<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8226343625671207502</id><updated>2012-02-23T00:14:29.788-05:00</updated><title type='text'>"Aw Snap" My website has been hacked!  Now what? A few tips from redleg.</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>22</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-412952889693030414</id><published>2012-02-22T15:33:00.001-05:00</published><updated>2012-02-22T15:34:48.899-05:00</updated><title type='text'>Redirects to costabrava.bee.pl or froling.bee.pl</title><summary type='text'>Seems like that has been an uptick in the number of sites I have seen lately with the redirects to costabrava.bee.pl or froling.bee.pl.

Typically redirects to http:// froling . bee . pl/ (costabrava . bee . pl ) are done using a bit of obfuscated php code, looks something like this


eval(base64_decode('Ul9BR0VOVCddOw0KaWYgKCR1YWcpIHs
NCmlmIChzdHJpc3RyKCRyZWZlcmVyLCJ5YWhvbyIpIG9yIHN0c
</summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/412952889693030414/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2012/02/costabrava-bee-pl.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/412952889693030414'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/412952889693030414'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2012/02/costabrava-bee-pl.html' title='Redirects to costabrava.bee.pl or froling.bee.pl'/><author><name>Red Leg</name><uri>http://www.blogger.com/profile/12083359752988855938</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-723040379212392002</id><published>2012-02-14T12:46:00.000-05:00</published><updated>2012-02-17T08:54:50.276-05:00</updated><title type='text'>Malware hosted on 31.184.242.102/</title><summary type='text'>

Update: 02/15/2012 In the hacks I am seeing now the code is similar to the code listed below but the domain has changed to http://31.184.242.103/s.php  .103 not .102.   This is pretty common with hacks, as soon as Google flags the domain as malicious the hackers move to a new domain, one that Google has not flagged yet.




I am seeing this hack on a lot of WordPress sites currently. The hack </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/723040379212392002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2012/02/malware-hosted-on-31184242102.html#comment-form' title='26 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/723040379212392002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/723040379212392002'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2012/02/malware-hosted-on-31184242102.html' title='Malware hosted on 31.184.242.102/'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>26</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-6469612313724240045</id><published>2012-01-18T08:33:00.000-05:00</published><updated>2012-02-09T21:57:57.030-05:00</updated><title type='text'>Malicious redirects in the .htaccess file are being re-written</title><summary type='text'>
In most (if not all) "malicious redirect" .htaccess hacks I have seen recently site owners have found that after cleaning up the .htaccess file the malicious code is being added back to the file within 30 minutes.  This is being done with  "backdoor(s)" the hackers have placed on the site. So far these have alll been php files placed on the site by the hackers. Site owners have reported the </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/6469612313724240045/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2012/01/malicious-htaccess-redirect-re-written.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/6469612313724240045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/6469612313724240045'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2012/01/malicious-htaccess-redirect-re-written.html' title='Malicious redirects in the .htaccess file are being re-written'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-9094180218879066887</id><published>2011-12-09T12:30:00.001-05:00</published><updated>2012-01-06T13:13:21.546-05:00</updated><title type='text'>Latest WordPress hack?</title><summary type='text'>



Malware hosted on adsa.fr.pn and holala02.in
or





Malware hosted on adsa.cn.pn and piz04.edu.tf
or





Malware hosted on adsa.co.at.pn and topddd14.in

I am seeing a number of WordPress sites hacked with a script call to a "rogue" php file over the last couple of days.  The hacks have all been fairly similar.  The hacker places a "rogue" php file on the site that, in most cases, has </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/9094180218879066887/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/12/latest-wordpress-hack.html#comment-form' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/9094180218879066887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/9094180218879066887'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/12/latest-wordpress-hack.html' title='Latest WordPress hack?'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-3300604107356261265</id><published>2011-11-07T07:58:00.000-05:00</published><updated>2011-11-23T13:07:37.019-05:00</updated><title type='text'>Malicious software hosted on nl.ai</title><summary type='text'>
The nl.ai hack is widespread on WordPress sites currently.  The hack consists of a block of malicious JavaScript being inserted (usually into the &lt;head&gt;&lt;/head&gt; section) into php pages on the site. Checking a page with the File Viewer Tool will show the code in a page. The malicious code appears like this in a page.


