<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	<title>MetaTalk posts tagged with exploit</title>
	<link>http://metatalk.metafilter.com/tags/exploit</link>
	<description>Posts tagged with 'exploit' at MetaTalk.</description>
	<pubDate>Tue, 02 Dec 2008 11:38:12 -0800</pubDate> <lastBuildDate>Tue, 02 Dec 2008 11:38:12 -0800</lastBuildDate>

	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>
	<item>
		<title>Getting it from the horse&apos;s mouth.</title>
		<link>http://metatalk.metafilter.com/17082/Getting%2Dit%2Dfrom%2Dthe%2Dhorses%2Dmouth</link>
		<description>&lt;a href=&quot;http://www.metafilter.com/77017/Oh-shit-I-just-broke-the-Internet#2360115&quot;&gt;This&lt;/a&gt; is why I still read MetaFilter.  </description>
		<guid isPermaLink="false">tag:metatalk.metafilter.com,2008:site.17082</guid>
		<pubDate>Tue, 02 Dec 2008 11:38:12 -0800</pubDate>
		<category>attack</category>
		<category>dns</category>
		<category>exploit</category>
		<category>hack</category>
		<category>internet</category>
		<category>kaminsky</category>
		<category>wiredmagazine</category>
		<dc:creator>timeistight</dc:creator>
	</item>
      <item>
		<title>the bad bad internets</title>
		<link>http://metatalk.metafilter.com/16580/the%2Dbad%2Dbad%2Dinternets</link>
		<description>so, about this post --&gt; http://www.metafilter.com/73909/History-of-the-DC-Universe ... please read all of more inside first before looking at the post. it looks like pixie already figured it out, but, for the benefit of all the other Mefi Jr. Detectives out there, let&apos;s break this thing down piece by piece.

&lt;li&gt; The second link in the post is http://dcu.smartmemes.com/ and it&apos;s infected by something. But, what? Let&apos;s look at the source. On the last line of the page is a script: &lt;blockquote&gt;&lt;small&gt;&lt;small&gt;eval(unescape(&quot;%77%69%6e% .... %3e%27%29&quot;));&lt;/small&gt;&lt;/small&gt;&lt;/blockquote&gt;&lt;li&gt;if you expand out the unescape portion, you get the following:&lt;blockquote&gt;[clever shit making people&apos;s browsers go gaga elided]&lt;/blockquote&gt;&lt;li&gt;How did we get from that gobbleygook of % signs and hexadecimal to actual that? Easiest way to figure it is out is to cut out the eval() part (which actually causes the code to run) and change it to a alert(), which causes it to open a prompt in your browser &lt;a href=&quot;http://farm4.static.flickr.com/3131/2740540925_2d4260e0a3_o.png&quot;&gt;like so&lt;/a&gt;. You can even run it from your browser via a javascript: handler like shown in the pic

&lt;li&gt;&lt;b&gt;Now, what you should never ever do is change the eval() to a document.write()&lt;/b&gt; Why? Because in the case of this code for example, the iframe html tag will actually get written to the page and you won&apos;t even know it! Which is what probably happened to &lt;a href=&quot;http://www.metafilter.com/73909/History-of-the-DC-Universe#2211205&quot;&gt;Leon&lt;/a&gt;, I&apos;m guessing. (Yeah, this whole metatalk post is really just a callout about that.)

&lt;li&gt;Anyway, now that we can actually see what the code is, and as pixie points out, it loads an iframe opening a webpage: hxxp://58.xxx.xxx.33/gpack/index.php (please don&apos;t actually visit that site). That site has more iframes which load something called the &lt;a href=&quot;http://www.secgeeks.com/gpack.html&quot;&gt;gpack exploit&lt;/a&gt;.

&lt;li&gt;Anyway, the gpack exploit itself is beyond the scope of this post, but, the important thing to remember is to keep ALL of your software up to date with security patches, because you&apos;ll never know when a site could be infected with something. (Or, if you&apos;re super paranoid like me, but, also an idiot who runs IE, add all of china to your IE restricted sites list. I had http://58-61.* in there, among other things. saved my ass it did!)

Oh. Since I&apos;m here anyway, can we get a &quot;this site infected with badware/malware&quot; pony, er, flag?&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt; </description>
		<guid isPermaLink="false">tag:metatalk.metafilter.com,2008:site.16580</guid>
		<pubDate>Thu, 07 Aug 2008 04:51:55 -0800</pubDate>
		<category>badlinkdeletion</category>
		<category>exploit</category>
		<category>gpack</category>
		<category>javascript</category>
		<category>mefi</category>
		<category>security</category>
		<dc:creator>yeoz</dc:creator>
	</item>
      
	</channel>
</rss>


