Forum Moderators: phranque
Blogger.com, one of the most visited blog sites, now owned by Google.com, has been compromised with several malicious scripts. The scripts have shown up on hundreds of Blogger.com sites, and in some cases, a possible vector of the Stration mass mailer is responsible for driving traffic to these sites.
Malicious Code Compromises Blogger.com [fortiguardcenter.com]
""A blogger recognizing the domain may be more tempted to visit the link.""
You have to take an action and click on a fake url in an email to go there it is not something that is in the blogger code itself...
They could've gotten the bad code just by using a 3rd party FREE template for blogger that contained the exploit, hard to say.
FWIW, just checked my blogspot site and it appears to be clean ;)
What you (spammers) do is open a blog account. If you can not stuff code into the blog message area itself you go to your preferences and edit the css template area (you stuff your Javascript in there). They use Javascript as Google can not pick it up. They probably use encoded Javascript to stop google from even seeing a domain name.
Then, Google loving blogs and especially their own rank the damn thing high because they can not see the redirect. Surfers get these in the first page of search returns, click the link, Javascript redirects to target site.
Again, that is not hacking. Hacking is where you find a vulnerability in the OS or application itself and exploit that. Blog sites that are dumb enough to allow people to add Javascript to their "blogs" just go to show how much Google has put on suits of anti-spam armour only to leave their own backsides bare.