&lt;sc ript&gt;eval(function(p,a,c,k,e,d){e=function(c){return(c&lt;a?'':e(parseInt(c/a)</summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/3300604107356261265/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/11/malicious-software-hosted-on-nlai.html#comment-form' title='54 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/3300604107356261265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/3300604107356261265'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/11/malicious-software-hosted-on-nlai.html' title='Malicious software hosted on nl.ai'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>54</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-518577394920747758</id><published>2011-09-22T15:22:00.000-04:00</published><updated>2012-01-22T15:47:40.445-05:00</updated><title type='text'>Early detection of spam hacks on a web site.</title><summary type='text'>I read a post today from John Mueller (Google guy) which I think is a great idea so I thought I would pass it on in a bog post. The post was in response to a question,  Why am I getting &gt; 2000 counts of words like adobe and cs5 on my joomla site? on Google's Webmaster Tools help forum. 

Hopefully you have never had to deal with a spam hack on your site, but if you have you know they can have a </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/518577394920747758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/09/warning-spam-hacks.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/518577394920747758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/518577394920747758'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/09/warning-spam-hacks.html' title='Early detection of spam hacks on a web site.'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-djbxG9p6Fy4/Tnt82E6TMWI/AAAAAAAAALg/nFdKz3IPId8/s72-c/my-account.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-5788434467258131722</id><published>2011-09-17T12:25:00.000-04:00</published><updated>2011-10-19T10:24:46.188-04:00</updated><title type='text'>redirects to uniqtext.com</title><summary type='text'>I am starting to see a few posts on the forums with sites being hacked to redirect to the domain uniqtext.com. The redirects occur randomly so they can be hard to detect. So far they have all been WordPress and Joomla sites. In addition to the redirect there was spammy links/content being inserted in the pages of the sites. In the 5 sites I have looked at the redirect code has been located in the</summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/5788434467258131722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/09/redirects-to-uniqtext.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5788434467258131722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5788434467258131722'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/09/redirects-to-uniqtext.html' title='redirects to uniqtext&amp;#46;com'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-5390369399319904749</id><published>2011-08-26T12:54:00.017-04:00</published><updated>2011-10-13T23:23:35.781-04:00</updated><title type='text'>Removing a malware warning Blogspot (Blogger) site</title><summary type='text'>
This question comes up fairly regularly on some of the forums where I participate. Suddenly Chrome or Firefox or Safari is blocking access to my blog with a reported attack sites page, has my blog been hacked? The answer is a very ambiguous "not exactly".

The first thing you need to do is check the Safe Browsing Diagnostic Page for your site at


http://www.google.com/safebrowsing/diagnostic?</summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/5390369399319904749/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/08/malware-blogspot-blooger.html#comment-form' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5390369399319904749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5390369399319904749'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/08/malware-blogspot-blooger.html' title='Removing a malware warning Blogspot (Blogger) site'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>16</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-5876396295101292190</id><published>2011-08-22T09:50:00.028-04:00</published><updated>2011-09-17T02:08:36.874-04:00</updated><title type='text'>Malicious software is hosted on newportalse.com, counter-wordpress.com, ?.us.to/kwizhveo.php</title><summary type='text'>

newportalse.com, counter-wordpress.com

There are currently a large number of Wordpress sites that have been hacked where the domain being listed on the warning page is newportalse.com. In most cases the first indicator of this hack has been when the site owner is notified by a user that they have gotten a warning when visiting the site and/or the site owner gets a warning when viewing one of </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/5876396295101292190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/08/malware-hosted-newportalsecom.html#comment-form' title='28 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5876396295101292190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5876396295101292190'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/08/malware-hosted-newportalsecom.html' title='Malicious software is hosted on newportalse.com, counter-wordpress.com, ?.us.to/kwizhveo.php'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>28</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-5830687794452953084</id><published>2011-06-27T22:53:00.006-04:00</published><updated>2011-07-01T09:08:16.377-04:00</updated><title type='text'>polko.cx.cc, dalanaya.cz.cc, holot.cx.cc kulop.cx.cc, kutol.cx.cc and all the other .(cx|cz).cc(s)</title><summary type='text'>It seems the latest virus that is going around is a JavaScript hack using .cx.cc and .cz.cc domains to host the malware. polko.cx.cc/, dalanaya.cz.cc/, holot.cx.cc/ kulop.cx.cc/, kutol.cx.cc/, adrieath.cx.cc/ carolinsoll.cz.cc/ are the most common domains being used currently. These domains will undoubtedly change over time and I will try to keep this list up to-date. If the diagnostic page or </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/5830687794452953084/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/06/polko-kulop-kutol-holot.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5830687794452953084'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5830687794452953084'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/06/polko-kulop-kutol-holot.html' title='polko.cx.cc, dalanaya.cz.cc, holot.cx.cc kulop.cx.cc, kutol.cx.cc and all the other .(cx|cz).cc(s)'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-5491338376970898678</id><published>2011-06-16T14:30:00.004-04:00</published><updated>2011-06-27T20:39:54.746-04:00</updated><title type='text'>Cleaning up the alienego.com hack</title><summary type='text'>It seems like there have been a rash of sites getting flagged for the alienego.com hack lately. The alienego is obfuscated JavaScript hack that is hitting all types of sites.  If the diagnostic page for your site or the browser warning screen indicates 

Malicious software is hosted on 1 domain(s), including alienego.com/.

Here are a couple of things to look for.

Typically with alienego.com the</summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/5491338376970898678/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/06/cleaning-up-alienegocom-hack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5491338376970898678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5491338376970898678'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/06/cleaning-up-alienegocom-hack.html' title='Cleaning up the alienego.com hack'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-4238923184861683009</id><published>2011-06-01T08:56:00.007-04:00</published><updated>2011-06-27T20:43:55.480-04:00</updated><title type='text'>Cleaning up the try_pick_colors redef_colors malware.</title><summary type='text'>I have seen an up-tick in the number of sites hacked with the "try pick colors" (aka redef_colors)  hack in the last few weeks.  While this hack has mostly been associated with osCommerce sites, recently the hack has been showing up on increasing numbers of Wordpress and Joomla sites. The hack can, and does show up on virtually any type of site.

The first part of the hack is some obfuscated </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/4238923184861683009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/06/try-pick-colors-redef-colors.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4238923184861683009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4238923184861683009'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/06/try-pick-colors-redef-colors.html' title='Cleaning up the try_pick_colors redef_colors malware.'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-4048667084793057179</id><published>2011-05-16T16:45:00.006-04:00</published><updated>2011-06-22T13:59:04.429-04:00</updated><title type='text'>Cleaning up the imgaaa.net (or imgbbb or imgccc or imgddd.net) hack</title><summary type='text'>First, In all the img???.net hacks I have seen so far the hackers have gained access to the sites via stolen FTP credentials from a compromised PC. Do a scan of your PC and make sure there are no Trojans/viruses capturing your ids/passwords, use a couple of different security packages. Change ALL passwords especially FTP. Never store/save your passwords in your FTP client, use secure FTP if </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/4048667084793057179/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/05/cleaning-up-imgaaanet-or-imgbbb-or.html#comment-form' title='20 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4048667084793057179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4048667084793057179'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/05/cleaning-up-imgaaanet-or-imgbbb-or.html' title='Cleaning up the imgaaa.net (or imgbbb or imgccc or imgddd.net) hack'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>20</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-838916128599359058</id><published>2011-05-15T17:44:00.004-04:00</published><updated>2011-07-08T11:31:11.388-04:00</updated><title type='text'>So just who is a hackers best friend?  (just ranting)</title><summary type='text'>OK guys I am frustrated today and while I would advise that you should never ever post anything when frustrated I am going against my own advice.  So this is going to be nothing more than a rant and if I were you I would not bothering reading it.

