<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>max.lueb.be &#187; Random</title>
	<atom:link href="http://lueb.be/category/random/feed/" rel="self" type="application/rss+xml" />
	<link>http://lueb.be</link>
	<description>Thoughts on tech and other rants.</description>
	<lastBuildDate>Mon, 05 Apr 2010 17:00:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Who Hacked Homer Simpson?</title>
		<link>http://lueb.be/2008/07/09/who-hacked-homer-simpson/</link>
		<comments>http://lueb.be/2008/07/09/who-hacked-homer-simpson/#comments</comments>
		<pubDate>Wed, 09 Jul 2008 20:09:03 +0000</pubDate>
		<dc:creator>mluebbe</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Random]]></category>

		<guid isPermaLink="false">http://intentionallyobsolete.com/?p=32</guid>
		<description><![CDATA[In an old episode of the Simpsons, Homer reveals that his aol account is &#8216;Chunkylover53&#8242;. Someone has gained access to this account and has posted in the away message:  &#8217;﻿CHECK OUT THE NEW SIMPSONS EPISODE THAT WE&#8217;RE ONLY RELEASING TO THE INTERNET AIM FANS! BE THE FIRST TO EXPERIENCE THE MAGIC BY CLICKING THE FOLLOWING [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; width: 42px; padding-right: 10px; margin: 0 0 0 10px;">
		<script type="text/javascript">
		<!--
		digg_url = "http://lueb.be/2008/07/09/who-hacked-homer-simpson/";
		digg_bgcolor = "#FFFFFF";
		digg_skin = "";
		digg_window = "";
		digg_title = "Who+Hacked+Homer+Simpson%3F";
		digg_media = "news";
		digg_topic = "";
		digg_bodytext = "";
		//-->
		</script>
		<script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script></div><p>In an old episode of the Simpsons, Homer reveals that his aol account is &#8216;Chunkylover53&#8242;. Someone has gained access to this account and has posted in the away message:</p>
<blockquote><p> &#8217;﻿CHECK OUT THE NEW SIMPSONS EPISODE THAT WE&#8217;RE ONLY RELEASING TO THE INTERNET AIM FANS!  BE THE FIRST TO EXPERIENCE THE MAGIC BY CLICKING THE FOLLOWING LINK:  <a href="http://d4.myfreefilehosting.com/d2/kimya.exe"><font><font size="3">http://d4.myfreefilehosting.com</font></font></a></p>
<p><font size="3">SELECT RUN, (or RUN from current location) OR save to DESKTOP and DOUBLE CLICK!</font></p>
<p><font size="3">ENJOY, AND SEND US YOUR FEEDBACK!</font>&#8216;</p></blockquote>
<p>This link points towards a kimya.exe (hmm, why would a video file be a windows executable?) My virus scanner shows this to be the trojan Truko-431.</p>
<p>As I doubt Homer Simpson is the kind of guy looking to mess up my system with malware, I wonder what kind of jerk would want to hack him? As I would assume that Matt Groening or one of the other Simpsons cabal created this account, has someone compromised one of their systems?</p>
<p>UPDATE:</p>
<p>Whomever has access to this account is now posting the following away message, probably because the first one was too obvious.</p>
<blockquote><p>﻿<br />
<strong><font color="#ff0000"><font size="3">The link is now fixed everyone.</font></font><font size="3"></p>
<p>CHECK OUT THE NEW SIMPSONS EPISODE THAT WE&#8217;RE ONLY RELEASING TO THE INTERNET AIM FANS!  BE THE FIRST TO EXPERIENCE THE MAGIC BY CLICKING THE FOLLOWING LINK:  <a href="http://66.197.197.101/%7Eydelcom/Episode439.exe"><font>http://66.197.197.101/~ydelcom/Episode439.exe</font></a></p>
<p>SELECT RUN, (or RUN from current location) OR save to DESKTOP and DOUBLE CLICK!</p>
<p>If the hyperlink is unavailable to you, you can copy and paste it into your browser.</p>
<p>ENJOY, AND SEND US YOUR FEEDBACK!</font></strong></p></blockquote>
<p>I carefully downloaded this file, and it has an identical md5 hash as the originally posted kimya.exe. Are people really this stupid? Doing a whois on the ip address provided the email address abuse@hostnoc.net, and I&#8217;ve informed them about their service being used to spam trojan horses. So far exploration on this server hasn&#8217;t provided much of interest, but it&#8217;s still early.</p>
]]></content:encoded>
			<wfw:commentRss>http://lueb.be/2008/07/09/who-hacked-homer-simpson/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
