Showing posts with label Blog Hijack - 2010. Show all posts
Showing posts with label Blog Hijack - 2010. Show all posts

Saturday, March 27, 2010

Blogger Blogs Redirecting To "freegadget2015.blogspot.com" / "freegadget-xde"

As yet another chapter in the tale of the hijacked Blogger blogs, today we have reports of blogs redirecting to "freegadget2015.blogspot.com" and "freegadget-xde".

For those newly experiencing this persistent assault upon our blogs, see the FAQ My Blog Has Been Hijacked - What Do I Do? for diagnosis and removal techniques. Note that you'll probably need to use the "Edit HTML" wizard, and delete the offending code, for expedient removal.

>> Top

Wednesday, March 24, 2010

Blog Hijackings - The Worst May Be Over

Blogger Support took control of the blog hijacking problem yesterday. Today, I did a search in "Add a Gadget", and found encouraging results.







I believe that they are now trying to disable the installed gadgets - so if you see a blank space on your blog, that's possibly why.


(Update 2010/11/25): And to celebrate Thanksgiving Day 2010, we see a report of yet another hijack attempt.

>> Top

Monday, March 22, 2010

Blogger Blogs Redirecting To "freegadget2014.blogspot.com"

In a disturbing repeat of problems experienced earlier this month, we have reports of blogs redirecting again, this time to "freegadget2014.blogspot.com".

For those of you experiencing this assault upon your blog, see the FAQ My Blog Has Been Hijacked - What Do I Do? for current diagnosis and removal techniques. Note that the gadgets noted this week, as earlier, appear to resist removal, so you'll probably need to use "Edit HTML", and delete the offending code.


(Update 2010/03/23): Blogger Support has taken ownership of the problem.
Our team is working to sort out these affected gadgets from our side, and hope to have this fix out shortly.



>> Top

Friday, March 5, 2010

Identifying And Removing HTML / JavaScript / XML Based Malware From Your Blog

Occasionally, in the recently discovered social engineering blog attacks that involve shiny blog accessories, we've seen reports of aggressively protected malware, that's being installed on some blogs.

When a misbehaving HTML gadget is the source of the problem, it's sometimes possible to click on the "Quick Edit" icon for the gadget, and click "Remove". Alternatively, go to "Page Elements", and click on the "Edit" link for the gadget in question. This does not always work so simply, however.

If you can't remove a recently installed gadget, because you get redirected when trying to use the "Layout" button from the dashboard, or the "Remove" button from the "Page Elements" wizard, you may have to be imaginative.
  • Use a well protected browser - minimally, one which blocks scripts from any non Blogger / Google domain, to clean your blog. This is the simplest possibility here.
  • Use an HTTP text proxy, to examine the blog code.
  • Remove the code manually.
    1. Use a protected browser or proxy server to access the blog, and "View Source".
    2. Look in the source, and find the offending gadget / module. If it was installed as an "HTML / JavaScript" or Blogger "Add a Gadget" (XML) gadget, look at the code carefully, and look for "Gadgetnn" and "HTMLnn", where "nn" will be the sequential number for that HTML / XML gadget. This is important.
    3. Manually access the Layout "Edit HTML" wizard for the blog.
    4. Do not check "Expand widget templates" - just "Edit HTML".
    5. Look in the code, carefully, for each "Gadgetnn" or "HTMLnn" entry.
      <div class='widget Gadget' id='Gadget1' />
      or
      <div class='widget HTML' id='HTML1' />
    6. Remove that line of code.
    7. Save.
  • As always, please backup the template before and after you do this cleanup!


If you cannot find an obvious culprit from a quick "View Source", then start removing all "HTML / JavaScript" gadgets, and all XML gadgets (possibly including some installed from the Blogger "Add a Gadget" wizard), installed most recently ("recently", in some cases, being 2 - 3 months back).
  1. Remove a gadget.
  2. Clear browser cache.
  3. Test.
  4. If no improvement, repeat.
Alternatively, just remove all accessories and gadgets - then re install and test everything, one by one.
  1. Add a gadget back.
  2. Clear browser cache.
  3. Test.
  4. If a problem is seen, remove that gadget and identify it.
  5. Repeat.
It's your blog, and your decision which way to go. Barring any obvious suspects, I think I'd try the latter.

If you do put some accessories back, or add anything more, keep an eye on what you add, and check your blog frequently. A lot of the complaints this week appears to involve hacks that may have been installed 2 or 3 months ago. Watch out for smart code, that doesn't activate (reactivate) the hacking immediately when installed.


It appears that some malware may be included in some gadgets installed by the Blogger "Add a Gadget" wizard. If you find removing any Blogger gadgets to provide you any relief, please report your findings in my article Some Hijack Malware Is Being Claimed To Be Blogger Provided. Your details, provided there, would be greatly appreciated.

Blogger Blogs Redirecting To "deplayer.net "

This week, we are seeing a few reports from anxious bloggers that their blogs are redirecting to mysterious URLs containing the domain "deplayer.net". This is somewhat reminiscent of the "searchinvented.com / smashingfeeds.com" hijacks seen during January 2010, and to the "sendptp.com" hijacks seen during February 2010.

Early reports mention the "Real time hit counter" gadget, seen by some as the "Halifax 2011" countdown gadget, or possibly the "Halloween 2010" countdown gadget, as being the gadget most successfully removed.

