<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3628901792876639936</id><updated>2011-07-07T23:14:51.009-07:00</updated><category term='open files flash'/><category term='rename variable'/><category term='obfuscate'/><category term='rename function'/><category term='attack'/><category term='open pdf flash'/><category term='launch video flash'/><category term='cd multimedia'/><category term='flash loader'/><category term='obfuscator'/><category term='scr virus'/><category term='malware'/><category term='fullscreen'/><category term='remove virus'/><category term='launch mp3 flash'/><category term='google blocked website'/><category term='safe swf'/><category term='clean web site'/><category term='SWF Obfuscator'/><category term='virus'/><category term='iframe virus'/><category term='encode swf'/><category term='protect swf'/><category term='clean'/><category term='virus injection'/><title type='text'>Saschart: Web Design and Programming</title><subtitle type='html'>Web pages building in an original design. Shopping cart and databases on the Internet in PHP and MySQL programming. Presentation on the CD and on the net for business and particular persons. Your business needs promotion and advertising on the net.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://saschart.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3628901792876639936/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://saschart.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>SaschArt</name><uri>http://www.blogger.com/profile/09861240200465209102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='13' src='http://2.bp.blogspot.com/_PZZepqt0Occ/SlW9ufCtenI/AAAAAAAAAAc/CejLM2Zznog/S220/logo.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3628901792876639936.post-705625690173163258</id><published>2009-07-05T10:07:00.000-07:00</published><updated>2009-07-16T05:18:57.080-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='clean web site'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe virus'/><category scheme='http://www.blogger.com/atom/ns#' term='clean'/><category scheme='http://www.blogger.com/atom/ns#' term='scr virus'/><category scheme='http://www.blogger.com/atom/ns#' term='attack'/><category scheme='http://www.blogger.com/atom/ns#' term='google blocked website'/><category scheme='http://www.blogger.com/atom/ns#' term='virus injection'/><category scheme='http://www.blogger.com/atom/ns#' term='remove virus'/><title type='text'>Iframe Virus, Malware, src Virus - How to Remove  ?</title><content type='html'>Right in this moment is a new massive hacking attack on web sites. This attack targeted a lot of webhosting providers!&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;How to clean your web site and remove the Iframe Virus, Malware or src Virus injection?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;The attacker will change in mass all your index files and your home files. The format of this viruses is almost like this:&lt;br /&gt;&lt;br /&gt;&lt;div style="PADDING-RIGHT: 4px; PADDING-LEFT: 4px; PADDING-BOTTOM: 4px; OVERFLOW: auto; WIDTH: 400px; PADDING-TOP: 4px; HEIGHT: 30px; BACKGROUND-COLOR: #f9f9f9;font-size:11;"&gt;&amp;lt;iframe style="VISIBILITY: hidden" src="http://other_domain..."&gt;&amp;lt;/iframe&gt;&lt;/div&gt;&lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;&lt;div style="PADDING-RIGHT: 4px; PADDING-LEFT: 4px; PADDING-BOTTOM: 4px; OVERFLOW: auto; WIDTH: 400px; PADDING-TOP: 4px; HEIGHT: 30px; BACKGROUND-COLOR: #f9f9f9;font-size:11;"&gt;&amp;lt;img src="http://other_domain.../" style="visibility: hidden;" /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Allmost attack is based on &lt;span style="FONT-WEIGHT: bold"&gt;src out&lt;/span&gt; of your domain, so you must find which pages have isertion with src which is not on your domain. Other posibility is in javascript, but this is encoded script which is hard to find it, in this case you must check javascript content other then yours which was added on your web site files.