Sites redirecting to asklots.com

DooLocsta

[H]ard|Gawd
Joined
Jan 26, 2005
Messages
1,875
I have some strange things happening on 2 of my webservers and wanted to know if anyone had any ideas. I have a few sites on different servers that will start jumping to an asklots.com/jump1 or similar. The strange thing about this is that it will happen for an hour straight and then as quick as it is happening it is gone with out a trace. I have checked everything I know on the web servers and SQL servers and can't find any time of rogue code or SQL injection. I have read a few things about some firefox google virus but this is happening in IE and also happening on my MAC in Safari so I am really stumped. Just wondering if you guys may have any idea on what I can check becuase I can't find anything.
 
We only run internal ads on the site that we create there aren't any external sources. We have a live chat feature that does call out but we turned that off and were still hit with it.
 
Would you mind giving us a URL to one of your sites? I could look for any javascript that may be causing it, or see if it's being redirected in the HTTP headers.
 
Would you mind giving us a URL to one of your sites? I could look for any javascript that may be causing it, or see if it's being redirected in the HTTP headers.

Sure the one that I am most concerned about it www.warehouseskateboards.com. Since this started happening randomly in the last 3 days our orders have tanked. Another site on a different server that it was happening to is www.wblivesurf.com.

Thanks for the help.

It is being redirected in the headers when it is happening and that is why it is so strange becuase it happens randomly. It is pulling http://66.240.153.188/aff.php and also going http://xmlfind.net/aff/portal.php. When the redirects are happening I can't find any instance of this in the sites or the databases. It is like it is happening on the fly. At this time it is not redirecting so it is really hard to troubleshoot but I am sure as soon as I am ready to relax it will start up again.
 
Last edited:
Spyware.

Read the sticky

I have to disagree, I have read the sticky in the past and ran everything I have even known against the server and it comes up squeeky clean. I do appreciate the feedback though.
 
sorry didn't read all the way didn't see webserver though home machine.

something with dns =)
 
sorry didn't read all the way didn't see webserver though home machine.

something with dns =)
Well, he says it's redirecting in the headers, like Location: blah. So, it can't be the DNS. I have yet to have it happen to me, but I'll keep refreshing the page throughout the day.
 
Yeah it is definately in the headers and I know it is hard to troubleshoot while it isn't doing it. I will paste a copy of the header log when it did it below.

GET /urchin.js HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Tue, 28 Jul 2009 18:02:15 GMT
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: ssl.google-analytics.com
Connection: Keep-Alive

HTTP/1.1 304 Not Modified
Last-Modified: Tue, 28 Jul 2009 18:02:15 GMT
Date: Thu, 13 Aug 2009 22:57:49 GMT
Cache-Control: max-age=604800, public
Server: Golfe

GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 55958
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG; path=/
Date: Thu, 13 Aug 2009 22:57:48 GMT

GET /warehouseskateboards.css HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Sat, 25 Jul 2009 13:29:16 GMT
If-None-Match: "a0c31de82bdca1:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 13900
Content-Type: text/css
Last-Modified: Sat, 25 Jul 2009 13:29:16 GMT
Accept-Ranges: bytes
ETag: "a0c31de82bdca1:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:48 GMT

GET /includes/clientside/globalFunctions.js HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Fri, 12 Dec 2008 20:57:05 GMT
If-None-Match: "76934d309c5cc91:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 9879
Content-Type: application/x-javascript
Last-Modified: Fri, 12 Dec 2008 20:57:05 GMT
Accept-Ranges: bytes
ETag: "76934d309c5cc91:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /__utm.gif?utmwv=1.3&utmn=1243569835&utmcs=windows-1252&utmsr=1920x1200&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=10.0%20r22&utmdt=Skateboards%20-%20Warehouse%20Skateboards%20offers%20Complete%20Skateboards%2C%20Skateboard%20Decks%2C%20Trucks%2C%20Wheels%20%26%20Much%20More!&utmhn=www.warehouseskateboards.com&utmhid=505836003&utmr=-&utmp=/ HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 35
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:58:30 GMT
Accept-Ranges: bytes
ETag: "ec80b058d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /__utm.gif?utmwv=1.3&utmn=1243569835&utmcs=windows-1252&utmsr=1920x1200&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=10.0%20r22&utmdt=Skateboards%20-%20Warehouse%20Skateboards%20offers%20Complete%20Skateboards%2C%20Skateboard%20Decks%2C%20Trucks%2C%20Wheels%20%26%20Much%20More!&utmhn=www.warehouseskateboards.com&utmhid=505836003&utmr=-&utmp=/&utmac=UA-68176-1&utmcc=__utma%3D90198812.636266065.1250202761.1250202761.1250203501.2%3B%2B__utmz%3D90198812.1250202761.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none)%3B%2B HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.google-analytics.com
Connection: Keep-Alive

HTTP/1.1 200 OK
Content-Length: 35
Date: Sun, 19 Jul 2009 17:30:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:50:30 GMT
Content-Type: image/gif
Server: Golfe

GET /script/ScriptServlet?aid=1EN9QV16R32BUUQ4QTAFGCIPQ0S HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: srv1.wa.marketingsolutions.yahoo.com
Connection: Keep-Alive
Cookie: B=5d5mnth54hmjk&b=3&s=0t; SO=v=0.4&t=1241808242; YLS=v=1&p=0&n=1; F=a=FCYzL7QMvTJACHcB3GLLaNcA1j6XUO0K9CUC0kAdySZwOKECabE3Nqbh3oqg50M5zx2mzQ0-&b=z1Lu; PH=fn=M6maYImOF6OxkrSuag--&l=en-US; C=mg=1; YSC=0; cna=T2WcAveCeQoBAZrSahgowEYL; SYSTEM_USER_ID=S4HOI7DC9D7FQNAIQHT712RNCS

HTTP/1.1 200 OK
Date: Thu, 13 Aug 2009 22:57:51 GMT
P3P: policyref = "http://p3p.yahoo.com/w3c/p3p2.xml", CP = "NOI DSP COR NID ADMa OUR STP COM NAV PRE"
Expires: Thu, 13 Aug 2009 22:57:51 GMT
Cache-Control: private
Connection: close
Transfer-Encoding: chunked
Content-Type: text/javascript
Content-Encoding: gzip

GET /includes/clientside/register.js HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 13 Aug 2009 21:45:48 GMT
If-None-Match: "af3bc26b5f1cca1:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 25094
Content-Type: application/x-javascript
Last-Modified: Thu, 13 Aug 2009 21:45:48 GMT
Accept-Ranges: bytes
ETag: "af3bc26b5f1cca1:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /flash_home/AC_RunActiveContent.js HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 13 Aug 2009 22:23:29 GMT
If-None-Match: "6d885faf641cca1:1ecd"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 8321
Content-Type: application/x-javascript
Last-Modified: Thu, 13 Aug 2009 22:23:29 GMT
Accept-Ranges: bytes
ETag: "6d885faf641cca1:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /images/blank.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:05 GMT
If-None-Match: "c02c6e2d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:05 GMT
Accept-Ranges: bytes
ETag: "c02c6e2d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /images/a_bullet.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:03 GMT
If-None-Match: "4a4f2c1d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 323
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:03 GMT
Accept-Ranges: bytes
ETag: "4a4f2c1d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /hc/30084425/?cmd=rating&site=30084425&type=indicator HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: server.iad.liveperson.net
Connection: Keep-Alive
Cookie: HumanClickID=-1440628355870-1250203607:-1:-1:-1:-1; HumanClickKEY=124311397328331345; HumanClickSiteContainerID_30084425=STANDALONE; HumanClickID=-1440628355870; HumanClickACTIVE=1250203831902

HTTP/1.1 302 Moved Temporarily
Date: Thu, 13 Aug 2009 22:57:51 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
Set-Cookie: HumanClickSiteContainerID_30084425=STANDALONE; path=/hc/30084425
Location: /hcp/pixel.gif?d=1250204271932
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 0

GET /meter/survey/www.warehouseskateboards.com/12.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 13 Aug 2009 21:55:03 GMT
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: images.scanalert.com
Connection: Keep-Alive

HTTP/1.1 304 Not Modified
Content-Type: image/gif
Last-Modified: Thu, 13 Aug 2009 11:46:56 GMT
Date: Thu, 13 Aug 2009 22:57:51 GMT
Connection: keep-alive
Cache-Control: max-age=0
Expires: Thu, 13 Aug 2009 11:46:56 GMT

GET /images/top_bg.jpg HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:57:10 GMT
If-None-Match: "d02af328d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 10143
Content-Type: image/jpeg
Last-Modified: Thu, 07 Aug 2008 20:57:10 GMT
Accept-Ranges: bytes
ETag: "d02af328d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /images/bg.jpg HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:05 GMT
If-None-Match: "207482d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG
 
