<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PHP User-Group Philippines &#187; aj</title>
	<atom:link href="http://www.phpugph.com/blog/author/ajbatac/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.phpugph.com/blog</link>
	<description></description>
	<lastBuildDate>Wed, 23 Dec 2009 04:00:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Update: PHPUGPH&#8217;s SMF maliciously attacked. Now back online</title>
		<link>http://www.phpugph.com/blog/2009/06/24/update-phpugphs-smf-maliciously-attacked-now-back-online/</link>
		<comments>http://www.phpugph.com/blog/2009/06/24/update-phpugphs-smf-maliciously-attacked-now-back-online/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 15:33:46 +0000</pubDate>
		<dc:creator>aj</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[krisbarteo]]></category>
		<category><![CDATA[phpugph]]></category>
		<category><![CDATA[smf]]></category>

		<guid isPermaLink="false">http://www.phpugph.com/blog/?p=49</guid>
		<description><![CDATA[I&#8217;ve done an audit on the files of phpugph.com&#8217;s SMF board and found that a certain user who&#8217;s only identity is krisbarteo@gmail.com using the IP 94.142.129.147 appended spam links to the Settings.php of SMF.
I&#8217;m no security expert, but I think what he did was he uploaded an avatar with a PHP code inside it, found [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve done an audit on the files of phpugph.com&#8217;s SMF board and found that a certain user who&#8217;s only identity is krisbarteo@gmail.com using the IP <a href="http://www.stopforumspam.com/ipcheck/94.142.129.147">94.142.129.147</a> appended spam links to the Settings.php of SMF.</p>
<p>I&#8217;m no security expert, but I think what he did was he uploaded an avatar with a PHP code inside it, found a server/script exploit and ran it. I opened up the avatar (after looking for it for hours) and found this code (see below screenshot). Then he launched the attack from there appending malicious links on a file that is being included everytime SMF draws a page.</p>
<p><img class="alignnone" title="1" src="http://www.phpugph.com/blog/wp-content/uploads/2009/06/1.jpg" alt="" width="400" height="246" /></p>
<p><img class="alignnone" title="2" src="http://www.phpugph.com/blog/wp-content/uploads/2009/06/2.jpg" alt="" width="400" height="98" /></p>
<p>A quick Diff on SMF&#8217;s base files and our SMF files revealed that a new readme.php was created. And it contained the following:</p>
<p><img class="alignnone" title="3" src="http://www.phpugph.com/blog/wp-content/uploads/2009/06/3.jpg" alt="" width="400" height="299" /></p>
<p>Decoding that garbled texts reveals that readme.php was run on the browser and that was the main cause of appending links on the Settings.php.</p>
<p>I am still baffled by the fact that some people would do such things. Disrupt service for profit? Well, as for  krisbarteo, yes you&#8217;ve succeeded in doing that. Then what? Happy now? If you only have used that smarts and skills on the good stuff, you&#8217;d probably be rich by now.</p>
<p>To all PHPugers, we hope that this thing doesn&#8217;t happen again even if we all know that the Internet isn&#8217;t safe from these crackers. It&#8217;s all good. For now.</p>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.phpugph.com%2Fblog%2F2009%2F06%2F24%2Fupdate-phpugphs-smf-maliciously-attacked-now-back-online%2F&amp;layout=standard&amp;show-faces=true&amp;width=450&amp;action=like&amp;font=arial&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:auto;"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.phpugph.com/blog/2009/06/24/update-phpugphs-smf-maliciously-attacked-now-back-online/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Mployd.ph Offers PHPUGPH Members 1-Year Free Subscription</title>
		<link>http://www.phpugph.com/blog/2008/10/17/mploydph-offers-phpugph-members-1-year-free-subscription/</link>
		<comments>http://www.phpugph.com/blog/2008/10/17/mploydph-offers-phpugph-members-1-year-free-subscription/#comments</comments>
		<pubDate>Fri, 17 Oct 2008 03:51:03 +0000</pubDate>
		<dc:creator>aj</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[mployd]]></category>
		<category><![CDATA[offer]]></category>
		<category><![CDATA[phpugph]]></category>

