Get YOUR Own Free Affiliate Cash-Pulling Website. Make Up To $13,500 Per Month Commissions!
 




Get Reviewed by this Blog for only $500
DealDotComTTZ MediaGoogle Adsense
Pepperjam NetworkBidvertiser
Text Link AdsKonterra

This morning, while I was checking my MyBlogLog community, I noticed that another site has mysteriously appeared on the list of sites and blog I author.

john.png

I don’t know what site that is or how it got there but it seems someone has figured out a way to get their blog listed in the Sites and Blogs I Author section of MyBlogLog members. Checking out the mystery blog shows the spammer managed to get himself listed onto other MyBlogLog accounts, including Shoemoney.

shoe.png

It’s clear the spammer is targeting popular MyblogLog communities to get his site in front of as many people as possible. So far, it looks like I’m the only one who has removed the offending blog. No doubt the spammer planned his attack on the weekend thinking the blog owners will be away till Monday.

MyblogLog seems to be growing faster than the Yahoo can handle. Spam is becoming a major problem and there are countless exploits that a spammer can use to gain access to the community. Yahoo needs to shut this crap down before MyBlogLog becomes another MySpace.

Find out what I am doing right now by following me on Twitter! If you like this post then please consider subscribing to my full feed RSS. You can also subscribe by Email and have new posts sent directly to your inbox.

Make Money Online with John Chow's Ad Network - Join TTZ Media Now!
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5 out of 5)
Loading ... Loading ...

Here's A Few More Related Posts

  • Added MyBlogLog To The Blog
  • MyAvatars for MyBlogLog Plugin Broken
  • MyAvatars For MyBlogLog
  • The Winner Of The MyBlogLog Contest Is
  • MyAvatars Finally Updates Their Plugin

    RSS feed | Trackback URI

    41 Comments »

    Comment by david
    2007-02-18 17:06:17
    MyAvatars 0.2

    Yep — I accepted one invitation to a MyBlogLog community over the weekend (my first one), and was flooded with e-mail spam within 30 minutes. I quit the community and likely won’t give MyBlogLog another chance…

     
    Comment by Gareth
    2007-02-18 17:11:57
    MyAvatars 0.2

    I received a phishing style email from someone over the weekend wanting me to become a co-author of another blog. Except I’d neve heard of the blog and the person who was meant to be offering had never visited my profile on mybloglog.

    I wonder how long it will take them to plug the holes that allowed you to become the owner of another blog?

    Comment by Jeff
    2007-02-18 21:58:40
    MyAvatars 0.2

    I get so much of that crap through mybloglog too… some guy going “thanks for visiting my site” or “wow great blog you have there” and what not.. it’s crap.

     
     
    Comment by HMTKSteve
    2007-02-18 17:19:30
    MyAvatars 0.2

    I think I know how he did it.

    If you see mt blog show up on your list you will know ;)

    Comment by HMTKSteve
    2007-02-18 17:53:50
    MyAvatars 0.2

    Check it out John Chow, you are now my co-author!!!

    That was a super easy hack. I may have to blog about this one!

    Comment by John Chow
    2007-02-18 18:01:33
    MyAvatars 0.2

    Yep. I say this is something to blog about.

    Comment by HMTKSteve
    2007-02-18 18:03:33
    MyAvatars 0.2

    Blog article complete. It should show up as a trackback here.

    (Comments wont nest below this level)
    Comment by Nomar
    2007-02-19 04:54:15
    MyAvatars 0.2

    Cool !! Nice articles guys

     
     
     
     
     
    Comment by Hannes Johnson
    2007-02-18 17:24:04
    MyAvatars 0.2

    Yeah, Yahoo needs to handle all these issues - Shoemoney also reported another MyBlogLog exploit a while back…

     
    Comment by HMTKSteve
    2007-02-18 17:34:46
    MyAvatars 0.2

    My guess is that the person in question has multiple mybloglog accounts and he experimented with the add co-author feature to the point where he figured out how to write up the confirmation link that comes via email. It’s possible that the email verification link is the weak point.

    John, check your spam filter for a co-author request from his account.

     
    Comment by HMTKSteve
    2007-02-18 17:35:36
    MyAvatars 0.2

    Wait a minute… When you were co-author, did you have any special admin powers?

     
    Comment by Ian
    2007-02-18 17:35:38
    MyAvatars 0.2

    This is a real shame as MyBlogLog has so much potential, I’ve read various other stories similar to this about people finding exploits.

