Forum Moderators: martinibuster

Message Too Old, No Replies

Site Hacked: AdSense Publisher ID Replaced

Suddenly, my page impression is ZERO!

         

jokomamamita

12:14 pm on Sep 22, 2006 (gmt 0)

10+ Year Member



Hello friends!

Well, I've been a google adsense user for about 4 months! In average, I would get page impressions in the range of 600 ~ 1100 a day and the earnings around $0.40 ~ $2.00 per day! But all of sudden, my page impressions showed 11 and the earnings is $0.00 (yesterday and today!)....I don't care much about the earnings as there are some times where I would get ZERO earnings but what about the page impression?

It dropped from an average of 800 page impressions to 11! And, my site is working fine!

Help me guys!

Thanx alot! =)

trannack

12:21 pm on Sep 22, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Where do you normally get your traffic from?

jokomamamita

12:28 pm on Sep 22, 2006 (gmt 0)

10+ Year Member



Sorry, I don't quite get your question!
I've put the ads in my blog as well as in my forum!
And, I would get around 110+ unique visitors!...
I still can't understand why it shows that my page impressions are 11 as of yesterday!

Cheers!

[edited by: jatar_k at 2:35 pm (utc) on Sep. 22, 2006]
[edit reason] no urls thanks [/edit]

vite_rts

12:29 pm on Sep 22, 2006 (gmt 0)

10+ Year Member



Do you have traffic analyse software or google analytics

Gian04

12:34 pm on Sep 22, 2006 (gmt 0)

10+ Year Member



There is only one logical conclusion to that. You only have 11 visitors, you cannot expect everyday you'll have the same visitors

hunderdown

1:46 pm on Sep 22, 2006 (gmt 0)



joko, check your stats in 6 hours. If they haven't changed by then, let us know.

jokomamamita

9:55 am on Sep 23, 2006 (gmt 0)

10+ Year Member



I'm back friends!

1) I don't use any Google Analytic(s) or any tracking script!

2) Well, my AWSTATS showed that I had around 180+ unique visitors 3 days back as well as for yesterday!

3) Today, the page impression is only 2 and the earning is $0.00

Please help me friends!
I don't think I had violated any of google's TOS! Even if they had banned my account, by right I should had received an email from them, ayt? But I did not!

Please help me!
I'm losing my earnings because of this... =(

Thanx and take care!

jokomamamita

10:11 am on Sep 23, 2006 (gmt 0)

10+ Year Member



Sorry for the double post!

But, I managed to check my adsense codes which I had inserted and find out that the CLIENT ID had been changed....

It showed :

google_ad_client = "ca-002932904202#*$!X-732614508765#*$!X";

*the #*$!X had been replaced by me which were originally numbers

Does it mean that my blog had been hacked?....
Anyway, the 732614508765#*$!X was actually my ID but I don't know what the hell is the front first bunch of numbers doing!.... =S

Help me!

trannack

11:07 am on Sep 23, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Have you contacted adsense about this. I have not heard about adsense code being hacked - but I don't doubt that some smart-a**e is capable of it. And surely if this is the case, than Adsense would just terminate that persons account.

goneinthesun

4:36 am on Sep 23, 2006 (gmt 0)

10+ Year Member




System: The following 9 messages were spliced on to this thread from: http://www.webmasterworld.com/google_adsense/3094221.htm [webmasterworld.com] by martinibuster - 7:38 pm on Sep. 23, 2006 (utc -8)


someone keep hacking my sites and replacing my ad google pub #. I don't know how they does it.

any advice would be greatly appreciated and desperatly needed.

jtwald

4:56 am on Sep 23, 2006 (gmt 0)

10+ Year Member



What kind of site do you run? Open php CMS and forums may have some vulnerabilities allowing to password hashes in your database.

Try a more secure password, and use a different one on your ftp then the ret of your site.

Play_Bach

5:56 am on Sep 23, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



> any advice would be greatly appreciated and desperatly needed.

Report their pub # to adsense-support@google.com

Khensu

6:09 am on Sep 23, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



You have their URL

You have their PUB#

You've got them!

Let us know what happens.

goneinthesun

6:11 am on Sep 23, 2006 (gmt 0)

10+ Year Member



thanks for the feedback. i will report them ad google. i am running a web directory. i think there is probably a security hole or back door.

any more advice from anyone would be great.

Alioc

1:51 pm on Sep 23, 2006 (gmt 0)

10+ Year Member



Maybe the directory script randomly rotates PUB IDs to keep it free. (even if that's questionable) Check the code and script provider.

jokomamamita

2:14 pm on Sep 23, 2006 (gmt 0)

10+ Year Member



yea...
I had the same problem too!...

someone hacked into my wordpress blog and changed the client ID to something like :

from : google_ad_client ="pub-myIDnumber"

to : google_ad_client = "somenumbers-ca-myIDnumber";

maxgoldie

9:33 pm on Sep 23, 2006 (gmt 0)

10+ Year Member



How did you determine this? Is WP support aware of this?

