AdrenalineX Forums

General => General Server Discussion => Topic started by: [MAF]Epoxi on January 10, 2014, 07:04:08 pm

Title: Has website been hacked?
Post by: [MAF]Epoxi on January 10, 2014, 07:04:08 pm
When I browse the forums this often happens:

(http://i.imgur.com/frBI5hG.png)

And I was once redirected to AdultFriendFinder.

I don't think it's spyware/adware on my computer because it only happens with adrenalinex.co.uk
Title: Re: Has website been hacked?
Post by: miko on January 10, 2014, 07:05:20 pm
same for me
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 10, 2014, 07:15:32 pm
And me
Title: Re: Has website been hacked?
Post by: Troublemaker on January 10, 2014, 07:18:03 pm
Same here, can't even post properly.
Title: Re: Has website been hacked?
Post by: [MAF]Epoxi on January 10, 2014, 07:19:24 pm
Did the AdultFriendFinder thing happen to you all too?
Title: Re: Has website been hacked?
Post by: [MAF]Cromiell on January 10, 2014, 07:20:22 pm
Yeah something is going on. My anti-virus is going crazy on redirection.
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 10, 2014, 07:22:43 pm
Did the AdultFriendFinder thing happen to you all too?

Not for me. Just no connection
Title: Re: Has website been hacked?
Post by: [MAF]Karlis on January 10, 2014, 07:32:40 pm
happened twice so far, no redirects tho, just no connection or block
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 10, 2014, 07:38:05 pm
KingJ at it again.

(http://i.imgur.com/KdfUOZV.png)
Title: Re: Has website been hacked?
Post by: [MAF]Karlis on January 10, 2014, 07:38:53 pm
site isn't hosted at kingj.
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 10, 2014, 07:39:52 pm
I know. It was sarcasm.
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 10, 2014, 08:53:25 pm
happened twice so far, no redirects tho, just no connection or block

same and my anti-virus found a trojan horse..
Title: Re: Has website been hacked?
Post by: nero on January 10, 2014, 10:09:14 pm
@ Cromiell / Ush: Are you using an AdBlocker?

I got the "No data recieved" too, but no redirects.
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 11, 2014, 02:33:50 am
Really weird. I refreshed about 50 times just now and I didn't even get one blank page/redirect.

If anyone gets redirected again post the URL here.
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 11, 2014, 02:40:39 am
I got directed to meatspin.com :'(

Joke.
Title: Re: Has website been hacked?
Post by: Troublemaker on January 11, 2014, 04:03:49 am
It stopped couple of hours ago for me.
Title: Re: Has website been hacked?
Post by: [MAF]Cromiell on January 11, 2014, 10:58:08 am
moo: e-mail the web hosting. It might be their fault.
Title: Re: Has website been hacked?
Post by: Exo on January 11, 2014, 12:36:11 pm
I just got redirected to this page lol
(http://s1.directupload.net/images/140111/g3bfh6at.jpg) (http://www.directupload.net)
And then my Antivirus blocked it
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 11, 2014, 01:05:13 pm
I just got redirected to this page lol
(http://s1.directupload.net/images/140111/g3bfh6at.jpg) (http://www.directupload.net)
And then my Antivirus blocked it

I had a similar adress but I clicked away before I read I should have posted it here.. and also my av gave me the signal it was no good ;_;
Title: Re: Has website been hacked?
Post by: [LSR]Cassidy on January 11, 2014, 01:20:06 pm
I just got redirected to this page lol
(http://s1.directupload.net/images/140111/g3bfh6at.jpg) (http://www.directupload.net)
And then my Antivirus blocked it
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 11, 2014, 01:34:44 pm
Have any of you been redirected while on one of the following parts of the site?
http://adrenalinex.co.uk
http://tools.adrenalinex.co.uk
http://blog.adrenalinex.co.uk

thanks
Title: Re: Has website been hacked?
Post by: [MAF]Karlis on January 11, 2014, 01:38:13 pm
doesn't happen for me after about 50 refreshes.
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 11, 2014, 01:39:11 pm
try using the "next »" link.. i think it might have something to do with it
Title: Re: Has website been hacked?
Post by: [MAF]Karlis on January 11, 2014, 01:43:59 pm
uhh, where is it?
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 11, 2014, 01:44:59 pm
near the top and bottom of every forum thread
Title: Re: Has website been hacked?
Post by: Exo on January 11, 2014, 02:00:48 pm
Have any of you been redirected while on one of the following parts of the site?
http://adrenalinex.co.uk
http://tools.adrenalinex.co.uk
http://blog.adrenalinex.co.uk

thanks
Happens only on http://forum.adrenalinex.co.uk for me
Title: Re: Has website been hacked?
Post by: Uitblinker on January 11, 2014, 02:26:57 pm
try using the "next »" link.. i think it might have something to do with it

Actually do not do this. It brings you to another website which contains a trojan-horse. Luckily my anit-virus scanner blocked it though.

