October 17, 2004

  • XANGA BLOGWORM


    Wednesday 6:21 pm: Are you being redirected to this site?  Please read the instructions below on how to remove the “Xanga Virus” in your Look and Feel.


    We shut down a self-proclaimed “Xanga Virus” yesterday, so that it stopped spreading and stopped working.  But this evening, the same virus started generating a popup that said: ”"Warning!  You have a Xanga virus!  The following page will help you delete it.”  If you clicked OK, you were redirected to a xanga post from an innocent user who had posted a fix for this virus. 


    The virus has been disabled, and we will run a program tonight to finish deleting it from our system.  If you’d like to make sure that any remnants of the virus are swept from your system, please do the following:


    INSTRUCTIONS ON CHECKING FOR AND REMOVING THIS “XANGA VIRUS”:



    • Go to your Look and feel page: http://www.xanga.com/claf
    • Search for the phrase “mtarea” or “aj.rezzycakes.com”
    • If you see it in your page, you’ve been infected .  You can delete the code by hand, and then click on “Save Changes”.

    I’m sorry about this…  we’ve been steadily increasing the security on Xanga over the past year.  We just disabled META tags last week because some users were using them to redirect users to spam/porn sites… and now we’re going to have to start disabling more JavaScript, so that this can’t happen again.  We’re migrating towards a JavaScript free system, as we add native support for a lot of the things that people are now kludging with JavaScript.  In the meantime, we are moving forward on a developing investigation to bring this attacker to justice.


    John


    ps Yesterday, the same Xanga Virus worked differently, redirecting visitors to an external site.  The external page looked like a Xanga signin page… but it wasn’t under the Xanga.com URL.  The hacker was “phishing” for usernames and passwords.  If you’ve “signed into” this outside page, your Xanga site may be at risk.  If this has happened to you, please change your password ASAP!


Comments (1582)

Post a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *