Social Icons

Pages

Showing posts with label Blog Hijack. Show all posts
Showing posts with label Blog Hijack. Show all posts

Friday, 2 August 2013

Recovering Stolen Blogs Is Not An Open And Shut Case

Recently, we've seen a few problems reports, in Blogger Help Forum: Something Is Broken, requesting return of blogs stolen from the rightful owner.

Supposedly, the "rightful" owner is the person posting the problem report. We've learned from past experiences that this may not always be the case, however.

Long ago, when a stolen blog claim was posted in the forum, we could report it to Blogger Support as a "blog theft".

In many cases, given enough patience, Blogger Engineering and Google Legal would carefully examine the blog ownership history, and eventually restore the blog to its "rightful" owner. Unfortunately, even with the most careful forensic examination, the "blog theft" claim was occasionally used by hackers, to steal other peoples blogs.

Most recently, when "blog theft" is reported, Blogger Support declines to consider the case. Considering all of the issues, we generally see that they are making a responsible business decision.

Instead of spending massive amounts of time verifying individual claims, Blogger Engineering appears to be working on overall improvements to Blogger - to encourage blog owners to not put themselves, or their accounts and blogs, in unrecoverable positions.

Any blog which contains abusive material - whether malware, porn, or spam, or illegally obtained material - can be reported using the proper complaint form. Blogs which do not contain abusive material are the property of the current owner - and Blogger / Google will respect and support the current owner.

Blog owners, claiming theft, can generally report a stolen blog as abusive - if the current content justifies that claim. Other than that, the best solution is to hire a lawyer and convince a judge to issue a court order - and require Google Legal to become involved.

The issue of Blogger account and blog recovery is a long and painful one - for many people.

>> Top

Thursday, 9 May 2013

Blogger Blogs Redirecting To "opromo . com"

This week, we're seeing a new stream of problem reports, from blog owners whose blogs are, once again, mysteriously redirecting their readers to unknown destinations.
When I open my blog, it automatically directs to another search engine display.

This appears to be yet one more gadget, willingly installed by many Blogger blog owners, which is now redirecting uninterested viewers. The target of the redirection, this week, is a parked domain website (ie, "search engine display") - for a product which was apparently installed, willingly, by the blog owners.

It appears that the "opromo . com" free visitor meter is the latest victim of expiring domain registrations.

Overview for opromo.com

Registrar Info
Name PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server whois.PublicDomainRegistry.com
Referral URL http://www.PublicDomainRegistry.com
Status clientTransferProhibited

Important Dates
Expires On May 09, 2013
Registered On May 09, 2006
Updated On May 09, 2013
People who earlier installed the Opromo free visitor meter will need to uninstall it, as it's apparently no longer operational. Reliable replacements would be SiteMeter and StatCounter - as well as Google Analytics.

From what we've seen, identification and removal of the problem code seems to be straightforward - just access the dashboard "Layout" menu wizard, find the gadget identified, and remove it.

As always, you are advised to clear cache and restart the browser, after removal and before testing for success. If the gadget makes your dashboard redirect, before you can remove the redirecting code, use a well protected browser, like Firefox with NoScript, to block the redirection.

>> Top

Tuesday, 9 April 2013

Blogger Blogs Being Hijacked By The Sociable Gadget

We're seeing a steady stream of reports, from blog owners in Blogger Help Forum: Something Is Broken, from Blogger blog owners, reporting the latest hijacking of their blogs.
My blog is being redirected to a search engine display.
or
My blog has a porn popup attached!
These are all blog owners who have installed the latest hack, willingly distributed by Blogger / Google.

This appears to be yet one more gadget, intentionally installed by many Blogger blog owners, which is now redirecting unwilling viewers. The redirection target is a website which provides commercial advertisements for various Internet services, which creates a variety of symptoms, as reported in the forums.

The Sociable gadget appears to be a Blogger accessory installed from the Blogger "Add a Gadget" wizard, when selected intentionally by many Blogger blog owners.

