<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2590733549034628316</id><updated>2012-01-29T19:41:33.974-08:00</updated><title type='text'>hpHosts Blog</title><subtitle type='html'>Blog for hpHosts, and whatever else I feel like writing about ....</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default?start-index=101&amp;max-results=100'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>868</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-53785897931683134</id><published>2012-01-27T19:03:00.000-08:00</published><updated>2012-01-27T19:13:07.537-08:00</updated><title type='text'>Formspring: 12,595 abusive pages later ....</title><summary type='text'>It's now been over a week since Formspring last replied (e-mails have been sent since, but no response).As such, I thought I'd list the current tally here again* - same criminals responsible as last time. You'd have thought that would make it easy to filter, especially given the keywords they're using are also exactly the same but alas - it seems they've resigned themselves to doing whatever it </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/53785897931683134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=53785897931683134' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/53785897931683134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/53785897931683134'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/formspring-12595-abusive-pages-later.html' title='Formspring: 12,595 abusive pages later ....'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2371339418015957759</id><published>2012-01-23T18:17:00.000-08:00</published><updated>2012-01-23T18:22:26.632-08:00</updated><title type='text'>securikai.com: In and out of common sense</title><summary type='text'>Oh dear, this isn't going to end well. To clarify folks - as securityerrata.org makes clear, there isn't a vulnerability here - it's a simple case of typo-squatting and attempted extortion.Introducing Arthur 'Wesley' Kenzie, aka SecurikaiLate in December of 2011, HD Moore received a curious email from "Arthur (Wesley) Kenzie" notifying him that Kenzie had "important information to discuss with </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2371339418015957759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2371339418015957759' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2371339418015957759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2371339418015957759'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/securikaicom-in-and-out-of-common-sense.html' title='securikai.com: In and out of common sense'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2366404034814938392</id><published>2012-01-22T18:23:00.000-08:00</published><updated>2012-01-22T18:29:18.220-08:00</updated><title type='text'>Formspring abuse: Oh dear ....</title><summary type='text'>Well, I was hopeful after their last response, that there was finally going to be a reduction, but sadly it appears this isn't the case.As of 2 seconds ago, the abuse is still prolific, and it's STILL the same parties responsible;1. download2d.com2. mSpyI've had no response from Formspring, to the e-mail I sent a few days ago, so god only knows what's going on over there, but until they get a </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2366404034814938392/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2366404034814938392' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2366404034814938392'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2366404034814938392'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/formspring-abuse-oh-dear.html' title='Formspring abuse: Oh dear ....'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2130761174055071065</id><published>2012-01-20T05:55:00.000-08:00</published><updated>2012-01-20T06:05:39.822-08:00</updated><title type='text'>Formspring continued - this time it's download2d.com as the MITM</title><summary type='text'>Well, seems they're not keeping on top of it that well, still a few from this morning still active;http://www.formspring.me/kifihiclihttp://www.formspring.me/rytelnucomhttp://www.formspring.me/abarlaforhttp://www.formspring.me/engatreperhttp://www.formspring.me/erlasticenhttp://www.formspring.me/pharigeschlinghttp://www.formspring.me/unelsenlahttp://www.formspring.me/inphabalrahttp://</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2130761174055071065/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2130761174055071065' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2130761174055071065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2130761174055071065'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/formspring-continued-this-time-its.html' title='Formspring continued - this time it&apos;s download2d.com as the MITM'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1908393572780427598</id><published>2012-01-19T20:35:00.001-08:00</published><updated>2012-01-19T20:41:32.394-08:00</updated><title type='text'>Formspring.me update</title><summary type='text'>I am pleased to report, I've been monitoring the Formspring.me abuse and they're now keeping on top of it, so all abusive pages created, are now being taken down relatively quickly.Still seems to be the same IP responsible for at least part of the abuse (188.143.232.113 - IP is well known for comment spam). Whether or not this is the same IP actually creating them in the first place, is something</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1908393572780427598/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1908393572780427598' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1908393572780427598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1908393572780427598'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/formspringme-update.html' title='Formspring.me update'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8673777628202329213</id><published>2012-01-19T20:31:00.000-08:00</published><updated>2012-01-19T20:35:11.326-08:00</updated><title type='text'>fSpamlist.com down temporarily</title><summary type='text'>Due to a power failure yesterday, the fSpamlist.com server was down from approx 21:20 (GMT London) until I woke up (around 40 minutes later) and fixed the issue. Sadly it turned out the power failure had corrupted not only the file system, but the MFT and MBR. This was fixed and the server brought back online.However, further corruption has been found in the PHP installation, preventing the sites</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8673777628202329213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8673777628202329213' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8673777628202329213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8673777628202329213'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/fspamlistcom-down-temporarily.html' title='fSpamlist.com down temporarily'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1119505995493429477</id><published>2012-01-18T21:01:00.000-08:00</published><updated>2012-01-18T23:55:04.879-08:00</updated><title type='text'>Alert: Eventbee.com abuse</title><summary type='text'>The formspring.me abuse is continuing, but in the meantime, it looks like they're having a bash on eventbee.com too.http://www.eventbee.com/v/pharm/event?eid=839465373http://www.eventbee.com/v/pharm/event?eid=809069363http://www.eventbee.com/v/pharm/event?eid=830974301http://www.eventbee.com/v/pharm/event?eid=849867363http://www.eventbee.com/v/pharm/event?eid=879564391http://www.eventbee.com/v/</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1119505995493429477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1119505995493429477' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1119505995493429477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1119505995493429477'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/alert-eventbeecom-abuse.html' title='Alert: Eventbee.com abuse'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-7813231024594177921</id><published>2012-01-17T17:18:00.000-08:00</published><updated>2012-01-17T17:22:07.228-08:00</updated><title type='text'>Formspring.me: Second verse, same as the first</title><summary type='text'>As of this morning, the current tally for 2012 (Formspring were dropped an e-mail yesterday, and will be dropped another one in a few minutes as whatever they're doing to prevent this, evidently isn't working);18/01/2012 01:15    http://www.formspring.me/warphororo18/01/2012 01:12    http://www.formspring.me/derslitemppe18/01/2012 01:08    http://www.formspring.me/heitaistorab18/01/2012 01:05    </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/7813231024594177921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=7813231024594177921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7813231024594177921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7813231024594177921'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/formspringme-second-verse-same-as-first.html' title='Formspring.me: Second verse, same as the first'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2919582784378877110</id><published>2012-01-17T10:41:00.000-08:00</published><updated>2012-01-17T13:31:35.749-08:00</updated><title type='text'>DomainMonster.com outage</title><summary type='text'>Looks like there's problems in the DomainMonster.com camp today. Their phones are coming back as temporarily unavailable, and whilst their website is working, mail servers seem to be down. The it-mate.co.uk incoming mail server is through DomainMonster, and sporadically failing, which sadly means I can send e-mails (different server), but can't receive them.I've tried both numbers available for </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2919582784378877110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2919582784378877110' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2919582784378877110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2919582784378877110'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/domainmonstercom-outage.html' title='DomainMonster.com outage'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2151791128548495617</id><published>2012-01-16T14:13:00.000-08:00</published><updated>2012-01-16T14:20:44.403-08:00</updated><title type='text'>Formspring.me abuse continuing</title><summary type='text'>Looks like Formspring still haven't pulled their finger out as the abuse over there is still drastically on-going, with no signs of anything changing.The latest batch includes;http://www.formspring.me/goamithedehttp://www.formspring.me/abteaneebehttp://www.formspring.me/adcommingsyndhttp://www.formspring.me/afodgageshttp://www.formspring.me/aftethenlanghttp://www.formspring.me/agunprosorhttp://</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2151791128548495617/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2151791128548495617' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2151791128548495617'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2151791128548495617'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/formspringme-abuse-continuing.html' title='Formspring.me abuse continuing'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-7Yjiq2AgZt0/TxShn-M_MdI/AAAAAAAAA60/Q_kNQ4L_Lbo/s72-c/imgformspring_me_-_mspy.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8444768502601871099</id><published>2012-01-02T12:03:00.001-08:00</published><updated>2012-01-02T12:50:01.758-08:00</updated><title type='text'>iLivid: Still using highly misleading marketing</title><summary type='text'>Checking a newly registered site (videocelebritynews.com), I stumbled upon what I thought at first, was going to be the usual fake codec notice that tends to lead to a trojan. Hovering over the image however, immediately pointed to its being an advert, rather than the typical fake codec stuff we're used to seeing.Following the URL led straight to an iLivid executable;1. hxxp://</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8444768502601871099/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8444768502601871099' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8444768502601871099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8444768502601871099'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2012/01/ilivid-still-using-highly-misleading.html' title='iLivid: Still using highly misleading marketing'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-rfLQuUonX1I/TwIN0ihWpuI/AAAAAAAAA6c/S9WJZQERM9w/s72-c/imgilivid_misleading_advertising-02012012.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5958896738283102251</id><published>2011-12-31T17:12:00.000-08:00</published><updated>2011-12-31T17:18:31.534-08:00</updated><title type='text'>Happy New Year!</title><summary type='text'>I know it's not 2012 everywhere yet, but it is here, so happy new year everyone!.2011 has been an exceptionally strange, and sometimes downright frustrating year, and I doubt 2012 will be any different as I don't forsee some of the hosting companies/registrars attitudes changing, nor do I see ICANN or Ripe/Arin et al, getting off their backside and doing their damn job for a change.However, 2011 </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5958896738283102251/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5958896738283102251' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5958896738283102251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5958896738283102251'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/happy-new-year.html' title='Happy New Year!'