Jump to content
Search In
  • More options...
Find results that contain...
Find results in...

Compromised Forum


Enverex

Recommended Posts

Just an FYI, the forums appear to be compromised with some sort of malware redirect under certain conditions, those conditions being; the user came to the forums directly from a Google search and it's the first time they did it (although not sure what the time period this is before it's reset and will happen again, seems to be daily).

 

To recreate the issue I'm referring to...

 

- Google for "emumovies forum"
- Click the result for "emumovies.com/forums" (technically any result that points to the forum should work)
 
Assuming you've not visited the forum already today, you should be redirected to some dodgy website. To clarify; this only happens if you come to the forum via a Google search result and it only happens once (per day or so).
 
The compromise is likely checking the referral URL of visitors to the site and only triggering when it detects they come from Google, thus if you come straight to the site or via a bookmark, it doesn't happen.
 
I've recreated this across several machines including a secured Linux server.
Link to comment
Share on other sites

Circo, might want to look into this ASAP. It's happening over on the HyperSpin forums as well. Thanks for the heads up Enverex.

Link to comment
Share on other sites

From Google search my Av is throwing a wobbly but from my bookmarks nothing.

Link to comment
Share on other sites

Working on it ugh, this is a battle. We stopped it once but this is happening all over with forums it seems. Cross platform as well. Only seems to affect Google search though. Will post when we have more info.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...