Latest News

Showing posts with label Proxy Server. Show all posts
Showing posts with label Proxy Server. Show all posts

Dynamic Template Blogs, And Some Proxy Servers

Some Blogger blogs cannot be viewed, in some proxy servers.

Proxy servers are useful, when diagnosing connectivity and other blog display issues. They are more useful, though, when the content of the blogs being diagnosed does not contribute to the problems.

The reported discrepancy appears to start with blogs published using dynamic templates.

Comparing blogs displayed using Anonymouse and GeoPeeker, we frequently see a discrepancy in display content.

One discrepancy appears to involve blogs published using dynamic templates. Both Anonymouse (a single location proxy) and GeoPeeker (a multi location proxy display) have been useful, repeatedly, in diagnosing and reporting multiple issues.

I first used GeoPeeker, as part of the EU Cookie Advice Banner discussions. I have used Anonymouse frequently, in demonstrating and diagnosing various blog problems.

First, examine this blog.

This blog, blogging.nitecruzr.net, is published to a non dynamic template. It is visible, in multiple proxy server displays.

Here's a display from Anonymouse, showing this blog, "blogging.nitecruzr.net".

http://anonymouse.org/cgi-bin/anon-www.cgi/https://blogging.nitecruzr.net/


Anonymouse, showing this blog, "blogging.nitecruzr.net".



Here's a display from GeoPeeker, showing this blog "blogging.nitecruzr.net".

https://geopeeker.com/fetch/?url=blogging.nitecruzr.net


GeoPeeker, showing this blog "blogging.nitecruzr.net".



Now, examine my blog, published using a dynamic template.

My Musings blog, musings.nitecruzr.net, is published to a dynamic template. It is visible, in some proxy server displays.

Here's a display from GeoPeeker, showing my dynamic template published blog "musings.nitecruzr.net".

https://geopeeker.com/fetch/?url=http%3A%2F%2Fmusings.nitecruzr.net%2F


GeoPeeker, showing "musings.nitecruzr.net".



Here's a display from Anonymouse, showing "musings.nitecruzr.net".

http://anonymouse.org/cgi-bin/anon-www.cgi/http://musings.nitecruzr.net


Anonymouse, showing "musings.nitecruzr.net".



Where's the beef, Clara?

And a third blog, also published using a dynamic template.

A third blog, thestimulatedbrain.blogspot.com, is published to a dynamic template. It is visible, in some proxy server displays.

Here's a display from GeoPeeker, showing a third dynamic template published blog, "thestimulatedbrain.blogspot.com".

https://geopeeker.com/fetch/?url=thestimulatedbrain.blogspot.com


GeoPeeker, showing "thestimulatedbrain.blogspot.com".



Here's a display from Anonymouse, showing "thestimulatedbrain.blogspot.com".

http://anonymouse.org/cgi-bin/anon-www.cgi/https://thestimulatedbrain.blogspot.com/


Anonymouse, showing "thestimulatedbrain.blogspot.com".



The owner of "thestimulatedbrain.blogspot.com" points out that many Blogger blogs, and non Blogger websites do display properly, using AnonyMouse and similar proxies. I will add details, as they are provided.

I'll check out more blogs, and more proxy servers, as the week continues.

I'll continue, by examining more blogs - dynamic template and non dynamic template - possibly using additional proxy servers - as time permits.

I'm not sure how many of these discrepancies can be - or should be - handled by Blogger Engineering. That said, I note a suggestion by a Blogger Support expert, that the opportunity be provided to Blogger Support, to diagnose and enhance the dynamic templates.



It appears that some #Blogger blogs do not display properly, using some proxy servers. The discrepancy appears to involve blogs published, using dynamic templates.

This makes verification of world wide blog visibility confusing, to some blog owners.

HTTPS Availability For All "blogspot.com" Blogs

The rollout of SSL, for "blogspot.com" published blogs, continues.

All "blogspot.com" published blogs will now offer HTTPS connectivity, to the reader. The choice, offered to the blog owner, is now whether to force every reader to use SSL - and the dashboard option is now labeled "HTTPS Redirect".

You can force your readers to use SSL, to access your blog - but will that make them more secure?

Every blog will offer SSL connectivity, to readers who use "HTTPS:" URLs.


The dashboard option is now "HTTPS Redirect".




The choice is now whether to force "HTTPS:" upon each reader - or allow some to continue to read, using "HTTP:".



If you select HTTPS Redirect, you will be limiting your reader population.

Some readers access our blogs, by using free proxy servers - and most proxy servers, when they offer HTTPS, offer it as a premium (with a paid subscription). You are entitled to require everybody to use SSL, if you wish - but you may see reader activity drop, as readers using free proxies find other blogs and websites to read.


Everybody will see the "HTTPS:" alias - with "HTTPS Redirect" set to "Yes".



My personal favourite connectivity diagnostic tool, Rex Swain HTTP Viewer, won't work with blogs that only support "HTTPS:" connectivity.

http://www.rexswain.com/cgi-bin/httpview.cgi?url=http://nitecruzr-test-ssl.blogspot.com/&uag=Mozilla/5.0+(X11%3B+CrOS+armv7l+7834.70.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2623.112+Safari/537.36&ref=http://www.rexswain.com/httpview.html&aen=&req=GET&ver=1.1&fmt=AUTO


No "HTTP:" diagnostics, for "HTTPS:" redirected blogs.



The "www" alias of a "blogspot.com" published blog will not work, using SSL.


Using the "www" alias, of a "blogspot.com" URL, will not work - with "HTTPS Redirect" set to "Yes".



Forcing SSL will not make your blogs readers more secure.

Use of "HTTPS Redirect", while nominally making your readers more secure, will limit access to your blog.

  • Readers, using proxy servers, may not be able to access your blog.
  • Diagnostics of blog problems, using proxy servers, will be limited.
  • Readers who bookmarked your blog, using the "www" alias, will not be able to access it.
  • Readers who are vulnerable to hijacking, when using "HTTP:", will not access your blog.

Offering SSL connectivity is good for everybody - but understand the limitations.

Enjoy offering SSL connectivity - and improved search engine reputation. But keep it in perspective.

People who explicitly use "HTTP:" to access your blog, and are vulnerable to hijacking, will see an imposters blog - even if your blog forces them to use SSL. Only people who explicitly use "HTTPS:", to access your blog, will predictably see your blog - and they won't benefit from being forced to use SSL.



As #Blogger continues the rollout of SSL to "blogspot.com" published blogs, they have changed the HTTPS option. All blogs which support SSL will offer "HTTPS:" connectivity, and the option will be to allow explicit access, using "HTTP:".

You may do well to consider what benefits you get, from forcing your readers to use SSL to access your blog.

Blog Owners Report Mysterious Blogs Added To Their Dashboard Blog List

We are seeing a small but steadily increasing stream of problem reports, in Blogger Help Forum: Something Is Broken, from Blogger blog owners, wondering where these mysterious blogs, being added to their dashboard "My blogs" list, are coming from.
Is anyone else experiencing random blogs being added to their dashboard? I login, and I notice that many blogs have been made - and they're all with names that are just a jumble of letters and numbers, but no posts. All of them lead to the same blog though.


Here's a random list of the names of 7 such blogs, which were recently created in the "blogspot.com" name space. If you wish to examine these blogs, and these have not yet been deleted by the Blogger anti spam processes, I strongly advise that you use a proxy server, or similar isolation technique. Never examine any hacking / spam attack component, unprotected.
yyxfkfgpiy
x24xd2wtu1
4o4fq0rqp9
26djmc3xyh
m9s5tdor2l
h62wo5uthr
bsojvu43gk

Some blog owners are seeing dozens of these mysterious blogs. Adding to the confusion, a couple owners have even thought that their legitimate blogs have been replaced. Fortunately, what is happening is that the legitimate blogs are still there - just not visible in the noise.

When queried for details, many owners report having received, and accepted, an offer involving FaceBook, and the suggestion to "Change your colors". Apparently, if logged in to both Blogger / Google, and FaceBook, this mysterious "FaceBook app" will simply setup quantities of BlogSpot hosted spam blogs, frighteningly reminiscent of blogs created as part of the long ago observed Russian Business Network spam blog farms.

Each blog created has the same initial content - a display, with the offer to "Change your FaceBook colors". The link to accept the offer then leads to a non Google website, which installs the malware, which creates the mysterious spam blogs, in mass quantity. For your examination, here is one example spam blog - which may or may not currently be online, using a proxy server link.
http://anonymouse.org/cgi-bin/anon-www.cgi/http://yyxfkfgpiy.blogspot.com/


We don't yet know what, if anything, is being installed on the computer used in the blogs creation - nor how malicious the virus is, when installed on one's own computer. Our advice is simple - avoid becoming a victim. If you are receiving invitations for this service, it's possible that your FaceBook friends, supposedly sending the invitations, are the current victims. If you ignore the offer, you should be safe.

It's possible, too, that this attack is enabled by the massive attacks of seemingly purposeless spam comments, being published on various blogs.

If you are concerned about this situation, you might want to check all of your blogs for unfamiliar code - then review your current protection, and even consider using Google 2-step verification.

>> Top

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code