Skip to main content

Don't Make Your Blog Vulnerable To Strategic Malware

In 2009, Blogger Help Forum: Get Help with an Issue had various reports about blogs mysteriously redirecting to "".

Later that year, and into 2010, we saw new reports mentioning "", then "". When we investigated the redirections, we found people with blogs that used a picturesque animated decoration known as "falling snow" - and later, as Valentines Day 2010 approached, "falling hearts".

The victimised blog owners, too frequently, admitted to having installed various gadgets provided by helpful non Blogger website owners. Diagnosing the problem, however, was frequently obscured by the claims.
But I installed that gadget months ago!
In some cases, diagnosed in December 2009 - February 2010, the misbehaving gadgets had been installed as far back as Summer of 2009.

Many misbehaving blog accessories were found available from various non Blogger websites, from helpful third party developers.

In Winter 2011 / Spring 2012, we discovered new classes of malware - gadgets being provided using "Add a Gadget", and served from Google sanctioned third party contributed libraries. We had redirectors like "", targeting websites such as "".

We have actually observed four waves of hijack attacks upon Blogger blogs (the above two are the best documented), which appear to provide commercial or financial reward to the hackers maintaining the malicious and misbehaving gadgets. Some websites served from the "" redirection were found to be serving very deviously packaged malware - that helped to enslave various reader computers, as botnet members.

This year, we're observing more victims, who have installed gadgets from "", and "" - with redirectors such as "". We also see problem reports from owners of blogs with NeoCounter and other NeoWorx products - and similar complaints from readers of the blogs.

When advised to remove identified gadgets, many blog owners again complain.
I installed that gadget months ago, and it's been working just fine! Surely, that is not my problem!!
But based on the other problem reports - and later by the admission of the blog owners - the gadgets removed will prove to be the source of the problem.

The lessons from all of this? You need to be very selective about where you get accessories and advice - and you need to accept skeptically - if at all - the casual evaluation.
It's working fine today, after I installed it last month - so it must be a good gadget! Now, I can recommend it to my friends!!
If it seems too good to be true, it probably is.

You get readers from informative, interesting, and unique content - not from free content and shiny gadgets.


Renee Ondrajka said…
This was very helpful. I appreciate the advice. I also removed my pin gadget, but it seems that my pictures still have it on there. What could be the reason? I still want my pics to be able to be pinned, but I thought removing the gadget would make that no longer possible. Thanks for any advice.
Nitecruzr said…
Hi Renee,

Thanks for asking the question.

IIRC, your blog has three Pinterest gadgets. You only need one. And if they are from "", they can be trusted. But you should only have one.

Popular posts from this blog

Embedded Comments And Main Page View

The option to display comments, embedded below the post, was made a blog option relatively recently. This was a long requested feature - and many bloggers added it to their blogs, as soon as the option was presented to us. Some blog owners like this feature so much, that they request it to be visible when the blog is opened, in main page view. I would like all comments, and the comment form, to be shown underneath the relevant post, automatically, for everyone to read without clicking on the number of comments link. And this is not how embedded comments work.

What's The URL Of My Blog?

We see the plea for help, periodically I need the URL of my blog, so I can give it to my friends. Help! Who's buried in Grant's Tomb, after all? No Chuck, be polite. OK, OK. The title of this blog is "The Real Blogger Status", and the title of this post is "What's The URL Of My Blog?".

With Following, Anonymous Followers Can't Be Blocked

As people become used to Blogger Following as just another tool to connect people, they start to think about the implications . And we see questions like How do I block someone who's been following my blog secretly? I couldn't see her in my Followers list (hence I couldn't use the "Block this user" link), but I have looked at her profile and could see that she's Following my blog. Following, when you look at the bottom line, is no more than a feed subscription and an icon (possibly) displayed on your blog, and linking back to the profile of the Follower in question. If someone Follows your blog anonymously, all that they get is a subscription to the blog feed. If you publish a feed from your blog, and if the feed is open to anybody (which, right now, is the case ), then it's open to everybody. If someone wants to use Following to subscribe to the feed, you can't stop this. You can't block it before, or after, the fact. You can't Block w