<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Servage hacked: Exploit-Iframe (Trojan) Infection</title>
	<atom:link href="http://www.proxyutza.com/exploit-iframe-trojan-infection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/</link>
	<description>About all sorth of things: PHP, Hacks, Scripts, Servers, Linux, Technology, News, Trends</description>
	<lastBuildDate>Wed, 03 Mar 2010 19:16:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: ProXy</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5930</link>
		<dc:creator>ProXy</dc:creator>
		<pubDate>Tue, 12 Jan 2010 20:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5930</guid>
		<description>If everything happened as stated above, you should be able to file a complaint and your credit card company should refund you the money, and next they should try and recover the money from servage.</description>
		<content:encoded><![CDATA[<p>If everything happened as stated above, you should be able to file a complaint and your credit card company should refund you the money, and next they should try and recover the money from servage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5929</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Tue, 12 Jan 2010 20:18:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5929</guid>
		<description>Recently i signed up with Servage.net for hosting and domain name registration.

I paid with a creditcard and recieved an autometed email informing me that my order would be processed within 30 minutes.

24 hours later, having received no confirmation i sent an email to sales@servage.net asking for the status of my order.

No reply. 

I sent another email to sales and also info@servage.net.

No reply.

I tried to cancel my order but the credit card company told me the oayment had been taken.

Using my right under Servage.net&#039;s published terms and conditions I sent an email requesting cancellation of my account within the first 5 days.

No reply. I tried to login
with my username and password. Account not activated.

I sent another email repeating my request for a refund and asking for a resolution to the issue.

No reply.

Servage.net simply took my money and ignored my emails.

I call that theft.

Avoid servage.net 
Use a different hosting firm or registrar.</description>
		<content:encoded><![CDATA[<p>Recently i signed up with Servage.net for hosting and domain name registration.</p>
<p>I paid with a creditcard and recieved an autometed email informing me that my order would be processed within 30 minutes.</p>
<p>24 hours later, having received no confirmation i sent an email to <a href="mailto:sales@servage.net">sales@servage.net</a> asking for the status of my order.</p>
<p>No reply. </p>
<p>I sent another email to sales and also <a href="mailto:info@servage.net">info@servage.net</a>.</p>
<p>No reply.</p>
<p>I tried to cancel my order but the credit card company told me the oayment had been taken.</p>
<p>Using my right under Servage.net&#8217;s published terms and conditions I sent an email requesting cancellation of my account within the first 5 days.</p>
<p>No reply. I tried to login<br />
with my username and password. Account not activated.</p>
<p>I sent another email repeating my request for a refund and asking for a resolution to the issue.</p>
<p>No reply.</p>
<p>Servage.net simply took my money and ignored my emails.</p>
<p>I call that theft.</p>
<p>Avoid servage.net<br />
Use a different hosting firm or registrar.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oli</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5871</link>
		<dc:creator>Oli</dc:creator>
		<pubDate>Mon, 17 Aug 2009 18:24:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5871</guid>
		<description>My servage account was today hacked by NobodyCoder@mail.ru all my sites changed, massive loss of earnings, seriously considering changing providers!</description>
		<content:encoded><![CDATA[<p>My servage account was today hacked by <a href="mailto:NobodyCoder@mail.ru">NobodyCoder@mail.ru</a> all my sites changed, massive loss of earnings, seriously considering changing providers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ProXy</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5540</link>
		<dc:creator>ProXy</dc:creator>
		<pubDate>Wed, 24 Jun 2009 11:15:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5540</guid>
		<description>Dave, in our case, with Servage hosting it&#039;s definitely not a local problem.

It&#039;s their servers &amp; staff who are to blaim</description>
		<content:encoded><![CDATA[<p>Dave, in our case, with Servage hosting it&#8217;s definitely not a local problem.</p>
<p>It&#8217;s their servers &#038; staff who are to blaim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5532</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Wed, 24 Jun 2009 00:43:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5532</guid>
		<description>Jeez guys, this is NOT and I repeat NOT a service provider issue. I&#039;ve been on so many forums and seen the same old shit about this virus. 

Whats happening here is that on your local PC you have a virus thats sniffing your FTP password when you upload new scripts / HTML files etc to your website. The passwords are ending up on a server I&#039;ve traced to the Ukraine, where your sites HTML and PHP files anre having the virus script injected into them. 

Within a few hours, your site is now acting as a distribution node for the virus. 

The only solution I have founf so far is to re-upload fresh copies of your sites files from backups (virus free ones) and then change the FTP password from your providers control panel. 

This way at least your sites are safe. 

I&#039;ve set up a completely fresh machine to make site changes now and all seems to be OK. I&#039;ve had tno re-infections. 

The trouble is that no one as far as I can tell, has clearly identified the virus to be able to disinfect it from your local machine. Some people are identifying it as GUMBLAR but the script charicteristics vary so widely that I suspect we are dealing with a wide range of copycats. 

Maybe the only way to track it down is to use something like Ethereal to sniff FTP sessions and see whats going on. 