&lt;br /&gt;&lt;br /&gt;Follow this steps:&lt;br /&gt;&lt;b&gt;&lt;/b&gt;1. Immediately &lt;span style="FONT-WEIGHT: bold"&gt;change your FTP password&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2. Login on your FTP account and order your files by date, the changed files will be on the top of list. Here is the target when you must check first &lt;span style="FONT-WEIGHT: bold"&gt;iframe&lt;/span&gt; or &lt;span style="FONT-WEIGHT: bold"&gt;src out&lt;/span&gt; of your domain, remove it and upload again your clean files.&lt;br /&gt;&lt;br /&gt;3. Securize your FTP account, &lt;span style="FONT-WEIGHT: bold"&gt;allow only your ip&lt;/span&gt; or a class of ip to can login using the firewall. In the Unix based OS if you have iptables enabled is very easy to do this using commands:&lt;br /&gt;&lt;br /&gt;iptables -A INPUT -p tcp --dport 21 -s 80.47.84.200 -j ACCEPT&lt;br /&gt;iptables -A INPUT -p tcp --dport 21 -s 80.47.84.201 -j ACCEPT&lt;br /&gt;iptables -A INPUT -p tcp --dport 21 -s 81.69.58.0/255 -j ACCEPT&lt;br /&gt;iptables -A INPUT -p tcp --dport 21 -j DROP&lt;br /&gt;&lt;br /&gt;This command will allow only 80.47.84.200, 80.47.84.201 ip to login and all 81.69.58 class.&lt;br /&gt;&lt;br /&gt;4. Make sure you have right the security features on your server to prevent server attack&lt;br /&gt;&lt;br /&gt;5. Check your OS with antispyware or anti trojans, is a lot of viruses in Windows which stole your FTP password from Cute FTP, Total Commander etc. and send it on the Internet!&lt;br /&gt;&lt;br /&gt;6. If Google allready find your virus or malware they will block your website, you must send to Google a request to recheck your web site here &lt;a href="http://www.google.com/webmasters/tools"&gt;http://www.google.com/webmasters/tools&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://soft.saschart.com/"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Clean Web Site&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; script can help you to make fast checking and clean your site files !&lt;br /&gt;&lt;br /&gt;This is a php based script malware remover using backup method. &lt;span style="FONT-WEIGHT: bold"&gt;Clean Web Site&lt;/span&gt; script can help you to keep clean and safe your site files to prevent iframe insertion, src virus injection, malware, backdoor or other attacks which change your site files content.&lt;br /&gt;&lt;br /&gt;HOW WORK ?&lt;br /&gt;&lt;br /&gt;after you upload a fresh and clean site files you will make a backup files from &lt;span style="FONT-WEIGHT: bold"&gt;Clean Web Site&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Clean Web Site&lt;/span&gt; will check every 6 hours in cron job (you can set the interval from your cron job) if your site files is the same with the last backup made&lt;br /&gt;&lt;br /&gt;if your site files was changed, remove or add other &lt;span style="FONT-WEIGHT: bold"&gt;Clean Web Site&lt;/span&gt; will send you an email with status of your files changed as date of changing, old and new size&lt;br /&gt;&lt;br /&gt;if this files was not changed by you after the last backup mean was changed by hacker, you must restore quickly your site files from the last clean backupWhat happen if you or you change files and don't make backup after changing ?&lt;br /&gt;&lt;br /&gt;You will receive a message from &lt;span style="FONT-WEIGHT: bold"&gt;Clean Web Site&lt;/span&gt; with status of your files changed and you will find your changing which is not made by hacker, so is not dangerous, you must make backup to have the last version of your site files.&lt;br /&gt;&lt;br /&gt;Visit &lt;a href="http://soft.saschart.com/"&gt;http://soft.saschart.com/&lt;/a&gt; to take the &lt;span style="FONT-WEIGHT: bold"&gt;Clean Web Site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3628901792876639936-705625690173163258?l=saschart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://saschart.blogspot.com/feeds/705625690173163258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3628901792876639936&amp;postID=705625690173163258' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3628901792876639936/posts/default/705625690173163258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3628901792876639936/posts/default/705625690173163258'/><link rel='alternate' type='text/html' href='http://saschart.blogspot.com/2009/07/clean-web-sitethis-is-php-based-script.html' title='Iframe Virus, Malware, src Virus - How to Remove  ?'/><author><name>SaschArt</name><uri>http://www.blogger.com/profile/09861240200465209102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='13' src='http://2.bp.blogspot.com/_PZZepqt0Occ/SlW9ufCtenI/AAAAAAAAAAc/CejLM2Zznog/S220/logo.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3628901792876639936.post-4073412917723709584</id><published>2009-07-01T01:57:00.000-07:00</published><updated>2009-07-09T05:58:25.880-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='flash loader'/><category scheme='http://www.blogger.com/atom/ns#' term='launch video flash'/><category scheme='http://www.blogger.com/atom/ns#' term='fullscreen'/><category scheme='http://www.blogger.com/atom/ns#' term='cd multimedia'/><category scheme='http://www.blogger.com/atom/ns#' term='open pdf flash'/><category scheme='http://www.blogger.com/atom/ns#' term='open files flash'/><category scheme='http://www.blogger.com/atom/ns#' term='launch mp3 flash'/><title type='text'>SaschArt Flash Loader</title><content type='html'>&lt;b&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;SaschArt Flash Loader - free version 1.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;Flash Loader is simple but smart application for &lt;b&gt;CD Multimedia Presentation&lt;/b&gt; in flash. With this application you can loading your swf file and use it like an application for all Windows Platforms. If you try to make windows projector from Flash you will can launch only other executables. My application can &lt;b&gt;launch all kind of files&lt;/b&gt; and open it in the default application with easy commands. For example you can open from your swf file: &lt;b&gt;doc, txt, pdf, exe, jpg, gif, avi, mp3&lt;/b&gt; and more. Also you can set in SaschArt Flash Loader swf sizes and path from another folder, border style and fullscreen style.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Commands setting:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;In the readme.txt file you can set border, fullscreen, sizes and relative path from your swf file. Make this settings in the follow order: &lt;table width="94%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="blue"&gt;&lt;li&gt;&lt;i&gt;border:true&lt;/i&gt; set true or false if you want to have border or not for your swf &lt;/li&gt;&lt;li&gt;&lt;i&gt;fullscreen:false&lt;/i&gt; set true or false if you want your swf to open it in fullscreen mode or not &lt;/li&gt;&lt;li&gt;&lt;i&gt;sizes:550x400&lt;/i&gt; set sizes for your swf file (if you set before &lt;i&gt;fullscreen:true&lt;/i&gt; can erase this command to open your swf file with screen size) &lt;/li&gt;&lt;li&gt;&lt;i&gt;/presentation.swf&lt;/i&gt; set relative path from your swf file&lt;br /&gt;&lt;br /&gt;Also you can make commands into your swf file to launch all kind of files or other like this: &lt;/li&gt;&lt;li&gt;&lt;i&gt;fscommand("open","readme.txt")&lt;/i&gt; to open any file &lt;/li&gt;&lt;li&gt;&lt;i&gt;fscommand("minimize")&lt;/i&gt; to minimize your swf file &lt;/li&gt;&lt;li&gt;&lt;i&gt;fscommand("quit")&lt;/i&gt; to close your swf file with application&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Visit &lt;a href="http://soft.saschart.com/"&gt;http://soft.saschart.com/&lt;/a&gt; to takeyour Flash Loader. &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3628901792876639936-4073412917723709584?l=saschart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://saschart.blogspot.com/feeds/4073412917723709584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3628901792876639936&amp;postID=4073412917723709584' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3628901792876639936/posts/default/4073412917723709584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3628901792876639936/posts/default/4073412917723709584'/><link rel='alternate' type='text/html' href='http://saschart.blogspot.com/2009/07/saschart-flash-loader.html' title='SaschArt Flash Loader'/><author><name>SaschArt</name><uri>http://www.blogger.com/profile/09861240200465209102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='13' src='http://2.bp.blogspot.com/_PZZepqt0Occ/SlW9ufCtenI/AAAAAAAAAAc/CejLM2Zznog/S220/logo.