the content I find 1 and 1 has grown into s more, well much more scripts, also much more control over individual choices regarding a shared hosting account than a few years ago. They are reliable, CS is A1, not cheap (unless your have an address in the US), but you get what you pay for as our grandparents always remind us of lol.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5969</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 20 Apr 2010 12:45:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5969</guid>
		<description>I&#039;ve only just found this, but over 10 times, mostly concentrated in the period mentioned by the poster, malicious code was inserted into all sites hosted with Servage.
They blamed it on my using &#039;old scripts with risks&#039; and said no other user had complained. 
I&#039;m moving all my accounts now, I&#039;m decided (all my sites are down today; thanks servage!)... Can anyone recommend a good, HONEST alternative to the lying Germans?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve only just found this, but over 10 times, mostly concentrated in the period mentioned by the poster, malicious code was inserted into all sites hosted with Servage.<br />
They blamed it on my using &#8216;old scripts with risks&#8217; and said no other user had complained.<br />
I&#8217;m moving all my accounts now, I&#8217;m decided (all my sites are down today; thanks servage!)&#8230; Can anyone recommend a good, HONEST alternative to the lying Germans?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Myers</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5961</link>
		<dc:creator>Alan Myers</dc:creator>
		<pubDate>Sun, 04 Apr 2010 23:48:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5961</guid>
		<description>We all know al about that. BUT that DOES NOT explain the constant hacking of Servage sites, the stealing of personal credit/ debit card details and the total lack of support from the clowns that run it. If you like Servage then good luck to you. If you ever ahve a problem with any aspect of their service and then try and get it resolved then you might realise why so many people run away from them and why so many people think they should be closed down for good. Judge for yourself.</description>
		<content:encoded><![CDATA[<p>We all know al about that. BUT that DOES NOT explain the constant hacking of Servage sites, the stealing of personal credit/ debit card details and the total lack of support from the clowns that run it. If you like Servage then good luck to you. If you ever ahve a problem with any aspect of their service and then try and get it resolved then you might realise why so many people run away from them and why so many people think they should be closed down for good. Judge for yourself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Langley</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5960</link>
		<dc:creator>Matt Langley</dc:creator>
		<pubDate>Sat, 03 Apr 2010 17:18:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5960</guid>
		<description>Also, don&#039;t migrate to HostDept. They are just as bad as Servage.</description>
		<content:encoded><![CDATA[<p>Also, don&#8217;t migrate to HostDept. They are just as bad as Servage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Langley</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5959</link>
		<dc:creator>Matt Langley</dc:creator>
		<pubDate>Sat, 03 Apr 2010 17:16:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5959</guid>
		<description>obviously I was talking about script tags above, but I used less than/greater than signs so it got filtered (rather than html encoded which is what I do with comments)...</description>
		<content:encoded><![CDATA[<p>obviously I was talking about script tags above, but I used less than/greater than signs so it got filtered (rather than html encoded which is what I do with comments)&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Langley</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5958</link>
		<dc:creator>Matt Langley</dc:creator>
		<pubDate>Sat, 03 Apr 2010 17:14:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5958</guid>
		<description>The original issue on this thread of  tags being inserted into web pages, sounds like a SQL Injection attack. This is where SQL in included in a form variable/query string and then incorporated into server script dynamic SQL statements, e.g.
querystring UserID=&quot;1;update categories set title=&#039;...&#039;;&quot;

causing the following sql to be created and run:
&quot;select * from atable where UserID=1;update categories set title=&#039;...&#039;;&quot;

If you then use the category titles when you build your page, your users get the script in their browser. 

It may also be possible to update the file system from within the SQL statement by running shell commands, or using export functions of the database.

This is a common attack and form/querystring data must be cleaned to prevent it.

Normally I would only expect one account to be effected but if an account with sufficient privileges is effected, the whole server could be infected.

(and before you ask, they don&#039;t need to know the table/column names, they just guess likely names and keep trying until they get a result.)

