Author Topic: solarsponge website flagged by google as harmful  (Read 2596 times)

0 Members and 1 Guest are viewing this topic.

Offline PsiTopic starter

  • Super Contributor
  • ***
  • Posts: 9946
  • Country: nz
solarsponge website flagged by google as harmful
« on: August 23, 2013, 09:05:51 am »
Not sure whats happening but Daves solar sponge website is currently flagged by google as harmful.

Greek letter 'Psi' (not Pounds per Square Inch)
 

Offline GeoffS

  • Supporter
  • ****
  • Posts: 1272
  • Country: au
Re: solarsponge website flagged by google as harmful
« Reply #1 on: August 23, 2013, 09:17:04 am »
I get no warning when accessing it.
 

Offline PsiTopic starter

  • Super Contributor
  • ***
  • Posts: 9946
  • Country: nz
Re: solarsponge website flagged by google as harmful
« Reply #2 on: August 23, 2013, 09:24:40 am »








« Last Edit: August 23, 2013, 09:29:23 am by Psi »
Greek letter 'Psi' (not Pounds per Square Inch)
 

Offline ve7xen

  • Super Contributor
  • ***
  • Posts: 1193
  • Country: ca
    • VE7XEN Blog
Re: solarsponge website flagged by google as harmful
« Reply #3 on: August 23, 2013, 09:47:58 am »
Looks like a redirect hijack, see: http://blog.sucuri.net/2010/04/conditional-redirects-or-the-htaccess-malware.html . Probably the account was compromised and an .htaccess file added to perform this redirect. You can confirm this behaviour yourself, if you're willing to touch the dirty server, which for some reason redirects to Bing, I guess for referral points?:

Quote
$> wget -q -O /dev/null -S --referer=http://www.google.com/ http://www.solarsponge.com
  HTTP/1.1 301 Moved Permanently
  Date: Fri, 23 Aug 2013 09:47:20 GMT
  Server: Apache
  Location: http://telenaro.net/uploadclient/traf.php
  Content-Length: 249
  Keep-Alive: timeout=5, max=100
  Connection: Keep-Alive
  Content-Type: text/html; charset=iso-8859-1

  HTTP/1.1 302 Found
  Date: Fri, 23 Aug 2013 09:47:18 GMT
  Server: Apache/2.2.22 (Ubuntu)
  X-Powered-By: PHP/5.3.10-1ubuntu3.6
  Location: http://www.bing.com/?FORM=MFEHPG&PUBL=GOOGLE&CREA=userid1743gophrasefphumem2khvlw7ml8dkb3h3kcgsoxz622
  Vary: Accept-Encoding
  Content-Length: 0
  Keep-Alive: timeout=15, max=256
  Connection: Keep-Alive
  Content-Type: text/html

  HTTP/1.0 200 OK
  Cache-Control: private, max-age=0
  Content-Type: text/html; charset=utf-8
  P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND"
  Date: Fri, 23 Aug 2013 09:47:11 GMT
  Connection: close
  Set-Cookie: _FP=EM=1; expires=Sun, 23-Aug-2015 09:47:11 GMT; domain=.bing.com; path=/
  Set-Cookie: _FS=NU=1; domain=.bing.com; path=/
  Set-Cookie: _SS=SID=0C2703FD5F1E4C0D9FB07A1CD4986FE4&C=20.0; domain=.bing.com; path=/
  Set-Cookie: MUID=1787A9BB28076C4335ECAC8929146CFB; expires=Sun, 23-Aug-2015 09:47:11 GMT; domain=.bing.com; path=/
  Set-Cookie: MUIDB=1787A9BB28076C4335ECAC8929146CFB; expires=Sun, 23-Aug-2015 09:47:11 GMT; path=/
  Set-Cookie: OrigMUID=1787A9BB28076C4335ECAC8929146CFB%2c569dce9d988941259c2625f49289cea5; expires=Sun, 23-Aug-2015 09:47:11 GMT; domain=.bing.com; path=/
  Set-Cookie: SRCHD=D=2968427&MS=2968427&AF=MFEHPG; expires=Sun, 23-Aug-2015 09:47:11 GMT; domain=.bing.com; path=/
  Set-Cookie: SRCHUID=V=2&GUID=7EB4632EF1D340FDA172C36F98AFE2A4; expires=Sun, 23-Aug-2015 09:47:11 GMT; path=/
  Set-Cookie: SRCHUSR=AUTOREDIR=0&GEOVAR=&DOB=20130823; expires=Sun, 23-Aug-2015 09:47:11 GMT; domain=.bing.com; path=/

« Last Edit: August 23, 2013, 09:51:11 am by ve7xen »
73 de VE7XEN
He/Him
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf