More Than Two: Moving toward and moving away

I’ve just written a blog post in the More Than Two book blog about building polyamorous relationships where we move toward something rather than moving away from something. Here’s the teaser:

I was recently asked to do a media interview about polyamory. This happens from time to time, and most of the questions I’m asked tend to be fairly predictable: How do you deal with jealousy? What do you tell your parents or your kids? Do you think polyamory is the next cultural revolution?

This interview was quite different, and one of the questions I was asked helped crystallize for me some of the guiding ideals about the relationships I choose.

The question concerned dealing with fears, and while I was answering it, it suddenly occurred to me: throughout my life, the relationships I have found most rewarding have been those that are guided toward something rather than away from something.

You can read the whole thing; feel free to respond there or here.

Spam network: Hold on to your networks!

I get, as most folks do, a lot of spam in my inbox. A lot of spam.

And, as most folks who follow my blog know, I dedicate some time to tracking down that spam, especially when it involves hacked Web sites.

Lately, I’ve been getting a tremendous amount of spam that all looks pretty similar. It usually offers phony lose-weight-quick products, miracle hair regrowers, and other health and beauty scams, and the emails all tend to look pretty much the same. Here’s an example:

Pretty bog-standard stuff.

These emails invariably contain URLs that are either hacked sites or sites that have no content at all on the home page. The hacked sites are straightforward; the spammers hack the site, put in a new subdirectory, and put an index file that redirects to another site. The sites that have no content on their top level are a puzzler; it’s not clear if the spammers are setting up these sites themselves, using fake or stolen credit card information, or are hacking into sites that have been reserved and configured for hosting but have never had any content placed in them.

Where it gets interesting is in what happens after that.

Clicking on the URL in a spam email takes you to the hacked or blank site, and leads to a redirector. The redirector leads to another, and another, and another, and another, until you finally end up at the spam site. The chain of events looks like this:

The first stop on the chain is ow.ly, a URL shortener used by Hootsuite, the social media company that lets you manage multiple Twitter, LinkedIn, Facebook, and other social media accounts.

Hootsuite is a large, rapidly-growing company that is filled with bright, ambitious programmers who appear to know very little about security and nothing at all about abuse prevention. I wrote a blog post a while ago with a flowchart of Web 2.0 startups; Hootsuite appears to be somewhere in the early stages of the Loss of Innocence part of the chart, having not yet keyed into the fact that their URL shortener is becoming popular with malware droppers and spammers. (The poor naive dears are still so innocent, they have no mechanism at all for reporting ow.ly spam! I predict that’s going to bite them in the ass in an ugly way, soon.)

After that, things get more interesting.

click here for technical stuff!

It’s finally happening!

For years, I’ve been on-again, off-again working on a book on polyamory.

It’s been discouraging, in that all the publishers I’ve talked to want me to make it a personal memoir, and that’s not what I want to write. The project has been languishing for a while, by which I mean for several years, lost beneath the shuffle of More Important Matters.

It has finally, at long last, been resurrected. My sweetie Eve and I have started working on a new book, one that combines her ideas about polyamory and mine. It’s going to be a monster–it’s looking to shape up as a 500-page hands-on guide for folks who want to explore polyamory, chock full of problem-solving ideas, hints and tips.

We’ve launched a new blog which will contain progress notes, ideas and essays that don’t fit into the Web site More Than Two but also don’t make it into the book, and more.

We’re going to crowdfund this project; to get around the small but nevertheless still niggling issue that publishers want a different book from the one we want to write, we’re launching a full-fledged publishing imprint to go along with it.

If you’d like to know more, check out the blog and keep watching this space!

Some thoughts on rape culture

A couple of days ago, someone on a (closed) Facebook group I belong to posted a link to a blog post about rape culture.

And, predictably, one of the first comments to that link was along the lines of “this is just another attempt to say that male sexuality is bad.”

It doesn’t even really matter where the linked blog post is (though if you’re interested, it’s here); the “you’re just demonizing men” reaction comes up on any conversation I’ve ever seen about rape culture, as sure as night follows day. And it’s annoying.

It seems to me that if that’s your take-away from discussions about rape culture, you aren’t paying attention.

Male sexuality is not inherently evil, and acknowledging that rape culture is a thing isn’t the same as “demonizing male sexuality.” This seems obvious to me, yet it’s a persistent trope: saying that we have a culture that normalizes, trivializes, and to a large extent even excuses sexual violence is conflated with demonizing male sexuality, as if, I don’t know, male sexuality were somehow inextricably tied to rape or something.


I personally have never met any women who believe that male sexuality is tied to rape, though I keep hearing from other men about that’s what “feminists think”.

When I see a trope become that deeply embedded in a conversation about something, I tend to wonder who it benefits. I definitely think there are men who benefit from this trope. There are some men who want to conflate “discussing the cultural component of sexual violence” with “demonizing all male sexuality.” These men want you to read articles like the blog post that led to all this and respond with “you’re saying men are evil! You’re saying all men are rapists!” That’s the interpretation they want you to have.

There are two kinds of men who want you to have that response: rapists, and men who want power over women.


Not all men are rapists.

There is, for some people, a knee-jerk response to any conversation about rape culture that goes “You just think all men are rapists!” That isn’t what this (and articles like it) say. What they say is that women have to act like all men are potentially rapists, because rapists don’t wear a special hat or have a special handshake or anything.

A strange man is probably not a rapist, but he might be. Since there’s no telltale signal that lets you tell a rapist from a not-rapist, women have to assume that a stranger could potentially be a rapist, simply out of self-preservation. A common analogy here is that not every strange dog will bite you, but it’s usually a good idea not to approach every strange dog you see with reckless abandon–because some of them might bite you, and you have no way of telling which.

Rapists and men who want power over women are quite pleased when people deflect conversations about rape culture with “you’re just saying male sexuality is evil,” because it shuts down conversation about the reality of rape culture…and that suits them just fine. It allows things to continue on exactly as they are–which is to say, allows society to continue blaming victims of rape for their own attacks (“did you see what she was wearing??!), allows rape victims who come forward to continue being disbelieved, allows the courts to continue under-prosecuting rape.

All of this serves the needs of men who rape and men who want to control women, and the only side effect (other than the fact that, y’know, women are marginalized) is that some men are treated like they might possibly be a rapist.

You’re a guy, and you don’t like it? You don’t like the idea that women who don’t know you might respond as though you are a potential rapist, even though that’s something you would never, ever, do? Do something about it! Do something to make our society less welcoming to rapists. Don’t trivialize rape. Don’t whine “but what about false accusations?” when women talk about how claims of rape are rarely taken seriously. Don’t treat tape as a punch line.

Look, this is not rocket science. If you’re a guy, you have a disproportionate amount of power, even if you personally don’t feel like it’s true. It’s not enough to say “Well, I’m not a rapist, and I don’t trivialize rape, so I don’t like it when women treat me like I might be a rapist!” You have to do more. You have to stand up to the people around you who do trivialize rape. You have to stand up to people who are rapists–yes, I’m talking to you, and yes, statistically, unless you live as a hermit in a one-room cabin in Montana you probably know at least one rapist in your social circle. Even if you don’t know who he is.

You don’t like the implications of discussing rape culture? Don’t dismiss those discussions; that doesn’t serve anyone except rapists. Do something about it.

Onyx 3.6 is now available!

After great feats of hard labor deep underground in the data mines, I have used my mighty hammer and anvil to forge a new version of Onyx, the Game of Sexual Exploration: version 3.6!

This new version fixes some minor bugs in 3.5, but more importantly, it retools things under the hood for improved compatibility with Windows 7 and 8, and versions of Mac OS X beyond 10.8.

Onyx is a free download for Mac, Windows, and Linux. It’s a fun, sexy party game for 2-6 players you’re close to, or would like to be. Explore new sexual activities, spice up your life, get closer to the people you know, and who knows? Maybe even find true happiness!

GoDaddy, malware, and an ISP’s fall from grace

Some time ago, I posted about a malware attack hitting a large number of sites all across the globe, in which hacked Web sites were subverted into distributing a Windows-based bit of malware called W32/Kuluoz, which attempts to steal banking, PayPal, eBay, FTP, and other passwords from your computer.

In that post, I charted the ISPs hosting the most malware-infected sites, and noted that US ISP GoDaddy was, by far, hosting the most active malware droppers.

I used to be a GoDaddy customer. I hosted many Web sites on their servers, some of them for eleven years, and I recommended them to my clients as well. A couple of years back, I started pulling my sites off GoDaddy and recommending that my clients do the same because they began experiencing severe performance issues affecting their shared hosting database servers.

In all the time I have hosted with them in the past, though, the one thing I’ve really liked about them was their abuse team. At the time, it was one of the swiftest, most savvy, most responsive abuse and security teams of any major ISP on the market.

Those days appear to be gone.


The post I linked to above was written in April. Right now, as I type this, many of the malware droppers I saw back then on GoDaddy’s servers are,unbelievably, still active.

GoDaddy, in the spam span of just a couple of years, seems to have gone from being one of the top anti-abuse ISPs to being one of the worst. I have, quite literally, seen tiny ISPs in normally spam and malware friendly havens like Romania deal with security and abuse issues better.

One one level, it might be assumed that large ISPs are just getting worse about security and abuse issues in general. After all, an ISP’s abuse and security team are paid to reduce the company’s revenue, something that’s hard to stomach in a world where hosting providers are becoming part of Wall Street, particularly in an economic downturn.

Or it could be a statistical fluke. As ISPs host more sites, the number of sites with security problems might naturally be expected to increase.

But neither of those ideas seems to explain GoDaddy’s problems. Other ISPs, even large ISPs which have in the past had serious issues with security (like Dreamhost, a hosting company which has in the past had serious security problems of its own), are actually getting better–more responsive, more secure, faster to take down malware-infected sites.

Nearly all the ISPs I have seen be targeted by the Kuluoz malware attacks have grown better at detecting them and better at shutting down compromised sites quickly.

Nearly all, that is, except GoDaddy.


It’s hard to say what’s happening inside GoDaddy. What’s happening from the outside, however, is plain. Its abuse team does not respond to malware and security reports. Reported malware sites stay active for months. There’s a site I first reported to GoDaddy in November that was only finally fixed in May, and I’m not sure it was GoDaddy’s doing; the site owner may have secured the site himself. Repeated complaints to GoDaddy’s abuse team, in email and using their abuse Web form, produce few or no results.

Meanwhile, the entire Internet suffers. GoDaddy customers have their sites compromised and taken over by organized crime. Web surfers get directed to malware droppers hosted by GoDaddy. GoDaddy appears to be aware of the situation, at least if they monitor their Web forms and abuse address (something which has not been conclusively demonstrated, I’ll admit), and chooses not to act.

For a short time, GoDaddy’s Twitter team was responsive to these problems. When I started tweeting about GoDaddy-hosted malware droppers which had been active on their servers for months, I would receive responses like this:

I was briefly hopeful, but the infected sites remained active, still spreadingthe Kuluoz malware.

It’s hard to understand why, as many ISPs move in the direction of being responsive and security-conscious, GoDaddy is moving in the opposite direction.

At the moment, as I type this blog post, I am aware of at many malware droppers on GoDaddy’s servers, many of which have been active for four months or more, including malware droppers on sites like www.buysynthetic.com and www.wiredprojects.com which GoDaddy has been notified of multiple times and which continue to remain active.

At this point, it appears the best course of action is to avoid GoDaddy and to advise others to do the same. I no longer recommend GoDaddy to my clients, and I’ve pulled my own sites off their servers. I am also transferring my domains away from GoDaddy as they come up for renewal.

It’s disappointing to see a large company that was once so responsive to abuse and security issues sink to the point where they’re now worse in that regard than ISPs in Romania and Kazakhstan.

There is a saying in the anti-spam community: the normal course of business of a spam-supporting ISP is to go out of business. It will be interesting to see if GoDaddy follows this course, or if they are able to change direction before their inability to act against compromised sites costs them significantly.


UPDATE: Two days after posting this, I received the following email from GoDaddy:

Dear Franklin

Thank you for sharing your feedback with us.

Please rest assured that GoDaddy takes security and malware issues seriously. We have fully investigated your concerns and at this time all reported malware has been removed. We encourage CMS users to follow best practices, keeping core and secondary components such as plug-ins and extensions up to date. We welcome any additional feedback you wish to share in reply.

Thank you for your time and as always, thank you for being a GoDaddy customer.

John M.
Office of the CEO, GoDaddy
14455. N. Hayden Rd. Suite 226
Scottsdale, AZ 85260
CEOTeam@GoDaddy.com
480-505-8828

I’ve checked the emails I’ve sent them, and sure enough, all the malware droppers are gone.

Movie Review: Star Trek Into Plot Holes

J J Abrams, the visionary director who brought you such cinematic masterpieces as Jimmy Kimmel Live! and Star Trek: A New Hope Reboot, returns to his director’s seat for Star Trek: Into Plot Holes.

The movie goes something like this:

CAPTAIN JAMES T. KIRK and BONES are RUNNING ACROSS A FIELD OF WEIRD RED TREES being CHASED BY PRIMITIVE ALIENS

BONES: Why are these aliens chasing us?
CAPTAIN JAMES T. KIRK: Because I stole their sacred scroll.
BONES: Why did you steal their sacred scroll?
CAPTAIN JAMES T. KIRK: To distract them from looking up at the shuttle we are sending into the volcano.
BONES: Oh, right.
BONES: Wait, what? If they were in the temple when you stole the scroll, which we know because they all came swarming out of it, they wouldn’t have been able to see the shuttle we’re sending into the volcano. So you got them all outside to chase us, where they would be more likely to see it.
CAPTAIN JAMES T. KIRK:
CAPTAIN JAMES T. KIRK: Jump off this cliff now.
BONES: Okay.

Clicky here to see more! Caution: Spoilers and bad plot choices beneath.

The world’s first 3D printed gun: Ho hum.

Today, a landmark in improvised engineering was reached. Plans for an (almost) entirely 3D printable firearm went up on the Internet, able to be freely downloaded by anyone.

The reactions around the Net are predictable. Libertarians and gun nuts are ecstatic, gushing all over themselves about how this will be the “end of gun control” and usher in some kind of “new age of freedom” or something.

Law and order types, gun control advocates, and the government are wetting themselves with the prospect of legions of terrorists printing up virtually undetectable firearms and taking over airplanes or something.

And it’s all completely ridiculous. Neither a new age of freedom nor a new age of terror are in the works; in fact, I’m quite confident in predicting the total impact of this technology will be statistically undetectable. Self-congratulatory (on the one side) and paranoid (on the other) ravings aside, this thing simply does not make any meaningful difference whatsoever.

First, let’s see this harbinger of freedom end of civilization toy for rich white kids:

It’s printed from ABS plastic on an $8,000 3D printer. Almost everything is plastic, including the barrel; the only non-plastic parts are an ordinary nail (for the firing pin) and the bullet itself (in this case, a .380 caliber).

Now, I’ve owned firearms and shot recreationally for most of my life,1 and the first thing I can say upon seeing this thing is that I wouldn’t want to fire it. My instinct is that it’s probably about as dangerous to whoever’s on the trigger end as whoever’s on the business end.

The one shown here was test-fired three times. The first time, it misfired. The second time, it successfully fired a .380 round without destroying itself. The third time, when the .380 was replaced with a 5.7×28 cartridge, it exploded.

Could it survive multiple shots with the smaller round? I don’t know. Maybe. I wouldn’t bet my life on it. Doesn’t really matter. Not only is this thing not a game changer, I reckon it’s about as significant in terms of its overall impact on society as whatever toy they choose to put into a box of Cracker Jacks next week.


For starters, what you’re looking at here is not only a shoddy firearm of dubious reliability and ruggedness; it’s an $8,050 $9,000 shoddy firearm of dubious reliability and ruggedness. This prototype was printed on an $8,000 3D printer with about $50 worth of materials, making it arguably the single most expensive zip gun that’s ever been fabricated. A person looking for cheap, untraceable guns would be able to buy an arsenal on the street for less than the cost of the printer that produced this thing. (Edit: It turns out that this gun actually requires $1,000 worth of plastic toner to print, making it arguably the most expensive zip gun ever made even if the cost of the 3D printer isn’t factored in.)

Now, I already know what you’re going to say. The cost of 3D printers is dropping quickly. People can rent one or use one at a school. Companies will 3D print parts for you.

All of which is true, but irrelevant; the ability to make crude, cheap firearms for a lot less than just the cost of the plastic alone for this thing has existed…well, for about as long as firearms have existed. Prisoners have been known to build guns from parts available in prisons.

It has never been lack of availability that has kept people from using small single-shot firearms like this. The reason every criminal in town isn’t sticking up convenience stores with zip guns isn’t that they have been languishing in wait for a Libertarian college student to design one that can be 3D printed and put on the Internet; it’s that these things are virtually worthless as weapons. They tend to be used in prisons but few places besides, because they’re unreliable, prone to failure, inaccurate, and dangerous to the operator.

Just like, ahem, the 3D printed version.

Seriously. Even when they work, you have to be at point-blank range (or better yet, in contact with your intended target) for them to be terribly effective.

Which leads to the next hand-wringing objection: OMG this is made of PLASTIC you can take it onto an AIRPLANE through a METAL DETECTOR!

Which is, err, only kind of true. It’s a bit bulky to hide on your person, and there’s still the fact that the firing pin and ammunition are metal. Now, you might be able to get a nail through security on some pretext or other, but I doubt many folks will let you carry ammunition onto a plane.

If they notice it, which is a different matter; I’ve had friends who’ve carried brass knuckles and switchblades onto planes without difficulty. The reality is that few people actually want to, and have the means to, attack an airplane; nearly all of what happens at the airport is security theater, not security.

But let’s assume just for amusement that you can get one of these onto a plane. So what? What of it?

If I wanted to attack an airplane with a weapon I made on a 3D printer, it wouldn’t be this gun. Even if it works, it only works once, and I doubt the other passengers would sit around idle while I reloaded it and prepared to fire again. Assuming that the first shot actually did any good anyway.

The guy who designed this says “You can print a lethal device. It’s kind of scary, but that’s what we’re aiming to show,” as if this is the first time that’s been possible. Sorry, kid, but you’re a ridiculous wanker; a 3D printed knife or spear is actually a lot more lethal than this toy gun. (There’s a reason shivs rather than zip guns are the preferred weapon in places like prisons, and it’s not all down to scarcity of ammunition; given how easily drugs flow into American prisons, ammo isn’t that much of a stretch if there were a demand for it.) The 9/11 hijackers, who were well-funded, used…box cutters.

But I wouldn’t carry a 3D printed knife, or even a cheaper and better ceramic knife, onto a plane with mischief in mind either, because I’m not suicidal. Post 9/11, one thing has actually made air travel safer: the fact that the other passengers aren’t about to sit quietly by and hope for the best if someone tries to take a plane. All the other security changes that have happened since then have paled in effectiveness next to passenger attitude.

So, here’s the million-dollar question. You take a plastic gun onto an airplane, and…what, exactly? What in the name of the seven holy fucks and the twelve lesser fucks do you do then? What’s your plan?

If your goal is to destroy the plane, you can’t do that with this thing. If your goal is to take over the plane, well…good luck with that. You might survive what the other passengers do to you, maybe, if you’re lucky. Everybody is shrieking about how this thing can defeat airline security…and then what?


In fact, that million-dollar question can be extended to just about any possible use for this thing. You’ve bought yourself an eight-grand 3D printer, or somehow got access to it. You download the plans like an eager little hacker and you print this out, and then you…um, what do you do then? Go online and brag to your Maker friends?

You aren’t going to use this for home defense. I mean, seriously. A baseball bat or a tire iron makes a better home defense weapon, and the baseball bat probably has a longer effective range.

You’re not going to use it to outfit your secret militia that’s pining for anticipating the day that the Federal government starts rolling the tanks down Main Street. You aren’t even going to use an AR-15 for that, because, listen, seriously? The government has drones. They can blow your ass to hell and gone and you’ll never even see someone to shoot at.

You aren’t going to take it down to the range and pop off a few rounds in the general direction of paper cutouts of zombies or Trayvon Martin. No gun range is going to let you anywhere near the firing line with this; it’s too dangerous to the other shooters.

And please, please tell me you think you can go hunting with this thing. Bring a video camera and let me know when the video is up on YouTube. You can’t get enough of that for my entertainment dollar.

So you’re going to print it out, you’re going to put it together, and then…what, exactly? I’m still not clear on that.

Now, if you designed it, what you’ll do is obvious: you’ll get media exposure for congratulating yourself on what a clever Libertarian you are. And as near as I can tell, that’s really this thing’s only usefulness.


1 Full disclosure: I’ve been a private firearm owner on and off since 1988. I like guns, I like target shooting, and I’m neither opposed to nor afraid of guns. All that being said, I still won’t fire one of these.

New essay on Promiscuity Keepers: Ending Rape

I’ve just posted an essay over on Promiscuity Keepers, Some Thoughts on Ending Rape. Here’s a teaser:

Recently, I started noticing references in my Twitter feed to a Twitter account called @EndingRape. The account belongs to a man named Richard Hart, who has a Web site and book called Keep Your Daughter Safe.

Now, I don’t think Richard Hart is a bad guy. I don’t think he’s evil or malicious. I think he probably sincerely believes that rape is a Bad Thing and he probably genuinely wants a world with less of it.

But his approach is deeply troubling, and in some cases even destructive, for a number of reasons.

Feel free to respond here or over there.

Stealth WordPress attack: How to get hacked without even knowing it

Lately, one of the contact forms on a Web site I run has started to get hammered with spam form submissions. The spam submissions appear to be able to defeat common CAPTCHA programs (those things that won’t send a Web form unless you type a blurry, wiggly word to show that you’re a person, the idea being that a computer has trouble reading the word).

Interestingly, these spam submissions seem to go to sites that are just fine; ordinary, everyday sites, most but not all running WordPress, with no spam in sight. The majority of the sites that aren’t running WordPress are, naturally, running Joomla.

Of course, being the suspicious bastard I am, I immediately suspected a subtle attack like the one I talked about in October of 2010, where modifications were made to the main WordPress loop PHP file that would serve up ordinary blog posts to ordinary visitors and serve up redirectors to spam if the visitor was a search engine or if the visitor came from a search engine.

And sure enough, a quick Google search showed I was right.


Here is one of the spam submissions I received on my contact form:

wkgFqTcoAqy

Where do you come from? <a href=” http://www.construction-accident.us “>cheap stendra</a> helpings of Peninah’s food are hard to resist. Peninah also runs the store in the Miti House 2. This is a major

If you visit the site www.construction-accident.us you see a perfectly ordinary WordPress site that appears to have nothing wrong with it.

Ah, but now let’s see what Google sees!

The site has been hacked and the main WordPress loop has been tampered with. When Google looks at the page, keywords advertising prescription drugs are inserted into the page’s code.

If you click on the link in Google, you’re sent to www.construction-accident.us and then promptly redirected back to Google. It seems like the redirection is based at least in part on the browser you are using; when I use Safari on Mac, I end up at Google, but changing my browser’s user agent to Explorer 7 results in no redirection, Explorer 8 and 9 redirect to Google. I haven’t quite figured out the magic combination of browser and platform user agents to see where the hostile redirection leads to.

I downloaded the page using wget (a terminal-based Web downloader) and looked at the file that was downloaded. Whenever the hacked site sees Google as the referrer, it modifies the page by adding pharmacy keywords to the Title tag:

<title>Buy Stendra Online | Construction Accident|Oil Rig Explosion|Dallas|Texas|Gulf Mexico|Construction Accident Lawyer|Construction Accident Lawyers|Construction Accident Attorney|Construction Accident Attorneys|Construction Accident Law Firm|Construction Accident Law Firms</title>

and then it inserts the following code after the WordPress header:

<div class=”post”><p>stendra</p>
</br><p>avanafil</p>
</br><p>stendra for sale</p>
</br><p>stendra (avanafil)</p>
</br><p>stendra side effects</p>
</br><p>stendra dosage</p>
</br><p>stendra vs viagra</p>
</br><p>stendra online</p>
</br><p>buy stendra</p>
</br><p>buy generic stendra</p>
</br><p>generic stendra</p>
</br><p>stendra generic</p>
</br><p>where can i buy stendra</p></br>
<p>cheap stendra</p></br><p>order stendra</p></br>
<p>stendra price</p></br><p>stendra cost</p></br><
p>stendra cost per pill</p></br><p>stendra coupon</p></br>
<p>stendra order</p></br><p>stendra online</p></br>
<p>stendra avanafil</p></div>

You can see this if you do a Google search for

site:www.construction-accident.us

and then look at the cached version of the first hit.


So that’s how the attack works. WordPress sites are hacked. The WordPress files are modified so that ordinary users and the site’s owner are not aware that anything is wrong. The site continues to look and work as normal.

But oh, people who find your site by using Google? They see ads for fake pharmaceuticals! If they visit your site from Google, they get redirected to God knows where.

There are a lot of sites that have been hacked this way. I’m getting buried under a blizzard of spam Web form submissions advertising WordPress sites that have been hacked.

A partial list from the last few days includes:

http://www.thevisualexperience.org (the hack is only visible in Google if you do a search that includes pharmacy keywords; for example:
accutane site:http://www.thevisualexperience.org
http://www.fro2012.com
http://javajitterprint.com
http://www.grouna.com
http://www.nutria.com/ (This one isn’t using WordPress; it’s using a CMS called Website Gadget by an outfit called Firefly Digital, but it looks very WordPress-like. It may be a WordPress derivative or clone.)
http://www.info-kod.si/ (Also not using WordPress)
http://autofinancedfw.com (Also not using WordPress)
http://www.guylaramee.com/ (If visited from Google, redirects to http://www.pharmacymall.net/prozac_generic.php, hosted in the Ukraine)
http://sedrez.com/ (If visited from Google, redirects to http://goldenpharma24x7.com/order-topamax-online.html, hosted in the Ukraine)
http://www.joomx.com/ (a professional Joomla developer’s site–oops!–that has been hacked; if visited from Google, redirects to http://goldenpharma24x7.com/order-topamax-online.html
http://www.fremantlefishingboatharbour.com/ (Running Joomla; if visited from Google, redirects to http://goldenpharma24x7.com/)


Once again, if you are running a WordPress or Joomla site, it is absolutely essential that you keep on top of all security patches PROMPTLY and that you use very strong admin passwords.

With this hack, it’s likely that you could be hacked and never even know it–at least until Google starts flagging your site with a “This site may be compromised” tag.