Social Icons

Pages

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Saturday, 28 September 2013

Team Blogs, And Confusion About Blogs Locked After Detected Account Hacking

We've been discussing deleted blogs, resulting from Blogger accounts locked after suspicious account activity is detected, for some time.

Recently, we've seen a variant on the account lock / deleted blogs problem.
I made one of my friends an admin for my blog. When Blogger deleted His Blogger account and his blogs, they deleted my blog also.
Here, we see the possibility of detected hacking, affecting other members in a team blog ownership.

If someone sets up a blog, then invites his friends to be administrators, everybody on the team becomes equal owners. This can also happen when one person maintains two or more Blogger accounts - whether accidentally or intentionally.

That's the definition of a team blog - and it's one known problem with team blogs. This case shows us another problem with team blogs.

If somebody on the team has a Blogger account locked for detected hacking, all blogs owned by that account are taken offline, for security checking. Any blogs owned by that account are going to simply disappear from the dashboards of all owners - because all owners produce the same security risk, to any owned blogs.

When a Blogger account is locked, review of blogs owned by the account starts after the account is unlocked. If the team member with the locked Blogger account doesn't get the account unlocked, the blogs owned can't be reviewed.

Once again, we see why it's a good idea to only have active team members, as blog owners.

>> Top

Sunday, 22 September 2013

Account / Blog Recovery May Involve Your Friends Email Archives

Recovering ownership of a Blogger account or blog may be a frustrating process.

Recovering control of a long forgotten account or blog starts with having a token sent to the recovery email address. If you don't have access to the recovery email account, you may be able to use the Google Account recovery wizard - if you can at least provide the email address that you used long ago, and a few personal details.

But what if you don't even remember the email address? Blogger won't just tell you what the address was.

In the latter case, you may have to involve your friends - and some detective work.

Now, you hope that when you registered your Blogger account long ago, you provided an email address that you used for real life activity.

When you need to identify the email address used, long ago, for registering your Blogger account, think back. Who did you email, long ago, around that time, for serious discussions?

If you're lucky, one of your friends, carefully searching her / his email archives, can find your email - and provide the email address that you were using.

With help from your friend, and now knowing the email address, that may even help you remember the password that you may have used. If you're lucky, you may be able to use that email address and password, and instantly recover control of the blog. Just don't spend a lot of time guessing, and cause account lock (aka "suspicious activity").

Having recovered the email address, try the Google Account recovery wizard, again. This is your best bet. Without this, you're probably going to need to establish your identity using a court order, issued by a sitting judge.

>> Top

Wednesday, 28 August 2013

Being A Hacking Victim Is Not Always The Fault Of The Account / Blog Owner

Even though being the victim of a hacking attack is not (always) the fault of the account / blog owner, the blog owner may have to bear some of the responsibility.

Since hacking detection is a fuzzy process, it's not always going to be detected immediately. The previous article discusses what happens when Google does detect a hacking attack - and in some cases reacts too diligently.

If Google is not able to detect an attack, in some cases, an attack may be successful.

With some blogs, that are not updated frequently, a hacker may take control, and successfully hijack a blog.

Occasionally we see another report
I just discovered that my blog contains spam - and I can't access the dashboard, to clean the blog!
This may well be a successfully hijacked blog, discovered too late.

Unfortunately, the latter report may also be another devious attempt to steal control of somebody's blog. Blogger Support cannot, reliably, support hacking recovery, on an individual basis.

From what I can tell, Blogger / Google is working on the larger picture - making the automated detection process more reliable. Given this concern, Blogger / Google won't be frequently available to diagnose and return control of individual hijacked blogs - even when the issue is righteous.

In general, blog owners have to support themselves, and learn how to protect themselves. This may be yet one more reason why 2-Step Verification is becoming less optional.

>> Top

Friday, 2 August 2013

Recovering Stolen Blogs Is Not An Open And Shut Case

Recently, we've seen a few problems reports, in Blogger Help Forum: Something Is Broken, requesting return of blogs stolen from the rightful owner.

Supposedly, the "rightful" owner is the person posting the problem report. We've learned from past experiences that this may not always be the case, however.

Long ago, when a stolen blog claim was posted in the forum, we could report it to Blogger Support as a "blog theft".

In many cases, given enough patience, Blogger Engineering and Google Legal would carefully examine the blog ownership history, and eventually restore the blog to its "rightful" owner. Unfortunately, even with the most careful forensic examination, the "blog theft" claim was occasionally used by hackers, to steal other peoples blogs.

Most recently, when "blog theft" is reported, Blogger Support declines to consider the case. Considering all of the issues, we generally see that they are making a responsible business decision.

Instead of spending massive amounts of time verifying individual claims, Blogger Engineering appears to be working on overall improvements to Blogger - to encourage blog owners to not put themselves, or their accounts and blogs, in unrecoverable positions.

Any blog which contains abusive material - whether malware, porn, or spam, or illegally obtained material - can be reported using the proper complaint form. Blogs which do not contain abusive material are the property of the current owner - and Blogger / Google will respect and support the current owner.

Blog owners, claiming theft, can generally report a stolen blog as abusive - if the current content justifies that claim. Other than that, the best solution is to hire a lawyer and convince a judge to issue a court order - and require Google Legal to become involved.

The issue of Blogger account and blog recovery is a long and painful one - for many people.

>> Top

Tuesday, 23 July 2013

Anonymous Blog Ownership, And Hacked Account Detection

This week, we're seeing a number of reports from blog owners with Blogger accounts recently hacked.
I was asked to change my password, because of suspicious activity. Having done that, my blogs are now deleted!

With hacked Blogger / Google accounts, causing deleted blogs, there's not a lot of advice that we can provide.
As you just discovered, the account is recovered almost immediately. Blog recovery, unfortunately, takes longer - sometimes, 1 to 2 days. You'll have to wait, patiently, until your blogs are verified by Google Security staff.

We're also seeing the normal amount of reports of blogs deleted by Blogger, when detected for malware, porn, or spam. In some cases, blog review ends with the conclusion that the blog was not, in fact, deleted for a TOS violation. In these cases, the blog won't be restored by Blogger Support.

In some cases, blog review - which starts with a claim of spurious classification for malware, porn, or spam hosting - ends with advice to have the owning Blogger / Google account recovered.

The blog owner has to wait until the review process is complete, to learn where he should have started, days ago. As I've observed a few times in the past, anonymity - whether intention or accidental - can cause problems with blog ownership. If your Blogger / Google account is locked, but you don't get the required notification, you can waste valuable time with the blog offline.

Whether you intentionally anonymise yourself - or accidentally create a second (or third) Blogger account, you may not get essential email from Google, advising you to recover your account. When that happens, your blog will stay offline until it can be reviewed - and review starts only after you recover the account that was locked.

