Infymus, who has a really broad knowledge in Internet protocol and web programming, said that it looked like it came through advertising. The ad server was hijacked with SQL server.
Shulem wrote:I got redirected to some page that said my computer was infected and it showed some typical computer drive icons and a downloading feature was supposedly taking place. I just closed down the browser with task manager.
Paul O
Which browser did that come up on?
I don't know. I use windows XP and Windows Explorer. Just now tried to get on tonight and got redirected to some sick looking porn site with women in it. Christ, Jesus!
I did a test of this with IE and was redirected to porn.
This does NOT happen with Firefox and adBlock+.
As I told Liz, I suspect wholly that this came in under advertising. It has happened to many sites - including Mormon owned KSL. It happens with the ad server gets hijacked with SQL script. It passes that onto the sites fishing up ads to display. Those get passed onto the browser and whalla, you're redirected to whatever site the script chooses.
People on KSL were being routed to porn sites left and right until they fixed it.
It's pretty hard to hack into a phpBB board without having the admin passwords OR having access to the php code which would mean FTP access at the ISP level.
So I suspect this was off an advertising script. I never saw any redirection here or never had an issue. Why? Because I use Firefox with adBlock+ and I block all advertising I see. I hate advertising to the core, targeted and what not. It's a big peeve of mine.
If you look at the bottom of mormondiscussion's main forum you see:
The last piece below on his page is causing the redirects. The upper portion is a typical google-analytics.
What shades can do right NOW to stop this is go modify - most likely - his "overallfooter.html" and "overallheader.html" found in his phpBB install under the board style. Look for any crap in there and remove it (most likely the above script, unless it's being injected by bad javascript). Then save it back to the FTP directory. Then go into phpBB cache and delete the old cache files.
The site "eacti41vities.rr.nu" or better, "rr.nu" is a well known spam, bot and hack site. ".nu is the Internet country code top-level domain (ccTLD) assigned to the island state of Niue." Did anyone even know there was a state of Niue?
Anyway, shades, the trouble is in your style "Discussions". It's become compromised. If you want to fix it without my help or Mav's help you CAN go back to your default style. Just log into admin control, go to the STYLES tab, and set your style back to ProSilver (the default).