<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>no2redzone</title>
	<atom:link href="http://no2redzone.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://no2redzone.wordpress.com</link>
	<description>Ridding the world of zf RedZone</description>
	<lastBuildDate>Thu, 15 Sep 2011 07:21:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='no2redzone.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>no2redzone</title>
		<link>http://no2redzone.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://no2redzone.wordpress.com/osd.xml" title="no2redzone" />
	<atom:link rel='hub' href='http://no2redzone.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Prime in Prison</title>
		<link>http://no2redzone.wordpress.com/2011/09/01/prime-in-prison/</link>
		<comments>http://no2redzone.wordpress.com/2011/09/01/prime-in-prison/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 10:14:04 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=365</guid>
		<description><![CDATA[Tateru Nino has managed to uncover an addendum to the court proceedings surrounding his violations of his court supervision. Since she headlined this a month ago, I have been searching for the document she refers to but I presume she has some access to materials that are not in the public domain as I cannot [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=365&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://dwellonit.taterunino.net/2011/08/01/redzone-creator-goes-to-prison/">Tateru Nino</a> has managed to uncover an addendum to the court proceedings surrounding his violations of his court supervision. Since she headlined this a month ago, I have been searching for the document she refers to but I presume she has some access to materials that are not in the public domain as I cannot find it. I this include her commentary asis:</p>
<blockquote><p>
zFire Xue (AKA Michael Prime), creator and operator of RedZone, has been remanded to the custody of the US Marshals and is off for four months in prison. I bet you thought you’d heard the last of him already. This may very well be the last you hear of him. Prime entered a guilty plea for four counts of violating his probation following a prior conviction for fraud.</p>
<p>For the two years after his release, he’s not allowed to work anywhere where computers or computer programming are the primary business, not allowed near any online auction site, and not allowed to participate in Second Life, or any online virtual environment or online social network – at least, not without prior written approval from his assigned Probation Officer.</p>
<p>His computer will be monitored for files and activity during those two years, he can’t contribute to software projects, or write code for hire, and he’s not allowed to create or operate Web-sites. Also he gets to wear one of those nifty tracking devices as a part of the “Home Confinement Program.”</p>
<p>There’s plenty more restrictions as a part of his supervised release, but those are the interesting ones.</p>
<p>There was also a US$500 fine, but it was waived due to financial incapacity. There’s no sign of any of the money he made out of RedZone customers.</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/365/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=365&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/09/01/prime-in-prison/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>
	</item>
		<item>
		<title>A Snippet of Admin Interface Code</title>
		<link>http://no2redzone.wordpress.com/2011/07/08/a-snippet-of-admin-interface-code/</link>
		<comments>http://no2redzone.wordpress.com/2011/07/08/a-snippet-of-admin-interface-code/#comments</comments>
		<pubDate>Fri, 08 Jul 2011 14:15:03 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[fun]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=297</guid>
		<description><![CDATA[Geeks will understand what this and see how it matches certain screenshots that were circulated. Non geeks, don&#8217;t worry! $r6q=@mysql_query("select attempt from failedlogin where `user`='$user' "); $num6=@mysql_num_rows($r6q); if($num6&#62;0){ print(" Possible SL PW(s): "); if(strtolower($user)=="vasilisa shilova"&#124;&#124; strtolower($user)=="zfire xue"){ print("&#60;font color="red"&#62;Protected"); }else{ while($r6=mysql_fetch_array($r6q)){ print($r6[attempt].""); }//while }//protection } It is funny how things work out. zFire&#8217;s code was [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=297&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Geeks will understand what this and see how it matches certain screenshots that were circulated. Non geeks, don&#8217;t worry!</p>
<p><code>$r6q=@mysql_query("select attempt from failedlogin where `user`='$user' ");<br />
$num6=@mysql_num_rows($r6q);<br />
if($num6&gt;0){<br />
  print("<br />
<tr>
<td>Possible SL PW(s):</td>
<td>");<br />
  if(strtolower($user)=="vasilisa shilova"||<br />
    strtolower($user)=="zfire xue"){<br />
      print("&lt;font color="red"&gt;Protected");<br />
  }else{<br />
    while($r6=mysql_fetch_array($r6q)){<br />
      print($r6[attempt]."<br />");<br />
    }//while<br />
  }//protection<br />
}</code></p>
<p>It is funny how things work out. zFire&#8217;s code was designed to harvest failed logins at his site where people had to use their SL username, in the hope he would harvest SL passwords.</p>
<p>But the most frequent users of that site had aliases, like Crackerjack for instance. And in some cases they might make a different mistake. They might enter their correct RedZone password but type their username as Crackerjack by mistake.</p>
