Fox T-Bird/Cougar Forums

General => Lounge => Topic started by: Masejoer on January 15, 2017, 03:39:33 PM

Title: Forum getting hijacked
Post by: Masejoer on January 15, 2017, 03:39:33 PM
This happens with some known Vbulletin exploit. I came here today and received a "MyFilestore.com - Your Free File Hosting" hijack page. For years on random vbulletin sites, if you see this page and go back in the browser, then re-load the compromised forum, the correct page will load. I was using a Google search to search this forum and clicked on one of the results, then received this page.

Just a heads-up - there's an issue on the forum host that needs to be addressed. I've seen these specific hijack on various sites for many years. It's server-side, not client-side ,so anyone that sees this hijack page shouldn't think their own computer is compromised.

A useful post on the topic: https://internetlifeforum.com/vbulletin/3071-vbulletin-redirection-hack-infection-only-one-time-google-fix/
Title: Forum getting hijacked
Post by: Thunder Chicken on January 15, 2017, 04:40:09 PM
Interesting, I'll have to let URLJet (our host) know

*EDIT* Just submitted a support ticket
Title: Forum getting hijacked
Post by: Masejoer on January 16, 2017, 11:44:14 AM
Quote from: Thunder Chicken;458908
Interesting, I'll have to let URLJet (our host) know

*EDIT* Just submitted a support ticket

Good to hear. I see such a thing once every few months during web searches and clicking-through a link to some random vbulletin forum. If you search "MyFilestore.com - Your Free File Hosting"" on a search engine and click though any of the links, you can often see the hijack page on some random compromised forum once, then if you load the same result again, the actual forum page loads.

I think I first saw such a hijack on the autogeekonline forum some 5+ years ago. Thing is - it's not easy to spot as a forum owner. Once you know how to reproduce it though, it's consistent.

How to reproduce:

1. Load https://www.google.com/search?q=site%3Afoxtbirdcougarforums.com+foglight&ie=utf-8&oe=utf-8
2. Right-click on a search result and open in a private window/incognito

The hijacked page always appears this way.
Title: Forum getting hijacked
Post by: V8Demon on January 16, 2017, 02:30:18 PM
Yup.  Happened to me as well.  Twice this week.