<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; 2007 &#187; November</title>
	<atom:link href="http://42.kaizeku.com/2007/11/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>DreamHost greylisted by Gmail</title>
		<link>http://42.kaizeku.com/google/dreamhost-is-being-sandbox-by-google/</link>
		<comments>http://42.kaizeku.com/google/dreamhost-is-being-sandbox-by-google/#comments</comments>
		<pubDate>Fri, 30 Nov 2007 19:35:23 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Dreamhost]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[Grayhat]]></category>

		<category><![CDATA[sandbox]]></category>

		<category><![CDATA[Web Hosting]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/dreamhost-is-being-sandbox-by-google/</guid>
		<description><![CDATA[<img src="http://i.kakkoi.net/dreamhost.png" alt="Dreamhost" width="156" height="33" title="drea,host" style="float:left;margin: 0pt 5px 1px 0pt;padding:10px" />I stumble on this interesting headline while browsing technorati. Beth's (afrogtokiss.net) is  having a minor problem with his wordpress for not receiving earlier notifications on new comments post. After a few comparison he discovered that <a href="http://blog.kakkoi.net/uri/YWZyb2d0b2tpc3MubmV0LzIwMDcvMTEvMzAvZ21haWwtaGFzLWdyZXlsaXN0ZWQtZHJlYW1ob3N0Lw.curie,80,302">dreamhost is being graylisted by google</a>.  The reason is still unclear but reading what beth's posted earlier on it seem like Dreamhost Team will not disclose it on open yet.

<h3>On to dreamhost official blog</h3>
<p>Hoping that I could get more clear view on this issue  I did some more checking on <strong>dreamhost official blogs</strong>. Unfortunately It doesn't fudge any relevant news. Their official webblog seems more like a casual blogs full with party pooper.</p> <p>I spend few minutes fiddling around in their archives before I get on <a href="http://blog.kakkoi.net/uri/aHR0cDovL2Jsb2cuZHJlYW1ob3N0LmNvbS8yMDA3LzA5LzI0L2FyZS15b3Utb2xkZXItdGhhbi1hLWZpZnRoLWdyYWRlci8.curie,80,302">"Are you older than fifth grade"</a>. Its actual content is much more interesting that the crappy headline. <cite class="vcard"><a class="url fn" href="http://www.dreamhost.com/profile-joshj.html"><span class="given-name">Josh</span> <span class="family-name">Jones</span></a> (<span class="org">Dreamhost</span> <span class="role">Co-Founder</span>)</cite> write a historic trackback of Dreamhost since 10 years ago. The below screenshot has lots thing to says about their business model.</p>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://i.kakkoi.net/dreamhost.png" alt="Dreamhost" width="156" height="33" title="dreamhost" class="fl" />I stumble on this interesting headline while browsing technorati. Beth&#8217;s (afrogtokiss.net) is having a minor problem with his wordpress for not receiving earlier notifications on new comments post. After a few comparison he discovered that <a href="http://blog.kakkoi.net/uri/YWZyb2d0b2tpc3MubmV0LzIwMDcvMTEvMzAvZ21haWwtaGFzLWdyZXlsaXN0ZWQtZHJlYW1ob3N0Lw.curie,80,302">GMail Has Greylisted DreamHost.</a>. The reason is still unclear, reading what beth&#8217;s posted earlier on it seem like Dreamhost Team will not disclose it on open yet.</p>
<h2>dreamhost official blog</h2>
<p>Hoping that I could get more clear view on this issue I did some more checking on <strong class="fw-">dreamhost official blogs</strong>. Unfortunately It doesn&#8217;t fudge any relevant news. Their official webblog seems more like a casual blogs full with party pooper.</p>
<p><span id="more-42"></span></p>
<p>I spend few minutes fiddling around in their archives before I get on <a href="/uri/aHR0cDovL2Jsb2cuZHJlYW1ob3N0LmNvbS8yMDA3LzA5LzI0L2FyZS15b3Utb2xkZXItdGhhbi1hLWZpZnRoLWdyYWRlci8.curie,80,302" class="exturl icn-r1">&#8220;Are you older than fifth grade&#8221;</a>. Its actual content is much more interesting that the crappy headline. <cite class="vcard"><a class="url fn" href="http://blog.kakkoi.net/uri/aHR0cDovL3d3dy5kcmVhbWhvc3QuY29tL3Byb2ZpbGUtam9zaGouaHRtbA.curie,80,302"><span class="given-name">Josh</span> <span class="family-name">Jones</span></a> (<span class="org">Dreamhost</span> <span class="role">Co-Founder</span>)</cite> write a historic trackback of Dreamhost since 10 years ago. The below screenshot has lots thing to says about their business model.</p>
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/dreamhost.JPG" alt="dreamhost 1997" width="501" height="311" /></p>
<p class="cb">The 9o&#8217;s tag clouds is much larger than today&#8217;s. So I&#8217;m sure you looking at the cloudy links. There is package for <strong>Adult site hosting</strong>. This is what Josh&#8217;s has to say regarding DreamHost early days marketing strategy.</p>
<p><small>Excerpt from are-you-older-than-a-fifth-grader</small></p>
<blockquote cite="http://blog.dreamhost.com/2007/09/24/are-you-older-than-a-fifth-grader/"><p class="cite">It took about a week before we realized that unlimited bandwidth plus adult content equals not good. Some of these people were using over a GB a day of transfer.. and according to an early email from michael, we needed to be making $200/GB to stay afloat! We immediately had to re-negotiate with some of those early adopters.. one guy began paying $700/month, and others left.<br/><br/>We did learn an important lesson though, and that was that some of those $100/month adult sites used hardly ANY bandwidth at all! And thus, the truth about overselling was realized!<br/><br/><strong>(Ha, if you thought having a dedicated adult hosting plan was crazy, before dreamhost.com launched we had a dedicated warez hosting plan!)</strong><br/><br/>We also had “colocation” options back then</p>
</blockquote>
<p>10 years ago this guys are crazy (for money, we all do). Back in 97&#8242; google is still in lab (and its not even called google they name it backrub). Search engine projects is still in early phase. So nothing to worry about adult hosting. After ten years I hope they do honest business and not making any high risks strategy.As getting cheap hosting is not a trends anymore.</p>
<p>In my opinion hosting companies should take more wider steps on building trusts based on standard web policy for hosting industry. Being graylisted by google wont make them very famous, nobody want to be on that lists. Dreamhost should resolved this issue immediately (pronto) or risked losing more customers. It would be a waste of 10 years glory. </p>
<p>This could be the worst case for dreamhost . Hopefuly they can clear beth&#8217;s and their Google problem. We dont have to see web hosting provider being banned as they new trends just right after recent controversy over &#8220;paid links &#038; payperpost&#8221; issue.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/dreamhost-is-being-sandbox-by-google/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove wordpress.net.in spams</title>
		<link>http://42.kaizeku.com/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/</link>
		<comments>http://42.kaizeku.com/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/#comments</comments>
		<pubDate>Fri, 30 Nov 2007 09:06:54 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[backdoor]]></category>

