Latest News

Showing posts with label Malware Review. Show all posts
Showing posts with label Malware Review. Show all posts

Train Security Products, And Keep Your Blog Clean

Everybody who uses a computer - and expects to use their computer for any amount of time - has one or more protective products on their computer.

Anybody who publishes a blog, with an audience that has any need for security, is going to receive occasional reports from would be readers.

I can't read your blog! My computer displays an "Unsafe website!" warning!

All computer security products, unfortunately, will occasionally generate false positives. Analysing false positive malware reports is as much a part of every security product, as identifying the actual malware.

If you publish a blog, you need to know how to handle reader malware alert reports.

Know online tools, for researching reported problems.

Google provides 2 websites, for analysis of blog / website malware alerts. Both Google SafeBrowsing, and VirusTotal, are Google products that can help to identify actual problems with blogs and websites.

Besides the two Google products above, I use 3 security analysis websites, which can identify specific security problems in blog / website code. Quttera Online Website Malware Scanner, and Sucuri SiteCheck, and Trend Micro SIte Safety Center, have been useful at various times, when a security problem is reported.

You may, from time to time, use all of these - and possibly others - in identifying and verifying a security problem with your blog, or with blogs and websites that you link. For best results, always specify the canonical blog URL, when requesting security analysis - and when sharing the blog, or individual posts.


Specify the canonical URL.




Not a country local domain.



Know what you need to do, to keep your blog healthy.

As a blog publisher, you will occasionally have 2 jobs to do, when receiving a malware alert report which references your blog.

  1. Verify / identify / remove any actual malicious content.
  2. Report false positives, to the protective service displaying a false positive.


Everybody who publishes a blog, with any reader audience, has seen this advice, or something similar, when surfing their blog.



Know how to keep your blog clean - and your reputation clean.

You have to use online malware analysis services, to identify any problem which you may have created, by installing the latest "gotta have this!" accessory on your blog. And, you have to report any false positive alert, to the owners of any security product, that falsely identifies your blog as a problem.

You do both, to support your readers. You do not want your readers computers hacked, through your inappropriately accessorising your blog - but at the same time,you want your readers to be able to read your blog.

  1. Keep your blog content clean.
  2. Keep your blog reputation clean.

Do both - or you may not have readers, to read your blog.



Any #Blogger blog owner needs to support the blog readers, by publishing a blog clean of any malware, and with a good reputation with the various security products that prevent malicious action by dangerous blogs and websites. Your readers need the ability to use their computers to read your blog - and they need their security to not falsely identify your blog as a problem.

Blog Owners, Unable To Request Restore Of A Blog

One of the more intriguing issues, seen in Blogger Help Forum: Something Is Broken, involves people unable to recover control of their blogs.
I recently changed ISPs, and now I can't login to update my blog.

Occasionally, this issue becomes more complicated, because the blog is deleted - and the owner can't request that it be restored, using the automated review request wizard. Sometimes, the would be blog owner may to try to bypass the current blog recovery policy, by claiming special circumstances.
The blog has been deleted. I received no suspicious activity or password change notification emails, or emails of any kind related to my blog.

What is the story here? Can blogs just disappear from the Blogosphere, without the involvement of the blog owners - and be unrecoverable?

Recovery of a deleted blog starts with the requirement that only a blog owner can un delete a deleted blog - and this is where many mysterious disappearances start.

Only the blog owner can initiate hacked blog unlock review.

Since a Blogger blog is the property of the owner, and the owner is allowed to delete a blog any time required, it would not be right to let people who are not the owner un delete a blog - or demand that the blog be un deleted. To enforce this requirement, Blogger added the dashboard based Restore wizard.

Since only the owner will have the deleted blog listed in their dashboard "Deleted Blogs" list, only the owner can request restore of the blog in question.

Dashboard requested restores have multiple purposes.

The dashboard Restore wizard serves blog owners, with blogs deleted under various circumstances.
  • Deleted by the owner.
  • Deleted by Blogger, as a suspected spam host.
  • Deleted by Google, for TOS Violation.
Any deleted blog will appear in a special dashboard list, "Deleted Blogs" or "Locked Blogs" - when it can be recovered. If the blog is not recoverable by the owner, there may not be a link.

Dashboard requested restores may not always be successful.

There are specific cases where a deleted blog may not be recoverable using the recovery wizard.
A blog locked, pending integrity check, cannot be requested for restore.

Dashboard requested restores start with owner requested unlock.

The owner has to first have the owning account unlocked. Similar to the account recovery process, Blogger / Google will require that the owner provide proof of ownership, before the account will be unlocked. Only if the account can be unlocked, security specialists will inspect each blog owned by the account, and verify that each does not contain evidence of tampering by a temporarily successful hacker.

With blog security review in progress, the blog will be offline and invisible.

While a blog is under integrity check, it won't be listed on the dashboard of the owner - either under "Deleted blogs", "Locked blogs", or "My blogs". Neither the owner, nor any third parties, will be able to do anything except wait, patiently.

Blogs found to contain malware can be locked as TOS Violations, with the owner later required to remove the malware found. This requirement will apply for malware installed by the owner (intentionally, or unintentionally), or for malware installed by a hacker.

With blog malware review in progress, the blog will be offline - but visible.

With a blog locked pending malware removal, the owner is given the benefit of the doubt, and allowed to simply remove the malware, no questions asked. In some cases, Blogger may be able to assist by providing specific identification of the malware found - but this won't happen, consistently.

A blog owned under another account must be un deleted by the owner of the other account. Again, only a blog owner can have a blog restored - whether deleted by an owner, or by Blogger / Google.

A blog deleted over 90 days previously cannot be recovered. It won't appear on the dashboard of any (former) owner, since it can't be recovered.
It's dead, Jim.

Either way, you the owner have to wait for review to complete.

The basic rule is simple. If your blog was deleted, and if you're able to un delete it (or request un deletion), you'll have a link on your dashboard. If a blog is not listed on your dashboard, you can't request, with any predictable success, that it be un deleted - any more than you can demand that a non deleted blog be restored to your control.

Some Blogger Blogs Being Locked As Malware Hosts

For a long time, we've been dealing with various malware / spam mitigation issues, in Blogger Help Forum: Something Is Broken.

Recently, malware detections, long simply identified as "Malicious JavaScript" in the well known Spam Appeal Guidelines, was given its own identity, and a separate classification / appeal process. We're now seeing several common types of JavaScript, included in blogs which are typically mentioned in forum reports.

It may be helpful to describe some examples of JavaScript code being seen, so blog owners can avoid making the same mistakes, by not including these scripts in their blogs.

There are several common types of JavaScript applications, found in many blogs with the owners requesting review / unlock action.
  1. CPA / Cost Per Action.
  2. Multiple popups, such as a generic "Welcome!", followed by "Like my blog, before you read it!".
  3. Password protection, on a page basis.
  4. Security warning popups, suggesting that you need to install a recommended security software.
  5. Social networking popups, demanding "Like my blog, before you read it!".
  6. Traffic Redirection, targeting other blogs / websites.
  7. Traffic redirection, targeting the canonical URL for the host blog.


CPA / CPALeads / Cost Per Action, and similar online marketing terminology, involves providing a reward for viewing a blog, or for subscribing to the blog feed. Some CPA scripts may be used to collect email addresses, also known as "email address mining", later used for hacking activity or spam distribution.

CPA scripts present another problem. Since Blogger blogs are intended to reward the readers by providing interesting and unique content, blogs which use CPA may be improperly designed or maintained. Blogger wants the blog owners to publish blogs which entertain or inform their readers - not blogs which require artificial or ingenious techniques to generate traffic, and visitor activity.

Multiple popups, such as an initial "Welcome to my blog!" greeting, followed by the well known FaceBook "Like my blog, to read my blog!" demand. If multiple popups should become an established practice, it's possible that malware producers could enjoy this technique, to conceal a malware installation.

Password protection, on a page basis, is an attempt to make a blog (or blog portion) private, by using a password. This protection is easily defeated, as the password is provided in the page (post / template) code, as plain text - and can easily be identified by anybody knowing how to view page source as text.

Besides the "protection" being easily bypassed, this is a problem because security scanning programs - such as the malicious scripting bot - can't pass through JavaScript code easily. When encountering this JavaScript application, your blog will be righteously classified, as a malicious script host.

Security warning popups, suggesting that your computer is infected - and offering, for immediate installation, the perfect tool to remove the claimed malware. Security experts know that this is similarly a favourite malware installation technique, where the computer owner would give permission to have the offered software installed - and the installed software would later install a botnet client or similar malicious trash.

Social networking popups are an arrogant way of wasting your readers time, and guaranteeing eventual malware classification of your blog. Popular among some WordPress blogs, the circular FaceBook "Like my blog, to read my blog!" demand is a good way to make genuine readers go elsewhere.

If you want genuine readers, who read a Blogger blog because of thoughtful, unique content, you will not get them by demanding that they boost your FaceBook popularity, before reading your blog. This is just another way of buying "Likes" - and it belongs in WordPress, not in Blogger.

Traffic Redirection, targeting other blogs / websites is a technique attempted by many hackers and spammers. The use of some blogs as gateways, leading to redistributors, which in turn lead to payload blogs or non Google websites, is part of many hacking / spam attacks. Google is trying to restrict the use of Blogger blogs as malware / spam hosts - and actively prevents scripts, which only shuffle readers from one blog to another, without choice.

Even though Blogger will not encourage you to move your blog, to Tumblr, Weebly, WordPress, or wherever, you are allowed to do this - if you feel the need.
Hello, faithful readers:

This blog is now hosted at my new blogging host. Please update your blog lists and bookmarks!
If you must do this, it's OK to post a notice, in your Blogger blog. You can even put a link, to the new blog, in the notice. You just can't use JavaScript, to automatically redirect the reader to the new blog.

Traffic redirection, targeting the canonical URL for the host blog, is a technique used by some blog owners who perceive Country Code Alias Redirection to present a problem. Some accessories installed on their blogs, and various non Google services which may be used to provide activity on their blogs, may not properly reference the canonical URL tag included in all Blogger blogs.

Since Blogger / Google wants all Blogger blog owners to benefit from improved world wide access to Blogger blogs, blogs which employ automatic canonical URL redirection may damage the effect of CC alias redirection. Blogs which host scripts which immediately redirect readers to the canonical URL, and are considered undesirable by any host government, may force an offended host government to block the entire Blogger service, in their country.

To prevent malicious misuse of Blogger by hackers and spammers, and to encourage effective long term use of Blogger by legitimate blog owners, Blogger / Google may detect any blogs which use these types of scripts as part of their general malware / spam classification strategy. Given the ability and willingness of the blog owner, to remove the JavaScript code in question, most blogs can be returned to service - but each blog will remain offline, until the removal is verified.

It's to everybody's benefit to identify, and to avoid use of, these scripts in our blogs, before it's too late. If your blog contains one of these scripts, why not remove the problem now, instead of waiting until you too have to post your problem report, in the forum
Help me! My blog was just locked for
MALICIOUS JAVASCRIPT
What do I do, now?

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code