Writing Shellcode in C/C++
expdev.byethost7.com
expdev.byethost7.com
It's a server-side redirect, not a script redirect, and searches suggest that it's commonly installed on exploited servers via web server configuration. If the person running the site sees this: check your .htaccess and other web server configuration, and see if your server has been compromised. (Check your browser too.) Might also be a problem with the hosting provider.
Meanwhile, could the submitter or an HN admin please take some steps to prevent exploits of HN readers, such as changing the URL to something innocuous (such as example.org) and posting the original URL in a comment?
In a way or another, I'll manage to publish my course. The best articles are yet to come (EMET and IE)! :)
FYI, having used byethost for free hosting before, I don't believe "securesignupoffers" itself is malware. It's what accounts which have been suspended or don't have a valid index page redirect to by default.
What happened is that someone set up a bunch of accounts on the host for malware/phishing/spamming/etc., and those URLs were used by malware. The host has rightly deleted those accounts, causing malware which forces the user into visiting the original URL to be taken to securesignupoffers instead.
This shellcoder handbook is good...
http://www.amazon.com/Shellcoders-Handbook-Discovering-Explo...
And articles such as this one by steve hanna
http://www.vividmachines.com/shellcode/shellcode.html
and this one by Aleph One on phrack,
http://phrack.org/issues/49/14.html
(by the way, many articles on phrack are really good)
Some more recent versions of smashing the stack are,
http://www.mgraziano.info/docs/stsi2010.pdf
https://paulmakowski.wordpress.com/2011/01/25/smashing-the-s...
also check out the ezines by 29A -- although they are old, but you know, some good stuff are still really good today...
just do a little search...there are tons of articles out there on this topic...
To access the cached copy, just search in google with the "cache" keyword prefix
"cache:" + ${original_URL}
for example: cache:expdev.byethost7.com/2015/05/22/shellcode/