Blogger System Sites Used for Phishing
jimbojw writes "In a recent security advisory Fortinet is reporting that due to Blogger's popularity, hackers have started to embed malicious scripts on some blogs. 'These scripts have shown up on hundreds of Blogger.com sites. In some cases, a variant of the Stration mass mailer is responsible for directing traffic to the Blogger.com sites.' CNET reports on the situation, quoting an unnamed Google representative as saying 'These are not legitimate blogs that were compromised. They appear to be deliberately set up to promote phishing, which is against our terms of service. We are investigating, and blogs found to include malicious code or promote phishing will be deleted.' The blogs in question use meta or JavaScript redirection to push traffic to a phishing or malware site. Links to the blogs are subsequently mass-mailed by infected visitors — typically via worms in the Stration family. We can only hope that this will not cause Google to remove Blogger.com's templating engine — which is both a source of its strength, and a potential liability as illustrated by these recent attacks."
Damn phishermen really get on my chimes >-(
This stuff just isn't ever going to be fixed. Some folks may not like it, but with all these silly problems, AJAX is the new MS Windows of the 21st century.
No, that's not a troll. Just an observation that many want to cover up.
That seems about right.
One ring to bind them - should probably have more fiber and less rings in their diet.
Not to mention blogs set up just to be filled with spam. Google must give these popular sites some leeway, before delisting them.
Libertarian Leaning Political Discussion Forum.
What's next, hacking a release server and modifying tarballs so blog updaters everywhere become vulnerable? Oh, wait...
These sites allow you to include script? What were they thinking?
Anybody home, McFly?
A template that allows people to slap a meta redirect into the header is strength that they hope Google will still respect? If you want to play those games, host your own site. The point of these blog-o-spaces is to let people do the easy stuff, not monkey with redirection. On the other hand, I can see how it might take, oh... at least 10 minutes to write a filter that would block the meta redirects on their side of things. That is a lot to ask, even in the face of being Google-blacked.
Don't disappoint your bird dog. Go to the range.
...can we call it "phlogging"?
I've had numerous attacks against my site, which of course don't work because I don't allow script tags, but I've reported the target sites to their respective webhosts and registrars, and had at least a few blocked/cancelled/warned/etc. Most registrars and webhosts are more than happy to put these sites out of their misery.
What has the world come to! You spammers should all be ashamed of yourselves!!
... where all of your wildest dreams will come true!!
Visit http://www.whorapedia.com/
Whore Yourself... @ http://whorapedia.com/
i guess people nowaday like to go "Fishing"..