Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 03-29-2011, 10:57 AM   #1
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
:mad Fuck - Server corrupted - Search Results from Google redirects...

question: how often do you click on the google search results for your own sites?

was made aware of this today and would have never noticed this myself:

if i go to www.fourstrokeentertainment.com directly nothing bad happens

but if i click on the search result in google i got redirected to some nasty polish URL which i won't post here for your security

any way i can automatically check my sites regularly?

fuckers.
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 11:00 AM   #2
Agent 488
Registered User
 
Industry Role:
Join Date: Feb 2006
Posts: 22,511
happened to me back in the day with my wordpress sites. interesting to check the url of that polish site in alexa.
Agent 488 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 11:03 AM   #3
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
http://www.alexa.com/siteinfo/osa.pl#
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 11:20 AM   #4
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
you sure its not on your end? I just googled you and went in and its fine..
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 11:37 AM   #5
SZNY
SZNY
 
SZNY's Avatar
 
Industry Role:
Join Date: May 2004
Location: Sexy Republic
Posts: 2,800
Same here it works perfect, just land on your domain. Maybe its something with the computer you working with (virus)
__________________
Telegram: sandroanthonio
SZNY is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 11:41 AM   #6
Si
Such Fun!
 
Industry Role:
Join Date: Feb 2008
Posts: 13,900
Quote:
Originally Posted by SZNY View Post
Same here it works perfect, just land on your domain. Maybe its something with the computer you working with (virus)


There is a malware going round that fucks google searches up and redirects them to some random shit.

Could be that.
Si is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 11:49 AM   #7
SZNY
SZNY
 
SZNY's Avatar
 
Industry Role:
Join Date: May 2004
Location: Sexy Republic
Posts: 2,800
Quote:
Originally Posted by Si View Post


There is a malware going round that fucks google searches up and redirects them to some random shit.

Could be that.
server or client sided?
__________________
Telegram: sandroanthonio
SZNY is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 12:01 PM   #8
directfiesta
Too lazy to set a custom title
 
directfiesta's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,590
Quote:
Originally Posted by Si View Post


There is a malware going round that fucks google searches up and redirects them to some random shit.

Could be that.
Exactly, I have that on my netbook ... Goes to other search results/pages, sometimes something like Zagonga ( or similar ) .
Reformat was to be done anyway ....
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT !

But I can't figure out how he can breathe or type , at the same time ....
directfiesta is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 12:08 PM   #9
pristine
So Fucking Banned
 
Industry Role:
Join Date: Dec 2010
Posts: 1,176
if you get malware then you're retarded and shouldn't be using a computer to begin with
pristine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 12:32 PM   #10
DangerX !!!
Confirmed User
 
DangerX !!!'s Avatar
 
Industry Role:
Join Date: Feb 2011
Location: La Isla Bonita Power Level: ❤❤❤❤❤❤❤❤❤❤
Posts: 886
Perhaps htaccess settings?
__________________
This is sig area!
DangerX !!! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 12:45 PM   #11
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
Your machine has been infected with a rootkit like TDSS.

http://threatinfo.trendmicro.com/vin...11209-TDSS.xml
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 12:51 PM   #12
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Use http://www.stopthehacker.com/ .I was one of the contributors
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 12:55 PM   #13
DangerX !!!
Confirmed User
 
DangerX !!!'s Avatar
 
Industry Role:
Join Date: Feb 2011
Location: La Isla Bonita Power Level: ❤❤❤❤❤❤❤❤❤❤
Posts: 886
Quote:
Originally Posted by MaDalton View Post
question: how often do you click on the google search results for your own sites?

was made aware of this today and would have never noticed this myself:

if i go to www.fourstrokeentertainment.com directly nothing bad happens

but if i click on the search result in google i got redirected to some nasty polish URL which i won't post here for your security

any way i can automatically check my sites regularly?

fuckers.
From curiosity, which OS do you use and which anti-virus?
__________________
This is sig area!
DangerX !!! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 01:18 PM   #14
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by k0nr4d View Post
you sure its not on your end? I just googled you and went in and its fine..
Quote:
Originally Posted by SZNY View Post
Same here it works perfect, just land on your domain. Maybe its something with the computer you working with (virus)

hosting company had already fixed it before i posted here - seems related to phpmyadmin



Quote:
Originally Posted by pristine View Post
if you get malware then you're retarded and shouldn't be using a computer to begin with
read above, then go fuck yourself, asshat
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 01:24 PM   #15
rogueteens
So fucking bland
 
rogueteens's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: England
Posts: 8,005
Quote:
Originally Posted by MaDalton View Post
hosting company had already fixed it before i posted here - seems related to phpmyadmin
So, was it a hack?
__________________
Free traffic and backlinks from one of the fastest growing adult pinsites on the net - SAUCY PICTURES!
Easily my best performing webcam sponsor - CLICK HERE!!
rogueteens is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 01:36 PM   #16
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by KlenTelaris View Post
Use http://www.stopthehacker.com/ .I was one of the contributors
interesting, gonna check this out


Quote:
Originally Posted by rogueteens View Post
So, was it a hack?
yes, gotta find out what exactly - they just said it's fixed - which it is
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 01:53 PM   #17
directfiesta
Too lazy to set a custom title
 
directfiesta's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,590
Quote:
Originally Posted by MaDalton View Post
interesting, gonna check this out




yes, gotta find out what exactly - they just said it's fixed - which it is
probably a mysql injection ...
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT !

But I can't figure out how he can breathe or type , at the same time ....
directfiesta is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 01:54 PM   #18
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
i cleaned someones server recently that had this sort of hack. not only was it redirecting google searchers but it setup a whole series of doorway pages that would surely get your domain banned in google
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 01:59 PM   #19
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
can be malware on your pc redirecting your SE traffic
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 02:02 PM   #20
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by seeandsee View Post
can be malware on your pc redirecting your SE traffic
you need to read before you post
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 02:03 PM   #21
AdultKing
Raise Your Weapon
 
AdultKing's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Outback Australia
Posts: 15,601
We have been testing for several common compromises on actual sites during our web crawling efforts for our search engine. A staggering 5% of all sites we crawl have had problems with injections, redirects, poorly constructed permissions leaving directories open and most commonly fully search-able directory structures.

The number of insecure sites is staggering.
AdultKing is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 02:26 PM   #22
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by AdultKing View Post
We have been testing for several common compromises on actual sites during our web crawling efforts for our search engine. A staggering 5% of all sites we crawl have had problems with injections, redirects, poorly constructed permissions leaving directories open and most commonly fully search-able directory structures.

The number of insecure sites is staggering.
actually i would think 5% is a very low number - lol

but it's almost a full time job if you have more than one website
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 02:34 PM   #23
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
ok, it was wordpress, nothing serious was harmed, just my traffic :-/

you better check your sites too from time to time
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 02:56 PM   #24
pimpware
Confirmed User
 
pimpware's Avatar
 
Join Date: Jan 2006
Location: Pt
Posts: 1,673
I got something like that yesterday.

crazy queries from google linking to folders that didn't exist on my website(redirecting). Nonsense text and pics.

It was a php and htaccess injection attack.

Removed all php files and disabled htaccess and even today I'm getting traffic from that crazy queries coming from google. I wonder how this will screw my indexed files and rankings, hope google "think" and "be smart" enough to not fuck my stuff.
__________________
icq: 284494832
realsexforyou.com
pimpware is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 02:59 PM   #25
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by pimpware View Post
I got something like that yesterday.

crazy queries from google linking to folders that didn't exist on my website(redirecting). Nonsense text and pics.

It was a php and htaccess injection attack.

Removed all php files and disabled htaccess and even today I'm getting traffic from that crazy queries coming from google. I wonder how this will screw my indexed files and rankings, hope google "think" and "be smart" enough to not fuck my stuff.

all my model blogs link to that site and i lost 90% of my traffic since last weekend. if this was the cause it seriously blows
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 03:06 PM   #26
pimpware
Confirmed User
 
pimpware's Avatar
 
Join Date: Jan 2006
Location: Pt
Posts: 1,673
Quote:
Originally Posted by MaDalton View Post
all my model blogs link to that site and i lost 90% of my traffic since last weekend. if this was the cause it seriously blows
From all my blogs and adult websites the one hacked was one from mainstream and in portuguese language, all those queries are in english so if I'm lucky google will "understand" that was not my fault ... fuck i'm pissed with this
__________________
icq: 284494832
realsexforyou.com
pimpware is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 03:18 PM   #27
pimpware
Confirmed User
 
pimpware's Avatar
 
Join Date: Jan 2006
Location: Pt
Posts: 1,673
Oh crap, can be a coincidence but some specific keywords that were giving me the first places on google (those with a map) I had almost always the letter A B or C, now it's almost gone
__________________
icq: 284494832
realsexforyou.com
pimpware is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 03:34 PM   #28
alias
aliasx
 
alias's Avatar
 
Join Date: Apr 2001
Posts: 19,010
Google webmaster tools is pretty good at finding those problems and emailing you, just verify the site in question and adjust settings.
__________________
https://porncorporation.com
alias is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 03:54 PM   #29
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by alias View Post
Google webmaster tools is pretty good at finding those problems and emailing you, just verify the site in question and adjust settings.
yeah, working on that
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 04:14 PM   #30
rogueteens
So fucking bland
 
rogueteens's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: England
Posts: 8,005
What should i check for to see if i'm infected or not?
__________________
Free traffic and backlinks from one of the fastest growing adult pinsites on the net - SAUCY PICTURES!
Easily my best performing webcam sponsor - CLICK HERE!!
rogueteens is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 04:20 PM   #31
pimpware
Confirmed User
 
pimpware's Avatar
 
Join Date: Jan 2006
Location: Pt
Posts: 1,673
Quote:
Originally Posted by rogueteens View Post
What should i check for to see if i'm infected or not?
htaccess file or your stats, look for nonsense queries coming from google and check some new folder you didn't create ... full of crap
__________________
icq: 284494832
realsexforyou.com
pimpware is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 04:35 PM   #32
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by rogueteens View Post
What should i check for to see if i'm infected or not?
just search for your generic URL on Google and then click on the search result. if it doesnt go to your site you have a problem. typing the url in the browser won't do it - thats the tricky thing here

edit: you can also look at your stats, you would see a massive drop in search engine traffic

now that i checked i would say i have that problem since last year october


Last edited by MaDalton; 03-29-2011 at 04:40 PM..
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 04:41 PM   #33
429mg
Confirmed User
 
429mg's Avatar
 
Industry Role:
Join Date: Jul 2010
Location: Rotterdam
Posts: 151
@MaDalton: are you using the I Love Social Bookmarks plugin for WP?
__________________
Got a gay blog? Submit your posts to Male Sharing
429mg is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 04:46 PM   #34
Supz
Arthur Flegenheimer
 
Supz's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: New York City
Posts: 11,056
Could be something on your computer.
Supz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 04:48 PM   #35
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by 429mg View Post
@MaDalton: are you using the I Love Social Bookmarks plugin for WP?
no, i dont
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 05:12 PM   #36
Pushcube
Registered User
 
Pushcube's Avatar
 
Industry Role:
Join Date: Dec 2007
Location: Ireland
Posts: 54
It's a XSS exploit. It's simple to fix so don't panic

If you have access to your .htaccess file add the following to prevent it happening:

Code:
RewriteCond %{QUERY_STRING} base64_encode.*(.*) [NC,OR]
RewriteRule ^(.*)$ ? [F,L]
If you have SSH you can hunt down modified files by:

Code:
grep -r "eval(base64_decode" *
I don't think I should post the infection PHP code here(obviously), but it will appear at the top of all the modified files, you will know it when you see it. Something like this:

PHP Code:
eval(base64_decode("ZXJyb3JfcmVwb3J0aW5nKDApOw0KJG5jY3Y9aGVhZGVyc19zZW50KCk7DQppZiAoISRuY2N2KXsNCiRyZWZlcmVyPSRfU0VSVkVSWydIVFRQX1JFRkVSRVInXTsNCiR1YT0kX1NFUlZFUlsnSFRUUF9VU0VSX0FHRU5UJ107DQblahblahblahblahblahblah etc et etc etc")); 
I'd also update to the latest version of PHP on your server(s) if you haven't already. Hope this helps
__________________
Server Optimisation - Pentesting - Secure WP Installs.
Pushcube is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 05:24 PM   #37
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,822
Quote:
Originally Posted by Pushcube View Post
It's a XSS exploit. It's simple to fix so don't panic

If you have access to your .htaccess file add the following to prevent it happening:

Code:
RewriteCond %{QUERY_STRING} base64_encode.*(.*) [NC,OR]
RewriteRule ^(.*)$ ? [F,L]
If you have SSH you can hunt down modified files by:

Code:
grep -r "eval(base64_decode" *
I don't think I should post the infection PHP code here(obviously), but it will appear at the top of all the modified files, you will know it when you see it. Something like this:

PHP Code:
eval(base64_decode("ZXJyb3JfcmVwb3J0aW5nKDApOw0KJG5jY3Y9aGVhZGVyc19zZW50KCk7DQppZiAoISRuY2N2KXsNCiRyZWZlcmVyPSRfU0VSVkVSWydIVFRQX1JFRkVSRVInXTsNCiR1YT0kX1NFUlZFUlsnSFRUUF9VU0VSX0FHRU5UJ107DQblahblahblahblahblahblah etc et etc etc")); 
I'd also update to the latest version of PHP on your server(s) if you haven't already. Hope this helps
thanks a lot

valuable info instead of insults or ignorance, who would have thought
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-29-2011, 08:20 PM   #38
AdultKing
Raise Your Weapon
 
AdultKing's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Outback Australia
Posts: 15,601
Quote:
Originally Posted by MaDalton View Post
actually i would think 5% is a very low number - lol

but it's almost a full time job if you have more than one website
5% of the number of websites we have fully crawled is a very very very big number lol, they say space is really really big (according to Douglas Adams), well so is the web!

I have no idea what the standard ratio of infected sites is on the web, however we are learning alot from our crawling efforts and it's interesting to see the stats and patterns that emerge when undertaking such a project.

I hope you get your problems sorted out quickly, just take comfort in that most of these attacks are completely automated by the attackers and if anything it helps you make your sites even more secure than before.
AdultKing is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.