PDA

View Full Version : This forum has been hacked with a redirect hack which sends people to various sites.



Gisioe
12-19-2016, 02:16 PM
This forum has been hacked with a redirect hack which sends people to various sites.
This happens when you do a Google or other search engine search and click on a link to the www.kysportsreport.com/forums/
https://www.google.com/search?q=site:http://www.kysportsreport.com/forums/
and is a known exploit of vBulletin powered boards.
I found more info on it here http://www.webhostchat.co.uk/business-technical-advice/29421-fix-vbulletin-redirecting-filestore72-info-url123-info-etc-redirect-google.html
Just Google it: Vbulletin redirecting to filestore72.info

Hope this is of some help to the admins

PedroDaGr8
12-19-2016, 02:22 PM
This appears to be legit. Based on what I have seen, some white-hat or grey-hat hackers have created a bot searching for this exploit and warning vBulletin admins about this. I just did as the bot said: If you search for the forum via google, the redirect occurs. Typing the link directly into your browser does not trigger the redirect.

EDIT: Further testing, the redirect doesn't trigger every time. I did get it to redirect at least once.

PedroDaGr8
12-19-2016, 04:25 PM
I wonder if this is why the REport Post function doesn't work.

dan_bgblue
12-19-2016, 04:38 PM
I have tried the instructions a few dozen times. I never got a redirect to the KSR front age link on google, but I did get one the first time I tried the KSR Forums link

dan_bgblue
12-19-2016, 04:42 PM
I did not get any funky redirects when using Bing or Yahoo and clicking on the links to the forums.

Does this mean Google has been hacked and not this site?

dan_bgblue
12-19-2016, 04:44 PM
I wonder if this is why the REport Post function doesn't work.

I have not used that function since the first few days of being on the new board when we first arrived. I do not know if that functionality has been broken for a long time or it just happened today

UKFlounder
12-19-2016, 05:25 PM
I actually used the report post function for this thread before anybody responded. It said it sent through, though I do not know if it actually did.

I had to change from default mobile style to the full site to see that option

PedroDaGr8
12-19-2016, 05:48 PM
I did not get any funky redirects when using Bing or Yahoo and clicking on the links to the forums.

Does this mean Google has been hacked and not this site?

I JUST got it to work again with google, 3 times out of like two dozen trys.. It is likely using the SourcePage function to decide when to trigger. That way regular uses (ie Admins) don't see it, but visitors would. Allows it to stick around longer.

KeithKSR
12-19-2016, 06:46 PM
I actually used the report post function for this thread before anybody responded. It said it sent through, though I do not know if it actually did.

I had to change from default mobile style to the full site to see that option

It worked. I see the thread as being flagged.

PedroDaGr8
12-19-2016, 07:18 PM
It worked. I see the thread as being flagged.

Weird, I tried to report earlier and it errored out. It worked when I tried just now. That being said, the redirect is still happening. I was able to make it happen again just now.

badrose
12-19-2016, 07:45 PM
I get redirects on Drudge a lot using Google. It doesn't happen on Firefox.

CitizenBBN
12-19-2016, 08:43 PM
Pedro -- can you check and see if it's cleared up? Have to clear cookies b/c it's set to only redirect the first time.

I think I whacked it but I'm not sure. Pain in the ass.

PedroDaGr8
12-19-2016, 10:57 PM
Pedro -- can you check and see if it's cleared up? Have to clear cookies b/c it's set to only redirect the first time.

I think I whacked it but I'm not sure. Pain in the ass.
Just tried, it didn't redirect. I'll test a few more times in the coming days and let you know.

Sent from my LGLS992 using Tapatalk

Gisioe
12-20-2016, 12:26 AM
Pedro -- can you check and see if it's cleared up? Have to clear cookies b/c it's set to only redirect the first time.

I think I whacked it but I'm not sure. Pain in the ass.

I cleared cookies and everything seems to work fine.

dan_bgblue
12-20-2016, 12:27 PM
I cleared cookies and everything seems to work fine.

By the say, thanks very much for the heads up on the issue. I really appreciate you doing so.

Darrell KSR
12-20-2016, 01:07 PM
I cleared cookies and everything seems to work fine.


By the say, thanks very much for the heads up on the issue. I really appreciate you doing so.

Same here. Appreciate your heads up, thank you very much.

UKFlounder
12-20-2016, 04:59 PM
My apologies for reporting this thread. I did not know what it meant and thought it might be a threat.

Sorry, Gisioe

Darrell KSR
12-21-2016, 05:38 AM
Reporting the thread is never bad. All it does is call attention to it, which is a good thing, as it allowed CBBN to fix whatever the issue was.