ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

HELP! Google Alerts Returning Hijacked Link

November 12, 2010 4:53pm

Subscribe [5]
  • #1 / Nov 12, 2010 4:53pm

    nessnzoe

    62 posts

    Hi EE,

    One of my clients, http://www.ruralintelligence.com forward me a google alert:

    Rural Intelligence | Credit Card Application
    Rural Intelligence > Member List > Credit Card Application. Credit Card Application. Member Group: Members. View all posts by this member ยท Ignore Member ...
    http://www.ruralintelligence.com/index.php/member/9064/

    This link goes to a page that says that the page has been moved with a link to another site. I’m gathering that RI has been hacked. Can you help with what I need to do about this? I’m going through all the pending members and deleting them. Is there a way to find this and delete it asap?

    Thanks,
    Vanessa

  • #2 / Nov 13, 2010 6:13pm

    Greg Salt

    3988 posts

    Hi Vanessa,

    This link http://www.ruralintelligence.com/index.php/member/9064/ does not seem to point to another site. It just shows that the member ID 9064 has been either deleted or banned by the site administrators. Unfortunately there is a fair amount of profile spam on the site and it might be these links that are generating the Google Alerts. This does not mean that the site has been hacked. You should at the very minimum set up member registration notifications for you and your clients so that you can monitor these registrations. In addition, there is a blog post and associated forum thread with a lot of information and ideas about how to combat profile spam.

    Cheers

    Greg

  • #3 / Nov 13, 2010 6:37pm

    nessnzoe

    62 posts

    Thanks Greg. I did manage to figure out how to delete the member from the database, but I’ll definitely look at the information above to familiarize myself with other tools we can put in place.

    Best,
    Vanessa

  • #4 / Nov 14, 2010 3:32pm

    Greg Salt

    3988 posts

    Hi Vanessa,

    Okay. Can you clarify something? I understand that you have deleted the member that would have been shown here http://www.ruralintelligence.com/index.php/member/9064/ but are you saying that before this member was deleted visiting this URL directly redirected you away to another site?

    Cheers

    Greg

  • #5 / Nov 14, 2010 4:26pm

    nessnzoe

    62 posts

    No. For one brief flash of a second, you could see the member page (like this one: http://www.ruralintelligence.com/index.php/member/9063/) then it resolved to an almost blank page that said “This page has been moved. Click here.” with a link to another website. In fact the entire browser window was one giant hotspot. When I viewed the source code it had all this hidden text that was about credit card applications.

    Thanks, Greg.

  • #6 / Nov 15, 2010 8:16am

    Sue Crocker

    26054 posts

    Time to delete that member too. 😊 Is everything OK now?

  • #7 / Nov 15, 2010 12:05pm

    nessnzoe

    62 posts

    Hi Sue,

    Yes.  :red: Other than the fact that I have to go through 3 years of members and decide who needs to be deleted!!  :ahhh:

    Is there an easier way to find users that are spam besides going one by one through the member list? I have hesitated for a long time in deleting members that get activated because it’s hard to tell sometimes whether a username is legitimate through View Members in the Admin. Any suggestions?

    Thanks, much!
    Vanessa

  • #8 / Nov 16, 2010 3:33am

    John Henry Donovan

    12339 posts

    Vanessa ,

    I would advise against deleting members but banning them instead.That way they wont be back with any of those details. Have a look at Member Utilities which may speed up you user spam search and banning

  • #9 / Nov 17, 2010 1:45am

    nessnzoe

    62 posts

    Thanks, John Henry. I’ll definitely need this as there are some 8K members that need to get cleaned up.

    Oy.

    😊

  • #10 / Nov 17, 2010 4:02pm

    Ingmar

    29245 posts

    So, does that solve it for you? Let us know if you need anything else, please.

  • #11 / Nov 17, 2010 7:00pm

    nessnzoe

    62 posts

    Hi Ingmar,

    Yes, it does. Please go ahead and close.

    Thanks everyone!
    Vanessa

  • #12 / Nov 18, 2010 4:39am

    Ingmar

    29245 posts

    Excellent. Please post again as needed.

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases