{"id":163,"date":"2011-09-02T00:02:38","date_gmt":"2011-09-01T22:02:38","guid":{"rendered":"http:\/\/blog.pi3.com.pl\/?p=163"},"modified":"2011-09-02T00:25:24","modified_gmt":"2011-09-01T22:25:24","slug":"facebook-used-for-attack","status":"publish","type":"post","link":"https:\/\/blog.pi3.com.pl\/?p=163","title":{"rendered":"Facebook used for attack?"},"content":{"rendered":"<p>Today I&#8217;ve received strange mail:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>Date: Thu, 01 Sep 2011 09:11:00 +0200<\/em><br \/>\n<em>From: gayroobaoll &lt;gayroobaoll@o2.pl&gt;<\/em><br \/>\n<em>To: pi3@itsec.pl<\/em><br \/>\n<em>Subject:<\/em><\/p>\n<p><em>Chcesz, http:\/\/facebook.com\/100002779484440<\/em><\/p>\n<p><em>&#8212; CUT &#8212;<\/em><\/p>\n<p>As we can see, there is no subject, mail include link to someone&#8217;s facebook profile and has got only one Polish world (yes, this is attack for the Polish ppl). &#8220;Chcesz&#8221; means &#8220;Do you want&#8221;. Strange, dosn&#8217;t it? Mail was send from the Polish portal (o2.pl) &#8211; free mails.<\/p>\n<p>OK \ud83d\ude09 Let&#8217;s check this profile&#8230;<\/p>\n<p><a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-167\" title=\"facebook_1\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_1-300x130.png\" alt=\"\" width=\"300\" height=\"130\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_1-300x130.png 300w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_1.png 791w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_13.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-170\" title=\"facebook_profile_1\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_13-225x300.jpg\" alt=\"\" width=\"225\" height=\"300\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_13-225x300.jpg 225w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_13.jpg 375w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/><\/a>\u00a0 <a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_22.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-176\" title=\"facebook_profile_2\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_22-300x207.jpg\" alt=\"\" width=\"300\" height=\"207\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_22-300x207.jpg 300w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/facebook_profile_22.jpg 513w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Hm&#8230; interesting \ud83d\ude09 In the section &#8220;About&#8221; we can find Polish sentence: &#8220;Cze\u015b\u0107. Chcesz si\u0119 pozna\u0107. Co prawda tu rzadko bywam, wi\u0119cej pisz\u0119 na &#8211; www.relithibi.com\/-lenaa pisz do mnie.&#8221; which can be translated to: &#8220;Hi. I want to meet you. To be honest, I&#8217;m here very rarely, I&#8217;m more active here &#8211; www.relithibi.com\/-lenaa contact with me.&#8221; But in the section personal web page we can find different link:<\/p>\n<p>http:\/\/agagwhili.com\/-lenaa<\/p>\n<p>But this two different URLs go to the same site http:\/\/randkipl.com\/user.php?page=id&amp;id=16112<\/p>\n<p><a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-179\" title=\"randkipl_1\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_11-300x137.png\" alt=\"\" width=\"300\" height=\"137\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_11-300x137.png 300w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_11-1024x469.png 1024w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_11.png 1275w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-180\" title=\"randkipl_2\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_2-300x138.png\" alt=\"\" width=\"300\" height=\"138\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_2-300x138.png 300w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_2-1024x473.png 1024w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/randkipl_2.png 1277w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>OK. What is important here? Anything what we can press on this site forward us to the registration form \ud83d\ude09 On the left site of this page we can see smth like chat box, but it isn&#8217;t. This is static talk (maybe sniffed somewhere else) which is always the same. Whenever we visit this page we can see exactly the same talk and sentence sent from the same nicknames. This talk suggest of course sex propositions \ud83d\ude09 But what is important this site detect from which IP address we visit this page and tries to get the possible city from where our IP are and resolve the name of the city and put to the chat box \ud83d\ude09 This is nice social engineering trick \ud83d\ude09 The same situation is in the middle of the site, where is information about profile which we visit. Of course the city name is the same which page detect and the same situation is with the country \ud83d\ude09 Of course in this profile is written that this woman are looking for a men who want to have sex with her \ud83d\ude09<br \/>\nOf course site tries to remember visitors (cookies) and not change so often the city name when we use different IPs.<\/p>\n<p>OK. So I thing this is good moment to check in more details the email which I received. Here is full headers:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>Return-Path: &lt;gayroobaoll@o2.pl&gt;<\/em><br \/>\n<em>X-Original-To: pi3@itsec.pl<\/em><br \/>\n<em>Delivered-To: pi3@itsec.pl<\/em><br \/>\n<em>Received: by itsec.pl (Postfix, from userid 1004)<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 id 97D164CE13; Thu,\u00a0 1 Sep 2011 09:00:43 +0200 (CEST)<\/em><br \/>\n<em>X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on itsec.pl<\/em><br \/>\n<em>X-Spam-Level:<\/em><br \/>\n<em>X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,FREEMAIL_FROM,<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RCVD_IN_DNSWL_NONE,SPF_PASS,TVD_SPACE_RATIO,T_TO_NO_BRKTS_FREEMAIL<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 autolearn=ham version=3.3.2<\/em><br \/>\n<em>Received: from mailout1.go2.pl (mailout1.go2.pl [193.17.41.11])<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 by itsec.pl (Postfix) with ESMTP id 84CF931F96<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 for &lt;pi3@itsec.pl&gt;; Thu,\u00a0 1 Sep 2011 09:00:24 +0200 (CEST)<\/em><br \/>\n<em>Received: from mailout1.go2.pl (unknown [10.0.0.103])<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 by mailout1.go2.pl (Postfix) with ESMTP id BEDA05D5158<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 for &lt;pi3@itsec.pl&gt;; Thu,\u00a0 1 Sep 2011 09:11:01 +0200 (CEST)<\/em><br \/>\n<em>Received: from o2.pl (unknown [10.0.0.40])<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 by mailout1.go2.pl (Postfix) with SMTP<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 for &lt;pi3@itsec.pl&gt;; Thu,\u00a0 1 Sep 2011 09:11:01 +0200 (CEST)<\/em><br \/>\n<em>Subject:<\/em><br \/>\n<em>From: gayroobaoll &lt;gayroobaoll@o2.pl&gt;<\/em><br \/>\n<em>To: pi3@itsec.pl<\/em><br \/>\n<em>Mime-Version: 1.0<\/em><br \/>\n<em>Message-ID: &lt;1a68707d.72ac5cea.4e5f3004.83a38@o2.pl&gt;<\/em><br \/>\n<em>Date: Thu, 01 Sep 2011 09:11:00 +0200<\/em><br \/>\n<em>X-Originator: 115.132.51.92<\/em><br \/>\n<em>Content-Type: text\/plain; charset=&#8221;UTF-8&#8243;<\/em><br \/>\n<em>Content-Transfer-Encoding: quoted-printable<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>The real IP address of someone\/something who sent this mail is: 115.132.51.92<br \/>\nThis IP address alive and reply for ICMP-echo message:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em># ping 115.132.51.92<\/em><br \/>\n<em>PING 115.132.51.92 (115.132.51.92) 56(84) bytes of data.<\/em><br \/>\n<em>64 bytes from 115.132.51.92: icmp_req=1 ttl=50 time=365 ms<\/em><br \/>\n<em>64 bytes from 115.132.51.92: icmp_req=2 ttl=50 time=363 ms<\/em><br \/>\n<em>64 bytes from 115.132.51.92: icmp_req=3 ttl=50 time=362 ms<\/em><br \/>\n<em>^C<\/em><br \/>\n<em>&#8212; 115.132.51.92 ping statistics &#8212;<\/em><br \/>\n<em>3 packets transmitted, 3 received, 0% packet loss, time 2002ms<\/em><br \/>\n<em>rtt min\/avg\/max\/mdev = 362.722\/363.863\/365.174\/1.225 ms<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>whois database:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em># whois 115.132.51.92<\/em><br \/>\n<em>% [whois.apnic.net node-2]<\/em><br \/>\n<em>% Whois data copyright terms\u00a0\u00a0\u00a0 http:\/\/www.apnic.net\/db\/dbcopyright.html<\/em><\/p>\n<p><em>inetnum:\u00a0\u00a0\u00a0\u00a0\u00a0 115.132.0.0 &#8211; 115.135.255.255<\/em><br \/>\n<em>netname:\u00a0\u00a0\u00a0\u00a0\u00a0 ADSLSTREAMYX<\/em><br \/>\n<em>descr:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 CORE IP NETWORK DEVELOPMENT,<\/em><br \/>\n<em>descr:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 TELEKOM MALAYSIA BERHAD<\/em><br \/>\n<em>country:\u00a0\u00a0\u00a0\u00a0\u00a0 MY<\/em><br \/>\n<em>admin-c:\u00a0\u00a0\u00a0\u00a0\u00a0 SM135-AP<\/em><br \/>\n<em>tech-c:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 EAK2-AP<\/em><br \/>\n<em>status:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 ALLOCATED PORTABLE<\/em><br \/>\n<em>remarks:\u00a0\u00a0\u00a0\u00a0\u00a0 -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+<\/em><br \/>\n<em>remarks:\u00a0\u00a0\u00a0\u00a0\u00a0 This object can only be updated by APNIC hostmasters.<\/em><br \/>\n<em>remarks:\u00a0\u00a0\u00a0\u00a0\u00a0 To update this object, please contact APNIC<\/em><br \/>\n<em>remarks:\u00a0\u00a0\u00a0\u00a0\u00a0 hostmasters and include your organisation&#8217;s account<\/em><br \/>\n<em>remarks:\u00a0\u00a0\u00a0\u00a0\u00a0 name in the subject line.<\/em><br \/>\n<em>remarks:\u00a0\u00a0\u00a0\u00a0\u00a0 -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+<\/em><br \/>\n<em>changed:\u00a0\u00a0\u00a0\u00a0\u00a0 hm-changed@apnic.net 20080805<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 APNIC-HM<\/em><br \/>\n<em>mnt-lower:\u00a0\u00a0\u00a0 MAINT-AP-STREAMYX<\/em><br \/>\n<em>changed:\u00a0\u00a0\u00a0\u00a0\u00a0 hm-changed@apnic.net 20080919<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 APNIC<\/em><\/p>\n<p><em>person:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Siti Fuwaizah Mohd. Ghazali<\/em><br \/>\n<em>nic-hdl:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 SM135-AP<\/em><br \/>\n<em>e-mail:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tm_osc@tmnet.com.my<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Telekom Malaysia Berhad<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Jalan Pantai Baru,\u00a0 Kuala Lumpur.<\/em><br \/>\n<em>phone:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 +603-83185434<\/em><br \/>\n<em>fax-no:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 +603-22402126<\/em><br \/>\n<em>country:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MY<\/em><br \/>\n<em>changed:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 fuwaizah@tm.com.my 20090402<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 TM-NET-AP<\/em><br \/>\n<em>abuse-mailbox:\u00a0 abuse@tm.net.my<\/em><br \/>\n<em>notify:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tmcops@tmnet.com.my<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 APNIC<\/em><\/p>\n<p><em>person:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 EMRAN AHMED KAMAL<\/em><br \/>\n<em>nic-hdl:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 EAK2-AP<\/em><br \/>\n<em>e-mail:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 ssc@tmnet.com.my<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Telekom Malaysia<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Jalan Pantai Baru, Kuala Lumpur.<\/em><br \/>\n<em>phone:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 +6-03-83185434<\/em><br \/>\n<em>fax-no:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 +6-03-22402126<\/em><br \/>\n<em>country:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MY<\/em><br \/>\n<em>changed:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 fuwaizah@tm.net.my 20080918<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 TM-NET-AP<\/em><br \/>\n<em>abuse-mailbox:\u00a0 abuse@tm.net.my<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 APNIC<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>So&#8230; of course IP address is &#8220;somewhere&#8221; \ud83d\ude09 In this case Malaysia Telekom is owner. Greetings for Polish ppl in Malaysia ;p xprobe2 says this is Apple machine:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em># xprobe2 -v -r 115.132.51.92<\/em><\/p>\n<p><em>Xprobe2 v.0.3 Copyright (c) 2002-2005 fyodor@o0o.nu, ofir@sys-security.com, meder@o0o.nu<\/em><\/p>\n<p><em>[+] Target is 115.132.51.92<\/em><br \/>\n<em>[+] Loading modules.<\/em><br \/>\n<em>[+] Following modules are loaded:<\/em><br \/>\n<em>[x] [1] ping:icmp_ping\u00a0 &#8211;\u00a0 ICMP echo discovery module<\/em><br \/>\n<em>[x] [2] ping:tcp_ping\u00a0 &#8211;\u00a0 TCP-based ping discovery module<\/em><br \/>\n<em>[x] [3] ping:udp_ping\u00a0 &#8211;\u00a0 UDP-based ping discovery module<\/em><br \/>\n<em>[x] [4] infogather:ttl_calc\u00a0 &#8211;\u00a0 TCP and UDP based TTL distance calculation<\/em><br \/>\n<em>[x] [5] infogather:portscan\u00a0 &#8211;\u00a0 TCP and UDP PortScanner<\/em><br \/>\n<em>[x] [6] fingerprint:icmp_echo\u00a0 &#8211;\u00a0 ICMP Echo request fingerprinting module<\/em><br \/>\n<em>[x] [7] fingerprint:icmp_tstamp\u00a0 &#8211;\u00a0 ICMP Timestamp request fingerprinting module<\/em><br \/>\n<em>[x] [8] fingerprint:icmp_amask\u00a0 &#8211;\u00a0 ICMP Address mask request fingerprinting module<\/em><br \/>\n<em>[x] [9] fingerprint:icmp_port_unreach\u00a0 &#8211;\u00a0 ICMP port unreachable fingerprinting module<\/em><br \/>\n<em>[x] [10] fingerprint:tcp_hshake\u00a0 &#8211;\u00a0 TCP Handshake fingerprinting module<\/em><br \/>\n<em>[x] [11] fingerprint:tcp_rst\u00a0 &#8211;\u00a0 TCP RST fingerprinting module<\/em><br \/>\n<em>[x] [12] fingerprint:smb\u00a0 &#8211;\u00a0 SMB fingerprinting module<\/em><br \/>\n<em>[x] [13] fingerprint:snmp\u00a0 &#8211;\u00a0 SNMPv2c fingerprinting module<\/em><br \/>\n<em>[+] 13 modules registered<\/em><br \/>\n<em>[+] Initializing scan engine<\/em><br \/>\n<em>[+] Running scan engine<\/em><br \/>\n<em>[-] ping:tcp_ping module: no closed\/open TCP ports known on 115.132.51.92. Module test failed<\/em><br \/>\n<em>[-] ping:udp_ping module: no closed\/open UDP ports known on 115.132.51.92. Module test failed<\/em><br \/>\n<em>[-] No distance calculation. 115.132.51.92 appears to be dead or no ports known<\/em><br \/>\n<em>[+] Host: 115.132.51.92 is up (Guess probability: 50%)<\/em><br \/>\n<em>[+] Target: 115.132.51.92 is alive. Round-Trip Time: 0.36246 sec<\/em><br \/>\n<em>[+] Selected safe Round-Trip Time value is: 0.72492 sec<\/em><br \/>\n<em>[-] fingerprint:tcp_hshake Module execution aborted (no open TCP ports known)<\/em><br \/>\n<em>[-] fingerprint:smb need either TCP port 139 or 445 to run<\/em><br \/>\n<em>[-] fingerprint:snmp: need UDP port 161 open<\/em><br \/>\n<em>[+] Primary guess:<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;Apple Mac OS X 10.3.7&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Other guesses:<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;Apple Mac OS X 10.3.8&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;Apple Mac OS X 10.3.9&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;Apple Mac OS X 10.4.0&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;Apple Mac OS X 10.4.1&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;HP JetDirect ROM F.08.08 EEPROM F.08.20&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;HP JetDirect ROM F.08.08 EEPROM F.08.05&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;HP JetDirect ROM F.08.01 EEPROM F.08.05&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;HP JetDirect ROM A.05.03 EEPROM A.05.05&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Host 115.132.51.92 Running OS: &#8220;HP JetDirect ROM A.03.17 EEPROM A.04.09&#8221; (Guess probability: 100%)<\/em><br \/>\n<em>[+] Cleaning up scan engine<\/em><br \/>\n<em>[+] Modules deinitialized<\/em><br \/>\n<em>[+] Execution completed.<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>OK. So let&#8217;s check who register randkipl.com domain:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>\u00a0\u00a0 Domain Name: RANDKIPL.COM<\/em><br \/>\n<em>\u00a0\u00a0 Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D\/B\/A PUBLICDOMAINREGISTRY.COM<\/em><br \/>\n<em>\u00a0\u00a0 Whois Server: whois.PublicDomainRegistry.com<\/em><br \/>\n<em>\u00a0\u00a0 Referral URL: http:\/\/www.PublicDomainRegistry.com<\/em><br \/>\n<em>\u00a0\u00a0 Name Server: NS1.REG.RU<\/em><br \/>\n<em>\u00a0\u00a0 Name Server: NS2.REG.RU<\/em><br \/>\n<em>\u00a0\u00a0 Status: clientTransferProhibited<\/em><br \/>\n<em>\u00a0\u00a0 Updated Date: 06-jun-2011<\/em><br \/>\n<em>\u00a0\u00a0 Creation Date: 26-nov-2010<\/em><br \/>\n<em>\u00a0\u00a0 Expiration Date: 26-nov-2011<\/em><\/p>\n<p><em>&gt;&gt;&gt; Last update of whois database: Thu, 01 Sep 2011 19:53:13 UTC &lt;&lt;&lt;<\/em><\/p>\n<p><em>&#8230;<\/em><br \/>\n<em>&#8230;<\/em><\/p>\n<p><em>The Registry database contains ONLY .COM, .NET, .EDU domains and<\/em><br \/>\n<em>Registrars.<\/em><br \/>\n<em>Registration Service Provided By: DOMAIN NAMES REGISTRAR REG.RU LTD.<\/em><br \/>\n<em>Contact: +7.4955801111<\/em><\/p>\n<p><em>Domain Name: RANDKIPL.COM <\/em><\/p>\n<p><em>Registrant:<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 PrivacyProtect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Domain Admin\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 (contact@privacyprotect.org)<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 ID#10760, PO Box 16<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Nobby Beach<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 null,QLD 4218<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 AU<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Tel. +45.36946676<\/em><\/p>\n<p><em>Creation Date: 26-Nov-2010 \u00a0<\/em><br \/>\n<em>Expiration Date: 26-Nov-2011<\/em><\/p>\n<p><em>Domain servers in listed order:<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 ns1.reg.ru<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 ns2.reg.ru<\/em><\/p>\n<p><em>Administrative Contact:<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 PrivacyProtect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Domain Admin\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 (contact@privacyprotect.org)<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 ID#10760, PO Box 16<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Nobby Beach<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 null,QLD 4218<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 AU<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Tel. +45.36946676<\/em><\/p>\n<p><em>Technical Contact:<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 PrivacyProtect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Domain Admin\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 (contact@privacyprotect.org)<\/em><\/p>\n<p><em>\u00a0\u00a0\u00a0 ID#10760, PO Box 16<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Nobby Beach<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 null,QLD 4218<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 AU<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Tel. +45.36946676<\/em><\/p>\n<p><em>Billing Contact:<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 PrivacyProtect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Domain Admin\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 (contact@privacyprotect.org)<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 ID#10760, PO Box 16<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Nobby Beach<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 null,QLD 4218<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 AU<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 Tel. +45.36946676<\/em><\/p>\n<p><em>Status:LOCKED<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Note: This Domain Name is currently Locked. In this status the domain <\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 name cannot be transferred, hijacked, or modified. The Owner of this <\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 domain name can easily change this status from their control panel. <\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 This feature is provided as a security measure against fraudulent domain name hijacking.<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>Hm&#8230; All contact suggest the owner is somewhere in Australia (AU) but telephone number has prefix<br \/>\nto Denmark (+45). Of course name servers are in Russia \ud83d\ude09 Interesting is also STATUS of the domain:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>Status:LOCKED<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Note: This Domain Name is currently Locked. In this status the domain<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 name cannot be transferred, hijacked, or modified. The Owner of this<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 domain name can easily change this status from their control panel.<\/em><br \/>\n<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 This feature is provided as a security measure against fraudulent domain name hijacking.<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>More information:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em># host randkipl.com<\/em><br \/>\n<em>randkipl.com has address 91.202.63.130<\/em><br \/>\n<em># host -t any randkipl.com<\/em><br \/>\n<em>randkipl.com name server ns2.reg.ru.<\/em><br \/>\n<em>randkipl.com name server ns1.reg.ru.<\/em><br \/>\n<em>randkipl.com has address 91.202.63.130<\/em><br \/>\n<em># host 91.202.63.130<\/em><br \/>\n<em>Host 130.63.202.91.in-addr.arpa. not found: 3(NXDOMAIN)<\/em><br \/>\n<em>% This is the RIPE Database query service.<\/em><br \/>\n<em>% The objects are in RPSL format.<\/em><br \/>\n<em>%<\/em><br \/>\n<em>% The RIPE Database is subject to Terms and Conditions.<\/em><br \/>\n<em>% See http:\/\/www.ripe.net\/db\/support\/db-terms-conditions.pdf<\/em><\/p>\n<p><em>% Note: this output has been filtered.<\/em><br \/>\n<em>%\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 To receive output for a database update, use the &#8220;-B&#8221; flag.<\/em><\/p>\n<p><em>% Information related to &#8216;91.202.60.0 &#8211; 91.202.63.255&#8217;<\/em><\/p>\n<p><em>inetnum:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 91.202.60.0 &#8211; 91.202.63.255<\/em><br \/>\n<em>netname:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 AKRINO-NET<\/em><br \/>\n<em>descr:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Akrino Inc<\/em><br \/>\n<em>country:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 VG<\/em><br \/>\n<em>org:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 ORG-AI38-RIPE<\/em><br \/>\n<em>admin-c:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IVM27-RIPE<\/em><br \/>\n<em>tech-c:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IVM27-RIPE<\/em><br \/>\n<em>status:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 ASSIGNED PI<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE-NCC-END-MNT<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>mnt-lower:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE-NCC-END-MNT<\/em><br \/>\n<em>mnt-routes:\u00a0\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>mnt-domains:\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<\/em><\/p>\n<p><em>organisation:\u00a0\u00a0 ORG-AI38-RIPE<\/em><br \/>\n<em>org-name:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Akrino Inc<\/em><br \/>\n<em>org-type:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 OTHER<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Akrino Inc.<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 P.O.Box 146 Trident Chambers<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Road Town, Tortola<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 BVI<\/em><br \/>\n<em>e-mail:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 noc.akrino@gmail.com<\/em><br \/>\n<em>mnt-ref:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<\/em><\/p>\n<p><em>person:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Igoren V Murzak<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Akrino Inc<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 P.O.Box 146 Trident Chambers<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Road Town, Tortola<\/em><br \/>\n<em>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 BVI<\/em><br \/>\n<em>phone:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 +1 914 5952753<\/em><br \/>\n<em>e-mail:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 noc.akrino@gmail.com<\/em><br \/>\n<em>nic-hdl:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IVM27-RIPE<\/em><\/p>\n<p><em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<\/em><\/p>\n<p><em>% Information related to &#8216;91.202.60.0\/22AS44571&#8217;<\/em><\/p>\n<p><em>route:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 91.202.60.0\/22<\/em><br \/>\n<em>descr:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 AKRINO BLOCK<\/em><br \/>\n<em>origin:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 AS44571<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<\/em><\/p>\n<p><em>% Information related to &#8216;91.202.63.0\/24AS44571&#8217;<\/em><\/p>\n<p><em>route:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 91.202.63.0\/24<\/em><br \/>\n<em>descr:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 AKRINO BLOCK #4<\/em><br \/>\n<em>origin:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 AS44571<\/em><br \/>\n<em>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MNT-AKRINO<\/em><br \/>\n<em>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>So Internet Service Provider is Akrino Inc. from Virgin Islands, British. If we google for this IP address we can discover that it was used many times for some attacks. Many domains was registered for this IP address, for example sex-v-odnoklassnikah.com, seks-v-mambe.com, sexnk.org, etc.<\/p>\n<p>Here is nmap scan:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>Nmap scan report for 91.202.63.130<\/em><br \/>\n<em>Host is up (0.045s latency).<\/em><br \/>\n<em>Scanned at 2011-09-02 00:43:47 CEST for 10s<\/em><br \/>\n<em>Not shown: 999 filtered ports<\/em><br \/>\n<em>PORT\u00a0\u00a0 STATE SERVICE<\/em><br \/>\n<em>80\/tcp open\u00a0 http<\/em><br \/>\n<em>Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port<\/em><br \/>\n<em>OS fingerprint not ideal because: Missing a closed TCP port so results incomplete<\/em><br \/>\n<em>Aggressive OS guesses: OpenWrt White Russian 0.9 (Linux 2.4.30) (93%), OpenWrt 0.9 &#8211; 7.09 (Linux 2.4.30 &#8211; 2.4.34) (93%), OpenWrt Kamikaze 7.09 (Linux 2.6.22) (93%), Crestron XPanel control system (87%), Netgear DG834G WAP (87%), OpenBSD 4.3 (87%), Apple Mac OS X 10.6.2 &#8211; 10.6.4 (Snow Leopard) (Darwin 10.2.0 &#8211; 10.4.0) (86%), Cisco IronPort C650 email security appliance (AsyncOS 7.0.1) (86%), FreeBSD 6.1-RELEASE (86%), OpenWrt (Linux 2.4.30 &#8211; 2.4.34) (86%)<\/em><br \/>\n<em>No exact OS matches for host (test conditions non-ideal).<\/em><br \/>\n<em>TCP\/IP fingerprint:<\/em><br \/>\n<em>SCAN(V=5.51%D=9\/2%OT=80%CT=%CU=%PV=N%G=N%TM=4E600AAD%P=i686-pc-linux-gnu)<\/em><br \/>\n<em>SEQ(SP=105%GCD=4%ISR=107%TS=U)<\/em><br \/>\n<em>SEQ(SP=102%GCD=2%ISR=109%TI=RI%TS=U)<\/em><br \/>\n<em>OPS(O1=M5B4SLL%O2=M578SLL%O3=M280%O4=M5B4SLL%O5=M218SLL%O6=M109SLL)<\/em><br \/>\n<em>WIN(W1=2000%W2=2000%W3=2000%W4=2000%W5=2000%W6=2000)<\/em><br \/>\n<em>ECN(R=Y%DF=Y%TG=40%W=2000%O=M5B4SLL%CC=N%Q=)<\/em><br \/>\n<em>T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)<\/em><br \/>\n<em>T2(R=N)<\/em><br \/>\n<em>T3(R=N)<\/em><br \/>\n<em>T4(R=Y%DF=Y%TG=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)<\/em><br \/>\n<em>U1(R=N)<\/em><br \/>\n<em>IE(R=N)<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>OK. It&#8217;s time to look a bit for the site. Here is headers from the connection:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>http:\/\/randkipl.com\/user.php?page=id&amp;id=16112<\/em><\/p>\n<p><em>GET \/user.php?page=id&amp;id=16112 HTTP\/1.1<\/em><br \/>\n<em>Host: randkipl.com<\/em><br \/>\n<em>User-Agent: Mozilla\/5.0 (X11; Linux i686; rv:6.0.1) Gecko\/20100101 Firefox\/6.0.1<\/em><br \/>\n<em>Accept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,*\/*;q=0.8<\/em><br \/>\n<em>Accept-Language: pl,en-us;q=0.7,en;q=0.3<\/em><br \/>\n<em>Accept-Encoding: gzip, deflate<\/em><br \/>\n<em>Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<\/em><br \/>\n<em>Connection: keep-alive<\/em><br \/>\n<em>Referer: http:\/\/agagwhili.com\/-lenaa<\/em><br \/>\n<em>Cookie: view=1; p=336; sub=1887; sex=0; erotic=1; typep=0; PHPSESSID=a7a9a32d77f07a11d3b3cce52a7b2910<\/em><\/p>\n<p><em>HTTP\/1.1 200 OK<\/em><br \/>\n<em>Server: nginx<\/em><br \/>\n<em>Date: Thu, 01 Sep 2011 19:24:43 GMT<\/em><br \/>\n<em>Content-Type: text\/html; charset=UTF-8<\/em><br \/>\n<em>Transfer-Encoding: chunked<\/em><br \/>\n<em>Connection: keep-alive<\/em><br \/>\n<em>X-Powered-By: PHP\/5.2.17<\/em><br \/>\n<em>Expires: Thu, 19 Nov 1981 08:52:00 GMT<\/em><br \/>\n<em>Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0<\/em><br \/>\n<em>Pragma: no-cache<\/em><br \/>\n<em>Set-Cookie: view=1; expires=Fri, 02-Sep-2011 19:24:43 GMT; path=\/<\/em><br \/>\n<em>Set-Cookie: p=336; expires=Sat, 01-Oct-2011 19:24:43 GMT; path=\/<\/em><br \/>\n<em>Set-Cookie: sub=1887; expires=Sat, 01-Oct-2011 19:24:43 GMT; path=\/<\/em><br \/>\n<em>Set-Cookie: sex=0; expires=Sat, 01-Oct-2011 19:24:43 GMT; path=\/<\/em><br \/>\n<em>Set-Cookie: erotic=1; expires=Sat, 01-Oct-2011 19:24:43 GMT; path=\/<\/em><br \/>\n<em>Set-Cookie: typep=0; expires=Sat, 01-Oct-2011 19:24:43 GMT; path=\/<\/em><br \/>\n<em>&#8212; CUT &#8212;<\/em><\/p>\n<p>Server is in fact Apache in version 1.3.42 but the fake server name is transfered (nginx). Server use PHP\/5.2.17 and create Cookies.<br \/>\nNext header:<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>http:\/\/randkipl.com\/js\/messages_pl.php?city=&lt;city&gt;<\/em><\/p>\n<p><em>GET \/js\/messages_pl.php?city=&lt;city&gt; HTTP\/1.1<\/em><br \/>\n<em>Host: randkipl.com<\/em><br \/>\n<em>User-Agent: Mozilla\/5.0 (X11; Linux i686; rv:6.0.1) Gecko\/20100101 Firefox\/6.0.1<\/em><br \/>\n<em>Accept: *\/*<\/em><br \/>\n<em>Accept-Language: pl,en-us;q=0.7,en;q=0.3<\/em><br \/>\n<em>Accept-Encoding: gzip, deflate<\/em><br \/>\n<em>Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<\/em><br \/>\n<em>Connection: keep-alive<\/em><br \/>\n<em>Referer: http:\/\/randkipl.com\/user.php?page=id&amp;id=16112<\/em><br \/>\n<em>Cookie: view=1; p=336; sub=1887; sex=0; erotic=1; typep=0; PHPSESSID=a7a9a32d77f07a11d3b3cce52a7b2910<\/em><\/p>\n<p><em>HTTP\/1.1 200 OK<\/em><br \/>\n<em>Server: nginx<\/em><br \/>\n<em>Date: Thu, 01 Sep 2011 19:24:43 GMT<\/em><br \/>\n<em>Content-Type: text\/html; charset=UTF-8<\/em><br \/>\n<em>Transfer-Encoding: chunked<\/em><br \/>\n<em>Connection: keep-alive<\/em><br \/>\n<em>X-Powered-By: PHP\/5.2.17<\/em><br \/>\n<em>&#8212; CUT&#8212;<\/em><\/p>\n<p>As we can see the city name is send to the server. This is what I wrote at the beginning. Site use this name to improve social engineering attack \ud83d\ude09<\/p>\n<p>I didn&#8217;t have a time to lok for the site closer, but it has a lot of bugs in the registering form. Here is simple XSS:<\/p>\n<p><a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-187\" title=\"register_1\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_1-252x300.png\" alt=\"\" width=\"252\" height=\"300\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_1-252x300.png 252w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_1.png 474w\" sizes=\"auto, (max-width: 252px) 100vw, 252px\" \/><\/a>\u00a0 <a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-188\" title=\"register_2\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_2-300x108.png\" alt=\"\" width=\"300\" height=\"108\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_2-300x108.png 300w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/register_2.png 990w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>In the cookies we can find information like chat box id, etc. \ud83d\ude09 Site was written probably by some russian guy &#8211; comments in the code suggest it:<\/p>\n<p>$(&#8216;#chat&#8217;).append(&#8220;&lt;p&gt;&lt;span&gt;\u0413\u043e\u0441\u0442\u044c&lt;\/span&gt; \u0433\u043e\u0432\u043e\u0440\u0438\u0442:&lt;br \/&gt;&#8221;);<br \/>\n<strong>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 it means &#8220;Guess write&#8221;<\/strong><\/p>\n<p>&lt;!&#8211;O mnie: &lt;b&gt;\u041c\u043e\u044f \u043a\u0440\u0430\u0441\u0438\u0432\u0430\u044f \u0433\u0440\u0443\u0434\u044c \u0432\u0441\u0435\u0433\u0434\u0430 \u0436\u0434\u0451\u0442 \u0436\u0430\u0440\u043a\u0438\u0445 \u0447\u0443\u0432\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0445 \u043f\u043e\u0446\u0435\u043b\u0443\u0435\u0432.<br \/>\n\u042f \u0433\u043e\u0442\u043e\u0432\u0430 \u043e\u0442\u0434\u0430\u0442\u044c\u0441\u044f \u043c\u0443\u0436\u0447\u0438\u043d\u0435, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0441\u043c\u043e\u0436\u0435\u0442 \u0441\u0432\u043e\u0438\u043c\u0438 \u043e\u043f\u044b\u0442\u043d\u044b\u043c\u0438 \u0440\u0443\u043a\u0430\u043c\u0438 \u0434\u043e\u0432\u0435\u0441\u0442\u0438<br \/>\n\u043c\u0435\u043d\u044f \u0434\u043e \u044d\u043a\u0441\u0442\u0430\u0437\u0430. \u0411\u043e\u043b\u044c\u0448\u0435 \u0432\u0441\u0435\u0433\u043e \u043e\u0431\u043e\u0436\u0430\u044e, \u043a\u043e\u0433\u0434\u0430 \u043c\u0435\u043d\u044f \u0431\u0435\u0440\u0443\u0442 \u0441\u0437\u0430\u0434\u0438.&lt;\/b&gt;&lt;br&gt;&#8211;&gt;<\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 I will not translate this \ud83d\ude09<\/strong><\/p>\n<p>About chat box. We can find it here:<\/p>\n<p>http:\/\/randkipl.com\/\/js\/messages_pl.php?city=&lt;city&gt;<\/p>\n<p><em>&#8212; CUT &#8212;<\/em><br \/>\n<em>var messages = <\/em><\/p>\n<p><em>new Array(<\/em><br \/>\n<em>&#8220;M6 &#8211; No tak fajnego ciala jeszcze nie widzialem, W5 powtorzmy w nast. tygodniu?!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W5 &#8211; Popatrzymy\\n&#8221;+<\/em><br \/>\n<em>&#8220;W2 &#8211; Dobrze wypoczelismy wczoraj w miescie &lt;city&gt;\\n&#8221;+<\/em><br \/>\n<em>&#8220;M12 &#8211; Hej! Starczy pornem sie bawic, kto wczoraj byl na spotkaniu grupowym w &lt;city&gt;? \\n&#8221;+<\/em><br \/>\n<em>&#8220;W2 &#8211; Ja bylam, chcesz powtorzyc? \\n&#8221;+<\/em><br \/>\n<em>&#8220;M12 &#8211; W2 no ze zdjec widac, ze niezle bylo, jestes taka mila ) \\n&#8221;+<\/em><br \/>\n<em>&#8220;M10 &#8211; Ci, ktorzy waslali swoje nagranie &#8216;W calym domu&#8217; prosze podac link do strony brunetki, bardzo mi sie spodobala \\n&#8221;+<\/em><br \/>\n<em>&#8220;W5 &#8211; Wyslalam Ci do privu\\n&#8221;+<\/em><br \/>\n<em>&#8220;W28 &#8211; dla poczatku by nie zaszkodzilo. Zobaczyc kto czego wart. I u kogo jak stoi)))\\n&#8221;+<\/em><br \/>\n<em>&#8220;M1 &#8211; To oczym pytanie &#8211; zapraszam do priwu albo do web przez skype!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W24 &#8211; Zgubilam wideo, to co wysylala W2? Prosze o podanie linku!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M6 &#8211; M2 aktywnie wyklada swoje domowe wideo, nawet podejrzewam, ze zapraszali kogos filmowac)!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M18 &#8211; Kto tam sie grozil zorganizowac striptiz przez skype?\\n&#8221;+<\/em><br \/>\n<em>&#8220;M19 &#8211; Starczy dreczyc, dziewczynki, wlaczajcie kamere! \\n&#8221;+<\/em><br \/>\n<em>&#8220;W24 &#8211; A kto mi obiecywal foto swojego ptaszka?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W25 &#8211; W24 &#8211; A kto, do rzeczy, obiecywal?\\n&#8221;+<\/em><br \/>\n<em>&#8220;M12 &#8211; Jestem gotowy do spotkania z dziewczyna z Piteru!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W5 &#8211; Juz zrzucilam Ci do priwu komorke &#8211; otrzymales?\\n&#8221;+<\/em><br \/>\n<em>&#8220;M6 &#8211; Kto uwielbia anal lesbijek, rzuce do priwu zajebisty filmik!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W26 &#8211; Mam propozycje dla powaznych mezczyzn. Zapraszam do mego priwu! (miasto &lt;b&gt;&lt;city&gt;&lt;\/b&gt;)\\n&#8221;+<\/em><br \/>\n<em>&#8220;M10 &#8211; Co znaczy powaznych? Z kasa?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W37 &#8211; Proponuje swoje realne intymne zdjecia\\n&#8221;+<\/em><br \/>\n<em>&#8220;W24 &#8211; Co za super! Z poczatku &#8211; no i potem koszmar, jak ona to wszystko wytrzyma?!))\\n&#8221;+<\/em><br \/>\n<em>&#8220;M19 &#8211; M7 &#8211;\u00a0 W2 w dzienniku ma taki ekstremalny, paluszki oblizesz! \\n&#8221;+<\/em><br \/>\n<em>&#8220;M1 &#8211; Aha. To ona tam sama chyba z dwoma facetami wystepuje, a wszystkim mowi, ze to jej kuzynka\\n&#8221;+<\/em><br \/>\n<em>&#8220;W2 &#8211; Namawiacie na skromna dziewczyne, niepotrzebnie)))\\n&#8221;+<\/em><br \/>\n<em>&#8220;W22 &#8211; W24 &#8211; Zajebiscie, co teraz zobaczylam z linku Sergieja. Popatrz!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W41 &#8211; Proponuje realny seks z dominowaniem w Moskwie!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M26 &#8211; czesc wszystkim. Jestem tu nowy. Naprawde tu zapoznywaja sie dla seksu, jestem z miasta&lt;city&gt;?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W28 &#8211; Zalezy od tego, co proponowac bedziesz\\n&#8221;+<\/em><br \/>\n<em>&#8220;W28 &#8211; Czy myslales, ze przyslismy tutaj w miasta grac?))\\n&#8221;+<\/em><br \/>\n<em>&#8220;M26 &#8211; Poczatek optymistyczny, do rzeczy\\n&#8221;+<\/em><br \/>\n<em>&#8220;M26 &#8211; Samara. Jestem gotowy do spotkania dzis wieczorem z sympatyczna dziewczyna) \\n&#8221;+<\/em><br \/>\n<em>&#8220;M10 &#8211; Polina &#8211; dinamo. Dalej zdjec nie pojdzie!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M9 &#8211; Kurde, dziewczynki, chce od razu dwoch &#8211; co robic?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W5 &#8211; zobacz ankiete M11 &#8211; dwie siostry ;)\\n&#8221;+<\/em><br \/>\n<em>&#8220;W41 &#8211; M9 &#8211; Przyjezdzaj do mnie na Sokol w Moskwie, wszystko zalatwie. Szczegoly &#8211; w priwie!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M10 &#8211; W41 powazna pani. Moze taaakie pokazac, juz widzialem!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W37 &#8211; M6 &#8211; Hejki! Nie zdradzales mi tutaj?Ostatnim razem nasze spotkanie bylo nawet za bardzo!)\\n&#8221;+<\/em><br \/>\n<em>&#8220;M6 &#8211; zdradzalem z dwiema brunetkami i jedna piersiasta lesbi. Poczekaj, zaraz Ci Linki podam!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W1 &#8211; Nie chlopaki poszli, a same masturbanty. Choc by ktos mi wsunal!)\\n&#8221;+<\/em><br \/>\n<em>&#8220;W30 &#8211; Oj, ja tez chce zobaczyc! M19, jestes z Moskwy?\\n&#8221;+<\/em><br \/>\n<em>&#8220;M19 &#8211; Tula! Proponuje dzisiaj grupowe spotkanie!