I think I've been hacked or something

Discussion in 'Site & Server Administration' started by Neil UK, Jul 18, 2010.

  1. #1
    Hi,

    I hope this is the right place for this problem. I think someone or something has changed and it appears redirected my site's main url. I fetched the page as a googlebot and got the following:
    HTTP/1.1 301 Moved Permanently
    Date: Sun, 18 Jul 2010 13:33:32 GMT
    Server: Apache/2.2.15 (CentOS) mod_ssl/2.2.15 0.9.8l DAV/2 mod_auth_passthrough/2.1 FrontPage/5.0.2.2635
    X-Powered-By: PHP/5.2.13
    Expires: Thu, 19 Nov 1981 08:52:00 GMT
    Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
    Pragma: no-cache
    Set-Cookie: PHPSESSID=c3ublesb98l44rtvbthpm6crt0; path=/
    Last-Modified: Sun, 18 Jul 2010 13:33:32 GMT
    Location: /toefl-ibt-books/
    Vary: Accept-Encoding
    Content-Encoding: gzip
    Content-Length: 20
    Keep-Alive: timeout=10, max=30
    Connection: Keep-Alive
    Content-Type: text/html

    All of a sudden my main url started going to http://www.toeflpages.com/toefl-books/
    I've spent ages trying to figure it out, but I'm no expert. Can anyone help, please?
    My main url is toeflpages.com
    Thanks
    Neil
     
    Neil UK, Jul 18, 2010 IP
  2. WindowsGuru

    WindowsGuru Peon

    Messages:
    37
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    What is in the toefl-books subfolder? Did you create that?
     
    WindowsGuru, Jul 18, 2010 IP
    Neil UK likes this.
  3. Neil UK

    Neil UK Peon

    Messages:
    20
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Hi WindowsGuru,

    Yes, I created a page with the url /toefl-books/. I created this page just like I created my other pages and I've never had a problem until now.
    I checked my static page settings and all normal. It's driving me crazy.
    Where would I find the toefl-books subfolder? I'm searching my server for a possible solution, but no luck.
     
    Neil UK, Jul 18, 2010 IP
  4. WindowsGuru

    WindowsGuru Peon

    Messages:
    37
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Are you on shared hosting, dedicated, or?

    FTP to your site and browse to the /toefl-books/ subfolder to view/access the contents.

    Since you are on Linux I would also check the web root (/) for .htaccess file and inspect it for any redirects etc.
     
    WindowsGuru, Jul 18, 2010 IP
  5. Neil UK

    Neil UK Peon

    Messages:
    20
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I'm not sure if my server is shared. I'm using wordpress but I pay for hosting on bluehost.
    I'm in ftp programme now, but I can't find anything to do with toefl-books and the .htaccess file is almost blank
     
    Neil UK, Jul 18, 2010 IP
  6. WindowsGuru

    WindowsGuru Peon

    Messages:
    37
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Have you opened at ticket with BlueHost yet?
     
    WindowsGuru, Jul 18, 2010 IP
  7. Neil UK

    Neil UK Peon

    Messages:
    20
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    No, I haven't contacted them yet. Is that the way forward?
    I appreciate your time.
     
    Neil UK, Jul 18, 2010 IP
  8. WindowsGuru

    WindowsGuru Peon

    Messages:
    37
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Yes for now. I would open a ticket/give them a call and see what they say.
     
    WindowsGuru, Jul 18, 2010 IP
  9. Neil UK

    Neil UK Peon

    Messages:
    20
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Thanks WindowsGuru,

    I've opened a ticket. Fingers crossed.

    Best wishes
    Neil
     
    Neil UK, Jul 18, 2010 IP
  10. airstand

    airstand Member

    Messages:
    64
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #10
    Dont use shared hostings :)
     
    airstand, Jul 19, 2010 IP
  11. WindowsGuru

    WindowsGuru Peon

    Messages:
    37
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #11
    It doesn't matter what kind of hosting you utilize if your web application has vulnerabilities.
     
    WindowsGuru, Jul 19, 2010 IP
  12. airstand

    airstand Member

    Messages:
    64
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #12
    It doesnt metter the application ONLY :)
     
    airstand, Jul 19, 2010 IP
  13. WindowsGuru

    WindowsGuru Peon

    Messages:
    37
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Okay, I guess you may have a point, if you use a mom and pop shared hosting company or something that doesn't know how to run their shared hosting infrastructure.

    All the hosting companies I deal with have security locked down on their shared hosting infrastructure.
     
    WindowsGuru, Jul 19, 2010 IP
  14. mcfox

    mcfox Wind Maker

    Messages:
    7,526
    Likes Received:
    716
    Best Answers:
    0
    Trophy Points:
    360
    #14
    Not sure what problem you think you're having but your site works fine and the folder you say you can't find is listed in your sitemap. :/

    http://www.toeflpages.com/toefl-books/
     
    mcfox, Jul 19, 2010 IP
  15. Neil UK

    Neil UK Peon

    Messages:
    20
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Hi all,

    I want to update you. I found the problem. It was a plugin called redirection. I hadn't configured it to redirect the problem page, but somehow it did. Anyway, I uninstalled it and everything is working fine.
    Thanks for all your replies and help.
     
    Neil UK, Jul 21, 2010 IP