		<category><![CDATA[cloacking]]></category>

		<category><![CDATA[default-filters]]></category>

		<category><![CDATA[goro]]></category>

		<category><![CDATA[spam]]></category>

		<category><![CDATA[web+sniffer]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-spam-injection-infected-by-mike-jagger-goro-class-mailphp/</guid>
		<description><![CDATA[

I found this while browsing WordPress support forum, some of these victims update their default_filters.php and upload class-mail.php inside their WordPress without being aware that it&#8217;s a backdoor (wordpress.net.in). There is no class-mail.php in WordPress except class-phpmailer.php. So don&#8217;t get confuse by it.
Below is a quick workaround on how you can removed the offending goro [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />I found this while browsing WordPress support forum, some of these victims update their <strong>default_filters.php</strong> and upload <tt class="di">class-mail.php</tt> inside their WordPress without being aware that it&#8217;s a <a href="http://en.wikipedia.org/wiki/Backdoor_%28computing%29" class="exturl icn-r1">backdoor</a> (wordpress.net.in). There is no <strong>class-mail.php</strong> in WordPress except <strong>class-phpmailer.php</strong>. So don&#8217;t get confuse by it.</p>
<p>Below is a quick workaround on how you can removed the offending <strong class="fw-">goro</strong> spamware injection before Google banned you from the internet pipes.</p>
<p><span id="more-51"></span></p>
<h2 class="cb mgt mgb-">Workaround</h2>
<ul class="xoxo exturl pdt">
<li>For temporary disable remote include in <tt class="di">php.ini</tt> settings.
<pre class="prebox">
;;;;;;;;;;;;;;;;;;
; Fopen wrappers ;
;;;;;;;;;;;;;;;;;;

