<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Simiens Crew 2005 - How They Did It!</title>
	<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/</link>
	<description>Web Development by Chovy</description>
	<pubDate>Sat, 06 Sep 2008 01:41:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>

	<item>
		<title>By: HAILEY RHEA</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-17036</link>
		<author>HAILEY RHEA</author>
		<pubDate>Thu, 30 Nov 2006 05:40:41 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-17036</guid>
		<description>I think this is an excellent post. I was referred by ProBlogger (as have many, no doubt).</description>
		<content:encoded><![CDATA[<p>I think this is an excellent post. I was referred by ProBlogger (as have many, no doubt).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-242</link>
		<author>Anonymous</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-242</guid>
		<description>Hi...&lt;br /&gt;&lt;br /&gt;We *anon* just got done over with same hack..&lt;br /&gt;except the f**kin looser who did it used his own webserver to upload the backdoor code from etc..&lt;br /&gt;&lt;br /&gt;anyway.. wanted to say I greatly appreciated finding your article.. and source codes... it has helped..&lt;br /&gt;&lt;br /&gt;nice work dude</description>
		<content:encoded><![CDATA[<p>Hi&#8230;</p>
<p>We *anon* just got done over with same hack..<br />except the f**kin looser who did it used his own webserver to upload the backdoor code from etc..</p>
<p>anyway.. wanted to say I greatly appreciated finding your article.. and source codes&#8230; it has helped..</p>
<p>nice work dude</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LifeSteward</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-243</link>
		<author>LifeSteward</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-243</guid>
		<description>We had about a dozen hit last night.  I was using AwStats 6.1 and hadn't heard of this yet.  They also deleted all the files and directories containing "log", so I couldn't look at the log files.  Worst yet, the LOGO images and many "blog" files were deleted as well.  Lots of fun.&lt;br /&gt;&lt;br /&gt;I posted about it &lt;A HREF="http://www.blogger.com/r?http%3A%2F%2Fwww.lifesteward.org%2Findex.php%3Ftitle%3Dugh_i_ve_been_hacked%26more%3D1%26c%3D1%26tb%3D1%26pb%3D1"&gt;at my blog&lt;/A&gt;.</description>
		<content:encoded><![CDATA[<p>We had about a dozen hit last night.  I was using AwStats 6.1 and hadn&#8217;t heard of this yet.  They also deleted all the files and directories containing &#8220;log&#8221;, so I couldn&#8217;t look at the log files.  Worst yet, the LOGO images and many &#8220;blog&#8221; files were deleted as well.  Lots of fun.</p>
<p>I posted about it <a HREF="http://www.blogger.com/r?http%3A%2F%2Fwww.lifesteward.org%2Findex.php%3Ftitle%3Dugh_i_ve_been_hacked%26more%3D1%26c%3D1%26tb%3D1%26pb%3D1">at my blog</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PoiSQueM</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-244</link>
		<author>PoiSQueM</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-244</guid>
		<description>Hey Chovy,&lt;br /&gt;&lt;br /&gt;I've an incident here in my company too. All the users pages has been compromised and the index.html overwritten by "Simiens Crew 2005, Enquanto Houver Fome Morte Guerra Simiens Existira". &lt;br /&gt;&lt;br /&gt;Just complementing your nice job, I took a look on those executables and  both are backdoors programs. tt.txt open an socket on port 3333 and dc.zip is a reverse shell.&lt;br /&gt;&lt;br /&gt;I couldn't reproduce this on my website. Any idea?&lt;br /&gt;Latter...</description>
		<content:encoded><![CDATA[<p>Hey Chovy,</p>
<p>I&#8217;ve an incident here in my company too. All the users pages has been compromised and the index.html overwritten by &#8220;Simiens Crew 2005, Enquanto Houver Fome Morte Guerra Simiens Existira&#8221;. </p>
<p>Just complementing your nice job, I took a look on those executables and  both are backdoors programs. tt.txt open an socket on port 3333 and dc.zip is a reverse shell.</p>
<p>I couldn&#8217;t reproduce this on my website. Any idea?<br />Latter&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-245</link>
		<author>Anonymous</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-245</guid>
		<description>My website was hit by this attack as well.  Thank you very much for your quick detective work.  Really appreciate it.</description>
		<content:encoded><![CDATA[<p>My website was hit by this attack as well.  Thank you very much for your quick detective work.  Really appreciate it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-246</link>
		<author>Anonymous</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-246</guid>
		<description>My site was hit. All index.php pages were changed. They all now have the monkey on it. Does anyone know who done this? I wished someone would prosecute them. My site deals with issues such as miscarriages, child loss, etc..&lt;br /&gt;And to really kick things in the butt these losers done it at a time when my family had a loss. I hope they are able to sleep at night.</description>
		<content:encoded><![CDATA[<p>My site was hit. All index.php pages were changed. They all now have the monkey on it. Does anyone know who done this? I wished someone would prosecute them. My site deals with issues such as miscarriages, child loss, etc..<br />And to really kick things in the butt these losers done it at a time when my family had a loss. I hope they are able to sleep at night.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chovy</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-247</link>
		<author>chovy</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-247</guid>
		<description>Don't take it personally, they've hit thousands of sites, because they were vulnerable. I don't know exactly what the portugeuse means, but somewhere I read it had some political motivation behind it. Best thing you can do is join security announcements mailing list for your linux distro (god help you if you use Microsoft).</description>
		<content:encoded><![CDATA[<p>Don&#8217;t take it personally, they&#8217;ve hit thousands of sites, because they were vulnerable. I don&#8217;t know exactly what the portugeuse means, but somewhere I read it had some political motivation behind it. Best thing you can do is join security announcements mailing list for your linux distro (god help you if you use Microsoft).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-248</link>
		<author>Anonymous</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-248</guid>
		<description>"enquanto houver fome morte guerra Simiens existira" roughly translates to "while there is hunger, death, and war, Simiens will exist."</description>
		<content:encoded><![CDATA[<p>&#8220;enquanto houver fome morte guerra Simiens existira&#8221; roughly translates to &#8220;while there is hunger, death, and war, Simiens will exist.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chovy</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-249</link>
		<author>chovy</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-249</guid>
		<description>Hmmm....and they're solving that problem by hacking sites. Why didn't I think of that?</description>
		<content:encoded><![CDATA[<p>Hmmm&#8230;.and they&#8217;re solving that problem by hacking sites. Why didn&#8217;t I think of that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-250</link>
		<author>Anonymous</author>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://www.chovy.com/personal/simiens-crew-2005-how-they-did-it/#comment-250</guid>
		<description>Hey..&lt;br /&gt;if you open that &lt;br /&gt;Welcome to Data Cha0s Connect Back Shell, Data Cha0s Connect Back Backdoor, lots of reference to .h files, tt.txt, dc.zip, lots of stuff.. Searching on google for "Data cha0s" finds loads of stuff about this PHP script.. Adding "hax0r" to the search finds a site defaced by "Data Cha0s"..&lt;br /&gt;.. Fecking crackers..&lt;br /&gt;- Ben</description>
		<content:encoded><![CDATA[<p>Hey..<br />if you open that <br />Welcome to Data Cha0s Connect Back Shell, Data Cha0s Connect Back Backdoor, lots of reference to .h files, tt.txt, dc.zip, lots of stuff.. Searching on google for &#8220;Data cha0s&#8221; finds loads of stuff about this PHP script.. Adding &#8220;hax0r&#8221; to the search finds a site defaced by &#8220;Data Cha0s&#8221;..<br />.. Fecking crackers..<br />- Ben</p>
]]></content:encoded>
	</item>
</channel>
</rss>