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6026398516892283729</id><published>2011-12-30T01:34:00.000-08:00</published><updated>2011-12-30T01:35:06.684-08:00</updated><title type='text'>hpHOSTS - UPDATED 29th December 2011</title><summary type='text'>The hpHOSTS Hosts file has been updated. There is now a total of 230,392 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 29/12/2011 00:15Last Verified: 28/12/2011 22:33Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6026398516892283729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6026398516892283729' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6026398516892283729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6026398516892283729'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/hphosts-updated-29th-december-2011.html' title='hpHOSTS - UPDATED 29th December 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2628408075560881245</id><published>2011-12-28T18:27:00.000-08:00</published><updated>2011-12-28T18:28:11.848-08:00</updated><title type='text'>hpHosts server issues</title><summary type='text'>Due to technical problems, the hpHosts server including the site and forums, will be down for a few hours.My apologies for any inconvenience.</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2628408075560881245/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2628408075560881245' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2628408075560881245'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2628408075560881245'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/hphosts-server-issues.html' title='hpHosts server issues'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-237425450821228163</id><published>2011-12-21T12:03:00.000-08:00</published><updated>2011-12-21T12:09:48.558-08:00</updated><title type='text'>Ransomware impersonating law enforcement</title><summary type='text'>Ransomware, the practice of providing fake notifications that “you’re infected” and then selling a fake solution that removes the fake malware they just installed, has been a boon for scammers. Now, they’re taking it a step farther, and throwing in a law enforcement scare.This time, an official-looking banner pops up, purporting to be from various law enforcement agencies, localized by region, </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/237425450821228163/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=237425450821228163' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/237425450821228163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/237425450821228163'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/ransomware-impersonating-law.html' title='Ransomware impersonating law enforcement'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-pUbFSzQmZB4/TvI8scACNBI/AAAAAAAAA6Q/b3fHoSWXKPU/s72-c/imgRansomware_LE.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8601343469763535488</id><published>2011-12-09T21:40:00.000-08:00</published><updated>2011-12-19T21:54:56.680-08:00</updated><title type='text'>Dear HostNOC - your servers are attacking a friend!</title><summary type='text'>I am assisting a friend at present, with an issue involving IPs constantly attacking his servers, and noted during one of his recent updates, that alot of them were HostNOC - turns out, there's quite the list of them (ignoring the others from known criminal networks). All are RFI etc, and all are already being blocked by ZBBlock (a script written by my friend Zaphod).The problem here, is HostNOCs</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8601343469763535488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8601343469763535488' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8601343469763535488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8601343469763535488'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/dear-hostnoc-your-servers-are-attacking.html' title='Dear HostNOC - your servers are attacking a friend!'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6795505404639628655</id><published>2011-12-09T12:21:00.000-08:00</published><updated>2011-12-23T12:58:32.367-08:00</updated><title type='text'>Blackhole exploit: For those wondering, Part 4 - Now its Amazons turn</title><summary type='text'>This one came in whilst I was asleep, no JS MITMs this time, just the link in the e-mail that uses a meta refresh to redirect you to the domain housing the Blackhole exploit itself;Hello,Shipping ConfirmationOrder # 651-5411744-0155168 &lt;http://ar.news.assyrianchurch.com/wp-content/uploads/fgallery/stay.html&gt;  Your estimated delivery date is:Tuesday, December 13, 2011Track your package &lt;http://</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6795505404639628655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6795505404639628655' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6795505404639628655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6795505404639628655'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/blackhole-exploit-for-those-wondering_3980.html' title='Blackhole exploit: For those wondering, Part 4 - Now its Amazons turn'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8454683861237192532</id><published>2011-12-08T22:29:00.000-08:00</published><updated>2011-12-08T22:58:17.785-08:00</updated><title type='text'>Blackhole exploit: For those wondering, Part 3 - Fake Facebook e-mail</title><summary type='text'>This one came in an e-mail claiming to be from Facebook, with the usual social engineering rubbish;facebook &lt;http://static77-68-16-117.live-dsl.net:8887/facebook-friend1/2t4bv271&gt;   Hi,You haven't been back to Facebook recently.You have received notifications while you were gone. &lt;http://static.ak.fbcdn.net/rsrc.php/v1/yS/r/I-6WhcLLGrb.gif&gt;   1 message &lt;http://static77-68-16-117.live-dsl.net:8887</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8454683861237192532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8454683861237192532' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8454683861237192532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8454683861237192532'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/blackhole-exploit-for-those-wondering_08.html' title='Blackhole exploit: For those wondering, Part 3 - Fake Facebook e-mail'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-vc9XHDq0pzc/TuGrxMiJyGI/AAAAAAAAA5U/YhH75qsDj6M/s72-c/imgFake_Facebook_email.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8444970995321369187</id><published>2011-12-08T11:55:00.000-08:00</published><updated>2011-12-08T12:09:16.166-08:00</updated><title type='text'>Fake Firefox e-mail leading to SpyEye trojan</title><summary type='text'>This little chap arrived in my spam box today, and almost got over-looked (I was checking the newest e-mails leading to the Blackhole exploit (one of which, couldn't decide if it was from LinkedIn or the FDIC)), and not surprisingly, is fake.The Payload, all 593KB of it, infects the unwitting victim with the SpyEye trojan. VT detection is utterly rubbish of course - only 2 vendors detecting </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8444970995321369187/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8444970995321369187' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8444970995321369187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8444970995321369187'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/fake-firefox-e-mail-leading-to-spyeye.html' title='Fake Firefox e-mail leading to SpyEye trojan'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-i37aVWUXas8/TuEW06JshuI/AAAAAAAAA5I/mP-6N84KUFo/s72-c/imgFake_Firefox_-_static77-68-16-117.live-dsl.net.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-9132086541921831721</id><published>2011-12-05T10:01:00.000-08:00</published><updated>2011-12-05T10:14:58.668-08:00</updated><title type='text'>Blackhole exploit: For those wondering, Part 2</title><summary type='text'>I received a comment to the 2009 blog. This one houses a variation of the MO used that I outlined in part 1 (was not going to be a part 2, but it's got a few changes that warranted it).The MO in this case, is;1. Site A2. ExploitThere's no MITMs this time. There's also a slight change in the code used on the exploit page itself, though curiously, it's even easier to decode than the last one (only </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/9132086541921831721/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=9132086541921831721' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/9132086541921831721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/9132086541921831721'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/blackhole-exploit-for-those-wondering_05.html' title='Blackhole exploit: For those wondering, Part 2'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-217727824197583427</id><published>2011-12-05T03:01:00.000-08:00</published><updated>2011-12-05T04:58:26.045-08:00</updated><title type='text'>Blackhole exploit: For those wondering</title><summary type='text'>For those wondering and not yet aware. The latest incarnations coming via e-mail have changed MO - the link to the exploit itself, isn't directly in the e-mail anymore. Instead, it goes via;1. Site A2. 4 x MITMs5. Exploit siteIn this case;cadcamengineers.com/6ebc21/index.html-&gt; napaul.com/statcounters.js-&gt; proplastics.rs/statcounters.js-&gt; rodns.eu/statcounters.js-&gt; sashandbow.com.au/</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/217727824197583427/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=217727824197583427' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/217727824197583427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/217727824197583427'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/12/blackhole-exploit-for-those-wondering.html' title='Blackhole exploit: For those wondering'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-mUfOypc45Bk/Ttyr42qS_3I/AAAAAAAAA4k/V51Gxr54zOU/s72-c/imgcadcamengineers_com.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-334621749327773745</id><published>2011-11-30T08:39:00.000-08:00</published><updated>2012-01-17T19:36:52.460-08:00</updated><title type='text'>Eset: Support-Scammer Tricks</title><summary type='text'>Having been blogging this topic for quite a while, I figure this might be a good time to highlight some of the snippets of information that people have posted on some of those blogs (anonymized, of course). You might also be interested in a resource page I've started here at AVIEN.One prospective victim instructed to connect via the Run window to www.support.me. This turns out to belong to </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/334621749327773745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=334621749327773745' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/334621749327773745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/334621749327773745'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/11/eset-support-scammer-tricks.html' title='Eset: Support-Scammer Tricks'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3596970071115101910</id><published>2011-11-21T12:12:00.000-08:00</published><updated>2011-11-21T12:13:04.974-08:00</updated><title type='text'>hpHOSTS - UPDATED November 21st, 2011</title><summary type='text'>The hpHOSTS Hosts file has been updated. There is now a total of 216,044 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 21/11/2011 18:30Last Verified: 21/11/2011 19:00Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3596970071115101910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3596970071115101910' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3596970071115101910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3596970071115101910'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/11/hphosts-updated-november-21st-2011.html' title='hpHOSTS - UPDATED November 21st, 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5206601233897781582</id><published>2011-11-15T23:17:00.001-08:00</published><updated>2011-11-15T23:20:40.741-08:00</updated><title type='text'>up-yours.com - Here we go again</title><summary type='text'>I thought I'd made this clear, but apparently not. I got an e-mail earlier, from a RoadRunner IP (residential US ISP), using an @up-yours.com address.There's two problems here however;1. It's an invalid address, so can't reply2. The e-mail houses a childish threat, without actually telling me what I did to deserve it*********************************************************************General*****</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5206601233897781582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5206601233897781582' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5206601233897781582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5206601233897781582'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/11/up-yourscom-here-we-go-again.html' title='up-yours.com - Here we go again'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6740154550950165230</id><published>2011-11-13T16:29:00.000-08:00</published><updated>2011-11-13T16:36:23.409-08:00</updated><title type='text'>Lavasoft gone dodgy?</title><summary type='text'>According to a post at my favorite news site, it looks like Lavasoft' new owners are the infamous chaps behind the well known "Interactive Brands". Should've seen this coming really, given they de-listed the well known malware player, WhenU, some time ago - I know that was 6 years ago, but it can't just be a coincidence, especially given who the new owners are.Anti-spyware company Lavasoft AB is </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6740154550950165230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6740154550950165230' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6740154550950165230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6740154550950165230'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/11/lavasoft-gone-dodgy.html' title='Lavasoft gone dodgy?'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-7586338626628458632</id><published>2011-11-11T05:03:00.001-08:00</published><updated>2011-11-11T05:32:04.950-08:00</updated><title type='text'>Internet.bs still not accepting abuse reports</title><summary type='text'>You may remember, in September I blogged about Internet.BS, well known as a bulletproof provider for domain registrations.Sadly, neither Verisign nor ICANN have done anything, and Internet.bs are still refusing reports (I say refusing because whilst the error is a 450, they were notified months ago and it's still producing the same error, preventing reports going through), courtesy of the Gmail </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/7586338626628458632/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=7586338626628458632' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7586338626628458632'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7586338626628458632'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/11/internetbs-still-not-accepting-abuse.html' title='Internet.bs still not accepting abuse reports'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-303966557802664286</id><published>2011-11-09T13:32:00.000-08:00</published><updated>2011-11-09T13:33:51.542-08:00</updated><title type='text'>Facebook Likes and cold-call scams</title><summary type='text'>Following an article I wrote recently for SC Magazine, Martijn Grooten of Virus Bulletin, who shares my interest in and dislike of support desk scams, contacted me about the web site associated with eFIX, a company claiming to offer online technical support. He and I, along with Steven Burn, who has a great deal of experience of working in this area, have been able to dig out some interesting </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/303966557802664286/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=303966557802664286' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/303966557802664286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/303966557802664286'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/11/facebook-likes-and-cold-call-scams.html' title='Facebook Likes and cold-call scams'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-7033769450486038155</id><published>2011-11-01T17:26:00.001-07:00</published><updated>2011-11-01T17:37:14.314-07:00</updated><title type='text'>webhosting.info compromised</title><summary type='text'>Look at the image on the left. See anything that shouldn't be there?I'll give you a hint - it's got a black background.I identified this whilst doing a routine enquiry on an IP housing a plethora of fake meds sites. I dropped a note to the sites owner and registrar, who informed me it most definitely should NOT be there.The content in question, is;&lt;script type="text/javascript" src="http://</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/7033769450486038155/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=7033769450486038155' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7033769450486038155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7033769450486038155'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/11/webhostinginfo-compromised.html' title='webhosting.info compromised'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Q-utPk3qAyc/TrCOUfmLA8I/AAAAAAAAA4Y/owSb58EzhJk/s72-c/imgwebhosting.info.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1644733844302977724</id><published>2011-10-24T12:34:00.000-07:00</published><updated>2011-10-24T12:35:53.110-07:00</updated><title type='text'>hpHOSTS - UPDATED October 24th, 2011</title><summary type='text'>The hpHOSTS Hosts file has been updated. There is now a total of 212,624 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 24/10/2011 19:40Last Verified: 23/10/2011 17:00Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1644733844302977724/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1644733844302977724' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1644733844302977724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1644733844302977724'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/10/hphosts-updated-october-24th-2011.html' title='hpHOSTS - UPDATED October 24th, 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6113638798784352285</id><published>2011-10-18T17:32:00.000-07:00</published><updated>2011-10-18T17:50:45.020-07:00</updated><title type='text'>Dear Cronon.net/rzone.de</title><summary type='text'>I received 4 spam e-mails earlier that housed 4 links pointing to zip files on 4 sites housed on rZone.de (Cronon) IP space - all of the files contain trojans - more on that later.As I normally do, I tried dropping the address listed in the net-block info an e-mail (cmueller@cronon.net and abuse@cronon.net), sadly it seems they don't want to receive abuse reports;Mail delivery to the following </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6113638798784352285/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6113638798784352285' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6113638798784352285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6113638798784352285'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/10/dear-crononnetrzonede.html' title='Dear Cronon.net/rzone.de'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3855311309614726876</id><published>2011-10-10T22:42:00.000-07:00</published><updated>2011-10-10T22:45:08.961-07:00</updated><title type='text'>Some TDL/TDSS rootkit sites to block</title><summary type='text'>From my friend Conrad;The following IPs are related to the TDL/TDSS rootkit. 212.36.9.52 / gic-kbmtu0zkvwylf.com appears to be a C&amp;C server. 94.63.149.1094.63.149.1194.63.149.1294.63.149.1394.63.149.1494.63.149.15146.185.250.140146.185.250.141195.3.145.251195.3.145.252195.3.145.253212.36.9.5294.63.149.0/24 is a Romanian host called Eurolan Solutions SRL, I've had this blocked for months with no </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3855311309614726876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3855311309614726876' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3855311309614726876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3855311309614726876'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/10/some-tdltdss-rootkit-sites-to-block.html' title='Some TDL/TDSS rootkit sites to block'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3222503579492629196</id><published>2011-10-08T19:10:00.000-07:00</published><updated>2011-10-08T19:31:10.676-07:00</updated><title type='text'>ALERT: microsoft-key.com, 91.217.153.17</title><summary type='text'>microsoft-key.com was registered through the well known criminal friendly, BIZCN on October 7th (key-microsoft.com existed previously, same IP range), and not surprisingly, is up to no good. The domain is presently only in German for some reason (auto-redirs to /de-DE/, and no other language dirs seem to exist).A translation via Google, since I don't speak German, shows;Welcome to the Microsoft </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3222503579492629196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3222503579492629196' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3222503579492629196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3222503579492629196'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/10/alert-microsoft-keycom-9121715317.html' title='ALERT: microsoft-key.com, 91.217.153.17'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-I9Pltnnr4dE/TpEEhUW6xcI/AAAAAAAAA4A/VxzYuyucTmo/s72-c/imgmicrosoft-key_com.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-669302336595880928</id><published>2011-10-05T17:01:00.000-07:00</published><updated>2011-10-05T17:04:00.105-07:00</updated><title type='text'>RIP Steve Jobs, and a warning to keep your eyes peeled</title><summary type='text'>Apple have announced the death of Steve Jobs, former CEO of Apple.http://www.apple.com/stevejobs/You can bet your life that the blackhat SEO gangs will be on to this like a rash in the next few hours, so please be extra careful out there.</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/669302336595880928/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=669302336595880928' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/669302336595880928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/669302336595880928'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/10/rip-steve-jobs-and-warning-to-keep-your.html' title='RIP Steve Jobs, and a warning to keep your eyes peeled'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6394215527284113046</id><published>2011-09-29T11:14:00.000-07:00</published><updated>2011-09-29T11:16:07.535-07:00</updated><title type='text'>hpHosts: Updated 29-09-2011</title><summary type='text'>Sorry for the delay folks.The hpHOSTS Hosts file has been updated. There is now a total of 222,922 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 29/09/2011 18:00Last Verified: 29/09/2011 01:00Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6394215527284113046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6394215527284113046' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6394215527284113046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6394215527284113046'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/hphosts-updated-29-09-2011.html' title='hpHosts: Updated 29-09-2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2798578554514774005</id><published>2011-09-28T15:47:00.000-07:00</published><updated>2011-09-28T15:50:54.399-07:00</updated><title type='text'>Dear internet.bs ....</title><summary type='text'>Q. How do you tell when a registrar is generating alot of abuse reports?A. When you receive failure messages such as;This is the mail system at host us.internet.bs.I'm sorry to have to inform you that your message could notbe delivered to one or more recipients. It's attached below.For further assistance, please send mail to postmaster.If you do so, please include this problem report. You </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2798578554514774005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2798578554514774005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2798578554514774005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2798578554514774005'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/dear-internetbs.html' title='Dear internet.bs ....'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3774717003240518570</id><published>2011-09-27T16:16:00.000-07:00</published><updated>2011-09-27T16:17:40.544-07:00</updated><title type='text'>Microsoft Security Advisory: Vulnerability in SSL/TLS Could Allow Information Disclosure</title><summary type='text'>Executive SummaryMicrosoft is aware of detailed information that has been published describing a new method to exploit a vulnerability in SSL 3.0 and TLS 1.0, affecting the Windows operating system. This vulnerability affects the protocol itself and is not specific to the Windows operating system. This is an information disclosure vulnerability that allows the decryption of encrypted SSL/TLS </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3774717003240518570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3774717003240518570' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3774717003240518570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3774717003240518570'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/microsoft-security-advisory.html' title='Microsoft Security Advisory: Vulnerability in SSL/TLS Could Allow Information Disclosure'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1144642620475617770</id><published>2011-09-21T12:50:00.000-07:00</published><updated>2011-09-21T12:53:28.766-07:00</updated><title type='text'>Microsoft dumps partner over telephone scam claims</title><summary type='text'>About bleedin time too.One of Microsoft's Gold Partners has had its relationship with the software giant unceremoniously terminated, after being revealed to be orchestrating a telephone support scam.Comantra, based in India, are said to have cold-called computer users in the UK, Australia, Canada and elsewhere, claiming to offer assistance in cleaning up virus infections.The bogus support calls </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1144642620475617770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1144642620475617770' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1144642620475617770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1144642620475617770'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/microsoft-dumps-partner-over-telephone.html' title='Microsoft dumps partner over telephone scam claims'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4055742615607620479</id><published>2011-09-17T18:50:00.000-07:00</published><updated>2011-09-17T19:08:00.133-07:00</updated><title type='text'>Alert: 70.85.43.147</title><summary type='text'>I was sent a URL earlier, that redirected to fake meds (surprise surprise). Checking further however, I arrived at the sites homepage to discover two scripts being loaded, one from a site that has now been cleaned, and another loaded from 70.85.43.147, that is still there;70.85.43.147/minitools.jsTrying a quick check, Malzilla, JSUnpack etc failed to decode it, so I figured I'd wait until I had a</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4055742615607620479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4055742615607620479' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4055742615607620479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4055742615607620479'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/alert-708543147.html' title='Alert: 70.85.43.147'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-O-bzrnQgFRo/TnVPqJKNENI/AAAAAAAAA3o/H7PaQMRK3Hc/s72-c/img70.85.43.147_minitools_js.