Skip to main content

Protect Your Readers - Install Third Party Code, On Your Blog, Selectively

Recently, we've seen a few reports of blogs which contain malware, or links to malware.

Unlike the Adult Friend Finder splogs, and similar blogs, the blogs recently identified are generally privately published, and contain genuinely intended material. The owners have added code, provided by third parties, that contain the malicious code or links to other web sites which contain the malicious code.

Inclusion of malware, or links to malware, is simply what I call a Layer 4/5 security malfunction by the blog owners.

Bloggers see a shiny feature on somebody's blog (maybe a blog produced by the malware producer, maybe by another victim of the malware), and decide that they want the shininess on their blog too.

Sometimes, Blogger Security will provide warnings.

Sometimes, but not always, Blogger Support will identify bad stuff.
It seems now that many of the reported URLs have a 'BlogLinker.com' code snippet in them- *please* stay away from this widget in the future; it is completely nefarious.

But we have to take the responsibility, here. Blogger Support can't help your readers repair their computers, after they are infected. If they manage to take your blog offline before it infects the general public, don't expect an email telling you what they found. You're going to have to find out what you did wrong, maybe with no blog to examine.

When you see interesting features on other blogs, be selective!

When you see a shiny feature on another blog or web site, think carefully. Maybe some online web site analysis would be a good idea, to avoid adding code to your web site that might hurt your readers.

If you don't check out a shiny item on somebody else's web site, before you install it, somebody else might check it out on your web site after you install it.

Blogger Buzz: Keeping Your Blog Secure points out other possibile problems.
For example, a site counter widget may indeed be providing your blog with helpful tracking data, but at the same time may also be discreetly sending that information to advertisers for the purpose of collecting the online habits of your readers. A blog template you downloaded from a third party site might include pop-up ads or links to dangerous sites that install malware on visitor's computers.

Even accessories that are distributed benevolently may break.

Even code that is not distributed for malicious purpose may harm your blog. You may end up using extraordinary means to remove it, too.

Third party code can be useful, when it's benevolently provided. Make sure that any code that you install on your web site is not harmful or malicious to your computer, or to your readers computers, before you install it.

Comments

Popular posts from this blog

Custom Domain Migration - Managing The Traffic

Your blog depends upon traffic for its success.

Anything that affects the traffic to your blog, such as any change in the URL, affects the success of your blog. Publishing the blog to a custom domain, like renaming the blog, will affect traffic to your blog. The effects of the change will vary from blog to blog, because of the different traffic to every different blog.Followers. People who find your blog because of recommendations by other people.Search engines. Robotic processes which methodically surf your blog, and provide dynamic indexing to people who search for information.Subscribers. People who read your content from their newsfeed reader, such as the dashboard Reading List.Viewers. People who read your content from their browser.No two blogs are the same - and no two blogs will have the same combinations of traffic sources.

Stats Components Are Significant, In Their Own Context

One popular Stats related accessory, which displays pageview information to the public, is the "Popular Posts" gadget.

Popular Posts identifies from 1 to 10 of the most popular posts in the blog, by comparing Stats pageview counts. Optional parts of the display of each post are a snippet of text, and an ever popular thumbnail photo.

Like many Stats features, blog owners have found imaginative uses for "Popular Posts" - and overlook the limitations of the gadget. Both the dynamic nature of Stats, and the timing of the various pageview count recalculations, create confusion, when Popular Posts is examined.