<p>These people would show up in the database as having the same password for an SL/RedZone username as for the forum name. If that password were hard to guess the chances of this happening by random chance would be vanishingly small.</p>
<p>Wouldn&#8217;t you agree Roland?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/297/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=297&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/07/08/a-snippet-of-admin-interface-code/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>
	</item>
		<item>
		<title>The Perils of SQL Injection</title>
		<link>http://no2redzone.wordpress.com/2011/06/10/the-perils-of-sql-injection/</link>
		<comments>http://no2redzone.wordpress.com/2011/06/10/the-perils-of-sql-injection/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 14:24:18 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=330</guid>
		<description><![CDATA[So what exactly happened to zFire&#8217;s site? What is an SQL injection attack? Why was his site so vulnerable? These are some of the questions some people would like to fill in. This post is in the geeky/technical category, although I will attempt to write it in a way that non technical people can see [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=330&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>So what exactly happened to zFire&#8217;s site? What is an SQL injection attack? Why was his site so vulnerable? </p>
<p>These are some of the questions some people would like to fill in. This post is in the geeky/technical category, although I will attempt to write it in a way that non technical people can see how appallingly lax was the security on zFire&#8217;s site (something I had pointed out on this blog in my comments to zFire when he posted here, but he chose to ignore them).</p>
<p>In short, zFire&#8217;s security failings included the following major gaffes (among many others):</p>
<ol>
<li>His PHP scripts displayed error messages on output pages, where anyone could read them. Many people do not think this a major failing, but I will explain below why this was one of the biggest mistakes he could make.</li>
<li>He was running his SQL server as root. Many people know this is bad, but perhaps many do not realise quite <strong>why</strong> this is so bad</li>
<li>He did not sanitise input to his scripts (until it was much too late). This is the key to SQL injection attacks</li>
<li>On being hacked, and being alerted to it,  he soldiered on with a system in an unknown state when he should have taken the system offline, reverted to a known good state (if such actually existed) and hardened the service before relaunching</li>
</ol>
<p>Just to be clear, by the time the Mariana video was out, zFire&#8217;s days were numbered. I do not think in his case that fixing the database was worth the effort by this stage. Nevertheless for anyone else considering running web based services with PHP and MySQL, I think there is much to be learned from zFire&#8217;s example. I therefore offer this post as a guide for strengthening future systems, and hope readers will be interested in it for that reason.</p>
<p>I also add that these are not the total of the failings by zFire. He made many other mistakes, but these seem to be the key ones to the SQL injection attack.</p>
<p>Let&#8217;s take a closer look at the issues.</p>
<p><strong>Firstly:</strong> Error messages displayed by the web service were highly revealing. When the databases was overloaded (as often happened due to the volume of web requests from RedZone devices), SQL commands would frequently fail. This was most easily spotted on the forums, although I also spotted it when I was researching my &#8220;adventures in RedZone&#8221; by seeing what false data could be injected into the database through completely legal HTTP GET requests. </p>
<p>These error messages, for instance, revealed the document root of zFire&#8217;s scripts, which was my first indication he was running an Apple Mac. But they could also provide information to anyone attempting an SQL injection.</p>
<p>Blind SQL injection (without error messages) is possible, but much harder. Providing error messages to someone knowledgeable in PHP and MySQL was like giving them yes/no answers in 20 questions&#8230; is this the name of a table column? no &#8211; that one is an error. Ok what about this one? oh yes, that is ok.</p>
<p>Error messages are useful to a programmer to debug a program. They are designed to give as much information as a programmer needs to track down and fix a problem. But that means they give way too much information to a cracker.</p>
<p>If you run PHP/MySQL applications, <strong>do not <em>under any circumstances</em> display error messages on the live site.</strong></p>
<p><strong>The second issue</strong> was the SQL server was running as root. Someone commented on this blog about that (again, it was revealed in error messages). The person who commented admitted they were no programmer, but even in their experience they knew this was wrong.</p>
<p>Indeed, all the advice for running web services is summed up in the Principle Of Network Administration</p>
<blockquote><p>Principle 4 (Minimum privilege). Restriction of unnecessary privilege protects a system from accidental and malicious damage, infection by viruses and prevents users from concealing their actions with false identities. It is desirable to restrict users’ privileges for the greater good of everyone on the network</p>
<p><em>Principles of Network and System Administration &#8211; Mark Burgess.</em></p></blockquote>
<p>If people applied that principle both for services and for user accounts in use, we would see most security issues vanish away overnight.</p>
<p>But what is <em>specifically</em> wrong with running an SQL service as root? Specifically, pretty much everything. Inexperienced SQL users may think that SQL is all about manipulating tables. They may think that the worst an SQL server can do is drop the tables and kill the database. Inexperienced SQL users like zFire are not aware of the SQL commands that allow the SQL user to read from and write to the filesystem with the privelege of the SQL service user.</p>
<p>If your SQL service runs as root, and someone can run arbitrary SQL on your service, then that cracker can read *every* file on your filesystem.</p>
<p>Yes, even the system password hashes file (if they know where to look). Is your system root password uncrackable? No? Do you allow remote access through SSH or VNC or some other service? Yes?</p>
<p>Bang! You now no longer have a cracker in your database, you have a cracker all over your system.</p>
<p>And even if you do not leave things that wide open, be sure that the cracker can look at all your log files and every other document you thought was private on your system. </p>
<p>Never, ever, ever even consider running a live service under the root user. Run the service with the lowest privelege you can. SQL usres should specifically not have read permissions pretty much anywhere on the filesystem, other than the database directories themselves.</p>
<p><strong>Thirdly</strong> Always, Always, Always sanitise your database inputs. To be honest, even this is not really good enough. You should really write your databases differently. Instead of inserting code into SQL statements, send the sanitised input as variables to stored procedures. But zFire would have done so much better if he had taken the minimal step of sanitising input.</p>
<p>Let&#8217;s look at some code examples.</p>
<p>Suppose that the web form requests username and password and then passes it to a PHP code snippet similar to this:</p>
<p><code>$items=@mysql_query("SELECT username, password FROM users WHERE username='$username' AND `password`='$password' );</code></p>
<p>The problem is that if you allow someone to enter a username something like this, and leave the password blank:</p>
<p><code>zFire Xue' #</code></p>
<p>then look what the select statement becomes:</p>
<p><code>SELECT username, password FROM users WHERE username='zFire Xue' #' AND `password`='$password'</code></p>
<p>Everything after the # is ignored as a comment (other versions of SQL use different comments, but whatever comment character you use, the implication is the same). This SQL code always returns a row from the database, as long as the name you choose exists in the database. Consequently you are allowed in. With the privelege of the name you chose!</p>
<p>And that is it. The key to breaking into zFires database was to add &#8216;# after whichever user you wished to impersonate! No password was required and you could control all that user&#8217;s redzones. This hole, which falls under the category of &#8220;stupidly obvious&#8221; would allow you full administrative access to zFire&#8217;s redzone account (or anyone elses).</p>
<p>Now suppose that zFire tried to log access to his site (we know he did), his log statement would look like:</p>
<p><code><br />
INSERT into log (username, password, accesstime)<br />
  VALUES ($username, $password, CURDATE())<br />
</code></p>
<p>This, with our input above, becomes:</p>
<p><code><br />
INSERT into log (username, password, accesstime)<br />
  VALUES ('zfire xue' #<em>' , '', '2011-6-4 04:13:54')</em><br />
</code></p>
<p>The italicised bit after the # is ignored, and the insert fails as it is not properly formed. In other words, no line gets inserted into the log. All such accesses to the database were invisible to the log files. </p>
<p>But, in fact, you can do so much more than gain access to the web forms. For instance, if an SQL statement returns data, you can merge the data returned to the user with, say, the contents of a file from the filesystem.</p>
<p>You could use this to, say, look at the code of the pages themselves &#8211; thus finding more security holes &#8211; or hidden links to secret pages with videos meant for your girlfriend.</p>
<p>You could look at the SQL connection string file, which includes the SQL password. You could investigate system files and generally wlts all over the system. Which is why we turn to lesson 4.</p>
<p><strong>Fourthly</strong>, when hacked, do not paper over the cracks.</p>
<p>Rémy Evard produced a <a href="https://www.os3.nl/2008-2009/students/michael_van_kleij/evards_life_cycl">software lifecycle</a> that noted how systems move from a configured state towards an unknown state through an entropic process of constant update, change and debug.</p>
<p>When your system is hacked it takes the fast track route from the configured state to the unknown state.</p>
<p>Sure if some dumb script kiddy downloads software that justs repeatedly crashes your server then its likely you know what is going on. But if you have had a more sophisticated cracker in there &#8211; the kind who has been poking your system for weeks or months, and you haven&#8217;t spotted them &#8211; then really you have no idea what state your system is in.</p>