Now, you're going to have to open every possible email account, and carefully look for the overlooked email. If you never find the missing email message, you're going to have to login to Blogger, using every possible email address that you may have ever used, until you hit the locked Blogger account.

When you do identify the locked account, you'll get the advice to change your password, solve a CAPTCHA, and / or answer a number of secret questions, to prove that you are the account owner. Or, if you're lucky, you can await a phone call (digital or voice) with a special code, to unlock your account. Either way, you'll be unlocking the account while under stress, with the blog offline.

And after you get the account unlocked, you'll still have to wait until the blog(s) can be verified.

If you try to blame Google, for this disaster
Why was my blog deleted? I did not spam!
you will simply be wasting your time. This is yet one more story that starts with gratuitous and uncontrolled creation of multiple Blogger accounts and email addresses.

>> Top

Wednesday, 3 July 2013

Hacking Detection Is (Generally) Not The Fault Of The Blogger Account Owner

We've been helping Blogger blog owners deal with spurious fuzzy content classification, for many years.

We started out, long ago, with blogs deleted because of spam classification. Later, Blogger added malware classification - and most recently, porn classification ("adult content", with objectionable advertisements). These three classification categories involve fuzzy blog content analysis.

A fourth category, which similarly results in blog(s) being deleted, I describe as "hacking detection". This category complements the other three, because the primary symptom of all four are remarkably similar.
Help me! Blogger has deleted my blog!!
This is a frequent complaint, seen in Blogger Help Forum: Something Is Broken.

One problem with using the term "hacking" is that some account owners take this diagnosis personally.
Why do you mention hacking? I am not a hacker!
And in almost all cases, the owners are correct.

Blogs are deleted by Blogger, currently, because of several different reasons.
  1. DMCA Violation.
  2. Hacking detection.
  3. Malware detection.
  4. Porn detection.
  5. Spam detection.
I list the different categories, collectively, because they are frequently reported, using the common symptom.
My blog was deleted, and I did not do it!

DMCA, malware, porn, and spam are generally based on what the blog owner did (though in many cases, what the owner "did" was simply to publish a blog). Hacking, on the other hand, is generally based on action by someone other than the blog owner.

DMCA, malware, porn, and spam classifications are based on content analysis (automated), or complaint (manual) - and these classifications can be somewhat avoided by the blog owner. Don't steal content or publish a blog containing malware, porn, or spam, to reduce your chance of having the blog classified.

Hacking detection, on the other hand, is based on analysis of Blogger account traffic - and this classification can not be avoided, as easily, by the blog owner. Hacking generally involves use of a cloud of computers, to systematically break into a Blogger account owned by the victim.

Though frequently, a hacking attack starts with unintentional disclosure of personal information by the victim, actual hacking activity is typically not initiated by the victim.

Detection of hacking attacks is best conducted by Google, because they can look for repetitive activity against multiple Blogger / Google accounts, from multiple computers located worldwide.
  • Most account owners can login to their accounts in one or two tries.
  • Very few account owners will, intentionally, attempt to login to their accounts, concurrently, from computers in Argentina, USA, and Zaire.
  • Very few computers will be used to access Blogger accounts owned by people in Brazil today, in China tomorrow, and in Denmark next week.

Recovery from hacking detection requires willful action by the victim - though Blogger makes the required action so simple, its purpose becomes transparent. The victim, or account owner, is simply required to change the account password, solve a CAPTCHA, and / or verify account ownership by providing various personal details.

Having initiated hacking recovery, the account owner is able to login to Blogger - but is greeted by an empty dashboard.
You are not yet the owner of any blogs. Create a blog, and get started!
This is where the confusion starts.

Not all Blogger account owners personally publish a blog. Some people setup Blogger accounts simply to comment on, and / or Follow blogs published by other people - and won't, necessarily, publish a blog using the account in question.

Blogger accounts with no owned blogs may still be under attack by hackers - and are subject to hacking detection. This makes the primary symptom so confusing.
You are not yet the owner of any blogs. Create a blog, and get started!
People who don't own any blogs (under this Blogger account) may, or may not, see this as a problem.

In cases where the initial symptom is a deleted blog, the blog owner must recover the hacked (locked) account, before the blog can be recovered. This is one more scenario where unplanned, anonymous blog ownership, just causes more confusion.

Having initiated hacking recovery, a blog owner is simply expected to wait patiently, until the blogs owned by the account are verified as free of content added by the hacker. Unfortunately, we sometimes see the blog owner, impatiently reporting in Blogger Help Forum: Something Is Broken.
I had to change my password, and having done that, Blogger deleted my blog!

Sometimes, hacking detection starts with the Blogger account owner, repetitively trying to recover access to the account, by sequentially trying every possible password (sometimes trying the same password, repeatedly).
I know it's one of these! But which one? Did I maybe type the one, incorrectly??
This repetitive action looks the same as any malicious hacking attack - and that is why hacking detection is so hard to canonically diagnose.

Please, consider these details, the next time you post your problem report.
Help me! Blogger has deleted my blog!!
In some cases, I may respond with a mention of hacking detection. If I do that, please don't take my response as a personal attack upon you.
Why do you mention hacking? I am not a hacker!

Even though being the victim of a hacking attack is not the fault of the account / blog owner, that person may still have to bear some of the responsibility. In general, blog owners have to support themselves - learn how to protect themselves, and use 2-step verification.

>> Top

Tuesday, 25 June 2013

Use Google 2-Step Verification, To Protect Your Blogger / Google Account - And Your Blogs

Our Blogger accounts, and blogs, are under persistent attack by some rather nasty Internet users.

Hackers, using other peoples computers, are constantly attempting to "guess" our Blogger passwords, and take control of our Blogger accounts and blogs. Blogger accounts are particularly vulnerable to attack, because too many blog owners
  • Reveal their account names (email addresses) to the world.
  • Base their passwords upon real life details.
  • Publish blogs, where their real life details are visible to the world.

Some blog owners think that by using only one computer forever, they should be able to register that one computer as theirs, and require Google to simply deny access to their Blogger / Google accounts, from any other computer. This is a very simple solution - and it's one which is doomed to failure.

Google knows that even the most careful person will periodically use a different computer - or possibly forget their Blogger account name and / or password.

Rather than attempt to restrict us to using one single computer, for eternity, Google gives us an option to use a previously registered telephone as an authentication token, whenever we use a different computer. The telephone can use either text or voice, and provide us with a one use passcode, to enter after we successfully enter our account name and password.

