The Accidental Smallholder Forum

Community => Coffee Lounge => Topic started by: northfifeduckling on July 01, 2011, 11:06:42 pm

Title: hijacked
Post by: northfifeduckling on July 01, 2011, 11:06:42 pm
our blog's under attack again. some @~~@#£%^ is linking us to hundreds of his own posts and has disabled the function of the bin - we can not remove the links like we can from other people. I am having very unkind thoughts , to put it mildly.... I actually wonder if he has hacked into our system and is not attacking it from the outside. Any blogging wizzards/witches in our community who can help with some technical advice, maybe per pm or email/chat? Or recommend a curse that works  >:( :P :pig:    :&>
Title: Re: hijacked
Post by: doganjo on July 01, 2011, 11:58:49 pm
Can you close it down for a while till you sort it out, Kerstin?  Dan may be able to help you.
Title: Re: hijacked
Post by: Sylvia on July 02, 2011, 08:27:50 am
Why do people do these things? Have they nothing in life to interest them? When found out they should be given an allotement and MADE to keep it nice! >:(
Title: Re: hijacked
Post by: northfifeduckling on July 02, 2011, 08:36:27 am
Absolutely, that would improve his state of mind. We think it might be personal. Google jealousy - a new term for the dictionary.  :P :&>
Title: Re: hijacked
Post by: supplies for smallholders on July 02, 2011, 02:10:23 pm
Sounds to me like he has managed to access the files on the server to get that type of control.

Often the only way to solve this is to completly wipe the site clean and restore from a known good backup. Then try (with your hosts assistance) to find out how they got in.

Unfortunately even if you find and clean the code that they have inserted then they often leave "backdoors" so they can access the site again.

Good Luck
Title: Re: hijacked
Post by: yankieGirl on July 02, 2011, 04:02:44 pm
In the US we  refer to these turds as adult men who still live with mommy and spend the day in the basement wearing nothing but their undies, playing with two things:  the computer (creating havoc for others) and a tube of KY jelly (creepers).

Hope this site doesn't shut down.  I need you folks!!!!!!

Title: Re: hijacked
Post by: Hilarysmum on July 03, 2011, 09:30:07 am
I put them on the same level as those who deliberately fool the public into thinking they are buying a tea cup pig and then damn the consequences. 

Shoot them all say I.  (Not that I am aggressive or anything  :) )
Title: Re: hijacked
Post by: northfifeduckling on July 22, 2011, 11:12:08 am
just had an idea - does any of you computer buffs know if swapping pcs might help? Using one for the blog that has not at all been on-line previously?

It's been getting worse over the last weeks, OH is spending too much time deleting the links, bl... waste of time. This guy does not have a different life other than " destroying" folks on-line.  ::) ::) :&>
Title: Re: hijacked
Post by: supplies for smallholders on July 22, 2011, 02:10:52 pm
You are wasting your time just deleting his enteries.

A hacker, once he accesses your site will make sure he always has a "back door" that will let him back in whenever he wants - you can delete entries till the cows come home, but unless you clean out the access code he will always be able to get back in - he owns your site now.

Only way (other than by examining every line of code in every programme file) to get rid of him is as follows:

1) Delete entire site from server - ask Host to wipe your hosting account clean.
2) Restore a KNOWN GOOD backup of your site - if you dont have one then ask your host, this must be from before a time when he first accessed your site.
3) Carry out a virus scan of your computer - specifically for "Key Loggers" that record everything you type (that includes passwords etc)
4) Change all you passwords - for everything.
5) If your Blog is "open source" software then look on the tech forums for how to plug any known security holes.

Without carrying out the above yo will never be rid of him!

Good Luck
Title: Re: hijacked
Post by: supplies for smallholders on July 22, 2011, 04:11:59 pm
OK thought about this some more - as you are using Blogspot which is part of Google it is very unlikely that this has been hacked - as that would be as difficult as hacking google itself.

This means that they are most likely accessing your blog via your username & Password - so it is vitally important that you scan your pc for a key logger then change your access passwords.
Title: Re: hijacked
Post by: tizaala on July 22, 2011, 04:13:09 pm
When it comes to passwords always include some numbers and some symbols  such as '' accidental47small@#$holder=3'' this makes their life a lot more difficult
Title: Re: hijacked
Post by: faith0504 on July 22, 2011, 04:16:22 pm
Hi i have been following this thread, SFS how do you scan for key loggers??  :wave:
Title: Re: hijacked
Post by: supplies for smallholders on July 22, 2011, 04:18:00 pm
Not really if a keylogger is in operation, as it just records everything you type - Including your bank access codes if u use pc for that !!

You can pick these up by accepting dodgy email attachments.........
Title: Re: hijacked
Post by: northfifeduckling on July 22, 2011, 04:28:53 pm
OH has changed his password many times, no difference. Most likely he's got remote access to the pc itself - which apparently is easy for a pro, so I was told. Hence the thought if switching machines may help.
Title: Re: hijacked
Post by: supplies for smallholders on July 22, 2011, 05:07:26 pm
I dont think you are reading what I said - if you have a key-logger on your pc it will record and send the new password to the hacker, and anything else you type. It could als be a programme called a Trojan which lets him steal your passwords, steal your files, and just do about anything he wants on your computer.

You can do an online scan of your pc here : http://www.internetinspiration.co.uk/Pest%20scan-free%20online%20spyware,%20trojan,hijacker,malware%20scan.htm (http://www.internetinspiration.co.uk/Pest%20scan-free%20online%20spyware,%20trojan,hijacker,malware%20scan.htm)

Or a good antivirus / anti-spyware programme - if you want a good free one try AVG Free edition which offers anti-spyware as part of the free edition functionality.

