<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Mass infection of IIS/ASP sites &#8211; robint.us</title>
	<atom:link href="http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: LizaMoon Mass SQL injection (ur.php) &#8211; Updates &#124; Sucuri</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-2521</link>
		<dc:creator>LizaMoon Mass SQL injection (ur.php) &#8211; Updates &#124; Sucuri</dc:creator>
		<pubDate>Mon, 04 Apr 2011 14:02:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-2521</guid>
		<description>[...] We posted more details on these types of attacks when the first one hit almost a year ago: Mass infection of IIS/ASP sites – robint.us [...]</description>
		<content:encoded><![CDATA[<p>[...] We posted more details on these types of attacks when the first one hit almost a year ago: Mass infection of IIS/ASP sites – robint.us [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Attacks against IIS/ASP sites &#8211; alisa-carter.com &#124; Sucuri</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-2435</link>
		<dc:creator>Attacks against IIS/ASP sites &#8211; alisa-carter.com &#124; Sucuri</dc:creator>
		<pubDate>Mon, 21 Mar 2011 20:13:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-2435</guid>
		<description>[...] pointing to http://alisa-carter.com/ur.php . It is done using the same SQL injection attack as used in the robint-us mass infection of a few months [...]</description>
		<content:encoded><![CDATA[<p>[...] pointing to <a href="http://alisa-carter.com/ur.php" rel="nofollow">http://alisa-carter.com/ur.php</a> . It is done using the same SQL injection attack as used in the robint-us mass infection of a few months [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hackers compromised thousands of Web sites! &#124; MalwareSurvival</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-2339</link>
		<dc:creator>Hackers compromised thousands of Web sites! &#124; MalwareSurvival</dc:creator>
		<pubDate>Fri, 21 Jan 2011 05:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-2339</guid>
		<description>[...] Sucuri.net has published the exploit findings on their Research Blog. [...]</description>
		<content:encoded><![CDATA[<p>[...] Sucuri.net has published the exploit findings on their Research Blog. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Attack against IIS/ASP sites &#8211; google-stat50.info &#124; Sucuri</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-2207</link>
		<dc:creator>Attack against IIS/ASP sites &#8211; google-stat50.info &#124; Sucuri</dc:creator>
		<pubDate>Tue, 28 Sep 2010 16:51:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-2207</guid>
		<description>[...] small sites, but some big ones got hit as well. It is the same SQL injection attack as used in the robint-us mass infection of a few months [...]</description>
		<content:encoded><![CDATA[<p>[...] small sites, but some big ones got hit as well. It is the same SQL injection attack as used in the robint-us mass infection of a few months [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dremeda</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-1744</link>
		<dc:creator>dremeda</dc:creator>
		<pubDate>Mon, 02 Aug 2010 19:17:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-1744</guid>
		<description>Thanks for the post. If it makes it easier try using &lt;a href=&quot;http://sucuri.pastebin.com&quot; target=&quot;_blank&quot;&gt;http://sucuri.pastebin.com&lt;/a&gt; then post the link here. 
 
Cheers. 
My recent post &lt;a href=&quot;http:\/\/blog.sucuri.net\/2010\/07\/ufc-com-blacklisted-by-google-indirectly.html&quot; target=&quot;_blank&quot;&gt;UFCcom blacklisted by Google indirectly&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>Thanks for the post. If it makes it easier try using <a href="http://sucuri.pastebin.com" target="_blank">http://sucuri.pastebin.com</a> then post the link here. </p>
<p>Cheers.<br />
My recent post <a href="http:\/\/blog.sucuri.net\/2010\/07\/ufc-com-blacklisted-by-google-indirectly.html" target="_blank">UFCcom blacklisted by Google indirectly</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: C-Note</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-1742</link>
		<dc:creator>C-Note</dc:creator>
		<pubDate>Mon, 02 Aug 2010 17:25:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-1742</guid>
		<description>Ok-- so my script is &#039;too long to post&#039;. Here is the NTEXT part to insert into CantalopeHeads script. I also adjusted the varchar to be nvarchar. 
 
-- This is for NTEXT ONLY  
DECLARE Col_Cur Cursor  
FOR SELECT COLUMN_NAME From INFORMATION_SCHEMA.COLUMNS  
WHERE Table_Name = @TableName and DATA_TYPE IN (&#039;ntext&#039;)  
OPEN Col_Cur  
SET @OutStr =&#039;UPDATE &#039; + @TableName + &#039; SET &#039; ;  
SET @ColCnt = 0;  
FETCH NEXT FROM Col_Cur INTO @ColName;  
 