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-7070805184687948184</id><published>2011-09-16T11:36:00.000-07:00</published><updated>2011-09-16T11:45:29.018-07:00</updated><title type='text'>Alert: Formspring abuse continuing.</title><summary type='text'>Not surprisingly, when the bad guys get a foot in, they take full advantage, and that's exactly what they're doing over at Formspring.me. Having started a campaign, and Formspring seemingly doing nothing to prevent it, the surge is continuing, with new ones being created every day so far.Thanks to someone that used to work for them, those that were reported to him, have been taken care of, but </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/7070805184687948184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=7070805184687948184' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7070805184687948184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7070805184687948184'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/alert-formspring-abuse-continuing.html' title='Alert: Formspring abuse continuing.'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-i3EOML0AuH8/TnOZKRXQOII/AAAAAAAAA3g/pFYvKHJrqZM/s72-c/imgformspring.me_contrumretivi.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5429704515017280541</id><published>2011-09-12T18:33:00.000-07:00</published><updated>2011-09-12T18:35:35.830-07:00</updated><title type='text'>Spambot Search Tool v0.53</title><summary type='text'>Date: 13-09-2011* Modified LogSpammerToDB (with thanks to Jay Riley, jayriley.com)+ Added blocklist.deDownload:http://support.it-mate.co.uk/?mode=Products&amp;p=spambotsearchtoolLive example:http://temerc.com/Check_Spammers/http://fspamlist.com/checkspammers/</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5429704515017280541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5429704515017280541' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5429704515017280541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5429704515017280541'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/spambot-search-tool-v053.html' title='Spambot Search Tool v0.53'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5960362103824863975</id><published>2011-09-09T19:11:00.000-07:00</published><updated>2011-09-09T19:35:45.002-07:00</updated><title type='text'>Alert: formspring.me abuse surge</title><summary type='text'>Seems there's somewhat of a surge of abuse over at formspring.com lately, same kind of abuse seen previously on similar providers.The following, all leading to varying locations, are currently active, and have been reported to the upstream, since Formspring don't want to publicize an abuse contact (CC'd the report to the address listed in the WhoIs for formspring' parent company).hxxp://</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5960362103824863975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5960362103824863975' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5960362103824863975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5960362103824863975'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/alert-formspringme-abuse-surge.html' title='Alert: formspring.me abuse surge'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8335265972478172648</id><published>2011-09-06T06:11:00.000-07:00</published><updated>2011-09-06T06:21:09.293-07:00</updated><title type='text'>Alert: 69.64.72.123 (Sinowal/Mebroot)</title><summary type='text'>New domains today, still only 71 unique MD5s, and all domains living at;IP: 69.64.72.123PTR: 69-64-72-123.dedicated.codero.netNS: *.dns-diy.netAS: 10316 69.64.64.0/19 CODERO-AS - CoderoSame registrar as all of the rest;Registrant: Frank Jorney / jormwyuh4@hotmail.comRegistrar: ONLINENIC, INC367u3hsl.com/files/18367u3hsl.com/files/19367u3hsl.com/files/23367u3hsl.com/files/24367u3hsl.com/files/</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8335265972478172648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8335265972478172648' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8335265972478172648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8335265972478172648'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/alert-696472123-sinowalmebroot.html' title='Alert: 69.64.72.123 (Sinowal/Mebroot)'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6425874093737043025</id><published>2011-09-03T05:02:00.000-07:00</published><updated>2011-09-03T05:06:50.282-07:00</updated><title type='text'>Alert: 67.210.105.156</title><summary type='text'>Well, yesterday Sinowall was at 108.59.2.213, as of today, there's 2 new domains and a new IP - still the same amount of files, same 71 unique MD5s;sghlymfsbvf.com/files/18 Trojan.Agentsghlymfsbvf.com/files/19 Trojan.Agentsghlymfsbvf.com/files/23 Trojan.Agentsghlymfsbvf.com/files/24 Trojan.Agentsghlymfsbvf.com/files/25 Trojan.Agentsghlymfsbvf.com/files/26 Trojan.Agentsghlymfsbvf.com/files</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6425874093737043025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6425874093737043025' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6425874093737043025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6425874093737043025'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/alert-67210105156.html' title='Alert: 67.210.105.156'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4456023983095407153</id><published>2011-09-02T06:11:00.000-07:00</published><updated>2011-09-02T07:17:18.230-07:00</updated><title type='text'>Alert: 108.59.2.213</title><summary type='text'>Q. What do you get if you cross 108.59.2.213 with a bunch of newly created domains?A. Over 600 newly malicious URLs of course!There's actually only a very small amount of domains, but 91 URLs to each domain, serving a grand total across them all, of 498 files and 71 unique MD5s;File    MD5    Sizef88deaeb24ee0ae8f783ed61c8508b37    aguyet47td.com\files\17    2.00 KB</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4456023983095407153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4456023983095407153' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4456023983095407153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4456023983095407153'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/alert-108592213.html' title='Alert: 108.59.2.213'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6253923895234882582</id><published>2011-09-01T18:59:00.001-07:00</published><updated>2011-09-02T05:46:09.699-07:00</updated><title type='text'>co.tv update: Sorry chaps, you're not doing enough</title><summary type='text'>co.tv have had quite the history, with a plethora of abuse of their service. They've previously been responsive as far as takedowns, but lately there's been no response, and those reported over the past week, have remained active.A lot of the domains are pointing to an IP that resolves to parking.co.tv, but this isn't actually a parking server - it is a redirector;Query: fuqayisi.co.tvHTTP/</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6253923895234882582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6253923895234882582' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6253923895234882582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6253923895234882582'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/09/cotv-update-sorry-chaps-youre-not-doing.html' title='co.tv update: Sorry chaps, you&apos;re not doing enough'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-9D4gF5L7hZY/TmA5trIMWyI/AAAAAAAAA3Y/cYxypzamMJQ/s72-c/imgfuqayisi.co.tv_pharmacyas_com.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8575723240903578506</id><published>2011-08-28T18:54:00.001-07:00</published><updated>2011-08-28T19:53:50.434-07:00</updated><title type='text'>Finally: co.tv cancels free "domain" registration service!</title><summary type='text'>Certainly took them long enough, but having been the latest service to be bombarded and misused by criminals, it seems at least one of the many heavily abused providers has seen sense and cancelled the option to create a free "domain" through them.If you've been taking note, you'll have noticed the sheer volume of hostnames created on *.co.tv that have been involved in fake meds and exploits. </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8575723240903578506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8575723240903578506' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8575723240903578506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8575723240903578506'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/finally-cotv-cancels-free-domain.html' title='Finally: co.tv cancels free &quot;domain&quot; registration service!'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-fxfKSFJNCa4/TlrxpRbeh4I/AAAAAAAAA3Q/WBN-CVShe1A/s72-c/imgco_tv.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4247937641760806177</id><published>2011-08-27T20:49:00.000-07:00</published><updated>2011-08-27T20:54:06.171-07:00</updated><title type='text'>ALERT: clickme**.fileave.com Part 2</title><summary type='text'>And courtesy of my friend Anthony at MalwareURL (and I'm shamefully admitting to not thinking of checking this myself), here comes another 328 of them;http://clickmeaa.fileave.com/http://clickmeab.fileave.com/http://clickmeac.fileave.com/http://clickmead.fileave.com/http://clickmeae.fileave.com/http://clickmeaf.fileave.com/http://clickmeag.fileave.com/http://clickmeah.fileave.com/http:/</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4247937641760806177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4247937641760806177' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4247937641760806177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4247937641760806177'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/alert-clickmefileavecom-part-2.html' title='ALERT: clickme**.fileave.com Part 2'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1675073286840791146</id><published>2011-08-27T18:39:00.000-07:00</published><updated>2011-08-27T19:15:31.047-07:00</updated><title type='text'>ALERT: clickme**.fileave.com</title><summary type='text'>Yet another mass compromise going on recently folks (yep, surprise surprise). This time, the malicious code leads to a URL in the format;clickme**.fileave.comWhere ** are letters based on the date/time. Yesterday (27th), these were clickmen[a-z].fileave.com, and today these are rather predictably, clickmeo[a-z].fileave.com.Yesterdays were reported to both Network Solutions, and to FileAve (</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1675073286840791146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1675073286840791146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1675073286840791146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1675073286840791146'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/alert-clickmefileavecom.html' title='ALERT: clickme**.fileave.com'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-7Tkm4NLklD4/Tlmf5lsLjkI/AAAAAAAAA3A/Y1TwrDNpClQ/s72-c/imgvurldissect_-_clickmeds.fileave.com.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-7356930595743575244</id><published>2011-08-27T15:18:00.000-07:00</published><updated>2011-08-27T15:21:17.357-07:00</updated><title type='text'>hpHosts: Updated August 27th 2011</title><summary type='text'>I know it's late folks, and my apologies (better late than never?). Sadly the connection has been rubbish lately (I had a second phone and broadband line installed with another provider Wednesday gone and the current line is being re-provisioned, so should hopefully see the issues vanish).The hpHOSTS Hosts file has been updated. There is now a total of 189,155 listed hostsnames.If you are NOT</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/7356930595743575244/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=7356930595743575244' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7356930595743575244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7356930595743575244'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/hphosts-updated-august-27th-2011.html' title='hpHosts: Updated August 27th 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3436408335688229618</id><published>2011-08-25T22:38:00.000-07:00</published><updated>2011-08-25T22:43:01.445-07:00</updated><title type='text'>ALERT: Windows Live Phish</title><summary type='text'>There's another phish doing the rounds lately it seems, this time targetting Windows Live users.If you've received an e-mail similar to the following, click "Mark As" &gt; "Phishing Scam" and delete it - DO NOT CLICK THE LINK!Windows-Live - Account ALERT! - *Re-activate your account* (24-Aug)?Dear (email address),We are sending you this e-mail because Microsoft SmartScreen Technology has </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3436408335688229618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3436408335688229618' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3436408335688229618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3436408335688229618'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/alert-windows-live-phish.html' title='ALERT: Windows Live Phish'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8325835548855433717</id><published>2011-08-11T15:56:00.000-07:00</published><updated>2011-08-11T15:58:55.904-07:00</updated><title type='text'>Alert: Inferno.name criminality and malware - again</title><summary type='text'>Something evil on 95.168.177.144: reddingtaxcm.com and inferno.namereddingtaxcm.com is a legitimate domain that is registered at GoDaddy and has been hijacked to serve up malware, hosted on 95.168.177.144 (NetDirekt, Germany but more below..).The malware appears to be a variant of Vundo / Virtumundo, the infection mechanism looks to be some sort of injection attack on third party sites.