Might not visit this website for a couple of days.
Title: Re: Has website been hacked?
Post by: nero on January 11, 2014, 02:39:41 pm
Just had this again after some visits without. Had to reload this topic 4-5 times (always with "no data recieved"-message) before it loaded the actual topic.
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 11, 2014, 03:18:59 pm
I've contacted our web host because as far as I can tell there is no problem with the forum.
Title: Re: Has website been hacked?
Post by: [MAF]Agus on January 11, 2014, 03:50:19 pm
Strange, I haven't had a single problem of the ones you are mentioning lol, the forum always loads and never sends me to another page.
Title: Re: Has website been hacked?
Post by: BorderLine on January 12, 2014, 03:58:46 am
I don't have any problems with the website do you still have it?  :(
Title: Re: Has website been hacked?
Post by: [LSR]Jalicno on January 15, 2014, 10:08:52 am
Got this minute ago...
http://adultfriendfinder.com/go/page/landing_page_ffadult_20?pid=p1011105.subdirs&ip=auto&no_click=1&alpo_redirect=1
Title: Re: Has website been hacked?
Post by: nero on January 15, 2014, 10:35:34 am
Same here:
http://adultfriendfinder.com/go/page/landing_page_ffadult_20?pid=p1011105.subdirs&ip=auto&no_click=1&alpo_redirect=1

Title: Re: Has website been hacked?
Post by: [2F2F]Hellmuth on January 15, 2014, 10:38:03 am
just got redirected to this URL http://1u5p1c3x8fruf19ds529vwn20135383de3d957495518a09b6d7637f0.youraustinpartybus.com/index2.php when I pressed "new" on what are you listening to now?
Title: Re: Has website been hacked?
Post by: Scorpion. on January 15, 2014, 10:46:16 am
guys use extension for chrome or mozilla

are called "Adblock" and "Do no track me"

in part, solves something and do not come redirected in other website
Title: Re: Has website been hacked?
Post by: Exo on January 15, 2014, 10:51:43 am
I'm using an Adblocker but it still happens to me
Title: Re: Has website been hacked?
Post by: Troublemaker on January 15, 2014, 11:17:12 am
I'm using an Adblocker but it still happens to me

Same here.
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 15, 2014, 11:20:00 am
And the blank pages are also still here..
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 15, 2014, 11:22:43 am
Strange, I haven't had a single problem of the ones you are mentioning lol, the forum always loads and never sends me to another page.
Title: Re: Has website been hacked?
Post by: 3DSexVilla on January 15, 2014, 11:49:35 am
adultfriend here too
Title: Re: Has website been hacked?
Post by: Scorpion. on January 15, 2014, 01:00:52 pm
I'm using an Adblocker but it still happens to me
and "do not track me" ;_; ?


Strange, I haven't had a single problem of the ones you are mentioning lol, the forum always loads and never sends me to another page.
Just many times like in the morning , the website fail to load but if i refresh load normaly
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 15, 2014, 01:31:08 pm
Just constant not page loading actually for me
Title: Re: Has website been hacked?
Post by: Scorpion. on January 15, 2014, 01:38:30 pm
yeah ,that i wanted to say
 :)
Title: Re: Has website been hacked?
Post by: pajk on January 15, 2014, 02:02:24 pm
i'm not experiencing any problems with adultfriender or some other trash, all is fine for me
Title: Re: Has website been hacked?
Post by: ivanduk on January 15, 2014, 02:21:59 pm
Strange, I haven't had a single problem of the ones you are mentioning lol, the forum always loads and never sends me to another page.
Title: Re: Has website been hacked?
Post by: [MAF]Karlis on January 15, 2014, 02:24:35 pm
firefox 29.1a beta here, no issues whatsoever.
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 15, 2014, 03:37:50 pm
I don't think it's very usefull to say you experience no problems.. fact is that a lot of us experience problems and that we have to find a solution for it.. and I don't think all going to FF + adblocker is that solution, although it helps. We just need to get rid of these ads.. and find out how they come here in the first place.
Title: Re: Has website been hacked?
Post by: nero on January 15, 2014, 03:58:01 pm
It definetly isn't an ad, AdBlock would just block it. Even AdBlock-users like me get these redirects.