; Whether to allow the treatment of URLs (like http:// or ftp://) as files.
allow_url_fopen = off
allow_url_include = off
</pre>
</li>
<li>Check your <em>.htaccess</em> for suspicious redirect.</li>
<li>Find <strong>class-mail.php</strong> inside <tt class="di">&#8220;*/wp-includes/&#8221;</tt> directory and removed it.</li>
<li>Find the following code inside <tt class="di">&#8220;*/wp-includes/default_filters.php&#8221;</tt> and removed it
<pre class="prebox">
add_action('wp_footer','wpc7c16b8466d864eeefd20050625c7775');
function wpc7c16<>b8466d864eeefd20050625c7775() {
@include('./wp-includes/class-mail.php');
if(sizeof($wparr)>0){
echo "!div id=\"goro\"!";
foreach($wparr as $k=>$v){
echo "“.ucwords($v[’key’]).”\n”;
if($i++==$inum) break;
}
echo “!/div!”.$_footer;
}
}
</pre>
</li>
<li>
<h3>Robots.txt Exclusion</h3>
<p><span class="fw">Optional</span> - Prevent googlebot from indexing the static spam page.<br />
Login to <tt class="di">Wordpress Admin > Manage > Files > Other Files</tt> &rarr; Key in &#8220;Robots.txt&#8221;. Add the following code.</p>
<pre class="prebox">
User-agent: Googlebot
Disallow: /*?*
Disallow: /*?
</pre>
<p>Refer <a href="http://blog.kakkoi.net/robots.txt" class="inturl icn-r1">robots.txt</a>.
</li>
</ul>
<h2>Possible WordPress class (suspicious) files that would be tempered</h2>
<p>Md5 checksum the following files, compare it with official versions from <a href="http://wordpress.org/download/release-archive/" class="exturl icn-r1">WordPress Release Archive</a>.</p>
<ul class="xoxo exturl">
<li><a href="http://xref.redalt.com/wptrunk/wp-includes/wp-db.php.source.htm">wp-db.php</a></li>
<li><a href="http://xref.redalt.com/wptrunk/wp-includes/gettext.php.source.htm">gettext.php</a></li>
</ul>
<p class="mgt">The above methods only remove and disabled the spams links, there is no guarantee that it will protected you from future vulnerabilities. Backup (or export your post using WordPress eXtended RSS -WRX) and perform a <a href="http://codex.wordpress.org/Upgrading_WordPress">full upgrade</a>.</p>
<dl class="r" style="padding:18px 2px;margin:18px 0px;border:1px solid #ccc;border-width:1px 0pt">
<dt class="title">Dec 13, 2007</dt>
<dd>
<p>I just notice this recently. You&#8217;ll need to check your site HTTP Header. Most of the hijacked websites doesn&#8217;t response with correct HTTP Status Header <tt class="di">(400<>500)</tt>. My guess is they did this to cloak from being crawl by search engine spiders. If you had cleaned all the infected files and your header doesn&#8217;t response correctly get a <a class="exturl icn-r1" href="http://www.google.com/search?q=apache+rootkit+scans">rookit scanner</a>.</p>
</dd>
<dd>
<p class="notice">Check your website status header, try cloak your browser (UA) as Search Engine Crawler. The following screenshot will show you how to setup this at web-sniffer.net.</p>
<p><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/change-user-agent-strings-as-googlebot.png' alt='change user agent strings as googlebot' style="padding:10px 2px;margin:10px 0px;border:1px solid #eee" width="584" height="274" longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/change-user-agent-strings-as-googlebot.png" />
<p>This methods may not work if the cloaking scripts used IP base tracking. So try on different user agent string (ie: inoktomi, askjeeves, ia_archiver). </p>
<h3>Firefox Browser</h3>
<p>You can also override your useragent string with firefox &darr;.</p>
<p> <tt class="db" style="padding:3px;background-color:#fff7c7;color:#333">about:config &rarr; general.useragent.overide = &#8216;<a href="http://www.google.com/search?q=search+engine+user+agent" rel="external nofollow" rev="google:query">ua strings</a>&#8216;</tt></p>
</dd>
</dl>
<h3>Wordpress.net.in Backdoor</h3>
<p><a href='#' id='open-extra-info' onclick='wpi_fxToggle("#extra-info");return false;'>Extra info</a></p>
<dl class="r">
<dd id="extra-info" style="display:none"><strong>Dec 14, 2007</strong>
<p>I did some research at <a href="http://www.archive.org">archive.org</a>. It seem our wordpress.net.in Seo Spam has been going on since 2005. The first variant used file_get_contents() PHP functions to retrieve their sources code (A <a href="http://www.phpclasses.org/browse/file/7820.html">UTF MAP Decoder</a> 1974 Php Class ). </p>
<p>I also found a signature name <strong>alxumuk</strong> (at MIT &#038; wordpress.net.in). His first historic test can be root back at <tt>*.media.mit.edu/~?</tt> server (I hide the userid as it may be &#8220;false positive&#8221;). After my first search on google for alxumuk all the results has been scraped out by Google &#038; &#8220;Google alert&#8221; so there is no references to this query in Google Index.</p>
<p>My query for <tt class="db" style="padding:3px;background-color:#fff7c7;color:#333">file_get_contents include require allintext:1974.*</tt> (the UTF decode package) and the signature (alxumuk) will return <em>403 Forbidden</em>.</p>
<p style="text-align:center"><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/google-advance-query-403.jpg' alt='Google advance query 403' longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/google-advance-query-403.jpg" width="469" height="600" /></p>
<p>As <a href="http://www.google.com/advanced_search?hl=en" hreflang="en" rel="external" rev="google:search">Google Advanced Search</a> blocked &#8220;the query&#8221; this may confirm that 1974.* (UTF decode) is probably the package for reading the bootstrap for wordpress.net.in backdoor (similar case like perl.santy net worm).</p>
<p> If this is a true Net Worm, I suggest anyone with older versions of Wordpress should removed\ the meta generator tag (Wordpress versions) and disabled XML-RPC(&#038; RSD) for <a href="http://www.google.com/search?q=hardening+wordpress">hardening wordpress</a> from remote vectors vulnerabilities.</p>
</dd>
</dl>
<h2>Wordpress.net.in Doorway</h2>
<p><span class="fw">Dec 24, 2007</span> &rarr; <tt class="di">http://www.wordpress.net.in/mentors/alxumuk/</tt></p>
<h2>Backdoor Files</h2>
<p>inside <tt class="di">wp-includes</tt> directory.</p>
<ul>
<li>compat.php - <small>(replace with latest version)</small></li>
<li>class-mail.php <small>delete</small></li>
</ul>
<p>scan &#038; removes all backdoor files and create a <tt class="di">.htaccess</tt> file inside <tt class="di">wp-includes</tt> &#038; <tt class="di">wp-content/plugins</tt>. Then add the following code to disabled directory listing (prevent informations leak &#038; Directory search index).</p>
<pre class="smallbox">Options -Indexes</pre>
<h2>Wordpress.net.in New Partner</h2>
<p><small>Feb 23th 2008</small>, We found a similar signature like wordpress.net.in at qwetro.com (germany). Probably from the same attacker with different agenda. </p>
<h2>removes malicious create_function wp_head filters</h2>
<p>This are fixes for <strong class="fw-">wordpress.net.in spams</strong> header injection.</p>
<pre class="prebox">&#47;&#42;&#42;
 &#42; Remove create_function action hook
 &#42; append on wordpress wp_head filters
 &#42;
 &#42; &#64;author Avice De&#39;v&#233;reux &#60;ck&#64;kaizeku&#46;com&#62;
 &#42; &#64;copyright Copyright &#40;c&#41; 2006 Avice De&#39;v&#233;reux
 &#42; &#64;version 1&#46;0
 &#42; &#64;license http&#58;&#47;&#47;www&#46;gnu&#46;org&#47;licenses&#47;lgpl&#46;html GNU Lesser General Public License
 &#42; &#64;link http&#58;&#47;&#47;blog&#46;kaizeku&#46;com&#47;wordpress&#47;goro&#45;spam&#45;injection&#45;wp&#45;head&#45;patch&#47;
 &#42;&#47;
function remove_create_function_action&#40;&#41;
&#123; global &#36;wp_filter&#59;