</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8325835548855433717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8325835548855433717' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8325835548855433717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8325835548855433717'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/alert-infernoname-criminality-and.html' title='Alert: Inferno.name criminality and malware - again'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4920300519603741180</id><published>2011-08-10T20:30:00.000-07:00</published><updated>2011-08-10T20:44:52.637-07:00</updated><title type='text'>Using LinkedIn? Seen this yet?</title><summary type='text'>Few people asked me to join LinkedIn recently, a site I've avoided like all other social networks for as long as I can remember, and I decided "at least it's not Facebook" (who themselves have now decided to get even worse), so popped over. I already know that social networks can't be trusted, they've proven that time and time again, and now it seems LinkedIn are proving it themselves;</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4920300519603741180/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4920300519603741180' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4920300519603741180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4920300519603741180'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/using-linkedin-seen-this-yet.html' title='Using LinkedIn? Seen this yet?'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3008536532561172571</id><published>2011-08-10T12:46:00.000-07:00</published><updated>2011-08-10T12:58:36.773-07:00</updated><title type='text'>hpObserver, hpHosts, BotScout</title><summary type='text'>A few updates today folks. Firstly, I've published a new hpObserver release. Nothing special, just a couple of bug fixes.The hpHosts release has also been delayed due to a worse than rubbish connection, drastically slowing down the validation process (almost 24 hours just to run a DNS validation on 3600 domains (only seems to be DNS affected by the slowdown so far)).I also noted yesterday </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3008536532561172571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3008536532561172571' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3008536532561172571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3008536532561172571'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/hpobserver-hphosts-botscout.html' title='hpObserver, hpHosts, BotScout'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3352964459559985092</id><published>2011-08-07T19:09:00.000-07:00</published><updated>2011-08-07T19:11:46.063-07:00</updated><title type='text'>hpObserver v0.6.4</title><summary type='text'>Version: 0.6.4Added: List ASN associated with IP. Fixed: IP formatting when saving to text and there's more than one IP  Downloadhttp://support.it-mate.co.uk/?mode=Products&amp;act=DL&amp;p=hpobserver</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3352964459559985092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3352964459559985092' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3352964459559985092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3352964459559985092'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/hpobserver-v064.html' title='hpObserver v0.6.4'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5877259520132472081</id><published>2011-08-03T18:30:00.000-07:00</published><updated>2011-08-03T18:38:40.923-07:00</updated><title type='text'>ALERT: mstdpro.com and botnets</title><summary type='text'>Just a warning folks, there's a replacement for the now suspended rulesbreacker.com/wsumg.com botnet, and it's mstdpro.com. Resolving to residential IPs and serving exploits and a trojan through URLs such as;mstdpro.com/mydata/forms/apisrv.phpmstdpro.com/appserver/mstdpro.com/efs/servlet/military/login.jspmstdpro.com/app/bps/main/mstdpro.com/arc/files/mstdpro.com/arc/files/archivo.exemstdpro.com/</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5877259520132472081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5877259520132472081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5877259520132472081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5877259520132472081'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/08/alert-mstdprocom-and-botnets.html' title='ALERT: mstdpro.com and botnets'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4339405225781770819</id><published>2011-07-30T15:48:00.000-07:00</published><updated>2011-07-30T16:15:51.816-07:00</updated><title type='text'>Be careful searching for Top Gear episodes</title><summary type='text'>Love Top Gear? I do to, can't wait for Sundays and Wednesdays, and tend to watch it on Dave through the week (seen them all hundreds of times since they're repeated around 5 times a day, but bah, there's normally nothing else on anyway). However, if you're searching for Top Gear episodes (thought everyone knew the official URL (http://bbc.co.uk/topgear), but obviously not), then you may find </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4339405225781770819/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4339405225781770819' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4339405225781770819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4339405225781770819'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/be-careful-searching-for-top-gear.html' title='Be careful searching for Top Gear episodes'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-bpWQ5ZyLuRI/TjSLbEQE2WI/AAAAAAAAA24/ng9OKaVuvUo/s72-c/imgwatchtopgear.info.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4367300161577008578</id><published>2011-07-26T16:20:00.000-07:00</published><updated>2011-07-28T20:29:12.206-07:00</updated><title type='text'>Security: Could you recover your valuables if they were stolen?</title><summary type='text'>There's lots been written on security for your machines and networks, be it routers, PCs, laptops, netbooks, iPads, Androids and Blackberrys and the likes - but all the security in the world isn't going to help you if these actually get stolen, either through a break-in or pick pocketing or the likes.Are you prepared for this? Could you tell the police how to identify and track your items, should</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4367300161577008578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4367300161577008578' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4367300161577008578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4367300161577008578'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/security-could-you-recover-your.html' title='Security: Could you recover your valuables if they were stolen?'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6974715936889255971</id><published>2011-07-24T08:27:00.000-07:00</published><updated>2011-07-28T20:30:20.535-07:00</updated><title type='text'>Part 11: Renos on the move</title><summary type='text'>The chaps behind Renos are on the move again as of today, this time to Russia based, Eurobyte Llc (AS35415), or best known, as a customer of Webazilla. Both known bulletproof hosting.New domain as of 30 mins ago, is through UK2 (surprise surprise), though there's been one prior to that, through DirectI (suspended a few mins after being reported);fileyourextension.net/New-Video-Addon.48560.exeIP: </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6974715936889255971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6974715936889255971' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6974715936889255971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6974715936889255971'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/part-11-renos-on-move.html' title='Part 11: Renos on the move'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3331930132583603367</id><published>2011-07-22T14:30:00.000-07:00</published><updated>2011-07-22T14:41:05.167-07:00</updated><title type='text'>Part 10: Renos on the move (previously: Interserver, malware, and the Scottish weather)</title><summary type='text'>I phoned HostNOC/Burst around an hour ago, regarding an IP that had been serving Renos for a while, and stayed on the phone until it was suspended. Expecting them to move to a new IP rather quickly, but sadly had to pop to the shops. Getting back however, I wasn't to be disappointed. The chaps behind Renos (still don't know who that is, but am working on it), had moved to a new IP yet again, </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3331930132583603367/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3331930132583603367' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3331930132583603367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3331930132583603367'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/part-10-renos-on-move-previously.html' title='Part 10: Renos on the move (previously: Interserver, malware, and the Scottish weather)'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-pSfMwMuctWQ/TintRrQ8VQI/AAAAAAAAA2w/BVPZNAg8Krk/s72-c/imgHostNOC_Burst.net.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4734649130352566060</id><published>2011-07-19T08:37:00.000-07:00</published><updated>2011-07-19T08:51:56.967-07:00</updated><title type='text'>Part 9: Interserver, malware, and the Scottish weather</title><summary type='text'>I love predictability, makes my job much easier (well, as far as these chaps are concerned anyway). 3 IPs as of today, same registrars (surprise surprise);UK2DirectINetEarthOne of the IPs is the same as yesterday (errr Burst.net/HostNOC - what happened to your 24 hour warning?).66.197.187.152 immovable.detectstakes.com AS21788 66.197.128.0/17 NOC - Network Operations Center Inc.193.105.171.120 </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4734649130352566060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4734649130352566060' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4734649130352566060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4734649130352566060'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/part-9-interserver-malware-and-scottish.html' title='Part 9: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8692337602329042366</id><published>2011-07-18T09:50:00.001-07:00</published><updated>2011-07-18T16:38:14.622-07:00</updated><title type='text'>Part 8: Interserver, malware, and the Scottish weather</title><summary type='text'>Well, I said it would happen and it has - my friends at Leaseweb finally nulled the server housing Renos, and as with their previous pattern - they're back to HostNOC/Burst.They're now using 66.197.187.152 (latest domain: worldmediaplugins.org), same registrars and infection, so nothing else to report I'm afraid. As far as UK2 and DomainContext, the latter is still failing to reply, and I'm </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8692337602329042366/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8692337602329042366' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8692337602329042366'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8692337602329042366'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/part-7-interserver-malware-and-scottish_18.html' title='Part 8: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8758848101602099744</id><published>2011-07-15T05:12:00.001-07:00</published><updated>2011-07-15T05:15:28.447-07:00</updated><title type='text'>Part 7: Interserver, malware, and the Scottish weather</title><summary type='text'>Looks like they're on the move to a new host, this time it's Leaseweb (Rob and Jottie will hopefully be getting it down shortly, so they shouldn't be there long). As of a few minutes ago, the latest Renos domain is pointing to;82.192.79.49The URL;makepan.in/New-Video-Addon.48563.exeReferencesPart 5a: Interserver, malware, and the Scottish weatherhttp://hphosts.blogspot.com/2011/06/part-5-</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8758848101602099744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8758848101602099744' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8758848101602099744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8758848101602099744'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/part-7-interserver-malware-and-scottish.html' title='Part 7: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1035228754915028961</id><published>2011-07-14T14:39:00.000-07:00</published><updated>2012-01-01T11:15:20.964-08:00</updated><title type='text'>Alert: Icky sticky, Facebook worm phishy</title><summary type='text'>Facebook worms are nothing new, having been documented as far back as 2008, but after a tip from a friend, I dipped into the DNS records for a couple of IPs, and plucked out this lovely lot. All of which appear involved in the same Facebook worm/phish that others have blogged about;10gambling.com11likes.info12v-dc-motor.motorsforsales.us2003-microsoft.officediscount.us2010-</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1035228754915028961/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1035228754915028961' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1035228754915028961'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1035228754915028961'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/alert-icky-sticky-facebook-worm-phishy.html' title='Alert: Icky sticky, Facebook worm phishy'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8644661594239745506</id><published>2011-07-12T09:10:00.000-07:00</published><updated>2011-07-12T09:33:07.318-07:00</updated><title type='text'>Part 6: Interserver, malware, and the Scottish weather</title><summary type='text'>I've not worked out their obsession with HostNOC yet, but so far, the only two hosting companies they're flitting between, are CoolVDS (AS50669, well known to be criminal friendly) having until a few hours ago, been housed at 193.105.171.226 since their last stint on HostNOC (184.22.253.11) until July 7th.You'll no doubt not be surprised to hear, other than their flitting between the two hosts, </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8644661594239745506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8644661594239745506' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8644661594239745506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8644661594239745506'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/part-6-interserver-malware-and-scottish.html' title='Part 6: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1951476068945746378</id><published>2011-07-06T06:09:00.000-07:00</published><updated>2011-07-06T07:10:29.598-07:00</updated><title type='text'>When is a 24 hour warning not a 24 hour warning? (aka HostNOC/Burst finally suspend Renos server)</title><summary type='text'>64.120.151.73 was first reported to HostNOC/Burst, on July 2nd, both via e-mail and via telephone. When speaking to them on the phone, I was advised they'd give the customer a 24 hour warning.Watching the new domains popping up each day, I continued to send them reports, and resorted to a second phone call last week (Sunday if memory serves), to be told yet again, they'd give the customer a 24 </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1951476068945746378/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1951476068945746378' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1951476068945746378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1951476068945746378'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/when-is-24-hour-warning-not-24-hour.html' title='When is a 24 hour warning not a 24 hour warning? (aka HostNOC/Burst finally suspend Renos server)'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3947475913496069206</id><published>2011-07-02T09:52:00.000-07:00</published><updated>2011-07-02T11:12:51.943-07:00</updated><title type='text'>Criminals part 2: AS56927 GOLDENIDEAS SC GoldenIdeas SRL</title><summary type='text'>This was never intended to be multipart, but I figured after part 1, I may as well do the other IPs they're using. As it happens, one of the other IP ranges they've got is through AS56927.The /24 in question, similar to the previous one, is 188.229.97.0/24. What's curious here, is that AS records show something interesting - an invisible link (AS52366 that AS records says doesn't exist. If we </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3947475913496069206/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3947475913496069206' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3947475913496069206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3947475913496069206'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/criminals-part-2-as56927-goldenideas-sc.html' title='Criminals part 2: AS56927 GOLDENIDEAS SC GoldenIdeas SRL'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2290299174908173683</id><published>2011-07-01T13:16:00.001-07:00</published><updated>2011-07-01T13:20:18.006-07:00</updated><title type='text'>Notice: Planned outage</title><summary type='text'>Just a note folks, the network housing the likes of fspamlist.com, mysteryfcm.co.uk and the Abelhadigital.com forums, will be down for around 2 hours tomorrow, to allow for maintenance. The exact time hasn't been finalized yet, but is expected to be between 15:00-17:00.Sites affected:*.mysteryfcm.co.uk*.</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2290299174908173683/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2290299174908173683' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2290299174908173683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2290299174908173683'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/notice-planned-outage.html' title='Notice: Planned outage'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6363789784201912979</id><published>2011-07-01T11:12:00.000-07:00</published><updated>2011-07-01T11:13:19.001-07:00</updated><title type='text'>hpHOSTS - UPDATED July 1st, 2011</title><summary type='text'>The hpHOSTS Hosts file has been updated. There is now a total of 154,282 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 01/06/2011 17:00Last Verified: 01/06/2011 12:00Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6363789784201912979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6363789784201912979' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6363789784201912979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6363789784201912979'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/07/hphosts-updated-july-1st-2011.html' title='hpHOSTS - UPDATED July 1st, 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3986494810005975814</id><published>2011-06-29T18:58:00.000-07:00</published><updated>2011-06-29T20:16:57.368-07:00</updated><title type='text'>Criminals: AS56860 ELETTROGRAF SC ELETTROGRAF SRL</title><summary type='text'>What do you do when you need lots of IPs to house your fake meds and other criminal sites? Use botnets? compromised sites/servers? That's certainly what the bad guys involved in exploits, malware and other badness like to do.Of course, another favourite of the bad guys, is to set up their own ASNs, complete with batches of IPs and IP ranges, to house their criminal activities. This is exactly </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3986494810005975814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3986494810005975814' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3986494810005975814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3986494810005975814'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/criminals-as56860-elettrograf-sc.html' title='Criminals: AS56860 ELETTROGRAF SC ELETTROGRAF SRL'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-JhcbXSteDmc/TgvgMm6WveI/AAAAAAAAA2o/bXwqM15u-Ug/s72-c/imgwowpeniss_com.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-7836189405784115579</id><published>2011-06-28T16:53:00.001-07:00</published><updated>2011-06-28T21:55:01.417-07:00</updated><title type='text'>Alert: Exploits on 78.111.51.100</title><summary type='text'>If you've not already done so, you'll want to block 78.111.51.100 asap. It's currently housing a plethora of domains that are serving malware via exploit.Payloads are coming from paths such as;thujkdswg.tld.tc/k.php?f=20&amp;e=3-&gt; about.exe--&gt; 3c6d68ea89512089df0cd7629439c378You'll no doubt notice the usual suspects as far as the ccTLD branches (redirection services serving off of ccTLDs such as .cc)</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/7836189405784115579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=7836189405784115579' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7836189405784115579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/7836189405784115579'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/alert-exploits-on-7811151100.html' title='Alert: Exploits on 78.111.51.100'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6332522268340580476</id><published>2011-06-28T05:03:00.000-07:00</published><updated>2011-07-12T09:25:50.180-07:00</updated><title type='text'>Part 5a: Interserver, malware, and the Scottish weather</title><summary type='text'>Looks like HostNOC/Burst, finally pulled their finger out. Over the past 24 hours, they've now moved to a bulletproof host (193.105.171.70, AS50669 COOLVDS-as FOP Kutcevol Maksum Mukolaevich). If you've not already, you may want to consider blackholing the following;91.218.120.0/22193.105.171.0/24Registrars used haven't changed, still using DirectI resellers, DomainContext and UK2. Thankfully, </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6332522268340580476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6332522268340580476' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6332522268340580476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6332522268340580476'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/part-5-interserver-malware-and-scottish_28.html' title='Part 5a: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3451906748830773628</id><published>2011-06-27T06:12:00.000-07:00</published><updated>2011-06-27T06:20:42.111-07:00</updated><title type='text'>Part 5: Interserver, malware, and the Scottish weather</title><summary type='text'>Ever get the feeling HostNOC/Burst aren't taking this seriously? They took 3 years to boot these guys the first time, and now all they're doing, is jumping across different IPs on the HostNOC/Burst AS.The new IP they're using as of today, 173.212.255.31Filenames occasionally change (new ones: New-Video-Addon.40028.exe, FlashPlayer.40028.exe, old ones produce fake 404s), but the infection </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3451906748830773628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3451906748830773628' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3451906748830773628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3451906748830773628'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/part-5-interserver-malware-and-scottish.html' title='Part 5: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8373740432765223583</id><published>2011-06-23T19:29:00.000-07:00</published><updated>2011-06-23T19:31:13.666-07:00</updated><title type='text'>Faking reviews? You should fret about more than illegality</title><summary type='text'>Opinion A recent newspaper investigation uncovered evidence that companies are paying agencies to create false online reviews for their services. But what those companies may not realise is that this is illegal and could ruin their businesses.The practice is called astroturfing, because it fakes grass-roots support, and it is not only ethically questionable, it is illegal. And if the law doesn't </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8373740432765223583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8373740432765223583' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8373740432765223583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8373740432765223583'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/faking-reviews-you-should-fret-about.html' title='Faking reviews? You should fret about more than illegality'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8858879615824306694</id><published>2011-06-22T21:48:00.000-07:00</published><updated>2011-06-22T21:57:29.599-07:00</updated><title type='text'>Part 4: Interserver, malware, and the Scottish weather</title><summary type='text'>Well that didn't take them long. They're back to .in domains, and have moved to the well known SwiftWay (AS35017).New payload URL;rhyzilch.in/FlashPlayer.40028.exeIP: 46.21.159.228PTR: 228.159.21.46.inferno.nameMD5: 42a61ad4f894d9d21434cc5d5819aaefThis /24 of course, as with all SwiftWay ranges, is no stranger to malicious content, having hosted everything from fake AVs to trojans, and even fake </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8858879615824306694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8858879615824306694' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8858879615824306694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8858879615824306694'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/part-4-interserver-malware-and-scottish.html' title='Part 4: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-503056290358908660</id><published>2011-06-22T20:43:00.000-07:00</published><updated>2011-06-22T21:02:29.734-07:00</updated><title type='text'>Part 3: Interserver, malware, and the Scottish weather</title><summary type='text'>Well, the bad guys tried fooling everyone by changing the filename yet again (sorry Mr Bad Guy - we're not that stupid).You'll remember that they were using HostNOC as of the latest incarnations, and I both e-mailed, and phoned HostNOC on the 20th, the day the move was made, and the person I spoke to advised me they were giving the customer a 24 hour warning. 