Forum Moderators: rogerd

Message Too Old, No Replies

Adware On User's Machine Creates Links on Your Site

         

knowledgepower

5:49 am on Mar 21, 2005 (gmt 0)

10+ Year Member



I run a mid-level fan site for a popular band and one large component is our discussions forum.

We noticed recently that a few user's posts would have links to a spammy search affiiliate driven website.

Our first concern was that we may have been hacked, because these users would never have made links like this (and we confirmed this by asking them). We use vBulletin, which has undergone a number of security updates recently.

I called up the administrative contact of this spamtastic website, #*$!xxmiracle.com and asked him what the hell was going on. It turns out that he distrubutes adware that automatically creates links in a user's posts. For instance, the word "nutrition" leads to a search for nutrition on their site.

He even admitted that they had been sued a number of times over their software, but that since they have a full-disclosure EULA--have been able to win every case.

Once it was clear they hadn't hacked into our site, but were basically responsible for the ads in my forums I politly ended the conversation. Not much else can be done, though talking to a black-hatter who personally affected my website was infuriating.

So, we've alerted the user to run some anti-adware tools and that's the best we could do. Has anyone else run into a problem like this?

kp

chadmg

3:26 pm on Mar 21, 2005 (gmt 0)

10+ Year Member



You could add some code to block links to his site. Determine the pattern of the links and just not allow them.

cmatcme

4:03 pm on Mar 21, 2005 (gmt 0)

10+ Year Member



Yes. If links are sometimes double-underlined and these

hard drive
theme park
jigsaw puzzles

are hyperlinked then you've been hacked by a software called Link Replacer.

Most software uninstalls it.

Try Microsoft Anti-Spyware. [google.com] It uninstalled it on our system.

rogerd

1:47 pm on Mar 22, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



I haven't encountered this, but I'd recommend turning off posting until the member gets disinfected.

A year or so ago I saw a discussion about malware that put a spam home page into vBB profiles (when an infected member registered). The member would have no idea it was there until someone asked him why he put that URL in his profile.

I guess the price of success means that software with a substantial market share will get targeted by hackers.

I haven't heard much about this issue, so I'm assuming that it has been addressed in some way.

cmatcme

4:27 pm on Mar 22, 2005 (gmt 0)

10+ Year Member



Would these links link to serverlogic3.com?