GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Fuck - Server corrupted - Search Results from Google redirects... (https://gfy.com/showthread.php?t=1016218)

MaDalton 03-29-2011 10:57 AM

Fuck - Server corrupted - Search Results from Google redirects...
 
question: how often do you click on the google search results for your own sites?

was made aware of this today and would have never noticed this myself:

if i go to www.fourstrokeentertainment.com directly nothing bad happens

but if i click on the search result in google i got redirected to some nasty polish URL which i won't post here for your security

any way i can automatically check my sites regularly?

fuckers.

Agent 488 03-29-2011 11:00 AM

happened to me back in the day with my wordpress sites. interesting to check the url of that polish site in alexa.

MaDalton 03-29-2011 11:03 AM

http://www.alexa.com/siteinfo/osa.pl#

k0nr4d 03-29-2011 11:20 AM

you sure its not on your end? I just googled you and went in and its fine..

SZNY 03-29-2011 11:37 AM

Same here it works perfect, just land on your domain. Maybe its something with the computer you working with (virus)

Si 03-29-2011 11:41 AM

Quote:

Originally Posted by SZNY (Post 18012178)
Same here it works perfect, just land on your domain. Maybe its something with the computer you working with (virus)

:thumbsup

There is a malware going round that fucks google searches up and redirects them to some random shit.

Could be that.

SZNY 03-29-2011 11:49 AM

Quote:

Originally Posted by Si (Post 18012204)
:thumbsup

There is a malware going round that fucks google searches up and redirects them to some random shit.

Could be that.

server or client sided?

directfiesta 03-29-2011 12:01 PM

Quote:

Originally Posted by Si (Post 18012204)
:thumbsup

There is a malware going round that fucks google searches up and redirects them to some random shit.

Could be that.

Exactly, I have that on my netbook ... Goes to other search results/pages, sometimes something like Zagonga ( or similar ) .
Reformat was to be done anyway ....

pristine 03-29-2011 12:08 PM

if you get malware then you're retarded and shouldn't be using a computer to begin with

DangerX !!! 03-29-2011 12:32 PM

Perhaps htaccess settings?

nation-x 03-29-2011 12:45 PM

Your machine has been infected with a rootkit like TDSS.

http://threatinfo.trendmicro.com/vin...11209-TDSS.xml

Klen 03-29-2011 12:51 PM

Use http://www.stopthehacker.com/ .I was one of the contributors :)

DangerX !!! 03-29-2011 12:55 PM

Quote:

Originally Posted by MaDalton (Post 18012023)
question: how often do you click on the google search results for your own sites?

was made aware of this today and would have never noticed this myself:

if i go to www.fourstrokeentertainment.com directly nothing bad happens

but if i click on the search result in google i got redirected to some nasty polish URL which i won't post here for your security

any way i can automatically check my sites regularly?

fuckers.

From curiosity, which OS do you use and which anti-virus?

MaDalton 03-29-2011 01:18 PM

Quote:

Originally Posted by k0nr4d (Post 18012119)
you sure its not on your end? I just googled you and went in and its fine..

Quote:

Originally Posted by SZNY (Post 18012178)
Same here it works perfect, just land on your domain. Maybe its something with the computer you working with (virus)


hosting company had already fixed it before i posted here - seems related to phpmyadmin



Quote:

Originally Posted by pristine (Post 18012297)
if you get malware then you're retarded and shouldn't be using a computer to begin with

read above, then go fuck yourself, asshat

rogueteens 03-29-2011 01:24 PM

Quote:

Originally Posted by MaDalton (Post 18012496)
hosting company had already fixed it before i posted here - seems related to phpmyadmin

So, was it a hack?

MaDalton 03-29-2011 01:36 PM

Quote:

Originally Posted by KlenTelaris (Post 18012370)
Use http://www.stopthehacker.com/ .I was one of the contributors :)

interesting, gonna check this out


Quote:

Originally Posted by rogueteens (Post 18012520)
So, was it a hack?

yes, gotta find out what exactly - they just said it's fixed - which it is

directfiesta 03-29-2011 01:53 PM

Quote:

Originally Posted by MaDalton (Post 18012569)
interesting, gonna check this out




yes, gotta find out what exactly - they just said it's fixed - which it is

probably a mysql injection ...

