Web Images Videos Maps News Groups Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Odd, Spammy Code in the Twitter Blog Post
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  10 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Brad Kellett  
View profile  
 More options Mar 8 2008, 6:32 pm
From: Brad Kellett <bradkell...@gmail.com>
Date: Fri, 7 Mar 2008 23:32:02 -0800 (PST)
Local: Sat, Mar 8 2008 6:32 pm
Subject: Odd, Spammy Code in the Twitter Blog Post
If you fire up the Twitter blog post -
http://www.barcampsydney.org/2008/03/06/barcampsydney-now-on-twitter/
- and look at the code, there seem to be some spammy links hidden in
the text, for example:

<li>JJ<noscript>Download <a href="http://www.toques-excelente.com/
avaliacoes-download-de-toques-para-celular.html">http://www.toques-
excelente.com/avaliacoes-download-de-toques-para-celular.html</a>
Jazz: Top Seleções Toques De Celular Ringtones Gratuitos Polifônicos e
Monofônicos.</noscript> Halans: @

Don't know where they are coming from, but someone really needs to
jump into the theme and do a solid clean out of any included JS and
such. No good.

~bck


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
russ - maxdesign  
View profile  
 More options Mar 8 2008, 6:58 pm
From: russ - maxdesign <r...@maxdesign.com.au>
Date: Sat, 08 Mar 2008 18:58:26 +1100
Local: Sat, Mar 8 2008 6:58 pm
Subject: Re: [BarCampSydney: 68] Odd, Spammy Code in the Twitter Blog Post

> Don't know where they are coming from, but someone really needs to
> jump into the theme and do a solid clean out of any included JS and
> such. No good.

Good pickup. Removed  :)

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Brad Kellett  
View profile  
 More options Mar 8 2008, 7:07 pm
From: Brad Kellett <bradkell...@gmail.com>
Date: Sat, 8 Mar 2008 00:07:15 -0800 (PST)
Local: Sat, Mar 8 2008 7:07 pm
Subject: Re: Odd, Spammy Code in the Twitter Blog Post
Cheers. I think the bigger problem is how these things are making
their way into the site to start with though.

~bck

On Mar 8, 6:58 pm, russ - maxdesign <r...@maxdesign.com.au> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
John Allsopp  
View profile  
 More options Mar 8 2008, 7:09 pm
From: John Allsopp <j...@westciv.com>
Date: Sat, 8 Mar 2008 19:09:01 +1100
Local: Sat, Mar 8 2008 7:09 pm
Subject: Re: [BarCampSydney: 68] Odd, Spammy Code in the Twitter Blog Post
If the site is run on wordpress, you need to upgrade to 2.3.3, or  
upgrade the XML-RPC file in your current instal

More info

http://wordpress.org/development/2008/02/wordpress-233/

john

On 08/03/2008, at 6:32 PM, Brad Kellett wrote:

John Allsopp

style master :: css editor :: http://westciv.com/style_master
about me :: http://johnfallsopp.com
Web Directions Conferences :: http://webdirections.org
My Microformats book :: http://microformatique.com/book


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Brad Kellett  
View profile  
 More options Mar 8 2008, 7:25 pm
From: Brad Kellett <bradkell...@gmail.com>
Date: Sat, 8 Mar 2008 00:25:06 -0800 (PST)
Local: Sat, Mar 8 2008 7:25 pm
Subject: Re: Odd, Spammy Code in the Twitter Blog Post
The site is already running on WP 2.3.3

On Mar 8, 7:09 pm, John Allsopp <j...@westciv.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
John Allsopp  
View profile  
 More options Mar 8 2008, 8:07 pm
From: John Allsopp <j...@westciv.com>
Date: Sat, 8 Mar 2008 20:07:18 +1100
Local: Sat, Mar 8 2008 8:07 pm
Subject: Re: [BarCampSydney: 72] Re: Odd, Spammy Code in the Twitter Blog Post
damned,

thought they'd fixed this problem with 2.3.3 -

john
On 08/03/2008, at 7:25 PM, Brad Kellett wrote:

John Allsopp

style master :: css editor :: http://westciv.com/style_master
about me :: http://johnfallsopp.com
Web Directions Conferences :: http://webdirections.org
My Microformats book :: http://microformatique.com/book


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jean-Jacques Halans  
View profile  
 More options Mar 8 2008, 9:22 pm
From: "Jean-Jacques Halans" <hal...@gmail.com>
Date: Sat, 8 Mar 2008 21:22:31 +1100
Local: Sat, Mar 8 2008 9:22 pm
Subject: Re: [BarCampSydney: 73] Re: Odd, Spammy Code in the Twitter Blog Post
According to Secunia "Successful exploitation requires valid user credentials."
http://secunia.com/advisories/28823/
Maybe look through the registered users and delete all which shouldn't be there?
Let people re-register if they want to post comments. Do you need
comments enabled to begin with?

But might be something else all together...
What version of Apache is it running? Maybe upgrade to latest version
(if you're running your own slice/vm)?
What version of PHP?
What are the access rights on the files and folders?
Are there any additional WP themes installed?

One of my hosts, MediaTemple, updated their php installations in January:
"There is a parameter for php called 'allow_url_fopen' that is
currently enabled in both our PHP4 and PHP5 environments.  If the
proper precautions are not taken in PHP a large number of code
injection vulnerabilities frequently reported in PHP-based web
applications are possible.  We understand that our customers install a
great number of PHP-driven applications, many of them from the
open-source community.  Unfortunately a great number of them can
potentially fall prey to these vulnerabilities. "
Has this been disabled on your server (allow_url_fopen can be found in php.ini)?
While you're at it, have a look at register_globals and turn that off too...

(Djee, I better have another look at my WP installation too...)

JJ

--
Jean-Jacques Halans

================================

================================

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Brad Kellett  
View profile  
 More options Mar 8 2008, 9:25 pm
From: Brad Kellett <bradkell...@gmail.com>
Date: Sat, 8 Mar 2008 02:25:53 -0800 (PST)
Local: Sat, Mar 8 2008 9:25 pm
Subject: Re: Odd, Spammy Code in the Twitter Blog Post
I guarantee it is something much simpler. The theme already had dogdy
stuff in it that was removed, should start with it and give the code a
good once over. Happy to volunteer for that.

~bck

On Mar 8, 9:22 pm, "Jean-Jacques Halans" <hal...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Andrew Fong  
View profile  
 More options Mar 8 2008, 10:41 pm
From: "Andrew Fong" <and...@clockworkdesign.com.au>
Date: Sat, 8 Mar 2008 22:41:41 +1100
Local: Sat, Mar 8 2008 10:41 pm
Subject: RE: [BarCampSydney: 76] Re: Odd, Spammy Code in the Twitter Blog Post
Is it worth giving the database the once over as well ? Check the table
contents.

In case someone has injected some code into it somewhere ?

Just a suggestion.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Ajay Ranipeta  
View profile  
 More options Mar 9 2008, 5:52 am
From: "Ajay Ranipeta" <ajay.ranip...@gmail.com>
Date: Sun, 9 Mar 2008 05:52:41 +1100
Local: Sun, Mar 9 2008 5:52 am
Subject: Re: [BarCampSydney: 79] Re: Odd, Spammy Code in the Twitter Blog Post

ok, gonna try and do a full and fresh install and copy data over,
v.carefully.. hope that might fix the problem.

thx for picking it up Brad

cheers,
-ajay-


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google