Go to Post Super Bowl, P-Diddy, Diet Pepsi. Super Bowl of Smarts, Dave Lavery, Diet Coke. - Gary Dillard [more]
Home
Go Back   Chief Delphi > Technical > IT / Communications > Website Design/Showcase
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Closed Thread
 
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 28-06-2009, 17:38
Andrew Schreiber Andrew Schreiber is offline
Joining the 900 Meme Team
FRC #0079
 
Join Date: Jan 2005
Rookie Year: 2000
Location: Misplaced Michigander
Posts: 4,068
Andrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond repute
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

Try renaming the page then having index.php redirect to index1.php. Odd problem.
__________________




.
  #2   Spotlight this post!  
Unread 28-06-2009, 18:51
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

we tried that, but it seems that the redirect connects the files just enough to cause the divs to keep appearing!

once the tech gets back, we'll try migrating the entire site to a different location on the server, then moving the DNS reference...

hopefully, that'll help.

-Z
__________________
[center]
  #3   Spotlight this post!  
Unread 29-06-2009, 16:15
OScubed's Avatar
OScubed OScubed is offline
Lee Drake, CEO, OS-Cubed Inc.
AKA: Lee Drake
FRC #1511 (Rolling Thunder)
Team Role: Parent
 
Join Date: Mar 2008
Rookie Year: 2006
Location: Rochester, NY
Posts: 156
OScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond repute
Send a message via ICQ to OScubed Send a message via AIM to OScubed Send a message via MSN to OScubed
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

It looks like link generating spam. This is placed into remote sites to point back at other sites for advertising SEO. Many spiders won't notice that they are in a hidden div, so the links back to the original sites increase (in a black hat kind of way) the linkscore of the target.

Have you commented out the following JS to be sure they're not injecting the div:

Colourloverscolorpicker.js
print.js
ddaccordion.js
lnews.js

Check this link on the moodle site for additional info:
http://moodle.org/mod/forum/discuss.php?d=116103

If your webmaster downloaded a template from a "free site" the linkspam js may be embedded in the moodle skin.
__________________
Lee Drake, CEO, OS-Cubed, Inc.
Business Mentor - team 1511
Rochester, NY

Building optimal, stable, secure solutions to your business challenges.


Last edited by OScubed : 29-06-2009 at 16:24.
  #4   Spotlight this post!  
Unread 29-06-2009, 16:41
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

Quote:
Originally Posted by OScubed View Post
Have you commented out the following JS to be sure they're not injecting the div:

Colourloverscolorpicker.js
print.js
ddaccordion.js
lnews.js
lnews.js and print.js are scripts we've written, and both of the other scripts have been heavily modified, and do not reference any other files, unless i missed something... (after all, i was working late at night)

now that you mention it,i've re-checked the scripts, and they are all clean...

the only scipt i haven't modified is http://ajax.googleapis.com/ajax/libs.../jquery.min.js, but i use that on several other sites without any issues...

looking at the pages referenced in the ghost div, it doesn't seem to be for advertizing... all the pages seem to be located on sites they have no relation to, most of which are schools and universities, and all of which run moodle

i wasn't able to get to the moodle discussuion board, as i do not have an account... however, i will talk with the tech coordinator at school to see if he has one.

thanks for the thought though,

-Z
__________________
[center]
Closed Thread


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless Networks(A/B/G/N) kiettyyyy Rules/Strategy 4 11-02-2009 15:04
Attention all Webmasters out there.... Meyer_Shuky Website Design/Showcase 46 12-01-2004 16:53
Webmasters...its here! blueWarrior Website Design/Showcase 0 25-12-2003 10:10
Exchange of Picture/Ideas for Webmasters Next Year archiver 2000 3 23-06-2002 23:21
Team Webmasters robophent Chit-Chat 6 06-03-2002 21:32


All times are GMT -5. The time now is 00:55.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi