Site Redirecting To Strange Links ?

Talk Electrician Forum

Help Support Talk Electrician Forum:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.
Status
Not open for further replies.
Sorry about the shutdown guys , I had to make some Security adjustments .    A few odd " Redirects " flying a bout  there . 

I also greased MySql  ....only me ever bothers with it . 

The link to the "Bare Breasted"  site has leached through from Steptoe's PC ........it was an Ubuntu Formatting problem which I have now corrected for him . 

I also blocked the other stuff on there ,   we didn't want to see that .  You'll thank me .  

What was it ?

Some wierd Scottish /Irish folk singers singing in that strange language Stepps speaks .

Then a load of Des O'Connor  albums  (  He thought he was one of The Dubliners )

Glad to see everyone back . 

 
Last edited by a moderator:
Sorry about the shutdown guys , I had to make some Security adjustments .    A few odd " Redirects " flying a bout  there . 

I also greased MySql  ....only me ever bothers with it . 

The link to the "Bare Breasted"  site has leached through from Steptoe's PC ........it was an Ubuntu Formatting problem which I have now corrected for him . 

I also blocked the other stuff on there ,   we didn't want to see that .  You'll thank me .  

What was it ?

Some wierd Scottish /Irish folk singers singing in that strange language Stepps speaks .

Then a load of Des O'Connor  albums  (  He thought he was one of The Dubliners )

Glad to see everyone back . 

thanks a bunch,

you deleted all my pix of SSS too   :(

do you know how much that telephoto lens cost me to hire???   :eek:

 
Just to dispel the rumors

We are having a problem with redirects (occasionally) from google to some random sites.

However the servers have not been hacked and the database is clean.

IPB are working on the issue as to date all we know is that no admin accounts or ftp accounts have been compromised and there has been no attack on MySql.

When we find out the root cause of the problem it will be reported here.

Sorry for any inconvenience caused.
Glad you got it fixed, that chick on the adultfriendfinder landing page has a face like a bag of spanners.

I'll spread the word you're back up and running on the other forum which I suspect was the cause of this thread being started.  

 
The annoying thing is Marvo, it seems our server, DB, SW etc all came out clean, but it was still happening?

The update was precautionary.

It seems that the common vulnerability for this issue is not there in the IPB software, but it still happened, and not through our servers/systems it seems.

The re-direct seemed to be between Google & us as it were.

Worrying if you think about it?

I await the full run down from the experts.

 
The annoying thing is Marvo, it seems our server, DB, SW etc all came out clean, but it was still happening?

The update was precautionary.

It seems that the common vulnerability for this issue is not there in the IPB software, but it still happened, and not through our servers/systems it seems.

The re-direct seemed to be between Google & us as it were.

Worrying if you think about it?

I await the full run down from the experts.
I'm not an expert on these particular vulnerabilities but it bears the hallmarks of a classic sql injection attack. It probably is on the servers and the exact cause could be anything from a 3rd party add-on to unauthorised cpanel or phpmyadmin access etc. This type of vulnerability has numerous variations and can be persistent and difficult to find up but the good news is it's been around a while and it's well documented.  

Is this attack the reason my posts don't appear?
No, I doubt it. If you're posts haven't been appearing it's probably some other reason.

**edit** maybe if the forum software was recently updated there could have been a few posts lost.

 
Last edited by a moderator:
An update to clear up all the gossip.

The redirects were the cause of a php injection through a php security flaw and not an sql injection, there was no unauthorised access to the server and no third party add ons caused this.

It was 5 small lines of encoded code using the eval() structure at runtime to decode itself and was contained within cache files on the server.

This is similar to a php security issue found in late 2012 that was patched.

Many thanks all for your help and please report any other issues in the forum support area.

Also many thanks to others who helped in the background.

Thread now closed. 

 
Last edited by a moderator:
Status
Not open for further replies.
Top