<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Who is thesource.ofallevil.com?</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=323" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=323</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: ecards</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-464</link>
		<dc:creator>ecards</dc:creator>
		<pubDate>Wed, 01 Oct 2008 19:15:06 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-464</guid>
		<description><![CDATA[Only problem is the Joke is getting a little stale.

With Google going nuts getting into everything like they are they might be the better joke for the next 6 years.
]]></description>
		<content:encoded><![CDATA[<p>Only problem is the Joke is getting a little stale.</p>
<p>With Google going nuts getting into everything like they are they might be the better joke for the next 6 years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spyware Free Removal</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-463</link>
		<dc:creator>Spyware Free Removal</dc:creator>
		<pubDate>Mon, 08 Sep 2008 19:33:11 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-463</guid>
		<description><![CDATA[What a set of scammers, that is bad, bad, bad!
]]></description>
		<content:encoded><![CDATA[<p>What a set of scammers, that is bad, bad, bad!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geekEleet</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-462</link>
		<dc:creator>geekEleet</dc:creator>
		<pubDate>Sat, 06 Sep 2008 20:34:02 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-462</guid>
		<description><![CDATA[This is the most perplexing thing I have seen on the web to-date.  Nobody has been able to solve the whole mystery.  6 years later, it&#039;s still being talked about.  Great post!
]]></description>
		<content:encoded><![CDATA[<p>This is the most perplexing thing I have seen on the web to-date.  Nobody has been able to solve the whole mystery.  6 years later, it&#8217;s still being talked about.  Great post!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anti-Free-Speecher</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-461</link>
		<dc:creator>Anti-Free-Speecher</dc:creator>
		<pubDate>Tue, 08 Apr 2008 17:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-461</guid>
		<description><![CDATA[Probably no legal ramifications in the United States.  Singapore, on the other hand ...
]]></description>
		<content:encoded><![CDATA[<p>Probably no legal ramifications in the United States.  Singapore, on the other hand &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: peace</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-460</link>
		<dc:creator>peace</dc:creator>
		<pubDate>Thu, 07 Feb 2008 07:45:12 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-460</guid>
		<description><![CDATA[good scam hehe
]]></description>
		<content:encoded><![CDATA[<p>good scam hehe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason Macpherson</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-459</link>
		<dc:creator>Jason Macpherson</dc:creator>
		<pubDate>Mon, 10 Sep 2007 13:49:33 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-459</guid>
		<description><![CDATA[I believe that Microsoft could block access to their site from those using the thesource.ofallevil.com.

HTTP 1.1 sends the site&#039;s name in the &quot;host&quot; field.  Apache (and probably IIS) can be configured to redirect anyone visiting via the evil DNS name.
]]></description>
		<content:encoded><![CDATA[<p>I believe that Microsoft could block access to their site from those using the thesource.ofallevil.com.</p>
<p>HTTP 1.1 sends the site&#8217;s name in the &#8220;host&#8221; field.  Apache (and probably IIS) can be configured to redirect anyone visiting via the evil DNS name.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-458</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 10 Sep 2007 09:44:22 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-458</guid>
		<description><![CDATA[IANAL, but the Mrs. is.

Her comments were that Internet libel case law was, for the most part, still a very new subj. for the courts.  It&#039;s not inconceivable that Microsoft could sue for libel, but they must _prove_ damages (the most difficult part of *any* libel case). And most of the time a large corporation is held to a higher standard of proof for showing damages.

My $.02 - It&#039;s much more likely that the bad press suing the owner of the domain name &gt; whatever damage it is currently causing.
]]></description>
		<content:encoded><![CDATA[<p>IANAL, but the Mrs. is.</p>
<p>Her comments were that Internet libel case law was, for the most part, still a very new subj. for the courts.  It&#8217;s not inconceivable that Microsoft could sue for libel, but they must _prove_ damages (the most difficult part of *any* libel case). And most of the time a large corporation is held to a higher standard of proof for showing damages.</p>
<p>My $.02 &#8211; It&#8217;s much more likely that the bad press suing the owner of the domain name > whatever damage it is currently causing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: googleboy</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-457</link>
		<dc:creator>googleboy</dc:creator>
		<pubDate>Thu, 26 Apr 2007 01:10:59 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-457</guid>
		<description><![CDATA[O, forgotten to mention: also theroot.ofallevil.com/ is existing, which is a duplicate of ... Verisign.

