From: AliceW.
Date: Wed, 25 Oct 2006 19:54:15 -0700
Local: Wed, Oct 25 2006 10:54 pm
Subject: Re: System Doctor 2006 ... huge problem
Loading very slowly though...
---------------- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: Swtrose
Date: Wed, 25 Oct 2006 19:57:54 -0700
Local: Wed, Oct 25 2006 10:57 pm
Subject: Re: System Doctor 2006 ... huge problem
Shawn is here at Google groups helping, but he is the webmaster of
eight websites plus runs three of his own and Dustin blog does not load slow on my end. You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: Shawn DesRochers
Date: Wed, 25 Oct 2006 20:44:08 -0700
Local: Wed, Oct 25 2006 11:44 pm
Subject: Re: System Doctor 2006 ... huge problem
Well the Gods bellowed and I have arrived as requested by AliceW ;-P
I apologize Dustin as I run a web hosting company and a graphic design So AliceW get a life I do this for a living not for fun and game, and I So Dustin to your problem, I have loaded your blog in several different However I had Rose load the blog and sure enough it comes up some vDEV So I reviewed your source code and again no obvious infractions of What have you added lately to your blog? any JavaScripts or plugins The mining cookie is the following and is your issue, I broke the link Do not click or Past the link in your browser you have been warned.. http://go. systemdoctor.com/ MzY2nw==/2 /971/ax=1/ed=2/ex=1// Now Dustin to view this yourself, increase your security to block 3-4 are blogger and the widgets but the one above and another one are Example of Source code! <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <link rel="EditURI" type="application/rsd+xml" title="RSD" <style type="text/css"> body { /* Page Structure background:url("http://www.blogblog.com/rounders2/corners_main_top.gif") /* Links /* Blog Header background:url("http://www.blogblog.com/rounders2/corners_cap_bot.gif") /* Posts /* Comments /* Profile background:url("http://www.blogblog.com/rounders2/corners_prof_top.gif") /* Sidebar Boxes ... You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: AliceW.
Date: Wed, 25 Oct 2006 21:30:09 -0700
Local: Thurs, Oct 26 2006 12:30 am
Subject: Re: System Doctor 2006 ... huge problem
So this is definitely a javascript? and definitely something he's added
himself (as in not some malware on his computer adding it without his knowledge)? The only js I see on this template is the "Pledge" js, so does that have to be the culprit then? And if it's cookies doing it, why the other day when I first clicked on And then, why did it redirect me the other day but not now? Thanks for helping. ---------------- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: phydeaux3
Date: Thu, 26 Oct 2006 05:09:51 -0000
Local: Thurs, Oct 26 2006 1:09 am
Subject: Re: System Doctor 2006 ... huge problem
Well just to throw some more out there.
I don't think it's on the users' end. The user may be infected now with For example. Here's the headers for an image on the server with http://www.originalrootzencenter.org/Art/buddha.jpg GET /Art/buddha.jpg HTTP/1.1 HTTP/1.x 200 OK Everything is fine then. That's the way it should always be. The image http://www.originalrootzencenter.org/Art/buddha.jpg GET /Art/buddha.jpg HTTP/1.1 HTTP/1.x 301 Moved Permanently Both of those are with cookies completely disabled so they aren't into With ANY referrer sent in the request, ANY file request on the A server sending a 301 means only one thing to me. Apache has been I would contact the host once again with that additional info, send Could something have been on the users computer to help the bad guys do Of course I'm just throwing out what I see. Your mileage may vary. You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: AliceW.
Date: Wed, 25 Oct 2006 22:24:51 -0700
Local: Thurs, Oct 26 2006 1:24 am
Subject: Re: System Doctor 2006 ... huge problem
I don't understand most of what you said, but...
Why then was I getting redirected the other day, but not now? I haven't When I click on that image link, I get redirected. And for the record, I wonder if all these hijack complaints are for blogs not hosted at Thanks phydeaux. ---------------- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: AliceW.
Date: Wed, 25 Oct 2006 22:26:12 -0700
Local: Thurs, Oct 26 2006 1:26 am
Subject: Re: System Doctor 2006 ... huge problem
This would affect everything hosted on that server then?
Seems like everyone being hosted on that server would be screaming ---------------- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: Shawn DesRochers
Date: Wed, 25 Oct 2006 23:07:01 -0700
Local: Thurs, Oct 26 2006 2:07 am
Subject: Re: System Doctor 2006 ... huge problem
Wow I suppose I should of taken a little more time to investigate, I
see it now but it never occurred to me to click an image.. As I stated above I wasn't being redirected or nothing of the sorts, I I am also behind a hardware firewall so my browser wasn't stopping http Clicking on an image redirects you instantly to System Doctor!!!! It seems that it is a hijack and pretty good one at that! As 'AliceW As Apache is used across the entire backbone as a server client module! I did a check at DNS tools and a whois and see he's on IPOWERDNS.COM, Unless he's on a VPS Server which his apache would be set to him alone When testing the site in Lynx I see a whole pile of COM's and Request Also find out what version of Apache your host provider is currently Kudos goes to AliceW! But when your not being redirected and source looks fine and nothing Shawn You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: phydeaux3
Date: Thu, 26 Oct 2006 06:29:33 -0000
Local: Thurs, Oct 26 2006 2:29 am
Subject: Re: System Doctor 2006 ... huge problem
I was just about to reply to Alice's statement and saw Shawns,
but as he notes it's possible other domains on the server are also compromised, but it could be just this domain. Depends on the server setup and what kind of access the bad guys got. And Alice's different behaviour may be because of the referral header "Kudos goes to AliceW! " Kudos to everyone, but wasn't I the one that found the 301's. :-) And But definitely the hosts tech support needs to be notified with the new You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
From: AliceW.
Date: Thu, 26 Oct 2006 00:12:07 -0700
Local: Thurs, Oct 26 2006 3:12 am
Subject: Re: System Doctor 2006 ... huge problem
I am being redirected again now. I seriously don't understand why
sometimes I am and other times not. Maybe has something to do with having clicked the image?? Because I did run adaware after having clicked his link the other day. And a virus scan on the puter every day, but that's been reporting that it's found nothing. His site was loading but without images until after I clicked the image link, and now I'm being redirected. But it's been a couple of hours since then, so something else could have happened somewhere during that time... Anyway. Thanks Phydeaux for bothering to look more closely. Now Dustin You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||
| Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy |
| ©2013 Google |