<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; script injection</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/script-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Blackhat SEO Spammer targeting High PR WordPress Blog</title>
		<link>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</link>
		<comments>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/#comments</comments>
		<pubDate>Thu, 14 Feb 2008 20:14:48 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[owned]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[css cloacking]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[script injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/</guid>
		<description><![CDATA[thinkingphp.org (PR6) &#038; jensfrake.com (PR7) has been hijacked by “Wordpress Blackhat SEO Spammer” for this month. Both sites were running on WordPress 2.3.2.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />I&#8217;ve been monitoring <span class="vcard"><a class="url fn microformat icn-r1" href="http://mattheaton.com" title="bluehost &#038; hostmonster CEO">mattheaton.com</a></span> &#8220;<strong class="fw-">wordpress.net.in goro spam injections</strong>&#8221; for this past few months. Noticeably, the blackhat spamming method is changing dramatically. For those who are still unaware of Wordpress Goro Spam please read my earlier post &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO's Official Blog Hacked">Wordpress.net.in Spam injection</a>&#038; <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Gaming Bluehost &#038; Hostmonster CEO&#8217;s Blog</a>.</p>
<p><a href="http://thinkingphp.org" class="exturl icn-r1" title="thinkingphp.org">thinkingphp.org </a><small>(PR6)</small> &#038; <a href="http://jensfrake.com" title="jensfrake.com" class="exturl icn-r1">jensfrake.com</a> <small>(PR7)</small> has been hijacked by &#8220;Wordpress Blackhat SEO Spammer&#8221; for this month. Both sites were running on <strong>WordPress 2.3.2</strong>. </p>
<p>By now the <strong class="fw-"><em title="id goro">&lt;div id=&#8221;goro&#8221;&gt;</em></strong> signature has been replaced with &#8220;Inline CSS&#8221; wrapper.</p>
<h3>Cloacking Check on Mattheaton.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>32,246 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-source.txt' title='mattheaton-com-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-source.txt</a></dd>
<dt>Google bot</dt>
<dd>34,646 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/mattheaton-com-googlebot-source.txt' title='mattheaton-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">mattheaton-com-googlebot-source.txt</a></dd>
<dt>Difference</dt>
<dd>2,400 characters</dd>
</dl>
<p><span id="more-209"></span></p>
<h3>Cloacking Check on jensfrake.com &#038; blog.jensfrake.com</h3>
<dl class="def">
<dt>Normal Browser</dt>
<dd>59,580 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blogjensfrakecomsource.txt' title='blogjensfrakecomsource.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom.txt</a></dd>
<dt>Google bot</dt>
<dd>59,699 characters - <a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/blog-jensfrake-com-googlebot-source.txt' title='blog-jensfrake-com-googlebot-source.txt' class="inturl icn-l1" rel="nofollow noarchive noindex" type="text/plain">blogjensfrakecom-googlebot.txt</a></dd>
<dt>Difference</dt>
<dd>119 characters</dd>
</dl>
<p class="notice">While scanning jensfrake.com their server return 400-500 error, so we had to scan his (clone) subdomain blog.jensfrake.com instead of the main site</p>
<p>This time around, you wont see the spam on both of this website, all the spam links is position out of the client view-port (top -3337px, left -2227px). </p>
<p><small>another mathematical jokes, l33t.</small></p>
<pre>
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;
</pre>
<h5 class="mgb-">What&#8217;s new with Goro spam 2008</h5>
<ul class="xoxo exturl">
<li>WordPress <= 2.3.2 is vulnerable to this attack. </li>
<li>Inject Spamlinks wrap with extra Inline CSS for cloacking</li>
<li>Target High PR Sites &rarr; PR5 and above</li>
</ul>
<h5 class="mgt mgb-">Related Post</h5>
<ul class="xoxo exturl">
<li><a class="inturl" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked">Matt Heaton BlueHost HostMonster CEO&#8217;s Official Blog Hacked</a></li>
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed Wordpress.net.in Spam Injection">How to Removed Wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/" title="Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h3 class="mgt">External Links</h3>
<ul class="xoxo exturl">
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" title="National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities">National Vulnerabilities Database (NVD) on Wordpress 2.0 &gt; 2.0.5 vulnerabilities</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/blackhat-seo-spammer-target-high-pr-wordpress-blog/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