And: a site search in Google (site:ofallevil.com) is giving ... 113.000 pages living behind ofallevil.com. - And a normal Google to ofallevil.com is giving 217.000 pages: they are rather quoted by people who refer to it as real MS pages with solutions for problems...
]]></description>
		<content:encoded><![CDATA[<p>O, forgotten to mention: also theroot.ofallevil.com/ is existing, which is a duplicate of &#8230; Verisign.</p>
<p>And: a site search in Google (site:ofallevil.com) is giving &#8230; 113.000 pages living behind ofallevil.com. &#8211; And a normal Google to ofallevil.com is giving 217.000 pages: they are rather quoted by people who refer to it as real MS pages with solutions for problems&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: googleboy</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-456</link>
		<dc:creator>googleboy</dc:creator>
		<pubDate>Thu, 26 Apr 2007 00:34:42 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-456</guid>
		<description><![CDATA[As far as I can see, it&#039;s a website with duplicated MS copyrighted stuff. And partially redirecting to (stealing bandwith from) MS itself: in the pages some MS css and js files are used (see source code), for instance:
css.microsoft.com/library/toolbar/3.0/quicklinks/en-us/ql.css
img.microsoft.com/downloads/loc/en/main.css
js.microsoft.com/library/svy/broker.js

I&#039;m not technical enough to analyze what is happening if the &quot;Validation Required&quot; button &quot;Continue&quot; is clicked (sending personal pc data to ofallevil.com?). They say: &quot;As described in our privacy statement, Microsoft will not use the information collected during validation to identify or contact you.&quot; - That will be correct, if the data are harvested by ofallevil.com and used by ofallevil.com and partners! Phishing?

I&#039;ve the same lack of technical know-how about what will be downloaded (didn&#039;t try!): maybe not the original MS files, but spyware / malware alternatives?

Anyway, I found that the IP Address: 69.64.38.157 (see www.who.is/whois-com/ip-address/ofallevil.com/ ) is the same IP used for 38 other websites / domain names (!); (see www.seologs.com/ip-domains.html ).

The others are commercial sites, so I guess it&#039;s not a joke, but at least a Search Engine Optimization trick.

PS:
I Googled the ofallevil page by searching for info about &quot;activate.exe&quot;, one of the downloading files. According to Spyware.net (www.fbmsoftware.com/spyware-net/Process/Activate_exe/3001/) that file is or can be a Trojan.
]]></description>
		<content:encoded><![CDATA[<p>As far as I can see, it&#8217;s a website with duplicated MS copyrighted stuff. And partially redirecting to (stealing bandwith from) MS itself: in the pages some MS css and js files are used (see source code), for instance:<br />
css.microsoft.com/library/toolbar/3.0/quicklinks/en-us/ql.css<br />
img.microsoft.com/downloads/loc/en/main.css<br />
js.microsoft.com/library/svy/broker.js</p>
<p>I&#8217;m not technical enough to analyze what is happening if the &#8220;Validation Required&#8221; button &#8220;Continue&#8221; is clicked (sending personal pc data to ofallevil.com?). They say: &#8220;As described in our privacy statement, Microsoft will not use the information collected during validation to identify or contact you.&#8221; &#8211; That will be correct, if the data are harvested by ofallevil.com and used by ofallevil.com and partners! Phishing?</p>
<p>I&#8217;ve the same lack of technical know-how about what will be downloaded (didn&#8217;t try!): maybe not the original MS files, but spyware / malware alternatives?</p>
<p>Anyway, I found that the IP Address: 69.64.38.157 (see <a href="http://www.who.is/whois-com/ip-address/ofallevil.com/" rel="nofollow">http://www.who.is/whois-com/ip-address/ofallevil.com/</a> ) is the same IP used for 38 other websites / domain names (!); (see <a href="http://www.seologs.com/ip-domains.html" rel="nofollow">http://www.seologs.com/ip-domains.html</a> ).</p>
<p>The others are commercial sites, so I guess it&#8217;s not a joke, but at least a Search Engine Optimization trick.</p>
<p>PS:<br />
I Googled the ofallevil page by searching for info about &#8220;activate.exe&#8221;, one of the downloading files. According to Spyware.net (www.fbmsoftware.com/spyware-net/Process/Activate_exe/3001/) that file is or can be a Trojan.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=323&#038;cpage=1#comment-455</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Sun, 25 Mar 2007 22:13:43 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=323#comment-455</guid>
		<description><![CDATA[@Thomas - Good point. I am not sure what legal action, but a simple lawsuit for some type of fraud might at least unmask the joker.

My initial reaction is that it *is* different from the items you mentioned, but you may be right - I&#039;ll have to think about it some more.
]]></description>
		<content:encoded><![CDATA[<p>@Thomas &#8211; Good point. I am not sure what legal action, but a simple lawsuit for some type of fraud might at least unmask the joker.</p>
<p>My initial reaction is that it *is* different from the items you mentioned, but you may be right &#8211; I&#8217;ll have to think about it some more.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