Also the random appearance is a sign it's not client-based but more of a host-based problem. What I discovered is that at least for me, I only get redirects when clicking on "forum-generated-standard-links", like "Unread posts" ( /index.php?action=unread) or stuff like that, never to specific posts (/index.php/topic,47.0/topicseen.html). I can't really verify this, but at least for me, this is true for the few times I got a redirect.

Interesting would be, what the redirects looks like in surf history, is it only a "direct redirect" or is the redirect across some sort of "spreader"-url which then redirects again to adultfriendfinder and others depending on user location.
Title: Re: Has website been hacked?
Post by: [2F2F]Hellmuth on January 15, 2014, 04:24:46 pm
well I have FF+adblock and it happen to me..
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 15, 2014, 08:07:41 pm
Even if you experience no problems it's best to write it here so I can see what's causing it.
Title: Re: Has website been hacked?
Post by: [MAF]Cromiell on January 15, 2014, 08:13:28 pm
But did you e-mail the hosting?
Title: Re: Has website been hacked?
Post by: [MAF]Agus on January 15, 2014, 08:19:49 pm
Like I said, I have no problems at all, and what I didn't say in my last post was that I don't have ad-blocker or any other blocker of that kind, just ESET antivirus, and I use Firefox 26.0
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 15, 2014, 10:27:31 pm
But did you e-mail the hosting?
i did and they asked how to replicate.. which i'm not sure yet
Title: Re: Has website been hacked?
Post by: BorderLine on January 16, 2014, 11:55:54 am
Seems like the entire Europe continent have this problem. Does the Yahoo World-Wide Malware Attack has something to do with this?
Title: Re: Has website been hacked?
Post by: [MAF]Cromiell on January 16, 2014, 12:41:07 pm
Also moo, it can be caused by some of scripts/plugins you use on the website/forum. It's a rare case but it might be... So if you installed something new lately - look into it.
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 16, 2014, 01:31:49 pm
Hm indeed but the last thing installed was the spoiler tag thing and that was ages ago
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 16, 2014, 01:40:22 pm
/me thinks everyone should go to the fastest, most secure, and most amazing internet browser ever.

Internet Explorer.
Title: Re: Has website been hacked?
Post by: nero on January 16, 2014, 03:01:58 pm
Would be interesting to see if this only happens to certain browsers. I already checked my installed plugins and extensions, but nothing suspicious there.

Using Chrome btw.
Title: Re: Has website been hacked?
Post by: Mute. on January 16, 2014, 05:47:04 pm
Even if you experience no problems it's best to write it here so I can see what's causing it.

i sometimes have the page not load but it loads after i refresh it a couple of times, and it hasn't happened in a couple of days, idk if this helps
Title: Re: Has website been hacked?
Post by: nero on January 16, 2014, 06:24:13 pm
Oh, what just came to my mind:

When the page doesn't load and the message "no data recieved" is shown by browser, it could also just be a malfunction of the redirect-shit-thing.
Title: Re: Has website been hacked?
Post by: BorderLine on January 17, 2014, 11:07:21 am
/me thinks everyone should go to the fastest, most secure, and most amazing internet browser ever.

Internet Explorer.
I use IE before. If only I could get used to it fast  :(  :L
Title: Re: Has website been hacked?
Post by: Rob_Zamora on January 17, 2014, 01:31:52 pm
I don't get any redirects, nor do I get the cannot connect thing. The cannot connect thing only happens when server goes down.