     
    2007-02-18 18:01:28
    MyAvatars 0.2

    [...] reading a post on John Chow’s blog mybloglog open to attacks. This hack allows an unknown blogger to attach their blog to the owner of a very popular community. [...]

     
    Comment by Mark Johnson
    2007-02-18 18:04:02
    MyAvatars 0.2

    I received one over the weekend from a Belgium site that blogs about Zune. They were asking me to join the blog as a co-author. Considering I that it was a non-english blog and that I didn’t know who it was, I just deleted the email. These Spam guys just find every loophole and spoil it for everyone don’t they. Pretty sickening.

    Comment by Kenny
    2007-02-18 22:04:42
    MyAvatars 0.2

    While these spam guys exploit weaknesses in the system, it provides an opportunity for sites such as mybloglog to go and fix these issues resulting in a more secure site.

    On the other hand, if they just sit idle and don’t fix these issues swiftly, the whole system will just collapse as bloggers move on to better services out there.

     
     
    Comment by Sharique
    2007-02-18 18:29:12
    MyAvatars 0.2

    This spam thing is becoming a big problem, not just limited to big communities but also small ones. As Mark pointed out regarding the Belgian site. Spammers always find a way out!

     
    Comment by Marc
    2007-02-18 18:50:36
    MyAvatars 0.2

    Well thankfully my blog is so low traffic that I haven’t been subject to anything like this ;)

    Score one for flying under the radar!

     
    Comment by Darren
    2007-02-18 19:06:03
    MyAvatars 0.2

    I had four emails last night from people inviting me to become authors of blog communities that I’d never heard of before - its quickly becoming a spam den over there :-(

     
    Comment by Meg
    2007-02-18 19:39:41
    MyAvatars 0.2

    I know it’s not the point, but it is pretty easy to remove the blog from your profile (see my latest post). It does highlight some issues though…

     
    Comment by Jennifer Lynn
    2007-02-18 19:47:13
    MyAvatars 0.2

    I received a phishing email for co-ownership from that Belgium blog as well. It will be sad if mbl continues to deteriorate ;/

     
    Comment by David Mackey
    2007-02-18 20:13:35
    MyAvatars 0.2

    hmmm…I’ve been hearing a bit about this mybloglog lately. Mainly about exploits, but it seems to be picking up some pretty good steam. I’ll give it a try.

     
    Comment by Jeremy Steele
    2007-02-18 20:14:01
    MyAvatars 0.2

    The exploit is probably because of A) There is a huge flaw in their verification code algorithm, or B) Some fool forgot to close off a database insert flaw, most likely because of the lack of string checks.

    Most likely it is B. Most security flaws are caused by a lack of data checks.

    Anyways, I’m getting pretty fed up with MyBlogLog as well. When I first joined a few weeks back it was fine, and about two weeks ago I noticed people with names like “FREEWINDOWSVISTA” visiting my profile. Stupid affiliate spam site people.

    What they need to do is add in a user voting system, so if a site gets below a certain rating it is automatically put up for moderation. If the site is deemed to be a spam site it will be banned forever.

     
    Comment by Bradford Knowlton
    2007-02-18 20:38:49
    MyAvatars 0.2

    Hello John,

    Sorry for the targeting your awesome blog. I’m a regular reader, and only choose people to target which I knew might have connections inside of MyBlogLog to get this fixed. This was just something that needed to be brought to attention before it got out of hand, with people automating the whole process, to ruin MyBlogLog.

    Thanks,
    Bradford Knowlton
    http://www.seoadwords.com/
    http://www.wig-dig.com/

     
    Comment by Webmaster Labor
    2007-02-19 00:12:48
    MyAvatars 0.2

    While it’s definitely an annoyance, this recent exploit/spam attack does serve as a (backhanded at least) compliment to mybloglog’s ability to get targeted traffic to blogs. I just recently open a mybloglog account and already get quite a bit of traffic from it to my offshore outsourcing site and free online traffic generation blog. Mybloglog is huge. You get traffic just by visiting people’s community sites. You don’t even have to leave a message. People see your profile, get curious, and check out your page.

     
    Comment by ilker
    2007-02-19 01:38:07
    MyAvatars 0.2

    I received several Co-Author Invitation emails as well. I will blog about it to expose those shameless people.

    Although, this should not be a long term problem as people are just discovering the bits of MBL waiting to be exploited.

    Comment by Leftblank
    2007-02-19 02:27:00
    MyAvatars 0.2

    Same here, up to 5 mails a day, while my blog isn’t even very popular or so, I wonder how they find the ones to spam.