As with many reported hijacks, access to the Blogger Layout wizard appears to be affected. If you need to remove this code from your blog, you may find yourself unable to use the Layout wizard. In this case, you will need to use Firefox with Noscript - or a similarly well protected browser - to prevent the redirecting code from executing.

After removing the identified code from your blog, as always, clear cache and restart the browser. Finally, I'll remind you again, to please be particular - only install third party code from trustworthy providers.

>> Top

Tuesday, 19 March 2013

Blogger Blogs Displaying Mysterious "SECURITY WARNING" Popup Boxes

This week, we're seeing a few concerned blog owners, in Blogger Help Forum: Something Is Broken, asking about a mysterious SECURITY WARNING popup box, on their blogs.

Like the earlier concern about the transparent boxes covering the blog, this appears to be another broken FaceBook Connect gadget.

The mysterious SECURITY WARNING isn't too hard to resolve.

Generally, the problem will start with a new FaceBook accessory, recently added.

<div id="fb-root"></div>
<script>(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "//connect.facebook.net/id_ID/all.js#xfbml=1";
fjs.parentNode.insertBefore(js, fjs);
}(document, 'script', 'facebook-jssdk'));</script>

<div class="fb-like-box" data-href="http://www.facebook.com/xxxxxxx" data-width="265" data-show-faces="true" data-stream="true" data-header="true"></div>

If you can identify the problem gadget in your blog, you can edit the gadget, and Remove it. Some owners have installed the code in question, in a specific post.

As an alternate solution, you may add CSS which will hide the warning. Using the "Add CSS" wizard in the Template Designer Advanced menu, add the following code:
#fb_xdm_frame_http, #fb_xdm_frame_https
{
display:none !important;
}

As always, after you add or remove the code in question, and save the changes, you will need to clear browser cache and restart the browser, to accurately test success in resolving the problem.

>> Top

Friday, 1 March 2013

Blogger Blogs Redirecting To "scmplayer . net"

This week, we're seeing a new stream of problem reports, from blog owners whose blogs are, once again, mysteriously redirecting their readers to unknown destinations.
When I open my blog, it automatically directs to another website, which is SCM Music Player.

This appears to be yet one more gadget, willingly installed by many Blogger blog owners, which is now redirecting uninterested viewers. The target of the redirection, in this case, is a website which is simply a commercial advertisement - for the product which was apparently installed, willingly, by the blog owners.

The website in question, "scmplayer . net", unlike some previous episodes of this nature, does not appear to be expired.
Overview for scmplayer.net

Registrar Info
Name GODADDY.COM, LLC
Whois Server whois.godaddy.com
Referral URL http://registrar.godaddy.com
Status clientDeleteProhibited, clientRenewProhibited,
clientTransferProhibited, clientUpdateProhibited

Important Dates
Expires On March 25, 2014
Registered On March 25, 2011
Updated On December 13, 2011

If we use a text only browser, such as an HTTP trace utility, the problem code is easily identified. Here's a redacted example, taken from the latest forum problem report.
<div class='widget HTML' id='HTML1'>
<div class='widget-content'>
<!-- SCM Music Player http : // scmplayer . net -->
<script type="text/javascript" src="http : // scmplayer . net/script . js"
data-config="{'skin':'skins/aquaOrange/skin.css','volume':50,'autoplay':true,'shuffle':true,'repeat':1,'placement':'top','showplaylist':false,'playlist':[{'title':'Waves','url':'http://youtu.be/IFS0Eo1eh6Y'},{'title':'Money Trees','url':'http://youtu.be/jSXiNdTbTA4'},{'title':'Keep it Moving','url':'http://youtu.be/XqRC_Fh--js'},{'title':'Find Away','url':'http://www.youtube.com/watch?v=KS6zq6_iMCk'},{'title':'Do your Love','url':'http://www.youtube.com/watch?v=2zVwbgXaMRo'},{'title':'Bitch Don%27t Kill My Vibe','url':'http://www.youtube.com/watch?v=OcYvaLIgjTk'},{'title':'True Livin','url':'http://youtu.be/wMFHqqiR3Co'}]}" ></script>
<!-- SCM Music Player script end -->


From what we've seen so far, identification and removal of the problem code seems to be straightforward - just access the dashboard "Layout" menu wizard, find the gadget identified, and remove it.

