Hi,
my traffic went down by 70%.
I thought i got a penalty but now i saw that url123.info steals my google traffic.
Search for a phrase: Se my Board on # 3, click on ist and get reffered to url123.info.
Some Idea what i can actually do?
This is a discussion on hacked by url123.info within the Security Topics forums, part of the vBSEO SEO Plugin category; Hi, my traffic went down by 70%. I thought i got a penalty but now i saw that url123.info steals ...
Hi,
my traffic went down by 70%.
I thought i got a penalty but now i saw that url123.info steals my google traffic.
Search for a phrase: Se my Board on # 3, click on ist and get reffered to url123.info.
Some Idea what i can actually do?
Funny I've got exactly the same problem, interesting to see how you get on.
And we are not alone. :-(
And here ist another one.
So we are 4 in between a few days. I have found some other Boards via the google search with the same "hack".
I haven´t found anything, checked my templates, my database.
I have no idea where else i can take a look for this.
I hope we will find it soon to get back our visitor and traffic!
*vBSEO Security Bulletin* All Supported Versions: Patch Release
Interesting this morning I ran the utility and had to reset the datastore.
Not sure whether this will fix it but alarming none the less.
Wondering whether disabling vbSEO might be an option.
Hello,
make sure that you are running the latest version of vBSEO and try this tool to check whether there are any suspicious plugins in DB: http://www.vbseo.com/f5/faqs-rogue-p...62/#post326304
Oleg Ignatiuk / Crawlability Inc.
Security bulletin - Patch Level for all supported versions released
Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!
Same problem here. vbSEO is up to date, your check plugin tool returns OK (no results). I've searched everything, source, templates, plugins, don't see anything. But 50% of the time, direct link from google to my site redirects to url123.info.
Please open a ticket with ftp/admincp access to check this.
Oleg Ignatiuk / Crawlability Inc.
Security bulletin - Patch Level for all supported versions released
Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!
I found my issue.
It was actually embedded in the vBulletin datastore under the plugin global_start.
Go into vb_datastore table, title of 'pluginlist', search it for base64. You're likely to see something. Remove that line with the base64_decode from it which is the redirect. Since this is in a serialized array (the datastore cache), you might need to do some jiggering to remove it properly.
Also note it sets a cookie 'vbsp' so it only happens once per a certain amount of time. I didn't go into too much depth cracking into the actual exploit code.
And another site here.
Tools downloaded, emptied datastore, disabled plugin. Time will tell.
Is that enough to sort the issue or should I be looking elsewhere?
I reset the datastore the traffic has improved ever since.
I didn't worry about disabling plugins or anything else like that.
Hello,
Cleaning up the datastore, finding and killing the rogue plugins should be enough. You can check this out though:
Easy Security Tips for vBSEO customers
Andrés Durán / Crawlability Inc.
ˇvBSEO 3.6.0 GOLD Liberado!
Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!
Síguenos en: Facebook | Síguenos en: Twitter
This has been happening here the past couple of weeks, on vb 3.8.7. Something regularly targets the vbseo datastore.
The only way to clear it is to uninstall and then reinstall the vbseo plugin. However, after a while, it happens again.
Something I want to make clear is that vbseo is the main target of this, and this happened to us before last May and resulting in our biggest site getting kicked out from Google News because of it.
It's really sickening that vbseo has become such an achilles heel for big popular sites. Makes me feel like downsizing to SMF to avoid these hack attacks.
Hello Brian ,
Filestore or Tiny4url redirects have nothing to do with an exploit within vBSEO. It is directly related to server security and boards that don't have vBSEO installed are facing the same issue.
Mert Gökçeimam / Crawlability Inc.
vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!
Twitter:@Depkac
Personal Blog : Mert Gökçeimam
I have the latest version of vb4 (4.1.12) and I was hit with this malicious redirect just yesterday when I noticed on google analytics that my traffic suddenly dried up. All of the big name search results produced the redirect to URL123.INFO - free url redirection and masking service. I had this same problem before the update and now it's back.
So Mert since you claim this isn't a vbseo problem should we even bother with taking the security measures andres">Andres linked to?
Thanks!