Whatever it is, this virus is a pain of the greatest magnitude,. But dont give your service provider hell. Its not theiir fault. 100%.</description>
		<content:encoded><![CDATA[<p>Jeez guys, this is NOT and I repeat NOT a service provider issue. I&#8217;ve been on so many forums and seen the same old shit about this virus. </p>
<p>Whats happening here is that on your local PC you have a virus thats sniffing your FTP password when you upload new scripts / HTML files etc to your website. The passwords are ending up on a server I&#8217;ve traced to the Ukraine, where your sites HTML and PHP files anre having the virus script injected into them. </p>
<p>Within a few hours, your site is now acting as a distribution node for the virus. </p>
<p>The only solution I have founf so far is to re-upload fresh copies of your sites files from backups (virus free ones) and then change the FTP password from your providers control panel. </p>
<p>This way at least your sites are safe. </p>
<p>I&#8217;ve set up a completely fresh machine to make site changes now and all seems to be OK. I&#8217;ve had tno re-infections. </p>
<p>The trouble is that no one as far as I can tell, has clearly identified the virus to be able to disinfect it from your local machine. Some people are identifying it as GUMBLAR but the script charicteristics vary so widely that I suspect we are dealing with a wide range of copycats. </p>
<p>Maybe the only way to track it down is to use something like Ethereal to sniff FTP sessions and see whats going on. </p>
<p>Whatever it is, this virus is a pain of the greatest magnitude,. But dont give your service provider hell. Its not theiir fault. 100%.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: servage - WHL Community Foren</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-5263</link>
		<dc:creator>servage - WHL Community Foren</dc:creator>
		<pubDate>Sat, 30 May 2009 17:36:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-5263</guid>
		<description>[...] kann nur sagen Finger weg von dem Hoster. Zu dem Sicherheits Problem bei Servage gibt es auch hier  http://www.proxyutza.com/exploit-ifr...jan-infection/ sehr interessante Informationen.              [...]</description>
		<content:encoded><![CDATA[<p>[...] kann nur sagen Finger weg von dem Hoster. Zu dem Sicherheits Problem bei Servage gibt es auch hier  <a href="http://www.proxyutza.com/exploit-ifr...jan-infection/" rel="nofollow">http://www.proxyutza.com/exploit-ifr&#8230;jan-infection/</a> sehr interessante Informationen.              [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: servage sucks and hosts idiots too</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-4400</link>
		<dc:creator>servage sucks and hosts idiots too</dc:creator>
		<pubDate>Fri, 27 Mar 2009 17:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-4400</guid>
		<description>@ drukpa
 w/ all due respect drukpa, you may indeed have the infections on your computer, but when it comes to servage you don&#039;t know what you&#039;re talking about.

some of us use unix, linux,  other os that are not windoze and it&#039;s the stupid fucks at servage that also allow their servers to get hacked every other fricking day.

do a little research before you blab about something you don&#039;t know anything about.

google has blocked/warned about thousands of sites hosted on servage that are malware infected sites.

your pc being infected is not the same as an iframe injection.

servage is run by a bunch of incompetent pimple faced druggies and hackers -- aparently with the same level of technical knowledge as some posters who still defend those sorry lame ass fucks.</description>
		<content:encoded><![CDATA[<p>@ drukpa<br />
 w/ all due respect drukpa, you may indeed have the infections on your computer, but when it comes to servage you don&#8217;t know what you&#8217;re talking about.</p>
<p>some of us use unix, linux,  other os that are not windoze and it&#8217;s the stupid fucks at servage that also allow their servers to get hacked every other fricking day.</p>
<p>do a little research before you blab about something you don&#8217;t know anything about.</p>
<p>google has blocked/warned about thousands of sites hosted on servage that are malware infected sites.</p>
<p>your pc being infected is not the same as an iframe injection.</p>
<p>servage is run by a bunch of incompetent pimple faced druggies and hackers &#8212; aparently with the same level of technical knowledge as some posters who still defend those sorry lame ass fucks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: drukpa</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-4262</link>
		<dc:creator>drukpa</dc:creator>
		<pubDate>Fri, 20 Mar 2009 11:35:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-4262</guid>
		<description>I think it&#039;s not a problem with servage or any other hosting. Your PC is infected with the trojan horse or something.

I have three websites at three different hostings. Today all my index(php and html) were all modified , an iframe was inserted into them all. Whenever a user tried to reach my site, the trojan would infect the user&#039;s pc too.

My PC is infected and it somehow got all the user/pass of my hosting accounts. So all the accounts at THREE different hosts got infected at the same time.</description>
		<content:encoded><![CDATA[<p>I think it&#8217;s not a problem with servage or any other hosting. Your PC is infected with the trojan horse or something.</p>
<p>I have three websites at three different hostings. Today all my index(php and html) were all modified , an iframe was inserted into them all. Whenever a user tried to reach my site, the trojan would infect the user&#8217;s pc too.</p>
<p>My PC is infected and it somehow got all the user/pass of my hosting accounts. So all the accounts at THREE different hosts got infected at the same time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mytob</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-3825</link>
		<dc:creator>Mytob</dc:creator>
		<pubDate>Mon, 23 Feb 2009 18:40:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-3825</guid>
		<description>Nice to see im not the only one getting this inserted into my sites! Id also keep an eye on any .js files as I have found similaer code put into them. Ayone no any good alternative to them BTW?</description>
		<content:encoded><![CDATA[<p>Nice to see im not the only one getting this inserted into my sites! Id also keep an eye on any .js files as I have found similaer code put into them. Ayone no any good alternative to them BTW?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andry</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/comment-page-3/#comment-3469</link>
		<dc:creator>Andry</dc:creator>
		<pubDate>Wed, 21 Jan 2009 10:46:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/#comment-3469</guid>
		<description>Stay away from servage!! Their server are good for hacking only. The support give stupid answer quickly. I can have the same answer with a random phrases generator.  STAY AWAY!!</description>
		<content:encoded><![CDATA[<p>Stay away from servage!! Their server are good for hacking only. The support give stupid answer quickly. I can have the same answer with a random phrases generator.  STAY AWAY!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
