<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.org/enblog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>en-US</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.org/enblog/read.php?257</link>
<title><![CDATA[Baidu.com DNS hijacking]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Others]]></category>
<pubDate>Tue, 12 Jan 2010 02:47:05 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?257</guid> 
<description>
<![CDATA[ 
	We received lots of reports about <strong>Baidu.com</strong>, the most popular search engine in China, had been unavailable since this moning.<br/><br/>As the time of writing, Baidu.com is also unavailable.<br/><br/>We noticed this case may be caused by DNS hijacking by the “Iranian cyber Army”, <a href="http://www.cisrt.org/enblog/read.php?256" target="_blank">the same guys</a> we mentioned several weeks ago.<br/><br/>A related news: <a href="http://thenextweb.com/asia/2010/01/12/breaking-baidu-hacked-iranian/" target="_blank"><u>Baidu, China’s Largest Search Engine, Hacked by “Iranian Cyber Army”</u></a><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=baidu.com" rel="tag">baidu.com</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=dns" rel="tag">dns</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=hijack" rel="tag">hijack</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?256</link>
<title><![CDATA[ISC: Twitter outage via DNS hijacking]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Others]]></category>
<pubDate>Fri, 18 Dec 2009 08:31:18 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?256</guid> 
<description>
<![CDATA[ 
	I just saw <a href="http://isc.sans.org" target="_blank"><u>Sans.org</u></a> reported that <a href="http://isc.sans.org/diary.html?storyid=7774" target="_blank"><u>Twitter outage via DNS hijacking</u></a>.<br/><br/>A reader posted a image in the comments of this report.<br/><br/><a href="http://i.imgur.com/Q1EgM.jpg" target="_blank">http://i.imgur.com/Q1EgM.jpg</a><br/><br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=twitter" rel="tag">twitter</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=hijack" rel="tag">hijack</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?255</link>
<title><![CDATA[First iPhone Worm Ikee]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Mon, 09 Nov 2009 00:43:26 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?255</guid> 
<description>
<![CDATA[ 
	There are lots of reports about first iPhone worm &quot;<strong>Ikee</strong>&quot; today.<br/><br/>F-Secure: <a href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank"><u>First iPhone worm found</u></a><br/><br/>Sophos: <a href="http://www.sophos.com/pressoffice/news/articles/2009/11/iphone-worm.html" target="_blank"><u>First iPhone worm spreading in the wild</u></a><br/><br/>ISC: <a href="http://isc.sans.org/diary.html?storyid=7549" target="_blank"><u>iPhone worm in the wild</u></a><br/><br/><br/><br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=ikee" rel="tag">ikee</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=iphone" rel="tag">iphone</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?254</link>
<title><![CDATA[Spams with Hello Darling]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 03 Nov 2009 11:37:52 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?254</guid> 
<description>
<![CDATA[ 
	The spams had been sent with the subject &quot;<strong>Hello Darling</strong>&quot; and attchment &quot;<strong>photo.zip</strong>&quot;.<br/><br/><strong>Subject</strong>: Hello Darling<br/><strong>Mail body</strong>:<br/>Hi, how are you? My photos Which I promised in attached file<br/><br/><strong>Attchment</strong>: photo.zip<br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=hello_darling" rel="tag">hello darling</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=photo.zip" rel="tag">photo.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=photo.exe" rel="tag">photo.exe</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?253</link>
<title><![CDATA[Get Back to My Office for More Details Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sun, 01 Nov 2009 10:55:09 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?253</guid> 
<description>
<![CDATA[ 
	I saw lots of spams which contained subject &quot;<strong>get back to my office for more details</strong>&quot; and attchment &quot;<strong>info.zip</strong>&quot; in recent two days. Be careful of them.<br/><br/><strong>From</strong>: boss &lt;&quot;boss&quot;&gt; <br/><strong>Subject</strong>: get back to my office for more details<br/><strong>Mail body</strong>:<br/>Please read the attached letter and get back to my office for more details to proceed further. <br/><br/>Thanks and have a very nice day. <br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=info.zip" rel="tag">info.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=get_back_to_my_office_for_more_details" rel="tag">get back to my office for more details</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?252</link>
<title><![CDATA[Facebook Password Reset Confirmation Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 27 Oct 2009 01:10:07 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?252</guid> 
<description>
<![CDATA[ 