	&#36;action_ref	&#61; &#39;wp_head&#39;&#59;
	&#36;filter 	&#61; &#36;wp_filter&#91;&#36;action_ref&#93;&#59;
	&#36;_lambda	&#61; array&#40;&#41;&#59;

	foreach&#40;range&#40;1&#44;10&#41; as &#36;priority&#41;&#123;

		if &#40;isset&#40;&#36;filter&#91;&#36;priority&#93;&#41;&#41;
		&#123;
			foreach&#40;&#36;filter&#91;&#36;priority&#93; as &#36;registered_filter &#41;&#123;

				&#36;callback &#61; &#40;string&#41; &#36;registered_filter&#91;&#39;function&#39;&#93;&#59;

				if &#40; preg_match&#40;&#34;&#47;lambda&#47;&#34;&#44; &#36;callback&#41; &#41; &#123;
		 	 		&#36;_lambda&#91;&#36;priority&#93;&#91;&#93; &#61; &#36;callback&#59;
				&#125;
			&#125;

		&#125;
	&#125;

	if &#40; count&#40;&#36;_lambda&#41; &#62;&#61; 0 &#41;&#123;

		foreach&#40;&#36;_lambda as &#36;priority &#61;&#62; &#36;callback&#41; &#123;
			if &#40; has_filter&#40;&#36;action_ref&#44;&#36;callback&#41; &#41;&#123;
				remove_filter&#40;&#36;action_ref&#44; &#36;callback&#44; &#36;priority&#44; 1&#41;&#59;
			&#125;
		&#125;
	&#125;
&#125;

