Google Groups Home Help | Sign in
Discussions > Crawling, indexing, and ranking > Our Google Listing Hijacked!
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
geek  
View profile
 More options Jan 25, 2:31 am
From: geek
Date: Thu, 24 Jan 2008 23:31:20 -0800 (PST)
Local: Fri, Jan 25 2008 2:31 am
Subject: Our Google Listing Hijacked!
This page describes exactly how the link in our Google listing (http://
denvergeeks.com)has been hijacked:

http://clsc.net/research/google-302-page-hijack.htm

We are a computer repair company, yet our url is being redirected to a
site that is infecting computers! It is devastating to us.

I filed a spam report with Google more than two months ago, but no
response has been received to date.

Can anyone help?


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JLH  
View profile
(2 users)  More options Jan 25, 3:39 am
From: JLH
Date: Fri, 25 Jan 2008 00:39:21 -0800 (PST)
Local: Fri, Jan 25 2008 3:39 am
Subject: Re: Our Google Listing Hijacked!
It's not a 302 hijacking.  Sorry.

Your site has probably been hacked.

If you use a firefox add-on like https://addons.mozilla.org/en-US/firefox/addon/953
and change the referer when visiting your site to something from
Google ( I used  http://www.google.com/search?q=site%3Adenvergeeks.com)
every time you load up a page on your site you will be redirected to
the offending site.  It has nothing to do with Google or a 302
hijacking.

My guess is that you didn't intend for this to happen and that your
site has some security holes in it and someone has injected some code
into it.

There are many different hacks, but this is just one explanation,
http://johnmu.com/hack-hidden-redirect/

On Jan 25, 1:31 am, geek wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
cass-hacks  
View profile
(1 user)  More options Jan 25, 3:39 am
From: cass-hacks
Date: Fri, 25 Jan 2008 00:39:51 -0800 (PST)
Local: Fri, Jan 25 2008 3:39 am
Subject: Re: Our Google Listing Hijacked!
As of a year and a half ago, according to the article on the page you
linked to, the problem described is no longer an issue.

Some time even before that, 302 SERPs hijacks were no longer possible.

What do you mean by, "our url is being redirected", do you mean that
if I go to the URL of your site, I would get redirected to another
site or do you mean the URL for listings of your content in the SERPs
is actually for a different site?

Craig

On Jan 25, 4:31 pm, geek wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
geek  
View profile
 More options Jan 25, 12:10 pm
From: geek
Date: Fri, 25 Jan 2008 09:10:08 -0800 (PST)
Local: Fri, Jan 25 2008 12:10 pm
Subject: Re: Our Google Listing Hijacked!
Hello JLH,

THANK YOU so much for such quick response. Sorry - not! I am very
hopeful to hear that it is not the problem described in that link...

Do you know where I can find some instructions to fix the problem?

Would re-building my site from scratch solve the problem, or is it
something happening above that directory where this site is located on
my hosted server?

What measures can I take to prevent this from happening in the future?

Best regards

On Jan 25, 1:39 am, JLH wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JLH  
View profile
(1 user)  More options Jan 25, 12:38 pm
From: JLH
Date: Fri, 25 Jan 2008 09:38:50 -0800 (PST)
Local: Fri, Jan 25 2008 12:38 pm
Subject: Re: Our Google Listing Hijacked!
I'm no expert at finding and fixing hacks by any stretch, but I have
heard that many have been injected by having some folders set to 777
access.  One that I saw had .htaccess changes in every subfolder on
the site and two rouge .php files inserted on the site.  If you can
view through FTP the files on your site and perhaps find a pattern of
dates of changes that you didn't make, then you may be able to find
the offending stuff.

I'd definitely get the host involved to let them know that the server
may be vulnerable to attack as it would be in their best interest to
protect you and their other clients as well.  Perhaps they can find
the hole and the intrusions as well.

On Jan 25, 11:10 am, geek wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
abracadabra  
View profile
(2 users)  More options Jan 25, 12:53 pm
From: abracadabra
Date: Fri, 25 Jan 2008 09:53:00 -0800 (PST)
Subject: Re: Our Google Listing Hijacked!
Hi Geek,

I'm not JLH but if i may here is my bit.

> Would re-building my site from scratch solve the problem, or is it
> something happening above that directory where this site is located on
> my hosted server?

