Technical Discussion
  >> Web Design / HTML / Web hosting Forum


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | 4 | [5] | 6 | (show all)   Print Thread
Standard User Taras
(eat-sleep-adslguide) Wed 04-Nov-09 22:00:49
Print Post

Re: Please help ! ! !


[re: Taras] [link to this post]
 
From a hosting prospective

At the end of the day this can and does happen on accounts on servers. We have seen this [censored] happen ourselves. Quite often its an issue with a security breach of the software being installed by clients.

That said Premier one has failed their clients by not looking into this and watching bandwidth usage on accounts. not checking temp directories. nor making sure insecurities in server software are addressed. Or to make any attempts to regain control of their infected server or servers (should have changed root password in the first instance)

Premier one should have announced in some way that users should check if they are leaving security holes and or update their php scripts.

That is basically their failings ..

_____________________________________________
<randomness>
streaming music - your music - spotify
Everything websites.... soon
My Blog .......... here (still in dev mode)
Me twittering go add
Standard User TrevorSP
(knowledge is power) Wed 02-Dec-09 12:00:09
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
I swear on whatever God you believe in that I will never move a domain to a hosting provider where I can not unlock it and order my own EPP keys ever again ! ! ! ! EVER

All sorted now, but look at the start date of this thread to get some idea about how long it has taken with virtually every day trying to contact a (IMHO) non existant support department! ! ! ! !

Just to give you an idea, this site http://www.whynotjewellery.co.uk/ was infected way before any of mine, and what have the hosting company done? Take a look at the source code for yourselves, it is quite safe if you don't mind the language or click on any links!!!!

Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.

Edited by TrevorSP (Wed 02-Dec-09 12:05:25)

Standard User deleted
(deleted) Wed 02-Dec-09 13:41:30
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
Oh, Trevor its crazy how long this has been going on AND that sites on those hosts are still infected!

Are you saying that the Host's solution to the hack is putting the "no display" Div around the link farm? I'm assuming so as the hackers would not benefit from the links being hidden, unless they are claiming fees for linking rather than click-throughs. Which seems very unlikely. I also see they are there and hidden on every page on the site. Its putting some interesting references in the CACHE of every visitor though isn't it.

Most (all?) of the ruder links are carrying a Refer Tag (w-a-t-c-h-i-t without the hyphens) which is how the hacker(s) would earn their money on click throughs. It might be worth complaining to the rude site about hacking that is carrying that Refer Tag. If they did cut off the referer's income at source it might discourage such attacks.


Register (or login) on our website and you will not see this ad.

Standard User Taras
(eat-sleep-adslguide) Wed 02-Dec-09 14:02:20
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
In reply to a post by KevinR:
Oh, Trevor its crazy how long this has been going on AND that sites on those hosts are still infected!

Are you saying that the Host's solution to the hack is putting the "no display" Div around the link farm? I'm assuming so as the hackers would not benefit from the links being hidden, unless they are claiming fees for linking rather than click-throughs. Which seems very unlikely. I also see they are there and hidden on every page on the site. Its putting some interesting references in the CACHE of every visitor though isn't it.

Most (all?) of the ruder links are carrying a Refer Tag (w-a-t-c-h-i-t without the hyphens) which is how the hacker(s) would earn their money on click throughs. It might be worth complaining to the rude site about hacking that is carrying that Refer Tag. If they did cut off the referer's income at source it might discourage such attacks.


its circular chained .. - it goes off to another site when is then linked to another infected site.. this is rwhy suPHP and 0777 on linux host must be put on and in the case 0777 banned

_____________________________________________
<randomness>
streaming music - your music - spotify
Everything websites.... soon
My Blog .......... here (still in dev mode)
Me twittering go add
Standard User deleted
(deleted) Wed 02-Dec-09 19:21:06
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
I'd bet the script that compromised the sites put the div there. So when the owner goes to the site, they think none the wiser.

But Google/Bing/Yahoo WILL see it regardless of the div status and then might create reciprocal links from/to the sites shown, spreading out the 'link juice'.

Matt
Standard User deleted
(deleted) Wed 02-Dec-09 20:34:37
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
So you mean the link will increase the search ranking of the targeted sites?

I was especially intrigued that the adult links are formed as normal refer links - that implies the hack could be tracked to a refer registered with the target. And those links make less sense to me if people cannot actually click on them. They go to one of the larger real adult sites unlike the other dodgy looking blogs, and pharmaceuticals, etc. Those unusual links could certainly help the ranking of the dodgy sites.
Standard User deleted
(deleted) Wed 02-Dec-09 20:40:06
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
If the 'rank' of the previous page is good, yes, certainly possible.

The idea of this 'hack' isn't for people to be able to click on them, but to build the credibility of the target sites by having them linked from 'normal', good, clean sites.

However, it can also work in reverse.. but instead damage the reputation of the referring site by linking to a 'bad' neighbourhood.

Matt
Standard User TrevorSP
(knowledge is power) Thu 03-Dec-09 09:29:03
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
I don;t think that happens with google?
Google banned one of my sites, www.manorhousephotos.co.uk from the search engine until I had corrected it and then I have to wait 90 days whilst they check it and THEN if it is clear after 90 days they will unblock it !!!! a bit harsh, but customers protected.

The other search engines don't seem to care a jot !

I hasten to point out that the above JEWELERY site is nothing to do with me, just on the same server as I USED TO BE ! ! ! !

Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.

Edited by TrevorSP (Thu 03-Dec-09 09:31:01)

Standard User deleted
(deleted) Thu 03-Dec-09 11:29:19
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
Trevor,

You can speed that process up.. by using Google Webmaster tools smile

Matt
Standard User TrevorSP
(knowledge is power) Thu 03-Dec-09 15:49:17
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
All done and dusted and all clean as a whistle now Matt, thanks, much faster, much more secure and with a company that I trust, that even has humans on the end of the phone ! ! !

I think pretty much all of the sites have been put back on Google now, bar a couple of dormant ones which I want to pull down and put back up in a different way, but easy as pie to do now, no more having to ask support to do simple jobs for me now, I can just get on and do it ! ! ! Brilliant Stuff!

And moving from Plesk to cPanel was actually no great shakes at all, some things are just named differently that is all, basically. What really helps though are the help panels and videos that go with it all, make it all as easy as pie smile

Which reminds me a need an IP addy and SSL but that can wait until next week now, can't be bothered with this week, too much to do still ! ! Might even be next year the way things are going at the moment......... Why do people always leave it until just before the Christmas holidays to ask for things that need doing ! ! ! !

Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.

Edited by TrevorSP (Thu 03-Dec-09 15:49:41)

Pages in this thread: 1 | 2 | 3 | 4 | [5] | 6 | (show all)   Print Thread

Jump to