<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A tale of searching for a hacker and his supporter, the idiot programmer</title>
	<atom:link href="http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/feed/" rel="self" type="application/rss+xml" />
	<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/</link>
	<description>About Linux, IT security,tips and tricks and otherstuff that comes into my mind</description>
	<lastBuildDate>Thu, 09 Sep 2010 05:57:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: clemens</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-279</link>
		<dc:creator>clemens</dc:creator>
		<pubDate>Sat, 24 May 2008 20:00:03 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-279</guid>
		<description>The  is the &quot;easiest-to-exploit&quot; mistake a programmer can ever make! 
It should be replaced with a switch- or an if-statement!

For example:


if($_GET[content]==&quot;login&quot;) {
 include(&quot;login.php&quot;);
}
..

Would increase the security very much..</description>
		<content:encoded><![CDATA[<p>The  is the &#8220;easiest-to-exploit&#8221; mistake a programmer can ever make!<br />
It should be replaced with a switch- or an if-statement!</p>
<p>For example:</p>
<p>if($_GET[content]==&#8221;login&#8221;) {<br />
 include(&#8220;login.php&#8221;);<br />
}<br />
..</p>
<p>Would increase the security very much..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Penz Blog &#187; Interview with a professional hacker</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-135</link>
		<dc:creator>Robert Penz Blog &#187; Interview with a professional hacker</dc:creator>
		<pubDate>Sat, 26 Apr 2008 20:59:46 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-135</guid>
		<description>[...] the DDOS attack against my blog this week , I decided to go to the channel I wrote in my initial hacker post about, as I believed that the most likely attacker is hacker I wrote about. After I joined the [...]</description>
		<content:encoded><![CDATA[<p>[...] the DDOS attack against my blog this week , I decided to go to the channel I wrote in my initial hacker post about, as I believed that the most likely attacker is hacker I wrote about. After I joined the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Penz Blog &#187; UDP Flood DDOS attack against my blog</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-132</link>
		<dc:creator>Robert Penz Blog &#187; UDP Flood DDOS attack against my blog</dc:creator>
		<pubDate>Thu, 24 Apr 2008 20:21:06 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-132</guid>
		<description>[...] the last 14 days. The only idea I&#8217;ve is that the hacker I found at the server of a friend and wrote about it wanted to get even. What counts for this theory is that it is carried out by hacked servers from [...]</description>
		<content:encoded><![CDATA[<p>[...] the last 14 days. The only idea I&#8217;ve is that the hacker I found at the server of a friend and wrote about it wanted to get even. What counts for this theory is that it is carried out by hacked servers from [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boyan Alexiev</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-130</link>
		<dc:creator>Boyan Alexiev</dc:creator>
		<pubDate>Wed, 23 Apr 2008 01:14:06 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-130</guid>
		<description>Robert, great article! Thank you for the detailed description which helped me find the tool used to hack my server. Although I first found and closed the whole (public_html dirs), because I have seen it before, it was hard to find the script until I used the find and walked through the long list - that was easy. Then I found the wget download and easily confirmed the source of the attack (using the timestamp with grep from the logs it gave me the exact line :). Then I only had to remove the crontab entry and the script itself from /var/tmp/.b folder.
The hack tool can still be downloaded at http://members.lycos.co.uk/foryouforyou/for.tgz - I have already filed an abuse report. If you are unable to find it and anyone is interested - I can give it away. I also keep a copy of the running script with all settings.

Kind regards,
Bobby</description>
		<content:encoded><![CDATA[<p>Robert, great article! Thank you for the detailed description which helped me find the tool used to hack my server. Although I first found and closed the whole (public_html dirs), because I have seen it before, it was hard to find the script until I used the find and walked through the long list &#8211; that was easy. Then I found the wget download and easily confirmed the source of the attack (using the timestamp with grep from the logs it gave me the exact line <img src='http://robert.penz.name/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . Then I only had to remove the crontab entry and the script itself from /var/tmp/.b folder.<br />
The hack tool can still be downloaded at <a href="http://members.lycos.co.uk/foryouforyou/for.tgz" rel="nofollow">http://members.lycos.co.uk/foryouforyou/for.tgz</a> &#8211; I have already filed an abuse report. If you are unable to find it and anyone is interested &#8211; I can give it away. I also keep a copy of the running script with all settings.</p>
<p>Kind regards,<br />
Bobby</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-95</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 19 Mar 2008 21:36:05 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-95</guid>
		<description>In my case the problem was the php script which used that function. I deactivated the hompeage and told the programmer to fix his code before it goes online again.</description>
		<content:encoded><![CDATA[<p>In my case the problem was the php script which used that function. I deactivated the hompeage and told the programmer to fix his code before it goes online again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joar</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-94</link>
		<dc:creator>Joar</dc:creator>
		<pubDate>Wed, 19 Mar 2008 21:23:37 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-94</guid>
		<description>I dont understand the code. How do I stop it from happening again?</description>
		<content:encoded><![CDATA[<p>I dont understand the code. How do I stop it from happening again?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-93</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 19 Mar 2008 20:11:59 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-93</guid>
		<description>with a security hole the programmer put into his code, look at the end of the post.</description>
		<content:encoded><![CDATA[<p>with a security hole the programmer put into his code, look at the end of the post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joar</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-92</link>
		<dc:creator>Joar</dc:creator>
		<pubDate>Wed, 19 Mar 2008 20:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-92</guid>
		<description>I have exactly the same problem on my server. How did this guy get access?</description>
		<content:encoded><![CDATA[<p>I have exactly the same problem on my server. How did this guy get access?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Evilo</title>
		<link>http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/comment-page-1/#comment-91</link>
		<dc:creator>Evilo</dc:creator>
		<pubDate>Wed, 19 Mar 2008 15:51:23 +0000</pubDate>
		<guid isPermaLink="false">http://robert.penz.name/44/a-tale-of-searching-for-a-hacker-and-his-supporter-the-idiot-programmer/#comment-91</guid>
		<description>Awesome article, made me chuckle at the end.
Well, I guess it&#039;s more of a ran/story than an article, but nonetheless a good job. : p</description>
		<content:encoded><![CDATA[<p>Awesome article, made me chuckle at the end.<br />
Well, I guess it&#8217;s more of a ran/story than an article, but nonetheless a good job. : p</p>
]]></content:encoded>
	</item>
</channel>
</rss>