HTTP/1.1 200 OK
Content-Length: 30401
Content-Type: image/jpeg
Last-Modified: Thu, 07 Aug 2008 20:56:05 GMT
Accept-Ranges: bytes
ETag: "207482d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /hcp/pixel.gif?d=1250204271932 HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: server.iad.liveperson.net
Connection: Keep-Alive
Cookie: HumanClickID=-1440628355870; HumanClickACTIVE=1250203831902

HTTP/1.1 200 OK
Content-Length: 49
Content-Type: image/gif
Content-Location: http://server.iad.liveperson.net/hcp/pixel.gif?d=1250204271932
Last-Modified: Tue, 28 Jul 2009 19:55:23 GMT
Accept-Ranges: bytes
ETag: "a2a3558bdfca1:b37"
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /images/mc_bg.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:37 GMT
If-None-Match: "50c44715d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 131
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:37 GMT
Accept-Ranges: bytes
ETag: "50c44715d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT


GET /hc/30084425/?cmd=repstate&site=30084425&channel=web&&ver=1&imageUrl=http: //www.warehouseskateboards.com/images HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: server.iad.liveperson.net
Connection: Keep-Alive
Cookie: HumanClickID=-1440628355870-1250203607:-1:-1:-1:-1; HumanClickKEY=124311397328331345; HumanClickSiteContainerID_30084425=STANDALONE; HumanClickID=-1440628355870; HumanClickACTIVE=1250203831902

HTTP/1.1 302 Moved Temporarily
Date: Thu, 13 Aug 2009 22:57:51 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_30084425=STANDALONE; path=/hc/30084425
Location: http://www.warehouseskateboards.com/images/repoffline.gif?d=1250204271963
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 0

GET /images/facebook-skateboards.jpg HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 05 Feb 2009 20:41:42 GMT
If-None-Match: "50102127d287c91:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 1029
Content-Type: image/jpeg
Last-Modified: Thu, 05 Feb 2009 20:41:42 GMT
Accept-Ranges: bytes
ETag: "50102127d287c91:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /images/youtube-skateboards.jpg HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 05 Feb 2009 20:41:42 GMT
If-None-Match: "eefeee26d287c91:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 859
Content-Type: image/jpeg
Last-Modified: Thu, 05 Feb 2009 20:41:42 GMT
Accept-Ranges: bytes
ETag: "eefeee26d287c91:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /images/myspace-skateboards.jpg HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 05 Feb 2009 20:41:41 GMT
If-None-Match: "8cedbc26d287c91:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 1179
Content-Type: image/jpeg
Last-Modified: Thu, 05 Feb 2009 20:41:41 GMT
Accept-Ranges: bytes
ETag: "8cedbc26d287c91:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /images/twitter-skateboards.jpg HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 05 Feb 2009 20:41:41 GMT
If-None-Match: "dea08f26d287c91:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 1091
Content-Type: image/jpeg
Last-Modified: Thu, 05 Feb 2009 20:41:41 GMT
Accept-Ranges: bytes
ETag: "dea08f26d287c91:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:50 GMT

GET /images/wordpress-skateboards.jpg HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 05 Feb 2009 20:41:41 GMT
If-None-Match: "98dd6b26d287c91:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 1070
Content-Type: image/jpeg
Last-Modified: Thu, 05 Feb 2009 20:41:41 GMT
Accept-Ranges: bytes
ETag: "98dd6b26d287c91:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /aff.php HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-ms-application, application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: 66.240.153.188
Connection: Keep-Alive

HTTP/1.1 200 OK
Date: Thu, 13 Aug 2009 22:57:59 GMT
Server: Apache/2.2.10 (Win32) PHP/5.2.7
X-Powered-By: PHP/5.2.7
Content-Length: 675
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