WHILE @@FETCH_STATUS = 0  
BEGIN  
SET @OutStr = @OutStr + @ColName + &#039;=CAST(REPLACE(CAST(&#039; + @ColName + &#039; AS nvarchar(max)),&#039;&#039;&#039; + @str + &#039;&#039;&#039;,&#039;&#039;&#039;&#039;) AS ntext),&#039; ;  
SET @ColCnt = @ColCnt + 1;  
FETCH NEXT FROM Col_Cur INTO @ColName;  
END  
SET @OutStr = LEFT(@OutStr, LEN(@OutStr) - 1) + &#039;;&#039;  
IF @ColCnt &gt; 0  
BEGIN  
PRINT @OutStr ;  
END  
CLOSE Col_Cur;  
DEALLOCATE Col_Cur; </description>
		<content:encoded><![CDATA[<p>Ok&#8211; so my script is &#039;too long to post&#039;. Here is the NTEXT part to insert into CantalopeHeads script. I also adjusted the varchar to be nvarchar. </p>
<p>&#8211; This is for NTEXT ONLY<br />
DECLARE Col_Cur Cursor<br />
FOR SELECT COLUMN_NAME From INFORMATION_SCHEMA.COLUMNS<br />
WHERE Table_Name = @TableName and DATA_TYPE IN (&#039;ntext&#039;)<br />
OPEN Col_Cur<br />
SET @OutStr =&#039;UPDATE &#039; + @TableName + &#039; SET &#039; ;<br />
SET @ColCnt = 0;<br />
FETCH NEXT FROM Col_Cur INTO @ColName;  </p>
<p>WHILE @@FETCH_STATUS = 0<br />
BEGIN<br />
SET @OutStr = @OutStr + @ColName + &#039;=CAST(REPLACE(CAST(&#039; + @ColName + &#039; AS nvarchar(max)),&#039;&#039;&#039; + @str + &#039;&#039;&#039;,&#039;&#039;&#039;&#039;) AS ntext),&#039; ;<br />
SET @ColCnt = @ColCnt + 1;<br />
FETCH NEXT FROM Col_Cur INTO @ColName;<br />
END<br />
SET @OutStr = LEFT(@OutStr, LEN(@OutStr) &#8211; 1) + &#039;;&#039;<br />
IF @ColCnt &gt; 0<br />
BEGIN<br />
PRINT @OutStr ;<br />
END<br />
CLOSE Col_Cur;<br />
DEALLOCATE Col_Cur;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: C-note</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-1741</link>
		<dc:creator>C-note</dc:creator>
		<pubDate>Mon, 02 Aug 2010 17:18:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-1741</guid>
		<description>Thanks to CantalopeHead for the script! I just used it on another malicious injection. I made a few updates to include nvarchar and ntext columns. I&#039;ll post separate due to length. Note the ntext fix will only work on SQL 2005 and later (it uses a CAST to leverage the new nvarchar(MAX) data type. When one has time, one should consider changing text fields to nvarchar(MAX) anyway. 
 
Hopefully I&#039;ll have some time soon to fix the root cause, but for now, at least I can clean up the damage. 
 
Oh, and to clarify, this generates the UPDATE statements, which you then copy,paste, and run to actually clean the database. When you are pissed about  the fact that your db is hacked, you may not realize that at first in your moment of anger ;) </description>
		<content:encoded><![CDATA[<p>Thanks to CantalopeHead for the script! I just used it on another malicious injection. I made a few updates to include nvarchar and ntext columns. I&#039;ll post separate due to length. Note the ntext fix will only work on SQL 2005 and later (it uses a CAST to leverage the new nvarchar(MAX) data type. When one has time, one should consider changing text fields to nvarchar(MAX) anyway. </p>
<p>Hopefully I&#039;ll have some time soon to fix the root cause, but for now, at least I can clean up the damage. </p>
<p>Oh, and to clarify, this generates the UPDATE statements, which you then copy,paste, and run to actually clean the database. When you are pissed about  the fact that your db is hacked, you may not realize that at first in your moment of anger <img src='http://blog.sucuri.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: This Month in the Threat Webscape &#8211; June 2010 &#124; HackerSafe Security Related Blog for all</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-1717</link>
		<dc:creator>This Month in the Threat Webscape &#8211; June 2010 &#124; HackerSafe Security Related Blog for all</dc:creator>
		<pubDate>Thu, 29 Jul 2010 21:28:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-1717</guid>
		<description>[...] 100k&#160;popular Web sites&#160;were compromised last month with a mass injection targeting&#160;IIS using ASP.net&#160;platform. The attack came from Chinese IP addresses and the injected iFrame led to a [...]</description>
		<content:encoded><![CDATA[<p>[...] 100k&nbsp;popular Web sites&nbsp;were compromised last month with a mass injection targeting&nbsp;IIS using ASP.net&nbsp;platform. The attack came from Chinese IP addresses and the injected iFrame led to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: This Month in the Threat Webscape &#8211; June 2010 : CU*Secure</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-1373</link>
		<dc:creator>This Month in the Threat Webscape &#8211; June 2010 : CU*Secure</dc:creator>
		<pubDate>Sun, 11 Jul 2010 10:00:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-1373</guid>
		<description>[...] 100k&#160;popular Web sites&#160;were compromised last month with a mass injection targeting&#160;IIS using ASP.net&#160;platform. The attack came from Chinese IP addresses and the injected iFrame led to a [...]</description>
		<content:encoded><![CDATA[<p>[...] 100k&nbsp;popular Web sites&nbsp;were compromised last month with a mass injection targeting&nbsp;IIS using ASP.net&nbsp;platform. The attack came from Chinese IP addresses and the injected iFrame led to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adobe 0-day used in mass injections &#124; HackerSafe Security Related Blog for all</title>
		<link>http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html/comment-page-1#comment-1320</link>
		<dc:creator>Adobe 0-day used in mass injections &#124; HackerSafe Security Related Blog for all</dc:creator>
		<pubDate>Tue, 06 Jul 2010 20:24:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=189#comment-1320</guid>
		<description>[...] related to the hxxp://ww.robint.us/[REMOVED].js attack earlier this week that our friends at Sucuri blogged about, where the common theme was that all Web sites were running on Microsoft IIS and used [...]</description>
		<content:encoded><![CDATA[<p>[...] related to the hxxp://ww.robint.us/[REMOVED].js attack earlier this week that our friends at Sucuri blogged about, where the common theme was that all Web sites were running on Microsoft IIS and used [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