add_action&#40;&#39;init&#39;&#44;&#39;remove_create_function_action&#39;&#41;&#59;
</pre>
<p>The plugin&#8217;s can be download at <a href="http://blog.kaizeku.com/wordpress/goro-spam-injection-wp-head-patch/">Kaizeku Ban, goro spam injection fixes</a></p>
<h2 class="cb mgb-" id="rel-links">Related Posts</h2>
<ul class="xoxo exturl">
<li><a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked" title="Bluehost HostMonster CEO Blog hacked (wordpress.net.in)" rev="site:related" rel="archive" class="inturl">Bluehost HostMonster CEO&#8217;s Blog hacked (wordpress.net.in)</a></li>
<li><a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEOs Hacked Again - Strike II" rev="site:related" rel="archive" class="inturl">Matt Heaton Bluehost Hostmonster CEO&#8217;s Hacked Again - Strike II</a></li>
</ul>
<h2 class="cb mgt mgb-" id="extt-links">External Links</h2>
<ul class="xoxo exturl">
<li><a rel="nofollow robots-nofollow" href="http://web-sniffer.net/">Websniffer View HTTP Request and Response Header</a></li>
<li><a rel="nofollow robots-nofollow" href="/uri/d29yZHByZXNzLm9yZy9zdXBwb3J0L3RvcGljLzE0NTg4MQ.curie,80,302">Wordpress Support Forum</a></li>
<li><a rel="nofollow" href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4743" rel="external" rev="nist:nvd">National Vulnerability Database Wordpress 2.0 > 2.0.6</a></li>
</ul>
<h3 class="cb mgt title-">Short URL</h3>
<ul class="xoxo dn">
<li>
<input type="text" size="40" class="on-click-select" value="http://blog.kakkoi.net/ref/fixwpblackhatspam" /></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to safely remove AcroRd32Info.exe</title>
		<link>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</link>
		<comments>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 13:05:00 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Adobe]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[AcroRd32Info]]></category>

		<category><![CDATA[acrotray]]></category>

		<category><![CDATA[AdobeReader.K]]></category>

		<category><![CDATA[Explorer]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[pdf]]></category>

		<category><![CDATA[prefetching]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</guid>
		<description><![CDATA[<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package  for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>

<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for  browsing the folder without opening any PDF files yet.</p> 

<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p> 

<p>AcroRd32Info stay in your memory so consider it as a pest. So how to disabled it?</p>
]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>
<p><span id="more-37"></span></p>
<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for browsing the folder without opening any PDF files yet.</p>
<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p>
<p>Adobe Reader is cheating. Its understable that with this methods it will improve the Acrobat boot time log, but I dont see much differences when its running in the background preparing to load a single PDF documents, its a pollutions.</p>
<p>AcroRd32Info stay in your memory so consider it as a <span class="hilite-3">pestware</span>.</p>
<p>Here&#8217;s how you can <em>safely</em> removed this programs. </p>
<h3 id="removed">The proper way</h3>
<ul>
<li>open <strong>Adobe AcroRd32</strong></li>
<li>Edit &raquo; Preferences </li>
<li>Select the <strong>internet</strong> categories in the menu list then disabled <br /><strong>Allow fast web view</strong> &#038; <strong>Allow speculative downloading in the background</strong></li>
</ul>
<p>If thats doesnt work, you try this <strong>unrecommended</strong> method to disabled it.</p>
<ul>
<li>Browse to Adobe Reader directory usually at &#8220;Program Files\Adobe\Reader\&#8221; </li>
<li>Find <strong>AcroRd32Info.exe</strong></li>
<li>Rename it from <strong>AcroRd32Info.exe</strong> to <strong>Acro_Rd32Info.exe</strong></li>
</ul>
<h2>Recent Exploit on Adobe Reader</h2>
<h3 id="AdobeReaderK">Exploit:W32/AdobeReader.K</h3>
<p class="notice" style="padding:10px;margin:18px auto;border:1px solid #ccc">From FSECURE, <a href="http://blog.kakkoi.net/uri/d3d3LmYtc2VjdXJlLmNvbS92LWRlc2NzL2V4cGxvaXRfdzMyX2Fkb2JlcmVhZGVyX2suc2h0bWw.curie,80,302" rel="external" title="External site">Exploit:W32/AdobeReader.K</a> is detection of a malicious PDF file that is being heavily spammed through e-mail and it appears as an attachment.<br />
This malicious PDF file takes advantage of a vulnerability on the URI handling of PDF files. This vulnerability affects IE7, Adobe Acrobat, and Adobe Reader on some platforms.<br />
Users should update their Adobe Reader installations. </p>
<h3>Affected Software Versions</h3>
<p>Adobe Reader 8.1 and earlier, Adobe Reader 7.0.9 and earlier. Adobe Acrobat Professional, 3D and Standard 8.1 and earlier versions, Adobe Acrobat Professional, Standard, 3D and Elements 7.0.9 and earlier.</p>
<p>More info on this exploits at <a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNy01MDIw.curie,80,302">National Vulnerability Database</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Condolense to Sean Taylor (Washington Redskin).</title>
		<link>http://42.kaizeku.com/news/condolense-to-sean-taylor-washington-redskin/</link>
		<comments>http://42.kaizeku.com/news/condolense-to-sean-taylor-washington-redskin/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 01:59:18 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[jackie garcia]]></category>