So who is a hackers best friend?  After several years of looking at many 1000s of hacked websites I have come to the conclusion that without a doubt a </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/838916128599359058/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/05/so-just-who-is-hackers-best-friend.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/838916128599359058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/838916128599359058'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/05/so-just-who-is-hackers-best-friend.html' title='So just who is a hackers best friend?  (just ranting)'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-3893877009250226152</id><published>2011-05-14T15:56:00.001-04:00</published><updated>2011-05-14T16:22:57.087-04:00</updated><title type='text'>Using Xenu Link SleuthTM to find malicious code on your site.</title><summary type='text'>I saw a post this morning over on the Badwarebusters.org forum from a poster who was assisting a website owner in clearing a imgbbb.net hack. The post

hi, Your problem is the same to me, I look for links to imgbbb.net on the infected site using xenulink ( http://home.snafu.de/tilman/xenulink.html ).  by bk27info 
and thought now that sounds interesting lets give it a try. 

I went to the site </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/3893877009250226152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/05/using-xenu-link-sleuth-tm-to-find.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/3893877009250226152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/3893877009250226152'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/05/using-xenu-link-sleuth-tm-to-find.html' title='Using Xenu Link Sleuth&lt;sup&gt;TM&lt;/sup&gt; to find malicious code on your site.'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-hHwmrZefP04/Tc7b5FPiOHI/AAAAAAAAAFk/pDWE2aQ0ZOQ/s72-c/xenu-screen.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-2406368533332794046</id><published>2011-02-27T19:31:00.024-05:00</published><updated>2012-01-28T21:46:32.404-05:00</updated><title type='text'>Spam Hacks, The Pharmacy Hack, The Porn Hack, etc.</title><summary type='text'>The pharmacy hack remains one of the most common posts we see on the Google Webmaster Tools Forum.  The posts' start out with one of the following questions,  "Why has my site suddenly dropped from page 1 of Google search results to page 863?"  or "Why is Google reporting my most common keyword is viagra or cialis, I can not find those terms anywhere on my site?  A search using the site: operator</summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/2406368533332794046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/02/pharmacy-hack.html#comment-form' title='37 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/2406368533332794046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/2406368533332794046'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/02/pharmacy-hack.html' title='Spam Hacks, The Pharmacy Hack, The Porn Hack, etc.'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>37</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-1058566543939105588</id><published>2011-01-17T15:00:00.009-05:00</published><updated>2011-09-11T22:43:42.234-04:00</updated><title type='text'>Google Malware Warning  False Positive?</title><summary type='text'>If you are reading this article you are probably one of the rare readers who arrived on this blog from a search results page and I am afraid you are not going to like what I have to say on the topic, but I hope you will take the time to read through what I have to say. 

I spend a fair amount of time hanging out on Google's Webmaster Tools Forum, the Malware and Hacked sites category and on the </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/1058566543939105588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/01/malware-warning-false-positive.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/1058566543939105588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/1058566543939105588'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/01/malware-warning-false-positive.html' title='Google Malware Warning  False Positive?'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rvsS1gG1odA/TTRTkqD1K2I/AAAAAAAAACk/1kMOESgwXSE/s72-c/alt-false-positive.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-4597333970617366772</id><published>2011-01-13T16:33:00.023-05:00</published><updated>2012-01-09T23:12:36.805-05:00</updated><title type='text'>Google says my site is redirecting to a malicious site, but it seems to work fine? Conditional hacks</title><summary type='text'>When a site has been flagged by Google it is all too common for site owners to see this message in the malware section of their Webmaster Tools Account, "When Google last tested this page, no content was returned from your server. Instead, the browser was redirected to a malicious web page. It is likely that your server configuration has been modified." However, when the site owner navigates to </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/4597333970617366772/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2011/01/redirect-to-malicious-site.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4597333970617366772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4597333970617366772'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2011/01/redirect-to-malicious-site.html' title='Google says my site is redirecting to a malicious site, but it seems to work fine? Conditional hacks'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-5464679054496551112</id><published>2010-12-12T22:38:00.024-05:00</published><updated>2012-01-23T08:12:51.833-05:00</updated><title type='text'>How do I check .htaccess for malware</title><summary type='text'>* The .htaccess is an Apache (Apache like) web server system file.  If you are hosted on an IIS server stop reading you will not have a .htaccess file on your site.