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3628901792876639936.post-333549831206320083</id><published>2009-06-08T10:08:00.000-07:00</published><updated>2009-07-16T05:23:22.519-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='protect swf'/><category scheme='http://www.blogger.com/atom/ns#' term='rename function'/><category scheme='http://www.blogger.com/atom/ns#' term='SWF Obfuscator'/><category scheme='http://www.blogger.com/atom/ns#' term='rename variable'/><category scheme='http://www.blogger.com/atom/ns#' term='encode swf'/><category scheme='http://www.blogger.com/atom/ns#' term='obfuscator'/><category scheme='http://www.blogger.com/atom/ns#' term='safe swf'/><category scheme='http://www.blogger.com/atom/ns#' term='obfuscate'/><title type='text'>SWF Obfuscator</title><content type='html'>&lt;strong&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;SWF Obfuscator - free version 1.0&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This SWF Obfuscator can easy to encode your swf files to protect your work. This obfuscator rename variable and functions names which you insert on the field, also you can find the functions names from your swf files.&lt;br /&gt;&lt;br /&gt;I use this in the script:&lt;br /&gt;&lt;br /&gt;&lt;div style="PADDING-RIGHT: 4px; PADDING-LEFT: 4px; PADDING-BOTTOM: 4px; OVERFLOW: auto; WIDTH: 400px; PADDING-TOP: 4px; HEIGHT: 140px; BACKGROUND-COLOR: #f9f9f9;font-size:11;"&gt;$fp=fopen($src,"rb") ;&lt;br /&gt;$head=fread($fp,3) ;&lt;br /&gt;if ($head&lt;&gt;"FWS" &amp;amp;&amp;amp; $head&lt;&gt;"CWS") {&lt;br /&gt;messageEcho("Uploaded file is not a valid SWF file");&lt;br /&gt;return;&lt;br /&gt;}&lt;br /&gt;$head.=fread($fp,5);&lt;br /&gt;$swfdata=fread($fp,filesize($src)-8);&lt;br /&gt;fclose($fp);&lt;br /&gt;if (substr($head,0,1)=="C")&lt;br /&gt;&lt;br /&gt;$swfdata=gzuncompress($swfdata);&lt;br /&gt;&lt;br /&gt;//change variables and functions name to obfuscate&lt;br /&gt;&lt;br /&gt;$swfdata=strtr($swfdata,array($old_var=&gt;$new_var,... ));&lt;br /&gt;&lt;br /&gt;if (substr($head,0,1)=="C")&lt;br /&gt;$swfdata=gzcompress($swfdata);&lt;br /&gt;$swfdata=$head.$swfdata;&lt;br /&gt;&lt;br /&gt;$fp=fopen($dest,"wb");&lt;br /&gt;$result=fwrite($fp,$swfdata);&lt;br /&gt;fclose($fp);&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Visit &lt;a href="http://soft.saschart.com/"&gt;http://soft.saschart.com/&lt;/a&gt; to &lt;span style="FONT-WEIGHT: bold"&gt;make safe your swf files.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="FONT-WEIGHT: bold"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3628901792876639936-333549831206320083?l=saschart.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://saschart.blogspot.com/feeds/333549831206320083/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3628901792876639936&amp;postID=333549831206320083' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3628901792876639936/posts/default/333549831206320083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3628901792876639936/posts/default/333549831206320083'/><link rel='alternate' type='text/html' href='http://saschart.blogspot.com/2009/07/swf-obfuscator.html' title='SWF Obfuscator'/><author><name>SaschArt</name><uri>http://www.blogger.com/profile/09861240200465209102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='13' src='http://2.bp.blogspot.com/_PZZepqt0Occ/SlW9ufCtenI/AAAAAAAAAAc/CejLM2Zznog/S220/logo.gif'/></author><thr:total>1</thr:total></entry></feed>
