Showing posts with label Strategic Malware. Show all posts
Showing posts with label Strategic Malware. Show all posts

Sunday, September 2, 2018

The "w i d g e t s e r v e r" Abandoned Domain Is Now Malicious

We've been dealing with a minor recent deluge of reports, from blog owners reporting mysterious redirection of their blogs.

The original typical report, which started like any report involving a respected Internet service going out of business, was annoying - yet benign.

Today, the status changed to malicious.

Right now, "w i d g e t s e r v e r . c o m" is redirecting to "l i b o s t u d i o s . com".

Please enter your email address to continue.

Many gadgets, long known for redirecting, are again redirecting - recently to "w i d g e t s e r v e r . c o m" - and now to "l i b o s t u d i o s . c o m". As some were diagnosed, a few owners advised that the misbehaving gadget had been installed long ago.

We've seen, so far, a few old (not!) friends. M a u k i e , N e o C o u n t e r, and "S u n a n d M o o n P h a s e" can be seen, in some topics.

A brief sample of forum topics involving "w i d g e t s e r v e r . c o m" mention gadgets previously installed by Blogger, using the "Add a Gadget" wizard. Recently, Blogger cleared out the third party gadgets from "Add a Gadget" - and the gadgets rejected by Blogger are now hosted by ""w i d g e t s e r v e r . c o m". And they are malicious.

We will not sell, rent, or share, your email address. Your privacy is important to us!

Yeah, right.

And what will you do, with my email address?



What more should be said?



For a week, we've been dealing with #Blogger blog owners reporting mysterious redirecting by their blogs. Many helpers have dismissed the issue, as another popular third party gadget publisher gone out of business.

Today, the redirection changed - to an email mining op.

Sunday, December 14, 2014

NeoWorx, And The Redirecting NeoCounter Gadgets

This week, we're seeing the anxious query, in Blogger Help Forum: Get Help with an Issue.
Is my blog for sale? I try to view my blog, and I see
This Domain Is for Sale
Have I lost my blog?
Fortunately, in most cases, the answer is "No, your blog is not for sale." - and "No, you have not lost your blog!".

In mid 2014, NeoWorx, the publisher of popular gadgets like NeoCounter, closed up shop. Back end code for their gadgets, installed on thousands of blogs and websites, had been served from their private libraries. Having closed their domains, the gadgets stopped working.

Initially, "neoworx-blog-tools.net" was purchased by a squatter.

The squatter apparently had hoped to capitalise on the traffic to the domain, provided by the blogs and websites that used the installed gadgets. In late 2014, the squatter gave up (or possibly, sold to another squatter), and "neoworx-blog-tools.net" is now showing a very plain parked page.
This Domain Is for Sale
Either the squatter made a profit on his purchase, by serving ads to the would be viewers of the host blogs and websites, and decided to cash in - or he lost his investment, and decided to cut his losses and move on.

In theory - and by early Internet rules of etiquette - anybody purchasing a domain that has accumulated traffic from the efforts of the prior owner, and expects to be receiving traffic from unwary people like our blog readers, should put advice on their home page.
Sorry, NeoWorx (publisher of NeoCounter and other blog / website accessories) is no more.
or
Looking for NeoCounter? Try their new website.
The advice, to at least accompany the ads displayed there, would provide a brief hint to the unwary reader, that what he sought (i.e., blog content - or a given gadget) is no longer available (as suggested by the first advice). If NeoWorx had renamed themselves, or been bought out, the second advice would have been useful.

The initial purchasers of "neoworx-blog-tools.net", in defiance or ignorance of etiquette, simply served a page full of ads, and no advice. The ads did not target the owners of the blogs and websites - they simply confused the unwary readers - and provided no hints of why they were there, instead of viewing the blog or website.

Subjected to waves of complaints from angry readers, the blog owners had earlier posted in Blogger Help Forum: Get Help with an Issue.
Why is my blog directing to a page full of ads?
And we would examine the blog code in our browsers, find the gadget which references "neoworx-blog-tools.net", and instruct the blog owner to remove the gadget.

Now, instead of angry readers, who complain of ads, the blog owners suffer questions from confused readers, asking if the blog is being sold. And we continue to advise people to remove the misbehaving gadgets.

To the former owners of NeoWorx, and the subsequent domain owners:
Blogger blog owners are not cash cows.
We appreciate accessories, if you can support them. But please, don't produce gadgets that require your program libraries, run up huge volumes of traffic to your library domains, then sell out to spammers.

Here, we have one very real example why adding gadgets from third party developers may not always be in your best, long term interest.

Wednesday, January 25, 2012

Identifying And Removing Deviously Engineered And Marketed Blog Hijacks

We saw the symptoms of the first carefully engineered blog hijacks, in Blogger Help Forum: Something Is Broken, two years ago. During each succeeding holiday season, each attack has apparently become more and more deviously engineered.

This season - each season starting in Fall of one year and lasting until Spring of the following year - we are seeing a hijack complement which appears to be devious in both marketing and installation technique, and which requires a complex search of the affected blogs. If you are receiving reports from your readers
Your blog starts to load - but is quickly replaced by a page full of advertisements!
you may need to exhaustively examine your blog for any third party code - and as always, the problem code may have been installed at any time in the past. When discovered, the hijacks are not consistently found in recently installed code.

The blog hijacks, being examined during this holiday season - appear to be deviously planned and marketed.
  • The hijacks use a variety of host accessories and gadgets.
  • The hijacks use a variety of distribution libraries.
  • The hijacks are being marketed to a diverse audience, which causes different installation techniques - and necessitates the complex search of affected blogs.

To find and remove a hijack from an affected blog, you'll need to start by viewing the blog in question, using a text only browser, or proxy service. I, personally, use several products.
  • hpHosts vURL is a text only browser, that runs as a stand alone application locally on your computer.
  • Notepad-Plus-Plus is an offline text editor, which provides a variety of search tools for text files. You can sometimes avoid use of your browser completely, by copying page source code directly from vURL.
  • Rex Swain's HTTP Viewer is a standard online text proxy that I use.
  • Lingo4you HTTP Web-Sniffer is an online alternative to Rex Swain.
All of these products may be more or less useful in identifying the source of your specific hijack. The Rex Swain and Web-Sniffer text proxies each have their effective differences.

If anybody uses alternative products, and cares to share information about the tools used, I will most gratefully add them to my library here.

The approach here is complex.
  1. Of course, backup the template, before starting.
  2. Load the blog, in question, in the text browser / proxy display of your choice.
  3. Do a simple text search for the identified host / target name in the URL, such as "adiwidget", "pagesinxt", or "ripway".
  4. You'll see several different possibilities.
    • The search may reveal the hijacking code in an HTML gadget. You can use the "Pages Elements" / Design tab (Classic GUI), or the "Layout" wizard (New GUI), and remove the offending gadget.
    • The search may reveal the hijacking code in the template HTML. You'll have to use the Template Editor, and remove the offending lines of code.
    • The search may not find any identified host name, in a text search. You'll have to do an extensive text search, looking for unknown HTML / JavaScript gadgets / snippets of code, and evaluate each gadget / snippet, on the fly.
  5. You may need to bypass the Blogger menu structure, to directly access the Blogger wizard needed, if trying to use the Blogger menus is also a problem.
  6. Clear browser cache, before checking for success.
  7. And always backup the template, again, after completing this task.

And hopefully, having found and removed a hijack from your blog, you will learn to be more discrete, in your choice of accessories and gadgets, in the future.

Friday, December 30, 2011

Blogger Blogs Redirecting To "pagesinxt.com" / "ripway.com"

In spite of my recently published caution against gratuitous additions of third party blog accessories, we're seeing a small yet steady stream of reports about mysterious blog hijackings, in Blogger Help Forum: Something Is Broken.
When I view my blog, it shows up for a few seconds - and then forwards to this weird website, that I've never heard of.
Not everybody is aware of the dangers of adding non Google developed code, to their blogs.

Unlike the blog hijacks from the past couple years, the "pagesinxt" / "ripway" hijacks being reported have no consistent diagnosis.
  • We have not yet observed a consistent host feature, such as "falling snow" (from 2010).
  • Some hijacking code, when found, is part of the template HTML.
  • Other hijacks are apparently being installed as HTML / JavaScript gadgets.

To find this latest hijack, you'll need to start by viewing the blog in question, using a text only browser, or proxy service. I, personally, use several products.All of these products may be more or less useful in identifying the source of your specific hijack.

The approach here is multi-phasic.
  1. Of course, backup the template, before starting.
  2. Load the blog, in question, in the browser of your choice.
  3. Do a simple text search for "pagesinxt" and for "ripway".
  4. You'll see several different possibilities.
    • The search may reveal the hijacking code in an HTML gadget. You can use the "Pages Elements" / Design tab (Classic GUI), or the "Layout" wizard (New GUI), and remove the offending gadget.
    • The search may reveal the hijacking code in the template HTML. You'll have to use the Template Editor, and remove the offending lines of code.
    • The search may not find either "pagesinxt" or "ripway". You'll have to do an extensive text search, for unknown HTML / JavaScript gadgets, and evaluate each gadget, on the fly.
  5. You may need to bypass the Blogger menu structure, to directly access the Blogger wizard needed, if trying to use the Blogger menus is also a problem.
  6. Clear browser cache, before checking for success.
  7. And always backup the template, again, after completing this task.

If you want more detailed help for identifying or removing your personal hijack, please start a new discussion, in Blogger Help Forum: Something Is Broken, state the URL of your blog, and state what URL the blog is redirecting.

>> Top

Friday, November 18, 2011

It's The Holiday Season Again, And It's Time To Decorate Our Blogs

The Winter Holiday season is approaching, and this week we're seeing queries by some blog owners, getting ready.
Why do my readers see a search display - instead of my blog?
and
How do I make it snow on my blog?
and a few owners, and visitors
Why does my browser freeze or lag when viewing this blog?
Many blog owners, who publish craft, family, and personal themed blogs, just have to make their blogs reflect their holiday wishes for their readers. Only later, they may re think their decision.

Some of us in Blogger Help Forum: Something Is Broken remember this season last year, though not fondly. Many blog owners, having previously decorated their blogs with Falling Leaves (Thanksgiving), Falling Snow (Christmas), and later Falling Hearts (Valentines Day), found themselves spending time in the forum, asking why nobody could see their blogs. The answer that they found was that their blogs, previously decorated with the Falling Leaves / Snow / Hearts animations, were redirecting their readers to websites which were not relevant to their readers interests or needs.

The owners of computers poorly protected against malicious software installation, when redirected from their friends holiday decorated blogs to the hijackers websites, found themselves later consulting their local computer guru. The gurus spent time (not always without expense) removing some unwanted software, installed by the hijackers websites.

The charming thing about the hijacks is that the Falling Leaves / Snow / Hearts gadgets, when installed, did not immediately redirect the various visitors to the malicious websites. This detail appeared to indicate very devious planning by the hijackers, who had waited, patiently, while thousands of blog owners had installed their trickery, before activating the hijack.

This caused some confusion in the forums. A normal part of problem diagnosis - which many of those of you, who have requested help here, may recognise - is the brief and very simple question
What changes have you made to the blog, recently?
Most blog owners, naturally, answered
Nothing interesting.
Later, when a malicious Falling Leaves / Snow / Heart accessory was identified, with the stern advice
Get rid of that!
The answer would be
I installed that 6 months ago! Surely, that's not the problem??!!

Only after large numbers of people had reported problems with their blogs, and we found the Falling Leaves / Snow / Heart accessory on the problem blogs, did we advise everybody
Remove all Falling Leaves / Snow / Heart accessories, from your blogs, immediately.

Besides the blatant blog hijack threat, there's another issue for you to consider. The animation - falling hearts / leaves / snow - requires intense processor activity. If people stop visiting your blog, because their browsers freeze up, you'll need to revisit your decorative decision.

So, as this years holiday season starts, we'll advise everybody to beware of any animated accessory, such as (but not limited to) Falling Leaves / Snow / Hearts. Install any third party accessory with care and discrimination. And remember everything installed, for a long time afterwards.

>> Top

Saturday, March 27, 2010

Blogger Blogs Redirecting To "freegadget2015.blogspot.com" / "freegadget-xde"

As yet another chapter in the tale of the hijacked Blogger blogs, today we have reports of blogs redirecting to "freegadget2015.blogspot.com" and "freegadget-xde".

For those newly experiencing this persistent assault upon our blogs, see the FAQ My Blog Has Been Hijacked - What Do I Do? for diagnosis and removal techniques. Note that you'll probably need to use the "Edit HTML" wizard, and delete the offending code, for expedient removal.

>> Top

Wednesday, March 24, 2010

Blog Hijackings - The Worst May Be Over

Blogger Support took control of the blog hijacking problem yesterday. Today, I did a search in "Add a Gadget", and found encouraging results.







I believe that they are now trying to disable the installed gadgets - so if you see a blank space on your blog, that's possibly why.


(Update 2010/11/25): And to celebrate Thanksgiving Day 2010, we see a report of yet another hijack attempt.

>> Top

Monday, March 22, 2010

Blogger Blogs Redirecting To "freegadget2014.blogspot.com"

In a disturbing repeat of problems experienced earlier this month, we have reports of blogs redirecting again, this time to "freegadget2014.blogspot.com".

For those of you experiencing this assault upon your blog, see the FAQ My Blog Has Been Hijacked - What Do I Do? for current diagnosis and removal techniques. Note that the gadgets noted this week, as earlier, appear to resist removal, so you'll probably need to use "Edit HTML", and delete the offending code.


(Update 2010/03/23): Blogger Support has taken ownership of the problem.
Our team is working to sort out these affected gadgets from our side, and hope to have this fix out shortly.



>> Top

Friday, March 5, 2010

Some Hijack Malware Is Being Claimed To Be Blogger Provided

As the ongoing investigations into the nature of the latest malware based blog hijacks continues, some victims are claiming that the malware that they installed, unwittingly, was possibly part of a Blogger provided gadget, installed using the Blogger "Add a Gadget" wizard in "Page Elements".

If you find this as you clean your blog, will you please report your finding here. Please state, in a comment below, as completely as possible
  • The title of the offending gadget.
  • The author of the offending gadget - this detail is very useful, as many popular gadgets are provided by multiple authors!
  • Any specific selections or settings that you made, when installing the gadget.
What you find, and what you provide here, will be passed on to Blogger Support, at all possible speed, for their verification.

All responsible bloggers thank you, for your honest contributions.

>> Top

Identifying And Removing HTML / JavaScript / XML Based Malware From Your Blog

Occasionally, in the recently discovered social engineering blog attacks that involve shiny blog accessories, we've seen reports of aggressively protected malware, that's being installed on some blogs.

When a misbehaving HTML gadget is the source of the problem, it's sometimes possible to click on the "Quick Edit" icon for the gadget, and click "Remove". Alternatively, go to "Page Elements", and click on the "Edit" link for the gadget in question. This does not always work so simply, however.

If you can't remove a recently installed gadget, because you get redirected when trying to use the "Layout" button from the dashboard, or the "Remove" button from the "Page Elements" wizard, you may have to be imaginative.
  • Use a well protected browser - minimally, one which blocks scripts from any non Blogger / Google domain, to clean your blog. This is the simplest possibility here.
  • Use an HTTP text proxy, to examine the blog code.
  • Remove the code manually.
    1. Use a protected browser or proxy server to access the blog, and "View Source".
    2. Look in the source, and find the offending gadget / module. If it was installed as an "HTML / JavaScript" or Blogger "Add a Gadget" (XML) gadget, look at the code carefully, and look for "Gadgetnn" and "HTMLnn", where "nn" will be the sequential number for that HTML / XML gadget. This is important.
    3. Manually access the Layout "Edit HTML" wizard for the blog.
    4. Do not check "Expand widget templates" - just "Edit HTML".
    5. Look in the code, carefully, for each "Gadgetnn" or "HTMLnn" entry.
      <div class='widget Gadget' id='Gadget1' />
      or
      <div class='widget HTML' id='HTML1' />
    6. Remove that line of code.
    7. Save.
  • As always, please backup the template before and after you do this cleanup!


If you cannot find an obvious culprit from a quick "View Source", then start removing all "HTML / JavaScript" gadgets, and all XML gadgets (possibly including some installed from the Blogger "Add a Gadget" wizard), installed most recently ("recently", in some cases, being 2 - 3 months back).
  1. Remove a gadget.
  2. Clear browser cache.
  3. Test.
  4. If no improvement, repeat.
Alternatively, just remove all accessories and gadgets - then re install and test everything, one by one.
  1. Add a gadget back.
  2. Clear browser cache.
  3. Test.
  4. If a problem is seen, remove that gadget and identify it.
  5. Repeat.
It's your blog, and your decision which way to go. Barring any obvious suspects, I think I'd try the latter.

If you do put some accessories back, or add anything more, keep an eye on what you add, and check your blog frequently. A lot of the complaints this week appears to involve hacks that may have been installed 2 or 3 months ago. Watch out for smart code, that doesn't activate (reactivate) the hacking immediately when installed.


It appears that some malware may be included in some gadgets installed by the Blogger "Add a Gadget" wizard. If you find removing any Blogger gadgets to provide you any relief, please report your findings in my article Some Hijack Malware Is Being Claimed To Be Blogger Provided. Your details, provided there, would be greatly appreciated.

Blogger Blogs Redirecting To "deplayer.net "

This week, we are seeing a few reports from anxious bloggers that their blogs are redirecting to mysterious URLs containing the domain "deplayer.net". This is somewhat reminiscent of the "searchinvented.com / smashingfeeds.com" hijacks seen during January 2010, and to the "sendptp.com" hijacks seen during February 2010.

Early reports mention the "Real time hit counter" gadget, seen by some as the "Halifax 2011" countdown gadget, or possibly the "Halloween 2010" countdown gadget, as being the gadget most successfully removed.

It's also possible that the "falling snow" and "Tweet This" gadget code has been upgraded to redirect to "deplayer.net". We also have reports of an "ITunes" accessory, a "Martin Luther King Jr Quotes" gadget, and a "yoga journal" / "yoga pose" gadget being involved this month.

As always, I'll caution you to be wary of any third party gadgets. It appears from some comments received that there is protective code in these newest gadgets, which aggressively blocks use of the "Page Elements" gadget GUI removal. If you try to hit the "Remove" button, or hit "Layout" from the dashboard link, and you are redirected, you have 2 choices.
  1. Use "the Page Elements" wizard from a browser / computer which blocks scripts from all third party domains, outside the Blogger / Google world.
  2. Access the Layout "Edit HTML" wizard directly, and remove the entry for the HTML / JavaScript gadget directly from the template code.


After removing the offending code, don't forget to clear cache, before testing your change!


It appears that some malware may be included in some gadgets installed by the Blogger "Add a Gadget" wizard. If you find removing any Blogger gadgets to provide you any relief, please report your findings in my article Some Hijack Malware Is Being Claimed To Be Blogger Provided. Your details, provided there, would be greatly appreciated.


>> Top

Tuesday, February 9, 2010

Valentine's Day Is Coming - Celebrate With Care

This Sunday, many bloggers will celebrate another important holiday in the year - the holiday of celebrated relationships, aka Valentine's Day. Some bloggers will decorate their blogs, using a Valentine's Day standard - falling hearts.

Incautiously chosen relationships cause pain and suffering - some even known as "the gift that keeps on giving", aka an STD. Some incautiously chosen falling hearts decorations have recently been found to cause another "gift that keeps on giving". At least one falling hearts variant, provided free by a hacker, has been reported as causing a blog hijack, noted by several bloggers in Blogger Help Forum as a "sendptp.com" hijack.

Like STDs, the blog hijacks being discovered recently don't always show up immediately. Normally, when people write in to the forum reporting
I´m being hacked! Every time I type the address to my blog, I´m getting redirected!
we advise them to remove any recently installed third party accessories.

Recently, the victims of "falling hearts" and its predecessor "falling snow" have reported having installed their problem accessory some time ago, and just recently noticed the hijack problem. A few accessories are removed, before the problem is discovered and removed.

It's possible that these accessories are being released intentionally, as stealth hijacks. Like STDs, you won't see the problem, until long after the fun is gone.

If you choose a "falling snow", "falling hearts" or maybe "falling flags" (for Fourth Of July?) decoration for your blog, choose with discretion. Don't wait for your readers to write to you
Why do I get a page full of advertisements, instead of your blog?


Remember - security for your readers begins with you.

>> Top

Wednesday, February 3, 2010

Blogger Blogs Redirecting To "sendptp.com"

This week, we are seeing a few reports from anxious bloggers that their blogs are redirecting to mysterious URLs containing the domain "sendptp.com". This is somewhat reminiscent of the "searchinvented.com / smashingfeeds.com" hijacks of January 2010.
I can log in to my blog, but then in a few seconds the page goes blank, and in the URL it says..sendptp.com/ramk2.html...at the bottom it says redirecting and flashing back and forth...


Immediate reports suggest a "falling snow" decoration, apparently acquired before Christmas 2009, as one known culprit. Other reports mention a possible variant, "falling hearts" (Valentines Day?).

http://everything-u-need-is-here.blogspot.com/2008/12/snow-effect-widget-for-blogger.html
http://h1.ripway.com/anand2360375/snow.js


In one case, the "searchinvented.com" / "smashingfeeds.com" redirect is being found on a blog that has a "falling snow" gadget.


I wouldn't bet that this is the only cause of this hijack, but it looks to be one place where you can look, should your blog show this problem.

So far, the problem code has been easily corrected, with a simple removal of the HTML / JavaScript gadget containing the offending code.

After removing the offending code, don't forget to clear cache, before testing your change!

>> Top

Wednesday, January 6, 2010

Blogger Blogs Redirecting To "smashingfeeds.com"

This week, we are seeing a few reports from anxious bloggers that their blogs are redirecting to mysterious URLs containing the domain "smashingfeeds.com". This is somewhat reminiscent of the "blogoholic.info" hijacks of June 2009.
My blog site has been hijacked & redirects to: http://searchinvented.com/?flrdr=yes&nxte=js&dn=smashingfeeds.com&fp=57S


Immediate reports from some bloggers suggest that removal of a possibly recently installed "Tweet This" gadget may be the most likely solution, when faced with this problem.

If you can access the "Page Elements" wizard, and if you have previously installed a "Tweet This" gadget on your blog, that's where you should start. Other blogs have the code installed directly into the template, and will have to use the "Edit HTML" wizard.

As with the "blogoholic.info" redirect, this exploit has been seen to cause corruption of the blog or gadget template, which may redirect you to "smashingfeeds.com" when you try to access the "Edit HTML" or "Page Elements" wizards. If you have this problem, you'll have to find out the blogID, then reference "Edit HTML" or "Page Elements" directly by URL.


In one case, the "searchinvented.com" / "smashingfeeds.com" redirect is being found on a blog that has a "falling snow" gadget.


After removing the offending code, don't forget to clear cache, before testing your change!

>> Top

Saturday, October 24, 2009

Keep Malicious Content Out Of Your Blog

Every day or so, we see reported from concerned bloggers, about unknown content in their blogs.
Where did those ads come from? I didn't add them!
or
How do I keep this other blogger from posting porn links in my blog?
As we add content to our blogs, and make them fun, interesting, and shiny, to attract readers, we risk adding undesirable content. This is a constant problem.

The bad guys are out there - and the more fun, interesting, and shiny your blog is, the more it's likely to have readership, reputation, and value.

The more readership, reputation, and value that your blog has, the more attractive it is to the bad guys. And the bad guys have various ways to attack a given blog.

  • Malicious Comments
  • Malicious Posts
  • Malicious Accessories
  • Malicious Blog Members
  • BlogList / Feed Gadgets

Malicious Comments

One of the easiest way to add third party content to your blog is from allowing comments.

Comments are contributed by people who, at best, you simply do not know. Any content from someone who you do not know can always be malicious, or obnoxious in some way.

Some blog owners will try to identify and block individual commentors. I will continue to insist that anybody who you should fear will not be bothered greatly by anything that you can do here.

You absolutely must moderate comments, or risk having a blog known for hosting malicious links - or worse.

Malicious Posts

Besides comments, posts are a constant concern. If you have a team blog, you have to be able to trust the other members in the blog.

Post moderation, using post editor to publish, isn't an option. Anybody who you make an author can publish what they feel like publishing. You can only moderate posts after they are published, when using post editor.

An alternative to using post editor to publish is Mail-to-Blogger, where contributions are emailed to the blog. If Mail-to-Blogger is setup to publish straight to the blog, and the bad guys figure out your MTB account and password, you'll have malicious content a plenty.

You can moderate before publishing, using Mail-to-Blogger.

Malicious Accessories

Any time that you install third party accessories of any type, you are placing your blog at risk.

Don't be overly paranoid - you have to make your blog interesting to your readers. But do keep the risks in mind.

This is similar to layered security for your computer, which is a related concern here.

Malicious Blog Members

Sometimes, possibly having unwisely installed a third party accessory, the install process may have enabled the addition of an unknown member to the blog. The unwanted content may be added by the attacker, using this unknown blog member.

If none of the above advice offers you an explanation for the existence of unwanted content, check your blog member list.

BlogList / Feed Gadgets

Occasionally, we may Follow a blog where the owner will later decide to try to get more traffic to the blog, and will redirect the blog feed to a cloud of random blogs. If you are Following such a blog, or have such a blog in your BlogList or Feed gadget, you'll see your BlogList or Feed gadget show odd content - and frequent spam.

Navigate» Become author for this Blog