<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Spyware hitting blogs</title>
	<link>http://www.metafilter.com/39817/Spyware-hitting-blogs/</link>
	<description>Comments on MetaFilter post Spyware hitting blogs</description>
	<pubDate>Mon, 21 Feb 2005 22:31:24 -0800</pubDate>
	<lastBuildDate>Mon, 21 Feb 2005 22:31:24 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Spyware hitting blogs</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs</link>	
		<description>I often say that blogs are currently where the web was in 1998, with history repeating itself only this time with blogs. The latest sign: &lt;a href=&quot;http://www.mt-law.com/blog/2005/01/spyware-on-blogspot.html&quot;&gt;spyware and viruses&lt;/a&gt; are &lt;a href=&quot;http://www.mt-law.com/blog/2005/02/update-another-blogspot-blog-that.html&quot;&gt;now being transmitted&lt;/a&gt; &lt;a href=&quot;http://gilbertwesleypurdy.blogspot.com/2005/02/elite-bar-adventures.html&quot;&gt;via blogs&lt;/a&gt;, specifically, random blogs on &lt;a href=&quot;http://www.blogspot.com/&quot;&gt;blogspot.com&lt;/a&gt;, found via the &quot;&lt;a href=&quot;http://stopdesign.com/log/2004/08/17/blogger-navbar.html&quot;&gt;Next Blog&lt;/a&gt;&quot; button. Remember, just because a delightful purple gorilla wants to read blog entries to you doesn&apos;t mean you should click on him.</description>
		<guid isPermaLink="false">post:www.metafilter.com,2005:site.39817</guid>
		<pubDate>Mon, 21 Feb 2005 22:15:19 -0800</pubDate>
		<dc:creator>mathowie</dc:creator>		<category>spam</category>		<category>spyware</category>		<category>blogs</category>		<category>blogging</category>		<category>viruses</category>
	</item>	<item>
		<title>By: riffola</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860444</link>	
		<description>It&apos;s still ok to input my credit number in the banner ad so that they can check and make sure it&apos;s not stolen right?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860444</guid>
		<pubDate>Mon, 21 Feb 2005 22:31:24 -0800</pubDate>
		<dc:creator>riffola</dc:creator>
	</item>	<item>
		<title>By: bobo123</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860448</link>	
		<description>So how is this nana294 installing spyware exactly? Which platforms/browsers? ActiveX exploit, javascript, some type of overflow exploit? Should I stop clicking links?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860448</guid>
		<pubDate>Mon, 21 Feb 2005 22:43:25 -0800</pubDate>
		<dc:creator>bobo123</dc:creator>
	</item>	<item>
		<title>By: mathowie</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860454</link>	
		<description>I suspect the exploits are all IE/windows only.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860454</guid>
		<pubDate>Mon, 21 Feb 2005 22:54:08 -0800</pubDate>
		<dc:creator>mathowie</dc:creator>
	</item>	<item>
		<title>By: teece</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860457</link>	
		<description>I&apos;m curious about that, too, bobo123.  Me, I use either Safari on OS X or Konqueror on Linux.  Neither of which makes me &quot;safe,&quot; but I am curious what the infection vector would be.  I strongly suspect ActiveX and IE on Windows, but what do I know (not much)?

It&apos;s a bummer though -- I like the &quot;Next Blog&quot; button.  If for nothing else, you can see just how bad some people&apos;s design sense is.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860457</guid>
		<pubDate>Mon, 21 Feb 2005 22:58:15 -0800</pubDate>
		<dc:creator>teece</dc:creator>
	</item>	<item>
		<title>By: Samizdata</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860459</link>	
		<description>Although, &lt;a href=&quot;http://opendiary.com/&quot;&gt;opendiary.com&lt;/a&gt; is a good source also.  &lt;a href=&quot;http://forums.techguy.org/archive/t-327453.html&quot;&gt;EliteBar&lt;/a&gt; is a pain to clean.

I am so glad I self-host.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860459</guid>
		<pubDate>Mon, 21 Feb 2005 23:02:44 -0800</pubDate>
		<dc:creator>Samizdata</dc:creator>
	</item>	<item>
		<title>By: DrJohnEvans</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860461</link>	
		<description>Okay, I bit and visited.  The culprit weblog looks pretty normal to me (Moz 1.7).  Badly written, overdone design, the usual fare.  A quick skim through the code didn&apos;t reveal anything extraordinarily suspicious.  Strange.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860461</guid>
		<pubDate>Mon, 21 Feb 2005 23:08:27 -0800</pubDate>
		<dc:creator>DrJohnEvans</dc:creator>
	</item>	<item>
		<title>By: DrJohnEvans</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860462</link>	
		<description>Note:  I use Mozilla variants via either Linux or Win98, so my spyware defence is based on a strategy of being in the obscure minority.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860462</guid>
		<pubDate>Mon, 21 Feb 2005 23:09:56 -0800</pubDate>
		<dc:creator>DrJohnEvans</dc:creator>
	</item>	<item>
		<title>By: keswick</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860467</link>	
		<description>Oh, scumbags, is there any part of the Internet you &lt;em&gt;won&apos;t&lt;/em&gt; ruin? First it was e-mail... Then it was Usenet... Then it was web ads &amp;amp; cookies... And IMs... 

Ah well, there&apos;s always Bittorrent.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860467</guid>
		<pubDate>Mon, 21 Feb 2005 23:28:05 -0800</pubDate>
		<dc:creator>keswick</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860471</link>	
		<description>This is ridiculous. First off, the author wont even mention the site in question so I can&apos;t test it and he keeps using terms like &quot;my browser&quot; instead of IE or Mozilla.  Someone should tell this guy that there&apos;s no such thing as security through obscurity and he should try writing some damn details as this just feeds into &quot;the web is unsafe&quot; nonsense.  IE may be unsafe, but I would be very surprised to see a cross-browser exploit which installed spyware.  Not to mention, someone this technically clueless may just not understand the fact that he may have been infected previously. Who knows. 

Details, people. They&apos;re good for you.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860471</guid>
		<pubDate>Mon, 21 Feb 2005 23:40:19 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: DaShiv</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860472</link>	
		<description>Thanks for giving those &quot;scumbags&quot; new ideas, keswick.  And for Christ&apos;s sake, don&apos;t mention Meta----- ######## NO CARRIER</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860472</guid>
		<pubDate>Mon, 21 Feb 2005 23:41:51 -0800</pubDate>
		<dc:creator>DaShiv</dc:creator>
	</item>	<item>
		<title>By: DrJohnEvans</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860473</link>	
		<description>skallas, the site in question is mentioned in the &quot;&lt;a href=&quot;http://www.mt-law.com/blog/2005/02/update-another-blogspot-blog-that.html&quot;&gt;now being transitted&lt;/a&gt;&quot; link, in the email copy.  It&apos;s quoted by the Blogger people in their reply:  &lt;a href=&quot;http://nana294.blogspot.com&quot;&gt;nana294.blogspot.com&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860473</guid>
		<pubDate>Mon, 21 Feb 2005 23:44:21 -0800</pubDate>
		<dc:creator>DrJohnEvans</dc:creator>
	</item>	<item>
		<title>By: salmacis</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860481</link>	
		<description>Er, I don&apos;t see a &quot;next blog&quot; button in the top right corner...

(Linux/Firefox)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860481</guid>
		<pubDate>Tue, 22 Feb 2005 00:05:27 -0800</pubDate>
		<dc:creator>salmacis</dc:creator>
	</item>	<item>
		<title>By: DrJohnEvans</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860482</link>	
		<description>salmacis, the MT Law blog moved to their own domain and turned off the Blogger bar.  You can still see it at &lt;a href=&quot;http://mtlaw.blogspot.com/&quot;&gt;their old domain&lt;/a&gt;, complete with zealous warning message.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860482</guid>
		<pubDate>Tue, 22 Feb 2005 00:11:33 -0800</pubDate>
		<dc:creator>DrJohnEvans</dc:creator>
	</item>	<item>
		<title>By: salmacis</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860484</link>	
		<description>BTW - I went to the nana294 blog and I got a Javascript popup saying &quot;Sorry, you are not using a WIN32 computer&quot;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860484</guid>
		<pubDate>Tue, 22 Feb 2005 00:12:28 -0800</pubDate>
		<dc:creator>salmacis</dc:creator>
	</item>	<item>
		<title>By: juv3nal</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860485</link>	
		<description>in firefox i see a &quot;additional plugins are required to display all the media on this page&quot; thingy.
likely it&apos;s IE only.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860485</guid>
		<pubDate>Tue, 22 Feb 2005 00:12:33 -0800</pubDate>
		<dc:creator>juv3nal</dc:creator>
	</item>	<item>
		<title>By: teece</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860486</link>	
		<description>I think I see what it is doing -- in a very general sense.  I am neither a Windows Guru nor has my clean programming mind been sullied with the vagaries of Javascript.  But the page gets a remote jscript that is ostensibly to play music (iWebTunes), but it also downloads another jscript which gets a file called v3cab.cab from searchmiracle.com/cab.  I don&apos;t know from a cursory glance how that little file does anything to your machine, but I would guess that is the entry point.  It is certainly Windows specific -- they are even kind enough to tell you in the jscript and in a browser pop-up.

Scum-bags.  But it also makes me wonder:  some people might just see a bit of javascript to play music on their blog, and think, yippee!, and install the code, and then infect people unknowingly.  But then again, who can install a bit of Javascript on their web page and not understand such simple things?