It's also possible that the "falling snow" and "Tweet This" gadget code has been upgraded to redirect to "deplayer.net". We also have reports of an "ITunes" accessory, a "Martin Luther King Jr Quotes" gadget, and a "yoga journal" / "yoga pose" gadget being involved this month.

As always, I'll caution you to be wary of any third party gadgets. It appears from some comments received that there is protective code in these newest gadgets, which aggressively blocks use of the "Page Elements" gadget GUI removal. If you try to hit the "Remove" button, or hit "Layout" from the dashboard link, and you are redirected, you have 2 choices.
  1. Use "the Page Elements" wizard from a browser / computer which blocks scripts from all third party domains, outside the Blogger / Google world.
  2. Access the Layout "Edit HTML" wizard directly, and remove the entry for the HTML / JavaScript gadget directly from the template code.


After removing the offending code, don't forget to clear cache, before testing your change!


It appears that some malware may be included in some gadgets installed by the Blogger "Add a Gadget" wizard. If you find removing any Blogger gadgets to provide you any relief, please report your findings in my article Some Hijack Malware Is Being Claimed To Be Blogger Provided. Your details, provided there, would be greatly appreciated.


>> Top

Tuesday, February 9, 2010

Valentine's Day Is Coming - Celebrate With Care

This Sunday, many bloggers will celebrate another important holiday in the year - the holiday of celebrated relationships, aka Valentine's Day. Some bloggers will decorate their blogs, using a Valentine's Day standard - falling hearts.

Incautiously chosen relationships cause pain and suffering - some even known as "the gift that keeps on giving", aka an STD. Some incautiously chosen falling hearts decorations have recently been found to cause another "gift that keeps on giving". At least one falling hearts variant, provided free by a hacker, has been reported as causing a blog hijack, noted by several bloggers in Blogger Help Forum as a "sendptp.com" hijack.

Like STDs, the blog hijacks being discovered recently don't always show up immediately. Normally, when people write in to the forum reporting
I´m being hacked! Every time I type the address to my blog, I´m getting redirected!
we advise them to remove any recently installed third party accessories.

Recently, the victims of "falling hearts" and its predecessor "falling snow" have reported having installed their problem accessory some time ago, and just recently noticed the hijack problem. A few accessories are removed, before the problem is discovered and removed.

It's possible that these accessories are being released intentionally, as stealth hijacks. Like STDs, you won't see the problem, until long after the fun is gone.

If you choose a "falling snow", "falling hearts" or maybe "falling flags" (for Fourth Of July?) decoration for your blog, choose with discretion. Don't wait for your readers to write to you
Why do I get a page full of advertisements, instead of your blog?


Remember - security for your readers begins with you.

>> Top

Wednesday, February 3, 2010

Blogger Blogs Redirecting To "sendptp.com"

This week, we are seeing a few reports from anxious bloggers that their blogs are redirecting to mysterious URLs containing the domain "sendptp.com". This is somewhat reminiscent of the "searchinvented.com / smashingfeeds.com" hijacks of January 2010.
I can log in to my blog, but then in a few seconds the page goes blank, and in the URL it says..sendptp.com/ramk2.html...at the bottom it says redirecting and flashing back and forth...


Immediate reports suggest a "falling snow" decoration, apparently acquired before Christmas 2009, as one known culprit. Other reports mention a possible variant, "falling hearts" (Valentines Day?).

http://everything-u-need-is-here.blogspot.com/2008/12/snow-effect-widget-for-blogger.html
http://h1.ripway.com/anand2360375/snow.js


In one case, the "searchinvented.com" / "smashingfeeds.com" redirect is being found on a blog that has a "falling snow" gadget.


I wouldn't bet that this is the only cause of this hijack, but it looks to be one place where you can look, should your blog show this problem.

So far, the problem code has been easily corrected, with a simple removal of the HTML / JavaScript gadget containing the offending code.

After removing the offending code, don't forget to clear cache, before testing your change!

>> Top

Wednesday, January 6, 2010

Blogger Blogs Redirecting To "smashingfeeds.com"

This week, we are seeing a few reports from anxious bloggers that their blogs are redirecting to mysterious URLs containing the domain "smashingfeeds.com". This is somewhat reminiscent of the "blogoholic.info" hijacks of June 2009.
My blog site has been hijacked & redirects to: http://searchinvented.com/?flrdr=yes&nxte=js&dn=smashingfeeds.com&fp=57S


Immediate reports from some bloggers suggest that removal of a possibly recently installed "Tweet This" gadget may be the most likely solution, when faced with this problem.

If you can access the "Page Elements" wizard, and if you have previously installed a "Tweet This" gadget on your blog, that's where you should start. Other blogs have the code installed directly into the template, and will have to use the "Edit HTML" wizard.

As with the "blogoholic.info" redirect, this exploit has been seen to cause corruption of the blog or gadget template, which may redirect you to "smashingfeeds.com" when you try to access the "Edit HTML" or "Page Elements" wizards. If you have this problem, you'll have to find out the blogID, then reference "Edit HTML" or "Page Elements" directly by URL.


In one case, the "searchinvented.com" / "smashingfeeds.com" redirect is being found on a blog that has a "falling snow" gadget.


After removing the offending code, don't forget to clear cache, before testing your change!

>> Top

Navigate» Become author for this Blog