Digital Point Forums
Winn and Sims

Go Back   Digital Point Forums > Search Engines > Google
Google Analytics
Log In to view
your analytics

Reply
 
Thread Tools
  #1  
Old Jun 5th 2008, 1:21 am
Geraldm's Avatar
Geraldm Geraldm is offline
of the Nightfall
 
Join Date: Oct 2006
Location: London, UK
Posts: 1,329
Geraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to all
Question Email from Google - Is it real?

Hi,

Just received the below email. The TO address contained all my currently registered email addresses for my domain:

Quote:
Dear site owner or webmaster of <my site url>,

While we were indexing your webpages, we detected that some of your pages were using techniques that are outside our quality guidelines, which can be found here: http://www.google.com/webmasters/guidelines.html. This appears to be because your site has been modified by a third party. Typically, the offending party gains access to an insecure directory that has open permissions. Many times, they will upload files or modify existing ones, which then show up as spam in our index.

The following is some example hidden text we found at delphi-php.net:

purchase zyrtec the drug zyrtec what is zyrtec zyrtec 5 mg zyrtec 10 mg tablet and pregnancy zyrtec 10 mg zyrtec 10 zyrtec 10mg zyrtec allergy pill zyrtec allergy pills zyrtec buy zyrtec canadian pharmacy zyrtec cheap zyrtec cost zyrtec d 12 zyrtec d description zyrtec d pregnancy zyrtec d prices zyrtec d tablet zyrtec d tablets zyrtec d zyrtec drug zyrtec for sale zyrtec from canada zyrtec hydrocodone zyrtec mexico zyrtec online zyrtec pfizer zyrtec pill discription zyrtec pill zyrtec pills zyrtec prescription drugs zyrtec prescription zyrtec price zyrtec tab 10mg zyrtec tab zyrtec tablets zyrtec tabs 10mg zyrtec tabs

[...]

In order to preserve the quality of our search engine, we have temporarily removed some of your webpages from our search results. Currently pages from delphi-php.net are scheduled to be removed for at least 30 days.

We would prefer to have your pages in Google's index. If you wish to be reconsidered, please correct or remove all pages (may not be limited to the examples provided) that are outside our quality guidelines. One potential remedy is to contact your web host technical support for assistance. For more information about security for webmasters, see http://googlewebmastercentral.blogsp...ebmasters.html.

When you are ready, please visit https://www.google.com/webmasters/to...nclusion?hl=en to learn more and submit your site for reconsideration.

Sincerely,
Google Search Quality Team
Is this email real? My site is a forum with 10k+ pages (6k+ pages indexed in google) but I do monitor it and have never seen a page with spam on it!

Cheers ....
Gerald.
Reply With Quote
  #2  
Old Jun 5th 2008, 1:24 am
godmode godmode is offline
Starcaller
 
Join Date: Dec 2006
Posts: 4,417
godmode is a splendid one to beholdgodmode is a splendid one to beholdgodmode is a splendid one to beholdgodmode is a splendid one to beholdgodmode is a splendid one to beholdgodmode is a splendid one to beholdgodmode is a splendid one to behold
What was the email address you received it from? and did they actually de-index?
Reply With Quote
  #3  
Old Jun 5th 2008, 1:26 am
farrhad farrhad is offline
of the Nightfall
 
Join Date: Jan 2008
Location: India
Posts: 2,360
farrhad is just really nicefarrhad is just really nicefarrhad is just really nicefarrhad is just really nicefarrhad is just really nice
What was the email address???
__________________
Reply With Quote
  #4  
Old Jun 5th 2008, 1:27 am
hsc hsc is offline
Banned
 
Join Date: Mar 2008
Posts: 238
hsc is on a distinguished road
Yes pl let us know email address , and if de-index your site?
Reply With Quote
  #5  
Old Jun 5th 2008, 1:28 am
Kuldeep1952 Kuldeep1952 is offline
Hand of A'dal
 
Join Date: Aug 2007
Location: India
Posts: 290
Kuldeep1952 will become famous soon enough
The e-mail seems to be real.

You can see a similar example on matt cutts blog at
http://www.mattcutts.com/blog/helping-hacked-sites/
__________________
Web-site Development | Altaindia | | Pages
Reply With Quote
  #6  
Old Jun 5th 2008, 1:28 am
kmofo's Avatar
kmofo kmofo is offline
Hand of A'dal
 
Join Date: Mar 2008
Posts: 336
kmofo will become famous soon enough
Seems to be real, because you've got some problems:
http://www.google.com/search?hl=en&q...delphi-php.net

If you look into the source of this: http://www.delphi-php.net/category/examples/
you will find a ton of hidden links.
Reply With Quote
  #7  
Old Jun 5th 2008, 1:41 am
tong1991's Avatar
tong1991 tong1991 is offline
Champion of the Naaru
 