Gee, I hope it can&apos;t infect wget on my mac  ... :-)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860486</guid>
		<pubDate>Tue, 22 Feb 2005 00:17:16 -0800</pubDate>
		<dc:creator>teece</dc:creator>
	</item>	<item>
		<title>By: DrJohnEvans</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860487</link>	
		<description>Hey, I opened about eight &quot;next blogs&quot; in new tabs, and one of &apos;em did manage to sneak a pop-up window through.

Nice bit of work, teece.  I imagine that if it was voluntarily installed (and I maintain that that particular blog looks too involved to be only a spyware front), then the installation instructions just called for a strategic copy-and-paste.

Okay, enough playing for tonight.  I&apos;m going to bed.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860487</guid>
		<pubDate>Tue, 22 Feb 2005 00:20:24 -0800</pubDate>
		<dc:creator>DrJohnEvans</dc:creator>
	</item>	<item>
		<title>By: teece</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860488</link>	
		<description>I bet you&apos;re right, DrJohnEvans -- it is only 4 lines of JavaScript that appears to be getting the trojan.  I wouldn&apos;t be at all surprised if the owner of that Blogger page simply Copy-n-Pasted that code into his/her blog, wanting it to play a tune.  It does appear to actually play music (or at least try to), but I don&apos;t have a Windows IE platform to test it -- and if I did I wouldn&apos;t.

Sigh.  Must everything turn into a sewer?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860488</guid>
		<pubDate>Tue, 22 Feb 2005 00:31:19 -0800</pubDate>
		<dc:creator>teece</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860511</link>	
		<description>&amp;gt;quoted by the Blogger people in their reply: nana294.blogspot.com.

Thanks doc.

Okay, I tested this on a winxp box with the following browsers:

Firefox: No effect. Not even the javascript pop-up boxes.

IESP2: I get two javascript pop-up boxes asking me to &quot;upgrade my browser.&quot;  The activeX handler showed me that software signed by  &quot;Enternet Media Inc&quot; was asking to be installed.

&lt;strong&gt;Summary:&lt;/strong&gt;

There is no exploit here. This is ActiveX. ActiveX is Microsoft&apos;s web installer. If you click Yes then you are installing software, software which may be spyware. If you click no, you are not.  Its that simple.  The javascript pop-ups are misleading, but are not an exploit at all.  Just a nag box to install this ActiveX control.

&lt;strong&gt;Suggestions:&lt;/strong&gt;

Windows 2000 and XP SP1 users should double check their ActiveX settings.  &lt;em&gt;&lt;strong&gt;ActiveX download should never be set to &quot;Enable.&quot;&lt;/strong&gt;&lt;/em&gt; It should be set to either &quot;Prompt&quot; or &quot;Disable.&quot; Users in general should avoid all ActiveX as it is a well known vector for spyware, with the exception of WindowsUpdate.  XP SP1 users should move to SP2 as soon as possible as it doesn&apos;t allow &quot;drive by&quot; ActiveX installs.  Ideally, users should try a non-Microsoft browser if they want to avoid this and other security problems.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860511</guid>
		<pubDate>Tue, 22 Feb 2005 02:34:53 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: dabitch</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860515</link>	
		<description>For anyone still worried, search miracle elitebar is IE on native systems only. Now you know how to avoid it. ;)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860515</guid>
		<pubDate>Tue, 22 Feb 2005 03:10:29 -0800</pubDate>
		<dc:creator>dabitch</dc:creator>
	</item>	<item>
		<title>By: salmacis</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860516</link>	
		<description>So how long before an XPI equivalent is in the wild for Firefox users?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860516</guid>
		<pubDate>Tue, 22 Feb 2005 03:13:07 -0800</pubDate>
		<dc:creator>salmacis</dc:creator>
	</item>	<item>
		<title>By: BobInce</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860517</link>	
		<description>There is no exploit here. But:

- EliteBar uses massively misleading software descriptions. The one I got was: 

&quot;YOU have an OUT OF DATE browser which can cause you to get infected with viruses, spam and spyware.  To prevent this press YES now.&quot;

- EliteBar has installed through IE exploits before (typically MS JVM exploits).

What *could* cause this software to install automatically would be a Trusted Publishers or Trusted Zone hack. Many of the recent very commonplace IE exploits categorised at &quot;CoolWebSearch&quot; add software providers including Enternet Media (EliteBar) to trusted lists, causing their software to get installed instantly without prompting. Typically they later open a web page from that publisher with their own affiliate code in. Anyway, if there was a previous infection, that would cause EliteBar to install without prompting again in the future.

Problems like these are all over the web now, including &apos;mainstream&apos; sites. &quot;Don&apos;t visit untrustworthy sites or porn&quot; just doesn&apos;t cut it any more. Turn up all your security settings or don&apos;t use IE.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860517</guid>
		<pubDate>Tue, 22 Feb 2005 03:30:44 -0800</pubDate>
		<dc:creator>BobInce</dc:creator>
	</item>	<item>
		<title>By: srboisvert</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860518</link>	
		<description>&lt;em&gt;Problems like these are all over the web now, including &apos;mainstream&apos; sites. &quot;Don&apos;t visit untrustworthy sites or porn&quot; just doesn&apos;t cut it any more. Turn up all your security settings or don&apos;t use IE.&lt;/em&gt;

I&apos;ve seen a couple of threads about popups hitting firefox on &lt;a href=&quot;http://slashdot.org/article.pl?sid=05/02/21/0143223&amp;tid=95&quot;&gt;slashdot&lt;/a&gt;.  They get around the blocker via flash or by dynamicaly linking to javascripts.

Serious exploits are only a matter of time and popularity.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860518</guid>
		<pubDate>Tue, 22 Feb 2005 03:38:53 -0800</pubDate>
		<dc:creator>srboisvert</dc:creator>
	</item>	<item>
		<title>By: fenriq</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860746</link>	
		<description>What I&apos;ve learned from this post is that the search bar and next blog thing on top of Blogger blogs is no longer voluntary. If you have a Blogger blog, you have the search bar on your blogs. Unless I just missed the switch off for it.

And a quick check shows that almost 70% of my site&apos;s visitors are still using IE, which is just sad.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860746</guid>
		<pubDate>Tue, 22 Feb 2005 08:33:55 -0800</pubDate>
		<dc:creator>fenriq</dc:creator>
	</item>	<item>
		<title>By: hank</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#860769</link>	
		<description>Crap.  I reported this trick to the Blogger management six months ago -- same sort of thing, installed SearchMiracle on Windows IE (hit a machine where I work, even with AdAware current and running).  It infected immediately if you clicked &apos;next blog&apos; and landed on the infected page.  I thought they&apos;d rooted it out.  They certainly have been aware it&apos;s possible for a long time.  

It was then a chunk of code that supposedly played music, that the naive weblog page owner had copied and pasted in -- and it installed a really nasty piece of adware that came in two pieces, each of which could recreate the other if you tried manually deleting it.  I&apos;ve fortunately forgotten the details but a search at AdAware for &quot;blogger&quot; ought to turn up the gory story.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-860769</guid>
		<pubDate>Tue, 22 Feb 2005 08:48:15 -0800</pubDate>
		<dc:creator>hank</dc:creator>
	</item>	<item>
		<title>By: mygothlaundry</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#861525</link>	
		<description>That bites, and I&apos;m glad it hasn&apos;t happened to me; this news is ruining my evening. I love the next blog button, I&apos;ve spent many useless wasted hours just clicking along through it all.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-861525</guid>
		<pubDate>Tue, 22 Feb 2005 18:17:53 -0800</pubDate>
		<dc:creator>mygothlaundry</dc:creator>
	</item>	<item>
		<title>By: teece</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#861543</link>	
		<description>mygothlaundry, just don&apos;t use IE and you will be fine -- the exploit relies upon ActiveX (and your clicking &apos;yes&apos; to a &quot;browser upgrade.&quot;)  If you aren&apos;t using Windows, then this is not a problem at all.

Hank -- you just describe exactly what the Javascripts I look at do, on the Blogger web page I saw.  So apparently Blogger has had no luck figuring out what to do about it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-861543</guid>
		<pubDate>Tue, 22 Feb 2005 18:38:07 -0800</pubDate>
		<dc:creator>teece</dc:creator>
	</item>	<item>
		<title>By: DrJohnEvans</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#861652</link>	
		<description>Yeah, this is &lt;b&gt;not&lt;/b&gt; an exploit of the &quot;next blog&quot; button.  This could be an unsuspected part of any personal website.

Heck, you could be visiting your little sister&apos;s Geocities website, and if she had decided that she wanted background music from iWebTunes, you&apos;d be attacked.  It&apos;s an IE vulnerability, not a Blogger one.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-861652</guid>
		<pubDate>Tue, 22 Feb 2005 20:16:24 -0800</pubDate>
		<dc:creator>DrJohnEvans</dc:creator>
	</item>	<item>
		<title>By: DrJohnEvans</title>
		<link>http://www.metafilter.com/39817/Spyware-hitting-blogs#861660</link>	
		<description>I couldn&apos;t find her email, so I left her a message on her Doodle Board.

I feel like I just turned on a hair dryer and pointed it at the rain.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2005:site.39817-861660</guid>
		<pubDate>Tue, 22 Feb 2005 20:21:31 -0800</pubDate>
		<dc:creator>DrJohnEvans</dc:creator>
	</item>
	</channel>
</rss>
