Re: Is google ignoring me?
I tried a traceroute and this is the output:
5 195.66.224.186 (195.66.224.186) 36.008 ms 32.383 ms 21.954 ms
6 83.244.255.5 (83.244.255.5) 25.271 ms 29.166 ms 24.561 ms
7 transit-i-gw2.hastwood.com (83.244.134.86) 24.363 ms 21.602 ms 26.281 ms
8 telivo-gw.cust.hastwood.net (83.244.171.178) 26.581 ms 30.005 ms 30.450 ms
After that I just have the ping rejected by firewalls
I have not been able to find any whois info on the 83.224 IP range other than the netblock 'owner'.
The browser logs show clear 200 responses for the content and no redirects in sight.
My only question relating to the browser logs is: what is squid doing?
X-Cache: HIT from localhost
Via: 1.0 localhost (squid/3.0.PRE5)
Connection: close
To explain: squid is a program which is being used by profilers like Phorm to do the nasty 307 redirects to data packets - it is how Phorm forges the profiling cookies and intercepts, to make a copy of, all your internet traffic.
I have sent a search engine bot to ibslog.com using google, msn and yahoo as useragent ID and each one was able to view the page with the correct content and did not show any redirects.
That leaves only one explanation: squid is redirecting googlebot on IP address sniffing to the advert page.
This could be happening through a router which has been hacked and has a DNS hijack malware / rootkit inserted into it. Or the host server itself could be hacked and sending whatever it is programmed to send via a back door.
David, if I were you I would contact the e-commerce section of you local police and report that you suspect an e-crime is/has being perpetrated at your hosting company and ask them to investigate. Print off the responses on this page as part of your evidence. Do it today before the compromised 'script' is removed from your host.
Good luck.
I don't recommend anyone else visit the site until the squid hijack has been removed (unless your computer is very well protected and you know how to disinfect rootkits)- new hosting highly recommended.
David, please edit your first post to add this warning for anyone who does not read down this far.
|