Digital Point Forums
Quick Collect

Go Back   Digital Point Forums > Design & Development > Site & Server Administration > Security
Google Analytics
Log In to view
your analytics

Reply
 
Thread Tools
  #1  
Old Jun 5th 2008, 6:25 am
KenYN KenYN is offline
Champion of the Naaru
 
Join Date: Apr 2007
Posts: 248
KenYN is on a distinguished road
Question Hack 302-ing site to anyresults.net

Someone I know's web site was hacked and chucked out of Google but he claimed to have fixed it recently. However, I noticed when I clicked through from Google Reader I ended up at http://anyresults.net. So, I decided to try this:

Code:
C:\>get -UdS -H "Referer: http://www.google.com" www.debito.org
GET http://anyresults.net/
Referer: http://www.google.com
User-Agent: lwp-request/2.07

GET http://www.debito.org --> 302 Found
GET http://anyresults.net/ --> 200 OK
Anyone familiar with this hack so I can tell him what to do? Google's not very useful at all. BTW, Yahoo! and Live do the same thing.
Reply With Quote
  #2  
Old Jun 5th 2008, 2:44 pm
mwill mwill is offline
Peon
 
Join Date: Apr 2008
Posts: 2
mwill is on a distinguished road
Yep! I just discovered yesterday that my site www.CoolBrit.net sometimes redirects to anyresults.net in Google search. I'm not sure if I've been tossed out of Google yet but my visitors have dropped dramatically. When I type in CoolBrit.net nothing comes up in Google but when I type in CoolBrit my site is still there

Any solutions for this redirect?
Reply With Quote
  #3  
Old Jun 5th 2008, 10:43 pm
BuenosAires BuenosAires is offline
Champion of the Naaru
 
Join Date: Oct 2006
Location: Buenos Aires
Posts: 159
BuenosAires is on a distinguished road
Same thing is happening to me.

My visitors have dropped dramatically over the past week or so.I couldn't work out the problem, as my rankings in Google are still there.

Then a friend just told me that sometimes when he clicks on a link to my site it goes to anyresults.net

Funny thing is, I can access my site fine and never get redirected.

Does anyone have any idea how to combat this?I can't find any kind of redirect in my source code. I use Wordpress. Really very worried...
Reply With Quote
  #4  
Old Jun 6th 2008, 1:01 pm
wicked9690's Avatar
wicked9690 wicked9690 is offline
Hand of A'dal
 
Join Date: May 2007
Posts: 396
wicked9690 is on a distinguished road
Hey folks,

This a new Wordpress exploit. Had the same thing happen to me last week. if you look here there is a solution:

http://wordpress.org/support/topic/1...=2#post-770581
__________________
Free Car Solution - Paying 75% Commission
Show People How They Can Get Paid To Drive Or Get A Free Car.
Hot Niche. Lots Of Affiliate Tools With More Coming!
Reply With Quote
  #5  
Old Jun 7th 2008, 7:22 am
clasione clasione is offline
of the Nightfall
 
Join Date: Jan 2005
Location: Long Island
Posts: 2,348
clasione is a name known to allclasione is a name known to allclasione is a name known to allclasione is a name known to allclasione is a name known to allclasione is a name known to all
After many hours of scanning the database and files with no luck, I believe I finally have the solution which is posted on my blog. This is what worked for me in my case: http://clasione.blogspot.com/2008/06...ck-search.html
__________________
-
Reply With Quote
  #6  
Old Jun 8th 2008, 4:46 am
rootbinbash's Avatar
rootbinbash rootbinbash is online now
of the Nightfall
 
Join Date: Feb 2007
Location: /root
Posts: 2,034
rootbinbash is just really nicerootbinbash is just really nicerootbinbash is just really nicerootbinbash is just really nice
Yes this is a very big security hole at wordpress.Patch the current wordpress.
__________________
Free Online Games | Adventure Games
Reply With Quote
  #7  
Old Jun 13th 2008, 5:07 am
scorechase scorechase is offline
Champion of the Naaru
 
Join Date: Dec 2006
Posts: 217
scorechase is on a distinguished road
Quote:
Originally Posted by KenYN View Post
Someone I know's web site was hacked and chucked out of Google but he claimed to have fixed it recently. However, I noticed when I clicked through from Google Reader I ended up at http://anyresults.net. So, I decided to try this:

Code:
C:\>get -UdS -H "Referer: http://www.google.com" www.debito.org
GET http://anyresults.net/
Referer: http://www.google.com
User-Agent: lwp-request/2.07

GET http://www.debito.org --> 302 Found
GET http://anyresults.net/ --> 200 OK
Anyone familiar with this hack so I can tell him what to do? Google's not very useful at all. BTW, Yahoo! and Live do the same thing.
Help .. how can I run this get command that you run? I feel my website is hacked as well and want to confirm somehow.
__________________
GMAT 700 | GMAT / MBA Blog |
Reply With Quote
  #8  
Old Jun 13th 2008, 6:17 am
clasione clasione is offline
of the Nightfall
 
Join Date: Jan 2005
Location: Long Island
Posts: 2,348
clasione is a name known to allclasione is a name known to allclasione is a name known to allclasione is a name known to allclasione is a name known to allclasione is a name known to all
Check your header file as noted here:
http://clasione.blogspot.com/2008/06...ck-search.html

They use a SQL Injection to add code to your header file.
__________________
-
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
StreetKorner.net PR2 hack-test script RectangleMan Sites 11 Jul 22nd 2008 5:15 pm
[WTS] Fabulous CCC.net for a Domain Hack at GoDaddy. L@@K!!! thedomainsella Domains 7 Apr 10th 2008 1:00 pm
How do I tell if a site is doing a 301 or 302 redirect? n0chance Site & Server Administration 2 Oct 9th 2007 8:17 am
Announced Don Sequel PR4 Site, SRK *ing SEO Guru Sites 7 Jun 2nd 2007 3:15 pm
phpBB hack installed for forum (introduction hack) vichousefc PHP 3 Dec 18th 2006 8:12 am


All times are GMT -8. The time now is 3:38 pm.