It's official, the new hacking trend is targeting social networking sites more than ever (from Facebook to LJ). Thing is, they are not just taking your password and spamming your flist, especially with LJ, they use it to take over your flist's journals also by whatever means possible.
I've been seeing this stuff crop up more and more, and since it's a little scary (especially for those who have a lot more than fics/art/other stuff on their LJ) decided to warn the lovely flist. Though you may have already heard of this from other LJ users.
So here's some information I've ran across in the past couple of months since the first bot friended me:
* If you get friended by a journal in Cyrillic only that seems to have links and random pictures or was recently created, don't respond or add. Report to LJ Abuse immediately and they'll deal with it.
o I've done this a couple of times and most of the journals are suspended within a week
o I've linked to some great posts by [info]nympholept before. She has more information on the bots and how to avoid them
* If you have or had a Hotmail address (that you used to start up LJ) sign in to it and make sure you still have full control of it. (By the way, don't delete your old Hotmail addresses, they recycle them and hackers can use them to fool LJ's servers into letting them through).
o Check LJ's Email Management and delete your old email addresses.
o If you have problems with this, check out this wonderful post by [info]wistfuljane on how to bypass that.
* One of the scariest aspects of this hack system is that they can easily take over any communities you moderate/maintain and spam them too.
o The worst thing is that these hackers seem to prefer completely emptying out your journal and community entries (see [info]shoebox_project's warning about that).
o Then they post an entry that links to a key-logging site while posing as you. This seems to be the most common way of getting to your flist and hacking their journals.
o Here's an example by [info]upstart_crow who was affected.
o Make sure to report any hacking. Additionally, if you moderate any communities or you are listed as a maintainer make sure to notify any co-mods and have them remove you as co-mod. Also try and warn members to avoid clicking any links (especially those that link to a so-called "new archive").
* Do you have a security question? No? That's dangerous.
o Enable Security Questions as this may put off your hacker or keep them out of your journal when you attempt to retake it.
* BACK UP YOUR LJ!!
o I'm guilty of not doing this, it's a bother, but it's worth it. I'd hate to lose all my work because I got hacked.
SINCE I'M NOT AN EXPERT, BY ANY MEANING OF THE WORD, HERE'S SOME MORE LINKS BY PEOPLE WHO'VE POSTED ABOUT THIS AND HAVE BEEN AFFECTED.
* [info]copperbadge was affected and has a great set of posts on this.
* One of the most informative posts is by [info]acari , definitely check it out as she seems more coherent than I am
Also, please remember that they are not LJ staff and don't have all the answers.
CONTACT LJ ABUSE AND TECH SUPPORT, HECK EVEN GOOGLE FOR MORE INFORMATION.
REMEMBER TO RUN YOUR SPY DETECTION AND ANTIVIRUS SOFTWARE ON THE REGULAR TO MAKE SURE YOU HAVEN'T BEEN INFECTED.
CAPS LOCK OUT.
Sidenote: Yahoo had a recent article about the Facebook hacks if you're interested.
ETA: LJ has a comprehensive FAQ sheet if you've been hacked, refer to this if you suspect you've been a victim.