Forum Moderators: phranque

Message Too Old, No Replies

Website hijack

         

david_uk

11:58 am on Aug 6, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Not sure what forum to post this in, but hoping someone can help.

This morning I looked at my website from my favourites, and got redirected to another site that looked like a domain park site. IE wall of ads. It purported to be my site, and the redirect happened from favourites in both IE an Opera. It only happened first thing this morning the once, and then the correct page was viewed from my favourites.

I've notified my host, but when they follow the link I gave them where it redirects you to, all they could see was the standard 404 error message for the site that does redirect correctly to my main index page.

I've since emailed the host with a copy of the code of the false page and am waiting a reply currently. I can't replicate the redirect by typing in the exact url of the redirect, but oddly enough when I used the "Bookmark this page" on the false page it added it to my favourites and I can now access both my real index and the interloper from the favourites menu. I've even emailed the url from one computer here to another, and looked at the site on a different computer.

Does anyone have any suggestions of things I can do to help my host as I can see the page and they can't?

daveVk

12:48 pm on Aug 6, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Tried tracing route. "tracert www.example.com" on windows box. May reveal something?

jdMorgan

3:25 pm on Aug 6, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



This sounds like a DNS exploit, where the 'bad guy' sets up a DNS server that points your domain to his server's IP address. Since DNS is a distributed function, sometimes the DNS translation will be correct (domain resolves to your server) and sometimes incorrect (resolves to his server).

When you ping or tracert the domain, look at the IP address you get -- Sometimes it may be his server's IP address instead of yours.

Previous threads [google.com]

Jim