Stu McLaren’s Blog Gets Infected by Hackers

June 26, 2008 · Print This Article

In my previous post “Bandwidth Limit Exceeded” I explained my frustration at being emailed a “not to be missed offer” but then unable to view the site due to the website exceeding its bandwidth!

Well in an attempt to contact the sender of the email, well known Internet Marketer Stu McLaren, I headed straight over to his blog.

http://myideaguy.com/blog/ (DO NOT GO THERE)

BUT I WAS IN FOR A SURPRISE…

A few moments after visiting the section:

http://myideaguy.com/blog/category/products/ (DO NOT GO THERE)

My installation of Kaspersky Security Suite ALERTED me to a TROJAN infection trying to infect my computer!!!

The culprit was: Trojan-Downloader.HTML.Agent.is

(HERE is a screenshot)

…a well known WordPress iFrame exploit, something perhaps Stu should have been alert to as his installation of WordPress is obviously insecure (a quick inspection revealed he is using version 2.3.3 INSTEAD of the latest version 2.5.1). Ignorance in business is no excuse when your customers are at risk :-(

Drive-by downloads like this are an increasingly common way to infect a computer or steal sensitive information.

They usually consist of malicious programs that automatically install when a potential victim visits a booby-trapped website like Stu’s currently is.

Increasingly, criminals are using these drive-bys to install “keyloggers” that steal login and password information. Other pieces of malicious code hijack a computer turning it into a “bot”, a remotely controlled computer that can be controlled remotely without the owners knowledge.

Grim, I know but a reality on the Internet today.

The moral here is: If you have a WordPress blog SECURE it. If you are using the Internet make sure you have protection!

As for Stu McLaren’s blog… I have no idea how many of his website visitors have been infected but I guess I will not be going back there for a while…

Marc Liron

 

 

 

 

Kind Regards

Marc Liron
SiteBuildIt Pro
www.marcliron.co.uk

Share this information with others! These icons link to social bookmarking sites where readers can share and discover new web pages.
  • bodytext
  • Sphinn
  • del.icio.us
  • Facebook
  • Technorati
  • Live
  • Google
  • Reddit
  • StumbleUpon
  • E-mail this story to a friend!
  • Print this article!
Find Your Niche

Comments

3 Responses to “Stu McLaren’s Blog Gets Infected by Hackers”

  1. Is Your WordPress Blog Infected Yet? on June 26th, 2008 8:21 pm
  2. ChristinaHills on June 27th, 2008 9:33 am

    Marc,

    I know Stu and he is a great guy and an excellent marketer. This kind of virus could happen to any of us. I had no idea a virus could get into a blog like this.

    Do you have any suggestions on how to prevent this on my blog.

    You implied that WP 2.5.1 had fixed this security hole. Do you know if Semiologic blogs are protected by this?

    Do you know of any plugins that I can install on my blog to protect from this?

    -Christina
    “The Shopping Cart Queen”

  3. admin on June 30th, 2008 11:44 am

    Hi Christina,

    Have now spoken with Stu by email and he appears to be fixed now :-)

    …as for Semilogic, it is basically Wordpress with addons and extra PHP code.

    So you would still have to make sure you are running the current version of WP 2.5.1

    …even WP 2.5.0 had a security bug!

    Regards

    Marc Liron

Got something to say?

You must be logged in to post a comment.