As always, you are advised to clear cache and restart the browser, after removal and before testing. If the gadget makes your dashboard redirect before you can un install the misbehaving code, use a well protected browser, like Firefox with NoScript, to block the redirection.

>> Top

Monday, 4 February 2013

Check Your Template, And Look For Unfamiliar JavaScript Code, Following Odd Blog Behaviour

Recently, we've been seeing some odd problem reports in Blogger Help Forum: Something Is Broken, suggesting deviously hijacked blogs.
My blog is requesting me to login, using a user name and password, when I view it.
Given the URL of the window requesting the login, it's a simple matter for us to use the right forensic Internet software, and to locate a relevant snippet of code, frequently installed as part of the blog template.

Sometimes, when we reply to the blog owner with advice to remove a bit of dodgy code, we get a response suggesting disbelief. Our advice
Use the Template Editor, and remove the highlighted code snippet.
may receive a confused or skeptical response.
Where did that bit of code come from? I never installed that!
How did the code in question get installed? Discussion of one possible scenario may require thinking outside the box. Not every unrecognised blog change is being caused by memory loss by the blog owner, after an intentional accessory install or template tweak.

Looking at the subject / theme of some blogs involved in recent problem reports, we're seeing a beginning of a trend, which may indicate a new - and very subtle - blog hijacking technique. We know that Blogger blogs are subjected to brute force password guessing attacks, and we know that Blogger / Google has to consider the possibility that a brute force attack detection is made after the attack was successful.

Current blog security, and defense against blog hijacks, involves detection of hijack attempts, by Google Security. It's possible that some blogs, with some owning Blogger accounts and passwords, are more vulnerable to sophisticated password guess hacking.

When you login to Blogger or Google, you hopefully know the right account name and password, and are generally able to get logged in - after maybe one or two mistakes. You learn, soon enough, that if you have to guess your account name or current password - and you require more than a couple tries - you may have to solve yet another CAPTCHA, or request account unlock, to continue.

The ever unpopular CAPTCHA / locked account comes from Google, detecting a possible brute force attack in progress, and protecting your account and your blogs. A Blogger blog, with its content providing enough clues, combined with a simple account password that is easily guessed, may allow an experienced hacker to login to your account in one or two tries, without being detected by Google attack monitors.

It's alternately possible that some attacks are being conducted by very patient hackers, who are able to use days, and / or thousands of different computers, to conduct a throttled brute force password attack. Again, just attack without providing a detectable pattern.

This may help to explain the mysterious spam blog setups, of last year.

A hacker, able to login to a Blogger account without being detected, could install small changes in a blog template without ever being discovered. The blog owner would never discover subtle template changes, made by an easily satisfied hacker.

Finally, install latent code that does not activate immediately, as we observed during Winter 2009 / 2010, so no blogs show symptoms until the hack is installed on thousands of blogs. If one or two blog owners discover the odd code in their blogs, who would ever suspect their blog being part of a massive cloud of victims?

If you report odd behaviour by your blog, you write to Blogger Help requesting advice, and you are advised to remove a bit of dodgy code from the template - and you do not remember having installed the noted dodgy code - you may want to review your Blogger / Google password, and make the password harder to guess. Better still, start using 2-step verification for logging in to your Blogger / Google account.

>> Top

Thursday, 22 November 2012

Use A Well Protected Browser, To Block Redirecting From Misbehaving Code And Gadgets

Regularly, in Blogger Help Forum: Something Is Broken, we advise people about problem code or gadgets in their blogs.

Generally, this follows reports by blog owners, that their readers are being redirected to unexpected and unwanted blogs and websites, from their blogs. Sometimes, we get the reply
I can't remove the code. Every time I login to Blogger, I am redirected, just as my readers are being treated!

When we see the latter complaint, we recognise yet one more blog owner who does not know how to properly protect himself, from malicious code and websites. Most people, who know about Layered Security, know that proper browser security is an essential complement to a properly chosen and maintained anti malware filter.

Many people, who care about browser based security, use Firefox with NoScript.

