We all know that Blogger is the root of all blogging evil. It’s been well documented in the past that Blogger has been hacked and malicious scripts, viruses and malware installed on users’ blogs.
BBC News is reporting today that Alex Eckelberry from Sunbelt Software noticed booby-trapped links on 27 August.
From the report:
Now many hundreds of blogs on the site have been updated with a short entry containing the link.
Mr Eckelberry said it was not yet clear how the links were posted to blogs. The bogus entries could have exploited a Blogger feature that lets users e-mail entries to their journal.
You would have thought that after the first three widely publicised takedowns that Google (who own Blogger) would have tightened security on the application. Apparently not.
Among the other recipients of spam e-mails generated by the virus are users’ mail2blogger accounts, which allow them to update their blogs via e-mail,” said the spokesperson.
The email addresses on mail2blogger accounts are stored in Blogger so that the system can associate the account with the email address. A simple (relatively of course) or an insider would be able to get said email addresses and pass/sell to the “gang”. This would mean two things:
1, The “gang” would be able to post the malicious scripts to blogs via cloaked email.
2. The “gang” would be able to email the script to the owner of the email address infecting their computer and causing it to pass on the script in the usual virus like manner.
I don’t know about others but I try my hardest to avoid blogs hosted by or running Blogger type software. Yes, I may be missing out on decent content but I just really can’t stand the interface, the spam advertising, the porn and the black templates of death.
My suggestions:
1. Avoid any blogs on blogger.
2. If you want to blog, use a decent service. Yes, it’s very restricted but so far there have been no reports of hacking into the system.
3. Get a Mac.