Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 03-08-2016, 06:44 AM
SaN-DeeP's Avatar
SaN-DeeP SaN-DeeP is offline
 
Join Date: Jun 2002
Location: Mumbai, India
Posts: 1,195
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Is our site infected with malware ? Kindly help

Some forum threads of Techarena are redirecting on other websites that are indexed in google. Some of the redirected websites are official sites like Lenovo, Asus, Nvidia, etc; but there are also other spam websites where the forum threads are redirecting such as Peel.com, Cognizant Infrastructure Services | Cognizant Technology Solutions, Exametc.com - Browse all India examination results and notifications of Secondary board, Higher secondary board, university, competitive examination and entrance examination, etc.

1. site:techarena.in forums techarena in - Google Search



2. site:techarena.in forums techarena in - Google Search



3. site:techarena.in forums techarena in - Google Search



4. https://www.google.co.in/search?safe...e=off&start=30



5. https://www.google.co.in/search?safe...e=off&start=40



6. https://www.google.co.in/search?safe...e=off&start=50



7. https://www.google.co.in/search?safe...=off&start=140



And there are many more issues following the same links of https://www.google.co.in/search?safe...=off&start=140
Reply With Quote
  #2  
Old 03-08-2016, 08:08 AM
SaN-DeeP's Avatar
SaN-DeeP SaN-DeeP is offline
 
Join Date: Jun 2002
Location: Mumbai, India
Posts: 1,195
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Adding another screenshot, try searching following in google without quotes:

"site:forums.techarena.in redirecto"

You will note that users are jumping away from our content to other sites.
Attached Images
File Type: jpg Untitled.jpg (70.4 KB, 0 views)
Reply With Quote
  #3  
Old 03-08-2016, 09:50 AM
SaN-DeeP's Avatar
SaN-DeeP SaN-DeeP is offline
 
Join Date: Jun 2002
Location: Mumbai, India
Posts: 1,195
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

We tried to run server scans as well. But nothing vulnerable on server software.

---------- SCAN SUMMARY -----------
Known viruses: 4313338
Engine version: 0.98.7
Scanned directories: 2276
Scanned files: 106245
Infected files: 0
Data scanned: 5928.69 MB
Data read: 9646.79 MB (ratio 0.61:1)
Time: 407.816 sec (6 m 47 s)

Scans that where done are maldet and clam Av scan, both finished negative.
Reply With Quote
  #4  
Old 03-08-2016, 09:55 AM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I just checked but all of the links in your first post are fine to me. They all link to your forum just fine.
Reply With Quote
  #5  
Old 03-08-2016, 01:27 PM
SaN-DeeP's Avatar
SaN-DeeP SaN-DeeP is offline
 
Join Date: Jun 2002
Location: Mumbai, India
Posts: 1,195
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Dave View Post
I just checked but all of the links in your first post are fine to me. They all link to your forum just fine.
Thank You,
Kindly check detailed information again in post 2
https://vborg.vbsupport.ru/showpost....61&postcount=2

--------------- Added [DATE]1457451111[/DATE] at [TIME]1457451111[/TIME] ---------------

We thought at once it was after DBSEO Pro version.. which was installed last few months ago..

But we got a reply its not because of there DBSEO software script but something else..

"This is due to a malware on your site, which is checking the referrer and redirecting when you arrive on your site from Google."
Reply With Quote
  #6  
Old 03-08-2016, 01:59 PM
z3r0's Avatar
z3r0 z3r0 is offline
 
Join Date: Apr 2005
Posts: 339
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Have you checked your plugins? the redirect stuff l've seen like that in the past was using the global_complete location, so it's worth checking through.
Reply With Quote
  #7  
Old 03-09-2016, 07:45 AM
SaN-DeeP's Avatar
SaN-DeeP SaN-DeeP is offline
 
Join Date: Jun 2002
Location: Mumbai, India
Posts: 1,195
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by z3r0 View Post
Have you checked your plugins? the redirect stuff l've seen like that in the past was using the global_complete location, so it's worth checking through.
Thank You for reply.
I have following two plugins using global_complete hook location.
Will you kindly take few minutes, helping us fix this crucial issue.

