Forum Moderators: open

Message Too Old, No Replies

Altavista redirects to ... Well. They've been hijacked!

Who'll be the next? Yahoo? G? Seeing is believing.

         

pendanticist

10:51 pm on Mar 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Please, pay close attention to what I am describing.

  • When you go to www.altavista.com and click on Images, the url then becomes www.altavista.com/images as it should.

  • By pulling the word "randomlink" back ( shown below ) and making it a clickable link ( within your own browser as I've spread it out ), you will be taken to a pornographic site - so do be careful.

  • Within AVs website there is no randomlink to be selected.

  • Take the link to your favorite header checking website and you will see exactly what I'm talking about.

  • These folks came to me from Level 3 Communications, PacBell, Ripe and Comcast out of New Jersey.

  • All six visitors hit with just a few seconds of each other, until the last entry which seems to be a straggler by about a minute ten seconds.

    65.57.***.** - - [04/Mar/2005:18:13:00 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.117"
    65.57.***.** - - [04/Mar/2005:18:13:00 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.117"
    82.226.***.** - - [04/Mar/2005:18:13:01 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.114"
    65.57.***.** - - [04/Mar/2005:18:13:02 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.117"
    adsl-67-***-**-**.dsl.snfc21.pacbell.net - - [04/Mar/2005:18:13:03 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.123"
    65.57.***.** - - [04/Mar/2005:18:13:06 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.117"
    65.57.***.** - - [04/Mar/2005:18:13:06 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.117"
    c213-100-**-***.swipnet.se - - [04/Mar/2005:18:13:06 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.114"
    michael.***.****.edu - - [04/Mar/2005:18:13:09 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.117"
    24.99.**.*** - - [04/Mar/2005:18:14:19 -0800] "GET /About_Blah.html HTTP/1.0" 403 480 "http://www.altavista.com/image/ randomlink" "webcollage/1.117"

    Note:

  • The only reason they were handed a 403 is because I have webcollage banned in htaccess.

  • The Blah files are actually image files on my server.
  • blaze

    11:22 pm on Mar 5, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    By pulling the word "randomlink" back ( shown below ) and making it a clickable link ( within your own browser as I've spread it out ), you will be taken to a pornographic site - so do be careful.

    "pulling the word"

    Not familar with that terminology. Exactly what are you doing here?

    pendanticist

    11:25 pm on Mar 5, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    Make it all one continuous link. After pasting it into your browser, backspacing usually 'pulls' the remaining phrase back into the root. The opposite of trimming.

    pageoneresults

    12:08 am on Mar 6, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



    [altavista.com...] + randomlink

    Take out the space and the + symbol. Put it all together and paste in your address bar.

    Note: The content you are going to be presented with once following the above link may not be suitable for young audiences and possibly some older audiences. ;)

    tedster

    5:02 am on Mar 6, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    It shows many kinds of sites, and most of the ones I saw are quite innocent - and apparently quite random.

    Within AVs website there is no randomlink to be selected.

    That may be true now, but the url itself has a ton of backlinks, and it even shows for the past two years in the Wayback machine.

    From searching on [altavista "random link"] it looks like the old AV site did have this "random link" resource back in 2003 - with suitable filters on it, I assume. Has the ghost of that old URL been hacked? Or is it just that it's still there and not actively considered by Yahoo/AV anymore?

    jdMorgan

    5:33 am on Mar 6, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    The log file entries look like the old AV random-link feature being used by WebCollage. More info on WebCollage is easily found by searching. Basically, it's just a 'cute' little Web app that displays a collage of images from the random sites it 'visits.' Built in a more innocent time, it now comes up with some adults-only collages occasionally. Adult webmasters and any webmasters with proprietary images might want to block the webcollage user-agent.

    Jim

    pendanticist

    5:50 am on Mar 6, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    What happens when you click the link in wayback?

    Is this event simply a webcollage push of some kind and NOT a hijacking?

    Would any of these impressions show in AVs access_log files?

    Hope I didn't go off half-cocked on this...thought I'd really discovered something.

    pendanticist

    9:01 am on Mar 7, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    Tremmelos - Silence is Golden, but my eyes still seeeeee....

    jdMorgan

    11:36 pm on Mar 7, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    > Would any of these impressions show in AVs access_log files?

    Yes, but I doubt that anyone there goes through their raw access logs -- probably (still) too big to handle.

    The 'new' aspect I find here is the adult content. I played with Webcollage when it was new. It was one of those interesting-for-an-hour type of things. At that time the Web was a whole lot less commercial, and I don't recall ever seeing any adult content in the collages. But I think the title of the Webcollage page is probably accurate - "A snapshot of the Web." Since the proportion of commercial and adult content has increased, so the liklihood of seeing commercial or adult images in Webcollage has increased.

    You'll also see Webcollage using Yahoo's random-link generator. Not sure if it is actually the same resource now that Yahoo owns AV, but "random links" were another popular diversion on the early Web. Services like StumbleUpon continue to promote them.

    Jim

    pendanticist

    1:06 am on Mar 8, 2005 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    Thanks for the info, Jim. :)