Google Blogoscoped

Forum

Google Heard Him

Ionut Alex. Chitu [PersonRank 10]

Wednesday, June 13, 2007
17 years ago3,601 views

http://img462.imageshack.us/img462/6287/googlehearmeqs7.png

http://www.google.com/search?hl=en&q=can+google+hear+me&btnG=Google+Search

{ via Digg: http://digg.com/tech_news/Can_Google_Hear_Me_Earns_Unwelcoming_Label_Courtesy_of_Google_Itself }

Colin Colehour [PersonRank 10]

17 years ago #

The site has a hidden iframe that goes to "m-gallery.org/images/111/index.php" I removed the HTTP part.

Stop Badwares message:
" (www.cangooglehearme.com/) has been determined by Google's testing to be a site that hosts or distributes badware. The following are examples of urls on (www.cangooglehearme.com/) that Google has determined can lead users to be infected by badware:"

http://www.stopbadware.org/reports/container?reportname=www.cangooglehearme.com%2F

Colin Colehour [PersonRank 10]

17 years ago #

Screenshot of code in question:
http://farm2.static.flickr.com/1427/543608842_73365fc401.jpg?v=0

Suresh S [PersonRank 10]

17 years ago #

the google result shows this

Can Google Hear Me – Trying to get Google's attention through the ...
<B>This site may harm your computer.</B>
After I asked him to, he drew up some concept sketches for me to look at, and I'd love to hear everyone's opinion on them. If you click on the graphic at ...
www.cangooglehearme.com/ – 11 Jun 2007 – Similar pages

Ionut Alex. Chitu [PersonRank 10]

17 years ago #

More about the site and its story:
http://blogoscoped.com/archive/2007-02-15-n63.html

Philipp Lenssen [PersonRank 10]

17 years ago #

Heh.

Is that iframe or m-gallery.org harmful, and if so why?

TOMHTML [PersonRank 10]

17 years ago #

Google heard him. But did Google *listened* to him? THAT is the question
   (-:

Colin Colehour [PersonRank 10]

17 years ago #

[put at-character here]Philipp, I did a site: search for the exact page that is included in the iframe and that page has the same StopBadware message in Google search results. I did not load the page in question though to know what is even on it.

Philipp Lenssen [PersonRank 10]

17 years ago #

Weird, I tried the same (site search) and didn't get the message...

Colin Colehour [PersonRank 10]

17 years ago #

Screenshot of what I get:
http://farm2.static.flickr.com/1140/544280067_591d6dd4ae_o.png

Also, I did a lookup of the IP address of CanGoogleHearMe.com and that IP is being hosted at DreamHost

It seems that 3500 ftp accounts on DreamHost were compromised. Maybe Aaron's site was one of those?

Here is a link to people discussing DreamHost hacked accounts:
http://www.mezzoblue.com/archives/2007/06/05/unsettling/

Colin Colehour [PersonRank 10]

17 years ago #

DreamHost posted about the security breach and has a recent update about it too.

Security Breach
http://www.dreamhoststatus.com/2007/06/06/security-breach/

Web Hosting Break-Ins, Security Update
http://www.dreamhoststatus.com/2007/06/11/web-hosting-break-ins-security-update/

James Xuan [PersonRank 10]

17 years ago #

http://expressionengine.com/forums/viewthread/53745/

James Xuan [PersonRank 10]

17 years ago #

I did a site: search like Colin and got the message. I clicked the link, got Googles "Malicious" Message, proceeded to the site, got Google Desktops' "Advisory" message, proceeded and finally it was just a white page, probably infecting my PC in the background. Yay!

Colin Colehour [PersonRank 10]

17 years ago #

Yeah, I was tempted to see what the page was all about but then I figured I didn't want to have to disinfect my computer just because I was curious about one site.

Colin Colehour [PersonRank 10]

17 years ago #

I was able to get the source code of the page without loading it in a browser. Its just a Javascript block of code. No HTML is on the page.

Screenshot of the code:
http://farm2.static.flickr.com/1168/544239432_3e350cd598_o.png

Colin Colehour [PersonRank 10]

17 years ago #

Is this a Javascript exploit?

Colin Colehour [PersonRank 10]

17 years ago #

Aaron has fixed his site and it shows up fine for me in Google now.

James Xuan [PersonRank 10]

17 years ago #

Good!

Forum home

Advertisement

 
Blog  |  Forum     more >> Archive | Feed | Google's blogs | About
Advertisement

 

This site unofficially covers Google™ and more with some rights reserved. Join our forum!