1.
Product = DragonByte Tech: Seo (Pro)
Title = Process Content: Global
Execution Order = 32767
Plugin PhP Code =
Code:
require(DIR . '/dbtech/dbseo/hooks/global_complete.php');
(attached the file global_complete.php)

2.
Product = 8WR Micro Debug
Title = micro DEBUG stats
Execution Order = 5
Plugin PhP Code =
Code:
$totaltime = microtime(true) - TIMESTART;
$templatecache = vB_Template::$template_usage;

$microdebug .= '<div class="footer_morecopyright" style="margin-top: 0px">';
$microdebug .= 'Page Time: <b>' . vb_number_format($totaltime, 5) . '</b> seconds &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;';
$microdebug .= function_exists('memory_get_usage') ? 'Memory: <b>' . number_format(memory_get_usage() / 1024) . '</b> KB &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;' : '';
$microdebug .= 'Queries: <b>' . $vbulletin->db->querycount . '</b> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;';
$microdebug .= 'Templates: <b>' . sizeof($templatecache) . '</b>';

if ($vbulletin->userinfo['usergroupid'] == 6)
{
	$templatequeries = vB_Template::$template_queries;
	$microdebug .= $templatequeries ? ' (<b>' . sizeof($templatequeries) . '</b> uncached)' : '';

	if ($uptime = @exec(uptime))
	{
		$microdebug .= '<br />';
		preg_match_all('/([\d\.]+)/',$uptime,$srv);
		$srv = $srv[1];

		if ($srv[10])
		{
			$microdebug .= 'Server Uptime: <b>' . $srv[3] . ' months ' . $srv[4] . ' days ' . $srv[5] . ' hours ' . $srv[6] . ' mins</b> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;';
			$microdebug .= 'Server Load: <b>' . $srv[8] . '</b> : ' . $srv[9] . ' : ' . $srv[10];
		}
		else if ($srv[9])
		{
			$microdebug .= 'Server Uptime: <b>' . $srv[3] . ' days ' . $srv[4] . ' hours ' . $srv[5] . ' mins</b> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;';
			$microdebug .= 'Server Load: <b>' . $srv[7] . '</b> : ' . $srv[8] . ' : ' . $srv[9];
		}
		else if ($srv[8])
		{
			$microdebug .= 'Server Uptime: <b>' . $srv[3] . ' hours ' . $srv[4] . ' mins</b> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;';
			$microdebug .= 'Server Load: <b>' . $srv[6] . '</b> : ' . $srv[7] . ' : ' . $srv[8];
		}
	}

	if ($templatequeries)
	{
		ksort($templatecache);
		$microdebug .= '<br /><table cellspacing="0" cellpadding="0" border="0" style="margin-left: auto; margin-right: auto;">';

		foreach ($templatecache AS $templatename => $times)
		{
			if ($templatequeries["$templatename"])
			{
				$microdebug .= '<tr><td style="color: red; text-align: left;"><b>' . $templatename . '</b></td><td style="padding-left: 10px;">(' . $times . ')</td></tr>';
			}
		}

		$microdebug .= '</table>';
	}
}

$microdebug .= "</div>";
$output = str_replace('</body>',$microdebug.'</body>', $output);
Attached Files
File Type: php global_complete.php (1.2 KB, 1 views)
Reply With Quote
  #8  
Old 03-09-2016, 02:26 PM
z3r0's Avatar
z3r0 z3r0 is offline
 
Join Date: Apr 2005
Posts: 339
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

They both look fine.
Reply With Quote
  #9  
Old 03-10-2016, 01:33 AM
RichieBoy67's Avatar
RichieBoy67 RichieBoy67 is offline
 
Join Date: Apr 2004
Location: CT - Down in a hole..
Posts: 3,057
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

What does google webmaster tools show?

--------------- Added [DATE]1457580944[/DATE] at [TIME]1457580944[/TIME] ---------------

Check this in another browser, clear your cookies, check browser extensions, etc. I do not see any issues here with any of your indexed links.

Sounds like your pc has malware, not your site.
Reply With Quote
  #10  
Old 03-10-2016, 07:49 AM
SaN-DeeP's Avatar
SaN-DeeP SaN-DeeP is offline
 
Join Date: Jun 2002
Location: Mumbai, India
Posts: 1,195
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank You for quick reply richie.
We thought about same first, but results appear same when tested with multiple PCs.
This is the result from a fresh Windows setup on chrome.

Kindly note the urls which are listed in Google.. When we click on them those take us to other site(s)
Attached Images
File Type: jpg infection tested with chrome on clean PC.jpg (61.0 KB, 0 views)
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:42 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06015 seconds
  • Memory Usage 2,293KB
  • Queries Executed 12 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_code
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (3)postbit_attachment
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • postbit_attachment
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete