GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   bunnylovemedia{at}gmail.com pornset.com hacked my site - who are these scumbags? (https://gfy.com/showthread.php?t=1134239)

mineistaken 02-22-2014 10:26 PM

bunnylovemedia{at}gmail.com pornset.com hacked my site - who are these scumbags?
 
Anyone heard of bunny love media?
I opened my site and it redirects to pornset.com :mad:

[email protected]

XSAXS 02-22-2014 10:41 PM

Can't help you, but damn... This world is full of assholes, cunts, and cocksuckers.

WDF 02-22-2014 10:47 PM

Is the redirect at the registrar or the server?

Time to do a password audit.

Search the email on Google, 1 result: http://netcomber.com/pornmaxim.com

a quick search of pornset.com reveals SOA info for DNS as:

pornset.com SOA 1 day ns55.pornset.com. cicasouris.gmail.com. 2013101501 86400 7200 3600000 86400

Do a historical Domain search of that email and find an old not privacy protected domain registration maybe for countrypoll.com, see what comes back.

mineistaken 02-22-2014 10:49 PM

Quote:

Originally Posted by WDF (Post 19992563)
Is the redirect at the registrar or the server?

Server. Found some malicious code inserted into files.
Interesting thing - server says last time those files were edited was June. And I have backup from September (clean files). Not sure how was that possible.

WDF 02-22-2014 11:06 PM

Edited my first post with more info for you.

What platform is used for the site? Check for updates?

Are you using shared hosting? Vps or Dedi? cpanel? If VPS or Dedi and cPanel Mod_Security will help with injection attacks. CSF is a good plug in also.

Review your logs to see where it came from. Notify your host.

mineistaken 02-22-2014 11:07 PM

On this shared account I have 5 WP websites, all of those has some malicious shit injected in all the php files, BUT only 1 of them redirects. I have cleaned the files, but it did not help.

Where to look for redirect if only 1 of 5 sites are redirecting while all of them has malicious code?
htaccess is clean..

WDF 02-22-2014 11:10 PM

Check your db and theme files.

mineistaken 02-22-2014 11:14 PM

Quote:

Originally Posted by WDF (Post 19992585)
Check your db and theme files.

Theme files are clean as I restored everything from back up. Let's see database..
Although it is still strange that only 1 of 5 sites redirects, usually when it gets hacked all sites go down..

WDF 02-22-2014 11:17 PM

You made certain index.php is clean?

Delete and upload new is uncertain.

mineistaken 02-22-2014 11:27 PM

Quote:

Originally Posted by WDF (Post 19992589)
You made certain index.php is clean?

Delete and upload new is uncertain.

100%. That's why it is strange. On top of only 1 of 5 sites being affected :)

WDF 02-22-2014 11:34 PM

I have left a message for my partner to check this thread when he gets online. He has a little better head for current exploits then I do.

Check through the db. There is a number of site settings relating to domain in 2 tables that may result in a redirect. You can view it in word pad, download a current copy and search for the domain the site is redirecting to.

I will stay for a while longer and try to help but it is fairly late here.

Added:

You need to find the vulnerability and fix that as well.

Redirect the domain in cpanel to 1 of your other sites for now if need be.

Did you report the hack to your hosts support. It may be more then your sites that have been compromised.

mineistaken 02-23-2014 08:48 AM

Thanks for the help and advice :thumbsup
I cleaned it up, it was one of the embeds from 2009 (I think I sold blog post to the site back then) that started redirecting all the site in 2014 :Oh crap

NEW XTC 02-23-2014 08:50 AM

WDF rocks...

WDF 02-23-2014 12:02 PM

Quote:

Originally Posted by mineistaken (Post 19992911)
Thanks for the help and advice :thumbsup
I cleaned it up, it was one of the embeds from 2009 (I think I sold blog post to the site back then) that started redirecting all the site in 2014 :Oh crap

No Problem, happy to help out when I can.

Quote:

Originally Posted by NEW XTC (Post 19992913)
WDF rocks...

Thanks for the recognition:thumbsup:)


All times are GMT -7. The time now is 09:51 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123