<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Reacties op: Keygenguru malware injection on server</title>
	<atom:link href="http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html</link>
	<description>When communication is needed</description>
	<lastBuildDate>Sun, 09 May 2010 22:00:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Door: smaert</title>
		<link>http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html/comment-page-1#comment-931</link>
		<dc:creator>smaert</dc:creator>
		<pubDate>Wed, 18 Nov 2009 17:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html#comment-931</guid>
		<description>Hi,

This looks like the same issue that I spent many days trying to fix.

I&#039;ve traced this to a vulnerability with php and inherited file descriptors being used to &#039;take over&#039; apache children and serve malicious redirects. 

I written much on this subject, including how to find the source of the problem, how to test if your webserver is vulnerable, and many details surrounding this clever attack.

Please read:

http://smaert.com/apache_mischief/writeup.txt

Regards,
smaert</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>This looks like the same issue that I spent many days trying to fix.</p>
<p>I&#8217;ve traced this to a vulnerability with php and inherited file descriptors being used to &#8216;take over&#8217; apache children and serve malicious redirects. </p>
<p>I written much on this subject, including how to find the source of the problem, how to test if your webserver is vulnerable, and many details surrounding this clever attack.</p>
<p>Please read:</p>
<p><a href="http://smaert.com/apache_mischief/writeup.txt" rel="nofollow">http://smaert.com/apache_mischief/writeup.txt</a></p>
<p>Regards,<br />
smaert</p>
]]></content:encoded>
	</item>
	<item>
		<title>Door: Robin</title>
		<link>http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html/comment-page-1#comment-929</link>
		<dc:creator>Robin</dc:creator>
		<pubDate>Mon, 16 Nov 2009 07:38:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html#comment-929</guid>
		<description>it uses a galleryscript most of the time to upload an image (jpg, gif, ...). After that they use that to execute a script in place of showing the image, because the file they uploaded is not an image but a script, this script will do some nasty things and make the popups and blanc pages!</description>
		<content:encoded><![CDATA[<p>it uses a galleryscript most of the time to upload an image (jpg, gif, &#8230;). After that they use that to execute a script in place of showing the image, because the file they uploaded is not an image but a script, this script will do some nasty things and make the popups and blanc pages!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Door: Tristan</title>
		<link>http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html/comment-page-1#comment-928</link>
		<dc:creator>Tristan</dc:creator>
		<pubDate>Sun, 15 Nov 2009 20:59:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html#comment-928</guid>
		<description>Any idea on what attack vector it uses to infect sites?</description>
		<content:encoded><![CDATA[<p>Any idea on what attack vector it uses to infect sites?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Door: Robin</title>
		<link>http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html/comment-page-1#comment-926</link>
		<dc:creator>Robin</dc:creator>
		<pubDate>Mon, 09 Nov 2009 06:42:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html#comment-926</guid>
		<description>yes we have fixed the problem.</description>
		<content:encoded><![CDATA[<p>yes we have fixed the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Door: Bonus</title>
		<link>http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html/comment-page-1#comment-924</link>
		<dc:creator>Bonus</dc:creator>
		<pubDate>Sun, 08 Nov 2009 21:22:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.cauwenbergh.be/no-category/keygenguru-malware-injection-on-server.html#comment-924</guid>
		<description>Did you fix it? We have same problem too...</description>
		<content:encoded><![CDATA[<p>Did you fix it? We have same problem too&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