This combination provides Unix level security, "deny by default, permit by exception". Simply install NoScript as an add-on, to Firefox, to get started. Alternately, you may use Chrome with ScriptSafe, or Opera with NotScripts.

When using your browser with a script filter, there will be specific Blogger / Google websites which you should trust, and others which you should not trust.

Every time you surf to a different website - and decide that the owners of the website, which you are now viewing, have your best interests in mind - configure NoScript to allow that website, to display properly on your computer. When you find that a trusted host website does not display properly, examine the NoScript taskbar and the list of websites used by the host website. Look at the NoScript Options menu, carefully. Allow specific websites which you trust, and Forbid all other websites which you do not trust.

Deciding which websites to trust, based on their presence in the NoScript Options menu, will be a learning experience for a while. For some host website pages, which use a large number of unfamiliar websites, you may have to carefully select to "Temporarily allow all this page" - or you can "Temporarily allow" each single website, one by one, until the host website page displays properly.

When you decide to (permanently) "Allow" any website, that website will be "Allowed" on all other host websites where you may surf. Conversely, any website which you never select to "Allow" - such as the problem website which is providing the misbehaving code - will never execute on your computer again. This will prevent redirection on your computer, allow you to safely use the Blogger dashboard, and edit or remove any dodgy code which may be part of your blog.

After removing any dodgy code from your blog, always clear cache and restart Firefox, to test the effects of your editing.

>> Top

Tuesday, 20 November 2012

Add A Simple "Recent Comments" / "Recent Posts" Gadget To Your Blog

The recently observed problems with some third party gadgets, previously added by many blog owners to their blogs, leaves these (and other) owners lacking a useful feature in their blogs. For many blog owners, fortunately, this is not an impossible problem to resolve.

Blogger provides us with a native accessory, called a "Blog Feed" gadget, which will provide acceptable "Recent Comments" and "Recent Posts" functionality, for many blog owners.

Look at the sidebar of this blog, for "The Real Blogger Status - Comments", and "The Real Blogger Status - Posts". Those are "Recent Comments" and "Recent Posts" gadgets, based on the Blogger supplied "Feed" gadget - which is not a third party accessory, and is not subject to future third party peccadilloes.

To make your new gadget, start with the URL of the blog feed desired. Then, add a Blogger supplied Feed gadget, using the "Add a gadget" wizard, in the dashboard Layout display.

This is the URL of this blog.
http://blogging.nitecruzr.net

This is the URL of the blog comments feed.
http://blogging.nitecruzr.net/feeds/comments/default

This is the URL of the blog posts feed.
http://blogging.nitecruzr.net/feeds/posts/default

Setting up a "Blog Feed" gadget is simple enough.
  1. Add a "Feed" gadget (Only select the "Feed" gadget, "By Blogger"!!!), using the "Add a gadget" wizard. Avoid any similarly named gadget not "By Blogger".
  2. Plug in the Feed URL (see my examples above), and Continue.
  3. Review / change the options offered, and Save.
  4. Test your new blog accessory - provided by Blogger - with no future hacking activity anticipated.

And, you're done. Wasn't that simple?

>> Top

Friday, 9 November 2012

Blogger blogs redirecting to "scrapur . com"

This week, we've seen several reports in Blogger Help Forum: Something Is Broken, from Blogger blog owners, reporting the latest hijacking of their blogs.
My blog is being redirected to a spam site - was it hijacked?


As is all too frequently the case, the redirection appears to come from third party code or gadgets, willingly installed by the blog owner. Examination of the website in question appears to indicate a long expired domain.
This domain name expired on Nov 7 2012 11:32:24:000AM
It's possible that, right now, this is not a maliciously planned hijack - though any expired domain can be re purchased for a devious or malicious purpose.

In several cases, the redirecting code appears as part of an installed XML gadget, a version of "Recent Comments". In other cases, we have observed naked JavaScript code, installed directly into the blog template. Here are identified examples - though you may see other variants.
<script style="text/javascript" src="http : // scrapur . com / index / wp-content / uploads / 2008 / 04 / rc . asp"> </script>
or possibly
<script src='http : // scrapur . com / index / wp-content / uploads / 2008 / 02 / smile . js' type='text/javascript'></script>
(Note the URLs have been modified, to prevent search engine indexing of a potentially malicious domain).

