25, July 2008

IFRAME worm tanked my traffic, google, and pagerank - webmaster forum

 
Webdigity webmaster forums
This forum shares its ad revenue with its members!
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: IFRAME worm tanked my traffic, google, and pagerank
« previous next »
Pages: [1] Print

Author Topic: IFRAME worm tanked my traffic, google, and pagerank  (Read 993 times)
My name is Bong, James Bong
*
Posts: 11
84 credits
Members referred : 0


« on: Apr 20, 2007, 04:21:02 PM »

Did anyone get hit with IFRAME?  It basically threw a line of code in my index file to redirect, etc.  My webhost took the stance of this is your site and you manage the content.  Though I would debate that if something is on your servers, then it could spread to other nodes using the same server and therfore it is your responsibility to clean your servers for your customers.....

Google rewarded me with This site may harm your computer and the stopbadware.org garbage.  Which made us fix the issue - I honestly was not even aware that this was going on - like everyone else - no e-mail, msg, just a banner on the google results that would not let you in to our site.

Anyway, our website sat in the top 3 on Google for 3-4 years and now  after this has been fixed, got a new webhost, tweaking the site a little, I'm monitoring things more closely now.  I wonder if we'll bounce back for traffic because now we sit at about 80 with a pagerank of 3.  Still though MSN & Yahoo didn't penalize us..... any comments?  - Graham
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 7975
40807 credits
Members referred : 3



« Reply #1 on: Apr 20, 2007, 09:03:06 PM »

I don't understand. How an <iframe> become problem Huh

Someone hacked you and run a script using this iframe, or something else happened?

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
My name is Bong, James Bong
*
Posts: 11
84 credits
Members referred : 0


« Reply #2 on: Apr 20, 2007, 09:17:50 PM »

yes that's exactly it - There was a nice 2-3 lines of code that got into the header of the index file. MY webhost said it was IFRAME.  I say it was a line of code executing some viral type spam or redirect.  In any case, we got flagged for it. 
Pinoy Webmaster
.com pimp
*****
Gender: Male
Posts: 1126
6048 credits
Members referred : 0


Philippine Beaches


« Reply #3 on: Apr 21, 2007, 01:31:02 AM »

if it redirects, you should have seen it and removed it before you got penalized by Google. why, dont you view your site often?


Last blog : Marigondon Beach, Cebu, Philippines
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 7975
40807 credits
Members referred : 3



« Reply #4 on: Apr 21, 2007, 06:54:08 PM »

Those are mostly javascript problems that happened to sites such as myspace, I didn't knew that people try to hit this way regular sites too

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
My name is Bong, James Bong
*
Posts: 11
84 credits
Members referred : 0


« Reply #5 on: Apr 21, 2007, 07:21:31 PM »

The other thing that this code did was to target machines running anything less than XP and below IE 5.5 so perhaps I should get on my Windows 95/98 machine ever once in a while to check.  If you think about it, a computer novice running AOL that hasn't updated windows or aol in years, could have gotten a piece of this code.... even our 2nd and 3rd world countries who are now just touching a computer for the very first time....  Anyway, doing my best with this, watching my site more closely, reading more, being a part of this forum has helped a lot.  Nice to hear what others do and go through.   Take care.  - Graham
Pinoy Webmaster
.com pimp
*****
Gender: Male
Posts: 1126
6048 credits
Members referred : 0


Philippine Beaches


« Reply #6 on: Apr 22, 2007, 05:38:09 AM »

Quote
Those are mostly javascript problems that happened to sites such as myspace, I didn't knew that people try to hit this way regular sites too

how could they inject javascript to Graham Slam's homepage?


Last blog : Marigondon Beach, Cebu, Philippines
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6280
38506 credits
Members referred : 374


It's time to use PHP5!


« Reply #7 on: Apr 22, 2007, 10:03:51 AM »



how could they inject javascript to Graham Slam's homepage?

sounds like he used some nasty 3rd party iframe on his page


Last blog : 4th of July Lottery from TemplateMonster.com
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 7975
40807 credits
Members referred : 3



« Reply #8 on: Apr 22, 2007, 01:30:27 PM »

The new hackers use a "javascript injection" way to run code in your site.

For example there is a url like :

example.com/?a=123

In your code you are using this $a variable in a javascript call. In that case with a little work the hacker can make a request (eg. an AJAX request) that changes the password.

Think what will happen if paypal has a vurnerability like that, and the hacker send 1 million emails from "paypal" with this url (which will not look fishy as the domain will be paypal.com)....

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6280
38506 credits
Members referred : 374


It's time to use PHP5!


« Reply #9 on: Apr 22, 2007, 01:34:45 PM »

The new hackers use a "javascript injection" way to run code in your site.

For example there is a url like :

example.com/?a=123

In your code you are using this $a variable in a javascript call. In that case with a little work the hacker can make a request (eg. an AJAX request) that changes the password.

Think what will happen if paypal has a vurnerability like that, and the hacker send 1 million emails from "paypal" with this url (which will not look fishy as the domain will be paypal.com)....

will say we need to validate client side variables too, or better secure target server side scripts...


Last blog : 4th of July Lottery from TemplateMonster.com
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 7975
40807 credits
Members referred : 3



« Reply #10 on: Apr 22, 2007, 01:40:50 PM »

Yes, but this kind of hacking is only happen to sites with lots of users, etc.

As far as I know that happened only to myspace (with user uploaded flash movies) and to bank web sites.

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
My name is Bong, James Bong
*
Posts: 11
84 credits
Members referred : 0


« Reply #11 on: Apr 22, 2007, 04:59:05 PM »

That's funny you say that becuase my index page has a cute little flash intro movie  that I wrote and then you can either enter the site or it redirects to our menu.   
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 7975
40807 credits
Members referred : 3



« Reply #12 on: Apr 22, 2007, 05:03:57 PM »

But in order for this to happen the hacker should somehow upload this flash to your website Wink

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
Pinoy Webmaster
.com pimp
*****
Gender: Male
Posts: 1126
6048 credits
Members referred : 0


Philippine Beaches


« Reply #13 on: Apr 23, 2007, 05:33:59 PM »

is there a means to upload it in your site Graham Slam?


Last blog : Marigondon Beach, Cebu, Philippines
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=6421
Tags : iframe google ranking msn yahoo pagerank Bookmark this thread : Digg Del.icio.us Dzone more....

Topic sponsors:
Get a permanent link here for $1.99!


Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: IFRAME worm tanked my traffic, google, and pagerank
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Jul 25, 2008, 12:00:30 AM





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!


Forum Statistics
Total Posts: 35.717
Total Topics: 7.379
Total Members: 3.711
Tutorials : 56
Resources : 143
Designs : 220
Latest Member: Asimina

34 Guests, 5 Users online :

11 users online today:



Readers

Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2008 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.