Storm Hits Blogger Network
ancientribe writes "Researchers have discovered the Storm Trojan nestled in hundreds of blog sites in Google's Blogger network, according to an article in Dark Reading. And this isn't simple comment spam, but actual blogs that post spam, and now, Storm executable files. A researcher who's been tracking the Storm-infested blog sites says he's working with Google to clean up this latest appearance of Storm."
The sad part is, from what I've seen and heard, this Storm "virus" does need human intervention.
It doesn't do anything technically new. The only thing new here is the particular brand of social engineering used, and it bothers me that this still works.
Don't thank God, thank a doctor!
A couple of days ago, I got tired of the formmail spam that my users were receiving from their "contact me here" webpages. After reviewing my logs, I made .htaccess files on my webserver:
.* - [F]
.blogspot.com referrers. I still see a few dozen hits every day from all of these, but they are all 403 now so I'm happy.
order allow,deny
deny from 206.51.229.
deny from 206.51.233.
allow from all
RewriteEngine on
RewriteCond %{HTTP_REFERER} blogspot\.com [NC]
RewriteRule
This has cut the formmail spam that I receive down to zero ever since I set it up.
The deny from lines take care of some guy who downloads the html submit form and posts spam from "Darksites.com", and the Rewrite denies access from all
Here is a single example from a few minutes ago:
72.47.89.233 --[30/Aug/2007:22:28:22 -0600] "GET / HTTP/1.0" 403 3931 "http://hydrocodone--4t1.blogspot.com" "Opera/9.0 (Macintosh; PPC Mac OS X; U; en)"
If you're a zombie and you know it, bite your friend!