<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Webshell hacks</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/webshell-hacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Just Like Sudoku</title>
		<link>http://www.thedarkvisitor.com/2007/12/just-like-sudoku/</link>
		<comments>http://www.thedarkvisitor.com/2007/12/just-like-sudoku/#comments</comments>
		<pubDate>Mon, 31 Dec 2007 03:26:00 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Chinese hacker hunt]]></category>
		<category><![CDATA[Webshell hacks]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=221</guid>
		<description><![CDATA[       Ever played Sudoku? There was a time when I couldn&#8217;t get away from the game.  Maybe it is my obsessive-complusive personality but finding out who hacked what is getting to be a lot like that. Fair warning, this Chinese hacker hunt isn&#8217;t very satisfactory, no picture of the guy at the end of the trail.  Still, I did it, so you will have to suffer the disappointment with me. Went back to an old favorite of mine, zoneh.cn and started looking at the hacked websites.  I don&#8217;t bother with  internal Chinese hacks but the ones outside of [...]]]></description>
			<content:encoded><![CDATA[<p ALIGN="center">  <img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/sudoku.JPG" ALT="sudoku.JPG" /></p>
<p>    Ever played Sudoku? There was a time when I couldn&#8217;t get away from the game.  Maybe it is my obsessive-complusive personality but finding out who hacked what is getting to be a lot like that.</p>
<p>Fair warning, this Chinese hacker hunt isn&#8217;t very satisfactory, no picture of the guy at the end of the trail.  Still, I did it, so you will have to suffer the disappointment with me.</p>
<p>Went back to an old favorite of mine, zoneh.cn and started looking at the hacked websites.  I don&#8217;t bother with  internal Chinese hacks but the ones outside of China just annoy me.</p>
<p>Coming in at number 6 in the standings of Top 20 Users is Webshell with 689:</p>
<p ALIGN="center"><a TITLE="webshell1.JPG" HREF="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell1.JPG"><img ALT="webshell1.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell1.thumbnail.JPG" /></a></p>
<p>One of the websites outside of China, listed under Webshell&#8217;s credits is http://www.photozone.co.kr: (Korean)</p>
<p ALIGN="center"><a HREF="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell2.JPG" TITLE="Webshell hacks"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell2.thumbnail.JPG" ALT="Webshell hacks" /></a></p>
<p ALIGN="left">Here is the mirror of Webshell&#8217;s hack:</p>
<p ALIGN="center"><a HREF="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell3.JPG" TITLE="webshell3.JPG"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell3.thumbnail.JPG" ALT="webshell3.JPG" /></a></p>
<p ALIGN="center">Translation: Whoosh, an amateur passed by. I am just a very young amateur.</p>
<p><span id="more-137"></span></p>
<p ALIGN="left">The  next website was http://www.casepower.com.tw: (Taiwanese)</p>
<p ALIGN="center"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell4.JPG" ALT="webshell4.JPG" /></p>
<p ALIGN="left"> and Webshell&#8217;s hack&#8230;</p>
<p ALIGN="center"><a HREF="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell5.JPG" TITLE="webshell5.JPG"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell5.thumbnail.JPG" ALT="webshell5.JPG" /></a></p>
<p ALIGN="left">    So what has Webshell given us to go on?  His e-mail address of course.  If Chinese hackers use e-mail addresses to recon their potential victims, I figure we can use them to find out about these guys.  Spare you the details of popping through a bunch of websites but finally it led to his blog at http://www.webshell.cn/.</p>
<p ALIGN="center"><a HREF="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell6.JPG" TITLE="webshell6.JPG"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell6.thumbnail.JPG" ALT="webshell6.JPG" /></a></p>
<p ALIGN="left">     Unfortunately, the only two pieces of information from the site of any use are that he was born on 27 April 1990 (yeah, a young one) and that he comes from Guangzhou City, Guangdong. While not useful, he also has a storefront on Taobao.com titled 0-day work room under http://shop35213037.taobao.com:</p>
<p ALIGN="center"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell7.JPG" ALT="webshell7.JPG" /></p>
<p ALIGN="left">    But, you roll through enough websites and you hit some interesting tid-bits.  Under an ICANN thread on registry failure he made the following post <a HREF="http://blog.icann.org/?p=134">http://blog.icann.org/?p=134</a>:</p>
<p ALIGN="center"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell8.JPG" ALT="webshell8.JPG" /></p>
<p ALIGN="left">     Tried to find listings under the name Lidongwei (wasn&#8217;t sure if this was a play on the name <a HREF="http://en.wikipedia.org/wiki/Lee_Teng-hui">Li Deng Hui</a>) but no  luck. However, a little more running around and I did bump into another one of his hacks on a Chinese website:</p>
<p ALIGN="center"><a TITLE="webshell9.JPG" HREF="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell9.JPG"><img ALT="webshell9.JPG" SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell9.thumbnail.JPG" /></a></p>
<p ALIGN="left">    The hack is on a Chinese site that advertises bathroom fixtures.  Webshell tells the site admin, <a HREF="http://www.thedarkvisitor.com/?p=140">much like our friend Tom</a>, that he has fixed the loopholes and is welcome to join his website security group.  Once again, this is for a bathroom fixture site admin.</p>
<p ALIGN="center"><a HREF="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell10.JPG" TITLE="webshell10.JPG"><img SRC="http://www.thedarkvisitor.com/wp-content/uploads/2007/12/webshell10.thumbnail.JPG" ALT="webshell10.JPG" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2007/12/just-like-sudoku/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

