<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "So called Arab hackers are all Americans"]]></title>
		<link>https://proxy2.de/forum/posts/list/2.php</link>
		<description><![CDATA[Latest messages posted in the topic "So called Arab hackers are all Americans"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>So called Arab hackers are all Americans</title>
				<description><![CDATA[ OK as most of you may be aware there is a major exploit in version 2.2 of the advanced guestbook. Because of this a lot of them have been defaced by people calling themselves sblack scorpion, red scorpion etc and claiming to be anti USA and the usual rubbish. Now I have been keeping a log of failed guestbook logins [url]www.carbonize.co.uk/guestbooklogins.php[/url] and nearly every IP resolves to an American ISP apart from one which is polish. Just how stupid are these people?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9596.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9596.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 12:34:23]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ ..extremely??]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9602.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9602.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 16:06:07]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I should improve the message I display upon a failed login to show their IP, what their IP resolves to and what ip2country shows for their ISP's country. Should scare the moronic idiots as none of them knows what they are doing.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9605.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9605.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 16:42:07]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ lol, good plan.<br /> Another way of doing it for an extreme solution is to only upload the admin stuff when you need it.<br /> <br /> _ Auron]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9607.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9607.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 17:35:10]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I've hard coded my password into an actual file so even if there is a similar exploit in 2.3.1 it will never get that far. I have actually suggested that people with 2.2 rename their admin.php file to something totally different remembering to change the [b]action="admin.php"[/b] part of the admin_enter.php template.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9608.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9608.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 17:44:07]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yeah I saw that post - a very good idea - another idea is to remove the link<br /> to the admin area from the templates because that's just stupid to start with.<br /> I know its not as good as yours but it's simpler and stops them from even<br /> getting to the admin panel unless they guess the URL to it.<br /> <br /> _ Auron]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9610.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9610.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 19:24:14]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ The url is always the guestbook directory/admin.php]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9611.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9611.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 20:26:31]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Carbonize"]The url is always the guestbook directory/admin.php[/quote]<br /> <br /> It is? I wouldn't know myself, never used it or even downloaded it.<br /> You learn something new everyday ^^]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9612.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9612.php</link>
				<pubDate><![CDATA[Tue, 3 Aug 2004 20:54:11]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title>Re: So called Arab hackers are all Americans</title>
				<description><![CDATA[ [quote="Carbonize"]OK as most of you may be aware there is a major exploit in version 2.2 of the advanced guestbook. Because of this a lot of them have been defaced by people calling themselves sblack scorpion, red scorpion etc and claiming to be anti USA and the usual rubbish. Now I have been keeping a log of failed guestbook logins [url]www.carbonize.co.uk/guestbooklogins.php[/url] and nearly every IP resolves to an American ISP apart from one which is polish. Just how stupid are these people?[/quote]<br /> <br /> Carbonize, I clicked on this link, but I have to say I don't know how to tell what is a good or bad login there.  Is there any way you can share with us who the hackers are and their IPs so the rest of us don't get hacked by them.  Maybe we can have a "known hackers" thread or something...?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9620.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9620.php</link>
				<pubDate><![CDATA[Wed, 4 Aug 2004 07:41:47]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ All of them are bad amber222. Look at the password field part. They are trying to use the exploit.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9622.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9622.php</link>
				<pubDate><![CDATA[Wed, 4 Aug 2004 08:36:13]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ It would serve no purpose because even if we listed all the IP's used so far if they have a dynamically assigned IP it would not stop them. Most dial up ISP's used dynamically assigned IP's. This means that everytime you connect you get assigned a different IP. The best security is to make sure you are not exploitable.<br /> <br /> As for the failed logins page it's format is simple and copied directly from my 404's log. First is the time of the attempt in GMT (or BST at present which is GMT+1), next is the password they tried to login with, then I have the link they came from but this is irrelevant, next is the useragent string their web browser sends out and finally is their IP.<br /> <br /> If you really want a laugh have a look at my 404 log, [url]http://www.carbonize.co.uk/404s.php[/url]. Starting at about 17:54 on August 2nd I had somebody trying a huge list of exploits against my site.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9623.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9623.php</link>
				<pubDate><![CDATA[Wed, 4 Aug 2004 08:37:49]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Your just popular is all. <img src="https://proxy2.de/forum//images/smilies/69934afc394145350659cd7add244ca9.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9625.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9625.php</link>
				<pubDate><![CDATA[Wed, 4 Aug 2004 08:40:54]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Well, thanks, Carbonize, for your quick response.  I guess I need to learn about hacking so I better understand how to defend myself.  Right now I am clueless as to how or why people do this.<br /> <br /> Thanks also for the great contributions you have made to this forum.  You have helped a lot of people.<br /> <br /> When I first saw the guestbook hacked by "Black Scorpion" I figured it was Americans in disguise.  Unfortunately, there are a lot of angry people here since 911 - filled with hate.  I guess some of us have forgotten that 2 wrongs don't make it right.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9632.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9632.php</link>
				<pubDate><![CDATA[Wed, 4 Aug 2004 18:14:44]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I don't think hate has anything to do with it. This will just be kids with no actual opinions of their own jumping on a bandwagon. I mean they claim to be defacing guestbooks as a show of defiance against the US and Israel and yet they deface guestbooks that are on UK sites that use the .co.uk domain. Me and JTD do on occasion do a google search to find hacked guestbooks and if possible fix them but a lot of them appear to have been abandoned by their webmasters/mistresses.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9634.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9634.php</link>
				<pubDate><![CDATA[Wed, 4 Aug 2004 18:21:23]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Just fixed 6 pages  worth of guestbooks from google. Sheesh Why dont people take a hint and upgrade to GB 2.3.1   <img src="https://proxy2.de/forum//images/smilies/908627bbe5e9f6a080977db8c365caff.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3439/9653.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3439/9653.php</link>
				<pubDate><![CDATA[Wed, 4 Aug 2004 23:11:35]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
	</channel>
</rss>