Skip to main content

Unmoderated Comments With JavaScript References

We have seen reports from several Bloggers that anonymous posters are making unmoderated comments to their blogs, containing a JavaScript reference, which redirects the reader to another web site. Right now, the reference, and the redirection, appears to be used for pumping up the reputation in individual quotes in QDB.com, but it doesn't require a lot of imagination to see how versatile this vulnerability could be in the long run.

Start by immediately moderating all blog comments, until this vulnerability is fixed.

>> Blogger Employee says
I pass it along (again) and we'll see if we can do anything about this.


>> (Update 7/6 10:00): Blogger Employee says
We made some changes to address the vulnerability issue (yesterday) so this should no longer be a problem.


>> Forum thread links: bX-*00055

>> Copy this tag: bX-*00055

>> Top

Comments

jjh said…
I have this problem on my blog, any word from Google if they're doing anything abou t it?

Popular posts from this blog

Adding A Link To Your Blog Post

Occasionally, you see a very odd, cryptic complaint I just added a link in my blog, but the link vanished! No, it wasn't your imagination.

Embedded Comments And Main Page View

The option to display comments, embedded below the post, was made a blog option relatively recently. This was a long requested feature - and many bloggers added it to their blogs, as soon as the option was presented to us. Some blog owners like this feature so much, that they request it to be visible when the blog is opened, in main page view. I would like all comments, and the comment form, to be shown underneath the relevant post, automatically, for everyone to read without clicking on the number of comments link. And this is not how embedded comments work.

What's The URL Of My Blog?

We see the plea for help, periodically I need the URL of my blog, so I can give it to my friends. Help! Who's buried in Grant's Tomb, after all? No Chuck, be polite. OK, OK. The title of this blog is "The Real Blogger Status", and the title of this post is "What's The URL Of My Blog?".