<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : Intercage/EstDomains</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/Intercage_2F00_EstDomains/default.aspx</link><description>Tags: Intercage/EstDomains</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>More Exploit sites</title><link>http://msmvps.com/blogs/hostsnews/archive/2007/08/25/more-exploit-sites.aspx</link><pubDate>Sat, 25 Aug 2007 09:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1136699</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2007/08/25/more-exploit-sites.aspx#comments</comments><description>&lt;p&gt;Landing on &amp;quot;&lt;em&gt;voyeurcampic(dot)com&lt;/em&gt;&amp;quot; my Antivirus (&lt;a class="" href="http://msmvps.com/controlpanel/blogs/www.eset.com" target="_blank"&gt;NOD32&lt;/a&gt;) jumps up with the following warning ...&lt;/p&gt;
&lt;p&gt;&lt;img src="http://mvps.org/winhelp2002/blog/voyeurcampic.gif" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;NOD32 halts the loading of any further content and offers to Terminate (I like that description) the connection. So I investigate that site first thru Google and then check the Whois info ... oh this is not good!&lt;/p&gt;
&lt;p&gt;&lt;img src="http://mvps.org/winhelp2002/blog/voyeurcampic1.gif" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Well as you can see Google reports that &amp;quot;&lt;em&gt;This site may harm your computer&lt;/em&gt;&amp;quot; ... yeah I&amp;#39;d say so ... so checking the Registration info we find that it&amp;#39;s Hosted at Intercage Inc (well known for allowing exploits) and Registered thru EstDomains and then the Whois info is protected/hidden by &amp;quot;&lt;em&gt;PrivacyProtect.org&lt;/em&gt;&amp;quot;.&lt;/p&gt;
&lt;p&gt;Seems like they went thru a lot of trouble to hide their identity ... and they are running quite a few sites with similar exploits.&lt;br /&gt;216.255.186.82 = 59 sites&lt;br /&gt;216.255.186.83 = 15 sites&lt;br /&gt;216.255.186.84 = 10 sites&lt;/p&gt;
&lt;p&gt;I already had the sites in the first two IP addresses listed in the &lt;a class="" href="http://www.mvps.org/winhelp2002/hosts.htm" target="_blank"&gt;HOSTS file&lt;/a&gt; and I&amp;#39;ve added the 10 from the last one ... wow 84 sites all linked to each other not counting other outside sites that may link to them ... ever get the feeling the Internet is becoming a dangerous place?&lt;/p&gt;
&lt;p&gt;Ok ... let&amp;#39;s see what McAfee&amp;#39;s SiteAdvisor says : &amp;quot;&lt;a class="" href="http://www.siteadvisor.com/lookup/?q=voyeurcampic.com" target="_blank"&gt;No results found&lt;/a&gt;&amp;quot; even though that site was &lt;a class="" href="http://whois.domaintools.com/voyeurcampic.com" target="_blank"&gt;registered&lt;/a&gt; in July 07.&lt;br /&gt;How about &amp;quot;ExploitLabs LinkScanner&amp;quot; = &amp;quot;Congratulations! &lt;a class="" href="http://linkscanner.explabs.com/linkscanner/checkstep.asp" target="_blank"&gt;LinkScanner Online&lt;/a&gt; did not find any exploits.&amp;quot; ... ouch!&lt;/p&gt;
&lt;p&gt;Be careful out there folks ...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1136699" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Intercage_2F00_EstDomains/default.aspx">Intercage/EstDomains</category></item></channel></rss>