     
    Comment by HMTKSteve
    2007-02-19 03:59:03
    MyAvatars 0.2

    Feel free to “re-use” my blog post on this hack, just be sure to give a link-back. I publish under a Creative Commons License.

     
     
    2007-02-19 04:10:33
    MyAvatars 0.2

    [...] worked. The spammer has attached their website to a lot of popular bloggers communities. More from John Chow This morning, while I was checking my MyBlogLog community, I noticed that another site has [...]

     
    Comment by Doug Karr
    2007-02-19 07:09:00
    MyAvatars 0.2

    Wow. That’s not good, I really like MyBlogLog. What did you do about it?

     
    Comment by Nick
    2007-02-19 07:33:05
    MyAvatars 0.2

    Everything has people exploiting features, MyBlogLog is no exception nor will anything ever be. I have received over 400 emails in the past two days from the site and it’s crazy - not to mention waking up this morning to be a co-author of 6 other sites.

    That is what I don’t understand - attacking John, Shoemoney, etc makes sense for traffic, but not the little guys.

    -Nick
    Blogger Time Capsule - 100,000 User Goal!

    Comment by Bradford Knowlton
    2007-02-19 10:32:10
    MyAvatars 0.2

    Hello Nick,

    I discovered the loophole late Saturday night. and I choose to add Shoemoney, John, Danny, Graywolf to my list for 1 reason. A) They are going to blog about it to people would find out it is happening, B) They are smart enough to just click remove and go on with life.

    I didn’t have any connection with the Beligum people, and the only reason I did anything was to draw attention to the problem and get it fixed. Everyone I choose, the top 10 bloggers, might have readers at MyBlogLog or Yahoo who could get this fixed.

    Lets hope it gets fixed,
    Bradford Knowlton
    http://www.wig-dig.com/
    http://www.seoadwords.com/

     
     
    2007-02-19 11:13:50
    MyAvatars 0.2

    [...] bloggers are talking about comment spam, author hacks, and other My Blog Log issues today - John Chow, Darren Rowse, Danny Sullivan. This is a huge issue for MBL - they better get into reputation [...]

     
    2007-02-19 12:19:24
    MyAvatars 0.2

    [...] : it seems that there’s other people (famous people or the A-List Blogger such as Shoemoney, John Chow, Darren Rowse, and Danny Sullivan) that got the same problem like me too. And now i know that [...]

     
    2007-02-19 14:21:01
    MyAvatars 0.2

    [...] John Chow and search guru Danny Sullivan have reported, they have been approached to become “co-authors” of [...]

     
    2007-02-19 16:13:47
    MyAvatars 0.2

    [...] they’d been added as authors on blogs that they didn’t write on including ShoeMoney, John Chow, Danny Sullivan and Web Metrics Guru. Reading the comments on these blogs shows that many others [...]

     
    Comment by Debbie
    2007-02-19 19:56:44
    MyAvatars 0.2

    John, I’ve noticed just by commenting on your blog for the first time a few days ago (before that, I was a lurker) that I’m getting a lot of comment spam on my blog now that I didn’t have before.

    Akismet seems to be catching it for now. But I wonder if the MyBlogLog spam is spilling over into this blog and following those of us who comment.

    Maybe it’s just coincidence.

     
    Comment by Eric Marcoullier Subscribed to comments via email
    2007-02-19 20:49:01
    MyAvatars 0.2

    Hey all — we’ve posted a long article on the MyBlogLog blog about what happened and what we’re doing in response. It’s long and involved enough that distilling it here isn’t going to be very useful. If you get a second, please have a look and let us know your thoughts. http://mybloglogb.typepad.com/my_weblog/2007/02/weekend_spamtac.html

     
    2007-02-21 04:15:50
    MyAvatars 0.2

    [...] then discovered the exact same thing reported on Blogpond. Apparently both Jeremy Shoemaker and John Chow were affected and added to be the co-authors of that spammy community. If you [...]

     
    2007-02-25 01:17:28
    MyAvatars 0.2

    [...] not the only problem, though - MyBlogLog has been reported to have some serious security flaws that allows random people to add their blog or site to your [...]

     
    2007-02-25 10:34:19
    MyAvatars 0.2

    [...] John Chow and search guru Danny Sullivan have reported, they have been approached to become [...]

     
    Comment by Ajith
    2007-02-25 21:55:04
    MyAvatars 0.2

    Some days before shoemoney put another one. thats MBL is tracking adsense and YPN also which they can allegedly sell to others

     
    Name (required)
    E-mail (required - never shown publicly)
    URI
    Your Comment (smaller size | larger size)
    You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.