<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: 0day 27-28May2008 in Flash</title>
	<atom:link href="http://geekbazaar.org/2008/05/28/0day-27-28may2008-in-flash/feed/" rel="self" type="application/rss+xml" />
	<link>http://geekbazaar.org/2008/05/28/0day-27-28may2008-in-flash/</link>
	<description>our few seconds of fame</description>
	<pubDate>Tue, 02 Dec 2008 00:31:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Spacer</title>
		<link>http://geekbazaar.org/2008/05/28/0day-27-28may2008-in-flash/#comment-6121</link>
		<dc:creator>Spacer</dc:creator>
		<pubDate>Thu, 29 May 2008 13:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://geekbazaar.org/?p=872#comment-6121</guid>
		<description>BTW that flash file is from today caught by Kaspersky as Trojan-Downloader.SWF.Small.y</description>
		<content:encoded><![CDATA[<p>BTW that flash file is from today caught by Kaspersky as Trojan-Downloader.SWF.Small.y</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sandro</title>
		<link>http://geekbazaar.org/2008/05/28/0day-27-28may2008-in-flash/#comment-6116</link>
		<dc:creator>sandro</dc:creator>
		<pubDate>Thu, 29 May 2008 03:51:04 +0000</pubDate>
		<guid isPermaLink="false">http://geekbazaar.org/?p=872#comment-6116</guid>
		<description>cheers ... the site is still up =)

flash1.swf: Macromedia Flash data, version 9
flash.swf:  Macromedia Flash data, version 9
lz.htm:     ASCII text, with CRLF line terminators
real.js:    ASCII text, with very long lines, with CRLF line terminators
rl.htm:     ASCII text, with CRLF line terminators
xl.htm:     ASCII text, with CRLF line terminators

looking at one of the html files ... its interesting to see them using variables which are popular names:
AntiVir
Silverlight
ActivePerl
Yorkfield
Samsung

This html file contains exploit code for Xunlei Thunder .. which seems to be .cn specific really.

Looking at the rest .. 
flash1.swf gets http://www.lovedai.cn - / - back.css and stores it to C:\6123t.exe 

http://www.lovedai.cn/ - seems to be a blog of geeky nature in Chinese. According to google translate, the latest post on this blog is about SQL injection. 

http://anubis.iseclab.org/result.php?taskid=32e80ae1e409da641560aad9c37c5cba&#038;refresh=1#id2292370
http://www.virustotal.com/analisis/81a419304ce50732be60e0e99255d765</description>
		<content:encoded><![CDATA[<p>cheers &#8230; the site is still up =)</p>
<p>flash1.swf: Macromedia Flash data, version 9<br />
flash.swf:  Macromedia Flash data, version 9<br />
lz.htm:     ASCII text, with CRLF line terminators<br />
real.js:    ASCII text, with very long lines, with CRLF line terminators<br />
rl.htm:     ASCII text, with CRLF line terminators<br />
xl.htm:     ASCII text, with CRLF line terminators</p>
<p>looking at one of the html files &#8230; its interesting to see them using variables which are popular names:<br />
AntiVir<br />
Silverlight<br />
ActivePerl<br />
Yorkfield<br />
Samsung</p>
<p>This html file contains exploit code for Xunlei Thunder .. which seems to be .cn specific really.</p>
<p>Looking at the rest ..<br />
flash1.swf gets <a href="http://www.lovedai.cn" rel="nofollow">http://www.lovedai.cn</a> - / - back.css and stores it to C:\6123t.exe </p>
<p><a href="http://www.lovedai.cn/" rel="nofollow">http://www.lovedai.cn/</a> - seems to be a blog of geeky nature in Chinese. According to google translate, the latest post on this blog is about SQL injection. </p>
<p><a href="http://anubis.iseclab.org/result.php?taskid=32e80ae1e409da641560aad9c37c5cba&#038;refresh=1#id2292370" rel="nofollow">http://anubis.iseclab.org/result.php?taskid=32e80ae1e409da641560aad9c37c5cba&#038;refresh=1#id2292370</a><br />
<a href="http://www.virustotal.com/analisis/81a419304ce50732be60e0e99255d765" rel="nofollow">http://www.virustotal.com/analisis/81a419304ce50732be60e0e99255d765</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
