Original URL: http://www.theregister.co.uk/2007/03/15/blogger_malware/
Blogger.com, home of the weblog publishing system owned by Google, has been infiltrated by a number of phishing sites, security watchers report.
In some cases, the Stration mass mailer is being used to drive traffic to these fraudulent sites. One such scam is a "storefront" for Pharmacy Express, which redirects from a Blogspot.com (now Blogger.com) link. The site is designed to harvest the personal information of prospective marks.
Beyond the problem of spam and phishing sites, a number of Blogger.com sites have been compromised with malicious code. For example, a blog site seemingly created by a Honda CR450 enthusiast is hosting the Wonka Trojan.
Hundreds of other Blogging sites (covering subjects ranging from Star Wars, school, furniture, Christmas, cars, and girlfriends) are also infected, according to net security appliance firm Fortinet, which has published an advisory (http://www.fortiguardcenter.com/advisory/FGA-2007-04.html) highlighting its concerns. ®
Miscreants subvert search results to punt malware (28 November 2007)
http://www.theregister.co.uk/2007/11/28/botnets_use_search_to_build_zombies/
Storm Worm descends on Blogger.com (29 August 2007)
http://www.theregister.co.uk/2007/08/29/storm_hits_blogger/
Researcher crosses swords with Google over XSS 'flaw' (21 August 2007)
http://www.theregister.co.uk/2007/08/21/google_modules_security_debate/
VXers publish blog poisoning tool (30 July 2007)
http://www.theregister.co.uk/2007/07/30/blog_poisoning_tool/
Security consultant's blog found pushing crudware (4 July 2007)
http://www.theregister.co.uk/2007/07/04/security_blog_pushes_crudware/
Google acquires 'sandbox' technology for secure browsing (29 May 2007)
http://www.theregister.co.uk/2007/05/29/google_security_acquisition/
Blogosphere threatened by Google downtime (16 May 2007)
http://www.theregister.co.uk/2007/05/16/blogger_downtime/
eBay users targeted by advanced Trojan (6 March 2007)
http://www.theregister.co.uk/2007/03/06/ebay_trojan/
MySpace hackers avoid extortion rap (27 February 2007)
http://www.theregister.co.uk/2007/02/27/myspace_hack_sentencing/
MSN punts 'scareware' (21 February 2007)
http://www.theregister.co.uk/2007/02/21/msn_messenger_scareware/
Script wreaks havoc on MySpace (31 January 2007)
http://www.theregister.co.uk/2007/01/31/myspace_spam/
© Copyright 2008