Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-22-2014, 10:26 PM   #1
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
bunnylovemedia{at}gmail.com pornset.com hacked my site - who are these scumbags?

Anyone heard of bunny love media?
I opened my site and it redirects to pornset.com

[email protected]
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 10:41 PM   #2
XSAXS
Confirmed User
 
XSAXS's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Las Vegas
Posts: 652
Can't help you, but damn... This world is full of assholes, cunts, and cocksuckers.
XSAXS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 10:47 PM   #3
WDF
Confirmed User
 
WDF's Avatar
 
Industry Role:
Join Date: Jan 2013
Location: Nashville,TN. Music City U.S.A.
Posts: 2,248
Is the redirect at the registrar or the server?

Time to do a password audit.

Search the email on Google, 1 result: http://netcomber.com/pornmaxim.com

a quick search of pornset.com reveals SOA info for DNS as:

pornset.com SOA 1 day ns55.pornset.com. cicasouris.gmail.com. 2013101501 86400 7200 3600000 86400

Do a historical Domain search of that email and find an old not privacy protected domain registration maybe for countrypoll.com, see what comes back.
__________________
Please HELP

Last edited by WDF; 02-22-2014 at 11:00 PM..
WDF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 10:49 PM   #4
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
Quote:
Originally Posted by WDF View Post
Is the redirect at the registrar or the server?
Server. Found some malicious code inserted into files.
Interesting thing - server says last time those files were edited was June. And I have backup from September (clean files). Not sure how was that possible.
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 11:06 PM   #5
WDF
Confirmed User
 
WDF's Avatar
 
Industry Role:
Join Date: Jan 2013
Location: Nashville,TN. Music City U.S.A.
Posts: 2,248
Edited my first post with more info for you.

What platform is used for the site? Check for updates?

Are you using shared hosting? Vps or Dedi? cpanel? If VPS or Dedi and cPanel Mod_Security will help with injection attacks. CSF is a good plug in also.

Review your logs to see where it came from. Notify your host.
__________________
Please HELP

Last edited by WDF; 02-22-2014 at 11:09 PM..
WDF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 11:07 PM   #6
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
On this shared account I have 5 WP websites, all of those has some malicious shit injected in all the php files, BUT only 1 of them redirects. I have cleaned the files, but it did not help.

Where to look for redirect if only 1 of 5 sites are redirecting while all of them has malicious code?
htaccess is clean..

Last edited by mineistaken; 02-22-2014 at 11:08 PM..
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 11:10 PM   #7
WDF
Confirmed User
 
WDF's Avatar
 
Industry Role:
Join Date: Jan 2013
Location: Nashville,TN. Music City U.S.A.
Posts: 2,248
Check your db and theme files.
__________________
Please HELP
WDF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 11:14 PM   #8
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
Quote:
Originally Posted by WDF View Post
Check your db and theme files.
Theme files are clean as I restored everything from back up. Let's see database..
Although it is still strange that only 1 of 5 sites redirects, usually when it gets hacked all sites go down..
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 11:17 PM   #9
WDF
Confirmed User
 
WDF's Avatar
 
Industry Role:
Join Date: Jan 2013
Location: Nashville,TN. Music City U.S.A.
Posts: 2,248
You made certain index.php is clean?

Delete and upload new is uncertain.
__________________
Please HELP
WDF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 11:27 PM   #10
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
Quote:
Originally Posted by WDF View Post
You made certain index.php is clean?

Delete and upload new is uncertain.
100%. That's why it is strange. On top of only 1 of 5 sites being affected
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-22-2014, 11:34 PM   #11
WDF
Confirmed User
 
WDF's Avatar
 
Industry Role:
Join Date: Jan 2013
Location: Nashville,TN. Music City U.S.A.
Posts: 2,248
I have left a message for my partner to check this thread when he gets online. He has a little better head for current exploits then I do.

Check through the db. There is a number of site settings relating to domain in 2 tables that may result in a redirect. You can view it in word pad, download a current copy and search for the domain the site is redirecting to.

I will stay for a while longer and try to help but it is fairly late here.

Added:

You need to find the vulnerability and fix that as well.

Redirect the domain in cpanel to 1 of your other sites for now if need be.

Did you report the hack to your hosts support. It may be more then your sites that have been compromised.
__________________
Please HELP

Last edited by WDF; 02-22-2014 at 11:49 PM..
WDF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-23-2014, 08:48 AM   #12
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
Thanks for the help and advice
I cleaned it up, it was one of the embeds from 2009 (I think I sold blog post to the site back then) that started redirecting all the site in 2014
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-23-2014, 08:50 AM   #13
NEW XTC
Confirmed User
 
NEW XTC's Avatar
 
Join Date: Jun 2010
Posts: 738
WDF rocks...
__________________
Those who can make you believe absurdities can make you commit atrocities.

-Voltaire
NEW XTC is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-23-2014, 12:02 PM   #14
WDF
Confirmed User
 
WDF's Avatar
 
Industry Role:
Join Date: Jan 2013
Location: Nashville,TN. Music City U.S.A.
Posts: 2,248
Quote:
Originally Posted by mineistaken View Post
Thanks for the help and advice
I cleaned it up, it was one of the embeds from 2009 (I think I sold blog post to the site back then) that started redirecting all the site in 2014
No Problem, happy to help out when I can.

Quote:
Originally Posted by NEW XTC View Post
WDF rocks...
Thanks for the recognition
__________________
Please HELP
WDF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.