Latest News

Showing posts with label Strategic Malware. Show all posts
Showing posts with label Strategic Malware. Show all posts

Blogger Blogs Redirecting To "opromo . com"

This week, we're seeing a new stream of problem reports, from blog owners whose blogs are, once again, mysteriously redirecting their readers to unknown destinations.
When I open my blog, it automatically directs to another search engine display.

This appears to be yet one more gadget, willingly installed by many Blogger blog owners, which is now redirecting uninterested viewers. The target of the redirection, this week, is a parked domain website (ie, "search engine display") - for a product which was apparently installed, willingly, by the blog owners.

It appears that the "opromo . com" free visitor meter is the latest victim of expiring domain registrations.

Overview for opromo.com

Registrar Info
Name PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server whois.PublicDomainRegistry.com
Referral URL http://www.PublicDomainRegistry.com
Status clientTransferProhibited

Important Dates
Expires On May 09, 2013
Registered On May 09, 2006
Updated On May 09, 2013
People who earlier installed the Opromo free visitor meter will need to uninstall it, as it's apparently no longer operational. Reliable replacements would be SiteMeter and StatCounter - as well as Google Analytics.

From what we've seen, identification and removal of the problem code seems to be straightforward - just access the dashboard "Layout" menu wizard, find the gadget identified, and remove it.

As always, you are advised to clear cache and restart the browser, after removal and before testing for success. If the gadget makes your dashboard redirect, before you can remove the redirecting code, use a well protected browser, like Firefox with NoScript, to block the redirection.

>> Top

Blogger Blogs Being Hijacked By The Sociable Gadget

We're seeing a steady stream of reports, from blog owners in Blogger Help Forum: Something Is Broken, from Blogger blog owners, reporting the latest hijacking of their blogs.
My blog is being redirected to a search engine display.
or
My blog has a porn popup attached!
These are all blog owners who have installed the latest hack, willingly distributed by Blogger / Google.

This appears to be yet one more gadget, intentionally installed by many Blogger blog owners, which is now redirecting unwilling viewers. The redirection target is a website which provides commercial advertisements for various Internet services, which creates a variety of symptoms, as reported in the forums.

The Sociable gadget appears to be a Blogger accessory installed from the Blogger "Add a Gadget" wizard, when selected intentionally by many Blogger blog owners.

As with many reported hijacks, access to the Blogger Layout wizard appears to be affected. If you need to remove this code from your blog, you may find yourself unable to use the Layout wizard. In this case, you will need to use Firefox with Noscript - or a similarly well protected browser - to prevent the redirecting code from executing.

After removing the identified code from your blog, as always, clear cache and restart the browser. Finally, I'll remind you again, to please be particular - only install third party code from trustworthy providers.

>> Top

Blogger Blogs Redirecting To "scmplayer . net"

This week, we're seeing a new stream of problem reports, from blog owners whose blogs are, once again, mysteriously redirecting their readers to unknown destinations.
When I open my blog, it automatically directs to another website, which is SCM Music Player.

This appears to be yet one more gadget, willingly installed by many Blogger blog owners, which is now redirecting uninterested viewers. The target of the redirection, in this case, is a website which is simply a commercial advertisement - for the product which was apparently installed, willingly, by the blog owners.

The website in question, "scmplayer . net", unlike some previous episodes of this nature, does not appear to be expired.
Overview for scmplayer.net

Registrar Info
Name GODADDY.COM, LLC
Whois Server whois.godaddy.com
Referral URL http://registrar.godaddy.com
Status clientDeleteProhibited, clientRenewProhibited,
clientTransferProhibited, clientUpdateProhibited

Important Dates
Expires On March 25, 2014
Registered On March 25, 2011
Updated On December 13, 2011

If we use a text only browser, such as an HTTP trace utility, the problem code is easily identified. Here's a redacted example, taken from the latest forum problem report.
<div class='widget HTML' id='HTML1'>
<div class='widget-content'>
<!-- SCM Music Player http : // scmplayer . net -->
<script type="text/javascript" src="http : // scmplayer . net/script . js"
data-config="{'skin':'skins/aquaOrange/skin.css','volume':50,'autoplay':true,'shuffle':true,'repeat':1,'placement':'top','showplaylist':false,'playlist':[{'title':'Waves','url':'http://youtu.be/IFS0Eo1eh6Y'},{'title':'Money Trees','url':'http://youtu.be/jSXiNdTbTA4'},{'title':'Keep it Moving','url':'http://youtu.be/XqRC_Fh--js'},{'title':'Find Away','url':'http://www.youtube.com/watch?v=KS6zq6_iMCk'},{'title':'Do your Love','url':'http://www.youtube.com/watch?v=2zVwbgXaMRo'},{'title':'Bitch Don%27t Kill My Vibe','url':'http://www.youtube.com/watch?v=OcYvaLIgjTk'},{'title':'True Livin','url':'http://youtu.be/wMFHqqiR3Co'}]}" ></script>
<!-- SCM Music Player script end -->


From what we've seen so far, identification and removal of the problem code seems to be straightforward - just access the dashboard "Layout" menu wizard, find the gadget identified, and remove it.