The .htaccess file is an Apache system file which provides a way to make configuration changes on a per-directory basis.  The .htaccess file is not a "required" file and may not be present at all on your site.  There can be multiple </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/5464679054496551112/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/check-htaccess-for-malware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5464679054496551112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5464679054496551112'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/check-htaccess-for-malware.html' title='How do I check .htaccess for malware'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-8054831548400414051</id><published>2010-12-12T14:51:00.015-05:00</published><updated>2011-09-22T15:48:52.179-04:00</updated><title type='text'>This site may be compromised</title><summary type='text'>While checking your site's performance in the search results you are shocked to see the notice


This site may be compromised.


below the link to your homepage.  Jeeez Google what now??



The warning  This site may be compromised﻿  from Google is relatively new and has just begun to show up on search results pages. 





 Google has explained, "when we are indexing the pages of a site and we </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/8054831548400414051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/this-site-may-be-compromised.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/8054831548400414051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/8054831548400414051'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/this-site-may-be-compromised.html' title='This site may be compromised'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rvsS1gG1odA/TQUgH0sVAhI/AAAAAAAAAA8/y2oNO6eAXuM/s72-c/may-be-compromised.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-5311442778457165658</id><published>2010-12-12T09:46:00.023-05:00</published><updated>2011-07-08T18:04:30.776-04:00</updated><title type='text'>Google's Safe Browsing Diagnostic page</title><summary type='text'>Well, *&amp;#@ visitors to my site are getting the red screen of death and Google is advising that I check the Safe Browsing Diagnostic page for my site. OK I have checked it, what the heck does it mean?  What can I learn from the page and how is it going to help me in clearing my site?

Google's Safe Browsing Diagnostic page for any site can be accessed at

http://www.google.com/safebrowsing/</summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/5311442778457165658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/googles-safe-browsing-diagnostic-page.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5311442778457165658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/5311442778457165658'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/googles-safe-browsing-diagnostic-page.html' title='Google&apos;s Safe Browsing Diagnostic page'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rvsS1gG1odA/TQTkEhEBYOI/AAAAAAAAAAw/6BCUGCX8JYE/s72-c/diag-suspicious.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8226343625671207502.post-4235877319847205181</id><published>2010-12-11T14:44:00.013-05:00</published><updated>2011-06-29T17:57:59.303-04:00</updated><title type='text'>Why has Google suddenly flagged my site  (I haven't change anything in 10 years)</title><summary type='text'>So, your site/blog has been published for years, you have not changed anything, posted anything in months and all of the sudden your visitors have started getting warnings? It has to be a mistake, a False Positive, right? Chances are it is not!   In this post we will discuss a couple of scenarios where you have not changed anything yet your site is serving malware.

The first thing to check is </summary><link rel='replies' type='application/atom+xml' href='http://redleg-redleg.blogspot.com/feeds/4235877319847205181/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/why-has-google-suddenly-flagged-my-site.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4235877319847205181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8226343625671207502/posts/default/4235877319847205181'/><link rel='alternate' type='text/html' href='http://redleg-redleg.blogspot.com/2010/12/why-has-google-suddenly-flagged-my-site.html' title='Why has Google suddenly flagged my site &lt;br/&gt; (I haven&apos;t change anything in 10 years)'/><author><name>redleg</name><uri>http://www.blogger.com/profile/06857850551616773983</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/-mGlNZH1qLXo/Tgy5I67FouI/AAAAAAAAAIo/r61fgcdY07M/s220/redleg.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_rvsS1gG1odA/TQRch3gl7_I/AAAAAAAAAAs/M7N2wDaSLY0/s72-c/diag-page.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