	Be careful of the new round of spams about <strong>Facebook Password Reset Confirmation</strong>. <br/><br/><strong>From</strong>: The Facebook Team &lt;service@facebook.com&gt;<br/><strong>Subject</strong>: Facebook Password Reset Confirmation.<br/><strong>Mail body</strong>:<br/>Hey gt , <br/><br/>Because of the measures taken to provide safety to our clients, your password has been changed. You can find your new password in attached document. <br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=facebook_password_6ff26.zip" rel="tag">facebook password 6ff26.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=facebook_password_c92dd.zip" rel="tag">facebook password c92dd.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=facebook_password_reset_confirmation" rel="tag">facebook password reset confirmation</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?251</link>
<title><![CDATA[Contract of Settlements Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sat, 24 Oct 2009 10:53:50 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?251</guid> 
<description>
<![CDATA[ 
	There is a new round of spams, which contained the subject titles as &quot;<strong>Contract of Settlements</strong>&quot; and the attachments as &quot;<strong>contract_1.zip</strong>&quot;.<br/><br/>Be careful.<br/><br/><strong>Subjects</strong>: Contract of Settlements<br/><br/><strong>Mail body</strong>:<br/>Greetings, <br/>We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers made alterations on the last page. If you agree all the provisions we are ready to make the payment on Friday for the first consignment, We are enclosing the file with prepared contract. Password: 34**** <br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=contract_1.zip" rel="tag">contract 1.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=contract_of_settlements" rel="tag">contract of settlements</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?250</link>
<title><![CDATA[Conflicker.B Infection Alert Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 20 Oct 2009 02:30:55 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?250</guid> 
<description>
<![CDATA[ 
	Be careful of spams about Conflicker.B Infection Alert.<br/><br/>They are the same gang as i mentioned <a href="http://www.cisrt.org/enblog/read.php?249" target="_blank"><u>before</u></a>.<br/><br/><strong>Subject</strong>:Conflicker.B Infection Alert<br/><strong>Mail body</strong>:<br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=conflicker.b" rel="tag">conflicker.b</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=install.zip" rel="tag">install.zip</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?249</link>
<title><![CDATA[More Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Thu, 15 Oct 2009 07:44:19 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?249</guid> 
<description>
<![CDATA[ 
	Numerous spams had been sent these days. The name of attchments are like &quot;DHL_package_label_1f553.zip&quot; , &quot;DHL_print_label_433a6.zip&quot; , &quot;DHL_Label_a4f79.zip&quot; , &quot;DHL_Package_ac42d.zip&quot; , &quot;install.zip&quot;, etc. <br/><br/>Be careful of these spams.<br/><br/>I listed some spams&#039; content:<br/><div class="quote"><div class="quote-title">Quotation</div><div class="quote-content"><strong>Subject</strong>: DHL service. You should get the parcel! Delivery NR.6445<br/><strong>Mail body</strong>:<br/>Hello! <br/><br/>The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. <br/><br/>You may pickup the parcel at our post office personaly! <br/><br/>Please note! <br/>The shipping label is attached to this e-mail. Please print this label to get this package at our post office. <br/><br/>Thank you for attention. <br/>DHL Delivery Services. </div></div><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=dhl_label" rel="tag">dhl label</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=dhl_package" rel="tag">dhl package</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=dhl_print_label" rel="tag">dhl print label</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=dhl_package_label" rel="tag">dhl package label</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=install.zip" rel="tag">install.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=trojan.win32.inject" rel="tag">trojan.win32.inject</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?248</link>
<title><![CDATA[Renren.com XSS Worm]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 25 Aug 2009 01:44:19 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?248</guid> 
<description>
<![CDATA[ 
	I noticed <a href="http://www.sophos.com/blogs/sophoslabs/v/post/6208" target="_blank"><u>Sophos</u></a> and <a href="http://isc.sans.org/diary.html?storyid=7015" target="_blank"><u>ISC</u></a> reported a Chinese social web site - <strong>renren.com</strong>(aka xiaonei.com), was attacked by a flash XSS worm.<br/><br/>If you can read Chinese, you may read more details written by <strong>KnownSec Team</strong> <a href="http://www.scanw.com/blog/archives/1133" target="_blank"><u>here</u></a>.<br/><br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=renren" rel="tag">renren</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=xiaonei" rel="tag">xiaonei</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=xss" rel="tag">xss</a>
]]>
</description>
</item>
</channel>
</rss>