As always, you are advised to clear cache and restart the browser, after removal and before testing. If the gadget makes your dashboard redirect before you can un install the misbehaving code, use a well protected browser, like Firefox with NoScript, to block the redirection.

>> Top

Check Your Template, And Look For Unfamiliar JavaScript Code, Following Odd Blog Behaviour

Recently, we've been seeing some odd problem reports in Blogger Help Forum: Something Is Broken, suggesting deviously hijacked blogs.
My blog is requesting me to login, using a user name and password, when I view it.
Given the URL of the window requesting the login, it's a simple matter for us to use the right forensic Internet software, and to locate a relevant snippet of code, frequently installed as part of the blog template.

Sometimes, when we reply to the blog owner with advice to remove a bit of dodgy code, we get a response suggesting disbelief. Our advice
Use the Template Editor, and remove the highlighted code snippet.
may receive a confused or skeptical response.
Where did that bit of code come from? I never installed that!
How did the code in question get installed? Discussion of one possible scenario may require thinking outside the box. Not every unrecognised blog change is being caused by memory loss by the blog owner, after an intentional accessory install or template tweak.

Looking at the subject / theme of some blogs involved in recent problem reports, we're seeing a beginning of a trend, which may indicate a new - and very subtle - blog hijacking technique. We know that Blogger blogs are subjected to brute force password guessing attacks, and we know that Blogger / Google has to consider the possibility that a brute force attack detection is made after the attack was successful.

Current blog security, and defense against blog hijacks, involves detection of hijack attempts, by Google Security. It's possible that some blogs, with some owning Blogger accounts and passwords, are more vulnerable to sophisticated password guess hacking.

When you login to Blogger or Google, you hopefully know the right account name and password, and are generally able to get logged in - after maybe one or two mistakes. You learn, soon enough, that if you have to guess your account name or current password - and you require more than a couple tries - you may have to solve yet another CAPTCHA, or request account unlock, to continue.

The ever unpopular CAPTCHA / locked account comes from Google, detecting a possible brute force attack in progress, and protecting your account and your blogs. A Blogger blog, with its content providing enough clues, combined with a simple account password that is easily guessed, may allow an experienced hacker to login to your account in one or two tries, without being detected by Google attack monitors.

It's alternately possible that some attacks are being conducted by very patient hackers, who are able to use days, and / or thousands of different computers, to conduct a throttled brute force password attack. Again, just attack without providing a detectable pattern.

This may help to explain the mysterious spam blog setups, of last year.

A hacker, able to login to a Blogger account without being detected, could install small changes in a blog template without ever being discovered. The blog owner would never discover subtle template changes, made by an easily satisfied hacker.

Finally, install latent code that does not activate immediately, as we observed during Winter 2009 / 2010, so no blogs show symptoms until the hack is installed on thousands of blogs. If one or two blog owners discover the odd code in their blogs, who would ever suspect their blog being part of a massive cloud of victims?

If you report odd behaviour by your blog, you write to Blogger Help requesting advice, and you are advised to remove a bit of dodgy code from the template - and you do not remember having installed the noted dodgy code - you may want to review your Blogger / Google password, and make the password harder to guess. Better still, start using 2-step verification for logging in to your Blogger / Google account.

>> Top

Use A Well Protected Browser, To Block Redirecting From Misbehaving Code And Gadgets

Regularly, in Blogger Help Forum: Something Is Broken, we advise people about problem code or gadgets in their blogs.

Generally, this follows reports by blog owners, that their readers are being redirected to unexpected and unwanted blogs and websites, from their blogs. Sometimes, we get the reply
I can't remove the code. Every time I login to Blogger, I am redirected, just as my readers are being treated!

When we see the latter complaint, we recognise yet one more blog owner who does not know how to properly protect himself, from malicious code and websites. Most people, who know about Layered Security, know that proper browser security is an essential complement to a properly chosen and maintained anti malware filter.

Many people, who care about browser based security, use Firefox with NoScript.

This combination provides Unix level security, "deny by default, permit by exception". Simply install NoScript as an add-on, to Firefox, to get started. Alternately, you may use Chrome with ScriptSafe, or Opera with NotScripts.

When using your browser with a script filter, there will be specific Blogger / Google websites which you should trust, and others which you should not trust.

Every time you surf to a different website - and decide that the owners of the website, which you are now viewing, have your best interests in mind - configure NoScript to allow that website, to display properly on your computer. When you find that a trusted host website does not display properly, examine the NoScript taskbar and the list of websites used by the host website. Look at the NoScript Options menu, carefully. Allow specific websites which you trust, and Forbid all other websites which you do not trust.

Deciding which websites to trust, based on their presence in the NoScript Options menu, will be a learning experience for a while. For some host website pages, which use a large number of unfamiliar websites, you may have to carefully select to "Temporarily allow all this page" - or you can "Temporarily allow" each single website, one by one, until the host website page displays properly.

When you decide to (permanently) "Allow" any website, that website will be "Allowed" on all other host websites where you may surf. Conversely, any website which you never select to "Allow" - such as the problem website which is providing the misbehaving code - will never execute on your computer again. This will prevent redirection on your computer, allow you to safely use the Blogger dashboard, and edit or remove any dodgy code which may be part of your blog.

After removing any dodgy code from your blog, always clear cache and restart Firefox, to test the effects of your editing.

>> Top

Add A Simple "Recent Comments" / "Recent Posts" Gadget To Your Blog

The recently observed problems with some third party gadgets, previously added by many blog owners to their blogs, leaves these blogs lacking various accessories.

One of the gadgets identified is the "Recent Comments" / "Recent Posts" gadget pair. For many blog owners, this gadget is not impossible to replace.

Blogger provides us with a native accessory, called a "Blog Feed" gadget, which will provide acceptable "Recent Comments" and "Recent Posts" functionality, for many blog owners.

Look at the sidebar of this blog, for "The Real Blogger Status - Comments", and "The Real Blogger Status - Posts". Those are "Recent Comments" and "Recent Posts" gadgets, which are based on the Blogger supplied "Feed" gadget - which is not a third party accessory, and is not subject to future third party peccadilloes.

To make your new gadget, start with the URL of the blog feed desired.

Add a Blogger supplied Feed gadget, using the "Add a gadget" wizard, in the dashboard Layout display.

This is the URL of this blog.
http://blogging.nitecruzr.net

This is the URL of the blog comments feed.
http://blogging.nitecruzr.net/feeds/comments/default

This is the URL of the blog posts feed.
http://blogging.nitecruzr.net/feeds/posts/default

Setting up a "Blog Feed" gadget is simple enough.

  1. Add a "Feed" gadget (Only select the "Feed" gadget, "By Blogger"!!!), using the "Add a gadget" wizard.
  2. Plug in the Feed URL (see my examples above), and Continue.
  3. Review / change the options offered, and Save.
  4. Test your new blog accessory - provided by Blogger - with no future hacking activity anticipated.

Avoid any similarly named gadget not "By Blogger" - distributed from "Add a Gadget", or from a private blog or non Google website.

And, you're done. Wasn't that simple?

Blogger blogs redirecting to "scrapur . com"

This week, we've seen several reports in Blogger Help Forum: Something Is Broken, from Blogger blog owners, reporting the latest hijacking of their blogs.
My blog is being redirected to a spam site - was it hijacked?


As is all too frequently the case, the redirection appears to come from third party code or gadgets, willingly installed by the blog owner. Examination of the website in question appears to indicate a long expired domain.
This domain name expired on Nov 7 2012 11:32:24:000AM
It's possible that, right now, this is not a maliciously planned hijack - though any expired domain can be re purchased for a devious or malicious purpose.

In several cases, the redirecting code appears as part of an installed XML gadget, a version of "Recent Comments". In other cases, we have observed naked JavaScript code, installed directly into the blog template. Here are identified examples - though you may see other variants.
<script style="text/javascript" src="http : // scrapur . com / index / wp-content / uploads / 2008 / 04 / rc . asp"> </script>
or possibly
<script src='http : // scrapur . com / index / wp-content / uploads / 2008 / 02 / smile . js' type='text/javascript'></script>
(Note the URLs have been modified, to prevent search engine indexing of a potentially malicious domain).

Use of a text proxy, such as Rex Swain's HTTP Viewer, when run from any browser, will allow you to safely examine the blog source, without interference by the redirecting code. In this case, simply load your blog using the URL, then use the browser test search, for "scrapur", in the proxy log. This will let you see if the code in question is part of an HTML gadget - or it is installed directly in the template.

As with many reported hijacks, access to the Blogger Layout and Template wizards appears to be affected. If you need to remove this code from your blog, you may find yourself unable to use either the Layout wizard (to remove an identified gadget) or the Template wizard (to remove directly installed code). In this case, you will need to use Firefox with Noscript - or a similarly well protected browser - to prevent the redirecting code from executing.

After removing the identified code from your blog, as always, clear cache and restart the browser. Finally, I'll remind you again, to please be particular - only install third party code from trustworthy providers.

>> Top

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code