YugaTech | Philippines, Technology News & Reviews

Philippines, Technology News & Reviews



Massive Blog Hackery Exposed

Tony of DJI talks about an unexpected outcome from TailRank’s River, a blog monitoring service. A large number of blogs turned out to have been hacked to promote spammy content and affiliate links.

Hidden content injected in the blog templates with links to each other in order to push the rankings in the SERPs. Blog monitoring services like TailRank, which tracks interlinking content, obviously showed those spammy content.

I’ve seen and have had experience with such types of blog hacking:

  • Modifying “header.php” or “footer.php” and inserting links to spammy sites. These text links are enclosed in DIV tags so they can be positioned way off of the screen.
  • Popular and free themes are modified and inserted with obfuscated PHP scripts to be injected remotely. The themes are then repackaged and re-distributed to the public. These scripts can then be manipulated later to inject spammy content and text links to any targeted sites. Much like a zombie blog.
  • Uploading CGI scripts into the “cgi-bin” directory via unrestricted folders. The CGI scripts can then be accessed and used to run whatever command lines the hacker wants.
  • SQL injections. Older and vulnerable versions of WordPress can be attacked via SQL injections to add content to existing/archived blog posts/entries with links to spammy sites.
  • Modifying .htaccess files to redirect (301) certain popular or high rankings pages to other spammy or affiliate-filled sites.
  • Directly modifying unrestricted pages to insert AdSense codes or modify existing AdSense Publisher ID to that of the hacker.
  • I’ve also seen blogs being sabotaged by creating empty folders that follow the same permalink structure as some of the pages of the blog. This, in effect, overrides the custom permalinks and disables the affected pages.

What’s surprising is that most of the hacks that I encountered were deployed by Filipinos too. Here are some snippets of their codes:

if ($epwd ne $npwd) {
$msg = “<br /><h1>Mukha Mo!</h1>
“;
}

print header( -COOKIE=>$cid ), start_html(”BUTAS”);

Either they coded the hack themselves or got the script somewhere else and modified it to their own liking. It was obvious because some of the coding (commands and variables) used in the script are in Tagalog.

Tony adds some advise on how to prevent this. I’ve written an more general blog post about security and contingency plans here as well.

permalink

Enter your email address:

Related Entries:

33 Responses to “Massive Blog Hackery Exposed”


  1. Gravatar Icon 1 Jeffrey Apr 7th, 2008 at 4:00 pm

    That’s why i no longer use free themes. But when i do use free ones, i just modify the Wordpress default theme.

  2. Gravatar Icon 2 Dexter Apr 7th, 2008 at 4:36 pm

    I was a victim of this one too.. The answer should be constant back up..

  3. Gravatar Icon 3 Janina Apr 7th, 2008 at 6:03 pm

    I hoff my blog wont be hack by this hackers. I dont how would i peel ip my site is hacks!

    Visit my site fleasee:
    http://www.janinablog.com

  4. Gravatar Icon 4 BrianB Apr 7th, 2008 at 6:54 pm

    Yep this happened to pmptoday around december and for the entire january. A porn site hacked us and we hardly noticed until we saw a dramatc decline in traffic.

  5. Gravatar Icon 5 BrianB Apr 7th, 2008 at 6:56 pm

    Just noticed Janina. Think about this guys. If it was celine lopez he’s spoofing, he would get his ass sued.

  6. Gravatar Icon 6 SELaplana Apr 7th, 2008 at 10:33 pm

    I recently discovered that my footer was modified and inserted a code that insert unknown image. I don’t know if it was done remotely or just automatically inserted by a worm or trojan or whatever when editing it using the CPANEL or theme Edit function of wordpress

  7. Gravatar Icon 7 FruityOaty Apr 8th, 2008 at 12:06 am

    I was recently hacked too (index.php file) and iframes were injected in my posts. It resulted in my site getting banned from Google Search results (distributing spyware). All Google results pertaining to my site were slapped with this warning: “This site may be harmful to your computer.” As a result, traffic from Google trickled to ZILCH. My Adsense dropped too.

    It was hell fixing the issue. After the fix, I had to request that Google re-assess my site. It was given a clean bill of health just a couple of weeks ago.

    I wanted to write about the incident, but I was afraid of attracting the hacker’s attention again.

    Since then, I toughened up my site’s security… well, to the best of my knowledge. (It’s a bit technical for some people, this topic.)

    I really recommend this site: http://blogsecurity.net/

    Got a lot of useful tips & tools (plugins) on how to secure WordPress a bit more.

  8. Gravatar Icon 8 FruityOaty Apr 8th, 2008 at 12:09 am

    Oh, P.S.

    Try this plugin called WP Security Scan:
    http://wordpress.org/extend/plugins/wp-security-scan/#post-4986

    Scans your WordPress installation for security vulnerabilities and suggests corrective actions.