This is not a foolproof solution.
  • Some people will not want to provide their phone number, to Google.
  • This strategy will only work with a preregistered phone - and registration can only be done when we are logged in to Google.
  • If the pre registered phone uses text (a smart phone / mobile computer), it will be usable only where cellular service is available.
  • If the pre registered phone uses voice, it will be usable only as well as we understand computer synthesised "speech".
  • In either case, in some cases, stress will contribute to the possibility of making a mistake.
  • Since a pre registered phone is required, we will be able to use this only as long as we carry our smart phone - or login from a pre determined location.

However, if we can deal with the above drawbacks, we have a much better chance of keeping our Blogger accounts and blogs under our control. Very few hackers, having successfully provided our account name and password, will be able to immediately use a pre registered telephone, to accept a one time use passcode.

>> Top

Monday, 24 June 2013

Hacking / Malware / Porn / Spam Classification, And Effects Upon Search Engine Reputation

Occasionally, we see concern in Blogger Help Forum: Something Is Broken, about the long term effects of Blogger hacking / malware / porn / spam classification or detection.
My blog was deleted, because of spurious spam classification - and later restored to service. Did my blog lose search engine reputation, in Google?

Any time a blog goes offline, its reputation is affected, to some extent. How much effect a hacking / malware / porn / spam classification or detection has, on any given blog, will vary widely.

Every blog or website has different factors, which affect its reputation.
  • Readers, and links in their blogs and websites.
  • Readers, and inherent reputation.
  • Search engines, and inherent reputation.
These factors will differ, from blog to blog, in almost infinite variety.

If your blog has readers who maintain their own blogs and websites, some will see you as a useful source of information, and will link from their blog / website, to your blog. As a readers blog / website is indexed by a search engine bot, and a link to your blog is encountered, your blog is indexed. This causes indirect search engine reputation.

Any time your blog is offline, even briefly, it loses reputation. If you use Google Webmaster Tools, look at the indexing logs. One event which you will see, from time to time, mentions "404 Not Found". Any time a search engine bot is indexing your blog, and it encounters a "404 Not Found", your blog loses reputation.

Loss of search reputation is similar to a person dying from blood loss. How fast the blood loss, and how long the loss continues, will affect how likely death will occur.

The longer your blog is offline, the more "404 Not Found" events will be logged, as the search engine bots attempt to index the various pages in the blog. Each succeeding "404 Not Found" represents your blogs reputation, leaking away, drop by drop. The longer your blog is offline, the more reputation loss it suffers, from indirect and direct indexing.

Until reputation is regained, your blog appears lower in search results, because of lower page rank. You suffer from less search engine generated traffic, and less new readers. This is a circular effect - less search engine reputation leads to less new reader traffic, which leads to less search engine reputation.

When your blog is reviewed and restored to online status, indexing resumes. Each time a search engine bot indexes the blog, and does not encounter a "404 Not Found", reputation picks up, again. Slowly, your blog regains its former reputation.

All 3 factors contribute to the loss of reputation, while the blog is offline - and to the regaining of reputation, when the blog is restored. This is similar to the effect of re indexing after the URL is changed.

How much reputation is lost and regained will vary, from blog to blog.
  • Each blog has different readers, with differing links in their blogs and websites.
  • Each blog has different readers, with differing inherent reputation.
  • Each blog has differing search engine relationships, with differing inherent reputation.
The direct result, of all of this, explains the frantic posts, in Blogger Help Forum: Something Is Broken
My blog was deleted by Blogger. How promptly can I get it restored?

If this threat concerns you, use Google 2-step verification, to protect your Blogger / Google account - and your blogs - from hacking. And be discrete in advertising and publishing your blog.

>> Top

Sunday, 9 June 2013

Blog Content, And Confusion About Blogs Locked After Detected Account Hacking

One Blogger mystery involves the varying periods of blog unavailability, after hacking activity is detected.
My blog just disappeared from my dashboard - and no, it's not listed under "Deleted blogs"!

When the owner mentions the notice about "suspicious" / "unusual" account activity, or having unlocked the account (by solving a CAPTCHA, receiving a phone message, changing the password) - and is advised to wait "24 to 48 hours" - many ask the obvious.
Is "24 to 48 hours" really accurate?

In reality, the legendary "24 to 48" hour time period is only a ball park figure - and both Blogger / Google, and the blog owner, contribute to the uncertainty.

The well known advice to "Wait 24 to 48 hours", after a Blogger account is locked for suspected hacking activity, is only an estimation of the waiting time, which the owner may have to endure. This is account / blog integrity verification.

There are several factors which can contribute to the accuracy of "24 to 48 hours" (which maybe should be stated as "one to two business days").
  • Availability of essential Blogger / Google personnel.
  • Current hacking activity level, and ongoing Blogger / Google workload.
  • Blog content, which complicates hacking payload analysis.

We've referenced the first two factors (personnel, and hacking activity level) in the well known Blogger FAQ How long will it take?. The third involves detail which only the blog owner can provide. Many blog owners contribute to this uncertainty, in the development of their blogs.

There are several types of content, which hackers like to add, to blogs temporarily under their control.
  1. Advertising - and similar shiny accessories.
  2. Custom code - and various template tweaks.
  3. Links to other blogs - and to websites outside Google address space.
  4. Team memberships - and multiple blog owners.
All of these features, also added by the owner - and allowed (and encouraged) by Blogger - can require extra effort as a blog is validated, after detected hacking activity.

Blogger / Google security experts, in examining an account / blog, must look for features possibly added by the hacker. Security experts have no immediate knowledge what was added by the owner, long ago - as opposed to by a hacker, more recently.

Any advertising, custom code, external links, or team memberships, intentionally added by the owner, will contribute to time spent validating blog integrity.
  • Leave a setting or tweak added by the hacker - and the blog remains a security risk, when returned to service.
  • Remove a setting or tweak added by a blog owner - and the blog becomes broken, when returned to service.
Neither is desired, by the blog owners - nor by Blogger / Google.

More accessories and tweaks == more time spent by security experts == more time the blog remains offline, while the owner waits in uncertainty.


This uncertainty, added to delayed deletion caused by cache latency, leads to mystery.

All of this brings to mind the old adage.
KISS
Keep it simple, stupid.

>> Top

Saturday, 8 June 2013

Comment Spam And Referer Spam Has Various Purposes

One of the most intriguing subjects discussed in Blogger Help Forum: Something Is Broken involves the seemingly purposeless spam which torments us in our comments and our Stats logs.
I see this random garbage on my blog - and the sites advertised are complete junk. Is there any actual reason for this?

Interestingly, both nice blog spam (in our comments), and referer spam (in our Stats logs), have purposes - though with the continually varying content used in both, it all looks very much like random garbage.

If we analyse the content, structure, and volume of the various spam attacks, we can see patterns - and an understanding of the overall purpose of the spam.

Both our comments - and our Stats logs - are continually assaulted by seemingly random and useless noise, in large volume. This is similar to the random spam which attacks our email.