Hope this helps,

Matt.</description>
		<content:encoded><![CDATA[<p>The original issue on this thread of  tags being inserted into web pages, sounds like a SQL Injection attack. This is where SQL in included in a form variable/query string and then incorporated into server script dynamic SQL statements, e.g.<br />
querystring UserID=&#8221;1;update categories set title=&#8217;&#8230;&#8217;;&#8221;</p>
<p>causing the following sql to be created and run:<br />
&#8220;select * from atable where UserID=1;update categories set title=&#8217;&#8230;&#8217;;&#8221;</p>
<p>If you then use the category titles when you build your page, your users get the script in their browser. </p>
<p>It may also be possible to update the file system from within the SQL statement by running shell commands, or using export functions of the database.</p>
<p>This is a common attack and form/querystring data must be cleaned to prevent it.</p>
<p>Normally I would only expect one account to be effected but if an account with sufficient privileges is effected, the whole server could be infected.</p>
<p>(and before you ask, they don&#8217;t need to know the table/column names, they just guess likely names and keep trying until they get a result.)</p>
<p>Hope this helps,</p>
<p>Matt.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ProXy</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5930</link>
		<dc:creator>ProXy</dc:creator>
		<pubDate>Tue, 12 Jan 2010 20:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5930</guid>
		<description>If everything happened as stated above, you should be able to file a complaint and your credit card company should refund you the money, and next they should try and recover the money from servage.</description>
		<content:encoded><![CDATA[<p>If everything happened as stated above, you should be able to file a complaint and your credit card company should refund you the money, and next they should try and recover the money from servage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5929</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Tue, 12 Jan 2010 20:18:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5929</guid>
		<description>Recently i signed up with Servage.net for hosting and domain name registration.

I paid with a creditcard and recieved an autometed email informing me that my order would be processed within 30 minutes.

24 hours later, having received no confirmation i sent an email to sales@servage.net asking for the status of my order.

No reply. 

I sent another email to sales and also info@servage.net.

No reply.

I tried to cancel my order but the credit card company told me the oayment had been taken.

Using my right under Servage.net&#039;s published terms and conditions I sent an email requesting cancellation of my account within the first 5 days.

No reply. I tried to login
with my username and password. Account not activated.

I sent another email repeating my request for a refund and asking for a resolution to the issue.

No reply.

Servage.net simply took my money and ignored my emails.

I call that theft.

Avoid servage.net 
Use a different hosting firm or registrar.</description>
		<content:encoded><![CDATA[<p>Recently i signed up with Servage.net for hosting and domain name registration.</p>
<p>I paid with a creditcard and recieved an autometed email informing me that my order would be processed within 30 minutes.</p>
<p>24 hours later, having received no confirmation i sent an email to <a href="mailto:sales@servage.net">sales@servage.net</a> asking for the status of my order.</p>
<p>No reply. </p>
<p>I sent another email to sales and also <a href="mailto:info@servage.net">info@servage.net</a>.</p>
<p>No reply.</p>
<p>I tried to cancel my order but the credit card company told me the oayment had been taken.</p>
<p>Using my right under Servage.net&#8217;s published terms and conditions I sent an email requesting cancellation of my account within the first 5 days.</p>
<p>No reply. I tried to login<br />
with my username and password. Account not activated.</p>
<p>I sent another email repeating my request for a refund and asking for a resolution to the issue.</p>
<p>No reply.</p>
<p>Servage.net simply took my money and ignored my emails.</p>
<p>I call that theft.</p>
<p>Avoid servage.net<br />
Use a different hosting firm or registrar.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oli</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5871</link>
		<dc:creator>Oli</dc:creator>
		<pubDate>Mon, 17 Aug 2009 18:24:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5871</guid>
		<description>My servage account was today hacked by NobodyCoder@mail.ru all my sites changed, massive loss of earnings, seriously considering changing providers!</description>
		<content:encoded><![CDATA[<p>My servage account was today hacked by <a href="mailto:NobodyCoder@mail.ru">NobodyCoder@mail.ru</a> all my sites changed, massive loss of earnings, seriously considering changing providers!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