    -passwords
    -file permissions
    -database security
    -version hiding
    -WordPress admin protection/security

  9. Gravatar Icon 9 Maki Apr 8th, 2008 at 12:52 am

    How do you check if a blog is hacked?

  10. Gravatar Icon 10 Eugene Apr 8th, 2008 at 11:19 am

    Hmmm… I guess it’s an advantage that I’m not running on WordPress, Movable Type, or other popular blog CMSs.

  11. Gravatar Icon 11 yuga Apr 8th, 2008 at 1:29 pm

    Yes, the advantage of not using a popular blog CMS.

  12. Gravatar Icon 12 Showbiz Intriga? Get It From Boy! Apr 9th, 2008 at 2:29 am

    Congrats Yuga, great post! and i’m sure tons of revenue, lol..why? this blogpost is in the Wordpress Admin Page!!just imagine the traffic!

  13. Gravatar Icon 13 Wangbu Apr 13th, 2008 at 8:57 am

    It is sad but true that humans, Filipinos or otherwise, always have double edge capabilities: one side for creation, another side for destruction.

    I just would like to ask is there any international protocol governing hacks? Or any institution regulating internet activity?

  14. Gravatar Icon 14 Ro Apr 14th, 2008 at 3:23 pm

    It’s not really hacking — it’s just programming. They create programming code and stick in templates you use for free.

    It’s totally evil and it sucks though, you’re right. Just check your code out before your use it — any of it.

  15. Gravatar Icon 15 Ensio Apr 21st, 2008 at 9:34 pm

    I just downloaded a couple of free wp themes from http://www.wpthemesfree.com/. The zips are strange, especially those with funny German addresses seen on prewiev. IZArc hangs badly when unzipping footer.php. I havent installed those themes, though, and never will.

  1. 16 Deep Jive Interests » UPDATE: Has ZDnet Been Hacked As Well? Pingback on Apr 8th, 2008 at 12:21 am
  2. 17 Weblog Tools Collection » Blog Archive » Vulnerable WordPress Blogs Not Being Indexed Pingback on Apr 8th, 2008 at 10:26 pm
  3. 18 Your Blog Might Be Hacked » Webomatica - Technology and Entertainment Digest Pingback on Apr 8th, 2008 at 10:45 pm
  4. 19 Vulnerable WordPress Blogs Not Being Indexed | BlogBroker24-7 Pingback on Apr 8th, 2008 at 11:11 pm
  5. 20 2718.us blog - covert blog hacks? Pingback on Apr 8th, 2008 at 11:24 pm
  6. 21 links for 2008-04-08 « PinoyBlurker @ PinoyBlogoSphere.com Pingback on Apr 8th, 2008 at 11:32 pm
  7. 22 links for 2008-04-08 « PinoyBlogoSphere.com | PhilippineBlogoSphere.com Pingback on Apr 8th, 2008 at 11:33 pm
  8. 23 Blog Hacking | The Rock | xTended Pingback on Apr 9th, 2008 at 1:13 am
  9. 24 WP Trackback Spam Attack | YugaTech | Philippines, Technology News & Reviews Pingback on Apr 9th, 2008 at 1:39 am
  10. 25 Basic Thinking Blog | Vorsicht vor freien Wordpress-Templates Pingback on Apr 9th, 2008 at 1:49 am
  11. 26 bsod » Wordpress 2.5 Pingback on Apr 9th, 2008 at 5:02 am
  12. 27 wordpress sicherheitsaspekte - warum fremde themes und plugins riskant sind | linux,macs, asterisk und anderes Pingback on Apr 9th, 2008 at 8:05 pm
  13. 28 Technorati Tidak Mengindex Wordpress Blog | Daniel Daphone Pingback on Apr 10th, 2008 at 2:31 pm
  14. 29 FEWL.NET - Stars & Stripes Hacked! China Involved? Pingback on Apr 13th, 2008 at 11:08 am
  15. 30 Blog Hacked: It Could Happen To You - Internet Business Blog Pingback on Apr 20th, 2008 at 6:35 pm
  16. 31 WordPress Theme Submission | SeoLuv Pingback on Apr 21st, 2008 at 3:05 pm
  17. 32 Dissection of a hacked WordPress Theme (how the hacked themes inject links and how to detect them)  »  Chaos Laboratory Pingback on May 31st, 2008 at 2:39 pm
  18. 33 nathanr|ca » Vulnerable WordPress Blogs Not Being Indexed Pingback on Jun 6th, 2008 at 5:06 pm

Leave a Reply




English flagItalian flagKorean flagChinese (Simplified) flagPortuguese flagGerman flagFrench flagSpanish flagJapanese flagArabic flagRussian flagGreek flagDutch flagBulgarian flagCzech flagCroat flagDanish flagFinnish flagHindi flagPolish flagRumanian flagSwedish flagNorwegian flag
By N2H