		<category><![CDATA[miami]]></category>

		<category><![CDATA[sean taylor]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/news/condolense-to-sean-taylor-washington-redskin/</guid>
		<description><![CDATA[

Miami native Sean Taylor was pronounced dead early Tuesday Morning, at Jackson Memorial Hospital in Miami. Sean Taylor was shot at his Palmetto Bay home early Monday morning in the upper part of his leg where he suffered massive blood loss from a severed femoral artery.
After surgery Sean Taylor was said to be responsive to [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Miami native <strong>Sean Taylor</strong> was pronounced dead early Tuesday Morning, at Jackson Memorial Hospital in Miami. Sean Taylor was shot at his Palmetto Bay home early Monday morning in the upper part of his leg where he suffered massive blood loss from a severed femoral artery.</p>
<p>After surgery Sean Taylor was said to be responsive to doctors which gave his family a little hope. But he passed away early in that morning. Police are investigating the home invasion and murder of Sean Taylor. Sean Taylor is survived by his high school sweetheart <strong>Jackie Garcia</strong>, eight-teen month old daughter named Jackie, and his family.</p>
<p>read more on this at <a href="http://blog.kakkoi.net/uri/d3d3Lm1pYW1paGVyYWxkLmNvbS80NTkvc3RvcnkvMzIzMDkzLmh0bWw.curie,80,302">Miami Herald</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/news/condolense-to-sean-taylor-washington-redskin/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mark W. Everson (American Red Cross) Resign Statement</title>
		<link>http://42.kaizeku.com/news/mark-w-everson-resign-statement/</link>
		<comments>http://42.kaizeku.com/news/mark-w-everson-resign-statement/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 01:16:56 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[mark everson]]></category>

		<category><![CDATA[Mark W. Everson]]></category>

		<category><![CDATA[on fire]]></category>

		<category><![CDATA[red cross]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/news/mark-w-everson-resign-statement/</guid>
		<description><![CDATA[

The American Red Cross Announced today that its Board of Governors asked for and received the resignation of President and CEO Mark W. Emerson, Effective immediately. Concurrently, the Board appointed Mary S. Elcano, General Counsel as Interim President and CEO.


Excerpt from washigtonpost
Everson, 53, who is married and has two children, released a statement today saying, [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/american-red-cross.gif' alt='american-red-cross.gif' style="float:left;margin-right: 5px;padding:10px" />The American Red Cross Announced today that its Board of Governors asked for and received the resignation of President and CEO <strong>Mark W. Emerson</strong>, Effective immediately. Concurrently, the Board appointed <strong>Mary S. Elcano</strong>, General Counsel as Interim President and CEO.</p>
<p><span id="more-30"></span><br />
<img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/mark-everson-statement.gif' alt='mark-everson-statement' class="fl" /><br />
<em>Excerpt from washigtonpost</em></p>
<blockquote cite="http://www.washingtonpost.com/wp-dyn/content/article/2007/11/27/AR2007112701307.html?hpid=topnews"><p>Everson, 53, who is married and has two children, released a statement today saying, &#8220;I am resigning my position for personal and family reasons and deeply regret it is impossible for me to continue in a job so recently undertaken. . . . I leave with extraordinary admiration for the American Red Cross, the service its men and women provide our nation, and for the humanitarian work of the Red Cross/Red Crescent movement across the world.&#8221;</p></blockquote>
<p><strong>Mark W. Everson</strong> resigned today because he engaged in a personal relationship with an employee. </p>
<p>More on this at <a title="Mark Everson at Washington Post articles" href="http://blog.kakkoi.net/uri/d3d3Lndhc2hpbmd0b25wb3N0LmNvbS93cC1keW4vY29udGVudC9hcnRpY2xlLzIwMDcvMTEvMjcvQVIyMDA3MTEyNzAxMzA3Lmh0bWw_aHBpZD10b3BuZXdz.curie,80,302">Washington Post</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/news/mark-w-everson-resign-statement/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt cutts Snippet video - The anatomy of a search result</title>
		<link>http://42.kaizeku.com/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/</link>
		<comments>http://42.kaizeku.com/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 18:58:15 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Google]]></category>

		<category><![CDATA[google+webmaster]]></category>

		<category><![CDATA[links]]></category>

		<category><![CDATA[matt+cutts]]></category>

		<category><![CDATA[meta]]></category>

		<category><![CDATA[pagerank]]></category>

		<category><![CDATA[seo]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/</guid>
		<description><![CDATA[

Matt cutts (Head of Google Webspam team) explained the important part of meta content.
view the video here

]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Matt cutts (Head of Google Webspam team) explained the important part of meta content.</p>
<p>view the video <a href="http://www.youtube.com/v/vS1Mw1Adrk0">here</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/matt-cutts-snippet-video-the-anatomy-of-a-search-result/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to Block Acces to Unsavory Websites Without using Firewall or third party software</title>
		<link>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/</link>
		<comments>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 17:42:51 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[block website]]></category>

		<category><![CDATA[dialer]]></category>

		<category><![CDATA[filtering]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[opendns]]></category>

		<category><![CDATA[phissing site]]></category>

		<category><![CDATA[spams]]></category>

		<category><![CDATA[window]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/</guid>
		<description><![CDATA[

There is many reason why you need to block certain website from being access in your network. below is a &#8220;the few reason why&#8221;. 

It&#8217;s a warez and porn sites.
I don&#8217;t want my employee to view my Competitor Websites.
I&#8217;m using illegal software and It seem necessary to disable the automated online registry checkup. ;p
I&#8217;m against [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>There is many reason why you need to block certain website from being access in your network. below is a &#8220;the few reason why&#8221;. </p>
<ol>
<li>It&#8217;s a warez and porn sites.</li>
<li>I don&#8217;t want my employee to view my Competitor Websites.</li>
<li>I&#8217;m using illegal software and It seem necessary to disable the automated online registry checkup. ;p</li>
<li>I&#8217;m against this [countryname] I want to block all this particular domain from being access.</li>
<li>I hated this [socialnetworksite]</li>
</ol>
<p><span id="more-26"></span></p>
<h2>Safe Blocking</h2>
<p>Here&#8217;s two methods you can safely used to block or redirect unwanted website from being access without using third party software.</p>
<h3>1. Block Website using Windows Host file</h3>
<p>Open Window explorer, browse to <em>C:\WINDOWS\system32\drivers\etc</em> click on the file name &#8220;<strong>host</strong>&#8221; <small>(the file has no extension)</small> make a backup copy first. Then right click view file properties and disabled the read only attributes and open it with a text editor (i.e: notepad).</p>
<h5>Windows host settings instructions note</h5>
<blockquote cite="http://blog.kakkoi.net/windows/how-to-block-website-without-using-firewall/"><p>This file contains the mappings of IP addresses to host names. Each entry should be kept on an individual line. The IP address should be placed in the first column followed by the corresponding host name. The IP address and the host name should be separated by at least one space.</p></blockquote>
<p><tt>route-to target-hostname</tt><br />
example<br />
<tt>127.0.1.1 www.thewebsite.com</tt></p>
<p class="notice">note: 127.0.1.1 is you localhost address this is where you want the target-hostname/website to redirect. thewebsite.com is the targeted website URL.</p>
<p>alternatively you can also redirect it to google<br />
<tt>64.233.167.99 www.thewebsite.com</tt></p>
<p>Save the file and restore back the read only mode, then type in the block address url in your browser see if works.</p>
<h2>OpenDNS filtering</h2>
<p>The second methods is universal, its work on any operating systems. <a href="http://www.opendns.com">OpenDNS</a>filtering. This articles wont teach you how to setup opendns, you can read it at <a href="http://www.opendns.com/support/article/39">https://www.opendns.com/start</a>. After you had setup OpenDNS account. Read their <a href="http://www.opendns.com/support/article/39">KB39 articles</a><br />
<img src="http://blog.kakkoi.net/wp-content/uploads/2007/11/open-dns-blokcdomain.png" alt="open-dns-blokcdomain.png" width="350" /><br />
its pretty much straight forward from there on. I&#8217;m sure you wont have problem configuring opendns filter . everything is just 2 click way.</p>
<h2 class="cb">Example Blocked Lists</h2>
<pre class="prebox">
127.0.0.1	babe.the-killer.bz
127.0.0.1	www.babe.the-killer.bz
127.0.0.1	babe.k-lined.com
127.0.0.1	www.babe.k-lined.com
127.0.0.1	did.i-used.cc
127.0.0.1	www.did.i-used.cc
127.0.0.1	coolwwwsearch.com
127.0.0.1	www.coolwwwsearch.com
127.0.0.1	coolwebsearch.com
127.0.0.1	www.coolwebsearch.com
127.0.0.1	hi.studioaperto.net
127.0.0.1	www.hi.studioaperto.net
127.0.0.1	webbrowser.tv
127.0.0.1	www.webbrowser.tv
</pre>
<p class="notice">Notes: Notice the double entries for each domain <span class="fw">example.com</span> and <span class="fw">www.example.com</span> , You will need both long and short URL for effective blocking. Dont depend on canonical address</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-block-website-without-using-firewall/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Beware of this site</title>
		<link>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/</link>
		<comments>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/#comments</comments>
		<pubDate>Sat, 24 Nov 2007 03:03:05 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Virus]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[JS/Exploit.ADODB.Stream NAP Trojan warez streaming]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/virus/js-exploit-adodb-stream-nap-rojan/</guid>
		<description><![CDATA[

Its quite rare to see website attacking visitors but the following site is an exception.

girlhell.org
66.79.184.58
Apr 27 08 - usawarez.net

There is few known threads from the above website

JS/Exploit.ADODB.Stream NAP Trojan
Hidden download.
usawarez - False Image Checksum/corrupted 

Fracois Paget from McAfee explain in great details regarding this Stream Attack and their Complete Methods. I&#8217;m quite amazed with the [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Its quite rare to see website attacking visitors but the following site is an exception.</p>
<ol>
<li><code>girlhell.org</code></li>
<li><code>66.79.184.58</code></li>
<li><small>Apr 27 08</small> - <code>usawarez.net</code></li>
</ol>
<p>There is few known threads from the above website</p>
<ol>
<li><strong>JS/Exploit.ADODB.Stream NAP Trojan</strong></li>
<li>Hidden download.</li>
<li>usawarez - False Image Checksum/corrupted </li>
</ol>
<p>Fracois Paget from McAfee explain in great details regarding this Stream Attack and their Complete Methods. I&#8217;m quite amazed with the analysis. read it all <a href="http://blog.kakkoi.net/uri/d3d3LmF2ZXJ0bGFicy5jb20vcmVzZWFyY2gvYmxvZy9pbmRleC5waHAvMjAwNy8wNS8yNS9hbm90aGVyLWlkZW50aXR5LXRoZWZ0LXN0b3J5LTIv.curie,80,302" title="McAfee Blog" rel="external">here</a>.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/virus/js-exploit-adodb-stream-nap-rojan/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Change Scarlett Johansson into a zombie</title>
		<link>http://42.kaizeku.com/web-services/sclipo/change-scarlett-johansson-into-a-zombie/</link>
		<comments>http://42.kaizeku.com/web-services/sclipo/change-scarlett-johansson-into-a-zombie/#comments</comments>
		<pubDate>Fri, 23 Nov 2007 22:55:59 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Photoshop]]></category>

		<category><![CDATA[Sclipo]]></category>

		<category><![CDATA[Tutorials]]></category>

		<category><![CDATA[Scarlett Johansson]]></category>

		<category><![CDATA[video]]></category>

		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/sclipo/change-scarlett-johansson-into-a-zombie/</guid>
		<description><![CDATA[

Learn how to change the sexy Hollywood star into a real zombie with this photoshop video &#8230;enjoy!
by MonaLisaChild


 



]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Learn how to change the sexy Hollywood star into a real zombie with this photoshop video &#8230;enjoy!</p>
<p>by <a href="http://blog.kakkoi.net/uri/d3d3LnNjbGlwby5jb20vdXNlci9Nb25hTGlzYXNDaGlsZA.curie,80,302">MonaLisaChild</a><br />
<span id="more-22"></span></p>
<dl style="margin: 0pt auto; padding: 0pt; width: 425px">
<dd style="margin: 0pt; padding: 0pt"> <object height="350" width="425"><param name="movie" value="http://www.sclipo.com/outer_flvplayer_new.swf?file=WWV3W8V2R3"></param><param name="wmode" value="transparent"></param><embed src="http://www.sclipo.com/outer_flvplayer_new.swf?file=WWV3W8V2R3" type="application/x-shockwave-flash" wmode="transparent" height="350" width="425"></embed></object>
</dd>
</dl>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/web-services/sclipo/change-scarlett-johansson-into-a-zombie/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Warez site with High Pagerank. That&#8217;s not fair Google</title>
		<link>http://42.kaizeku.com/google/warez-site-with-high-pagerank-thats-not-fair-google/</link>
		<comments>http://42.kaizeku.com/google/warez-site-with-high-pagerank-thats-not-fair-google/#comments</comments>
		<pubDate>Mon, 19 Nov 2007 18:14:51 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[linkexchange]]></category>

		<category><![CDATA[matt+cutts]]></category>

		<category><![CDATA[pagerank]]></category>

		<category><![CDATA[payperpost]]></category>

		<category><![CDATA[pr6]]></category>

		<category><![CDATA[trustrank]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/warez-site-with-high-pagerank-thats-not-fair-google/</guid>
		<description><![CDATA[Just google for "warez full apps", most of results sites has PR6. I don't like to put any name here so do your own research and go ask Matt's for good answered. If you arent satisfied with this issue I suggest you open Google Webmaster accounts and submit those site for reviews/sandbox.

After the recent controversy over payperpost and linkexchange policy. What do you think of PR over this issue? Do you care about SEO?.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p>Just google for &#8220;warez full apps&#8221;, most of results sites has PR6. I don&#8217;t like to put any name here so do your own research and go ask <a href="http://www.mattcutts.com/blog/">Matt&#8217;s</a> for good answered. If you arent satisfied with this issue I suggest you open Google Webmaster accounts and submit those site for reviews/sandbox.</p>
<p>After the recent controversy over payperpost and linkexchange policy. What do you think of PR over this issue? Do you care about SEO?.</p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/warez-site-with-high-pagerank-thats-not-fair-google/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