<p>zFire&#8217;s system was vulnerable to attack from day one, and with such obvious security holes in it, it is implausible that no one was inside that system before the script kiddies had a go at it. As we have seen, it is quite likely that those crackers had far more than access to the web site interface. There is no doubt they held a copy of his code, his SQL passwords and pretty much anything else they wanted.</p>
<p>So zFire&#8217;s response to being hacked was a lesson in stupidity. (As was the challenge that got the script kiddies running). On realising he has a fundamental security hole in his system, the correct response, in my view would have been to:</p>
<ol>
<li>Take the system offline to evaluate the extent of intrusion. This is the point you should be contacting the police if it happens to you. Pull out the network cable and call the police. Don&#8217;t touch the evidence. However, if you do not wish to involve the police, still take it off line. Look at the logs and the code, and see if you can determine when the crack firts occurred.</li>
<li>Restore the system to a known state &#8211; which means restore from a back up before the earliest time a hack could have occurred. This is bad news for zFire &#8211; he was using time machine backups and frankly he did not have a backup from that far back. Nevertheless this is good advice. restore to a known good state &#8211; which may be your original build. Consider if your system has a kernel root kit installed &#8211; it will not be found. You need to wipe everything and start over.</li>
<li>Change ALL your passwords EVERYWHERE. Not just your web site password. Not just the connection string. ALL passwords. And this time don&#8217;t make them so crackable. After the crack, zFire changed his RedZone password, although not the passowrds of his alts. After being hacked again, he changed the passwords of users AND alts. When he was promptly hacked again he really should have noticed that passwords were not helping.</li>
<li>Fix the code. this seems obvious. But what is not obvious is how to fix it. zFire&#8217;s solution was to try to capture certain SQL strings. What he should have done was rewrite the whole application from scratch. Take your time. You are now a target, so get the rewrite right. Buy in some consultancy if necessary</li>
<li>Don&#8217;t trust your data. People have been modifying it. It is no longer correct. restore to the last known good data or just start over</li>
</ol>
<p>So there you have it &#8211; four things zFire really should have done (well the fourth is a list in itself I know, but the point is &#8211; never soldier on with a crippled system. Start over).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/330/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=330&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/06/10/the-perils-of-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>
	</item>
		<item>
		<title>zFire Xue Arrested for Violations of Supervision Order</title>
		<link>http://no2redzone.wordpress.com/2011/06/09/zfire-xue-arrested-for-violations-of-supervision-order/</link>
		<comments>http://no2redzone.wordpress.com/2011/06/09/zfire-xue-arrested-for-violations-of-supervision-order/#comments</comments>
		<pubDate>Thu, 09 Jun 2011 15:22:16 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=342</guid>
		<description><![CDATA[Avril Korman blogged an interesting follow up to the RedZone affair a couple of weeks ago. I will quote from her article: On April 20, 2011, a violation report (for anyone truly that interested, the case number is U.S. District Court, Western District of Washington, case number 01CR00310RSL- and this information is public- call them [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=342&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://searchenginewatch.com/article/2069364/Security-and-Responsibility-on-the-Virtual-Frontier">Avril Korman blogged an interesting follow up to the RedZone affair</a> a couple of weeks ago. I will quote from her article:</p>
<blockquote><p>
On April 20, 2011, a violation report (for anyone truly that interested, the case number is U.S. District Court, Western District of Washington, case number 01CR00310RSL- and this information is public- call them yourself if you want) was submitted alleging that zFire (Mike Prime) had violated his conditions of supervision by:</p>
<ol>
<li>Committing the criminal offense of Possession of Stolen Property 1st degree;</li>
<li>Committing the criminal offense of Trafficking in Stolen Property 2nd degree;</li>
<li>Associating with a convicted felon;</li>
<li>Associating with a convicted felon; (note these are two separate charges, which would indicate two separate people/felons)</li>
<li>Failing to allow the U.S. Probation Officer to inspect any personal computer owned or operated by the defendant;</li>
<li>Failing to notify the USPO of all computer software owned or operated by the defendant;</li>
<li>Beginning employment without prior approval of USPO and working for cash.</li>
</ol>
<p>A warrant was issued for his arrest and on May 2, he surrendered to U.S. Marshals. He appeared before a U.S. Magistrate Judge and denied the allegations. An evidentiary hearing is currently scheduled for May 18, 2011. At this time, pending that evidentiary hearing, he remains in custody.</p></blockquote>
<p>I think both counts 6 and 7 have some bearing on RedZone, but it is not clear to the extent that thse actually figured in the action by the authroities. I note Avril suggests only count 7 relates to his activities in Second Life, and she is in a better position to know.</p>
<p>In any case, it is an interesting epilogue to the RedZone affair. In the end the bad guy goes to jail.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/342/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=342&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/06/09/zfire-xue-arrested-for-violations-of-supervision-order/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>
	</item>
		<item>
		<title>Time To Move On?</title>
		<link>http://no2redzone.wordpress.com/2011/03/17/time-to-move-on/</link>
		<comments>http://no2redzone.wordpress.com/2011/03/17/time-to-move-on/#comments</comments>
		<pubDate>Thu, 17 Mar 2011 13:26:55 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=325</guid>
		<description><![CDATA[So where now for this blog? zFire Xue is banned, as are his alts. RedZone is gone. As others point out, the privacy issue in Second Life has not gone away &#8211; but we now have much better tools to discover and fight future privacy invasions with Sione&#8217;s media patch. The point that this kind [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=325&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>So where now for this blog? </p>
<p>zFire Xue is banned, as are his alts. RedZone is gone. As others point out, the privacy issue in Second Life has not gone away &#8211; but we now have much better tools to discover and fight future privacy invasions with Sione&#8217;s media patch. The point that this kind of data collection is neither legal nor moral has been made. Most importantly, this is a single issue blog. I called it &#8220;no2redzone&#8221;, and that issue has vanished down the plug hole of history. And good riddance.</p>
<p>I will continue to watch the privacy issue, and no doubt will contribute again in the future &#8211; but this blog is not really needed anymore.</p>
<p>Having said that, there are some loose ends that could be tied up &#8211; I may blog about some of these. In particular, I may write an article about how that database could have been so much better protected. I am still considering whether that would be worthwhile to my readers and how I should do that.</p>
<p>But other than a couple of follow up articles, I do not intend to keep up this site. I may archives some news posts but I will keep the general interest stuff available for a historical perspective. However in a couple of weeks I intend to turn comments off on the articles and leave things be. </p>
<p>Now having said that, I could not resist a couple of things. One correction: zFire claimed in his Alphaville Herald article that no one had proven he had a page tracking locations of IP addresses. </p>
<p>In fact I can reveal that the page that did this was hidden in his error404.php document. If logged in as zFire or his girlfriend, the 404 page showed a search box that allowed you to enter an Avatar name and it showed you the location associated with their IP address. Even though I was given access to this information, I did not bother report this as, amongst all the other revelations, that page seemed pretty lame. Just thought I would mention it now though.</p>
<p>The second thing, I just felt that as we are all missing Crackerjack, we should have a quote from him. This written by Crackerjack on 19 February:</p>
<blockquote><p>my particular expertise is in network security and although i am not an expert in database programming i do work with programmers and know what an sql injection is and how it can be performed and they havent the expertise nor the methodology to do it</p></blockquote>
<p>Once again many thanks to readers of this blog for your interest.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/325/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/325/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=325&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/03/17/time-to-move-on/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>
	</item>
		<item>
		<title>Latest News: RedZone is Gone. zFire Xue and Alts are Banned</title>
		<link>http://no2redzone.wordpress.com/2011/03/16/latest-news-redzone-is-gone-zfire-xue-and-alts-are-banned/</link>
		<comments>http://no2redzone.wordpress.com/2011/03/16/latest-news-redzone-is-gone-zfire-xue-and-alts-are-banned/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 07:11:16 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=321</guid>
		<description><![CDATA[It is done! RedZone has been banned. The shop has been nuked by Soft Linden. Devices are being systematically removed from inventories by Linden Lab. zFire Xue and his alts have been banned from Second Life. Thanks to everyone who has written ARs, blogged, commented, posted, voted and in any way helped make this happen! [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=321&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><div id="attachment_327" class="wp-caption alignnone" style="width: 410px"><a href="http://no2redzone.files.wordpress.com/2011/03/27_074.png"><img src="http://no2redzone.files.wordpress.com/2011/03/27_074.png?w=400" alt="The End of RedZone" title="The End of RedZone" width="400" class="size-thumbnail wp-image-327" /></a><p class="wp-caption-text">Soft Linden Nukes the RedZone Store As Crowds Party</p></div>It is done! RedZone has been banned. The shop has been nuked by Soft Linden. Devices are being systematically removed from inventories by Linden Lab. zFire Xue and his alts have been banned from Second Life.</p>
