ok, sorry
it makes sense that if it made them millions over years, they improved the way they do it
Printable View
ok, sorry
it makes sense that if it made them millions over years, they improved the way they do it
omg, just checked my forum and it is hacked as well again :/ :D
Sorry to hear that Sherlock,
One thing that might help a little, is if anyone sees this, let us know the search string you used at google that presented you with this redirect.
Just post it here in this thread would be fine and with Michael traveling, Anthony and I will certainly try and keep monitoring this thread so we can occasionally discuss it with Alan and the tech's at the office if needed.
This may help allowing them to recreate the redirects while tracing.
Rick
Universal4
For me it happened last time for googling "sportsbet gpwa": https://www.google.com.br/url?sa=t&r...ACDgTYqYqU-UJA
The issue here is that they somehow use timer, that must be based on cookies or something like that (probably not on IP).
While catching this bug, it is bet to use anonymous mode of browser, because then the redirect occurs in 100% of cases, because cookies are always deleted.
One of my VB sites this as well, last time was base64 code added via VBSEO (2 years ago) So Ill start digging into this one as well now :(
here is a basic guide, also has a base64 pearl script at the end to search your server.
http://www.blackberryos.com/off-topi...ct-google.html
correct, it is the vbseo plugin
i can not believe i paid for this vb crap
Buy dragonbyteSEO then remove it (VBSEO) (delete all files as well)
It coverts 100% over and works 100%
as pointed out above, the hot fix does not work at least for me
programmer says he went through thousands of rows of code, found som other viruses, but redirects are not located yet
the redirects are in base64 code
thanks, that is good
we have now made some hotfix, let we see how it goes, so far it is ok, but i am not sure if it disabled some admin features or not
Thanks for posting all this research guys, I am not sure what if anything Alan has come accross, but we will make sure he sees this thread.
Rick
Universal4
This forum obviously is hacked! Now I will be censored in my own diary?
"And why everytime somebody delete screens from Leopold...???"
Source: https://www.gpwa.org/forum/leopolds-...tml#post778497
A simple screenshot, an evidence (!), that the GPWA seal will still be used by a former sponsor (https://www.gpwa.org/forum/leopolds-...tml#post778489), will be removed again and again by a ghost here.
For me as a complete moron it do not look like technical (!) issue, because first it was hosted here: http://abload.de/img/testl4ime.jpg
Then -because I thought it is a technical problem- I hosted it directly on my own website: http://roulettezeitung.com/7/gpwa-au.jpg
And again it was removed, a simple screenshot, but an evidence!
And not only from my post, also from another GPWA member, who quoted the post with a screenshot.
I re-edited it now the 4th time to insert the evidence. If the evidence of abusing the GPWA seal will disappear one more time, then I will call Anthony after his return from LAC, to ask him, what's going on here and if it's now policy of GPWA to delete harmless screenshots, evidences. I can't do my job properly!
I will make a copy of this post and sent it directly after "submit reply" via PM to Anthony, that no one can say later "Oh, it's deleted by human error."
If this is any technical, then fix it soon, because it's very annoying, and I can't do my job well.
Leopold
No one is censoring you, but your post here in this thread is completely OFF TOPIC. Not one thing you posted had anything to do with the VBulletin redirect hack issue.
This thread is not about your thread in the fun section, it is about a serious issue with VBulletin Forum software and how to recreate the redirects, and steps that we an others are taking to combat this hack.
Further off-topic posts will be moved.
Rick
Universal4
Hi,
I've find this post because a friend of me have his forum with the redirect hack.
For reproduce it :
Open IE
Clear the history and all files cache
Open Google
Looking for GPWA
Click on "Forum" link
The hack will run. I don't know how to eradicate this :(
If someone have an idea. Move to DBSEO is maybe the solution....
Portekoi
in the moment i dont see any bugs or exploits...on FF
Start a private navigation on chrome. Search GPWA on Google. Click on the forum link. You will have filtestore page :(