If you have a clean backup of your site
uploading that would be a good first step.

Also, as you are on an Apache server, look
at your .htaccess files (They are normally hidden)
and make sure there is nothing unexpected in there.
Your hosting provider may have placed some
directives there so consult with them also.

Also go over your entire webspace and look
for anything you did not put there.

If used, don't forget cgi-bin.

Also I see that your hosting server has
FrontPage 5.0.2.2635.SR1.2 extensions
installed. These have vulnerabilities that
need to be addressed and patched.
Check with your hosting provider in
regard to this.

YES, the server itself beyond your webspace may be affected.
Again, Contact your hosting provider and Demand action.

I'd also change your access passwords.

All this needs to be addressed.

Also, here is a Google post regarding general
security measures that are most useful:
http://googlewebmastercentral.blogspot.com/2007/09/quick-security-che...

This may not be an all comprehensive list of
all possible measures but should be a good start.

Blast those (&@$#% hackers...

Hope that helps,
Abracadabra
On Jan 25, 12:10 pm, geek wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Berghausen Google employee  
View profile
(2 users)  More options Jan 25, 2:16 pm
From: Berghausen
Date: Fri, 25 Jan 2008 11:16:40 -0800 (PST)
Local: Fri, Jan 25 2008 2:16 pm
Subject: Re: Our Google Listing Hijacked!
Hi, geek-

Your situation is very unfortunate, though not uncommon.  I'm sorry it
had to happen to the geeks from such a good town.  I've have a soft
spot for Denver since I spent a vacation there shopping at Cherry
Creek and exploring the downtown nightlife with some friends who were
at DU for college and grad school.

The bad news is that it looks like JLH is right, you've been hacked,
and visitors from our search results are being redirected to a malware
distributor.

Although I cannot tell specifically how you were script-injected or
where the script that's doing the redirection is located, here are
some general pointers for cleaning up:

 - You're running Apache.  Check all your .htaccess files for code
that doesn't belong there.  Get rid of it.
 - Look for scripts [usually php] that you did not write.  Get rid of
those, if you can.  Sometimes permissions get hacked in unfriendly
ways, so you may need to contact your host for help.  Make sure to
look for hidden files and files whose names start with ., too.
 - Call your webhost and have them check the directories above your
site for sketchy files if you are on virtual hosting.
 - If you are running a CMS, image gallery, forum, or any other open
source CGI application on your site, make sure it's up to date.
Hackers often take advantage of known security holes in open source
software by attacking sites that have not kept their CMS up to date.
 - You're also running cpanel.  Have your host make sure it too is up-
to-date.  cPanel hacks can be nigh impossible to clean up with normal
login permissions, so you will almost assuredly need your host's help
to get rid of the injected scripts if this is the case.

That being said--best of luck!  I hope the short bout of "warm"
weather (well, 40's is warm for winter in Denver) can keep you cheery
as you take this on.

-Bergy

PS. Goodness, JLH and Abracadabra just posted in the time it took me
to draft this.  Thanks for helping, guys.  Nobody likes being hacked--
hearing the voice of experience is much appreciated.

On Jan 25, 9:10 am, geek wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
PCweb  
View profile
(1 user)  More options Jan 25, 2:40 pm
From: PCweb
Date: Fri, 25 Jan 2008 11:40:19 -0800 (PST)
Local: Fri, Jan 25 2008 2:40 pm
Subject: Re: Our Google Listing Hijacked!
I'm having a similar problem. The offending content has been deleted
from our site, but as part of the hack, they put referring URLs on
another organization's Web site that point people to our site when
they search for certain porn-related terms. I've contact that org but
no response yet. How can I get Google to delete all references to
those files ASAP???

    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
geek  
View profile
(2 users)  More options Jan 26, 4:07 am
From: geek
Date: Sat, 26 Jan 2008 01:07:59 -0800 (PST)
Local: Sat, Jan 26 2008 4:07 am
Subject: Re: Our Google Listing Hijacked!
JLH, abracadabra, and Berghausen --

You guys are my new HEROES!

I spent the last few hours installing a fresh copy of the CMS source
code on my site, and rebuilding all of my site pages, replacing the
entire subdirectory with all new files, and VOILA - no more malicious
redirect!!

I can't thank you enough - you are sooo AWESOME...

Thank you

Thank you

Thank you


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2008 Google