<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The website hack you&#8217;d never find</title>
	<atom:link href="http://johnmu.com/hack-hidden-redirect/feed/" rel="self" type="application/rss+xml" />
	<link>http://johnmu.com/hack-hidden-redirect/</link>
	<description>John Mueller's technical website tips and tricks</description>
	<lastBuildDate>Mon, 26 Dec 2011 05:37:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: John Burns</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-1274</link>
		<dc:creator>John Burns</dc:creator>
		<pubDate>Wed, 11 May 2011 20:25:02 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-1274</guid>
		<description>Hi, I am pretty sure I have this same hack. It is very tricky. I think it is on 3 of my websites. I clicked my link through google and was forwarded to an affiliate site for a competing company selling a similar product that I sell. I am willing to pay John Mu to do the research for me and find out. Everyone in my organization thinks I&#039;m crazy and that it&#039;s spyware on my computer. However, my buddy with a apple computer also searched on google and clicked through my link on google and ended up on the same redirected site, and he was using a Mac, I am on PC.

It doesn&#039;t do it all the time, only some times. And it&#039;s not currently doing it right now, but I have seen it happen on multiple occasions. Please contact me I am willing to hire you John Mu to take a look and try to help me prove my organization wrong. They are telling me that it is spyware on my PC(which it could be) but I am almost certain that the website is hacked. Please contact me.</description>
		<content:encoded><![CDATA[<p>Hi, I am pretty sure I have this same hack. It is very tricky. I think it is on 3 of my websites. I clicked my link through google and was forwarded to an affiliate site for a competing company selling a similar product that I sell. I am willing to pay John Mu to do the research for me and find out. Everyone in my organization thinks I&#8217;m crazy and that it&#8217;s spyware on my computer. However, my buddy with a apple computer also searched on google and clicked through my link on google and ended up on the same redirected site, and he was using a Mac, I am on PC.</p>
<p>It doesn&#8217;t do it all the time, only some times. And it&#8217;s not currently doing it right now, but I have seen it happen on multiple occasions. Please contact me I am willing to hire you John Mu to take a look and try to help me prove my organization wrong. They are telling me that it is spyware on my PC(which it could be) but I am almost certain that the website is hacked. Please contact me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gray</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-1150</link>
		<dc:creator>Gray</dc:creator>
		<pubDate>Sun, 22 Mar 2009 21:51:31 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-1150</guid>
		<description>Update: I recreated the redirect by browsing through a proxy. I notified my hosting company... sent them the transcript on this page for them to read, and told them to inspect the http.conf file and to look for rewrites.  They emailed me back after an hour informing me that they had found the malicious code and removed it, also put measures in to stop it happening again.  They were pretty shocked and surprised to say the least.  So thankyou for taking the time and effort to post here what happened to you, allowing us to benefit from your experience.</description>
		<content:encoded><![CDATA[<p>Update: I recreated the redirect by browsing through a proxy. I notified my hosting company&#8230; sent them the transcript on this page for them to read, and told them to inspect the http.conf file and to look for rewrites.  They emailed me back after an hour informing me that they had found the malicious code and removed it, also put measures in to stop it happening again.  They were pretty shocked and surprised to say the least.  So thankyou for taking the time and effort to post here what happened to you, allowing us to benefit from your experience.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gray</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-1149</link>
		<dc:creator>Gray</dc:creator>
		<pubDate>Sun, 22 Mar 2009 12:16:11 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-1149</guid>
		<description>I have a similar problem, noticed whenever I search google for my site form another computer I get this redirect to a lvhook.biz with an alert from avg about a trojan.  Only once, then subsequent searches goes straight to my site.  Is this code hidden on my page somewhere? I reported the problem to my host, but they could find no problem on the server.  I&#039;d already worked out it was the google referer that triggered this, and searching found this page. Great work by the way.</description>
		<content:encoded><![CDATA[<p>I have a similar problem, noticed whenever I search google for my site form another computer I get this redirect to a lvhook.biz with an alert from avg about a trojan.  Only once, then subsequent searches goes straight to my site.  Is this code hidden on my page somewhere? I reported the problem to my host, but they could find no problem on the server.  I&#8217;d already worked out it was the google referer that triggered this, and searching found this page. Great work by the way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hackers stealing your PageRank &#187; johnmu.com</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-1086</link>
		<dc:creator>Hackers stealing your PageRank &#187; johnmu.com</dc:creator>
		<pubDate>Sun, 07 Dec 2008 23:44:58 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-1086</guid>
		<description>[...] last time I wrote about a hacked site, it was using a redirect that sent some users to a different site. This kind of hack is pretty [...]</description>
		<content:encoded><![CDATA[<p>[...] last time I wrote about a hacked site, it was using a redirect that sent some users to a different site. This kind of hack is pretty [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben LaGrone</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-1066</link>
		<dc:creator>Ben LaGrone</dc:creator>
		<pubDate>Sat, 04 Oct 2008 23:27:07 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-1066</guid>
		<description>I found that some of the sites like this often deploy a cookie the first time you visit, then change it on a later visit. The contents of the cookie determine where they will redirect you.

My impression was that their intent was to get their money by redirecting click traffic, and then using the virus page to scare away curious return snoopers.

I also found the Microsoft Spam Double Funnel paper to be useful information http://research.microsoft.com/research/pubs/view.aspx?type=Technical%20Report&amp;id=1269.</description>
		<content:encoded><![CDATA[<p>I found that some of the sites like this often deploy a cookie the first time you visit, then change it on a later visit. The contents of the cookie determine where they will redirect you.</p>
<p>My impression was that their intent was to get their money by redirecting click traffic, and then using the virus page to scare away curious return snoopers.</p>
<p>I also found the Microsoft Spam Double Funnel paper to be useful information <a href="http://research.microsoft.com/research/pubs/view.aspx?type=Technical%20Report&#038;id=1269" rel="nofollow">http://research.microsoft.com/research/pubs/view.aspx?type=Technical%20Report&#038;id=1269</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Chansky</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-1062</link>
		<dc:creator>Rob Chansky</dc:creator>
		<pubDate>Tue, 30 Sep 2008 22:36:57 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-1062</guid>
		<description>Oh crap. I&#039;ve been hacked by this.

I was redirected to this page by a buddy of mine when I mentioned the problem I was having. A few months ago my site stats reported a 90% drop in hits which have all turned into 302 temporary redirect messages.

What can I do to get rid of this??</description>
		<content:encoded><![CDATA[<p>Oh crap. I&#8217;ve been hacked by this.</p>
<p>I was redirected to this page by a buddy of mine when I mentioned the problem I was having. A few months ago my site stats reported a 90% drop in hits which have all turned into 302 temporary redirect messages.</p>
<p>What can I do to get rid of this??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben LaGrone</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-988</link>
		<dc:creator>Ben LaGrone</dc:creator>
		<pubDate>Mon, 28 Apr 2008 17:23:57 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-988</guid>
		<description>John,

BTW I&#039;ve found Fiddler very useful, but have hit a brick wall.</description>
		<content:encoded><![CDATA[<p>John,</p>
<p>BTW I&#8217;ve found Fiddler very useful, but have hit a brick wall.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben LaGrone</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-987</link>
		<dc:creator>Ben LaGrone</dc:creator>
		<pubDate>Mon, 28 Apr 2008 17:22:21 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-987</guid>
		<description>Hi John,

I&#039;m trying to solve a similar mystery. Can I PM you the URL and see if you have any ideas. I&#039;m trying to trace a cloaked redirect...</description>
		<content:encoded><![CDATA[<p>Hi John,</p>
<p>I&#8217;m trying to solve a similar mystery. Can I PM you the URL and see if you have any ideas. I&#8217;m trying to trace a cloaked redirect&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tristan</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-960</link>
		<dc:creator>Tristan</dc:creator>
		<pubDate>Sat, 01 Mar 2008 04:01:44 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-960</guid>
		<description>Great project!! You should be on google payrole!

John: &quot;That could be a security issue in Firefox&quot; :- given this would you recommend staying with Internet Explorer / Other for security reasons? I was considering Firefox due to repeated &quot;IE not responding&quot;.

Do you think the antivirus advert (hidden hack redirect) was a joke or a moneyspinner or both?

BTW FYI I found this page after visiting http://groups.google.com/group/Google_Webmaster_Help-Requests/browse_thread/thread/3238914c52ff7b18/3f4de587650273fc

After an AVG activex thing popped up in ie7 while visiting a christianity page.  I clicked no.  Did that mean the page was triggering AVG or a virus pretending to? I ran AVG afterwards  and it found a &quot;virus identified exploit.ANI&quot; in my temp.  Did I prevent the virus spreading out of temp by clicking NO on the ActiveX request or prevent AVG catching it?  What use is the thing in temp anyway? 

Just curious (re:spam protection on this page).. Sum of 7 + 4.. can see how me typing in 11 would partially suggest I was a human; but as 11 is allready show in the field does this mean SHOWING question is redundant? My guess is prob&#039; no, but I&#039;m so curious :)