<p>Thanks to everyone who has written ARs, blogged, commented, posted, voted and in any way helped make this happen!</p>
<p>There will be some more news on this blog soon.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/321/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/321/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=321&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/03/16/latest-news-redzone-is-gone-zfire-xue-and-alts-are-banned/feed/</wfw:commentRss>
		<slash:comments>81</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>

		<media:content url="http://no2redzone.files.wordpress.com/2011/03/27_074.png?w=150" medium="image">
			<media:title type="html">The End of RedZone</media:title>
		</media:content>
	</item>
		<item>
		<title>Breaking News: zFire Xue is a Convicted Criminal</title>
		<link>http://no2redzone.wordpress.com/2011/03/14/breaking-news-zfire-xue-is-a-convicted-criminal/</link>
		<comments>http://no2redzone.wordpress.com/2011/03/14/breaking-news-zfire-xue-is-a-convicted-criminal/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 16:22:33 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=304</guid>
		<description><![CDATA[Never let it be said that zfRedZone is drama free. In a sensational development, someone has uncoverd evidence that everything we said about zFire Xue is true. I have said I will not use his full real name on this forum (although I have known it for quite some time). In the light of this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=304&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><img src="http://i877.photobucket.com/albums/ab335/prime6/January2011/P1050450.jpg" alt="Ebay Fraudster Since 1997" width="250" align="left" style="padding:1em;" />Never let it be said that zfRedZone is drama free. In a sensational development, someone has uncoverd evidence that everything we said about zFire Xue is true. I have said I will not use his full real name on this forum (although I have known it for quite some time). In the light of this news, I say stuff it!</p>
<p>Michael Stefan Prime has multiple criminal convictions, including convictions for ebay fraud. <a href="http://community.seattletimes.nwsource.com/archive/?date=19990905&amp;slug=2981192">This is an article about Mike Prime &#8211; zFire Xue</a>. A longer <a href="http://www.cedar.buffalo.edu/papers/articles/USvPrime2004.pdf">PDF court record is here</a>, and a <a href="http://query.nytimes.com/gst/fullpage.html?res=9407E5DC1F3DF930A3575BC0A9669C8B63&amp;pagewanted=all">New York Times article is here.</a> Note from the court record that he had a string of previous convictions for first and second degree theft, two counts of possession of stolen property in the second degree, and forgery &#8211; at the age of 19!!</p>
<p>Bronxelf released this <a href="http://law.justia.com/cases/federal/appellate-courts/F3/363/1028/531950/">link to the court records for this case</a> in a sensational post on SLUniverse a short while ago. Theia Magic confirmed this was the information she passed on to Linden Lab on Friday, and that the Lab is therefore now aware of zFire&#8217;s criminal record.</p>
<p>As zFire&#8217;s usual response is to fib and deny, I will pre-empt questions as to whether this is the same Michael Prime by saying that the age and details in this report fit him perfectly (19 in 1999 &#8211; he is 30 now, which we know is correct), and I had already scoured the web some months ago and I am 99.9% confident that he is the only Mike Prime in the Seattle area in the region of 30 years old. Theia Magic has also spent the weekend confirming identity and turning up some interesting names to others we have seen before &#8211; including John Hamlin. Theia&#8217;s blog is linked on the right, so check there to see if she posts updates.</p>
<p>So there you have it. It is as we always knew it: The fight between us and RedZone was always about thousands of honest sim owners and content creators on the one side, and a small band of thieves and criminals on the other. And the criminals built a system called RedZone.</p>
<p>Now, in our view, Linden Lab must act.</p>
<p>Consider what we have here:</p>
<ol>
<li>Mike Prime set up a system that unreliably but with some success links alts by IP address. He does not care about false positives, as long as he finds a few real positives because:</li>
<li>Most people who have lats use the same password or some variation on the same.</li>
<li>Mike Prime has been harvesting password information from the 5,000+ users of his site by logging real passwords and failed attempts.</li>
</ol>
<p>there is a <strong>very real risk </strong>that Mike Prime intends to use stolen accounts and stolen alt accounts for more petty theft and fraud.</p>
<p><em><strong>URGENT: </strong></em>Please put aside all grudges and tell all users of RedZone, and anyone who ever registered at Mike Prime&#8217;s site to <strong>CHANGE THEIR PASSWORD IMMEDIATELY IN ALL PLACES THEY USE THAT PASSWORD!</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/304/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=304&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/03/14/breaking-news-zfire-xue-is-a-convicted-criminal/feed/</wfw:commentRss>
		<slash:comments>52</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>

		<media:content url="http://i877.photobucket.com/albums/ab335/prime6/January2011/P1050450.jpg" medium="image">
			<media:title type="html">Ebay Fraudster Since 1997</media:title>
		</media:content>
	</item>
		<item>
		<title>Latest Neighbourhood Watch Updates</title>
