We saw the symptoms of the first carefully engineered blog hijacks, in Blogger Help Forum: Something Is Broken, two years ago. During each succeeding holiday season, each attack has apparently become more and more deviously engineered.
This season - each season starting in Fall of one year and lasting until Spring of the following year - we are seeing a hijack complement which appears to be devious in both marketing and installation technique, and which requires a complex search of the affected blogs. If you are receiving reports from your readersYour blog starts to load - but is quickly replaced by a page full of advertisements!
you may need to exhaustively examine your blog for any third party code - and as always, the problem code may have been installed at any time in the past. When discovered, the hijacks are not consistently found in recently installed code.
The blog hijacks, being examined during this holiday season - appear to be deviously planned and marketed.- The hijacks use a variety of host accessories and gadgets.
- The hijacks use a variety of distribution libraries.
- The hijacks are being marketed to a diverse audience, which causes different installation techniques - and necessitates the complex search of affected blogs.
To find and remove a hijack from an affected blog, you'll need to start by viewing the blog in question, using a text only browser, or proxy service. I, personally, use several products.- hpHosts vURL is a text only browser, that runs as a stand alone application locally on your computer.
- Notepad-Plus-Plus is an offline text editor, which provides a variety of search tools for text files. You can sometimes avoid use of your browser completely, by copying page source code directly from vURL.
- Rex Swain's HTTP Viewer is a standard online text proxy that I use.
- Lingo4you HTTP Web-Sniffer is an online alternative to Rex Swain.
All of these products may be more or less useful in identifying the source of your specific hijack. The Rex Swain and Web-Sniffer text proxies each have their effective differences.
If anybody uses alternative products, and cares to share information about the tools used, I will most gratefully add them to my library here.
The approach here is complex.- Of course, backup the template, before starting.
- Load the blog, in question, in the text browser / proxy display of your choice.
- Do a simple text search for the identified host / target name in the URL, such as "adiwidget", "pagesinxt", or "ripway".
- You'll see several different possibilities.
- The search may reveal the hijacking code in an HTML gadget. You can use the "Pages Elements" / Design tab (Classic GUI), or the "Layout" wizard (New GUI), and remove the offending gadget.
- The search may reveal the hijacking code in the template HTML. You'll have to use the Template Editor, and remove the offending lines of code.
- The search may not find any identified host name, in a text search. You'll have to do an extensive text search, looking for unknown HTML / JavaScript gadgets / snippets of code, and evaluate each gadget / snippet, on the fly.
- You may need to bypass the Blogger menu structure, to directly access the Blogger wizard needed, if trying to use the Blogger menus is also a problem.
- Clear browser cache, before checking for success.
- And always backup the template, again, after completing this task.
And hopefully, having found and removed a hijack from your blog, you will learn to be more discrete, in your choice of accessories and gadgets, in the future.
We see the pain, in Blogger Help Forum: Something Is Broken, of blog owners who do not understand the need for keeping the name of their Blogger account a secret.I forgot the email address that I was using. Why can't Blogger just tell me the address??
and some askHow did this unknown person "xxxxx xxxxx" get control of my blog?
Years ago, the local police would have to convince home ownersPlease, stop leaving a spare key under a rock, near the door!
Both many blog owners (today) - like some home owners (years ago) - had the same basic problem - naivete.
Like the home owners of years ago, who kept a spare key under a rock near the front door, for emergencies, blog owners will use tricks to remember their password.
Don't - please don't - use a guessable password!
One favourite technique, for remembering the password, is so obvious.
Pick a password based upon something that you can remember.
For a blog owner who is married, the answer is obvious.
What is my spouse's name?
and there's your password. If you forget that, you have worse problems, that cannot be addressed here.
If the name of one's spouse was a secret, using the name would not be a problem. But knowing that many blogs either contain the name (and picture, maybe) of the whole family - or lead to a Profile page or website (FaceBook, Instagram, Twitter, ...) with similarly useful information - how secret is the password going to be?
Hackers love blogs with guessable passwords.
Knowing both the Blogger account name (email address) that owns any blog of interest, and the URL of the blog, any hacker has a simple enough task.
- Scrape blog content, into a text analyzer.
- Extract a few hundred details (spouse's name, and others) from the blog content, as analysed.
- Run the known details through a password generation program.
- Now, the hacker has a database, containing "10,000 good possible passwords", specifically relevant to this blog.
- Go to "www.blogger.com", plug in the account name, and try out the 10,000 passwords, one by one.
- That's a simple brute force password attack.
- Sit back, and watch any botnet, controlled by the hacker, go to work.
- Given enough time, the hacker very likely gets access to the Blogger account, and to the blogs owned by the account.
Steps 1 - 8, for any experienced hacker, will be summed into one step.Plug in the URL of the blog.
Everything needed is just more coding - and a nice robust botnet or two.
The hacker, of course, will be targeting thousands of different blogs, simultaneously. So what if he (she) fails to find what details she (he) needs, to steal your blog? He'll (she'll) gladly settle for another - while the botnet works on yours.
Besides using a "strong" password (which carries it's own risks such as forgetting the password - and now we're here, again), the best way to prevent a brute force attack is by preventing step 5.
Keep the account name / email address a secret.
Additionally, if you have a blog and a business - or otherwise exchange email with strangers, separate your Blogger / Google account and your email account. Use two separate email addresses, for Blogger and email.
Learn to appreciate efforts made, by Google, keeping your account and blogs safe.
If you need to recover access to your Blogger account, don't expect to use the Blogger "Forgot?" wizard, plug in your blog URL, and get a reply
Email was sent to your address xxxxxxx@yyyyy.zzz
And, if you post in the forum.
Please email me advice, to "xxxxxxx@yyyyy.zzz"!
expect to get a stern warning
Please, do not post Blogger account names, or email addresses, in the forum.
People objecting to the recent Blogger policy of masking email addresses, in Blogger commenting and similar services, as "no-reply @ blogger . com", may also need to consider this very real issue. Possibly, even use Google+, instead of Blogger commenting, for networking with ones peers.
Google tries to identify brute force attacks, and takes action when possible.
And, if your Blogger / GMail / Google account is disabled - and you get a mysterious notice about
Suspicious / Unusual activity on your account
this could well be the other side of a brute force attack against your account, intercepted by Google.
Don't be offended by the various precautions.
If you find the precautions and problems to be unacceptable, consider using Google 2-step verification, to protect your account against brute force hacking.
This is not fiction here - it's all very real.
None of this is fiction or paranoia - it's based on some very real, recent events, and even involves a recent National Scandal - and leads to some very real conundrums.
Similarly, we have a very distasteful answer, to a seemingly worthy need. And another apparently "ceremonial" but necessary answer, to somebody in need of understanding and support, that can't be provided.
You have to make the effort, to maintain and protect your blog.
You will get no sympathy, when you complain how unsupportive Blogger is.
You have to make some effort - and remember some basic information - if you are going to maintain a Blogger blog. And, encourage your friends to keep their accounts and blogs safe.