<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Script kiddies have awesome tools</title>
	<atom:link href="http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/</link>
	<description>no buzzwords allowed</description>
	<lastBuildDate>Wed, 10 Mar 2010 17:47:15 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: read this</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-20955</link>
		<dc:creator>read this</dc:creator>
		<pubDate>Fri, 06 Nov 2009 19:56:46 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-20955</guid>
		<description>Dman script kids, they got my WP infected with the &quot;eval(gzinflate(base64_decode(‘FJ3HcqPsFkUf&quot; crap, and never new what the hell it was behind it. I always kept deleting and reinstalling WP until I got the idea to change ALL my passwords and do a clean install. That took care of them.
Since then I always upgrade.</description>
		<content:encoded><![CDATA[<p>Dman script kids, they got my WP infected with the &#8220;eval(gzinflate(base64_decode(‘FJ3HcqPsFkUf&#8221; crap, and never new what the hell it was behind it. I always kept deleting and reinstalling WP until I got the idea to change ALL my passwords and do a clean install. That took care of them.<br />
Since then I always upgrade.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis Yusupoff</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-19199</link>
		<dc:creator>Dennis Yusupoff</dc:creator>
		<pubDate>Thu, 01 Oct 2009 09:11:59 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-19199</guid>
		<description>I&#039;ve got compromize my website even after installed mod_security. Moreover, php.ini has a lot of hardening options:
[code]
disable_functions = exec,system,shell_exec,passthru,phpinfo,proc_open,popen,shows_source
allow_url_include=0
allow_url_fopen=0
enable_dl=0
[/code]

and in apache conf set &quot;php_admin_value open_basedir /usr/local/www/site:/usr/local/php&quot;!

Thanks god, ClamAV knows about this script:
[code]
/usr/local/www/forum.site/httpdocs/c99.php: PHP.Rst-1 FOUND
/usr/local/www/forum.site/httpdocs/cache/drfgtt.php: PHP.Rst-1 FOUND
/usr/local/www/forum.site/httpdocs/xs_mod/images/index.php: PHP.Rst-1 FOUND
/usr/local/www/site/httpdocs/shop/images/other/prodaves/owertime.php: PHP.Rst-1 FOUND
/usr/local/www/site/httpdocs/shop/smarty/internals/lool.php: PHP.Rst-1 FOUND
/usr/local/www/site/httpdocs/shop/smarty/plugins/conf.phpmodifier.uppers.php: PHP.Rst-1 FOUND
/usr/local/www/site/httpdocs/reviews/rc_models/Protech_Razor/thumbnails/c99.php: PHP.Rst-1 FOUND
/usr/local/www/site/httpdocs/reviews/rc_models/Reflex_XTR/c99.php: PHP.Rst-1 FOUND
/usr/local/www/site/httpdocs/SHIP/mod.php: PHP.Rst-1 FOUND
[/code]</description>
		<content:encoded><![CDATA[<p>I&#8217;ve got compromize my website even after installed mod_security. Moreover, php.ini has a lot of hardening options:<br />
[code]<br />
disable_functions = exec,system,shell_exec,passthru,phpinfo,proc_open,popen,shows_source<br />
allow_url_include=0<br />
allow_url_fopen=0<br />
enable_dl=0<br />
[/code]</p>
<p>and in apache conf set &#8220;php_admin_value open_basedir /usr/local/www/site:/usr/local/php&#8221;!</p>
<p>Thanks god, ClamAV knows about this script:<br />
[code]<br />
/usr/local/www/forum.site/httpdocs/c99.php: PHP.Rst-1 FOUND<br />
/usr/local/www/forum.site/httpdocs/cache/drfgtt.php: PHP.Rst-1 FOUND<br />
/usr/local/www/forum.site/httpdocs/xs_mod/images/index.php: PHP.Rst-1 FOUND<br />
/usr/local/www/site/httpdocs/shop/images/other/prodaves/owertime.php: PHP.Rst-1 FOUND<br />
/usr/local/www/site/httpdocs/shop/smarty/internals/lool.php: PHP.Rst-1 FOUND<br />
/usr/local/www/site/httpdocs/shop/smarty/plugins/conf.phpmodifier.uppers.php: PHP.Rst-1 FOUND<br />
/usr/local/www/site/httpdocs/reviews/rc_models/Protech_Razor/thumbnails/c99.php: PHP.Rst-1 FOUND<br />
/usr/local/www/site/httpdocs/reviews/rc_models/Reflex_XTR/c99.php: PHP.Rst-1 FOUND<br />
/usr/local/www/site/httpdocs/SHIP/mod.php: PHP.Rst-1 FOUND<br />
[/code]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: B</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-18981</link>
		<dc:creator>B</dc:creator>
		<pubDate>Thu, 24 Sep 2009 13:31:38 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-18981</guid>
		<description>Yeah I recently found a similar thing on a compromised site. It called itself &quot;Locus7s Modified c100 Shell&quot;. It had the expected stuff like a file manager and self removal stuff but it also had some hardcore features for privilege escalation and kernel attacks. I was surprised at how advanced some of it was.</description>
		<content:encoded><![CDATA[<p>Yeah I recently found a similar thing on a compromised site. It called itself &#8220;Locus7s Modified c100 Shell&#8221;. It had the expected stuff like a file manager and self removal stuff but it also had some hardcore features for privilege escalation and kernel attacks. I was surprised at how advanced some of it was.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BEWERK &#124; web dingetjes</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-12247</link>
		<dc:creator>BEWERK &#124; web dingetjes</dc:creator>
		<pubDate>Mon, 18 May 2009 20:37:16 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-12247</guid>
		<description>[...] Script kiddies have awesome tools &#124; dow.ngra.de.   Categories: Besturings systemen, IT - Tags: [...]</description>
		<content:encoded><![CDATA[<p>[...] Script kiddies have awesome tools | dow.ngra.de.   Categories: Besturings systemen, IT &#8211; Tags: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tagz &#124; &#34;Script kiddies have awesome tools &#124; dow.ngra.de&#34; &#124; Comments</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-12088</link>
		<dc:creator>Tagz &#124; &#34;Script kiddies have awesome tools &#124; dow.ngra.de&#34; &#124; Comments</dc:creator>
		<pubDate>Sat, 16 May 2009 16:55:36 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-12088</guid>
		<description>[...]               [upmod] [downmod]     Script kiddies have awesome tools &#124; dow.ngra.de  (dow.ngra.de)    3 points posted 6 months, 1 week ago by SixSixSix  tags imported programming [...]</description>
		<content:encoded><![CDATA[<p>[...]               [upmod] [downmod]     Script kiddies have awesome tools | dow.ngra.de  (dow.ngra.de)    3 points posted 6 months, 1 week ago by SixSixSix  tags imported programming [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mitty Stone</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-5686</link>
		<dc:creator>Mitty Stone</dc:creator>
		<pubDate>Fri, 30 Jan 2009 10:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-5686</guid>
		<description>Shell creator site
http://madnet.name/files/1/10.html</description>
		<content:encoded><![CDATA[<p>Shell creator site<br />
<a href="http://madnet.name/files/1/10.html" rel="nofollow">http://madnet.name/files/1/10.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Toomas Römer</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-3768</link>
		<dc:creator>Toomas Römer</dc:creator>
		<pubDate>Tue, 25 Nov 2008 18:38:35 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-3768</guid>
		<description>@Flux Cool product, seems to be a firewall for HTTP :) Had not heard about it before.</description>
		<content:encoded><![CDATA[<p>@Flux Cool product, seems to be a firewall for HTTP :) Had not heard about it before.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Flux</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-3765</link>
		<dc:creator>Flux</dc:creator>
		<pubDate>Tue, 25 Nov 2008 17:28:30 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-3765</guid>
		<description>Not sure if it would have helped in this case, but run your web applications behind an application firewall like ModSecurity (http://www.modsecurity.org).

If you do use an app firewall, make sure that is actually blocking bad stuff and not just logging that it happened.</description>
		<content:encoded><![CDATA[<p>Not sure if it would have helped in this case, but run your web applications behind an application firewall like ModSecurity (<a href="http://www.modsecurity.org" rel="nofollow">http://www.modsecurity.org</a>).</p>
<p>If you do use an app firewall, make sure that is actually blocking bad stuff and not just logging that it happened.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bert Heymans</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-3130</link>
		<dc:creator>Bert Heymans</dc:creator>
		<pubDate>Wed, 05 Nov 2008 10:50:47 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-3130</guid>
		<description>Thanks for the Wordpress security awareness!</description>
		<content:encoded><![CDATA[<p>Thanks for the Wordpress security awareness!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Toomas Römer</title>
		<link>http://dow.ngra.de/2008/11/04/script-kiddies-have-awesome-tools/comment-page-1/#comment-3129</link>
		<dc:creator>Toomas Römer</dc:creator>
		<pubDate>Wed, 05 Nov 2008 07:23:26 +0000</pubDate>
		<guid isPermaLink="false">http://dow.ngra.de/?p=413#comment-3129</guid>
		<description>@Jon There is a link in the reddit thread, http://www.reddit.com/r/programming/comments/7bcsj/script_kiddies_have_awesome_tools/</description>
		<content:encoded><![CDATA[<p>@Jon There is a link in the reddit thread, <a href="http://www.reddit.com/r/programming/comments/7bcsj/script_kiddies_have_awesome_tools/" rel="nofollow">http://www.reddit.com/r/programming/comments/7bcsj/script_kiddies_have_awesome_tools/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