3 days later, and it was still online</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/503056290358908660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=503056290358908660' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/503056290358908660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/503056290358908660'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/part-3-interserver-malware-and-scottish.html' title='Part 3: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5424725669534532018</id><published>2011-06-22T12:10:00.000-07:00</published><updated>2011-06-22T12:11:51.661-07:00</updated><title type='text'>hpHosts move completed</title><summary type='text'>The move to the new server has now completed. DNS propogation should be complete for most, but if you're still seeing the old 208. address, please refresh your DNS cache.Please let me know if you notice any problems.</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5424725669534532018/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5424725669534532018' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5424725669534532018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5424725669534532018'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/hphosts-move-completed.html' title='hpHosts move completed'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6876699547627610015</id><published>2011-06-22T11:22:00.001-07:00</published><updated>2011-06-22T11:23:18.608-07:00</updated><title type='text'>hpHosts moving to new server</title><summary type='text'>Tip: don't get your hair stuck in the car window when closing it - it hurts like hell!Just a note folks, the hpHosts website and forums, are in the process of being moved to a new server, so will be down for around an hour or so.My apologies for any inconvenience.</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6876699547627610015/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6876699547627610015' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6876699547627610015'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6876699547627610015'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/hphosts-moving-to-new-server.html' title='hpHosts moving to new server'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3025725337765947746</id><published>2011-06-19T09:52:00.000-07:00</published><updated>2011-06-19T10:02:14.906-07:00</updated><title type='text'>Part 2: Interserver, malware, and the Scottish weather</title><summary type='text'>Not surprisingly, since my last post, they've switched the latest ones back to HostNOC/Burst.Net (same company that took 3 years to boot them last time). Registrars are primarily DirectI and UK2 (who don't seem to be replying ....). DirectI have been shutting down those I've found, within 30 mins of their being reported.I've likely missed quite a few since my sleeping meds knocked me out for a </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3025725337765947746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3025725337765947746' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3025725337765947746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3025725337765947746'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/part-2-interserver-malware-and-scottish.html' title='Part 2: Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2345982092367410285</id><published>2011-06-16T18:45:00.000-07:00</published><updated>2011-06-16T19:13:50.210-07:00</updated><title type='text'>Interserver, malware, and the Scottish weather</title><summary type='text'>They say, if you don't like the Scottish weather, wait 20 mins. That's all I've got on that one.In the last few weeks alone, 2 specific IPs have racked up a count of over 2000 malicious domains, most through just a handful of registrars (all those through DirectI have been suspended within around 20 mins on average, of being discovered, with DirectI suspending several thousand more related </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2345982092367410285/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2345982092367410285' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2345982092367410285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2345982092367410285'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/interserver-malware-and-scottish.html' title='Interserver, malware, and the Scottish weather'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4219948621404193499</id><published>2011-06-12T09:13:00.001-07:00</published><updated>2011-06-12T09:14:53.191-07:00</updated><title type='text'>Oh dear, someone isn't reading properly</title><summary type='text'>I get a few of these, and they always make me laugh. Seems some people don't bother reading or researching, what hpHosts actually is, before e-mailing me.Name: HugoE-mail: {REMOVED}How did you find us?: Other... Other: Not providedSite navigation: Very easyComments: Please add my site to your database. I've removed his e-mail address to save him some embarrassment, but little hint to those of you</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4219948621404193499/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4219948621404193499' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4219948621404193499'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4219948621404193499'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/oh-dear-someone-isnt-reading-properly.html' title='Oh dear, someone isn&apos;t reading properly'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8809791449966936672</id><published>2011-06-01T23:50:00.000-07:00</published><updated>2011-06-01T23:52:02.376-07:00</updated><title type='text'>Info: Google to stop supporting Firefox 3.5, Internet Explorer 7, and Safari 3</title><summary type='text'>For web applications to spring even farther ahead of traditional software, our teams need to make use of new capabilities available in modern browsers. For example, desktop notifications for Gmail and drag-and-drop file upload in Google Docs require advanced browsers that support HTML5. Older browsers just don’t have the chops to provide you with the same high-quality experience.For this reason, </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8809791449966936672/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8809791449966936672' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8809791449966936672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8809791449966936672'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/06/info-google-to-stop-supporting-firefox.html' title='Info: Google to stop supporting Firefox 3.5, Internet Explorer 7, and Safari 3'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6679709312323366805</id><published>2011-05-26T18:23:00.001-07:00</published><updated>2011-05-26T18:49:31.232-07:00</updated><title type='text'>Dear bad guys ....</title><summary type='text'>Seems the bad guys don't believe we actually check sites/files we're coming across anymore, only that we look for a specific filename. I've been monitoring a couple sites leading to trojans, and having the domains shut down. Over the past few days (approx the 20th), they've disabled the specific filename the malicious code points to, possibly believing we'll say "okay, it doesn't exist anymore, </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6679709312323366805/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6679709312323366805' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6679709312323366805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6679709312323366805'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/dear-bad-guys.html' title='Dear bad guys ....'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-QWdK9UrCYLU/Td796D-jiuI/AAAAAAAAA2M/7Yh_fnfupEU/s72-c/imgflashplayer.45187.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2346808658141937435</id><published>2011-05-26T09:02:00.000-07:00</published><updated>2011-05-26T09:11:20.898-07:00</updated><title type='text'>Info: Notification of downtime</title><summary type='text'>Just an FYI folks. To allow my ISP to identify a fault on the line, I've got to take the entire network offline for an hour. This will obviously mean all servers will be unavailable.The network will be taken offline this evening at 19:00 GMT London, and will be back at 20:00 GMT London.Sites affected:*.mysteryfcm.co.uk*.</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2346808658141937435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2346808658141937435' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2346808658141937435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2346808658141937435'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/info-notification-of-downtime.html' title='Info: Notification of downtime'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-8632043578738238881</id><published>2011-05-25T10:49:00.000-07:00</published><updated>2011-05-25T10:50:32.207-07:00</updated><title type='text'>hpHosts - Updated 25th May 2011</title><summary type='text'>The hpHOSTS Hosts file has been updated. There is now a total of 149,988 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 25/05/2011 15:30Last Verified: 25/05/2011 01:00Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/8632043578738238881/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=8632043578738238881' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8632043578738238881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/8632043578738238881'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/hphosts-updated-25th-may-2011.html' title='hpHosts - Updated 25th May 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4871619769507319083</id><published>2011-05-24T21:21:00.001-07:00</published><updated>2011-05-25T09:51:11.124-07:00</updated><title type='text'>Facebook Wants Your Pre-Teen</title><summary type='text'>My other half, though in her 20's, is also part of the "share it all" and "it'll never happen to me" generation, despite being as paranoid and insecure as heck about everything (though generally only paranoid about what her friends think, what I think etc, rather than things that actually matter). Drives me up the wall, especially given she should be mature enough to know better.Kids are already </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4871619769507319083/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4871619769507319083' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4871619769507319083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4871619769507319083'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/facebook-wants-your-pre-teen.html' title='Facebook Wants Your Pre-Teen'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4382521991855043211</id><published>2011-05-24T19:43:00.000-07:00</published><updated>2011-05-24T19:44:56.434-07:00</updated><title type='text'>BT spying on customers</title><summary type='text'>Oh dear, this isn't going to end well (especially given they were involved in the Phorm debacle too);BT reserves, and makes use of, the right to remotely detect all devices connected to LANs owned by its broadband customers – for their own good, of course.BT Broadband customers can expect to have their network checked any time the operator feels it needs to take a peek to help it provide the </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4382521991855043211/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4382521991855043211' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4382521991855043211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4382521991855043211'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/bt-spying-on-customers.html' title='BT spying on customers'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-3976223756486361964</id><published>2011-05-22T22:33:00.000-07:00</published><updated>2011-05-22T22:37:06.227-07:00</updated><title type='text'>WARNING: Telephony scams still ongoing</title><summary type='text'>As if you needed telling, but sadly to state the obvious, the scammers traced back to India are still very much involved in defrauding insuspecting victims, and are now apparently going one step further by infecting their machines to boot.In previous iterations of this scam the person on the phone would get you to click through to the event viewer to "find something red". Strangely enough there </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/3976223756486361964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=3976223756486361964' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3976223756486361964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/3976223756486361964'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/warning-telephony-scams-still-ongoing.html' title='WARNING: Telephony scams still ongoing'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-4791103233544798726</id><published>2011-05-22T10:07:00.000-07:00</published><updated>2011-05-23T07:02:09.583-07:00</updated><title type='text'>WARNING: Fake VirusTotal site serving trojan and fake AV</title><summary type='text'>My friend and co-admin at MalwareDomainList just alerted me to a site impersonating VirusTotal, for the purposes (surprise surprise) of infecting unwitting victims with both a fake AV and a trojan.I've sent an e-mail to my friend Ross at Dot.tk, to have the .tk domain taken out, and will be getting in touch with the host and registrar, for the site it's pointing to, but in the meantime, you can </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/4791103233544798726/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=4791103233544798726' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4791103233544798726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/4791103233544798726'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/warning-fake-virustotal-site-serving.html' title='WARNING: Fake VirusTotal site serving trojan and fake AV'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-bhQFgiUCp6o/TdlDlHaJQxI/AAAAAAAAA2E/IDLOSAamaEA/s72-c/imgnew-virustotal.tk.