If you look at enough comment and Stats log spam, you will start to see patterns - and reasons for the spam. The spam, though apparently random in content, is not purposeless.

First, some warning may be appropriate.
  1. If you wish to examine the sites advertised in comment or referer spam, learn to use a proxy server.
  2. Unless you are a computer security expert, with a properly protected (or intentionally sacrificial) computer, do not surf these sites advertised, using an unprotected computer. Avoidance is the best way to protect yourself.
  3. If you do, even inadvertently, surf a comment or referer spam site, quarantine and scan your computer as soon as convenient. If you must surf the sites advertised, while unprotected, diagnosis is the next best way to protect yourself (and others around you).

Examining the comment and Stats based spam diagnostically, you'll see various purposes behind the spam.
  • Spam delivery. It is called "comment spam" / "referer spam", after all.
  • Malware delivery. This is the secondary purpose, known by many people - and the reason why I provide the above advice.
  • Attacks against third party, non spammers. Various third party blogs and websites, who do not subscribe to the service, may be maliciously targeted, by some spam.
  • Strategic malware delivery. Some malware may be packaged in portions, delivered through multiple attacks.
  • Filter poisoning. Some spam may be simply intended to overwhelm the malware / spam detection systems.
  • Email address mining. Some very special comment spam, which I call "Nice Blog" spam, is a very imaginative email address mining technique.

The best way to identify comment and referer spam may be to simply follow the various forum discussions - and observe which spam techniques are reported by multiple blog owners, being assaulted in identical style. As the old saying goes,
If it quacks, it's probably a duck.

>> Top

Sunday, 21 April 2013

Recovering And Protecting Your GMail Account

Blogger blog owners may have productive action, when their Blogger accounts are successfully hacked through an attack on their GMail accounts.

GMail account owners can get detailed instructions on recovering a successfully hacked account, and on preventing future hacking attacks from being successful. Some of the instructions are specific to GMail use - but overall, Blogger account owners will benefit from their use.

To benefit from the GMail instructions, one should consider the differences between Blogger, email, and Google accounts.

Gmail Account Recovery: Gmail Account Recovery and Security provides complete and detailed instructions for recovering a hacked and stolen GMail email account.

The Recovery instructions include specific mentions of Disabled / Suspended accounts, successfully Stolen accounts, and accounts locked or deleted because of Underage owners.

Accompanying the recovery advice is Gmail help and information: How NOT To Get Hacked. These are instructions for preventing a recurrence of a reported problem. This includes discussion of using a strong and secure password, identifying hacking techniques that involve the account owner, and preventing attacks which are conducted using the computer or network in use by the account owner.

The Prevention instructions, many which are common sense issues to any IT professional or security expert, are specifically written to apply to GMail account owners. There may be additional issues which apply in general, to Blogger accounts - and specifically, to Blogger accounts which are based on non GMail email accounts.

There are a few differences between Blogger blog ownership and GMail account ownership, which will cause issues that cannot be easily resolved by Blogger Support, or by GMail Support, to the satisfaction of the (former) blog owner.

GMail accounts are, by nature, single owner - and ownership of a GMail account is never transferred. In contrast, Blogger blogs can be under team ownership - and ownership can be transferred.
  • Intentional team blog ownership. Team blog ownership can cause problems with loss of blog control, when all known blog administrators (accidentally or intentionally) remove themselves as administrators, leaving an unknown administrator.
  • Intentional transfer of control. A blog owner may assign administrator status to another person, voluntarily - then later regret his decision.
  • Un intentional transfer of control. A blog owner may assign administrator status to another person, voluntarily - and the other person may then remove the former owner administrator status.
  • Ownership theft after account hacking. A hacker, having temporarily gained control of a Blogger account, may transfer ownership of a blog to another Blogger account.
All of these scenarios are regarded as simple transfer of blog ownership, by Blogger Support.

Though maybe not preferred by the (former) blog owner, the blog in question will now be under control of another person. It's possible that some of these scenarios are considered by Google Security, when reviewing Blogger / Google accounts after hacking activity is detected.

Blogger accounts, based on non GMail email addresses, will be subject to the typical uncertainty which accompanies any third party service in Blogger. Some details may be involve the email provider, while others will involve Blogger - and arbitrating between the two will be the responsibility of the Blogger account owner.

Owners of Blogger accounts which are based on non GMail email addresses will need to contact the providers of the actual email service, for resolution of some of these issues.

In general though, the GMail Account Loss Prevention and Recovery instructions provide good advice, for any Blogger account owner.

>> Top

Thursday, 18 April 2013

Blogger And Google+ Continue To Move Ever Closer Together

Today, Blogger announced the most innovative step in integrating Blogger and Google+, since sharing of Blogger posts to Google+.

The December 2011 sharing option lets us publish our blog posts to Google+. Today, Blogger added the ability to do the same - and more - with our blog comments. Like basic Google+ post sharing, Google+ Comments will be shared, and be visible, on a Circle by Circle basis.

The ability to post a comment, against a Blogger blog post shared in Google+, and have the comment publish to the blog will make for interesting comment based conversations.

There will be challenges to this feature, however. One of the most annoying problems with Blogger comments, right now, involves the embedded comment form, and security limitations caused by cookie filtering on many readers computers.

This blog uses a full page comment form, because too many of my readers need to post comments, in spite of the cookie filtering on their computer. Blogger Google+ Commenting requires use of the embedded comment form.
Google+ Comments lets you bring the following conversations together in one place, right under your blog post:
  • Comments made on your Blogger blog post
  • Comments on the blog post that you’ve shared to Google+
  • Shared content on Google+ that links to your blog post
Readers will need a Google+ page or profile to comment on your blog.

Anybody who publishes a blog, and has readers who do not understand the reason for allowing third party cookies, will not want to use an embedded comment form - and won't benefit from Google+ Commenting, either. Until either
  • Blogger resolves their "third party cookies" problem, with the embedded comment form.
  • All Blogger blog readers resolve their issues with filtering "third party cookies".
Google+ Comments will have a limited audience.

Many blog owners may find a problem, in the moderation process.
Once you enable Google+ Comments, you can moderate comments within the blog post itself.
Owners of large blogs may not enjoy having to check each post, one by one, to moderate comments.

I check my dashboard Comments menu, several times daily - and see all comments posted to the blog, in one convenient place. Having to look at each post, to moderate comments, won't be as convenient.

A third challenge will come from blog owners who want everybody to be able to comment, on their blogs. Requiring a Google+ account to comment won't be widely accepted by blog owners who have readers who comment either Anonymously, or using an OpenID.

One of the benefits of Google+ Commenting will be a reduction in comment based spam. The increasingly annoying "nice blog" spam - and the accompanying security risks from having it published on our blogs - should be eliminated, from blogs using Google+ Comments.

