Showing posts with label Blog Hijack. Show all posts
Showing posts with label Blog Hijack. Show all posts

Thursday, February 6, 2020

Blogger Blogs Redirecting To Blogrolling.Com #2

Slightly less than 1 calendar week ago, nosotros started seeing reports inward Blogger Help Forum: Something Is Broken, suggesting all the same to a greater extent than or less other hijack of Blogger spider web log readers.
When trying to persuasion my spider web log I am redirected to http://rpc.blogrolling.com. Has my spider web log been hacked?
The titles (questions) are phrased thus differently, too posted inward such numbers, inward the forums (and every bit comments to my blog), that suggests that nobody publishing these questions sees how many other people are reporting the same problem. And fifty-fifty amongst many of us knowing virtually the problem, too having developed a unproblematic diagnostic procedure, the reports hold coming.

Why create nosotros run into thus many reports, virtually 1 unproblematic problem?

Obviously, the diagnostic physical care for is non obvious, fifty-fifty amongst my repetitive too seemingly copied too pasted response.
Using the "Page Elements" GUI wizard, take away gadget HTMLxx from your blog.
With the proper technique, identifying the work gadget "HTMLxx" (with "xx" expected to vary from spider web log to blog), left over from a 3rd political party accessory that stopped working over a twelvemonth ago, takes less than five minutes.

Identifying the work gadget is quite straightforward, too requires solely 1 tool - any "text only", or properly hardened, browser.
  1. Load the contents of the spider web log inward question, into whatsoever browser that is not dependent champaign to JavaScript based redirects.
  2. View the origin of the blog.
    1. If this is a hardened browser, that displays the spider web log contents graphically (such every bit what you lot are viewing, correct now), you'll ask to purpose the "View Source" carte du jour option.
    2. If this is a text solely browser (or text based proxy display), you lot volition already live on looking at the source.
  3. Search for the commutation text - "blogrolling".
  4. Look at the typical search result.
    <script language="javascript" src="http://rpc.blogrolling.com/display.php?r=aaed69f2505e892af783636f3f5a204c" type="text/javascript"></script>
  5. Slightly inward a higher house the search result, you'll uncovering the gadget identified.
    <div class='widget HTML' id='HTML3'>
  6. And at that topographic point it is.
    HTML3
  7. And now, my advice.
    Using the "Page Elements" GUI wizard, take away gadget HTML3 from your blog.
  8. Now, it's your plough (since you lot ain the spider web log amongst the misbehaving gadget, HTML3).
    1. Use "Page Elements".
    2. Find gadget "HTML3".
    3. Edit, too then Remove, HTML3.
    4. Done.
  9. What to a greater extent than advice is needed? Get to work, on your blog.
The details - such every bit "xx" - volition differ - but the procedure, in 1 lawsuit you lot larn it, tin live on done inward two minutes.

Since I dedicated this blog, long ago, to publishing details virtually Blogger blogs
Chuck, everybody knows that!
yet
Why did you lot hold off thus long to write this article?
The schizophrenic abuse of my patience continues.

>> Top

Monday, February 3, 2020

If Yous Gave Command Of Your Spider Web Log To Individual Else, It's Non Your Blog

We run into this naive question, from fourth dimension to time, inwards Blogger Help Forum: How Do I?.
I added my friend every bit an administrator, to my blog. He changed permissions, locked me out, in addition to straight off I don't bring access. Can Blogger teach my weblog back?
Here, nosotros bring bad intelligence for you.

The solely mode you lot tin dismiss prove ownership of a blog is yesteryear having control.

If you lot give upward command of your blog, it becomes mortal else's blog. If you lot desire command of the weblog restored to you, this becomes an internal dispute betwixt you lot (the old owner), in addition to your previous friend (the electrical current owner).

Blogger Support can't ask themselves inwards internal disputes.

Once again, nosotros bring to remind you lot to solely grade command of your blog, to people you lot tin dismiss trust.

The weblog that you lot salve may travel your own.

Saturday, February 1, 2020

Getting Rid Of The Mystery Blogs Inwards The Reading List

A few folks discover unexpected content inwards their Reading List.
How produce I destination Following that blog? It's non listed, inwards "Manage Blogs I'm Following", in addition to I never Followed it!

When you lot cheque the "Manage Blogs I'm Following" wizard, you lot teach a listing of the blogs that you lot Follow, amongst the Settings link for each.

Oddly enough, these mysterious blogs - that you lot can't retrieve Following - won't survive listed, nether the observed title, on the "Manage" magician display.

Some blogs, for i argue or another, volition redirect their feeds to exactly about other weblog or website.

Other blogs may merely no longer reveal a feed. In exactly about cases, this volition piece of work out people seeing completely unrecognised - or unwanted - content, inwards their Reading List.

Fortunately, it's non complicated to discover these mystery blogs, in addition to withdraw them from your Reading List.

Any unknown content, listed inwards the aggregated reading list, volition every bit good survive listed inwards an private entry underneath "All blogs". Just teach downwardly the list, overlooking the titles, i weblog at a time, in addition to you'll discover the unwanted content.

Once you lot lay the titles of the blogs that comprise the unwanted content, teach to the "Manage Blogs I'm Following" wizard, discover the occupation blogs past times title, in addition to remove the unknown blogs.

Then contact the weblog owners, in addition to enjoin them the error that they made. Alternately, report the gullible weblog owners, in addition to thence Blogger Support tin inform the owners.

Friday, December 13, 2019

It's The Vacation Flavor Again, As Well As It's Fourth Dimension To Decorate Our Blogs

The Winter Holiday flavor is approaching, in addition to this calendar week we're seeing queries past times but about spider web log owners, getting ready.
Why create my readers meet a search display - instead of my blog?
and
How create I larn far snowfall on my blog?
and a few owners, in addition to visitors
Why does my browser freeze or lag when viewing this blog?
Many spider web log owners, who issue craft, family, in addition to personal themed blogs, but accept to brand their blogs reverberate their vacation wishes for their readers. Only later, they may re intend their decision.

Some of us inwards Blogger Help Forum: Something Is Broken recollect this flavor final year, though non fondly. Many spider web log owners, having previously decorated their blogs alongside Falling Leaves (Thanksgiving), Falling Snow (Christmas), in addition to subsequently Falling Hearts (Valentines Day), flora themselves spending fourth dimension inwards the forum, asking why nobody could meet their blogs. The reply that they flora was that their blogs, previously decorated alongside the Falling Leaves / Snow / Hearts animations, were redirecting their readers to websites which were non relevant to their readers interests or needs.

The owners of computers poorly protected against malicious software installation, when redirected from their friends vacation decorated blogs to the hijackers websites, flora themselves subsequently consulting their local figurer guru. The gurus spent fourth dimension (not e'er without expense) removing but about unwanted software, installed past times the hijackers websites.

The charming affair close the hijacks is that the Falling Leaves / Snow / Hearts gadgets, when installed, did non at in ane trial redirect the diverse visitors to the malicious websites. This especial appeared to betoken really devious planning past times the hijackers, who had waited, patiently, acre thousands of spider web log owners had installed their trickery, earlier activating the hijack.

This caused but about confusion inwards the forums. H5N1 normal occupation of job diagnosis - which many of those of you, who accept requested assist here, may recognise - is the brief in addition to really unproblematic question
What changes accept you lot made to the blog, recently?
Most spider web log owners, naturally, answered
Nothing interesting.
Later, when a malicious Falling Leaves / Snow / Heart accessory was identified, alongside the stern advice
Get rid of that!
The reply would be
I installed that vi months ago! Surely, that's non the problem??!!

Only after large numbers of people had reported problems alongside their blogs, in addition to nosotros flora the Falling Leaves / Snow / Heart accessory on the job blogs, did nosotros suggest everybody
Remove all Falling Leaves / Snow / Heart accessories, from your blogs, immediately.

Besides the blatant spider web log hijack threat, there's but about other effect for you lot to consider. The animation - falling hearts / leaves / snowfall - requires intense processor activity. If people halt visiting your blog, because their browsers freeze up, you'll demand to revisit your decorative decision.

So, equally this years vacation flavor starts, we'll suggest everybody to beware of whatsoever animated accessory, such equally (but non express to) Falling Leaves / Snow / Hearts. Install whatsoever 3rd political party accessory alongside assist in addition to discrimination. And recollect everything installed, for a long fourth dimension afterwards.

>> Top

Friday, November 29, 2019

Our Reading Lists, Hijacked Yesteryear Spammers

I've been writing virtually spammer activities, in addition to virtually diverse blog hijacks, for about time. There's a special, rather devious weblog hijack, involving spammer activity, that we've been aware of, for about time. In Blogger Help Forum: Something Is Broken, nosotros occasionally run into the query
How create I larn rid of spam, inward my Reading List? I did non Follow this blog!
Nobody will, intentionally, Follow a weblog amount of spam. In about cases, though, people Follow blogs that are published yesteryear naive weblog owners, who convey been conned yesteryear the spammers, into working for them.

The never ending ask for more Followers, readers, search engine reputation, subscribers, in addition to traffic, is a ofttimes expressed draw of piece of occupation concern inward Blogger Help Forum: How Do I?.

In discussions exterior Blogger Help Forum, ane mightiness perchance uncovering suggestions of other, to a greater extent than imaginative ways to larn to a greater extent than traffic to your blog. With Blogger blogs, there's a very obscure in addition to easily used feature, that tin plough over the sack live on used to publicise your blog, randomly, to readers that yous would not, otherwise, address.

All that yous ask create is to redirect your weblog feed into a "feed redistribution cloud", that randomly redirects the readers of whatsoever blog, to viewing the feed from about other blog, similarly using the redirect.

By redirecting your readers, yous are exposing them to other blogs, randomly selected. Similarly, readers of other participating blogs are randomly redirected to your weblog - in addition to at that spot is the promised publicity for your blog.

This is such a bully idea, isn't it? Think again.

  1. Your Followers (and subscribers) desire to read the feed from your blog - non from about random blog.
  2. Many Blogger weblog owners don't role this feature.
  3. Many users of this characteristic are non legitimate Blogger weblog owners, but publishers of spam blogs in addition to websites.
  4. Should yous redirect your readers into a "feed redistribution cloud", the chances are greater that your readers volition live on reading a weblog published yesteryear a spammer.
  5. No spammer volition redirect the feed from his blog. He's going to exceed away on all of his traffic, to himself
  6. Since no existent people knowingly subscribe to feeds from spam blogs in addition to websites, your weblog won't live on getting whatsoever reciprocal crowd of eager would live on readers, originating from the spam blogs in addition to websites.
  7. And, nosotros are here.

As a Follower (and non a weblog owner), having examined your Reading List in addition to flora yourself reading a weblog amount of spam - that yous sure did non Follow - what create yous do? It's a uncomplicated - but perchance ho-hum - chore to identify in addition to remove the weblog owned yesteryear the naive person, who was conned yesteryear the spammers, that yous are Following.

Having done that, why non become ane pace further, in addition to help us to assistance Blogger in addition to Google to interdict the spammer activity?

If yous tin plough over the sack position the URL of a blog, that yous are Following, that is redirecting its feed inward this manner, Blogger / Google tin plough over the sack position in addition to terminate whatsoever Google hosted blogs in addition to websites that are advertising this easy, random agency to publicise your weblog - that is but about other fob used yesteryear the spammers, into getting the naive weblog owners to create their dingy work.

All that nosotros ask is the URL of whatsoever blog, that yous were Following, that rudely redirects its subscribers (like you) into the "feed redistribution cloud". Blogger / Google tin plough over the sack create the rest.

You tin plough over the sack comment, hither - or foremost a discussion, inward Blogger Help Forum: Something Is Broken - it's your choice. Just assistance position the naive weblog owners.

Do your part, in addition to assistance us build clean upward the Blogger Blogosphere.

Wednesday, November 20, 2019

Blogger Blogs Displaying Mysterious Transparent Boxes, Roofing Weblog Content

We're seeing a steady inundation of occupation reports most diverse Blogger blogs that bring developed a mysterious transparent box, roofing to a greater extent than or less component of the weblog surface when displayed. Some blogs display the box for all views, others for principal page sentiment only, as well as nonetheless others for specific private posts. The box may hold upwardly visible at the summit of the page or inwards the center - as well as may scroll amongst the screen, or may stay fixed relative to the display. In many cases, it blocks of import weblog content, as well as / or prevents clicking on crucial links.

Initial observations, during the forthwith previous 2 - 3 days. referred to a "FaceBook or similar Social Networking gadget". Digging deeper, as well as looking closely at reported cases, nosotros tin laissez passer on the sack await for the occupation itself.

After repeated exam of multiple cases, we're seeing a to a greater extent than specific pattern, inwards the occupation source code. Using a text browser tool, nosotros respect the next code (with gratis occupation breaks added for readability), which appears to hold upwardly the marrow of the problem.

<div id="fb-root"></div><script> (function(d, s, id) {   var js, fjs = d.getElementsByTagName(s)[0];   if (d.getElementById(id)) return;   js = d.createElement(s); js.id = id;   js.src = "//connect.facebook.net/en_US/all.js#xfbml=1";   fjs.parentNode.insertBefore(js, fjs); }(document, 'script', 'facebook-jssdk')); </script><br /> <div class="fb-like" data-href="https://www.facebook.com/xxxxxxxxxxx" data-send="false" data-show-faces="true"  data-width="450"></div> 

(Note that "xxxxxxxxxxx" volition hold upwardly the FaceBook user name, providing the proper addressing to the concern human relationship where the "Like" transaction is targeted).

The occupation appears to involve the FaceBook Like accessory. It's possible that FaceBook Support tin laissez passer on the sack render a ameliorate diagnosis - but for correct now, I'll but advise removal of the higher upwardly code. In the cases where the code was installed into an empty HTML / JavaScript gadget (and amongst no other accessories installed in that place also), I'll advise removal of the gadget containing the code.

If y'all tin laissez passer on the sack lay the occupation gadget inwards your blog, y'all tin laissez passer on the sack edit the gadget, as well as Remove it.

As an alternate solution, y'all may add together CSS which volition cover the boxes. Only fourth dimension volition tell, if this is a ameliorate option for many weblog owners. Using the "Add CSS" wizard inwards the Template Designer Advanced menu, add together the following:
#fb_xdm_frame_http, #fb_xdm_frame_https {  display:none !important; } 

Depending upon your marker of technical comfort as well as expertise, y'all may elect whatever i of 3 solutions.
  1. Remove the entire HTML gadget.
  2. Remove the specific occupation code.
  3. Add CSS to cover the problem.
It's your blog, as well as your accessories.

Note that subsequently y'all add together or take the code inwards question, as well as relieve the changes, y'all volition involve to clear browser cache as well as restart the browser, to accurately examine success inwards resolving the problem.

>> Top

Tuesday, November 19, 2019

Having A Blogger Weblog Removed Or Restored, Later Driblet Dead Of The Weblog Possessor - The Adjacent Chapter

The enquiry of disposition of blogs, left behind yesteryear deceased spider web log owners, comes upward inward Blogger Help Forum: How Do I?, from fourth dimension to time.

As Blogger blogs - in addition to similar Google products - locomote mature, in addition to equally to a greater extent than people who divulge Blogger blogs locomote susceptible to former historic menstruation in addition to death, this employment volition locomote to a greater extent than critical. As late equally 2010, inward guild to assume command (or asking deletion) of such a blog, Blogger required alone a faxed re-create of the driblet dead certificate.

In 2013, Google refined the recovery process, in addition to added additional requirements for concern human relationship recovery.

Google is beingness careful to protect actively owned blogs, from misuse of the "deceased" possessor recovery process.

They desire to encourage that nosotros accolade each deceased, yesteryear ensuring that nobody tin pocket your seat unit of measurement member's identity, in addition to blog. The driblet dead certificate is alone i business office of a formal procedure, which Blogger / Google forthwith uses, inward the dual locomote of

  • Compassion, inward allowing a friend or loved i to appropriately assume command of blogs left behind.
  • Due Diligence, inward preventing fraudulent claims yesteryear people who convey no legal or moral correct to assume command of blogs.

Deceased concern human relationship recovery is forthwith a iv footstep process.

  1. Documentation, including a re-create of the driblet dead certificate - in addition to a re-create of electronic mail headers, from the seat unit of measurement fellow member email.
  2. Google Legal verifies Step #1.
  3. Certification of your human relationship amongst the seat unit of measurement member, using a local judge. in addition to a courtroom order.
  4. Google Legal reviews Step #3.

It is possible that the spider web log possessor planned for disposal of her / his blog, which could forestall you lot from assuming command - or fifty-fifty viewing the blog, using Google: Inactive Account Manager.

Both pity for bereaved - in addition to due diligence, in addition to security, are righteous.

Both Compassion in addition to Due Diligence are righteous goals - in addition to are needed to assistance Google cut hijacking of active Blogger blogs.

As business office of an improved physical care for for disposition of Blogger blogs left behind yesteryear deceased owners, Blogger forthwith uses Google Help: Submit a asking regarding a deceased user's account equally guidelines. The novel guidelines

  1. Use a 2 business office physical care for - a preliminary review, followed yesteryear a formal courtroom documented process.
  2. Include a dedicated facsimile transmission / postal postal service address.
  3. Include additional requirements, which formally seat the human relationship of the soul requesting command of the spider web log inward question, to the deceased.

The preliminary review specifies a facsimile transmission / postal postal service address:

Google Inc.
Gmail User Support - Decedents’ Accounts
c/o Google Custodian of Records
1600 Amphitheatre Parkway
Mountain View, CA 94043
Fax: 650-644-0358

in addition to a formal listing of textile required, for Part 1 - preliminary review.

  1. Your total name.
  2. Your physical mailing address.
  3. Your electronic mail address.
  4. A photocopy of your government-issued ID or driver’s license.
  5. The Gmail address of the deceased user.
  6. The driblet dead certificate of the deceased user. If the document is non inward English, delight furnish a certified English linguistic communication translation prepared yesteryear a competent translator in addition to notarized.
  7. The next data from an electronic mail message that you lot convey received at your electronic mail address, from the Gmail address inward question:
    • The total header from the electronic mail message. See instructions on how to discovery headers inward Gmail in addition to other webmail electronic mail providers. Copy everything from 'Delivered-To:' through the 'References:' line
    • The entire content of the message

When specified yesteryear Blogger Support, nosotros were instructed to substitute the spider web log URL, for the Gmail address (as #5). No addendum referencing the electronic mail message (as #7) was provided.

The instructions for Part 2 are non likewise defined, equally for Part 1.

Part 2 volition require you lot to teach additional legal physical care for including an guild from a U.S.A. of America courtroom and/or submitting additional materials. Please authorities notation that submitting these materials volition non guarantee that nosotros volition live on able to furnish Gmail content then nosotros recommend non embarking on Part 2 until you lot take away heed dorsum from us regarding Part 1.

These requirements may look onerous to the less observant. Actually, yesteryear formalising the process, this should cut the number of fraudulent claims, in addition to arrive easier for Google personnel to legitimately physical care for claims, piece exercising both pity in addition to due diligence.

Blogger Blogs Redirecting To Kunoichi . Info

In the latest circular of weblog hijacks, from misbehaving or miswritten accessory gadgets, nosotros produce got reports this calendar month inwards Blogger Help Forum: Something Is Broken nearly blogs redirecting to "kunoichi . info".
My Blogger site, xxxxxxx . blogspot . com, alongside over viii years of weblog posts archived, has been redirected without my permission, to "kunoichi . info". I run into my weblog for a few seconds earlier it goes to the novel site.

If nosotros role a text entirely browser, such equally an HTTP draw utility, the offending code is direct visible. Here's an example, taken from the latest forum occupation study (and rigourously redacted).

<div class='widget HTML' id='HTML2'>
<h2 class='title'>Recent Comments</h2>
<div class='widget-content'>
<script style="text/javascript" src="http : // kunoichi . information / blogger _ buster / comments.js"></script><script style="text/javascript">var a_rc=5;var m_rc=true;var n_rc=true;var o_rc=100;</script><script src="http : // xxxxxxx . blogspot . com /feeds/comments/default?alt=json-in-script&callback=showrecentcomments"></script>

So far, identification in addition to removal, of the occupation code, seems to endure straightforward - only access the "Page Elements" sorcerer (Classic Blogger GUI) or the "Layout" carte du jour sorcerer (New Blogger GUI), notice the offending gadget, in addition to take away it. As always, y'all are advised to clear cache in addition to restart the browser, later on removal in addition to earlier testing.

>> Top

Monday, November 18, 2019

Blogger Blogs Beingness Hijacked Past Times Instagram Gadgets

We're seeing a noticeable sum of vibrations today, from weblog owners reporting that their blogs appear to last susceptible to antivirus detection - together with others reporting that their readers are complaining of mysterious misdirection, when viewing their blogs.
My weblog is struggling to fully load, together with hangs proverb "Waiting for platotv . com" together with "Waiting for directagain . net"
and
I'm getting warnings from Avast when I essay to persuasion my blog!


Upon exam of the blogs affected, nosotros meet a large let on which comprise the "I'm An Instagram Addict!", or similar, gadget. Most weblog owners who acknowledge to having an Instagram gadget accept reported relief, having removed the gadget inward question. We're all the same looking, to meet where these dodgy gadgets are coming from.

(Update 2012/10/08): We are instantly seeing suggestions from diverse people, representing themselves equally employees of "BadgePLZ", suggesting that the problems amongst their code has been fixed.

If your weblog is generating antivirus alerts - or if your readers study misdirection - yous may wishing to take away whatsoever Instagram accessories, late installed. You may wishing to clear cache together with restart the browser, afterwards removal. You may request direct access to diverse dashboard wizards, inward unopen to extreme cases.

Right now, the bulk of the problems reported seem to involve an "IFrame", targeting "badgeplz . com".
<iframe src='http : // badgeplz . com / instagram / ?u=mun_mun90&t=c&bgclr=f2f2f2&brclr=cccccc&px=1&py=5&pb=5&brds=5&incls=n&svc=instagram&pbclr=ffffff&sze=75' allowtransparency='true' frameborder='0' scrolling='no' style='border:none; overflow:hidden; width:118px; height: 482px'></iframe>
We're currently unsure whether this is an intentional hijacking, or merely bad coding. Until the owners of "badgeplz . com" soil their intentions, we'll merely advise yous to take away this gadget, if yous accept added it to your blog.

As usual, I'll caution yous against indiscriminate installation of 3rd political party gadgets, inward general.

>> Top

Blogger Blogs Redirecting To Blogspot - Ping . Com

Today, nosotros run into the latest inwards the never ending saga of spider web log owners, who previously (maybe / peradventure non recently) installed to a greater extent than or less deviously created software - whether intentionally or non - together with who at nowadays discovery their readers unable to stance their blogs, together with themselves fifty-fifty unable to access the template editor to take away the malicious code.
My blogs are redirecting car to ping . blogspot - ping . com", tin anybody tell me how to gear upwardly this?


The malicious redirecting appears to endure drive past times a pocket-sized snippet of JavaScript code - which has been installed, inwards nearly cases, every bit template HTML. Alternatively, to a greater extent than or less spider web log owners bring added separate HTML / JavaScript gadgets, to host this code.

It's slowly plenty to position - non together with therefore slowly to remove, every bit to a greater extent than or less owners bring found. In many cases, nosotros are seeing reports that fifty-fifty when directly accessing the Layout sorcerer or Template Editor, the malicious code activates, together with redirects the spider web log owner's browser.

Since the redirect is running from a snippet of JavaScript code, blocking the malicious code volition preclude the redirection, together with permit corrective access to the Layout sorcerer or Template Editor.
<script src='http : // ping . blogspot - ping . com / ping . js' type='text/javascript'></script>
Whichever GUI sorcerer you lot purpose to take away the code, recollect to clear cache together with restart the browser subsequently removal together with earlier testing for success.

Since I routinely - together with consistently - purpose Firefox amongst NoScript to browse, I was able to access i victim spider web log without the redirection occurring, stance the spider web log source, together with extract the inwards a higher house code. If you lot purpose NoScript, you lot (the spider web log owner) should endure too able to access your dashboard, together with the Template Editor, together with take away the bogie.