Use of a text proxy, such as Rex Swain's HTTP Viewer, when run from any browser, will allow you to safely examine the blog source, without interference by the redirecting code. In this case, simply load your blog using the URL, then use the browser test search, for "scrapur", in the proxy log. This will let you see if the code in question is part of an HTML gadget - or it is installed directly in the template.

As with many reported hijacks, access to the Blogger Layout and Template wizards appears to be affected. If you need to remove this code from your blog, you may find yourself unable to use either the Layout wizard (to remove an identified gadget) or the Template wizard (to remove directly installed code). In this case, you will need to use Firefox with Noscript - or a similarly well protected browser - to prevent the redirecting code from executing.

After removing the identified code from your blog, as always, clear cache and restart the browser. Finally, I'll remind you again, to please be particular - only install third party code from trustworthy providers.

>> Top

Friday, 26 October 2012

Blogger Blogs Redirecting To "blogspot - ping . com"

Today, we see the latest in the never ending saga of blog owners, who previously (maybe / maybe not recently) installed some deviously created software - whether intentionally or not - and who now find their readers unable to view their blogs, and themselves even unable to access the template editor to remove the malicious code.
My blogs are redirecting auto to ping . blogspot - ping . com", can anybody tell me how to fix this?


The malicious redirecting appears to be cause by a small snippet of JavaScript code - which has been installed, in most cases, as template HTML. Alternatively, some blog owners have added separate HTML / JavaScript gadgets, to host this code.

It's easy enough to identify - not so easy to remove, as some owners have found. In many cases, we are seeing reports that even when directly accessing the Layout wizard or Template Editor, the malicious code activates, and redirects the blog owner's browser.

Since the redirect is running from a snippet of JavaScript code, blocking the malicious code will prevent the redirection, and allow corrective access to the Layout wizard or Template Editor.
<script src='http : // ping . blogspot - ping . com / ping . js' type='text/javascript'></script>
Whichever GUI wizard you use to remove the code, remember to clear cache and restart the browser after removal and before testing for success.

Since I routinely - and consistently - use Firefox with NoScript to browse, I was able to access one victim blog without the redirection occurring, view the blog source, and extract the above code. If you use NoScript, you (the blog owner) should be likewise able to access your dashboard, and the Template Editor, and remove the bogie.

Please note that the code snippet, excerpted above, has extra spaces inserted into the URLs, to prevent advertising of the actual hijacking domain.

Anybody who knows where this bogie originated, and how it was deviously conned upon the blog owners, can help a lot of people by identifying the origin. Only when this is done, can we try to prevent the problem - rather than advise how to remove the problem.

First, install the popular Mozilla browser, Firefox. Having added Firefox, install the add-on NoScript. NoScript uses a Unix level security policy.
Deny by default, permit by exception.
Keep in mind the different trust levels of Blogger and BlogSpot - with NoScript, you will have to allow Blogger, yet forbid BlogSpot. Code from unknown domains, such as "blogspot - ping . com", will not run on any NoScript protected computer - unless you, intentionally, enable it. Knowing the threat from this bogie, you will hopefully choose to not enable this domain.

>> Top

Thursday, 27 September 2012

Blogger Blogs Being Hijacked By Instagram Gadgets

We're seeing a noticeable amount of noise today, from blog owners reporting that their blogs appear to be susceptible to antivirus detection - and others reporting that their readers are complaining of mysterious misdirection, when viewing their blogs.
My blog is struggling to fully load, and hangs saying "Waiting for platotv . com" and "Waiting for directagain . net"
and
I'm getting warnings from Avast when I try to view my blog!


Upon examination of the blogs affected, we see a large number which contain the "I'm An Instagram Addict!", or similar, gadget. Most blog owners who admit to having an Instagram gadget have reported relief, having removed the gadget in question. We're still looking, to see where these dodgy gadgets are coming from.

(Update 2012/10/08): We are now seeing suggestions from various people, representing themselves as employees of "BadgePLZ", suggesting that the problems with their code has been fixed.

If your blog is generating antivirus alerts - or if your readers report misdirection - you may wish to remove any Instagram accessories, recently installed. You may wish to clear cache and restart the browser, after removal. You may need direct access to various dashboard wizards, in some extreme cases.

Right now, the majority of the problems reported seem to involve an "IFrame", targeting "badgeplz . com".
<iframe src='http : // badgeplz . com / instagram / ?u=mun_mun90&t=c&bgclr=f2f2f2&brclr=cccccc&px=1&py=5&pb=5&brds=5&incls=n&svc=instagram&pbclr=ffffff&sze=75' allowtransparency='true' frameborder='0' scrolling='no' style='border:none; overflow:hidden; width:118px; height: 482px'></iframe>
We're currently unsure whether this is an intentional hijacking, or simply bad coding. Until the owners of "badgeplz . com" state their intentions, we'll simply advise you to remove this gadget, if you have added it to your blog.

As usual, I'll caution you against indiscriminate installation of third party gadgets, in general.

>> Top

Wednesday, 25 July 2012

Blogger Blogs Redirecting To "kunoichi . info"

In the latest round of blog hijacks, from misbehaving or miswritten accessory gadgets, we have reports this month in Blogger Help Forum: Something Is Broken about blogs redirecting to "kunoichi . info".
My Blogger site, xxxxxxx . blogspot . com, with over 8 years of blog posts archived, has been redirected without my permission, to "kunoichi . info". I see my blog for a few seconds before it goes to the new site.

If we use a text only browser, such as an HTTP trace utility, the offending code is directly visible. Here's an example, taken from the latest forum problem report (and rigourously redacted).

<div class='widget HTML' id='HTML2'>
<h2 class='title'>Recent Comments</h2>
<div class='widget-content'>
<script style="text/javascript" src="http : // kunoichi . info / blogger _ buster / comments.js"></script><script style="text/javascript">var a_rc=5;var m_rc=true;var n_rc=true;var o_rc=100;</script><script src="http : // xxxxxxx . blogspot . com /feeds/comments/default?alt=json-in-script&callback=showrecentcomments"></script>

So far, identification and removal, of the problem code, seems to be straightforward - just access the "Page Elements" wizard (Classic Blogger GUI) or the "Layout" menu wizard (New Blogger GUI), find the offending gadget, and remove it. As always, you are advised to clear cache and restart the browser, after removal and before testing.

>> Top

Tuesday, 24 July 2012

Having A Blogger Blog Removed Or Restored, After Death Of The Blog Owner - The Next Chapter

The question of disposition of blogs, left behind by deceased blog owners, comes up in Blogger Help Forum: How Do I?, from time to time.

As Blogger blogs - and similar Google products - become mature, and as more people who publish Blogger blogs become susceptible to old age and death, this problem will become more critical. As recently as 2010, in order to assume control (or request deletion) of such a blog, Blogger required only a faxed copy of the death certificate.

We are now seeing that the death certificate is only one part of a formal procedure, which Blogger / Google now uses, in the dual role of
  • Compassion, in allowing a friend or loved one to appropriately assume control of blogs left behind.
  • Due Diligence, in preventing fraudulent claims by people who have no legal or moral right to assume control of blogs.
Both roles are righteous, and are needed to help Google reduce hijacking of active Blogger blogs.

As part of an improved procedure for disposition of Blogger blogs left behind by deceased owners, Blogger now uses GMail Help: Accessing a deceased person's mail as guidelines. The new guidelines
  1. Use a two part process - a preliminary review, followed by a formal court documented process.
  2. Include a dedicated facsimile transmission / postal mail address.
  3. Include additional requirements, which formally identify the relationship of the person requesting control of the blog in question, to the deceased.