Google+ Comments is a feature that is needed, on some Blogger blogs - but it needs to remain optional, for some time.

If you're in one of my Circles, and wish to test this new feature, see if you can comment, on my recipes blog, Chuck's Kitchen.

>> Top

Sunday, 24 March 2013

If You Comment On Blogs Extensively, You Should Consider Using Google 2-Step Verification

One recently identified cause of deleted Blogger blogs appears to involve brute force hacking against our Blogger / Google accounts.

We've known, for some time, about blog owners receiving alerts about "suspicious" / "unusual" account activity. The alerts frequently involve locked or deleted Blogger / Google accounts - and generally include the owner having to change their password, solve a CAPTCHA, and / or provide their phone number (mobile or home phone) to login.

Later, people started reporting that their blogs were being deleted - possibly as a result of having to change their password, solve a CAPTCHA, and / or provide their phone number.

I've been observing - and blocking - an annoying style of comment based spam, which I have termed "nice blog" spam, for some time.
Nice blog. I will keep visiting this blog very often.
This style of spam, from what I can tell, has been published by the millions, in various blog comments, on both Blogger and non Blogger platforms.

The reason for the spam always intrigued me. Observing that the spam was published in the millions, suggested to me that it had a special purpose, intended by its creators. Looking at a typical spam message, in my email (since I moderate before publishing), I could see no consistent type of content.
  • Some messages would contain links, others not.
  • Some messages would mention what looked like commercial products, other references were obviously imaginary targets.
  • Some messages would appear to be mere babble.

Recently, I discovered one strong possibility for the purpose of the spam - a very ingenious form of email address mining. The spam comment is only needed to allow a hacker to subscribe to a given comment stream, using the "Email follow-up comments to ..." option. It's possible that the subscription is not even affected by moderation - whether the blog owner is moderating, either before or after the comment is published to the blog, the hacker remains subscribed to the comment stream.

All that the hacker / spammer has to do is to publish a spam comment, select the "Email follow-up comments to ..." option, and watch while his Inbox fills up with subsequent comments from other Blogger / Google / OpenID account owners. Any comment containing an email address, and linking to a Blogger blog, would go straight into the hackers database.

Later, the hacker could go to work against the Blogger accounts referenced in the comments. In some cases, this would result in successfully hijacked Blogger blogs, which would become part of a spammers blog farm where advertisements of various nature could be hosted. Valuable blogs, with established reader populations, could also be used to serve malware (and more hacking) to unsuspecting readers.

The demographics of some hijacking attacks provide interesting clues. In one episode, we had a significant number of home / personal / small business blogs that had been hijacked by one specific individual. Many of the victim blogs
  • Contained details relevant to the owners, which provided clues to passwords used by the owners.
  • Were owned by people who used commenting extensively, for networking both with friends, and with business targets.
  • Were read (and commented upon) by similar people, who similarly provided password clues in their own blogs.

Having been part of the restore process, both with people who had their blogs hijacked, and who had their accounts locked and blogs deleted, I observed that the former (hijacked blogs) seem to have decreased in volume as the latter (accounts and blogs locked / deleted) increased in volume. I don't think that the relationship is coincidental - or spurious.

My opinion is that the locking of Blogger / Google accounts - and subsequent deletion of blogs - directly results from detected attacks against the accounts in question ("suspicious" / "unusual" activity). Noting that the attacks seem to be more common to people who comment on blogs as a form of networking, it appears that commenting can lead to accounts and blogs being locked or deleted, as Google protects us against hacking.

Considering this possible cause and effect relationship, Google 2-step verification is a good idea. Click here, for Google instructions on setting up 2-step verification.

Use of 2-step verification helps safeguard our accounts against brute force hacking. This will help anybody who is anxious about accounts and blogs being deleted or locked, as a result of "suspicious" / "unusual" activity. If you own a blog which is subject to this threat, you should consider using 2-step verification.

The sanity (heart attack, ulcer) that is saved may be your own.

>> Top

Thursday, 14 March 2013

Confusion Over Accounts Locked For Suspicious / Unusual Account Activity

One of the more intriguing tales of Blogger blogs, currently being explored, involves blogs mysteriously deleted by Blogger.
My blog just disappeared from my dashboard - and no, it's not listed under "Deleted blogs"!
In some cases, the owner knows more than is implied, from the obvious wording of that problem report.

As Blogger / Google continues to improve the hacking / malware detection and removal process, they are making the recovery of accounts locked for "suspicious" / "unusual" activity easier - and more transparent. The increased transparency may, in some cases, cause mystery.

Diagnosing the many mysterious blog disappearances, currently being reported in Blogger Help Forum: Something Is Broken, may involve what the blog owner does not report - as much as what the owner does report.

Blogger / Google is constantly refining the hacking detection / recovery process, to both improve the possibility that any activity will be detected, and to make it easier for the victims of the hacking to deal with the recovery process. As they make it easier for the owners to recover the accounts locked, they make it less likely that the owners will mention the locked account recovery, when later reporting the blogs, mysteriously missing from the dashboard.

In some cases, the blog owner will provide vague clues, which refer to an immediately previous account unlock.
  • Required to change the account password.
  • Required to provide a phone number - and receive either a text or voice message with a recovery code.
  • Required to solve a CAPTCHA.
All of these clues can be relevant to a locked account, or to various other anti-hacking / anti-spam activity by Blogger / Google - and can be overlooked as a locked account symptom, when stated in a forum problem report.

In other cases, the only clue provided will be that the blogs in question are missing, and not listed in any dashboard list - "Deleted blogs", "Locked blogs", or "My blogs". In cases where we've simply reported missing blogs for malware / spam review, to Blogger Support, we're later advised to instruct the blog owner to recover the account.

Since immediate review of any blog cannot be always guaranteed by Blogger Support, it's to everybody's benefit that we request clues to verify the problems being reported. Unfortunately, the questions asked may not always seem relevant to some blog owners, unhappy about the mysterious loss of their blogs - even though they may contribute to the problem, inadvertently.

And thanks to the possibility that not all blog owners may even get a notice when their accounts are locked, owners with multiple accounts may not even realise that a given Blogger account is locked. These owners find out that a given blog has been deleted, only after it goes offline and expires from cache. This will make some blog owners even less cooperative, when asked to provide diagnostic details about their problems.

>> Top

Sunday, 10 March 2013

Blog Owners, Unable To Request Restore Of A Deleted Blog

One of the more intriguing issues, seen in Blogger Help Forum: Something Is Broken, involves people unable to recover control of their blogs.
I recently changed ISPs, and now I can't login to update my blog.

