<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
 <channel>
  <title>Pharmacy Alert Security Team: Feedback</title>
  <link>http://pharmalert.zoomshare.com/5.shtml</link>
  <description>Pharmacy Alert Security Team: Feedback</description>
  <lastBuildDate>Sat, 06 Oct 2007 16:53:26 -0500</lastBuildDate>
  <item>
   <link>http://pharmalert.zoomshare.com/5.shtml/e5fa53d3c056485d2abadfe7b5d94d71_470802a1.writeback</link>
   <title>Comments please</title>
   <pubDate>Sat, 06 Oct 2007 16:48:17 -0500</pubDate>
   <description>&lt;a href=&quot;null&quot; target=&quot;_blank&quot;&gt;&lt;/a&gt; When a 
machine is hijacked as a &lt;ol&gt;&lt;li&gt;proxy web 
server&lt;li&gt;proxy image server&lt;li&gt;proxy name 
server&lt;/ol&gt; there is a degree of damage performed 
by the hijacker.
&lt;br&gt;&lt;br&gt;
This damage has become more severe over time. 
Functions removed may include&lt;ul&gt;
&lt;li&gt;chattr&lt;li&gt;lsattr&lt;li&gt;wget
&lt;li&gt;passwd&lt;li&gt;shutdown&lt;li&gt;shadowconfig&lt;li&gt;netstat
&lt;li&gt;lsof&lt;li&gt;reboot&lt;/ul&gt;
&lt;br&gt;&lt;br&gt;
This information varies with time. If you are 
recovering a hijacked machine, please provide 
your experiences here for others to share. 

Please comment on whether the information 
contained here was sufficient for your purposes, 
and suggest any additions.</description>
  </item>
  <item>
   <link>http://pharmalert.zoomshare.com/5.shtml/de331203d8dc8a3dc03d0a39b1bd9c2c_44fb9666.writeback</link>
   <title>Respond with your experiences and questions</title>
   <pubDate>Sun, 03 Sep 2006 21:58:46 -0500</pubDate>
   <description>If you received a Pharmacy Alert, you can respond
here with any questions and to share your
experiences in removing the trojan&lt;br&gt;&lt;br&gt;Thank 
you from the Pharmacy Alert Security Team</description>
  </item>
 </channel>
</rss>
