<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: The website hack you&#8217;d never find</title>
	<link>http://johnmu.com/hack-hidden-redirect/</link>
	<description>John Mueller's technical website tips and tricks</description>
	<pubDate>Thu, 28 Aug 2008 18:11:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Ben LaGrone</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-988</link>
		<dc:creator>Ben LaGrone</dc:creator>
		<pubDate>Mon, 28 Apr 2008 17:23:57 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-988</guid>
		<description>John,

BTW I've found Fiddler very useful, but have hit a brick wall.</description>
		<content:encoded><![CDATA[<p>John,</p>
<p>BTW I&#8217;ve found Fiddler very useful, but have hit a brick wall.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben LaGrone</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-987</link>
		<dc:creator>Ben LaGrone</dc:creator>
		<pubDate>Mon, 28 Apr 2008 17:22:21 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-987</guid>
		<description>Hi John,

I'm trying to solve a similar mystery. Can I PM you the URL and see if you have any ideas. I'm trying to trace a cloaked redirect...</description>
		<content:encoded><![CDATA[<p>Hi John,</p>
<p>I&#8217;m trying to solve a similar mystery. Can I PM you the URL and see if you have any ideas. I&#8217;m trying to trace a cloaked redirect&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tristan</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-960</link>
		<dc:creator>Tristan</dc:creator>
		<pubDate>Sat, 01 Mar 2008 04:01:44 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-960</guid>
		<description>Great project!! You should be on google payrole!

John: "That could be a security issue in Firefox" :- given this would you recommend staying with Internet Explorer / Other for security reasons? I was considering Firefox due to repeated "IE not responding".

Do you think the antivirus advert (hidden hack redirect) was a joke or a moneyspinner or both?

BTW FYI I found this page after visiting http://groups.google.com/group/Google_Webmaster_Help-Requests/browse_thread/thread/3238914c52ff7b18/3f4de587650273fc

After an AVG activex thing popped up in ie7 while visiting a christianity page.  I clicked no.  Did that mean the page was triggering AVG or a virus pretending to? I ran AVG afterwards  and it found a "virus identified exploit.ANI" in my temp.  Did I prevent the virus spreading out of temp by clicking NO on the ActiveX request or prevent AVG catching it?  What use is the thing in temp anyway? 

Just curious (re:spam protection on this page).. Sum of 7 + 4.. can see how me typing in 11 would partially suggest I was a human; but as 11 is allready show in the field does this mean SHOWING question is redundant? My guess is prob' no, but I'm so curious :)

Brilliant work btw.. Tris.</description>
		<content:encoded><![CDATA[<p>Great project!! You should be on google payrole!</p>
<p>John: &#8220;That could be a security issue in Firefox&#8221; :- given this would you recommend staying with Internet Explorer / Other for security reasons? I was considering Firefox due to repeated &#8220;IE not responding&#8221;.</p>
<p>Do you think the antivirus advert (hidden hack redirect) was a joke or a moneyspinner or both?</p>
<p>BTW FYI I found this page after visiting <a href="http://groups.google.com/group/Google_Webmaster_Help-Requests/browse_thread/thread/3238914c52ff7b18/3f4de587650273fc" >http://groups.google.com/group/Google_Webmaster_Help-Requests/browse_thread/thread/3238914c52ff7b18/3f4de587650273fc</a></p>
<p>After an AVG activex thing popped up in ie7 while visiting a christianity page.  I clicked no.  Did that mean the page was triggering AVG or a virus pretending to? I ran AVG afterwards  and it found a &#8220;virus identified exploit.ANI&#8221; in my temp.  Did I prevent the virus spreading out of temp by clicking NO on the ActiveX request or prevent AVG catching it?  What use is the thing in temp anyway? </p>
<p>Just curious (re:spam protection on this page).. Sum of 7 + 4.. can see how me typing in 11 would partially suggest I was a human; but as 11 is allready show in the field does this mean SHOWING question is redundant? My guess is prob&#8217; no, but I&#8217;m so curious <img src='http://johnmu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Brilliant work btw.. Tris.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mrg</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-166</link>
		<dc:creator>mrg</dc:creator>
		<pubDate>Tue, 04 Sep 2007 17:51:21 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-166</guid>
		<description>Adding a little... You don't need to use a proxy if you are on windows. Back when we looked at the other hacked site with this same exploit all I had to do was to repair the connection to get a new IP address. And every time after that, when checking LiveHTTPHeaders it triggered the 302.</description>
		<content:encoded><![CDATA[<p>Adding a little&#8230; You don&#8217;t need to use a proxy if you are on windows. Back when we looked at the other hacked site with this same exploit all I had to do was to repair the connection to get a new IP address. And every time after that, when checking LiveHTTPHeaders it triggered the 302.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Show heute fällt leider aus &#124; seoFM - der erste deutsche PodCast für SEOs und Online-Marketer</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-108</link>
		<dc:creator>&#187; Show heute fällt leider aus &#124; seoFM - der erste deutsche PodCast für SEOs und Online-Marketer</dc:creator>
		<pubDate>Tue, 28 Aug 2007 14:32:37 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-108</guid>
		<description>[...] Der wohl sneaky-ste Website Hack bislang [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Der wohl sneaky-ste Website Hack bislang [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hearne</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-92</link>
		<dc:creator>Richard Hearne</dc:creator>
		<pubDate>Sun, 26 Aug 2007 10:33:58 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-92</guid>
		<description>Indeed rather scary stuff. Possibly one of the nastier exploits I've heard of recently.

I think tracking down the aff codes might help - removing some of the financial gain would be a start. I'm sure the installed payload is also just as nasty given the lengths the hackers have gone to...</description>
		<content:encoded><![CDATA[<p>Indeed rather scary stuff. Possibly one of the nastier exploits I&#8217;ve heard of recently.</p>
<p>I think tracking down the aff codes might help - removing some of the financial gain would be a start. I&#8217;m sure the installed payload is also just as nasty given the lengths the hackers have gone to&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Mueller</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-79</link>
		<dc:creator>John Mueller</dc:creator>
		<pubDate>Fri, 24 Aug 2007 11:01:48 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-79</guid>
		<description>Good, then it's not that bad :-) *big sigh of relief*</description>
		<content:encoded><![CDATA[<p>Good, then it&#8217;s not that bad <img src='http://johnmu.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> *big sigh of relief*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Altoft</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-78</link>
		<dc:creator>Patrick Altoft</dc:creator>
		<pubDate>Fri, 24 Aug 2007 11:00:04 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-78</guid>
		<description>I do use FF. It does just show the persons name at the top of the page.</description>
		<content:encoded><![CDATA[<p>I do use FF. It does just show the persons name at the top of the page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Mueller</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-77</link>
		<dc:creator>John Mueller</dc:creator>
		<pubDate>Fri, 24 Aug 2007 10:57:42 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-77</guid>
		<description>I tried Netvibes - you don't get redirected, but you see a part of the content here on their page (at least that's what I see). I see the name of the person from the original posting on the netvibes page and then this blog entry opens up in a separate window. Maybe I was a bit too sneaky for my own good, I hid that name from indexing by using javascript to display it (so that this page doesn't rank for his name). Apparently that javascript snippet is executed on the old page, before the redirect to the new window takes place. That could be a security issue in Firefox... (did you use Firefox as well?)</description>
		<content:encoded><![CDATA[<p>I tried Netvibes - you don&#8217;t get redirected, but you see a part of the content here on their page (at least that&#8217;s what I see). I see the name of the person from the original posting on the netvibes page and then this blog entry opens up in a separate window. Maybe I was a bit too sneaky for my own good, I hid that name from indexing by using javascript to display it (so that this page doesn&#8217;t rank for his name). Apparently that javascript snippet is executed on the old page, before the redirect to the new window takes place. That could be a security issue in Firefox&#8230; (did you use Firefox as well?)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Mueller</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-76</link>
		<dc:creator>John Mueller</dc:creator>
		<pubDate>Fri, 24 Aug 2007 10:36:58 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-76</guid>
		<description>@Patrick: that doesn't sound too good, but since the exploit only triggers when a user comes from Google, it shouldn't matter. Is Netvibes interpreting some of the markup? Did it really redirect or did it link to the site?</description>
		<content:encoded><![CDATA[<p>@Patrick: that doesn&#8217;t sound too good, but since the exploit only triggers when a user comes from Google, it shouldn&#8217;t matter. Is Netvibes interpreting some of the markup? Did it really redirect or did it link to the site?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Altoft</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-75</link>
		<dc:creator>Patrick Altoft</dc:creator>
		<pubDate>Fri, 24 Aug 2007 08:55:47 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-75</guid>
		<description>When I looked at this in your RSS feed in netvibes it redirected me to the infected site...........</description>
		<content:encoded><![CDATA[<p>When I looked at this in your RSS feed in netvibes it redirected me to the infected site&#8230;&#8230;&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JLH</title>
		<link>http://johnmu.com/hack-hidden-redirect/#comment-74</link>
		<dc:creator>JLH</dc:creator>
		<pubDate>Fri, 24 Aug 2007 04:19:50 +0000</pubDate>
		<guid>http://johnmu.com/hack-hidden-redirect/#comment-74</guid>
		<description>I'm glad you are one of the good guys...you've got some scary skills in figuring things out.</description>
		<content:encoded><![CDATA[<p>I&#8217;m glad you are one of the good guys&#8230;you&#8217;ve got some scary skills in figuring things out.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
