Author |
Message |
v-tec
Hangin' Around

Joined: Jul 19, 2009
Posts: 33
|
Posted:
Mon Nov 16, 2009 3:15 pm |
|
|
|
 |
nuken
RavenNuke(tm) Development Team

Joined: Mar 11, 2007
Posts: 2024
Location: North Carolina
|
Posted:
Mon Nov 16, 2009 3:48 pm |
|
You could disable html in the forums. That should disable whatever redirect that was posted. |
_________________ Only registered users can see links on this board! Get registered or login! |
|
|
 |
v-tec

|
Posted:
Mon Nov 16, 2009 3:54 pm |
|
does it mean all links posted on the forum will go inactive ?
will disabling html stop the forced redirecting problem |
|
|
|
 |
v-tec

|
Posted:
Mon Nov 16, 2009 3:59 pm |
|
update :
disabling html is not working, the certain links to the posts in the forum are getting redirected to this annoying mybookface.net website |
|
|
|
 |
eldorado
Involved


Joined: Sep 10, 2008
Posts: 424
Location: France,Translator
|
Posted:
Mon Nov 16, 2009 4:26 pm |
|
Maybe go in phpmyadmin and look for all the posts in that forum...You might see that wanabe stuff  |
_________________ Only registered users can see links on this board! Get registered or login! (My RN site)- Only registered users can see links on this board! Get registered or login!(cod4 clan) - Only registered users can see links on this board! Get registered or login! |
|
|
 |
v-tec

|
Posted:
Mon Nov 16, 2009 6:20 pm |
|
thanks for the idea mate.
i will give myphpadmin a go |
|
|
|
 |
evaders99
Former Moderator in Good Standing

Joined: Apr 30, 2004
Posts: 3221
|
Posted:
Mon Nov 16, 2009 8:19 pm |
|
Simple issue: you've been hacked!
Your link is returning malicious iframe and Javascript code. I expect your files have been tampered with. Delete and restore a clean backup. Use your access logs to see how the hacker got in. |
_________________ - Only registered users can see links on this board! Get registered or login! -
Need help? Only registered users can see links on this board! Get registered or login! |
|
|
 |
hicuxunicorniobestbuildpc
The Mouse Is Extension Of Arm

Joined: Aug 13, 2009
Posts: 1123
|
Posted:
Tue Nov 17, 2009 6:05 am |
|
Ups. I agree with evaders99. This is not a normal redirect behaviour. U have been hacked for sure. |
|
|
|
 |
Guardian2003
Site Admin

Joined: Aug 28, 2003
Posts: 6799
Location: Ha Noi, Viet Nam
|
Posted:
Tue Nov 17, 2009 9:51 am |
|
Check your htaccess file as well as that is being redirected as well. |
|
|
|
 |
v-tec

|
Posted:
Thu Nov 19, 2009 4:20 pm |
|
cheers for your response mates.
I found out what was causing the problem
the ebay link with eBayISAPI.dll was causing the mayhem.
i am not sure why so it could be the windows system function the .dll extenstion calls . Basically any post with eBayISAPI.dll goes all bananas .
removed the eBayISAPI.dll from affected posts and now no redirections no errors. Can anyone explain whats causing it ? (anything within Raven Nuke ? )
And plus how many sites on Raven nuke has been hacked so far? As i think RN is much safer compared to a lot of CMS around atm. |
|
|
|
 |
nuken

|
Posted:
Thu Nov 19, 2009 4:30 pm |
|
where was the .dll file stored? on your site or a remote server? How was it included in the post?
edit: Are you using byethost for your webhosting? |
|
|
|
 |
v-tec

|
Posted:
Fri Nov 20, 2009 8:06 am |
|
nuken wrote: | where was the .dll file stored? on your site or a remote server? How was it included in the post?
edit: Are you using byethost for your webhosting? | i think so the site is on bytehost or one of its resellers called 0fees.net
the text eBayISAPI.dll is a part of ebay link for example
Only registered users can see links on this board! Get registered or login!
now if the post contains the word eBayISAPI.dll anywhere on the post either as a part of a link or just on its own.
the post goes all mental and starts redirecting.
but once the text or word eBayISAPI.dll was removed from affected posts , all was ok.
wonder what was causing this anamoly |
|
|
|
 |
Susann
Moderator

Joined: Dec 19, 2004
Posts: 3191
Location: Germany:Moderator German NukeSentinel Support
|
Posted:
Fri Nov 20, 2009 9:00 am |
|
Scan your PC and search for eBayISAPI.dll there are thousands of Google search results. You should also search for mybookface.net you will find entries from different free host users. |
|
|
|
 |
nuken

|
Posted:
Fri Nov 20, 2009 10:17 am |
|
The reason I asked is because bytehost and a few other free webhosts redirect links to mybookface.net by default if the link is either a dead link or if the content it points to is considered against their terms of service. mybookface.net pays them to direct traffic to them and this may be a host issue and not site issue. |
|
|
|
 |
|