		<link>http://no2redzone.wordpress.com/2011/03/14/latest-neighbourhood-watch-updates/</link>
		<comments>http://no2redzone.wordpress.com/2011/03/14/latest-neighbourhood-watch-updates/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 07:22:16 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=302</guid>
		<description><![CDATA[I have always said the neighbourhood watch is one of the nastiest things on zFire&#8217;s site. Right now, however, I am enjoying it. I expect zFire will delete these when he sees them. We are not meant to criticise him after all.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=302&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<div id="attachment_301" class="wp-caption alignnone" style="width: 160px"><a href="http://no2redzone.files.wordpress.com/2011/03/nwatchxue.png"><img src="http://no2redzone.files.wordpress.com/2011/03/nwatchxue.png?w=150&#038;h=88" alt="zFire Xue is panned on his own gossip forum" title="Neighbourhood Watch" width="150" height="88" class="size-thumbnail wp-image-301" /></a><p class="wp-caption-text">zFire is a victim of his own nasty forum</p></div>
<p>I have always said the neighbourhood watch is one of the nastiest things on zFire&#8217;s site. Right now, however, I am enjoying it.</p>
<p>I expect zFire will delete these when he sees them. We are not meant to criticise him after all.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/302/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=302&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/03/14/latest-neighbourhood-watch-updates/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>

		<media:content url="http://no2redzone.files.wordpress.com/2011/03/nwatchxue.png?w=150" medium="image">
			<media:title type="html">Neighbourhood Watch</media:title>
		</media:content>
	</item>
		<item>
		<title>Does Anyone Still Trust zFire Xue?</title>
		<link>http://no2redzone.wordpress.com/2011/03/12/does-anyone-still-trust-zfire-xue/</link>
		<comments>http://no2redzone.wordpress.com/2011/03/12/does-anyone-still-trust-zfire-xue/#comments</comments>
		<pubDate>Sat, 12 Mar 2011 23:51:30 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=284</guid>
		<description><![CDATA[Since this time yesterday when zFire was hacked in response to his foolish challenge to test his (pathetic) security, it seems he has been hacked again &#8211; at least once. a whole bunch of SQL tables or maybe even the entire database was dropped in what looks like yet another SQL insertion attack. It is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=284&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Since this time yesterday when zFire was hacked in response to his foolish challenge to test his (pathetic) security, it seems he has been hacked again &#8211; at least once. a whole bunch of SQL tables or maybe even the entire database was dropped in what looks like yet another SQL insertion attack. It is clear that zFire has been gemming up on avoiding SQL injection attacks. Keep reading zFire &#8230; you will get there eventually. </p>
<p>But not before it is all too late. Password outing functionality, and indeed the veracity of the video we carried this week has been confirmed by the hackers from last night who released their findings to the <a href="http://alphavilleherald.com/2011/03/zf-redzone-security-breached-sl-passwords-compromised.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+AlphavilleHerald+%28Alphaville+Herald%29">Alphaville Herald</a>. It may be they attempted to contact us with the information first, for which I thank them but I think the Alphaville Herald is a good place for that report.</p>
<p>Yesterday&#8217;s hack was still annoyingly obvious &#8211; and today&#8217;s moreso. I can allay some fears however in that I understand that significant quantities of false data have been injected into that database by yet another person or persons who have demonstrated they understood the security vulnerability well enough to do this. This same source suggests that zFire was about to manually add the names of all members of the inworld GreenZone users group to the list of &#8220;known copybotters&#8221;[sic]. Attached is the evidence provided &#8211; snipped away are well over 1000 names take from the group membership.<div id="attachment_286" class="wp-caption alignright" style="width: 160px"><a href="http://no2redzone.files.wordpress.com/2011/03/zfirelet.png"><img src="http://no2redzone.files.wordpress.com/2011/03/zfirelet.png?w=150&#038;h=68" alt="Letter to zFire Xue from Merlin Swordthain" title="Letter to zFire Xue from Merlin Swordthain" width="150" height="68" class="size-thumbnail wp-image-286" /></a><p class="wp-caption-text">Letter to zFire Xue from Merlin Swordthain</p></div></p>
<p>Since today&#8217;s hack the forums appear to have had it although it looks like there was a recent database backup. If anyone else is thinking of cracking this database I should point out that its no great challenge but at this time the working database is zFire&#8217;s biggest albatross It shows he has been a very very bad boy so please do not be tempted to take it offline. False IP address reports will do no harm though.</p>
<p>To end on a lighter note, Theia was confused by this remark from new RedZone poster arooga:</p>
<blockquote><p>by arooga » Fri Mar 11, 2011 1:48 am</p>
<p>I would like to have crackerjack&#8217;s babies for the way he got Theia Magic<br />
Done Up Like A Kipper she was, hung by her own petard</p></blockquote>
