<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hostlogue</title>
	<atom:link href="http://hostlogue.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://hostlogue.wordpress.com</link>
	<description>Total Dedication to customer&#039;s satisfaction</description>
	<lastBuildDate>Fri, 12 Jun 2009 10:58:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hostlogue.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Hostlogue</title>
		<link>http://hostlogue.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hostlogue.wordpress.com/osd.xml" title="Hostlogue" />
	<atom:link rel='hub' href='http://hostlogue.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Gumblar &#8211; Malware</title>
		<link>http://hostlogue.wordpress.com/2009/06/12/gumblar-malware/</link>
		<comments>http://hostlogue.wordpress.com/2009/06/12/gumblar-malware/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 10:58:17 +0000</pubDate>
		<dc:creator>websarga</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Gumbler Attack]]></category>

		<guid isPermaLink="false">http://hostlogue.wordpress.com/2009/06/12/gumblar-malware/</guid>
		<description><![CDATA[A very serious malware has surfaced in the internet and it proves to be very dangerous and malicious than the previous versions of similar malwares. The simple reason being it sends spam, sniffs ftp login details, overwrites .htaccess files to hijack your search engine results of your website and disables essential security software. When users [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hostlogue.wordpress.com&amp;blog=7440822&amp;post=60&amp;subd=hostlogue&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A very serious malware has surfaced in the internet and it proves to be very dangerous and malicious than the previous versions of similar malwares. The simple reason being it sends spam, sniffs ftp login details, overwrites .htaccess files to hijack your search engine results of your website and disables essential security software.<br />
When users visit a site that is infected with this malware, it installs itself in the visitors machine and starts acting on it own.<br />
Sniffing FTP Login Details<br />
——————–<br />
This is very dangerous and malicious part of the malware function. It sniffs the ftp logins that are used by the infected systems to upload their contents. It then sends the sniffed login details to the remote attacker. Once the ftp logins are received the remote attacker starts uploading perl files [.pl], .cgi files, .js files, .php files, .htm files which contain injected iframe or malware redirection coding. Previously these coding were evident while viewing the source of the file. But of late, they have started insterting malicious code as ascii numbers or hexas so that a noivce developer will not notice quickly.<br />
This type of injection cannot be scanned any anti-virus software as it wont be active unless it is view from a website.<br />
This is also injected to a website directly without ftping via sql injection or vulnerable include files that have full write permission etc. Also if the users have unprotected directories with full permission, then they will be tragetted to upload directly in to the server.<br />
Sending Spam<br />
———–<br />
Once the remote attacker uploads the malicious perl file using the password that he has sniffed using the above method, that file can be used to send spam mails / phishing mails at will. It is difficult to trace them or control them as most of the websites will have send mail enabled by default.<br />
Hijacking the Search Engine Results<br />
—————————-<br />
One common way these attackers use to spread this malware is to overwrite your .htaccess file to send all search engine hits from google/yahoo etc to their malware site. Hence as a user you might view the site when you access the site as www.domain.com but when you click on a search result of that domain in google or yahoo, it will be redirected to a malware website.<br />
Disables Security Software<br />
———————<br />
This malware is also capable of disabling the security software such as anti-virus in that system in which it is downloaded. But this type of disabling is more predominant in windows based systems only.<br />
How to secure yourself from such an attack<br />
———————————–<br />
1. First change the password for all your websites immedietly. Make sure that ftp login details are tough and not easy<br />
2. Review the code of your infected website particularly look for include files, .js files etc. Look out for iframe / sql injection coding / large sequence of numbers and digits<br />
3. Look out in your sql database for any field that has junk codes or iframes injected<br />
4. Check for your .htaccess file in various direcotries like public_html and see whether any undesired changes are done in it.<br />
5. Check for any .pl, .cgi file uploaded in your website or in cgi-bin folder<br />
6. Check for any unknown files appear nearly to your file names uploaded in your website.<br />
7. The best way to safe guard is to keep a backup of your website, mail, database. Terminate the account. Recreate it in your whm. Review the coding and database thoroughly and upload your website.<br />
8. Make sure that your local lan and systems are with latest version of OS with proper updates<br />
9. Make sure that all your security softwares are upto date and function properly<br />
10. Do not allow any one to access unwanted sites in your local lan or system or laptop<br />
11. Make sure that a firewall such as Windows firewall or Zone lab firewall is installed and enabled in your systems<br />
12. Warn all your customers about this issue and make sure that they also keep their systems clean and secure<br />
13. Advise your customers to change passwords regularly and make sure that passwords are always tough<br />
14. Advise your customers to use secure and safe ftp software while uploading webpages and desist from uploading via public terminals</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hostlogue.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hostlogue.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hostlogue.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hostlogue.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hostlogue.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hostlogue.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hostlogue.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hostlogue.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hostlogue.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hostlogue.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hostlogue.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hostlogue.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hostlogue.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hostlogue.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hostlogue.wordpress.com&amp;blog=7440822&amp;post=60&amp;subd=hostlogue&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hostlogue.wordpress.com/2009/06/12/gumblar-malware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/aa79870137e21ddee435ca461d8f6716?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">websarga</media:title>
		</media:content>
	</item>
		<item>
		<title>About Hostlogue</title>
		<link>http://hostlogue.wordpress.com/2009/04/21/hello-world/</link>
		<comments>http://hostlogue.wordpress.com/2009/04/21/hello-world/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 05:20:40 +0000</pubDate>
		<dc:creator>websarga</dc:creator>
				<category><![CDATA[Web Hosting India]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Since opening our doors in 2008, HostLogue has been committed to bringing the power of the Internet to our customers across the globe with innovative, easy-to-use products and services that are supported by unmatched customer service. HostLogue is now an industry leading Web Service Provider (WSP) in India and around the globe. The combined product [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hostlogue.wordpress.com&amp;blog=7440822&amp;post=1&amp;subd=hostlogue&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="w100 fl-l mart22 fs20 ffla fcdgrey"><strong><br />
</strong></div>
<div class="w100 fl-l mart10 nrmtext2">
<div class="planimg2">Since opening  our doors in 2008, HostLogue has been committed to bringing the power of the  Internet to our customers across the globe with innovative, easy-to-use products  and services that are supported by unmatched customer service. HostLogue is now  an industry leading Web Service Provider (WSP) in India and around the  globe.</div>
<p>The combined product portfolio of HostLogue includes &#8211; Domain Name  Registration, Web Hosting and Web Design, Website Maintenance, Search Engine  Optimization, Payment Gateway Solutions, SSL Digital Certificates, Dedicated  Servers, Personal &amp; Corporate E-Mail Solutions, E-Commerce Solutions and  other similar web services. </p>
<p><em><strong>HostLogue is managed and owned by <a href="http://www.websarga.com" target="_blank">WebSarga</a> Solutions.</strong></em></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hostlogue.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hostlogue.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hostlogue.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hostlogue.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hostlogue.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hostlogue.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hostlogue.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hostlogue.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hostlogue.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hostlogue.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hostlogue.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hostlogue.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hostlogue.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hostlogue.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hostlogue.wordpress.com&amp;blog=7440822&amp;post=1&amp;subd=hostlogue&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hostlogue.wordpress.com/2009/04/21/hello-world/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/aa79870137e21ddee435ca461d8f6716?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">websarga</media:title>
		</media:content>
	</item>
	</channel>
</rss>
