0
Welcome Guest! Login
0 items Join Now

Strange Spam

    • Webmosa's Avatar
    • Webmosa
    • Rocketeer
    • Posts: 80
    • Thanks: 0

    Strange Spam

    Posted 15 years 1 month ago
    • Hello Everyone for the last few weeks I have seen some strange spam on the top of rockettheme site its about Viagra and Cialus. The strange this is that I can only see it in one version of firefox 3.6 on one of my computers I can't see a trace of it anywhere else but if you put in the search terms of Rockettheme viagra or rockettheme cialus google comes up with links back to diffrent pages of rockettheme and is happens on all browsers and all computers. so who has been hacked me or rocket theme or what the heck is going on?
    • John Hodgkinson's Avatar
    • John Hodgkinson
    • Hero Rocketeer
    • Posts: 421
    • Thanks: 0
    • Retired, but build and run websites for organisations of school leaders and others - e.g. http://www.icponline.org, http://www.aspa.asn.au, http://www.appa.asn.au

    Re: Strange Spam

    Posted 15 years 1 month ago
    • I tried your search term = rockettheme viagra in Google in FF3.6. They did take me to RocketTheme pages, but none of them had any of that "spam" at the top of the pages or in the page source code.
    • Webmosa's Avatar
    • Webmosa
    • Rocketeer
    • Posts: 80
    • Thanks: 0

    Re: Strange Spam

    Posted 15 years 1 month ago
    • exactly what I have seen happening and I have gotten the spam to disappear 3 different times trough running different methods of clearing cache and other private data but then it will randomly reappear again it is a very bizarre phenomenon.
    • John Hodgkinson's Avatar
    • John Hodgkinson
    • Hero Rocketeer
    • Posts: 421
    • Thanks: 0
    • Retired, but build and run websites for organisations of school leaders and others - e.g. http://www.icponline.org, http://www.aspa.asn.au, http://www.appa.asn.au

    Re: Strange Spam

    Posted 15 years 1 month ago
    • Have you checked that computer with the problem for viruses and malware, etc etc?
    • Webmosa's Avatar
    • Webmosa
    • Rocketeer
    • Posts: 80
    • Thanks: 0

    Re: Strange Spam

    Posted 15 years 1 month ago
    • yep all clean. and if it was my computer only how would those results end up in the search engine for all of us.


      NOTE: I think I have figure out why I am seeing it. I am still not sure where its coming from but I can only see it if I have firebug open and then go to one of the pages. if I clear my cache and restart the browser its gone until I open firebug and reload one of RT pages
    • Sam Lewis's Avatar
    • Sam Lewis
    • Jr. Rocketeer
    • Posts: 26
    • Thanks: 0

    Re: Strange Spam

    Posted 15 years 1 month ago
    • Webmosa wrote:
      NOTE: I think I have figure out why I am seeing it. I am still not sure where its coming from but I can only see it if I have firebug open and then go to one of the pages. if I clear my cache and restart the browser its gone until I open firebug and reload one of RT pages

      Weird, I am seeing the same thing but I think it is actually FirePHP that is causing it. I can leave firebug enabled but disable firephp and I don't see the links. But as soon as I enable FirePHP the links are there.
    • Sam Lewis
      Moxie Media, LLC

      GoMoxieMedia.com
    • Sam Lewis's Avatar
    • Sam Lewis
    • Jr. Rocketeer
    • Posts: 26
    • Thanks: 0

    Re: Strange Spam

    Posted 15 years 1 month ago
    • Curious if Rockettheme is using FirePHP on their site. Seems like it would have to be generated from code on their site somewhere. I can't find mention of this type of thing anywhere else online. Can't find any FirePHP security issues and my nature of how it works it seems that the links have to be coming from rocketthemes server somewhere.
    • Sam Lewis
      Moxie Media, LLC

      GoMoxieMedia.com
    • Andy Miller's Avatar
    • Andy Miller
    • Preeminent Rocketeer
    • Posts: 9919
    • Thanks: 96
    • Web Kahuna

    Re: Strange Spam

    Posted 15 years 1 month ago
    • I had not heard of FirePHP before, and we are not using it as far as i'm aware. I downloaded and installed it though in Firefox, and was able to replicate the spam on this page:

      www.rockettheme.com/showcase

      As you say disabling FirePHP stops the issue. Frankly i have no clue what's going on. We're looking into it though.
    • Andy Miller's Avatar
    • Andy Miller
    • Preeminent Rocketeer
    • Posts: 9919
    • Thanks: 96
    • Web Kahuna

    Re: Strange Spam

    Posted 15 years 1 month ago
    • ok we tracked it down and found that it was a pretty sophisticated 'hack' that was intended to only be displayed for search engines to piggy back on our pagerank. It seems that the FirePHP tool toggled the header in such a way that it appeared when that was enabled also. Anyway, we found down the offending file that has been used to add this hack and it appears that this file has been sitting dormant for quite a few months, just waiting to be used for nefarious purposes. Anyway, file removed, code removed, and security measures in place to watch for any new/changes to files. Hopefully this is now resolved once and for all. Thanks for bringing it to our attention!

      Cheers!
    • Webmosa's Avatar
    • Webmosa
    • Rocketeer
    • Posts: 80
    • Thanks: 0

    Re: Strange Spam

    Posted 15 years 1 month ago
    • No problem I am glad that I found it for you guys. I love the work you do, and I am a coder myself so I know how i would feel if someone was doing something like that to me. Plus it helps improve security and that's good for all of us.

Time to create page: 0.062 seconds