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W11 &#8211; co do seks-party w Tule zwracaj sie do mnie &#8211; w zeszlym miesiecu bylo niezle!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W23 &#8211; Prosze i dla mnie troche czegoc slodziutkiego zostawic!)\\n&#8221;+<\/em><br \/>\n<em>&#8220;M9 &#8211; W2 &#8211; A jak Ci sie bardziej podoba?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W2 &#8211; gdy w dupe, ale ostroznie! \\n&#8221;+<\/em><br \/>\n<em>&#8220;M18 &#8211; Starczy nakrecac, lepiej wyloz swoje nowe przygody w biurze!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M26 &#8211; Popatrzcie w moim dzienniku na msj skarb i konczycie na siebie!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W15 &#8211; Aha. Juz widzialam. Naprawde zachwyca! A to naprawde twoj?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W1 &#8211; Ehe. Widzialam w realu, jeszcze wiekszy)))\\n&#8221;+<\/em><br \/>\n<em>&#8220;M1 &#8211; Gdy u niego wstaje, M26 pada!))))\\n&#8221;+<\/em><br \/>\n<em>&#8220;W26 &#8211; Kto chce nie przez skype &#8211; prosze do priwu po telefon i warunki!) \\n&#8221;+<\/em><br \/>\n<em>&#8220;M26 &#8211; M6 &#8211; A co, spotykales sie z Oksana?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W10 &#8211; Patrzcie na ta rzecz. Krecili prosto na lekcji!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M1 &#8211; Kurwa! Jak to oni wpali na sposob &#8211; prosto na podlodze!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M21 &#8211; Tak, ciekawa poza, trzeba bedzie sprobowac!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M24 &#8211; Starczy masturbowac, kto tam z &lt;city&gt; &#8211; przyjezdzajcie do mnie, pogramy w doroslych!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W10 -M24 &#8211; telefon i zdjecie wyslij, moze i przyjade\\n&#8221;+<\/em><br \/>\n<em>&#8220;W5 &#8211; No jestem z &lt;city&gt;.\u00a0 A co umiesz?\\n&#8221;+<\/em><br \/>\n<em>&#8220;M24 &#8211; Co zechcesz &#8211; polize, anal, seks zabawki!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W18 &#8211; Romka jest wielkim wymyslaczem! W sobote konczylam z nim 5 razy!)))\\n&#8221;+<\/em><br \/>\n<em>&#8220;M15 &#8211; A mi sie podobaja dziewczyny z piercingiem na wargach sromowych! Sa takie?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W12 &#8211; Tutaj wszyscy takie!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W27 &#8211; Aha, i nie tylko na wargach. Mam na pepku i jezyku pierscionek!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M12 &#8211; Mowia, lody z piercingiem sa uajebiste! \\n&#8221;+<\/em><br \/>\n<em>&#8220;W22 &#8211; A ty co, nie probowalecs? To 7 niebo!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M1 &#8211; M10 &#8211; Sluchaj, widziales W1 w realu?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W1 &#8211; kto tu plotkuje o mnie? A psik!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W5 &#8211; W2 &#8211; Popatrz-no, laseczko, na to! I to trzeba pod takim ujeciem zfilmowac! \\n&#8221;+<\/em><br \/>\n<em>&#8220;M12 &#8211; Prosze mi tez to pokazac, ocenie!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W2 &#8211; WoW! Jak ona go tam wsunela?\\n&#8221;+<\/em><br \/>\n<em>&#8220;M6 &#8211; W11 &#8211; A ja o czym mowie? Rzucilem Ci do priwu link do bezoplatnego porno.\\n&#8221;+<\/em><br \/>\n<em>&#8220;W30 &#8211; A kto co wiecej lubi?\\n&#8221;+<\/em><br \/>\n<em>&#8220;M19 &#8211; ja uwielbiam lesbi z zabawkami)))\\n&#8221;+<\/em><br \/>\n<em>&#8220;W36 &#8211; Tak-tak, jak jedna druga straponem &#8230; &#8211; to superrrrrrr)))))\\n&#8221;+<\/em><br \/>\n<em>&#8220;W9 &#8211; Chce sie mezczyzny zywego &#8211; z penisem\u2026\\n&#8221;+<\/em><br \/>\n<em>&#8220;M15 -W9 &#8211; Posluchaj, jak zrozumialem, jestes z Moskwy, to spotkajmy sie? \\n&#8221;+<\/em><br \/>\n<em>&#8220;W9 &#8211; Lap w priwie telefon!\\n&#8221;+<\/em><br \/>\n<em>&#8220;M24 &#8211; M7 &#8211; Zobacz, penisa dziewczynkom sie zechcialo. Moze pomozemy laseczkam? Zrobimy stoleczne swing-party? \\n&#8221;+<\/em><br \/>\n<em>&#8220;M7 &#8211; Tak zawsze za. W36, podaj numerek!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W36 &#8211; M24 i M7 napiszcie do priwu!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W35 &#8211; Popatrzcie, to ja z komorki swego chlopaka krecilam!\\n&#8221;+<\/em><br \/>\n<em>&#8220;W24 &#8211; Co za, jakiego ma miecza! Jak go przyjmujesz?\\n&#8221;+<\/em><br \/>\n<em>&#8220;W35 &#8211; Latwo!)))\\n&#8221;+<\/em><br \/>\n<em>&#8220;M26 &#8211; W48 &#8211; to Twoje wideo wysylal M2?\\n&#8221;<\/em><\/p>\n<p><em>);<\/em><\/p>\n<p><em>function rand(l,k)<\/em><br \/>\n<em>{<\/em><br \/>\n<em>\u00a0 var rand_no = Math.random();<\/em><br \/>\n<em>\u00a0 rand_no = l+rand_no * (k-l);<\/em><br \/>\n<em>\/\/\u00a0 alert(&#8220;&#8221;+rand_no+&#8221; &#8220;+Math.ceil(rand_no));<\/em><\/p>\n<p><em>\u00a0 return Math.round(rand_no);<\/em><br \/>\n<em>};<\/em><\/p>\n<p><em>var rndnum = getCookie(&#8216;curchattext&#8217;);<\/em><br \/>\n<em>if (rndnum) <\/em><br \/>\n<em>{<\/em><br \/>\n<em>\u00a0 if ((rndnum&lt;0) || (rndnum&gt;=messages.length))<\/em><br \/>\n<em>\u00a0 {<\/em><br \/>\n<em>\u00a0\u00a0\u00a0 rndnum = rand(0, messages.length-1);<\/em><br \/>\n<em>\u00a0 }<\/em><br \/>\n<em>}<\/em><br \/>\n<em>else<\/em><br \/>\n<em>{<\/em><br \/>\n<em>\u00a0 rndnum = rand(0, messages.length-1); \u00a0<\/em><br \/>\n<em>}<\/em><br \/>\n<em>setCookie(&#8216;curchattext&#8217;,rndnum);<\/em><\/p>\n<p><em>\/\/alert(rndnum);<\/em><br \/>\n<em>var messagesArray=messages[rndnum].split(&#8220;\\n&#8221;);<\/em><\/p>\n<p><em>\/\/alert(messagesArray.length);<\/em><\/p>\n<p><em>var boys=new Array(<\/em><br \/>\n<em>&#8220;dar&#8221;,<\/em><br \/>\n<em>&#8220;michalkania&#8221;,<\/em><br \/>\n<em>&#8220;Alex&#8221;,<\/em><br \/>\n<em>&#8220;Amadeus&#8221;,<\/em><br \/>\n<em>&#8220;Znieczulenie&#8221;,<\/em><br \/>\n<em>&#8220;Andrzey&#8221;,<\/em><br \/>\n<em>&#8220;Kamil&#8221;,<\/em><br \/>\n<em>&#8220;Jakub&#8221;,<\/em><br \/>\n<em>&#8220;Patrick&#8221;,<\/em><br \/>\n<em>&#8220;Adrian&#8221;,<\/em><\/p>\n<p><em>&#8220;Mihial&#8221;,<\/em><br \/>\n<em>&#8220;David&#8221;,<\/em><br \/>\n<em>&#8220;Katsper&#8221;,<\/em><br \/>\n<em>&#8220;Mateus&#8221;,<\/em><br \/>\n<em>&#8220;Ivan&#8221;,<\/em><br \/>\n<em>&#8220;Marcin&#8221;,<\/em><br \/>\n<em>&#8220;Daniel&#8221;,<\/em><br \/>\n<em>&#8220;Shimon&#8221;,<\/em><br \/>\n<em>&#8220;Bartlomieja&#8221;,<\/em><br \/>\n<em>&#8220;Philip&#8221;,<\/em><br \/>\n<em>&#8220;Christian&#8221;,<\/em><br \/>\n<em>&#8220;Paul&#8221;,<\/em><br \/>\n<em>&#8220;Adam&#8221;,<\/em><br \/>\n<em>&#8220;Arkady&#8221;,<\/em><br \/>\n<em>&#8220;Conrad&#8221;,<\/em><br \/>\n<em>&#8220;Lukas&#8221;,<\/em><br \/>\n<em>&#8220;Dariush&#8221;,<\/em><br \/>\n<em>&#8220;Dominique&#8221;,<\/em><br \/>\n<em>&#8220;Oscar&#8221;,<\/em><br \/>\n<em>&#8220;Andrew&#8221;,<\/em><br \/>\n<em>&#8220;Damian&#8221;,<\/em><br \/>\n<em>&#8220;Przemyslaw&#8221;,<\/em><br \/>\n<em>&#8220;Radoslav&#8221;,<\/em><br \/>\n<em>&#8220;Rafal&#8221;<\/em><br \/>\n<em>);<\/em><\/p>\n<p><em>var boys_colors=new Array(<\/em><br \/>\n<em>&#8220;red&#8221;, <\/em><br \/>\n<em>&#8220;blue&#8221;, <\/em><br \/>\n<em>&#8220;#e69240&#8221;, <\/em><br \/>\n<em>&#8220;green&#8221;, <\/em><br \/>\n<em>&#8220;black&#8221;, <\/em><br \/>\n<em>&#8220;#c96a6a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;red&#8221;, <\/em><br \/>\n<em>&#8220;blue&#8221;, <\/em><br \/>\n<em>&#8220;#e69240&#8221;, <\/em><br \/>\n<em>&#8220;green&#8221;, <\/em><br \/>\n<em>&#8220;black&#8221;, <\/em><br \/>\n<em>&#8220;#c96a6a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><\/p>\n<p><em>&#8220;red&#8221;, <\/em><br \/>\n<em>&#8220;blue&#8221;, <\/em><br \/>\n<em>&#8220;#e69240&#8221;, <\/em><br \/>\n<em>&#8220;green&#8221;, <\/em><br \/>\n<em>&#8220;black&#8221;, <\/em><br \/>\n<em>&#8220;#c96a6a&#8221;,<\/em><br \/>\n<em>&#8220;red&#8221;<\/em><br \/>\n<em>);<\/em><br \/>\n<em>var girls=new Array(<\/em><br \/>\n<em>&#8220;\u041e\u043b\u044f&#8221;,<\/em><br \/>\n<em>&#8220;niunia&#8221;,<\/em><br \/>\n<em>&#8220;aniaw&#8221;,<\/em><br \/>\n<em>&#8220;Oliwia&#8221;,<\/em><br \/>\n<em>&#8220;ania&#8221;,<\/em><br \/>\n<em>&#8220;xxmartaxx&#8221;,<\/em><br \/>\n<em>&#8220;milenka&#8221;,<\/em><br \/>\n<em>&#8220;Katanyna&#8221;,<\/em><br \/>\n<em>&#8220;Jana&#8221;,<\/em><br \/>\n<em>&#8220;kari&#8221;,<\/em><br \/>\n<em>&#8220;Emanuela&#8221;,<\/em><br \/>\n<em>&#8220;Elica&#8221;,<\/em><br \/>\n<em>&#8220;mi6kata&#8221;,<\/em><br \/>\n<em>&#8220;krissito&#8221;,<\/em><br \/>\n<em>&#8220;Zocha&#8221;,<\/em><br \/>\n<em>&#8220;korona&#8221;,<\/em><br \/>\n<em>&#8220;rainaxristovaa&#8221;,<\/em><br \/>\n<em>&#8220;lusinda&#8221;,<\/em><br \/>\n<em>&#8220;Mada&#8221;,<\/em><br \/>\n<em>&#8220;Ewa&#8221;,<\/em><br \/>\n<em>&#8220;Brygid&#8221;,<\/em><br \/>\n<em>&#8220;Kunigunde&#8221;,<\/em><br \/>\n<em>&#8220;Krysta&#8221;,<\/em><br \/>\n<em>&#8220;Yalgonata&#8221;,<\/em><br \/>\n<em>&#8220;Lidia&#8221;,<\/em><br \/>\n<em>&#8220;Ingrid&#8221;,<\/em><br \/>\n<em>&#8220;sensoria&#8221;,<\/em><br \/>\n<em>&#8220;rosito&#8221;,<\/em><br \/>\n<em>&#8220;justysia&#8221;,<\/em><br \/>\n<em>&#8220;Grazyna&#8221;,<\/em><br \/>\n<em>&#8220;pysia&#8221;,<\/em><br \/>\n<em>&#8220;hotbeborana&#8221;,<\/em><br \/>\n<em>&#8220;bebeto&#8221;,<\/em><br \/>\n<em>&#8220;ognyanov&#8221;,<\/em><br \/>\n<em>&#8220;treis&#8221;,<\/em><br \/>\n<em>&#8220;LadyBetina&#8221;,<\/em><br \/>\n<em>&#8220;crazyangel&#8221;,<\/em><br \/>\n<em>&#8220;angel&#8221;,<\/em><br \/>\n<em>&#8220;eli4ka&#8221;,<\/em><br \/>\n<em>&#8220;lo6omomi4e&#8221;,<\/em><br \/>\n<em>&#8220;niczky&#8221;,<\/em><br \/>\n<em>&#8220;ledenataaaa&#8221;,<\/em><br \/>\n<em>&#8220;aniaw&#8221;,<\/em><br \/>\n<em>&#8220;justysia&#8221;,<\/em><\/p>\n<p><em>&#8220;Krystyna&#8221;,<\/em><br \/>\n<em>&#8220;Elwira&#8221;,<\/em><br \/>\n<em>&#8220;Lodoiska&#8221;<\/em><br \/>\n<em>);<\/em><\/p>\n<p><em>var girls_colors=new Array(<\/em><br \/>\n<em>&#8220;red&#8221;, <\/em><br \/>\n<em>&#8220;blue&#8221;, <\/em><br \/>\n<em>&#8220;#e69240&#8221;, <\/em><br \/>\n<em>&#8220;green&#8221;, <\/em><br \/>\n<em>&#8220;black&#8221;, <\/em><br \/>\n<em>&#8220;#c96a6a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;,<\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;red&#8221;, <\/em><br \/>\n<em>&#8220;blue&#8221;, <\/em><br \/>\n<em>&#8220;#e69240&#8221;, <\/em><br \/>\n<em>&#8220;green&#8221;, <\/em><br \/>\n<em>&#8220;black&#8221;, <\/em><br \/>\n<em>&#8220;#c96a6a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;,<\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;,<\/em><br \/>\n<em>&#8220;#7979e9&#8221;, <\/em><br \/>\n<em>&#8220;#3c8d51&#8221;, <\/em><br \/>\n<em>&#8220;#4dafa9&#8221;, <\/em><br \/>\n<em>&#8220;#426664&#8221;, <\/em><br \/>\n<em>&#8220;#e2631e&#8221;, <\/em><br \/>\n<em>&#8220;#16910a&#8221;<\/em><br \/>\n<em>);<\/em><\/p>\n<p><em>&#8212; CUT &#8212;<\/em><\/p>\n<p>The name of the city is bold in the messages. This text are randomly put to the chat box with the random nick name. Of course we can post some java script code there instead of city \ud83d\ude09<br \/>\n<a href=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/chat_box_1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-190\" title=\"chat_box_1\" src=\"http:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/chat_box_1-300x144.png\" alt=\"\" width=\"300\" height=\"144\" srcset=\"https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/chat_box_1-300x144.png 300w, https:\/\/blog.pi3.com.pl\/wp-content\/uploads\/2011\/09\/chat_box_1.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Probably there is much more useful bugs. I didn&#8217;t register myself to play more, because I don&#8217;t have time to do that. If someone is interested in this topic and have some extra info please contact with me \ud83d\ude09<\/p>\n<p>Best regards,<br \/>\nAdam Zabrocki<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I&#8217;ve received strange mail: &#8212; CUT &#8212; Date: Thu, 01 Sep 2011 09:11:00 +0200 From: gayroobaoll &lt;gayroobaoll@o2.pl&gt; To: pi3@itsec.pl Subject: Chcesz, http:\/\/facebook.com\/100002779484440 &#8212; CUT &#8212; As we can see, there is no subject, mail include link to someone&#8217;s facebook profile and has got only one Polish world (yes, this is attack for the Polish [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[4,5,1],"tags":[],"class_list":["post-163","post","type-post","status-publish","format-standard","hentry","category-bughunt","category-exploiting","category-o-wszystkim-i-o-niczym"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=\/wp\/v2\/posts\/163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=163"}],"version-history":[{"count":29,"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=\/wp\/v2\/posts\/163\/revisions"}],"predecessor-version":[{"id":207,"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=\/wp\/v2\/posts\/163\/revisions\/207"}],"wp:attachment":[{"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.pi3.com.pl\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}