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6816499246238979250</id><published>2011-05-12T01:25:00.000-07:00</published><updated>2011-05-13T13:55:21.256-07:00</updated><title type='text'>RIP: Zango/Pinball Publisher Corp</title><summary type='text'>Oh I do love good news in the morning. Zango/Pinball need no introduction, everyone is aware of their ongoing shenanigans over the years, and it looks like they're down for the count for now. Or at least, business filings say they are (well all know Zango tried the same hide and seek method, and left a trail that led to the switch to Pinball Corp being discovered relatively quickly).I've said it </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6816499246238979250/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6816499246238979250' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6816499246238979250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6816499246238979250'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/rip-zangopinball-publisher-corp.html' title='RIP: Zango/Pinball Publisher Corp'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5821131701910054398</id><published>2011-05-05T18:40:00.000-07:00</published><updated>2011-05-05T19:40:36.573-07:00</updated><title type='text'>AS43134: CompLife Ltd + DonServers = HOSTSERV (AS42741) = bulletproof hosting for criminals</title><summary type='text'>Ever wonder why some hosting companies try and send you on a "we're waiting, it's resolved, really we're just the innocent victims here, please be patient" game, that results in your getting frustrated and the criminals staying online even longer?Well, the answer is companies (and I use the term companies loosely in this case) such as Don Servers, which is actually the same "company" as CompLife </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5821131701910054398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5821131701910054398' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5821131701910054398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5821131701910054398'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/as43134-complife-ltd-donservers.html' title='AS43134: CompLife Ltd + DonServers = HOSTSERV (AS42741) = bulletproof hosting for criminals'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-eeBKxrI2CYk/TcNZWzEIgVI/AAAAAAAAA10/KAsSNZHQxmw/s72-c/imgdonservers.ru.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5239983364069221717</id><published>2011-05-05T12:26:00.000-07:00</published><updated>2011-05-05T12:27:26.717-07:00</updated><title type='text'>hpHosts - Updated May 2011</title><summary type='text'>hpHOSTS - Updated May 2011The hpHOSTS Hosts file has been updated. There is now a total of 124,448 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 05/05/2011 17:00Last Verified: 05/05/2011 06:00Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5239983364069221717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5239983364069221717' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5239983364069221717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5239983364069221717'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/hphosts-updated-may-2011.html' title='hpHosts - Updated May 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6775482796209444086</id><published>2011-05-04T13:05:00.000-07:00</published><updated>2011-05-04T13:07:52.945-07:00</updated><title type='text'>Microsoft SysInternals update</title><summary type='text'>Hat tip to the guys at the ISC for the heads up (got the Microsoft RSS on the reader but didn't notice this one).We have received notification that Sysinternals has had some updates. One in particular that is a favorite among handlers is Process Explorer. It now includes: Process Explorer v14.11 includes the ability to configure network and disk activity icons in the tray. Check out the </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6775482796209444086/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6775482796209444086' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6775482796209444086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6775482796209444086'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/microsoft-sysinternals-update.html' title='Microsoft SysInternals update'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-5598686240041283609</id><published>2011-05-04T04:14:00.000-07:00</published><updated>2011-05-04T04:55:22.963-07:00</updated><title type='text'>Fake AVs: Back to using Instra Corporation Pty Ltd</title><summary type='text'>Seems the fake AV gang responsible for these campaigns, have gone from Tucows, back to Instra Corp again. This lot were first created March 24th, and are now being used yet again;</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/5598686240041283609/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=5598686240041283609' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5598686240041283609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/5598686240041283609'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/05/fake-avs-back-to-using-intra.html' title='Fake AVs: Back to using Instra Corporation Pty Ltd'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1298722083265578133</id><published>2011-04-28T01:58:00.000-07:00</published><updated>2011-04-28T02:18:53.937-07:00</updated><title type='text'>Tucows + Fake AV + new (but old) /24</title><summary type='text'>It was bound the happen, after having their IPs killed a few days ago, and I'm actually surprised it took them this long, but alas as of the 28th, there's yet more malicious fake AV domains via Tucows (wonder if Tucows are actually going to put a stop to this?).</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1298722083265578133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1298722083265578133' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1298722083265578133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1298722083265578133'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/04/tucows-fake-av-new-but-old-24.html' title='Tucows + Fake AV + new (but old) /24'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1444143423180779789</id><published>2011-04-26T20:26:00.000-07:00</published><updated>2011-04-26T20:29:18.101-07:00</updated><title type='text'>Have a router with wireless? Have it secured yet?</title><summary type='text'>Many have been bleating on about securing WiFi pretty much since WiFi was first available to the masses, but many still don't bother securing it, leaving them wide open to abuse at best, and at worst, being prosecuted because someone used YOUR unsecured wireless connection, to download child pornography.A case has been brought to light yet again, of a man prosecuted because a neighbour used his </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1444143423180779789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1444143423180779789' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1444143423180779789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1444143423180779789'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/04/have-router-with-wireless-have-it.html' title='Have a router with wireless? Have it secured yet?'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-843990222461083563</id><published>2011-04-24T22:53:00.000-07:00</published><updated>2011-04-24T22:56:34.960-07:00</updated><title type='text'>Success!: Fake AVs at CaroNet (AS11368)</title><summary type='text'>I am pleased to report, with the help of my friend William (GoDaddy), every single one of the following, has had their IPs suspended by CaroNet (better late than never). I fully expect them to move to new IPs, but in the meantime, it's ~500 sites less, that can infect its </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/843990222461083563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=843990222461083563' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/843990222461083563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/843990222461083563'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/04/success-fake-avs-at-caronet-as11368.html' title='Success!: Fake AVs at CaroNet (AS11368)'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6106213668974745630</id><published>2011-04-19T20:18:00.000-07:00</published><updated>2011-04-19T20:19:19.710-07:00</updated><title type='text'>hpHOSTS - Updated April 2011</title><summary type='text'>hpHOSTS - Updated April 2011The hpHOSTS Hosts file has been updated. There is now a total of 122,034 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 20/04/2011 03:00Last Verified: 20/04/2011 01:00Download hpHosts now!http://hosts-file.net/?s=Download</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6106213668974745630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6106213668974745630' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6106213668974745630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6106213668974745630'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/04/hphosts-updated-april-2011.html' title='hpHOSTS - Updated April 2011'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-6502349141972553845</id><published>2011-03-16T20:13:00.000-07:00</published><updated>2011-03-16T20:51:00.900-07:00</updated><title type='text'>Take downs: The good, the bad - and RapidSwitch</title><summary type='text'>Taking down malicious sites has been part of daily life for years now, and I still love every second of it. Primarily because it annoys the bad guys, but mostly because it means there's less malicious sites (for a second anyway) for people to get infected via.During the years, there's been many changes in the responses from hosting companies and registrars. GoDaddy have become one of the best at </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/6502349141972553845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=6502349141972553845' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6502349141972553845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/6502349141972553845'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/03/take-downs-good-bad-and-rapidswitch.html' title='Take downs: The good, the bad - and RapidSwitch'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-2798392126168436733</id><published>2011-03-15T19:42:00.000-07:00</published><updated>2011-03-15T19:47:43.666-07:00</updated><title type='text'>hpHosts: Scheduled downtime</title><summary type='text'>Just a note folks. The hpHosts website and forums will be offline between 20:00 - 21:30 PST for maintenance.That's 06:00 this morning for us in the UK btw ;o)</summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/2798392126168436733/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=2798392126168436733' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2798392126168436733'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/2798392126168436733'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/03/hphosts-scheduled-downtime.html' title='hpHosts: Scheduled downtime'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2590733549034628316.post-1827676055766253949</id><published>2011-03-12T16:00:00.001-08:00</published><updated>2011-03-12T16:18:27.719-08:00</updated><title type='text'>eBay: Do you read before bidding/buying?</title><summary type='text'>Sites such as eBay are extremely useful for finding that wonderful collectable, part or a multitude of other things you've been meaning to and wanting to, buy for yourself.Sadly however, as with many other sites, there are those on these sites, that are doing as much as possible, to part you with your money. There are millions of legit users on there, just like yourself, but don't forget - </summary><link rel='replies' type='application/atom+xml' href='http://hphosts.blogspot.com/feeds/1827676055766253949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2590733549034628316&amp;postID=1827676055766253949' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1827676055766253949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2590733549034628316/posts/default/1827676055766253949'/><link rel='alternate' type='text/html' href='http://hphosts.blogspot.com/2011/03/ebay-do-you-read-before-biddingbuying.html' title='eBay: Do you read before bidding/buying?'/><author><name>MysteryFCM</name><uri>http://www.blogger.com/profile/02934157746337952448</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-RFQ_F_zkM0g/TXwK-WQmyUI/AAAAAAAAA1U/5efEP1mJ56Y/s72-c/imgeBay_Postage.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
