<?xml version="1.0" standalone="yes"?>
<?xml-stylesheet type="text/xsl" href="css/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>Blast's Security-恶意站点：xunqu.com</title><link>http://www.sacour.cn/post/84.html</link><generator>RainbowSoft Studio Z-Blog 1.8 Walle Build 91204</generator><language>zh-CN</language><pubDate>Sat, 02 Jan 2010 21:48:54 +0800</pubDate><item><title>Re:恶意站点：xunqu.com</title><author>sacour.cn@it-mate.co.uk (Steven)</author><link>http://www.sacour.cn/post/84.html#cmt31</link><pubDate>Sun, 10 Jan 2010 09:16:05 +0800</pubDate><guid>http://www.sacour.cn/post/84.html#cmt31</guid><description><![CDATA[Just an FYI, this one's got a new MITM (same filenames, just a different domain/path). The new domain and path is;<br/><br/>xnfcgx.16824.com.cn:173/360/33/<br/><br/>Domain resides at 204.188.206.11 (AS46844 204.188.192.0/18<br/>SharkTECH Internet Services)<blockquote><div class="quote quote3"><div class="quote-title">blast 于 2010-1-10 11:03:02 回复</div>Seems like its owner has regestered many domains, I found another two in the link you've posted :)<br/><br/>my.xingan5.cn:8886/360/33<br/>cocoexe.8gcc.com:8886/360/33<br/><br/>BTW, by searching their site statistics(count.51yes.com/index.aspx?id=507829494) through bing.com, I found that they are likely to spread very early from March 09 but somehow they slowed down their work these days may be the leak of new exploits</div></blockquote>]]></description></item></channel></rss>
