<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for [R|H]ack</title>
	<atom:link href="http://growl.superhappykittymeow.com/hacks/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://growl.superhappykittymeow.com/hacks</link>
	<description>Investigating compromises and cleaning up the internet</description>
	<lastBuildDate>Mon, 17 Jan 2011 21:58:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Detecting the first signs of a compromise by Evan</title>
		<link>http://growl.superhappykittymeow.com/hacks/2009/09/detecting-the-first-signs-of-a-compromise/comment-page-1/#comment-2609</link>
		<dc:creator>Evan</dc:creator>
		<pubDate>Mon, 17 Jan 2011 21:58:17 +0000</pubDate>
		<guid isPermaLink="false">http://growl.superhappykittymeow.com/hacks/?p=3#comment-2609</guid>
		<description>Nice post! I particularly like the use of &quot;!!$&quot;. One small nitpick, though, and I know this is an old post so you may very well know this by now, but the -a in netstat -plan makes the -l redundant, since -a shows both listening and established connections. I do like the mnemonic of -plan though :D

I personally tend to separate the listings into -antp and -anup, leaving -anxp for IPC research if lsof or ps are suspicious.</description>
		<content:encoded><![CDATA[<p>Nice post! I particularly like the use of &#8220;!!$&#8221;. One small nitpick, though, and I know this is an old post so you may very well know this by now, but the -a in netstat -plan makes the -l redundant, since -a shows both listening and established connections. I do like the mnemonic of -plan though <img src='http://growl.superhappykittymeow.com/hacks/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>I personally tend to separate the listings into -antp and -anup, leaving -anxp for IPC research if lsof or ps are suspicious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dissection of a Zbot spam by Xmitter Technologies &#187; Blog Archive &#187; Email Phishing Warning</title>
		<link>http://growl.superhappykittymeow.com/hacks/2009/10/dissection-of-a-zbot-spam/comment-page-1/#comment-7</link>
		<dc:creator>Xmitter Technologies &#187; Blog Archive &#187; Email Phishing Warning</dc:creator>
		<pubDate>Mon, 19 Oct 2009 22:46:37 +0000</pubDate>
		<guid isPermaLink="false">http://growl.superhappykittymeow.com/hacks/?p=29#comment-7</guid>
		<description>[...] has written a detailed report about a complex phishing email that has been sighted in the wild. This phishing message makes use [...]</description>
		<content:encoded><![CDATA[<p>[...] has written a detailed report about a complex phishing email that has been sighted in the wild. This phishing message makes use [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dissection of a Zbot spam by kale</title>
		<link>http://growl.superhappykittymeow.com/hacks/2009/10/dissection-of-a-zbot-spam/comment-page-1/#comment-3</link>
		<dc:creator>kale</dc:creator>
		<pubDate>Wed, 14 Oct 2009 23:34:32 +0000</pubDate>
		<guid isPermaLink="false">http://growl.superhappykittymeow.com/hacks/?p=29#comment-3</guid>
		<description>Hello Ricardo,

First step is to run some anti-virus on their computer! F-Secure has an online scanner available &lt;a href=&quot;http://www.f-secure.com/en_US/security/security-lab/tools-and-services/online-scanner/index.html&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;, which should be able to detect this Zbot variant and clean his computer.  After the virus is removed, educate your coworker to not click on links from strangers :-)</description>
		<content:encoded><![CDATA[<p>Hello Ricardo,</p>
<p>First step is to run some anti-virus on their computer! F-Secure has an online scanner available <a href="http://www.f-secure.com/en_US/security/security-lab/tools-and-services/online-scanner/index.html" rel="nofollow">here</a>, which should be able to detect this Zbot variant and clean his computer.  After the virus is removed, educate your coworker to not click on links from strangers <img src='http://growl.superhappykittymeow.com/hacks/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dissection of a Zbot spam by Ricardo</title>
		<link>http://growl.superhappykittymeow.com/hacks/2009/10/dissection-of-a-zbot-spam/comment-page-1/#comment-2</link>
		<dc:creator>Ricardo</dc:creator>
		<pubDate>Wed, 14 Oct 2009 17:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://growl.superhappykittymeow.com/hacks/?p=29#comment-2</guid>
		<description>Hello, today a coworker got an email like this and clicked on the link. What should I do?

Dear user of the idiomasperucom mailing service!
We are informing you that because of the security upgrade of the mailing service your mailbox (elsol_soporte@idiomasperu.com) settings were changed. In order to apply the new set of settings click on the following link:
http://idiomasperu.com/owa/service_directory/settings.php?email=elsol_soporte@idiomasperu.com&amp;from=idiomasperu.com&amp;fromname=elsol_soporte
Best regards, idiomasperu.com Technical Support.

Please give me some advice. I think this is a current massive phishing attack.</description>
		<content:encoded><![CDATA[<p>Hello, today a coworker got an email like this and clicked on the link. What should I do?</p>
<p>Dear user of the idiomasperucom mailing service!<br />
We are informing you that because of the security upgrade of the mailing service your mailbox (elsol_soporte@idiomasperu.com) settings were changed. In order to apply the new set of settings click on the following link:<br />
<a href="http://idiomasperu.com/owa/service_directory/settings.php?email=elsol_soporte@idiomasperu.com&amp;from=idiomasperu.com&amp;fromname=elsol_soporte" rel="nofollow">http://idiomasperu.com/owa/service_directory/settings.php?email=elsol_soporte@idiomasperu.com&amp;from=idiomasperu.com&amp;fromname=elsol_soporte</a><br />
Best regards, idiomasperu.com Technical Support.</p>
<p>Please give me some advice. I think this is a current massive phishing attack.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