Please authorities notation that the code snippet, excerpted above, has extra spaces inserted into the URLs, to preclude advertising of the actual hijacking domain.

Anybody who knows where this bogie originated, together with how it was deviously conned upon the spider web log owners, tin aid a lot of people past times identifying the origin. Only when this is done, tin nosotros endeavour to preclude the occupation - rather than propose how to take away the problem.

First, install the pop the dissimilar trust levels of Blogger together with BlogSpot - amongst NoScript, you lot volition bring to permit Blogger, notwithstanding forbid BlogSpot. Code from unknown domains, such every bit "blogspot - ping . com", volition non run on whatever NoScript protected figurer - unless you, intentionally, enable it. Knowing the threat from this bogie, you lot volition hopefully select to non enable this domain.

>> Top

Blogger Blogs Redirecting To Scrapur . Com

This week, we've seen several reports inwards Blogger Help Forum: Something Is Broken, from Blogger weblog owners, reporting the latest hijacking of their blogs.
My weblog is beingness redirected to a spam site - was it hijacked?


As is all likewise often the case, the redirection appears to come upward from 3rd political party code or gadgets, willingly installed yesteryear the weblog owner. Examination of the website inwards inquiry appears to betoken a long expired domain.
This domain mention expired on November vii 2012 11:32:24:000AM
It's possible that, correct now, this is non a maliciously planned hijack - though whatsoever expired domain tin travel re purchased for a devious or malicious purpose.

In several cases, the redirecting code appears every bit business office of an installed XML gadget, a version of "Recent Comments". In other cases, nosotros convey observed naked JavaScript code, installed straight into the weblog template. Here are identified examples - though you lot may run into other variants.
<script style="text/javascript" src="http : // scrapur . com / index / wp-content / uploads / 2008 / 04 / rc . asp"> </script>
or possibly
<script src='http : // scrapur . com / index / wp-content / uploads / 2008 / 02 / smiling . js' type='text/javascript'></script>
(Note the URLs convey been modified, to forestall search engine indexing of a potentially malicious domain).

Use of a text proxy, such every bit Rex Swain's HTTP Viewer, when run from whatsoever browser, volition allow you lot to safely examine the weblog source, without interference yesteryear the redirecting code. In this case, exactly charge your weblog using the URL, hence utilisation the browser bear witness search, for "scrapur", inwards the proxy log. This volition allow you lot run into if the code inwards inquiry is business office of an HTML gadget - or it is installed straight inwards the template.

As amongst many reported hijacks, access to the Blogger Layout as well as Template wizards appears to travel affected. If you lot ask to take away this code from your blog, you lot may reveal yourself unable to utilisation either the Layout sorcerer (to take away an identified gadget) or the Template sorcerer (to take away straight installed code). In this case, you lot volition ask to use Firefox amongst Noscript - or a similarly good protected browser - to forestall the redirecting code from executing.

After removing the identified code from your blog, every bit always, clear cache as well as restart the browser. Finally, I'll remind you lot again, to delight travel item - only install 3rd political party code from trustworthy providers.

>> Top

Add A Uncomplicated Recent Comments / Recent Posts Gadget To Your Blog

The lately observed problems amongst to a greater extent than or less 3rd political party gadgets, previously added past times many weblog owners to their blogs, leaves these blogs lacking diverse accessories.

One of the gadgets identified is the "Recent Comments" / "Recent Posts" gadget pair. For many weblog owners, this gadget is non impossible to replace.

Blogger provides us amongst a native accessory, called a "Blog Feed" gadget, which volition render acceptable "Recent Comments" as well as "Recent Posts" functionality, for many weblog owners.

Look at the sidebar of this blog, for " - Comments", as well as " - Posts". Those are "Recent Comments" as well as "Recent Posts" gadgets, which are based on the Blogger supplied "Feed" gadget - which is non a 3rd political party accessory, as well as is non dependent champaign to hereafter 3rd political party peccadilloes.

To brand your novel gadget, outset amongst the URL of the weblog feed desired.

Add a Blogger supplied Feed gadget, using the "Add a gadget" wizard, inwards the dashboard Layout display.

This is the URL of this blog.
http://blogging.nitecruzr.net

This is the URL of the weblog comments feed.
http://blogging.nitecruzr.net/feeds/comments/default

This is the URL of the weblog posts feed.
http://blogging.nitecruzr.net/feeds/posts/default

Setting upwardly a "Blog Feed" gadget is uncomplicated enough.

  1. Add a "Feed" gadget (Only guide the "Feed" gadget, "By Blogger"!!!), using the "Add a gadget" wizard.
  2. Plug inwards the Feed URL (see my examples above), as well as Continue.
  3. Review / alter the options offered, as well as Save.
  4. Test your novel weblog accessory - provided past times Blogger - amongst no hereafter hacking activeness anticipated.

Avoid whatever similarly named gadget non "By Blogger" - distributed from "Add a Gadget", or from a someone weblog or non Google website.

And, you're done. Wasn't that simple?

Use A Good Protected Browser, To Block Redirecting From Misbehaving Code In Addition To Gadgets

Regularly, inwards problem code or gadgets inwards their blogs.

Generally, this follows reports yesteryear spider web log owners, that their readers are beingness redirected to unexpected as well as unwanted blogs as well as websites, from their blogs. Sometimes, nosotros acquire the reply
I can't withdraw the code. Every fourth dimension I login to Blogger, I am redirected, merely equally my readers are beingness treated!

When nosotros encounter the latter complaint, nosotros recognise even as well as thence 1 to a greater extent than spider web log possessor who does non know how to properly protect himself, from malicious code as well as websites. Most people, who know nearly Layered Security, know that proper browser safety is an essential complement to a properly chosen as well as maintained anti malware filter.

Many people, who attention nearly browser based security, purpose Firefox amongst NoScript.

This combination provides Unix degree security, "deny yesteryear default, permit yesteryear exception". Simply install NoScript equally an add-on, to Firefox, to acquire started. Alternately, yous may purpose Chrome amongst ScriptSafe, or Opera amongst NotScripts.

When using your browser amongst a script filter, in that place volition last specific Blogger / Google websites which yous should trust, as well as others which yous should non trust.

Every fourth dimension yous surf to a dissimilar website - as well as create upward one's heed that the owners of the website, which yous are straightaway viewing, bring your best interests inwards heed - configure NoScript to permit that website, to display properly on your computer. When yous notice that a trusted host website does non display properly, examine the NoScript taskbar as well as the listing of websites used yesteryear the host website. Look at the NoScript Options menu, carefully. Allow specific websites which yous trust, as well as Forbid all other websites which yous produce non trust.

Deciding which websites to trust, based on their presence inwards the NoScript Options menu, volition last a learning sense for a while. For closed to host website pages, which purpose a large expose of unfamiliar websites, yous may bring to carefully pick out to "Temporarily permit all this page" - or yous tin "Temporarily allow" each unmarried website, 1 yesteryear one, until the host website page displays properly.

When yous create upward one's heed to (permanently) "Allow" whatsoever website, that website volition last "Allowed" on all other host websites where yous may surf. Conversely, whatsoever website which yous never pick out to "Allow" - such equally the occupation website which is providing the misbehaving code - volition never execute on your reckoner again. This volition preclude redirection on your computer, permit yous to safely purpose the Blogger dashboard, as well as edit or withdraw whatsoever dodgy code which may last business office of your blog.

After removing whatsoever dodgy code from your blog, ever clear cache as well as restart Firefox, to seek out the effects of your editing.

>> Top

Saturday, November 9, 2019

Blogger Blogs Redirecting To Pagesinxt.Com / Ripway.Com

In spite of my lately published caution against complimentary additions of 3rd political party weblog accessories, we're seeing a modest nonetheless steady stream of reports virtually mysterious weblog hijackings, inwards Blogger Help Forum: Something Is Broken.
When I sentiment my blog, it shows upwards for a few seconds - in addition to and thus forwards to this weird website, that I've never heard of.
Not everybody is aware of the dangers of adding non Google developed code, to their blogs.

Unlike the weblog hijacks from the yesteryear duad years, the "pagesinxt" / "ripway" hijacks beingness reported convey no consistent diagnosis.
  • We convey non nonetheless observed a consistent host feature, such equally "falling snow" (from 2010).
  • Some hijacking code, when found, is purpose of the template HTML.
  • Other hijacks are patently beingness installed equally HTML / JavaScript gadgets.

To discover this latest hijack, you'll demand to outset yesteryear viewing the weblog inwards question, using a text exclusively browser, or proxy service. I, personally, utilisation several products.All of these products may locomote about useful inwards identifying the root of your specific hijack.

The approach hither is multi-phasic.
  1. Of course, backup the template, earlier starting.
  2. Load the blog, inwards question, inwards the browser of your choice.
  3. Do a elementary text search for "pagesinxt" in addition to for "ripway".
  4. You'll run into several dissimilar possibilities.
    • The search may give away the hijacking code inwards an HTML gadget. You tin utilisation the "Pages Elements" / Design tab (Classic GUI), or the "Layout" sorcerer (New GUI), in addition to take the offending gadget.
    • The search may give away the hijacking code inwards the template HTML. You'll convey to utilisation the Template Editor, in addition to take the offending lines of code.
    • The search may non discover either "pagesinxt" or "ripway". You'll convey to create an extensive text search, for unknown HTML / JavaScript gadgets, in addition to evaluate each gadget, on the fly.
  5. You may demand to bypass the Blogger carte du jour structure, to conduct access the Blogger sorcerer needed, if trying to utilisation the Blogger menus is also a problem.
  6. Clear browser cache, earlier checking for success.
  7. And e'er backup the template, again, subsequently completing this task.

If you lot desire to a greater extent than detailed aid for identifying or removing your personal hijack, delight outset a novel discussion, inwards Blogger Help Forum: Something Is Broken, acre the URL of your blog, in addition to acre what URL the weblog is redirecting.

>> Top

Friday, October 18, 2019

Identifying Together With Removing Deviously Engineered Together With Marketed Weblog Hijacks

We saw the symptoms of the offset carefully engineered weblog hijacks, inward Blogger Help Forum: Something Is Broken, 2 years ago. During each succeeding vacation season, each gear upwards on has manifestly acquire to a greater extent than in addition to to a greater extent than deviously engineered.

This flavor - each flavor starting inward Fall of 1 twelvemonth in addition to lasting until Spring of the next twelvemonth - nosotros are seeing a hijack complement which appears to live devious inward both marketing in addition to installation technique, in addition to which requires a complex search of the affected blogs. If yous are receiving reports from your readers
Your weblog starts to charge - precisely is chop-chop replaced past times a page amount of advertisements!
you may demand to exhaustively examine your weblog for whatsoever 3rd political party code - in addition to every bit always, the work code may convey been installed at whatsoever fourth dimension inward the past. When discovered, the hijacks are non consistently establish inward latterly installed code.

The weblog hijacks, existence examined during this vacation flavor - appear to live deviously planned in addition to marketed.
  • The hijacks role a diversity of host accessories in addition to gadgets.
  • The hijacks role a diversity of distribution libraries.
  • The hijacks are existence marketed to a various audience, which causes unlike installation techniques - in addition to necessitates the complex search of affected blogs.

To honour in addition to take a hijack from an affected blog, you'll demand to start past times viewing the weblog inward question, using a text entirely browser, or proxy service. I, personally, role several products.
  • hpHosts vURL is a text entirely browser, that runs every bit a stand upwards solitary application locally on your computer.
  • Notepad-Plus-Plus is an offline text editor, which provides a diversity of search tools for text files. You tin sometimes avoid role of your browser completely, past times copying page beginning code straight from vURL.
  • Rex Swain's HTTP Viewer is a measure online text proxy that I use.
  • Lingo4you HTTP Web-Sniffer is an online choice to Rex Swain.
All of these products may live to a greater extent than or less useful inward identifying the beginning of your specific hijack. The Rex Swain in addition to Web-Sniffer text proxies each convey their effective differences.

If anybody uses choice products, in addition to cares to portion data close the tools used, I volition most gratefully add together them to my library here.