Using Chrome, no adblock or any other plug-ins for chrome
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 17, 2014, 01:44:12 pm
Seems like the problem is Europe based
Title: Re: Has website been hacked?
Post by: nero on January 20, 2014, 02:35:18 pm
Just happened again, here is a screenshot of the redirect in browser history:

(http://abload.de/img/bildschirmfoto2014-01e2iv7.png)


Browser is Mozilla Firefox 26.0
Browser Plugins:
- AdBlock Plus
- ProxTube
- ColorZilla
- FireBug
- MeasureIt
- TinEye Reverse Image Search

The redirect happened after I clicked on the "Unread posts since last visit" link.
Title: Re: Has website been hacked?
Post by: [LSR]Jalicno on January 20, 2014, 02:56:07 pm
I think its hosting fault cause same problems started on LSR forum 10 minutes ago...i am 100 percent sure whole forum code is clean and there no any recently mods installed
Title: Re: Has website been hacked?
Post by: pajk on January 20, 2014, 03:27:31 pm
Happened to me first time today on android phone. (Adultfriender)
Title: Re: Has website been hacked?
Post by: [MAF]Agus on January 20, 2014, 03:36:07 pm
Happened for the first time to me, it redirected me to some weird page I didn't know, but I forgot to copy it :(
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 20, 2014, 04:07:09 pm
blank page..
Title: Re: Has website been hacked?
Post by: nero on January 20, 2014, 05:31:13 pm
Aaaaand again, this time with Chrome 32.0

Here is the browser history:
(http://abload.de/img/unbenannt4iqio.jpg)

And, next story, asked a friend of mine who has a lot of knowledge with servers/databases etc., he googled "adrenalinex", clicked on link and got also redirected to:
[spoiler=Don't click link]http://saj9j6p2dg38fo9y69jhnlp.blognotu.com/index.php?y=dXFrb3NsaT1jaHNtJnRpbWU9MTQwMTIwMTUxNDgwNDU2MjQ4MSZzcmM9MTMmc3VybD1hZHJlbmFsaW5leC5jby51ayZzcG9ydD04MCZrZXk9RkE1ODJFOTYmc3VyaT0v[/spoiler]

Edit: After browsing the forum for some minutes now, I get 50 % of the time "no data recieved" messages when clicking a forum link.
Title: Re: Has website been hacked?
Post by: Troublemaker on January 20, 2014, 06:04:23 pm
Edit: After browsing the forum for some minutes now, I get 50 % of the time "no data recieved" messages when clicking a forum link.

Same here, I whether get that message or redirect to some of already mentioned pages...
Title: Re: Has website been hacked?
Post by: [RSD]Seoson on January 20, 2014, 06:09:28 pm
Hello guys,

I've just signed up because "nero" asked me if I could investigate what's happening with your forums (And I loved AX on GTA:U). I can confirm that the website is randomly redirecting me to different sites.

One example:
Code: [Select]
http://saj9j6p2dg38fo9y69jhnlp.blognotu.com/index.php?y=dXFrb3NsaT1jaHNtJnRpbWU9MTQwMTIwMTUxNDgwNDU2MjQ4MSZzcmM9MTMmc3VybD1hZHJlbmFsaW5leC5jby51ayZzcG9ydD04MCZrZXk9RkE1ODJFOTYmc3VyaT0vDO UNDER NO CIRCUMSTANCES OPEN UP THIS LINK IF YOU DON'T KOW WHAT YOU DO!

That happened while accessing the main website, so it seems that if something is going wrong not only your forums are affected. Also I can confirm that the webserver interrupts my connection sometimes.

Without knowing further details - I will need some time to reproduce and capture what is going on -  I would highly suggest verifying the binaries of your webserver if you have access to them or contact your hosting provider to do so.
I've recently red about black hats doing exactly the same as described here: Changing the server binaries and randomly redirecting none admins.

I will update my post or push this thread when I've got anything new.

Best regards,
Seoson
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 20, 2014, 06:34:52 pm
Also admins are having redirecting problems here.
Title: Re: Has website been hacked?
Post by: [MAF]Epoxi on January 20, 2014, 06:54:20 pm
Stopped happening for a while but happening again for me too:

(http://i.imgur.com/PQAdXea.png)
Title: Re: Has website been hacked?
Post by: [LSR]Jalicno on January 20, 2014, 07:05:13 pm
Also admins are having redirecting problems here.
As i wrote in upper post,doesnt matter who you are admin or regular user. I am having same problem on LSR forum. You should check your forum aswell to make sure mooman contact KJ with full list of details if same stuff happens on yours cause i am pretty sure you use clean SMF theme without any add-on if am correct  ;)
Title: Re: Has website been hacked?
Post by: [FSR]Ush on January 20, 2014, 07:41:25 pm
I didn't have problems on my page yet, but I am not much around there. I will check more often from now on, to see if there's any problem as well.
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 20, 2014, 07:52:23 pm
thanks all, i've submitted another ticket to the hosting company, hopefully they'll sort it out
Title: Re: Has website been hacked?
Post by: [RSD]Seoson on January 20, 2014, 07:56:48 pm
O.K.

