<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is this a hacker&#8217;s tool?</title>
	<atom:link href="http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=is-this-a-hackers-tool</link>
	<description>The Magic of Open Source</description>
	<lastBuildDate>Fri, 10 Feb 2012 18:02:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
	<item>
		<title>By: Michael Lafferty</title>
		<link>http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/comment-page-1/#comment-443</link>
		<dc:creator>Michael Lafferty</dc:creator>
		<pubDate>Wed, 26 Dec 2007 23:13:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/#comment-443</guid>
		<description>Based upon our being hit by similar and often far simpler Perl scripts, we have tentatively concluded that the targeted application is Zen-Cart, an open source electronic commerce cart, and specifically the MySQL component in which customer and transaction data is stored. The simplest script we have seen to date is this:

	

That script only attempts to determine if a MySQL database can be copied but makes not attempt to do so.

We have not isolated the source of these scripts, as they are typically bounced though US-based ISP or ISP client servers. We did see what we think was a direct transmission from IP 208.69.192.133, which appears to be originating from a server in Argentina.</description>
		<content:encoded><![CDATA[<p>Based upon our being hit by similar and often far simpler Perl scripts, we have tentatively concluded that the targeted application is Zen-Cart, an open source electronic commerce cart, and specifically the MySQL component in which customer and transaction data is stored. The simplest script we have seen to date is this:</p>
<p>That script only attempts to determine if a MySQL database can be copied but makes not attempt to do so.</p>
<p>We have not isolated the source of these scripts, as they are typically bounced though US-based ISP or ISP client servers. We did see what we think was a direct transmission from IP 208.69.192.133, which appears to be originating from a server in Argentina.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Lord</title>
		<link>http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/comment-page-1/#comment-428</link>
		<dc:creator>Alan Lord</dc:creator>
		<pubDate>Thu, 20 Dec 2007 16:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/#comment-428</guid>
		<description>Cool - thanks for the analysis.</description>
		<content:encoded><![CDATA[<p>Cool &#8211; thanks for the analysis.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Bell</title>
		<link>http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/comment-page-1/#comment-427</link>
		<dc:creator>Alan Bell</dc:creator>
		<pubDate>Thu, 20 Dec 2007 14:27:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.theopensourcerer.com/2007/12/20/is-this-a-hackers-tool/#comment-427</guid>
		<description>my guess is that there is a PHP application which has site.php as its index page, that page is insecure and will retrieve content from URLs and inject them into itself. The script itself is just trying to execute commands on the server, and reporting back what works. &quot;net start&quot; will list running services on a windows box so if the return value of net start contains &quot;windows&quot; then it proves that the &quot;net start&quot; command has been successfully executed. I am not sure what the application is that they are targeting with this, but it certainly isn&#039;t WordPress.</description>
		<content:encoded><![CDATA[<p>my guess is that there is a PHP application which has site.php as its index page, that page is insecure and will retrieve content from URLs and inject them into itself. The script itself is just trying to execute commands on the server, and reporting back what works. &#8220;net start&#8221; will list running services on a windows box so if the return value of net start contains &#8220;windows&#8221; then it proves that the &#8220;net start&#8221; command has been successfully executed. I am not sure what the application is that they are targeting with this, but it certainly isn&#8217;t WordPress.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