The approach hither is complex.
  1. Of course, backup the template, earlier starting.
  2. Load the blog, inward question, inward the text browser / proxy display of your choice.
  3. Do a uncomplicated text search for the identified host / target shout out inward the URL, such every bit "adiwidget", "pagesinxt", or "ripway".
  4. You'll encounter several unlike possibilities.
    • The search may give away the hijacking code inward an HTML gadget. You tin role the "Pages Elements" / Design tab (Classic GUI), or the "Layout" magician (New GUI), in addition to take the offending gadget.
    • The search may give away the hijacking code inward the template HTML. You'll convey to role the Template Editor, in addition to take the offending lines of code.
    • The search may non honour whatsoever identified host name, inward a text search. You'll convey to create an extensive text search, looking for unknown HTML / JavaScript gadgets / snippets of code, in addition to evaluate each gadget / snippet, on the fly.
  5. You may demand to bypass the Blogger card structure, to straight access the Blogger magician needed, if trying to role the Blogger menus is also a problem.
  6. Clear browser cache, earlier checking for success.
  7. And e'er backup the template, again, subsequently completing this task.

And hopefully, having establish in addition to removed a hijack from your blog, yous volition learn to live to a greater extent than discrete, inward your selection of accessories in addition to gadgets, inward the future.

Monday, September 30, 2019

Account Recovery Options, Together With Prevention Of Blogger Concern Human Relationship / Spider Web Log Hijacks

Ever since Blogger started using Google accounts to authenticate Blogger draw of piece of work organisation human relationship access, weblog owners guide hold had trouble maintaining access to their accounts as well as their blogs.

Not all Blogger weblog owners empathize - as well as less guide hold - the measures that Blogger has taken, to prevent malicious activity, past times unknown persons who would role Internet obscurity to hijack their accounts, as well as their blogs.

Every day, nosotros come across numerous complaints inwards Blogger Help Forum: How Do I?, virtually inability to recover draw of piece of work organisation human relationship access. And, nosotros come across occasional (not occasional enough) reports virtually blogs at ane time owned past times people who are non personally known past times the rightful weblog owner.

Blogger is continually improving their account recovery, authentication, as well as draw of piece of work organisation human relationship hijack prevention policies. Unfortunately, equally they ameliorate inwards ane area, they brand things to a greater extent than hard inwards another.

Until slow 2010, Blogger / Google offered several options, for recovering draw of piece of work organisation human relationship / weblog access.
  • An automated wizard, where you lot could supply the URL of your blog, as well as guide hold draw of piece of work organisation human relationship recovery instructions sent to the e-mail address registered amongst the Blogger account(s) that administered the blog, accompanied past times the welcomed advice
    We've sent password reset instructions to your e-mail draw of piece of work organisation human relationship xxxxxxx@yyyyy.zzz.
  • An option, should the latter e-mail draw of piece of work organisation human relationship live on unusable (the possessor graduated from school, changed ISPs, changed jobs), to walk into many regional Google offices, introduce proof of identity, as well as regain access to to a greater extent than or less Blogger accounts.
  • In to a greater extent than or less express cases, to transmit a facsimile of specific proof of identity documents to a Google office, guide hold identity verified remotely, as well as regain access to to a greater extent than or less Blogger accounts.

In early on 2011, nosotros noted a meaning number of cases where people were reporting logging inwards to Blogger, as well as finding diverse personal blogs missing from the dashboard weblog lists. Checking the blogs themselves, they were constitute to live on nevertheless online - exactly at ane time owned past times other persons. In an alarming number of cases, the persons as well as then owning the mysterious blogs appeared to live on constituent of a malicious as well as good planned attack, against Blogger accounts as well as blogs.

In mid 2011, Blogger changed check each account, ane past times one, until login instructions are found.

To trim the take away for local as well as remote identity verification, Google enhanced the account recovery wizard, where the weblog possessor tin supply an e-mail address (whether or non usable for incoming email), supply secondary details to attempt identity, as well as regain access. They likewise added prevent hijackings, as well as to recover draw of piece of work organisation human relationship access.

Unfortunately, people who idly forget the password as well as the e-mail address, or who forget (or never provide) secondary personal details when setting upward their Google account, volition e'er live on a challenge. Another challenge is provided past times people who value anonymity, as well as setup multiple e-mail accounts to obscure their existent life identity from their Blogger weblog ownership.

In specific cases, Blogger is known to supply mysterious "hints" to people who guide hold gratuitously used multiple e-mail accounts - as well as who cannot at ane time recall all accounts used.
Your e-mail address is a***0@yahoo.com.
However, the limited effectiveness of hints should e'er live on noted. The Blogger Help Forum: [FAQ] Regarding account-related issues won't live on going away, for lack of traffic, whatever fourth dimension soon.

>> Top

Thursday, September 12, 2019

Non Really Weblog Feeds, Replaced Past Times Mysterious Content, On Our Reading Lists

Periodically, nosotros come across reports inwards Blogger Help Forum: Something Is Broken, close hijacked blogs. Sometimes, the reports come upward from weblog owners (or onetime weblog owners) who cannot straight off command (or publish) their blogs - or maybe who study mysterious content on their blogs. Other times, the reports come upward from people who study mysterious too unwanted content inwards their Reading List (Google Reader) displays.

Of the latter group, many are existence establish to conduct maintain before Followed blogs owned yesteryear people who are naively trying to attract random readers to their blogs, too who overlook the argue for having weblog feeds inwards general. Different Followers would study seeing multiple streams of randomly changing content inwards their Reading Lists.

Recently, we've gotten reports from people who are seeing a single, too unique hijacker inwards their Reading Lists - producing consistent streams of duplicated, repetitive content. This does non appear to ask weblog owners, naively misusing the Post Feed Redirect.

Some fourth dimension ago, nosotros explored a mysterious scenario, of people unsuccessfully trying to setup a weblog feed gadget, who reported a mythical "Net-Temps Job Search Feed" displayed inwards their "Configure Feed" display. It appears that Blogger fixed the status which caused the "Configure Feed" gadget to display the mythical "Net-Temps Job Search Feed".

Now, people who Follow blogs lacking a feed, or who Subscribe to blogs amongst no feed, are non seeing an fault message - they are exactly seeing an unwanted feed inwards their Blog Feed gadget or Reading List / Google Reader displays.

If yous are seeing mysterious, repetitive, too unwanted content inwards your Reading List / Google Reader display, conduct maintain exactly about fourth dimension too diligently banking concern fit each private feed. Instead of finding 1 or ii blogs which are using an inappropriately redirected feed, yous may honor multiple entries referencing non really feeds. Blogs that yous were legitimately Following may straight off endure producing no feed.
  • Blogs that conduct maintain been deleted.
  • Blogs that are straight off private.
  • Blogs that exactly conduct maintain the feed disabled.
Any of these blogs, viewed en masse, may straight off endure producing a single, repetitive current of mysterious too unwanted content. This volition perhaps endure to a greater extent than probable amongst homogenous too large Followed communities.

>> Top

Saturday, September 7, 2019

How To Non Transcend Content For Your Blog

One of the oddest displays of naivete nosotros see, from around weblog owners, bespeak inwards Blogger Help Forum: How Do I?, would be
How produce I permit anybody postal service to my blog?
These owners direct maintain no persuasion how pop they would be, amongst spammers, were this to happen.

If you lot direct maintain a blog, in addition to you lot desire to permit upward to 99 of your closest friends release their thoughts to your blog, you lot tin laissez passer on the sack setup a squad blog, in addition to direct maintain fun. Beyond that limit, you lot cannot - nor should you lot - go.

Occasionally, inwards successfully attacked, yesteryear hackers or spammers, in addition to who right away come across content which they produce non appreciate, beingness posted inwards their blog.

Leaving weblog opened upward to world authorship volition brand your weblog spammer friendly.

If you lot were to voluntarily permit anybody postal service inwards your blog, without requiring that anybody hack to make command surreptitiously, your weblog volition instruct really pop amongst spammers.

After spammers saturate your weblog content, your genuine friends volition notice elsewhere to postal service - in addition to your remaining friends volition last spammers. And your novel friends (spammers) volition tell their friends (more spammers), almost a weblog which accepts ads (posts) from everybody.

Your weblog volition last like shooting fish in a barrel classified equally a spam host.

Shortly later this happens, your weblog volition last - righteously - classified equally a spam host, in addition to taken offline. And if you lot cannot demo whatever non spam content, it volition probable remain offline.
We're sorry, only your weblog cannot last restored. It was late confirmed equally spam. Blogger suggests that you lot read the TOS.

You are responsible for content distributed yesteryear your "guest authors".

Another affair to consider, equally the possessor of a "host" blog, where "guests" postal service contributed material, is that you volition last responsible for the content posted yesteryear your guests - whether you lot permit the earth postal service - or designated members.
  • If you lot allow invitee posts inwards your blog, you, equally the weblog owner, are responsible for the content of those posts.
  • If your "guest" posts the same fabric elsewhere (as inwards his ain blog, or a 3rd person's blog), in addition to search engines index both blogs, both blogs may have "duplicated content" penalties.
  • Nobody benefits, from duplicated content.

Unfortunately, you direct maintain to prepare your weblog content, yourself. Don't expression the world to render your content for you lot - in addition to computer programme to continue your weblog online for long.

Sunday, September 1, 2019

Blogger Blogs Displaying Mysterious Transparent Boxes, Roofing Weblog Content

We're seeing a steady inundation of occupation reports most diverse Blogger blogs that bring developed a mysterious transparent box, roofing to a greater extent than or less component of the weblog surface when displayed. Some blogs display the box for all views, others for principal page sentiment only, as well as nonetheless others for specific private posts. The box may hold upwardly visible at the summit of the page or inwards the center - as well as may scroll amongst the screen, or may stay fixed relative to the display. In many cases, it blocks of import weblog content, as well as / or prevents clicking on crucial links.

Initial observations, during the forthwith previous 2 - 3 days. referred to a "FaceBook or similar Social Networking gadget". Digging deeper, as well as looking closely at reported cases, nosotros tin laissez passer on the sack await for the occupation itself.

After repeated exam of multiple cases, we're seeing a to a greater extent than specific pattern, inwards the occupation source code. Using a text browser tool, nosotros respect the next code (with gratis occupation breaks added for readability), which appears to hold upwardly the marrow of the problem.

<div id="fb-root"></div><script> (function(d, s, id) {   var js, fjs = d.getElementsByTagName(s)[0];   if (d.getElementById(id)) return;   js = d.createElement(s); js.id = id;   js.src = "//connect.facebook.net/en_US/all.js#xfbml=1";   fjs.parentNode.insertBefore(js, fjs); }(document, 'script', 'facebook-jssdk')); </script><br /> <div class="fb-like" data-href="https://www.facebook.com/xxxxxxxxxxx" data-send="false" data-show-faces="true"  data-width="450"></div> 

(Note that "xxxxxxxxxxx" volition hold upwardly the FaceBook user name, providing the proper addressing to the concern human relationship where the "Like" transaction is targeted).

The occupation appears to involve the FaceBook Like accessory. It's possible that FaceBook Support tin laissez passer on the sack render a ameliorate diagnosis - but for correct now, I'll but advise removal of the higher upwardly code. In the cases where the code was installed into an empty HTML / JavaScript gadget (and amongst no other accessories installed in that place also), I'll advise removal of the gadget containing the code.

If y'all tin laissez passer on the sack lay the occupation gadget inwards your blog, y'all tin laissez passer on the sack edit the gadget, as well as Remove it.

As an alternate solution, y'all may add together CSS which volition cover the boxes. Only fourth dimension volition tell, if this is a ameliorate option for many weblog owners. Using the "Add CSS" wizard inwards the Template Designer Advanced menu, add together the following:
#fb_xdm_frame_http, #fb_xdm_frame_https {  display:none !important; } 

Depending upon your marker of technical comfort as well as expertise, y'all may elect whatever i of 3 solutions.
  1. Remove the entire HTML gadget.
  2. Remove the specific occupation code.
  3. Add CSS to cover the problem.
It's your blog, as well as your accessories.

Note that subsequently y'all add together or take the code inwards question, as well as relieve the changes, y'all volition involve to clear browser cache as well as restart the browser, to accurately examine success inwards resolving the problem.

>> Top