I can now proof and reproduce what is going on.

The webserver, a PHP script, a htaccess file or similiar configuration file (depends on webserver, OS and configuration) is redirecting the user using a 302 redirect to other websites.

Proof:
http://cloud.kab-s.de/public.php?service=files&t=5e6ec7531188453cfe77f89c3d72673d
In the lower right corner you can identify the answer from host "adrenalinex.co.uk" as a 302 redirect by the "Location:" tag. It's redirecting you to some strange website where traffic management is handled and the user is redirected again a few times to obfuscate what's going on. After a few seconds the user is redirected to a landing page with some randome ads or maleware.

How to reproduce (DON'T DO THAT IF YOU DON'T KNOW WHAT YOU DO):
1. Logout from this forum
2. Close any tabs in your browser that are related to AX.
3. Clear your cookies as well as your browser's cache.
4. Restart your router for a new IP (This won't work with static IPs)
5. Go to google.de (or the correspondig google website for your country)
6. Search for "adrenalin x"
7. Click on "AdrenalineX Racing - play.adrenalinex.co.uk:7777"
8. I was redirected with a chance of about 90%. (From Germany with Firefox)

It appears that you have to match certain conditions, because I was unable to reproduce this in Chrome. I've logged all the traffic using smartsniff so I'm relatively sure that this is not related to adware.

If you (Admins) are sure that this is not related to a security breach on your side, you should contact your hoster right away. If I were you I would also think about changing your hosting provider. If any assistance is required me and I think alos the rest of the RSD-Clan are willing to help you out.

Please note: I'm not a native speaker ;-)

Best regards,
Seoson
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 20, 2014, 08:01:06 pm
Just got this email from our host:
Quote
Hi

We have identified a security issue on our cPanel server "web1" which is causing intermittent timeout and redirection issues for some users. The best way of ensuring this is completely resolved is to reinstall the server, so that is what we are currently organising.

The maintenance will be carried out as follows:

1. A new full backup of all account data will be taken. This was started at 19:30 GMT and we expect it to finish around 21:30

2. Once the backup is complete, the server will be re-installed with CentOS Linux and cPanel. (Approx 2hrs)

3. The server will be configured/secured (Approx 30mins)

4. We will initiate restore of account data, and will monitor the progress, restoring Dedicated IP's and SSL certificates (If applicable to your account) automatically. This will likely take several hours to complete as accounts will be restored one by one.

Updates will be posted on our blog www.pcsmarthosting.net if there are any issues or delays.

We apologize for any inconvenience this may cause, however this is the best option available to us to ensure the integrity of your data, and security of the server and your websites.

Kind Regards,

The PCSmart Team
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 20, 2014, 11:03:52 pm
Things should be ok now. If anything weird happens again post here with details. I'm not sure how much my emails influenced our host but, in any case, thanks everyone for posting information here.
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 20, 2014, 11:32:12 pm
bleh or not!
Quote
Hi

Due to some issues at our datacentre we have been unable to complete the works tonight as planned.

We will be rescheduling this in due course, in the meantime we are doing what we can to keep the service as stable as possible.

Kind Regards,

The PCSmart Team
Title: Re: Has website been hacked?
Post by: [MAF]Snoopy on January 20, 2014, 11:34:45 pm
I love KingJ

KJ 2008-2014 <3
Title: Re: Has website been hacked?
Post by: RuBenXitoH on January 22, 2014, 07:44:25 pm
page is back but ''Players'' section isn't working for me..
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 22, 2014, 07:50:13 pm
site isn't fully restored yet, working with host to fix it
Title: Re: Has website been hacked?
Post by: [MAF]mooman on January 23, 2014, 07:11:49 am
everything should be ok now
Title: Re: Has website been hacked?
Post by: [LSR]Jalicno on January 23, 2014, 08:40:24 am
There is 2.0.7(SMF) available for few days already, i have installed this morning since my forum is completely messed up
Title: Re: Has website been hacked?
Post by: [MAF]Aj_Lajk_Bir on February 06, 2014, 09:38:47 pm
good i wasn't on forum while that shit