Hacked? Who/whom? – btclush

  • Unknown's avatar

    Hi. While googling (for something else), I found out that beside “kutukamus.wordpress.com ” (my blog), there is also
    kutukamus.btclush.com (mirror site? whose?)
    Curious, I tried
    wpbtips.btclush.com
    1tess.btclush.com
    Yep, both exist. The loading time is considerably longer, though—for the btclush version transfers data from wordpress first. Any idea?
    Thanks.

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar

    Hi there, the good news is you weren’t exactly hacked. WordPress.com has really good security.

    What you’re seeing is what’s sometimes called “scraper sites.” These are sites often setup by spammers and other undesirables that just setup some site somewhere and steal the content from another site wholesale.

    These sites exist outside of WordPress.com so WordPress has no control over them. Here’s a support article with some tips on how to handle situations like this.

    http://en.support.wordpress.com/content-theft-what-to-do/

  • Unknown's avatar

    Hi stothek, thanks for the response. What I’m trying to say is:

    “They redirect (kind of), every click of the way”

    Say, you have: “stothek.wordpress.com”
    Now try: “stothek.btclush.com”

    Since it’s just reading the data from wordpress, the btclush one has all your latest update (posts, comments etc), every click of the way.

    And since the data is still on the wordpress’s servers, the way I see it, the real victim is wordpress, more than us users.

  • Unknown's avatar

    Yes, I see what you’re saying now. Basically, it’s just a generic redirect kind of thing, there’s not actually any content on there at all, it’s just showing the original stuff from WordPress.com

    The site seems to not be doing anything else, but it seems like a perfect vector for malicious software.

    The domain shows it’s registered at Namesilo.com and the abuse address is (email visible only to moderators and staff)

  • Unknown's avatar

    Thanks for the heads up. We’ll look into it.

  • Unknown's avatar

    @lizthefair
    Hi there,
    I found this thread this morning and tagged it for Staff intervention. Thanks for looking into this for kutukamus.

  • Unknown's avatar

    If we upgrade to WP Enterprise service, there is available Frame Buster plugin.
    If I type in the browser directly (eg simomot.btclush.com), so will appear the “simomot.btclush.com”. But when people are clicking on any link (post or category) that I put in simomot.com, the page that opens is the original page of simomot; the redirect function of btclush does not work.
    It’s different if you do not use the Frame Buster plugin, all the pages of your blog continue to appear in the iframe btclush.com.

  • Unknown's avatar
  • Unknown's avatar

    @duto
    There are more than one way to evade the btclush redirection (it can be done even without some paying WP version) but I guess that’s not the point here. The idea is:

    Should we let it be?
    (and/or let whoever did it get away with this?)

    And, if the answer is no, what are we going to do about it?

  • Unknown's avatar

    One reason these sites exist is to circumvent censorship, eg the Great Firewall of China. Something to consider.

    Of course, if they have ads on them, rip out their colon and show it to them as they die slowly. Here are instructions:

    What to Do When Someone Steals Your Stuff

    I have made grown men cry with this completely legal, easy technique.

  • Unknown's avatar
  • Unknown's avatar

    Hi, I have the same problem with my blog (jumbleskine.com)! ;(

  • Unknown's avatar

    We are aware of this issue and are investigating. Thanks for the reports.

  • Unknown's avatar

    Just to let you know I’m having the same problem. Everything on my WordPress blog (endlesserring.wordpress.com) is also mirrored on endlesserring.btclush.com. How can I remove the btclush site?

  • Unknown's avatar

    Same with me :'( I’m encountering this same situation with my blog (friendiary.wordpress.com) Good thing I found this thread and seems like the staffs are investigating it.

  • Unknown's avatar

    my blog has it too but there is one good thing out of this for the bloggers. Exposure. If the words they stole, like mine are not too important to you than it’s a way for more people to see your blog. Granted this is not the way I would prefer and I do hope WordPress takes care of it as they are very much stealing wordpress. Still I’m on the fence about if I care deeply about it.

  • The topic ‘Hacked? Who/whom? – btclush’ is closed to new replies.