In the header of Matt Heaton’s blog, who is the CEO and President of Bluehost, Hostmonster, and Fastdomain, a script was found. In the Bluehost forum Jasonj75 describes how he found the script in the header of Matt Heaton’s blog, while searching for a new web hosting company. He found it by running Firefox with a plugin called NoScript. (BTW: Turning javascipt off in a browser performs the same function as NoScript in this case.) Jasonj75 asks, “What kind of google shenanigans are going on here and why on Earth is the CEO of a reputable company taking part?” Below is the text he found in the CEO’s header.
levitra tagging levitra size levitra viagra comparision levitra and premature ejaculation levitra vardenafil hci tablets levitra usage levitra vs cialis vs viagra levitra vs cialis vardenafil how to take it vardenafil dosage purchase vardenafil diabeties viagra cialis levitra levitra type pills levitra clinical data levitra online ordersibutramine buy meridia meridia diet pill meridia side effects generic meridia meridia diet drug meridia effectiveness meridia weight loss does meridia work meridia discount meridia weight loss drug no prescription meridia meridia weight loss drug law suits in canada meridia diet pills meridia and wellbutrin meridia prescription
Look how Heaton’s blog appeared to Jasonj75. Jasonj75 discovered, when he clicked on any of the words above, it would lead him to webreakstuff.com. (a web design firm)
Basil came to a similar discovery, “Google cache does *not* lie.” In Basil’s findings when clicking on any of the key words directed him to wildproxy.net. WildProxy is a hosted proxy service.
Ok, I have something very weird going on here. In Opera I see this when clicking a key word. In Galeon, Firefox, Seamonkey, and Konqueror, I view something completely different clicking on the same key word all using Linux. On a Windows 2000 PC, I found this on Seamonkey. And once again I find something completely different with Firefox, Opera, and Flock clicking on the same key word. So what is going on here? What does anyone else see when clicking on the link? Please state your browser and operating system. What does anyone else come up with on brainware-india.com?
So why is Matt Heaton pimpin meds like Cialis, Viagra, and Levitra in the header of his blog?
So Matt Heaton what exactly do you have going on here?
Citation: Source code found in the header for webreakstuff, wildproxy, and brainware-india all in .txt format.
It appears the powers to be at Bluehost forum are under taking damage control by deleting the thread “What’s up w/ the CEO blog?”
CP
I would love to tell you who I am but then as an insider I will get fired. So now you can post this or not I do not care. I noticed that you have several things that bother you about Bluehost.com / Hostmonster.com / FastDomain.com simply put these are all owned by Matt Heaton and the Boys. Okay now for the juicy part; His blog gets hacked from time to time because they lack the know how to stop hackers (so much for security) and this is not limited to his blog but also the client servers. Proof: look around and someday will find people who were hacked on a Bluehost.com server (it was a root level attack that removed all index pages, what backups they did have and all log files.) and if I had the box number handy I would tell you so you can verify it. The only thing in between the client servers and the WWW is a CISCO 6900 router and IP tables on the boxes. BUT, I would not worry about that but the lack of skills in the level 3 area as they have full root access to the box and most don’t know crap about linux.
I will come back sometime and fill you all in with great detail and I do mean Great! as it will show the attitude of the Bluehost.com / Hostmonster.com / FastDomain.com employees, admins and the worst part of it the management and owners.
Enjoy, for now.
Sorry@sorry.com
THe supposed insider. Has no clue I have worked at blue host for over 2 years. We have only had 1 incident in which are servers had a root level hack and it was committed by a ADMIN who we fired. It was a revenge attack. Peoples sites get hacked all the time on our network and other hosts. It si common if dip shits are not using the proper security or updated scripts. Our servers are very secure. So to the insider you are a fucking idiot and don’t know shit about what you are talking about. if you are an employee here I hope it is not for much longer. You are a stupid idiot who makes are ocmp[any look bad id this is your level of intelligence. Yes matt’s blog ahs ben hacked before it is because he does not have the time to update is wordpress. It is not because of weak or insecure servers. SO you are a fucking idiot and I hope you are no longer employed by us because you are sop fucking dumb you would have us lose customers with your lack of true knowledge. You are amazingly fucking stupid. All the level 3′s here are required to take a very extensive linux test. You must be mad because you fucking failed it. You are a fucking asswipe.
It is interesting “Me another isnider” ip (74.220.195.115) leads back to office.bluehost.com so I am regarding this as an “official statement” from Bluehost’s technical support.
The above comment is another reason to avoid Bluehost. The language of the individual is not only highly unprofessional but is extremely derogatory.
Doesn’t it just give you warm fuzzies knowing a person like this is looking after your best interests concerning your web hosting account at Bluehost?
What a great advertisement for Bluehost when a Bluehost representative refers to Bluehost clients as “dip shits“?
Bluehost fails once again to provide decent customer service.