<p>Her comment to that was amusing bit this is even more amusing in the light of this:<br />
<div id="attachment_294" class="wp-caption alignnone" style="width: 160px"><a href="http://no2redzone.files.wordpress.com/2011/03/cjisarooga.png"><img src="http://no2redzone.files.wordpress.com/2011/03/cjisarooga.png?w=150&#038;h=44" alt="Arooga is Crackerjack" title="Arooga is Crackerjack" width="150" height="44" class="size-thumbnail wp-image-294" /></a><p class="wp-caption-text">Arooga is Crackerjack</p></div></p>
<p>[Edit: Someone challenged the image showing that Arooga is Crackerjack, saying anyone could have written that on the forum. I edited down the screenshot I was given and now include a bit more to show this was a message sent directly to zFire. The message and the screenshot predate Friday's crack on the database.]</p>
<p>It seems Crackerjack, in an attempt to beef up his security by changing his email address, locked himself out of that account. He decided Arooga would be fun for alt games. Strange from someone who finds alt outing so important.</p>
<p>So Arooga wants to have Crackerjack&#8217;s babies? Nice to see him getting in touch with his feminine side.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/284/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=284&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/03/12/does-anyone-still-trust-zfire-xue/feed/</wfw:commentRss>
		<slash:comments>46</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>

		<media:content url="http://no2redzone.files.wordpress.com/2011/03/zfirelet.png?w=150" medium="image">
			<media:title type="html">Letter to zFire Xue from Merlin Swordthain</media:title>
		</media:content>

		<media:content url="http://no2redzone.files.wordpress.com/2011/03/cjisarooga.png?w=150" medium="image">
			<media:title type="html">Arooga is Crackerjack</media:title>
		</media:content>
	</item>
		<item>
		<title>Hack&#8230;or Cover Up</title>
		<link>http://no2redzone.wordpress.com/2011/03/11/hack-or-cover-up/</link>
		<comments>http://no2redzone.wordpress.com/2011/03/11/hack-or-cover-up/#comments</comments>
		<pubDate>Fri, 11 Mar 2011 22:20:26 +0000</pubDate>
		<dc:creator>no2redzone</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://no2redzone.wordpress.com/?p=279</guid>
		<description><![CDATA[A few minutes ago someone pasted a link on a group to Merlin Swordthain saying that someone had hacked his account on the isellsl forum. As I was browsing the forum the whole site died. It may be that someone took zFire up on his challenge to beat his security. I hope not really. But [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=279&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>A few minutes ago someone pasted a link on a group to Merlin Swordthain saying that someone had hacked his account on the isellsl forum. As I was browsing the forum the whole site died.</p>
<p>It may be that someone took zFire up on his challenge to beat his security. I hope not really. But if they did, we could see quite an extended outage!</p>
<p>Move along now&#8230;there is nothing more to see.</p>
<p>Oh, but another theory: Merlin may have been watching for the posting of that URL. This may have been an attempt to bow out graciously &#8211; take the server down when people will think it is hacking&#8230; blame the griefers and walk away.</p>
<p>Either way &#8211; RedZone could be gone.</p>
<p>EDIT 3:12 SLT &#8211; This is a confirmed crack on the database. </p>
<p>ZFire had posted this earlier:</p>
<blockquote><p>Originally Posted by zFire Xue<br />
Let me be very clear when I say:<br />
zFire did not &#8220;underestimate the tech savvy community of Secondlife if he thinks they will not [insert illegal hack attack here]&#8230;&#8221;</p>
<p>My server remains online, DDOS, URL probing, port scans, and seriously did you just try to &#8220;NUKE&#8221; me on port 139 Mr Germany?<br />
They offer technical resumes, and warnings of everything they feel I did wrong.<br />
My server is still online, even with low tech abuse reports to my ISP, DDOS of 860 million a second (Impressive but pointless), and whatever else.<br />
This therefore means that my server is the most secure server and database in all of Secondlife.<br />
That is a challenge.<br />
Many people have already made battle cries, suggested methods, or claimed not to support methods of hacking.<br />
Bring it on. </p>
<p>I am the guy that logs your shoe size right? Do you think any server software exists that does NOT log the IP, date and time of an attempted cybercrime? Wow this will be fun.</p>
<p>&#8220;My computer is bigger than your computer&#8221;<br />
Cyber criminals need banning, so please feed attempts to isellsl.ath.cx</p></blockquote>
<p>His site was actually an exercise in how not to do security, but I am annoyed that this crack was so unsubtle. That&#8217;s what happens when you challenge the whole Internet to come hack your server.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/no2redzone.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/no2redzone.wordpress.com/279/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=no2redzone.wordpress.com&#038;blog=19667974&#038;post=279&#038;subd=no2redzone&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://no2redzone.wordpress.com/2011/03/11/hack-or-cover-up/feed/</wfw:commentRss>
		<slash:comments>33</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/8fe90e7a7a080f8e28762854e2f0546e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">no2redzone</media:title>
		</media:content>
	</item>
	</channel>
</rss>