GET /images/dd-toptile.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:15 GMT
If-None-Match: "fceaff7d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 201
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:15 GMT
Accept-Ranges: bytes
ETag: "fceaff7d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /images/dd-lt-tile.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:12 GMT
If-None-Match: "c2ea596d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:12 GMT
Accept-Ranges: bytes
ETag: "c2ea596d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /images/dd-rt-tile.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:13 GMT
If-None-Match: "fcbdce6d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:13 GMT
Accept-Ranges: bytes
ETag: "fcbdce6d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /images/dd-lt.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:12 GMT
If-None-Match: "7e5e8e6d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 396
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:12 GMT
Accept-Ranges: bytes
ETag: "7e5e8e6d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /images/dd-rt.gif HTTP/1.1
Accept: */*
Referer: http://www.warehouseskateboards.com/
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
If-Modified-Since: Thu, 07 Aug 2008 20:56:13 GMT
If-None-Match: "7a1df7d0f8c81:1ec3"
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 200 OK
Content-Length: 397
Content-Type: image/gif
Last-Modified: Thu, 07 Aug 2008 20:56:13 GMT
Accept-Ranges: bytes
ETag: "7a1df7d0f8c81:2081"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /portal.php HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-ms-application, application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Referer: http://66.240.153.188/aff.php
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: s6xml.com
Connection: Keep-Alive

HTTP/1.1 200 OK
Date: Thu, 13 Aug 2009 22:57:51 GMT
Server: Apache/2.2.10 (Win32) PHP/5.2.7
X-Powered-By: PHP/5.2.7
Content-Length: 138
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

GET /logos/small/Pro%20Tec.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: http://www.warehouseskateboards.com/flash_home/dynamic-brands.swf
x-flash-version: 10,0,22,87
Cache-Control: no-transform
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: www.warehouseskateboards.com
Connection: Keep-Alive
Cookie: __utma=90198812.636266065.1250202761.1250202761.1250203501.2; __utmb=90198812; __utmz=90198812.1250202761.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); __utmc=90198812; ASPSESSIONIDAASSRBDA=GGFBFHECPJOOMNABCIDOILFH; ASPSESSIONIDCCSSTDBA=FNIDDNECOBCCOOJLOBGFFOBG

HTTP/1.1 404 Not Found
Content-Length: 18824
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 13 Aug 2009 22:57:51 GMT

GET /search.php?username=9324&keywords=computer%20repair HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-ms-application, application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Referer: http://s6xml.com/portal.php
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: s6xml.com
Connection: Keep-Alive
 
cont. :confused:

HTTP/1.1 200 OK
Date: Thu, 13 Aug 2009 22:57:51 GMT
Server: Apache/2.2.10 (Win32) PHP/5.2.7
X-Powered-By: PHP/5.2.7
Content-Length: 54
Keep-Alive: timeout=5, max=99
Connection: Keep-Alive
Content-Type: text/html

GET /aff/portal.php HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-ms-application, application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Referer: http://66.240.153.188/aff.php
Accept-Language: en-us
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618)
Host: xmlfind.net
Connection: Keep-Alive
 
Last edited:
Well, it seems to be an iframe or javascript being put on the pages at certain times of the day. I'm going to keep trying to catch it. (this is the most I've worked for free in a long time :p)
 
The last time it was doing it 6:30EST-8:40EST yesterday I scoured the site for any iframe and found absolutely nothing. BTW I do appreciate your help.
 
You're welcome.

The page that seems to be starting the chain reaction is that http://66.240.153.188/aff.php. That has to get included somewhere on the page. I'm running a bot I quickly made that'll load your page every 5 minutes and check for either aff.php or 66.240.153.188. Let's hope we find it. If you get on and it starts doing it, let me know. Maybe finding out where it is in the html, and what exactly it is will help you pinpoint what's causing it.
 
Finally found it. An ftp username was brute forced and a script was writing to a .js file deep within the site. It was happening right in front of me, written to the .js file then removed and then back again. Arctic Fire I really appreciate all of your help today. Thank you. Time for beer!
 
No prob man. I'm glad you found it. I knew somebody had to be putting it in one of your files. (but compromised FTP never came to mind, go figure)
 
No prob man. I'm glad you found it. I knew somebody had to be putting it in one of your files. (but compromised FTP never came to mind, go figure)

I think I mis-spoke it was actually an RDP user they brute forced that had rights to the site directory and that is one of the reasons why it took so long to find. FTP logs were clean! I am just glad it is working and we getting orders again. I was afraid I was going to loose all ranking and be "F`ed" forever.
 
Hi, please consider me a novice, as I don't think I understand the previous forum posts. My site is somehow hijacked by a Javascript, and it's also being redirected to AskLots.com. My readers are warning me about the problem, and I am afraid of posting anything new because I've already had one link-sharing site ban me because of the Javascript intrusion on my site.

Can anyone please help me?

Thanks!
MsU
 
Back
Top