Brilliant work btw.. Tris.</description>
		<content:encoded><![CDATA[<p>Great project!! You should be on google payrole!</p>
<p>John: &#8220;That could be a security issue in Firefox&#8221; :- given this would you recommend staying with Internet Explorer / Other for security reasons? I was considering Firefox due to repeated &#8220;IE not responding&#8221;.</p>
<p>Do you think the antivirus advert (hidden hack redirect) was a joke or a moneyspinner or both?</p>
<p>BTW FYI I found this page after visiting <a href="http://groups.google.com/group/Google_Webmaster_Help-Requests/browse_thread/thread/3238914c52ff7b18/3f4de587650273fc" rel="nofollow">http://groups.google.com/group/Google_Webmaster_Help-Requests/browse_thread/thread/3238914c52ff7b18/3f4de587650273fc</a></p>
<p>After an AVG activex thing popped up in ie7 while visiting a christianity page.  I clicked no.  Did that mean the page was triggering AVG or a virus pretending to? I ran AVG afterwards  and it found a &#8220;virus identified exploit.ANI&#8221; in my temp.  Did I prevent the virus spreading out of temp by clicking NO on the ActiveX request or prevent AVG catching it?  What use is the thing in temp anyway? </p>
<p>Just curious (re:spam protection on this page).. Sum of 7 + 4.. can see how me typing in 11 would partially suggest I was a human; but as 11 is allready show in the field does this mean SHOWING question is redundant? My guess is prob&#8217; no, but I&#8217;m so curious <img src='http://johnmu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Brilliant work btw.. Tris.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mrg</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-166</link>
		<dc:creator>mrg</dc:creator>
		<pubDate>Tue, 04 Sep 2007 17:51:21 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-166</guid>
		<description>Adding a little... You don&#039;t need to use a proxy if you are on windows. Back when we looked at the other hacked site with this same exploit all I had to do was to repair the connection to get a new IP address. And every time after that, when checking LiveHTTPHeaders it triggered the 302.</description>
		<content:encoded><![CDATA[<p>Adding a little&#8230; You don&#8217;t need to use a proxy if you are on windows. Back when we looked at the other hacked site with this same exploit all I had to do was to repair the connection to get a new IP address. And every time after that, when checking LiveHTTPHeaders it triggered the 302.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Show heute fällt leider aus &#124; seoFM - der erste deutsche PodCast für SEOs und Online-Marketer</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-108</link>
		<dc:creator>&#187; Show heute fällt leider aus &#124; seoFM - der erste deutsche PodCast für SEOs und Online-Marketer</dc:creator>
		<pubDate>Tue, 28 Aug 2007 14:32:37 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-108</guid>
		<description>[...] Der wohl sneaky-ste Website Hack bislang [...]</description>
		<content:encoded><![CDATA[<p>[...] Der wohl sneaky-ste Website Hack bislang [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hearne</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-92</link>
		<dc:creator>Richard Hearne</dc:creator>
		<pubDate>Sun, 26 Aug 2007 10:33:58 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-92</guid>
		<description>Indeed rather scary stuff. Possibly one of the nastier exploits I&#039;ve heard of recently.

I think tracking down the aff codes might help - removing some of the financial gain would be a start. I&#039;m sure the installed payload is also just as nasty given the lengths the hackers have gone to...</description>
		<content:encoded><![CDATA[<p>Indeed rather scary stuff. Possibly one of the nastier exploits I&#8217;ve heard of recently.</p>
<p>I think tracking down the aff codes might help &#8211; removing some of the financial gain would be a start. I&#8217;m sure the installed payload is also just as nasty given the lengths the hackers have gone to&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Mueller</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-79</link>
		<dc:creator>John Mueller</dc:creator>
		<pubDate>Fri, 24 Aug 2007 11:01:48 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-79</guid>
		<description>Good, then it&#039;s not that bad :-) *big sigh of relief*</description>
		<content:encoded><![CDATA[<p>Good, then it&#8217;s not that bad <img src='http://johnmu.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  *big sigh of relief*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Altoft</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-78</link>
		<dc:creator>Patrick Altoft</dc:creator>
		<pubDate>Fri, 24 Aug 2007 11:00:04 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-78</guid>
		<description>I do use FF. It does just show the persons name at the top of the page.</description>
		<content:encoded><![CDATA[<p>I do use FF. It does just show the persons name at the top of the page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Mueller</title>
		<link>http://johnmu.com/hack-hidden-redirect/comment-page-1/#comment-77</link>
		<dc:creator>John Mueller</dc:creator>
		<pubDate>Fri, 24 Aug 2007 10:57:42 +0000</pubDate>
		<guid isPermaLink="false">http://johnmu.com/hack-hidden-redirect/#comment-77</guid>
		<description>I tried Netvibes - you don&#039;t get redirected, but you see a part of the content here on their page (at least that&#039;s what I see). I see the name of the person from the original posting on the netvibes page and then this blog entry opens up in a separate window. Maybe I was a bit too sneaky for my own good, I hid that name from indexing by using javascript to display it (so that this page doesn&#039;t rank for his name). Apparently that javascript snippet is executed on the old page, before the redirect to the new window takes place. That could be a security issue in Firefox... (did you use Firefox as well?)</description>
		<content:encoded><![CDATA[<p>I tried Netvibes &#8211; you don&#8217;t get redirected, but you see a part of the content here on their page (at least that&#8217;s what I see). I see the name of the person from the original posting on the netvibes page and then this blog entry opens up in a separate window. Maybe I was a bit too sneaky for my own good, I hid that name from indexing by using javascript to display it (so that this page doesn&#8217;t rank for his name). Apparently that javascript snippet is executed on the old page, before the redirect to the new window takes place. That could be a security issue in Firefox&#8230; (did you use Firefox as well?)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.221 seconds -->