Join Date: Jun 2008
Posts: 215
tong1991 is on a distinguished road
What was the email address you received it from? and did they actually de-index?
Reply With Quote
  #8  
Old Jun 5th 2008, 2:06 am
hiteshb's Avatar
hiteshb hiteshb is offline
of the Nightfall
 
Join Date: May 2008
Location: India
Posts: 1,191
hiteshb has a spectacular aura abouthiteshb has a spectacular aura about
i think the email address was correct. I think if the question is about email address then the from and reply-to must be same. All the way everything is correct in mail.
__________________
Cricket Schedule | IPL Highlights
Reply With Quote
  #9  
Old Jun 5th 2008, 2:19 am
johnenderson's Avatar
johnenderson johnenderson is offline
Twilight Vanquisher
 
Join Date: Mar 2008
Location: United Kingdom
Posts: 542
johnenderson will become famous soon enough
all the details are correct.

Matt cutts has specified always in his blog and interviews with many peoples
like he said already in the blog, mattcutts.com/blog/helping-hacked-sites/

now they have improved many techniques and support team so there is lots of chances of get support with Email which you received.

Now just take care about Guidelines which they has specified in email.

Thanks

John
Reply With Quote
  #10  
Old Jun 5th 2008, 4:50 am
Freewebspace Freewebspace is offline
Astral Walker
 
Join Date: Aug 2006
Location: Madurai,India
Posts: 6,090
Freewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond reputeFreewebspace has a reputation beyond repute
First check to header of mail to see that you received it from Google

if it's from Google, Go ahead check all your pages for the above words in database

if your query returns go ahead and remove it... otherwise there is possibility that these might have posted by a spammer in athread using some technique and it might have been indexed by Google before the mods had removed it...
Reply With Quote
  #11  
Old Jun 5th 2008, 5:32 am
Lovely Lovely is online now
of the Nightfall
 
Join Date: Oct 2005
Location: www.velnetweb.co.uk
Posts: 2,320
Lovely will become famous soon enough
...check the header of the mail, it will enable to know if the mail is from Google or not.
__________________
UK Webmaster Forum | Cheap MySQL PHP Web Hosting
PM me for your quality one way link building
Reply With Quote
  #12  
Old Jun 5th 2008, 6:01 am
Geraldm's Avatar
Geraldm Geraldm is offline
of the Nightfall
 
Join Date: Oct 2006
Location: London, UK
Posts: 1,329
Geraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to allGeraldm is a name known to all
Hi,

After investigating, the email is ligitimate and my site had been hacked.

Someone had managed to copy two files to my blog:
  • zip.php
  • 1.zip
Contained in the 1.zip file were .html files containing links to spam sites. They were also able to modify my header.php file to include a hidden section containing these spam links.

I have since removed all the spam crap and changed my cpanel/ftp password, I've also changed the permissions on the folder where the files were found to 'read only'.

I've just completed Google's online form requesting to be included again in the Google index.

The only thing I can think of for them to be able to do this is a brute force password hack which must of taken them a while to do. What other way could they have done it?

Cheers ....
Gerald.
Reply With Quote
  #13  
Old Jun 5th 2008, 7:37 pm
WishBone WishBone is offline
of the Nightfall
 
Join Date: May 2007
Posts: 1,346
WishBone is on a distinguished road
Well done investigating, my friend's site got the same problem and situation too, that zip file was found on his FTP folder. He's looking now for better web hosting.
__________________
Reply With Quote
  #14  
Old Jun 6th 2008, 1:15 am
kmofo's Avatar
kmofo kmofo is offline
Hand of A'dal
 
Join Date: Mar 2008
Posts: 336
kmofo will become famous soon enough
Quote:
Originally Posted by Geraldm View Post
What other way could they have done it?
Some kind of code/sql injection that would allow a further file upload. Wordpress is not that vulnerable, but one of the plugins might be...

You can check if one of these fits: http://securitydot.net/search.php?sc...word+press+zip
Reply With Quote
  #15  
Old Jun 6th 2008, 3:33 am
dpking's Avatar
dpking dpking is offline
of the Nightfall
 
Join Date: Oct 2007
Location: New Delhi
Posts: 1,017
dpking will become famous soon enough
Yes this is true !!
__________________
Shimla Hotels | Nainital Hotels | |
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Adsense Disabled with no reason in email. How long before Google respond to my email? Proximity AdSense 21 Oct 9th 2008 5:23 pm
Send email with Google's email server with a non Google address? John M General Business 6 Jan 5th 2008 9:41 am
[WTS] Real Email Contact List for 10$[1000 Real Msn Contacts] Hugeforum Buy, Sell or Trade 1 Nov 18th 2007 9:23 pm
[WTS] Real Email Contact List for 10$[1000 Real Msn Contacts] Hugeforum Services 0 Nov 18th 2007 5:39 pm
*I recieved this email - is it real???? cprntr Publisher Network 11 Jun 27th 2006 6:00 pm


All times are GMT -8. The time now is 6:14 am.