SmokeyTheBear 03-29-2011 01:54 PM

i cleaned someones server recently that had this sort of hack. not only was it redirecting google searchers but it setup a whole series of doorway pages that would surely get your domain banned in google

seeandsee 03-29-2011 01:59 PM

can be malware on your pc redirecting your SE traffic

MaDalton 03-29-2011 02:02 PM

Quote:

Originally Posted by seeandsee (Post 18012614)
can be malware on your pc redirecting your SE traffic

you need to read before you post

AdultKing 03-29-2011 02:03 PM

We have been testing for several common compromises on actual sites during our web crawling efforts for our search engine. A staggering 5% of all sites we crawl have had problems with injections, redirects, poorly constructed permissions leaving directories open and most commonly fully search-able directory structures.

The number of insecure sites is staggering.

MaDalton 03-29-2011 02:26 PM

Quote:

Originally Posted by AdultKing (Post 18012625)
We have been testing for several common compromises on actual sites during our web crawling efforts for our search engine. A staggering 5% of all sites we crawl have had problems with injections, redirects, poorly constructed permissions leaving directories open and most commonly fully search-able directory structures.

The number of insecure sites is staggering.

actually i would think 5% is a very low number - lol

but it's almost a full time job if you have more than one website

MaDalton 03-29-2011 02:34 PM

ok, it was wordpress, nothing serious was harmed, just my traffic :-/

you better check your sites too from time to time

pimpware 03-29-2011 02:56 PM

I got something like that yesterday.

crazy queries from google linking to folders that didn't exist on my website(redirecting). Nonsense text and pics.

It was a php and htaccess injection attack.

Removed all php files and disabled htaccess and even today I'm getting traffic from that crazy queries coming from google. I wonder how this will screw my indexed files and rankings, hope google "think" and "be smart" enough to not fuck my stuff.

MaDalton 03-29-2011 02:59 PM

Quote:

Originally Posted by pimpware (Post 18012739)
I got something like that yesterday.

crazy queries from google linking to folders that didn't exist on my website(redirecting). Nonsense text and pics.

It was a php and htaccess injection attack.

Removed all php files and disabled htaccess and even today I'm getting traffic from that crazy queries coming from google. I wonder how this will screw my indexed files and rankings, hope google "think" and "be smart" enough to not fuck my stuff.


all my model blogs link to that site and i lost 90% of my traffic since last weekend. if this was the cause it seriously blows :(

pimpware 03-29-2011 03:06 PM

Quote:

Originally Posted by MaDalton (Post 18012746)
all my model blogs link to that site and i lost 90% of my traffic since last weekend. if this was the cause it seriously blows :(

From all my blogs and adult websites the one hacked was one from mainstream :Oh crap and in portuguese language, all those queries are in english so if I'm lucky google will "understand" that was not my fault ... fuck i'm pissed with this :mad:

pimpware 03-29-2011 03:18 PM

Oh crap, can be a coincidence but some specific keywords that were giving me the first places on google (those with a map) I had almost always the letter A B or C, now it's almost gone :Oh crap:Oh crap:mad:

alias 03-29-2011 03:34 PM

Google webmaster tools is pretty good at finding those problems and emailing you, just verify the site in question and adjust settings.

MaDalton 03-29-2011 03:54 PM

Quote:

Originally Posted by alias (Post 18012817)
Google webmaster tools is pretty good at finding those problems and emailing you, just verify the site in question and adjust settings.

yeah, working on that

rogueteens 03-29-2011 04:14 PM

What should i check for to see if i'm infected or not?

pimpware 03-29-2011 04:20 PM

Quote:

Originally Posted by rogueteens (Post 18012936)
What should i check for to see if i'm infected or not?

htaccess file or your stats, look for nonsense queries coming from google :2 cents: and check some new folder you didn't create ... full of crap

MaDalton 03-29-2011 04:35 PM

Quote:

Originally Posted by rogueteens (Post 18012936)
What should i check for to see if i'm infected or not?

just search for your generic URL on Google and then click on the search result. if it doesnt go to your site you have a problem. typing the url in the browser won't do it - thats the tricky thing here

edit: you can also look at your stats, you would see a massive drop in search engine traffic

now that i checked i would say i have that problem since last year october

http://www.isaleporn.com/pix/SE.jpg

429mg 03-29-2011 04:41 PM

@MaDalton: are you using the I Love Social Bookmarks plugin for WP?

Supz 03-29-2011 04:46 PM

Could be something on your computer.

MaDalton 03-29-2011 04:48 PM

Quote:

Originally Posted by 429mg (Post 18013040)
@MaDalton: are you using the I Love Social Bookmarks plugin for WP?

no, i dont

Pushcube 03-29-2011 05:12 PM

It's a XSS exploit. It's simple to fix so don't panic :)

If you have access to your .htaccess file add the following to prevent it happening:

Code:

RewriteCond %{QUERY_STRING} base64_encode.*(.*) [NC,OR]
RewriteRule ^(.*)$ ? [F,L]

If you have SSH you can hunt down modified files by:

Code:

grep -r "eval(base64_decode" *
I don't think I should post the infection PHP code here(obviously), but it will appear at the top of all the modified files, you will know it when you see it. Something like this:

PHP Code:

eval(base64_decode("ZXJyb3JfcmVwb3J0aW5nKDApOw0KJG5jY3Y9aGVhZGVyc19zZW50KCk7DQppZiAoISRuY2N2KXsNCiRyZWZlcmVyPSRfU0VSVkVSWydIVFRQX1JFRkVSRVInXTsNCiR1YT0kX1NFUlZFUlsnSFRUUF9VU0VSX0FHRU5UJ107DQblahblahblahblahblahblah etc et etc etc")); 

I'd also update to the latest version of PHP on your server(s) if you haven't already. Hope this helps :)

MaDalton 03-29-2011 05:24 PM

Quote:

Originally Posted by Pushcube (Post 18013099)
It's a XSS exploit. It's simple to fix so don't panic :)

If you have access to your .htaccess file add the following to prevent it happening:

Code:

RewriteCond %{QUERY_STRING} base64_encode.*(.*) [NC,OR]
RewriteRule ^(.*)$ ? [F,L]

If you have SSH you can hunt down modified files by:

Code:

grep -r "eval(base64_decode" *
I don't think I should post the infection PHP code here(obviously), but it will appear at the top of all the modified files, you will know it when you see it. Something like this:

PHP Code:

eval(base64_decode("ZXJyb3JfcmVwb3J0aW5nKDApOw0KJG5jY3Y9aGVhZGVyc19zZW50KCk7DQppZiAoISRuY2N2KXsNCiRyZWZlcmVyPSRfU0VSVkVSWydIVFRQX1JFRkVSRVInXTsNCiR1YT0kX1NFUlZFUlsnSFRUUF9VU0VSX0FHRU5UJ107DQblahblahblahblahblahblah etc et etc etc")); 

I'd also update to the latest version of PHP on your server(s) if you haven't already. Hope this helps :)

thanks a lot :thumbsup

valuable info instead of insults or ignorance, who would have thought :winkwink:

AdultKing 03-29-2011 08:20 PM

Quote:

Originally Posted by MaDalton (Post 18012686)
actually i would think 5% is a very low number - lol

but it's almost a full time job if you have more than one website

5% of the number of websites we have fully crawled is a very very very big number lol, they say space is really really big (according to Douglas Adams), well so is the web!

I have no idea what the standard ratio of infected sites is on the web, however we are learning alot from our crawling efforts and it's interesting to see the stats and patterns that emerge when undertaking such a project.

I hope you get your problems sorted out quickly, just take comfort in that most of these attacks are completely automated by the attackers and if anything it helps you make your sites even more secure than before.


All times are GMT -7. The time now is 05:29 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123