Simple Machines Community Forum

SMF Support => SMF 2.0.x Support => Topic started by: bhamel712 on September 16, 2020, 04:11:45 PM

Title: Google and Bing Redirect
Post by: bhamel712 on September 16, 2020, 04:11:45 PM
If I lookup my forum from google or bing and click the link it redirects me to a medication site.  If I type the address directly or the sub sites it works fine.  It looks like bing is going to the index.php on the main site and I cannot find where it is getting the redirect.  Can anyone help?

https://www.bing.com/search?q=smokinitforums
The second result is the problem.
www.smokinitforums.com is the site.
 

Thanks
Ben
Title: Re: Google and Bing Redirect
Post by: AlanDewey on September 17, 2020, 09:23:52 AM
Very interesting.

I tried it, and when I clicked on the result in Bing, I got the drug site also.

If I put https://www.smokinitforums.com/index.php  in the address bar of the browser, I get your forum.

I hover over the Bing result, I see  https://www.smokinitforums.com/index.php which certainly appears that it will send me to https://www.smokinitforums.com/index.php  but, like you, I click it, I get the drugs.

I even hover over the Bing result, click "copy link location", paste it in Notepad and I see https://www.smokinitforums.com/index.php

I am a beginner at this, but you know to expect the question "what mods do you have installed?"

Look what I get at google when searching your forum name.

Title: Re: Google and Bing Redirect
Post by: Dzonny on September 17, 2020, 09:32:38 AM
I get some kamagra sites from google in description.
Looks like you have injected some code in your files somewhere to me though.

Can you attach your index.php file from root of your forum, and index.template.php file from your theme?
Do you have anything in your error log? Any mods installed?
Title: Re: Google and Bing Redirect
Post by: Elmacik on September 17, 2020, 11:27:30 AM
Google cache of your main page shows that once your forum had that drug content (just the same with that drug web site) already: https://webcache.googleusercontent.com/search?q=cache:tUYOFo7HhA8J:https://www.smokinitforums.com/+&cd=3&hl=tr&ct=clnk&gl=tr

Seems like you have some kind of "Redirection Board" modification installed and possibly through that mod, some JavaScript injection could have been done.

You should search for "kamagra" keyword in your forum DB and source files; because the redirection code includes this keyword at the destination. (Or better remove the mod completely?) Probably this injection has a referrer trigger which triggers the redirection only when it senses that the visitor clicked from Google. This way it redirects only from Google results but it doesn't redirect when entered the direct link, so that it tries to keep you from noticing it.
Title: Re: Google and Bing Redirect
Post by: AlanDewey on September 18, 2020, 07:21:13 AM
Interesting......

I usually use DuckDuckGo.com for searching.      Go to DuckDuckGo.com and enter this in search     site:smokinitforums.com

I tried about 50 of the results and all of them went to the expected page of your forum, NOT the drug site.

I sure have no idea how this is being done, but the drug people's trick does not work with DuckDuckGo.com


The site that google sends me to is  rx-24-online.com    so search for that in your files and database.
Title: Re: Google and Bing Redirect
Post by: AlanDewey on September 18, 2020, 07:26:18 AM
You may also try going to your google webmaster account and see what it reports for "security issues"
Title: Re: Google and Bing Redirect
Post by: AlanDewey on September 18, 2020, 07:42:06 AM
Your cookie settings?

-->  Server Settings --> Cookies and Sessions

Use subdomain independent cookies ?

Force cookies to be secure ?

Title: Re: Google and Bing Redirect
Post by: Ricky. on September 18, 2020, 02:00:18 PM
Looks like your site has been compromised and they are using some referrer validation to show their site if user is visiting through search engine, this could be the reason that you are not seeing that drug site when you open it directly.
Title: Re: Google and Bing Redirect
Post by: Ricky. on September 27, 2020, 02:01:20 PM
Is this issue resolved. I recently came across another similar case but was using some outdated version of Joomla. 
Essentially, his site hacked and they are using a method call Cloacking". One can read more about here:
https://developers.google.com/web/fundamentals/security/hacked/fixing_the_cloaked_keywords_hack
Title: Re: Google and Bing Redirect
Post by: bhamel712 on October 12, 2020, 03:23:05 PM
Thank you all for the help.  I have been sick for a couple of weeks.  I am working on your suggestions now.  I will let you know what I find.
Title: Re: Google and Bing Redirect
Post by: bhamel712 on October 12, 2020, 04:58:23 PM
Here is my index.php and index.template.php

Title: Re: Google and Bing Redirect
Post by: Kindred on October 12, 2020, 05:17:20 PM
Have you resolved the issue?   Because there is nothing wrong in the two files that you attached.     If you are still having the problem, then the hack was more clever than the usual injection.
Title: Re: Google and Bing Redirect
Post by: bhamel712 on October 12, 2020, 05:35:31 PM
I have not resolved the issue.  I am going insane trying to find this.
Title: Re: Google and Bing Redirect
Post by: shawnb61 on October 12, 2020, 06:04:31 PM
It sure sounds like the links in Google & bing themselves are wrong...

I would setup google (& bing) webmaster tools & trigger a recrawl.
Title: Re: Google and Bing Redirect
Post by: bhamel712 on October 12, 2020, 10:11:14 PM
I deleted and reloaded all of the files for the default theme and the active theme.  I have requested a reindex from google.  Now is the waiting game for the indexing.

Thanks,
Ben
Title: Re: Google and Bing Redirect
Post by: Ricky. on October 13, 2020, 06:08:19 AM
SMF is probably not a culprit, its somewhere that his server or account is compromised and hackers have access to his files, they have installed some .htaccess based redirection.