Thanks
Title: Re: hijacked
Post by: northfifeduckling on July 22, 2011, 05:24:44 pm
we've got AVG, Ccleaner, spybot s&d on all our machines. tried Avast, too but took it off in favour of AVG.

I do read what you say SfS - I do not ask the question to annoy you - could changing the pc make a difference if it can't be solved otherwise? As we have a spare clean machine the one affected or infected could be taken off the net (and passwords changed after of course) - if it helps
 :bouquet: :&>
Title: Re: hijacked
Post by: supplies for smallholders on July 22, 2011, 05:30:45 pm
It would be worth a try - as the blogspot programmes are (almost) impossible to hack so he must be getting access via your password and user ID, if you have all the security measures in place that you say above then Im puzzled how this could happen.

Ill do a little more research...........
Title: Re: hijacked
Post by: supplies for smallholders on July 22, 2011, 05:41:57 pm
Ok - a couple of things I have found out:

1) Access to your blog can be gained by inserting certain "Gadgets" - I see you have some on your site.

2) Have a look at this discussion thread - re what to do on suspected blogspot hacks.

A bit of work for you I think...

Whoops - forgot to post the link ! : http://www.google.com/support/forum/p/blogger/thread?tid=5b1c62045e623ca6&hl=en (http://www.google.com/support/forum/p/blogger/thread?tid=5b1c62045e623ca6&hl=en)
Title: Re: hijacked
Post by: lill on July 22, 2011, 05:50:15 pm
I can sympathise with you, its not nice to get hijacked. A good going over with a 4x2 would do the trick and leave him needing someone else to wipe his own ar-e for a while. It may not be nice but it sure get rid of your frustration
Title: Re: hijacked
Post by: doganjo on July 22, 2011, 06:11:16 pm
I can sympathise with you, its not nice to get hijacked. A good going over with a 4x2 would do the trick and leave him needing someone else to wipe his own ar-e for a while. It may not be nice but it sure get rid of your frustration
Both my hotmail accounts were hacked and horrid links being sent out on them.  My grandchildren are on my contacts list so you can imagine my and their parents' anguish and frustration that Hotmail would not let me completely delete the accounts there and then - they apparently have a 'cool off ' period of 270 days.  However, I persevered and deleted them after I had deleted my contacts lists, changed the display names to 'no-one' and 'this is not me',  and STIll nessages are being received!  Not once did it occur to me to resort to physical viloence!

It is such a pity that these hackers could not turn their minds to constructive use instread of malevolent as the modern world would be such a better place to live in.
Title: Re: hijacked
Post by: Sylvia on July 22, 2011, 06:15:51 pm
I can sympathise with you, its not nice to get hijacked. A good going over with a 4x2 would do the trick and leave him needing someone else to wipe his own ar-e for a while. It may not be nice but it sure get rid of your frustration

Actually, a good going over with a 4x4 would do the job better ;D
Title: Re: hijacked
Post by: bazzais on July 22, 2011, 07:35:00 pm
I agree with the 4x4, and make it a huge tractor too not just a mere one ton machine link a landrover - better still get one of those porche cayenne 4x4, run over their head (where it will probably get stuck) then set fire to it with them underneath :)


It sounds very strange as blogger auto install alot of mechanisms to stop password guessing and normal bedroom attacks and security issues when they are found.

Are you using blogger?

Is the spamming appearing actually in the blog or as comments?

Do they have access to your email address password (the one you can send password reminders too?) - crucial!!!

Baz
Title: Re: hijacked
Post by: northfifeduckling on July 22, 2011, 07:36:06 pm
thanks, SfS for the links, we'll give them a go. Everyone else for your moral support  ;) :&>
Title: Re: hijacked
Post by: supplies for smallholders on July 22, 2011, 07:42:38 pm
No Problem,

Its always an uphill struggle trying to keep one step ahead of hackers and in our case jumping through hoops to pass payment card industry web-site scans.

I think reading the posts that the biggest danger on Blogspot is using EZ-install add-ons, there is a link at the bottom of the page I posted regarding social engineering hacks.

Thanks
Title: Re: hijacked
Post by: northfifeduckling on July 22, 2011, 07:43:38 pm
we're using blogspot. No evidence of any other access to email etc. He's just obviously attaching links to his own sites ( by the 100s a post)to knock us off the top spot we believe. They are only visible when logged on, I can't see them if I just look at the blog. :&>
Title: Re: hijacked
Post by: bazzais on July 22, 2011, 07:48:35 pm
Delete all your other security programs as most malware circumvent them installing properly and infect the programs directly.

Does the computer have a legit version of windows on it - if not your knackered.  If you have not updated your pirate version of windows since windows 2000 you'll get a virus in seconds just by plugging into the web.

I know its a swear word - but microsoft - install http://www.microsoft.com/en-gb/security_essentials/default.aspx (http://www.microsoft.com/en-gb/security_essentials/default.aspx) - you'll need a correct windows license for this.

After doing a complete scan, change all your passwords to nothing obvious - try reversing a telephone number you know from childhood and combining it with a street address - the longer the better

It is possible for a computer to be so infected its impossible to fix, do you have a restore disk and a means of posting all your pictures and information via google to yourself? (they scan email)

Ta

Baz
Title: Re: hijacked
Post by: bazzais on July 22, 2011, 07:52:35 pm
After reading the previous :

It sounds like its not a problem then, someone posting without admin privileges - ie its not published.

I dont know exactly how blogger works I am afraid so I cant comment further by it sounds like someone has just propagated your submission page and it may be robots doing the work.?

Baz

Title: Re: hijacked
Post by: Victorian Farmer on July 25, 2011, 10:25:14 am
most people use pass words for msn bank pay pal etc and they will try to use this infermation.iv had msn Hackett and pay pal not very good.