<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Malicious Site Analysis for dota11.cn injection</title>
	<atom:link href="http://www.sudosecure.net/archives/83/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sudosecure.net/archives/83</link>
	<description>is anything truly secure...</description>
	<pubDate>Fri, 05 Dec 2008 16:06:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>By: Mike</title>
		<link>http://www.sudosecure.net/archives/83#comment-116</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sat, 16 Aug 2008 07:05:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=83#comment-116</guid>
		<description>Now I'm no techy, but this mentioned .cn domain site link has replaced my profile information on an international penpal website. Seems strange, my email account has also been hacked by somebody who is now sending out emails with .cn links, not to mention the daily pile of spam sent with .cn links. Hotmail has been contacted - hopefully they can sort it out!</description>
		<content:encoded><![CDATA[<p>Now I&#8217;m no techy, but this mentioned .cn domain site link has replaced my profile information on an international penpal website. Seems strange, my email account has also been hacked by somebody who is now sending out emails with .cn links, not to mention the daily pile of spam sent with .cn links. Hotmail has been contacted - hopefully they can sort it out!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://www.sudosecure.net/archives/83#comment-55</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Wed, 28 May 2008 21:44:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=83#comment-55</guid>
		<description>This morning I reported dota11.cn to Google.com and they then reported the site to
&lt;a href="http://www.stopbadware.org/" title="StopBADware.org" rel="nofollow"&gt;

Google uses the StopBADware database to decide when to show a warning page to users.  And so Google users should now get a warning.

The bigger question is how is this happening?

In this case the targeted web servers seem to belong to small/medium businesses with low technical knowledge:

&lt;a href="http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=3409559&#38;SiteID=1" title="Microsoft Forum - SQL Server Data Access" rel="nofollow"&gt;

-Richard
comet at transbay dot net</description>
		<content:encoded><![CDATA[<p>This morning I reported dota11.cn to Google.com and they then reported the site to<br />
<a href="http://www.stopbadware.org/" title="StopBADware.org" rel="nofollow"></p>
<p>Google uses the StopBADware database to decide when to show a warning page to users.  And so Google users should now get a warning.</p>
<p>The bigger question is how is this happening?</p>
<p>In this case the targeted web servers seem to belong to small/medium businesses with low technical knowledge:</p>
<p></a><a href="http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=3409559&amp;SiteID=1" title="Microsoft Forum - SQL Server Data Access" rel="nofollow"></p>
<p>-Richard<br />
comet at transbay dot net</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