		<guid isPermaLink="false">http://www.phpugph.com/blog/?p=47</guid>
		<description><![CDATA[If you are a member of PHPUGph.com, you are entitled to a 1 year free account subscription at Mployd.ph. The account subscription is worth Php 10,000 approx. ($250).
Login to PHPUGPH now and grab the exclusive promo code. Hurry! This offer expires October 31, 2008 is extended till the end of the year!
]]></description>
			<content:encoded><![CDATA[<p>If you are a member of <a href="http://phpugph.com">PHPUGph.com</a>, you are entitled to a 1 year free account subscription at <a href="http://mployd.ph">Mployd.ph</a>. The account subscription is worth Php 10,000 approx. ($250).</p>
<p><a href="http://phpugph.com/talk">Login to PHPUGPH now</a> and grab the exclusive promo code. Hurry! This offer expires <span style="text-decoration: line-through;">October 31, 2008</span> is extended till the end of the year!</p>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.phpugph.com%2Fblog%2F2008%2F10%2F17%2Fmploydph-offers-phpugph-members-1-year-free-subscription%2F&amp;layout=standard&amp;show-faces=true&amp;width=450&amp;action=like&amp;font=arial&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:auto;"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.phpugph.com/blog/2008/10/17/mploydph-offers-phpugph-members-1-year-free-subscription/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Globe Innovation Convention: Globe Labs Launch &#8211; &#8220;Enriching lives through Innovative Communications&#8221;</title>
		<link>http://www.phpugph.com/blog/2008/07/23/globe-innovation-convention-globe-labs-launch-enriching-lives-through-innovative-communications/</link>
		<comments>http://www.phpugph.com/blog/2008/07/23/globe-innovation-convention-globe-labs-launch-enriching-lives-through-innovative-communications/#comments</comments>
		<pubDate>Wed, 23 Jul 2008 02:46:05 +0000</pubDate>
		<dc:creator>aj</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[globe labs]]></category>
		<category><![CDATA[phpugph]]></category>

		<guid isPermaLink="false">http://www.phpugph.com/blog/?p=45</guid>
		<description><![CDATA[Spreading the news
Date: August 7, 2008 (Thursday)
Time: 7:30 AM &#8211; 5:00 PM
Venue: Isla Ballroom, Tower Wing, EDSA Shangrila
Globe Labs is a new organization within Globe Telecom whose mission is to help bring in the newest future technology services at the earliest market-relevant time. We explore new and future technologies, and partner with developers to create [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Spreading the news</strong></p>
<p><strong>Date: </strong>August 7, 2008 (Thursday)<br />
<strong>Time: </strong>7:30 AM &#8211; 5:00 PM<br />
<strong>Venue:</strong> Isla Ballroom, Tower Wing, EDSA Shangrila</p>
<p><a href="http://www.globelabs.com.ph/">Globe Labs</a> is a new organization within Globe Telecom whose mission is to help bring in the newest future technology services at the earliest market-relevant time. We explore new and future technologies, and partner with developers to create new Internet, wired and wireless applications.</p>
<p><em>What Globe have in store for you: Learn, Build, Compete and Succeed</em></p>
<ul>
<li>Discover the different opportunities with Globe Labs</li>
<li>Learn how to use Telco tools and various development platforms to build innovative applications</li>
<li>Join the Globe Labs Challenge and compete amongst the best</li>
</ul>
<p><a href="http://phpugph.com/">PHP User Group Philippines, Inc.</a>, being one of the institution partners of Globe Labs, has been given 200 SLOTS for this upcoming big event.</p>
<p>We are inviting PHPUGPH members to attend. T-SHIRTS designed for PHPUGPH would be given away as freebies plus exciting raffle prizes awaits you…</p>
<p><em>***FIRST 300 individual registrants gets a GIFT***</em></p>
<p><strong>Below are some links of articles regarding the event:</strong><br />
From Businessworld (Entreprenews)<br />
<a href="http://entreprenews.com.ph/main.php?id=062508.gonzalez">http://entreprenews.com.p…in.php?id=062508.gonzalez</a><br />
From the Inquirer:<br />
<a href="http://technology.inquirer.net/infotech/infotech/view/20080625-144726/Globe-Labs-targets-3G-mobile-developers">http://technology.inquire…gets-3G-mobile-developers</a><br />
From the Manila Times:<br />
<a href="http://www.manilatimes.net/national/2008/june/27/yehey/techtimes/20080627tech5.html">http://www.manilatimes.ne…htimes/20080627tech5.html</a><br />
From Manila Bulletin:<br />
<a href="http://www.mb.com.ph/INFO20080627128372.html">http://www.mb.com.ph/INFO20080627128372.html</a><br />
From PCWorld:<br />
<a href="http://www.pcworld.com.ph/?_s=7&amp;_ss=P&amp;P=3&amp;PN=7313&amp;L=H&amp;II=485&amp;ID=H,485,PWP,PWP-16">http://www.pcworld.com.ph…5&amp;ID=H,485,PWP,PWP-16</a><br />
From Yugatech:<br />
<a href="http://www.yugatech.com/blog/telecoms/gt-opens-globe-labs-division/">http://www.yugatech.com/b…pens-globe-labs-division/</a><br />
From Globe Labs website:<br />
<a href="http://www.globelabs.com..../News/Forms/AllItems.aspx">http://www.globelabs.com…./News/Forms/AllItems.aspx</a></p>
<p><a href="../../talk/index.php/topic,5998.msg49415.html#msg49415">More information here</a></p>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.phpugph.com%2Fblog%2F2008%2F07%2F23%2Fglobe-innovation-convention-globe-labs-launch-enriching-lives-through-innovative-communications%2F&amp;layout=standard&amp;show-faces=true&amp;width=450&amp;action=like&amp;font=arial&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:auto;"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.phpugph.com/blog/2008/07/23/globe-innovation-convention-globe-labs-launch-enriching-lives-through-innovative-communications/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Top 25 Active PHPUGPH Users</title>
		<link>http://www.phpugph.com/blog/2008/07/08/top-25-active-phpugph-users/</link>
		<comments>http://www.phpugph.com/blog/2008/07/08/top-25-active-phpugph-users/#comments</comments>
		<pubDate>Tue, 08 Jul 2008 03:25:03 +0000</pubDate>
		<dc:creator>aj</dc:creator>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[top25]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://www.phpugph.com/blog/?p=44</guid>
		<description><![CDATA[Here are the top 25 active PHPUGPH users