JinxBoy

3:26 am on Sep 24, 2006 (gmt 0)

10+ Year Member



As quite a few of us use wordpress to some extend I'm interested to hear what's going on here....

Is this brought to the attention of WP support? Do you guys run the latest version of the software?

Marcia

4:30 am on Sep 24, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



There are also some Cpanel vulnerabilities that some hosts haven't fixed (in case it's cpanel being used).

joeking

9:29 am on Sep 24, 2006 (gmt 0)

10+ Year Member



Frightening stuff. Please let us know what AS support say and whether you have reported the vulnerability to Wordpress.

nailah phoomee

2:36 am on Sep 25, 2006 (gmt 0)

10+ Year Member



"There are also some Cpanel vulnerabilities that some hosts haven't fixed (in case it's cpanel being used). "

Please explain how they can do it without the Cpanel password?
I have the same problem and am running my sites on share hosting with Cpanel and dedicated server with Cpanel.

Mainly the file and folder permissions were changed to 777 . My hosting support said
"This is due to them being made/modified/uploaded from a script. This inturn makes the files owned by nobody(Apache Web Server). "

Well, the support already changed it back to secure permission and my sites were working fine but a few days later it happend again.

I keep changing my passwords but still they can hack my sites.

I reported google my problem and sent them the alien pubs and so far they said
"While I'm unable to provide you with the results of our investigation for privacy and security reasons, please be assured that appropriate action will be taken against the accounts in question.
"

Any advice would be greatly appreciated.

level80

3:32 am on Sep 25, 2006 (gmt 0)

10+ Year Member



It's a zero day exploit in cpanel. It's only pretty recently that this has got into the news. There have been unofficial patches and workarounds suggested to stop it. As you pointed out the exploit doesn't require the account username/password to do it. chmod 777 refers to the fact that that file or folder with has read (eg it can be viewed), write (eg it can be changed) and execute (eg it can be run as a program) for the owner, group and public. It's mentioned in more detail here [news.netcraft.com] . Cpanel have released a fix though so once the hosting company applies that there shouldn't be any more problems caused by the security hole.

nailah phoomee

2:59 pm on Sep 28, 2006 (gmt 0)

10+ Year Member



They keep hacking my sites. I tried to do so many things I can think of but they still be able to do it .

I'm really wondering how they can do it. Again, I keep changing my password, contact hosting people so many times about this problem ( i think they are sick of my by now ) but the problem is still there and keep haunting me .

I'm willing to do anything to stop these people, please if anybody have any suggestions I'd be greatly appreciated.
Otherwise I'm just easily broke which is not what I plan to be.

Here are the alien pubs if anybody knows who they are or you can take a look at your sites if any of them has given you a visit :
1. <snip>
2. <snip>
3. <snip>
4. <snip>

I really need help please......

[edited by: engine at 3:38 pm (utc) on Sep. 28, 2006]
[edit reason] No specifics. See TOS [webmasterworld.com] [/edit]

jomaxx

3:07 pm on Sep 28, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Document this and be sure to tell Google about it. Needless to say, hacking into web servers and replacing the publisher id is not going to be looked upon kindly.

Also, if it keeps happening then get a better host and move your site.

nailah phoomee

3:13 pm on Sep 28, 2006 (gmt 0)

10+ Year Member



Thanks, jomaxx. I'm working with a new hosting now and moving some of my sites there and kind of monitoring now if the alien pub will find me or not.

[edited by: martinibuster at 7:38 am (utc) on Oct. 2, 2006]
[edit reason] Removed Email Excerpt. [/edit]

photo200

7:14 pm on Sep 30, 2006 (gmt 0)

10+ Year Member



Is your blog hosted on wordpress server?
Or you run .php script on your own server?

nailah phoomee

6:07 am on Oct 2, 2006 (gmt 0)

10+ Year Member



I run .php files on my own server . Would that lead them to get into edit my files?

potentialgeek

6:16 am on Oct 12, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I motion for criminal prosecution. It's not just hacking; it's theft. B*stard$!

p/g

born2run

4:06 pm on Oct 12, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Hire a professional server hardening expert ...

andye

4:19 pm on Oct 12, 2006 (gmt 0)

10+ Year Member



I run .php files on my own server . Would that lead them to get into edit my files?

It would if they have root access to your server. In that case they can do anything they like with it.

Can you get your ISP to do a security audit on your box?

hth, a.

This 31 message thread spans 2 pages: 31