The preliminary review specifies a facsimile transmission / postal mail address:
Google Inc.
Gmail User Support - Decedents’ Accounts
c/o Google Custodian of Records
1600 Amphitheatre Parkway
Mountain View, CA 94043
Fax: 650-644-0358
and a formal list of material required, for Part 1 - preliminary review.
  1. Your full name.
  2. Your physical mailing address.
  3. Your email address.
  4. A photocopy of your government-issued ID or driver’s license.
  5. The Gmail address of the deceased user.
  6. The death certificate of the deceased user. If the document is not in English, please provide a certified English translation prepared by a competent translator and notarized.
  7. The following information from an email message that you have received at your email address, from the Gmail address in question:
    • The full header from the email message. See instructions on how to find headers in Gmail and other webmail email providers. Copy everything from 'Delivered-To:' through the 'References:' line
    • The entire content of the message
When specified by Blogger Support, we were instructed to substitute the blog URL, for the Gmail address (as #5). No addendum referencing the email message (as #7) was provided.

The instructions for Part 2 are not as well defined, as for Part 1.
Part 2 will require you to get additional legal process including an order from a U.S. court and/or submitting additional materials. Please note that submitting these materials will not guarantee that we will be able to provide Gmail content so we recommend not embarking on Part 2 until you hear back from us regarding Part 1.

These requirements may seem onerous to the less observant. Actually, by formalising the process, this should reduce the number of fraudulent claims, and make it easier for Google personnel to legitimately process claims, while exercising both compassion and due diligence.

>> Top

Friday, 6 July 2012

Blog Control And URL Availability Hacking - Four Sides Of The Same Story

Occasionally, in Blogger Help Forum: How Do I?, we see various queries about our blogs, and how to gain or regain control.
  • How do I get a blog, which is attacking me (impersonating me, insulting me, publishing my secrets), removed from Blogger?
  • How do I claim a dormant URL?
  • How do I recover control of my blog?
  • My blog is now under somebody else's control! How do I get my blog back?
In some cases, all of these queries are simply one more attempt to gain control of a blog, or a URL. As we gain experience in reading between the lines in Blogger Help Forum, and as Blogger Support gains experience in researching blog histories, we can start to see patterns, and signs of multiple attempts to assume control of the blog - or the URL - in question.

Many blog or URL hacking attempts start quite innocently. Two of the more common ones are quite naive, and completely separate, tales.
Some people, denied recovery of the blog, because they can't prove ownership, will try another tactic.
I'll tell them that the blog was stolen from me. Surely if they think the blog was hacked, I can get it back, since I used to be the owner!
People trying to gain control of a dormant blog will likewise use their imagination.
If I get the blog deleted as spam, I can grab the URL. Surely a Dormant blog is just another type of Spam, in Blogger!
Unfortunately, these techniques have been used, already - and have resulted in still other tales of anguish.

It requires the wisdom of Solomon - and the patient persistence of Gil Grissom - to sort through the problems reports. Claims
I just graduated from college, and I can't use my email address to recover the password!
and
I just woke up from a 7 year coma, to find my family blog under control of a hacker!
and let us not overlook
My friend just died. Can I please have control of the blog, so I can put a notice to all of his friends, on the blog?
and
I never updated my Blogger only account to a Blogger / Google account - and I never got any email, warning me of the impending change!
All of these tales have enormous human interest - and seem to justify mercy for the plaintive requests.

Unfortunately, these stories - and others like them - are not always what they seem. What we sometimes see are the other side of the story.
  • Attempts to steal control of an active blog.
  • Attempts to gain control of the URL which would be perfect for their new blog, if only the URL was available.
  • Attempts to probe and reveal the identity of a blog owner, who is guaranteed anonymous blog ownership, by Blogger policy.

So, if you beg and plead for attention
None of these tools help me, in the least. Can I please speak to a live human, so I can explain my special need?
Please, do not be surprised to be directed to read about why Blogger Help is the only contact, and why you absolutely must prove ownership of the blog, before being given control. And even the ultimate insult, you must provide a copy of the death certificate plus get a court order, as you grieve for the loss of your friend or loved one.

The bottom line here is that, if you intend to publish a Blogger blog, it is your responsibility - and only your responsibility - to maintain control of your blog. You are an adult (or are presumed to be one) - and you have responsibilities, as an adult.

>> Top