Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Someone wasted a nice bug on spyware... |
|---|---|
| Date: | Wed, 28 Dec 2005 21:19:11 +0100 |
Indeed, this is quite an annoyance. Buytoolbar.biz/xpl.wmf also works. I sent it to Microsoft a few days ago and they're looking into it. It looks like it's going to be a bad week at MSRC :( I whoised the owners of a couple domains who host the image and got the following information:
[...]
[...]Technical Contact ID: 6464086-SRSPLUS Technical Contact Name: Ezhi Brozkevitsh Technical Contact Organization: Ezhi Brozkevitsh Technical Contact Address1: Al. Armii Ludowej 24 Technical Contact City: Warszawa Technical Contact Postal Code: 00-609 Technical Contact Country: Poland Technical Contact Country Code: PL Technical Contact Phone Number: +21.225798400
This information does look promising. Iframeurl.biz is also registered to
the same individual. Perhaps the Polish authorities could apprehend this
culprit (either that, or a Polish reader of full-disclosure could pay him a
visit ;). That is, of course, assuming he is stupid enough to use his real
name to register a domain for illegal use.
Nope.
First, Ezhi seems not to match any Polish name even in terms of phonetic transcription. Brozkevitsh in turn looks like Brożkiewicz in Polish.
Second, as far as I know our international phone number always starts with +48...
Third, (for those of you who don't know, since 1989 something has changed in Poland and street name as Al. Armii Ludowej seems veeeery unlikely. However, to tell you the truth, it concerns to Warsaw which is a strange city itself (I personally live in Poznan) and nearly everything is plausible there (no offense, Warsaw).
Tomasz Kokowski (http://www.put.poznan.pl/~tommy) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] Re: [MailServer Notification]To recipient: Message matched eManager setting and action was taken., Michael Holstein |
|---|---|
| Next by Date: | Re: [Full-disclosure] test this, Thierry Zoller |
| Previous by Thread: | RE: [Full-disclosure] Someone wasted a nice bug on spyware..., Paul |
| Next by Thread: | Re: [Full-disclosure] Someone wasted a nice bug on spyware..., ad@heapoverflow.com |
| Indexes: | [Date] [Thread] [Top] [All Lists] |