Breaking! TailRank Exposes Massive Number Of Blogs Hacked
by Tony Hung on April 7, 2008
UPDATE 4.7.08: Looks like ZDnet was hacked as well (although they’ve since cleaned up)
So in some innocent conversation earlier today with Allen Stern, he noticed that Tailrank was getting hammered with spam, via Tailrank’s River — something Duncan Riley also noticed. To be honest, I’ve noticed it as well, noting snarkily that perhaps it wasn’t so much that Tailrank was getting hammered, as much as Tailrank’s algorithm was getting fooled, as it looks to grab content by skimming the content of feeds. That is, perhaps Tailrank was grabbing rotten spammy content.
Or … was it?
I had a closer look at many of the blogs concerned that had spammy content — pages promoting credit cards, pharmaceuticals and the like, and I realized that if you go to the root domain they are all legitimate blogs. Not scraper blogs that were being auto-generated with adsense / affiliate links, which was extremely curious, and actually reminiscient of something that hit home a few months ago.
A few months ago, this blog got hacked — but in a sneaky way. Not only did the hackers insert “invisible” code into my template, so that I was getting listed in Google for all manner of sneaky (and NSFW terms), so that people could click on those links with the hacker getting the affiliate cash — but *actually*, said hackers also inserted fake tempates into my wordpress theme.
I didn’t notice, because Dreamhost automatically installed a ton of themes, and so they were buried in there, but I only noticed when I started looking at my analytics and really odd pages started getting hits. Randomly.
I never got around to blogging about it before because it was all too strange, but with Tailrank, its clear that I’m not the only one that was buggered — its happening to a TON of blogs, and people don’t even know about it.
There seems to be two kinds of hackery going on, just like I’ve described:
1. Inserting “invisible” HTML full of links (for NSFW sites) into your WP template that isn’t obvious when you go to your blog, but is VERY obvious when you look at the source code (and start seeing that you’re getting traffic for some “peculiar” terms).
2. Inserting whole new source code / new sneaky themes that copy other blogs / content *exactly*, which is full of spammy content and affiliate links.
Why are there two? Why would you have any pages with nothing obvious to the reader?
Read on, because this is where it gets really nefarious.
First here are some examples.
- http://www.helmethairblog.com: Blogs about motorbikes. Has a ton of invisible code inserted into the WP theme right in his header. Check out the source code or try this file (I saved it): helmethairblog-source Note how all of the adsense if for *credit cards* (and not on motorbicycles)
- http://www.andysummers.com: A professional site for a guitarist named Andy Summers. Inside the press directory you can find at least six directories that contain pages for pharmacy, credit cards, and loans. Here is one of those pages.
- http://blog.jimnovo.com: the marketing and productivity blog for Jim Novo, who has a book called Drilling Down. This is probably one of the sneakiest (yet to be verified personally from Mr. Novo however) — the blog is running on WordPress, however, it looks like someone has sneaked in some extra php code, under a separate file called news.php. Given a particular value for the variable “blog”, it serves up different pages. For example, serving up “credit”, serves up this page which is ranking very well for Mr. Novo (accidentally of course).
The devious thing? The entire site is ripped off from CreditHit.com, and its a little unclear if this is therefore something perpetrated *by* CreditHit (because links are tracked and go back to them), or an affiliate *of* CreditHit (which would be strange, as the site is an affiliate portal for credit cards).
At any rate, if the number of blogs on TailRank are any judge (through the Tailrank River –> tailrank.com/river), there are a HUGE number of blogs / sites that are hacked and don’t even know it.
http://www.internmentcamp.com –> silent HTML spam
http://www.vinokeeno.com/ –> silent HTML spam
http://www.alexharford.com/ –> silent HTML spam
http://www.gossiportruth.com –> silent HTML spam
http://amandabanana.net/ –> silent HTML spam
http://license2code.com–> silent HTML spam
http://selfportraitchallenge.net/–> silent HTML spam
http://www.firstcrackpodcast.com/–> silent HTML spam
So, let’s get back to the two kinds of spam. Why is there all of this content that is “invisible” (and even selected out to be invisible by some CSS?)
The *REAL* Devious thing, and the heart of the matter, is that the pages full of *silent* spam are tracking back to a few particular sites, such as the jimnovo.com site and the andysummers site. The reason why? One need only look at the TailRank.com/River site to know why, as Jimnovo.com’s blog is headlining almost every node.
The other blog that many of those blogs link to is Interaccess.org, which is a site for a not-for-profit organization that focuses on art and technology. Its blog is here, called Axon, Interaccess.org/blog. But of course, the money is in the pages that have been sneaked in, like this one: http://interaccess.org/blog/?drug=4/pill-377-tramadol.html
What does this really all mean?
It means that these silent pages are a blackhat SEO tactic to *promote* a few select blogs / sites that have been hacked with prominent affiliate / spam links and spam content, thereby bumping up their relative standing on Google.
That’s right.
Some enterprising hackers have put together a scheme whereby they hack a number of blogs, so that they can create their own network pages and links back to a few select blogs, to pages that are not easily visible. It takes advantage of the organic and real page rank of all of the sites in question, and probably makes some bucks for the hacker involved.
Why is this bad for *you*?
Other than the knowledge that someone is profiting off of your back, what can happen is that if you’re running Adsense, Google might notice all the hidden text and penalize you and pull you right out of the Index.
De-indexed. It happened to me, and the above, in retrospect, is the very reason for it.
So, at this moment you might be wondering — what can I do to protect myself? How can *you* tell if your blog has been hacked?
Here are three ways (pray it doesn’t get to the three).
1. You start getting traffic from google for terms you never write about (say, credit cards)
2. If you use Adsense, you start seeing ads on your blog for stuff that in no way matches your content (credit cards for example)
3. If you get banned from Adsense for promoting content in a sneaky way.
My suggestion is that if you find yourself in this position, comb through your templates carefully to find the hidden HTML and delete it.
THEN, go through your blog / site directory with FTP, turn ON the “look for hidden things” and start hunting for any potential directories that look suspicious — i.e. you didn’t put them there.
Bottom Line: This all happened to DJI a few months ago, both as a “host” site for the affiliate / spam content (I’ve since deleted the fake WP theme) and a site that hosted silent / invisible links, but I didn’t have the wherewithal to figure it out.
I’m not a security expert, so I can’t tell you if the security breach is through WordPress (perhaps an older version) or higher up — on a wholescale level through hosting providers.
But irrespective of where the leak is, I think this should be a bit of a wake up call to everyone. Look real carefully to see if your blog has been compromised — because you in fact, may be the stooge for someone else’s nefariously devious Blackhat tactics.
ADDENDUM: oh … and Tailrank should also get its act together and realize what kind of content they’re promoting. They exposed this large scale hackery, but did so unintentionally. :P
Update: Looks like JimNovo.com *was* hacked … he removed the offending piece of code, and so you won’t be able to see the changes. Interaccess.org was also fixed as well.

85 comments
[...] than Machetera but Mark Evans, who runs the Deep Jive Interests blog posted one description just a few days ago: How can *you* tell if your blog has been hacked? Here are three ways (pray it doesn’t get to the [...]
by Freedom of the press for those who own one « Machetera on April 10, 2008 at 9:03 pm. #
[...] and exploited WordPress blogs. This comes after the recent spat of hacks that were discovered on various high profile blogs and websites. What was even more interesting was the fact that some of these hacks and exploitations might have [...]
by Vulnerable WordPress Blogs Not Being Indexed on April 11, 2008 at 1:30 am. #
[...] possibly being involved in a 10,000 strong network of hacked sites is actually referring to a recently discovered trend in popular sites, running the WordPress blogging software, having spam-related links embedded [...]
by FEWL.NET - Stars & Stripes Hacked! China Involved? on April 12, 2008 at 11:04 pm. #
I’ve seen the encrytption strings in wordpress over and over again, usually “hidden” in the footer file, during the past 12 months. Always just kind of deleted them and shrugged. I think initially they were just generating adsense ads, so this cross-linking strategy is a more developed strategy.
Surprises me that the story has taken this long to break.
by Rokwan on April 14, 2008 at 1:38 am. #
[...] ¿Aún no has actualizado Wordpress? ¿Todavía estás usando alguna versión atrasada de WordPress? No te sorprendas si tu blog resultan con spam links en alguno de los posts, gracias a una reciente ola de ataques a blogs con versiones de WordPress vulnerables. [...]
by ¿Aún no has actualizado Wordpress? « Javier Aroche @ Wordpress on April 14, 2008 at 4:06 am. #
[...] this week, it was discovered that a massive number of WordPress Blogs were hacked by an organized scheme, including installations at ZDNet, utilizing an xml-rpc [...]
by DrakNet Web Hosting on April 16, 2008 at 11:19 am. #
[...] Worpdress vulnerables y que hallan sido comprometidos. Esto es una respuesta a la reciente ola de ataques a blogs usando viejas versiones de WordPress, que en muchos casos intentan agregar spam links y otras cosillas. Los blogs de ZDnet parecen haber [...]
by Technorati no indexará blogs vulnerables on April 17, 2008 at 4:52 am. #
[...] Sim, admito, sou paranóico o suficiente para andar a chafurdar em logs, ver se está tudo bem, se não há erros manhoso, ver “last modified files”… Mas como na vida tenho mais que fazer e a comichão nos tomates já vai grande, que nem tempo para os coçar tenho, não me apercebi e fui uma das vítimas dum hackanço de blogs. Este. [...]
by P de quê?! » Upgrade e de paciência fodida on April 20, 2008 at 10:06 pm. #
My blog got ‘hacked’ recently and am hiring a guy to recover it. I can’t even make a new post! I hate hackers!
by borzack on April 21, 2008 at 6:18 am. #
This happened to one of my WordPress sites – but, for whatever damn reason, it also changed all of my pages into posts, thus breaking my entire site. all sorts of bad…
by Warwell on April 21, 2008 at 4:05 pm. #
Hi there
Thanks for this – we were targeted too – so maybe it is against SEO blogs, i don’t know.
I’m still working out how to get the damned thing to accept posts again, despite getting rid of all the crap (which was in the footer) and deletig the fake theme.
Nikki
http://www.299steps.com
by Nikki Pilkington on April 24, 2008 at 3:01 am. #
[...] Here’s more info. [...]
by Has Your WordPress Blog Been Hacked? - Family Clay on April 27, 2008 at 8:39 am. #
[...] and exploited WordPress blogs. This comes after the recent spat of hacks that were discovered on various high profile blogs and websites. What was even more interesting was the fact that some of these hacks and exploitations might have [...]
by blog.rotracker.net » Blog Archive » Vulnerable WordPress Blogs Not Being Indexed on May 7, 2008 at 5:11 pm. #
[...] early March, we’ve been fighting what turns out to be this massive hacking scheme, which has apparently compromised thousands or more [...]
by Body Impolitic - Blog Archive - » Where Oh Where Has Body Impolitic Gone? - Laurie Toby Edison: Photographer on May 12, 2008 at 6:53 pm. #
[...] and exploited WordPress blogs. This comes after the recent spat of hacks that were discovered on various high profile blogs and websites. What was even more interesting was the fact that some of these hacks and exploitations might have [...]
by nathanr|ca » Vulnerable WordPress Blogs Not Being Indexed on June 6, 2008 at 5:05 am. #
[...] and exploited WordPress blogs. This comes after the recent spat of hacks that were discovered on various high profile blogs and websites. What was even more interesting was the fact that some of these hacks and exploitations might have [...]
by Vulnerable WordPress Blogs Not Being Indexed | Wordpress Blog NL on July 16, 2008 at 4:45 am. #
[...] WordPress 2.6 July 18th, 2008 at 3:39 pm If you’re a user of WordPress, you should probably always upgrade when a new version comes out for security reasons. However, with the new release of WordPress 2.6, there are three features that really stand out [...]
by Deep Jive Interests » Three Things I Love About Wordpress 2.6 on July 18, 2008 at 3:39 pm. #
I like very much the writings and pictures and explanations in your adress so I look forward to see your next writings. I congratulate you.
by Marry on July 30, 2008 at 10:52 am. #
exploited WordPress blogs
by FMS GROUP on July 30, 2008 at 7:02 pm. #
The best pictures of cats,pictures of cute cats,funny pictures of cats,funny cats videos,in the htt://www.pictures-of-cat.com
by jeery on August 3, 2008 at 4:29 am. #
[...] Aber was ist heute noch sicher? Ein Grund warum position worx dieses Thema aufgreift ist die hohe Anzahl der neuerlich infizierten Blogs und die Hinterlistigkeit, wie dieser Angreifer sich andere Blogs zu nutzen macht. Der Schaden für jeden privaten Blog, sowie auch jeden Corporate Blog ist immens, denn meist ist ein Blog Bestandteil einer ganzen Präsenz. Ein Delisting aus dem Google Index, und sei es “nur mit einem Blog”, zieht selbstverständlich auch die Toplevel Domain mit ins Schlamassel. Folglich kann ein gezielter Angriff, von dem Sie selber nicht viel merken werden, Ihr Online Business von heute auf morgen auslöschen. Ein neuerlicher Hack macht die Tage die Runde, der eben so hart zuschlägt wie beschrieben. Nennen wir ihn Hidden Footer Links WordPress Exploit. [...]
by Wordpress Cloaking Exploit – Hidden Footer Links on January 27, 2009 at 5:56 am. #
[...] this is no uncommon thing. Dr Tony Hung recently discovered several WordPress websites that got hacked (include ZDNet) and affiliate links [...]
by Find If Someone Hacked Your WordPress Blog & Changed The Files | Moving Stones on February 27, 2009 at 5:50 am. #
That’s such a uncommon thing, maybe it got hacked or so?
by Doorlopend Krediet on April 15, 2009 at 2:46 pm. #
the Vortex system amazed even me.
by limewire on May 16, 2010 at 2:22 am. #
Thank you so much! I checked out the other two tutorials you’ve put up linked from digg and found them helpful, but this sealed it for me. Your site is now in my daily routine of places to check! Keep up the good work.
by sex shop on May 16, 2010 at 6:02 am. #
good.
by kely on May 23, 2010 at 6:40 am. #
ihn Hidden Footer Links WordPress Exploit
by tattoos on May 23, 2010 at 6:41 am. #
I’m still working out how to get the damned thing to accept posts again, despite getting rid of all the crap (which was in the footer) and deletig the fake theme.
by design on May 23, 2010 at 6:41 am. #
That’s such a uncommon thing, maybe it got hacked or so?
by lpn on May 23, 2010 at 6:42 am. #
that some of these hacks and exploitations might
by health on May 23, 2010 at 6:42 am. #
Computer hacking is most common among teenagers and young adults, although there are many older hackers as well. Many hackers are true technology buffs who enjoy learning more about how computers work and consider computer hacking an “art” form. They often enjoy programming and have expert-level skills in one particular program. For these individuals, computer hacking is a real life application of their problem-solving skills. It’s a chance to demonstrate their abilities, not an opportunity to harm others.
by Ethical Hacking Forum on October 19, 2010 at 11:57 pm. #
“Greg says that Well, when it comes to lawyers, foreign lawyers can only advise, but westerners can advise westerners better than Chinese with little or no western exposure can. Chinese lawyers who work for foreign law firms lose their right/license to operate in a Chinese court.
Also, last month one of the better known financial rags mentioned that after AIG’s bailout, it became known that 20% of China’s forex reserves existed as AIG corporate bonds. I was pretty surprised to read that and I began to wonder where else China has put its forex reserves other than “crates of cash in a warehouse”.
As for other foreign experts in China, well, the spectrum is pretty broad. But I really think that if Beijing and municipalities didn’t think they needed foreign expertise in areas like urban planning, mining, etc. they wouldn’t be handing out contracts to them. Having foreign experts practicing in China is actually useful in China though as that knowledge is taken by Chinese companies to Africa, Latin America and the Middle East,can anyone comment on this?”
by ã¡ã¿ãã¬ã¼ãã¼8 on March 22, 2011 at 12:35 am. #
The Ship Shape container is part of Alessi’s line of playful objects for the home. A fun design which offers a lidded container with a concealed spreader/spatula for cutting or spreading. A perfect fit for a stick of butter or soft cheese. Very cute and uninhibited approach that is becoming more of the fashion in design for the new century. Available in your choice of four colors, i really enjoyed this amazing blog.
by ã¡ã¿ãã¬ã¼ãã¼4 on March 22, 2011 at 10:48 am. #
The simplicity of this blog is very attractive and it is causing the attraction to the traffic towards it self and the color scheme of this blog is also amazing due to its simplicity and i hope that this blog will continue its jurney towards the success.
by GGC Live Gifting on April 3, 2011 at 12:19 pm. #
Michelle says that Wow, you got to meet HappySlip and Josh Verdes!! That’s so coool, Jon’! I was actually in Manila last Feb. 7-10. So little time, so much to do gd bi and dw na shy pa ko so I didn’t contact you before if we can meet.hehe,can anyone comment on this?
by sildenafil price on April 3, 2011 at 12:20 pm. #