Occasionally, this issue becomes more complicated, because the blog is deleted - and the owner can't request that it be restored, using the automated review request wizard. Sometimes, the would be blog owner may to try to bypass the current blog recovery policy, by claiming special circumstances.
The blog has been deleted. I received no suspicious activity or password change notification emails, or emails of any kind related to my blog.

What is the story here? Can blogs just disappear from the Blogosphere, without the involvement of the blog owners - and be unrecoverable?

Recovery of a deleted blog starts with the requirement that only a blog owner can un delete a deleted blog - and this is where many mysterious disappearances start.

Since a Blogger blog is the property of the owner, and the owner is allowed to delete a blog any time required, it would not be right to let people who are not the owner un delete a blog - or demand that the blog be un deleted. To enforce this requirement, Blogger added the dashboard based Restore wizard.

Since only the owner will have the deleted blog listed in their dashboard "Deleted Blogs" list, only the owner can request restore of the blog in question.

The dashboard Restore wizard serves blog owners, with blogs deleted under various circumstances.
  • Deleted by the owner.
  • Deleted by Blogger, as a suspected spam host.
  • Deleted by Google, for TOS Violation.
Any deleted blog will appear in a special dashboard list, "Deleted Blogs" or "Locked Blogs" - when it can be recovered. If the blog is not recoverable by the owner, there may not be a link.

There are specific cases where a deleted blog may not be recoverable using the recovery wizard.
  • The blog is locked, pending integrity check (following account lock for suspicious activity).
  • The blog is owned under a different Blogger account, and is listed on another dashboard, under "Deleted blogs".
  • A blog owner deleted the blog, long ago - and the blog is no longer recoverable.

A blog locked, pending integrity check, cannot be requested for restore. The owner has to first have the owning account unlocked. Similar to the account recovery process, Blogger / Google will require that the owner provide proof of ownership, before the account will be unlocked. With the account unlocked, security specialists will inspect each blog owned by the account, and verify that each does not contain evidence of tampering by a temporarily successful hacker.

While a blog is under integrity check, it won't be listed on the dashboard of the owner - either under "Deleted blogs", "Locked blogs", or "My blogs". Neither the owner, nor any third parties, will be able to do anything except wait, patiently.

Blogs found to contain malware can be locked as TOS Violations, with the owner later required to remove the malware found. This requirement will apply for malware installed by the owner (intentionally, or unintentionally), or for malware installed by a hacker.

With a blog locked pending malware removal, the owner is given the benefit of the doubt, and allowed to simply remove the malware, no questions asked. In some cases, Blogger may be able to assist by providing specific identification of the malware found - but this won't happen, consistently.

A blog owned under another account must be un deleted by the owner of the other account. Again, only a blog owner can have a blog restored - whether deleted by an owner, or by Blogger / Google.

A blog deleted over 90 days previously cannot be recovered. It won't appear on the dashboard of any (former) owner, since it can't be recovered.
It's dead, Jim.

The basic rule is simple. If your blog was deleted, and if you're able to un delete it (or request un deletion), you'll have a link on your dashboard. If a blog is not listed on your dashboard, you can't request, with any predictable success, that it be un deleted - any more than you can demand that a non deleted blog be restored to your control.

>> Top

Sunday, 3 March 2013

Some Blogger Blogs Being Locked As Malware Hosts, Because Of Malicious JavaScript

For a long time, we've been dealing with various malware / spam mitigation issues, in Blogger Help Forum: Something Is Broken.

Recently, malware detections, long simply identified as "Malicious JavaScript" in the well known Spam Appeal Guidelines, was given its own identity, and a separate classification / appeal process. We're now seeing several common types of JavaScript, included in blogs which are typically mentioned in forum reports.

It may be helpful to describe some examples of JavaScript code being seen, so blog owners can avoid making the same mistakes, by not including these scripts in their blogs.

There are 3 common types of JavaScript applications, found in many blogs with the owners requesting review / unlock action.
  1. CPA / Cost Per Action.
  2. Traffic Redirection, targeting other blogs / websites.
  3. Traffic redirection, targeting the canonical URL for the host blog.


CPA / CPALeads / Cost Per Action, and similar online marketing terminology, involves providing a reward for viewing a blog, or for subscribing to the blog feed. Some CPA scripts may be used to collect email addresses, also known as "email address mining", later used for hacking activity or spam distribution.

CPA scripts present another problem. Since Blogger blogs are intended to reward the readers by providing interesting and unique content, blogs which use CPA may be improperly designed or maintained. Blogger wants the blog owners to publish blogs which entertain or inform their readers - not blogs which require artificial or ingenious techniques to generate traffic, and visitor activity.

Traffic Redirection, targeting other blogs / websites is a technique enjoyed by many hackers and spammers. The use of some blogs as gateways, leading to redistributors, which in turn lead to payload blogs or non Google websites, is part of many hacking / spam attacks. Google is trying to restrict the use of Blogger blogs as malware / spam hosts - and actively prevents scripts, which only shuffle readers from one blog to another, without choice.

Even though Blogger will not encourage you to move your blog, to Tumblr, Weebly, WordPress, or wherever, you are allowed to do this - if you feel the need.
Hello, faithful readers:

This blog is now hosted at my new blogging host. Please update your blog lists and bookmarks!
If you must do this, it's OK to post a notice, in your Blogger blog. You can even put a link, to the new blog, in the notice. You just can't use JavaScript, to automatically send the reader to the new blog.

Traffic redirection, targeting the canonical URL for the host blog, is a technique used by some blog owners who perceive Country Code Alias Redirection to present a problem. Some accessories installed on their blogs, and various non Google services which may be used to provide activity on their blogs, may not properly reference the canonical URL tag included in all Blogger blogs.

Since Blogger / Google wants all Blogger blog owners to benefit from improved world wide access to Blogger blogs, blogs which employ automatic canonical URL redirection may damage the effect of CC alias redirection. Blogs which host scripts which immediately redirect readers to the canonical URL, and are considered undesirable by any host government, may force an offended host government to block the entire Blogger service, in their country.

To prevent malicious misuse of Blogger by hackers and spammers, and to encourage effective long term use of Blogger by legitimate blog owners, Blogger / Google may detect any blogs which use these types of scripts as part of their general malware / spam classification strategy. Given the ability and willingness of the blog owner, to remove the JavaScript code in question, most blogs can be returned to service - but each blog will remain offline, until the removal is verified.

It's to everybody's benefit to identify, and to avoid use of, these scripts in our blogs, before it's too late. If your blog contains one of these scripts, why not remove the problem now, instead of waiting until you too have to post your problem report, in the forum
Help me! My blog was just locked for
MALICIOUS JAVASCRIPT
What do I do, now?

>> Top

Friday, 22 February 2013

Browser Cache, And Confusion About Blogs Locked After Suspected Account Hacking

The effects of browser cache, upon our Internet life, are not always understood.

Most of us know, by now, to clear cache and restart the browser, after updating a blog, for consistent testing. Some folks know that blog security changes don't always take complete and immediate effect.

Recently, we're seeing a new effect, reported by owners of Blogger accounts locked, after hacking activity is detected.
I got a message mentioning suspicious account activity, when I logged in to Blogger. I provided my phone number, and I received a code on my phone, that I had to enter before I could then log in. My blog was working fine just after I logged in. A short while later, though, it was gone. Why was my blog deleted, because I unlocked my account?
This blog owner is just slightly confused, about the cause and effect here.

Google robotic processes are constantly monitoring account login activity, and watching for signs of hacking activity, such as brute force password entry.

When hacking is detected, the detection may not be immediate - so Google protects us by considering the possibility that the hacking could have been successful, and deletes or locks blogs owned by the account under attack. The blogs in question are taken offline, immediately, when hacking is detected.

If a blog owner has just been working on a blog, as is frequently the case, the blog contents will be cached somewhere between the owner and the Blogger servers. Blogger can take the blogs offline, on their servers - but any cache containing the blogs will remain. If the blog owner is working on a blog while the Blogger account is under attack, what's in cache will remain, visible to the owner, until cache expires.

If a Blogger account is attacked, and the attack is detected, shortly after the owner has viewed a blog, what's in cache will be used, until it expires. The owner won't see the effects of the blog being deleted until the cache expires, and the browser tries to retrieve a fresh copy from the Blogger servers.

The blog owner sees the blog go offline shortly after he verifies account ownership, and thinks that the verification process caused the blog to go offline. In reality, the blog was taken offline before the owner even knew of "suspicious" account activity.

Now, the blog owner can do nothing, except wait until the account and the blogs are examined for signs of tampering. In some cases, no notification of progress will be received - and the owner will see the blog(s) returned to service, sometime later.

How much later the blogs return to service will vary widely, depending upon several details - and this variation, added to the uncertainty caused by cache latency, leads to mystery.

>> Top

Saturday, 9 February 2013

Deleted / Locked Blogs Have Several Causes, And Various Resolutions

Many blog owners are occasionally confused, by the effects of several Blogger / Google security processes, when they are simply trying to login to Blogger and work on their blogs. We see the agony, daily, in Blogger Help Forum: Something Is Broken.

The side effects of the security processes are similar - and depending upon various owner specific details, can be easily confused for each other. The possibility of confusion requires careful initial analysis, when we are faced with an angry blog owner.
My blog was deleted, by Blogger. How could they do this? I do not publish spam!
This is a typical problem report, which can reflect any one of the processes, each requiring different action in the forums.

There are various Blogger / Google security / TOS enforcement processes, each of which will cause a Blogger account and / or blog to be unavailable for full access, at any time.Each different process has a different effect on the Blogger account and blogs owned - and requires different attention by the blog owners, by the forum helpers, and by Blogger Support and Google Security.

DMCA Violation

Accounts and blogs can be deleted, for progressive DMCA violations.

The DMCA violation process originated with complaints made by the major entertainment industry content enforcement organisations, citing theft of "intellectual property" which they control. In the USA, this would involve the "MPAA" (Motion Picture Association of America), and the "RIAA" (Recording Industry Association of America). I have been told that similar content enforcement organisations exist in other countries.

In more recent events, private citizens have been known to use the DMCA Violation complaint process, for miscellaneous copyright violation reporting.

DMCA Violations have a formal complaint and appeal process.

Hacking detection

Blogger / Google network monitors are constantly analysing account login activity, and looking for signs of brute force password hacking. When hacking activity is discovered, the Blogger account - and all blogs owned by the account - are deleted and locked, pending account verification by the owner, and blog integrity checking by Google Security.

The blog owner, after changing the account password, solving a CAPTCHA, and / or verifying account ownership by providing various personal details, is left waiting for the blogs owned by the account to be examined for signs of abuse by the hacker. Until the blog(s) are returned to online status, they appear in neither the "Deleted blogs" or "Locked blogs" dashboard lists. The owner, even when logged in to the right Blogger account, simply sees the dashboard advice
You are not an author on any blogs.
In this case, neither the blog owner nor the forum helpers can do anything useful, except wait, anxiously - possibly, with no notice provided. The blog being offline may not be immediately observed by the owner - and this may cause more confusion.

Malware detection

Blogger robotic processes are constantly checking the various blogs, looking for malicious blog accessories, components, and scripts. When a blog is subject to "Malware" classification, the blog will appear in one of two dashboard lists, in sequence.
  1. Initially, the blog will appear in the "Deleted blogs" list. While the blog is in "Deleted" status, the blog owner will be able to do nothing, except request "Restore".
  2. Once the owner has requested "Restore", the blog is undeleted, and placed into the "Locked blogs" list. While the blog is in "Locked" status, all authors can access the blog to remove malware - but the blog remains offline, to all viewers. Once all malware has been removed from the blog, the owner can "Request Unlock Review".

If the blog remains in "Locked" status for over 48 hours, the blog owner may report this in the forums, and may request a manual review. The forum helpers, and online viewers, will generally see the blog displayed as "TOS violation".
This blog is in violation of Blogger Terms of Service and is open to authors only

Adult Content / Porn Detection

Blogger will soon classify and delete blogs with "adult content", which host advertisements to commercial porn sites. Like spam classification, this will probably involve both false negatives and false positives.

Spam detection

Blogger robotic processes are constantly checking the various blogs, looking for signs of spam activity and content. When a blog is subject to "Spam" classification, the blog will be displayed in the "Deleted blogs" dashboard list. The owner can do nothing, except request "Restore".

If the blog remains in "Deleted" status for over 48 hours, the blog owner may report this in the forums, and may request a manual review. The forum helpers, and online viewers, will generally see the blog displayed as "Removed".
Blog has been removed
Sorry, the blog at xxxxxxx.blogspot.com has been removed. This address is not available for new blogs.

Repeated Offenses

We have recently noted that repeated TOS Violations, involving DMCA, Malware, Porn, and Spam, are being dealt with in increasing severity.

Owner deletion or rename

Mistakes made by the owner can be confused with Spam detection. When a blog is deleted by the owner, it will appear in the dashboard "Deleted blogs" list for up to 90 days. During the 90 days, the owner (or a team member, when applicable) may "Restore" the blog. After the 90 days expire, the blog will be removed from "Deleted blogs", and will be unrecoverable. Besides being unrecoverable, no other details have been determined.

If the blog is renamed (published under a different BlogSpot URL), the external symptom may be similar to deletion by the owner.
Blog has been removed

Sorry, the blog at myblog.blogspot.com has been removed. This address is not available for new blogs.
In this case, the blog will be listed in the dashboard "My blogs" list, under the right Title. The owner needs to setup a stub blog, pointing the readers to the new URL.

Team Ownership

Any blogs owned by a deleted / locked Blogger account may simply disappear from the dashboards of other team members. If the Blogger account is not restored / unlocked, the blogs owned by that account - including any team owned blogs - may remain deleted - and inaccessible to everybody.

The Confusion Accumulates

Because of anonymous blog ownership, loss of account control, team blog ownership, and use of inactive or non existent email addresses, any account / blog which is deleted or locked for hacking (actively / as a victim), malware, and / or spam may not be easily discovered or recovered by the owner. These issues cause further confusion and frustration.

These scenarios may appear, to the untrained eye, to be signs of fraudulent, malicious, and / or petty actions by Blogger - and are loudly claimed so by spammers with their own agenda. None of these accusations are true - the above processes simply represent Blogger and Google attempting, in the best possible way, to protect everybody against the various hacking, malware, porn, and spam attacks which are constantly in progress.

>> Top

Wednesday, 6 February 2013

"Nice Blog" Spam Is Recently Becoming More Obscure, In Content And Style

In 2009, we discovered an odd style of spam comments which, from all appearances, served no purpose.
I recently came across your blog, and have been reading along. I thought I would leave my first comment. I don't know what to say except that I have enjoyed reading. Nice blog. I will keep visiting this blog very often.
When discovered, Google Search suggested that over 22,000,000 copies of these comments had been successfully installed, on various blogs and websites.

Last year, I suggested a possible reason for the spam - and later showed how Google+, and various Blogger security measures, were making the spam less useful.

Last month, we began to see suggestions, from some blog owners, that this "nice blog" spam was morphing, into more obscurely phrased and structured styles.
A lot of spam comments are being published on my blog. This problem started a few weeks ago - though previously, Google almost always put them in my Spam Folder.
Upon examination of examples of the spam comments, we see the same spam style as observed in 2009 - yet more imaginatively phrased.

Today, I spent a couple hours, and scanned through the comments queues on this blog. Both the Awaiting, and Spam, folders yielded some interesting specimens.
This topic is very educational and it took my interest. Hope it will always be alive! And provide productive information to many others.
and
Nice post. I learn something new and challenging on websites I stumble upon every day. It's always interesting to read articles from other writers and practice a little something from other sites.
These were the comment bodies of just two examples which I located - and these resemble others identified by various other blog owners.

The bodies of the comments examined, this week, will sometimes contain embedded links, while other examples will have external links - and some comments seem to contain no links at all, to any payload. The only thing consistent about the comments is their vague and apparently pointless nature.

The comments are both large in volume, and varied in content and structure. Both patience and persistence, from every blog owner moderating the spam, is required. The spam filters must be trained, to recognise the new content and structures - and this will require more effort, from everybody seeing the spam.

Since various reports about the spam have been seen recently, in Blogger Help Forum: Something Is Broken, we added a rollup discussion there, where we are requesting minimally organised details about the comments being observed.
  • Are you moderating before, or after publishing?
  • What's the average amount of time the spam comment sits in "Awaiting" or "Published", before being moved to "Spam"?
  • How often do you check "Awaiting" and "Published", looking for more spam comments?
  • How often do you check "Spam", looking for non spam comments?
  • How many spam comments do you typically dispatch, in each batch?
  • Looking objectively in your personal "Awaiting", "Published", and "Spam" folders, what number of this style of comments do you typically see in each, without your intervention?
  • When did you first observe this threat, in your comment folders?
As always, please help here by answering as carefully and completely as possible - and please only post relevant replies. Do not turn the rollup discussion into a chat room.

>> Top

Monday, 4 February 2013

Check Your Template, And Look For Unfamiliar JavaScript Code, Following Odd Blog Behaviour

Recently, we've been seeing some odd problem reports in Blogger Help Forum: Something Is Broken, suggesting deviously hijacked blogs.
My blog is requesting me to login, using a user name and password, when I view it.
Given the URL of the window requesting the login, it's a simple matter for us to use the right forensic Internet software, and to locate a relevant snippet of code, frequently installed as part of the blog template.

Sometimes, when we reply to the blog owner with advice to remove a bit of dodgy code, we get a response suggesting disbelief. Our advice
Use the Template Editor, and remove the highlighted code snippet.
may receive a confused or skeptical response.
Where did that bit of code come from? I never installed that!
How did the code in question get installed? Discussion of one possible scenario may require thinking outside the box. Not every unrecognised blog change is being caused by memory loss by the blog owner, after an intentional accessory install or template tweak.

Looking at the subject / theme of some blogs involved in recent problem reports, we're seeing a beginning of a trend, which may indicate a new - and very subtle - blog hijacking technique. We know that Blogger blogs are subjected to brute force password guessing attacks, and we know that Blogger / Google has to consider the possibility that a brute force attack detection is made after the attack was successful.

Current blog security, and defense against blog hijacks, involves detection of hijack attempts, by Google Security. It's possible that some blogs, with some owning Blogger accounts and passwords, are more vulnerable to sophisticated password guess hacking.

When you login to Blogger or Google, you hopefully know the right account name and password, and are generally able to get logged in - after maybe one or two mistakes. You learn, soon enough, that if you have to guess your account name or current password - and you require more than a couple tries - you may have to solve yet another CAPTCHA, or request account unlock, to continue.

The ever unpopular CAPTCHA / locked account comes from Google, detecting a possible brute force attack in progress, and protecting your account and your blogs. A Blogger blog, with its content providing enough clues, combined with a simple account password that is easily guessed, may allow an experienced hacker to login to your account in one or two tries, without being detected by Google attack monitors.

It's alternately possible that some attacks are being conducted by very patient hackers, who are able to use days, and / or thousands of different computers, to conduct a throttled brute force password attack. Again, just attack without providing a detectable pattern.

This may help to explain the mysterious spam blog setups, of last year.

A hacker, able to login to a Blogger account without being detected, could install small changes in a blog template without ever being discovered. The blog owner would never discover subtle template changes, made by an easily satisfied hacker.

Finally, install latent code that does not activate immediately, as we observed during Winter 2009 / 2010, so no blogs show symptoms until the hack is installed on thousands of blogs. If one or two blog owners discover the odd code in their blogs, who would ever suspect their blog being part of a massive cloud of victims?

If you report odd behaviour by your blog, you write to Blogger Help requesting advice, and you are advised to remove a bit of dodgy code from the template - and you do not remember having installed the noted dodgy code - you may want to review your Blogger / Google password, and make the password harder to guess. Better still, start using 2-step verification for logging in to your Blogger / Google account.

>> Top