]]></description>
			<content:encoded><![CDATA[<p>Here are the top 25 active PHPUGPH users</p>
<p><a href="http://wordle.net/gallery/wrdl/57017/PHPUGPH.com%27s_Top_25_Active_Users"><img class="alignnone" src="http://phpugph.com/blog/wp-content/uploads/2008/07/top25.jpg" alt="" /></a></p>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.phpugph.com%2Fblog%2F2008%2F07%2F08%2Ftop-25-active-phpugph-users%2F&amp;layout=standard&amp;show-faces=true&amp;width=450&amp;action=like&amp;font=arial&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:auto;"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.phpugph.com/blog/2008/07/08/top-25-active-phpugph-users/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Scrawlr: Crawls your website for SQL Injection</title>
		<link>http://www.phpugph.com/blog/2008/07/03/scrawlr-crawls-your-website-for-sql-injection/</link>
		<comments>http://www.phpugph.com/blog/2008/07/03/scrawlr-crawls-your-website-for-sql-injection/#comments</comments>
		<pubDate>Thu, 03 Jul 2008 03:16:34 +0000</pubDate>
		<dc:creator>aj</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Beginner]]></category>
		<category><![CDATA[Intermediate]]></category>
		<category><![CDATA[Software Review]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[parameters]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[web applications]]></category>

		<guid isPermaLink="false">http://www.phpugph.com/blog/?p=43</guid>
		<description><![CDATA[
Scrawlr, short for SQL Injector and Crawler will crawl your website and will analyze the parameters of each individual pages for SQL injection vulnerabilities. Very useful tool for small to medium sized websites. Free for the first 1,500 pages.
From HPs website:
Technical details for Scrawlr

Identify Verbose SQL Injection vulnerabilities in URL parameters
Can be configured to use [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx?jumpid=reg_R1002_USEN"><img src="https://download.spidynamics.com/Products/scrawlr/scrawler-screenshot.png" alt="" width="400" height="272" /></a></p>
<p><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx?jumpid=reg_R1002_USEN">Scrawlr</a>, short for SQL Injector and Crawler will crawl your website and will analyze the parameters of each individual pages for SQL injection vulnerabilities. Very useful tool for small to medium sized websites. Free for the first 1,500 pages.</p>
<p>From HPs website:</p>
<blockquote><p><em>Technical details for Scrawlr</em></p>
<ul>
<li><em>Identify Verbose SQL Injection vulnerabilities in URL parameters</em></li>
<li><em>Can be configured to use a Proxy to access the web site</em></li>
<li><em>Will identify the type of SQL server in use</em></li>
<li><em>Will extract table names (verbose only) to guarantee no false positives</em></li>
</ul>
<p><em>Scrawlr does have some limitations versus our professional solutions and our fully functional SQL Injector tool<br />
</em></p>
<ul>
<li><em>Will only crawls up to 1500 pages</em></li>
<li><em>Does not support sites requiring authentication</em></li>
<li><em>Does not perform Blind SQL injection</em></li>
<li><em>Cannot retrieve database contents</em></li>
<li><em>Does not support JavaScript or flash parsing</em></li>
<li><em>Will not test forms for SQL Injection (POST Parameters)</em></li>
</ul>
</blockquote>
<p><a href="https://download.spidynamics.com/Products/scrawlr/">It&#8217;s worth trying out.</a></p>
<p>&#8211;aj</p>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.phpugph.com%2Fblog%2F2008%2F07%2F03%2Fscrawlr-crawls-your-website-for-sql-injection%2F&amp;layout=standard&amp;show-faces=true&amp;width=450&amp;action=like&amp;font=arial&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:auto;"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.phpugph.com/blog/2008/07/03/scrawlr-crawls-your-website-for-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
