Gearslutz.com Hijacked?

Recording Techniques, People Skills, Gear, Recording Spaces, Computers, and DIY

Moderators: drumsound, tomb

User avatar
MisterMark
gettin' sounds
Posts: 134
Joined: Thu May 08, 2003 11:52 am
Location: Dallas, Tejas
Contact:

Gearslutz.com Hijacked?

Post by MisterMark » Thu Mar 01, 2012 7:14 am

Has anyone noticed when you go to gearslutz.com you get a portal to a porn site? Seems they may have been hijacked!

-Mark
Placid Audio - Home of the Copperphone

"Turn it up till it squeals then back it down a hair"
"Take these pills and pull down your pants... um, I mean, here take these pills"

User avatar
farview
tinnitus
Posts: 1204
Joined: Tue Aug 31, 2004 1:42 pm
Location: St. Charles (chicago) IL
Contact:

Post by farview » Thu Mar 01, 2012 8:42 am

Either it's fixed now, or your computer has been hijacked.

hasbeen
audio school graduate
Posts: 13
Joined: Wed Jul 12, 2006 7:55 pm

Post by hasbeen » Thu Mar 01, 2012 9:45 am

It may be fixed in your area but here in MA I am getting porn since last night.

hasbeen
audio school graduate
Posts: 13
Joined: Wed Jul 12, 2006 7:55 pm

Post by hasbeen » Thu Mar 01, 2012 9:49 am

Looks like it may be a cookie, google smart ad or cache thing, I am invetigating as it works on my phone.

User avatar
T-rex
dead but not forgotten
Posts: 2192
Joined: Mon Apr 05, 2004 5:44 am
Location: Louisville KY

Post by T-rex » Thu Mar 01, 2012 9:54 am

Works fine here. Honestly though, with a name like gearslutz you are pretty much asking for it. :shock:

User avatar
red cross
buyin' gear
Posts: 556
Joined: Wed May 28, 2003 4:43 am
Location: The Far East

Post by red cross » Thu Mar 01, 2012 11:43 am

Hacked for me as well. :lol:

User avatar
vvv
zen recordist
Posts: 10166
Joined: Tue May 13, 2003 8:08 am
Location: Chi
Contact:

Post by vvv » Thu Mar 01, 2012 11:55 am

I'm in Chicago - it's hacked for me as well.

(Just another kinda porn, eh? :twisted: )
bandcamp;
blog.
I mix with olive juice.

User avatar
Recycled_Brains
resurrected
Posts: 2354
Joined: Tue Nov 22, 2005 6:58 pm
Location: Albany, NY
Contact:

Post by Recycled_Brains » Thu Mar 01, 2012 12:05 pm

Reason number 1,974,234 to not bother with GS.
Ryan Slowey
Albany, NY

http://maggotbrainny.bandcamp.com

User avatar
MisterMark
gettin' sounds
Posts: 134
Joined: Thu May 08, 2003 11:52 am
Location: Dallas, Tejas
Contact:

Post by MisterMark » Thu Mar 01, 2012 12:27 pm

Hmmm... cleared my history and cookies and I'm still getting the porn portal... not looking for granny dating sites right now... any ideas?

-Mark
Placid Audio - Home of the Copperphone

"Turn it up till it squeals then back it down a hair"
"Take these pills and pull down your pants... um, I mean, here take these pills"

User avatar
T-rex
dead but not forgotten
Posts: 2192
Joined: Mon Apr 05, 2004 5:44 am
Location: Louisville KY

Post by T-rex » Thu Mar 01, 2012 12:58 pm

What browser are you using? I am getting the normal GS site with Firefox and Chrome.

For the record I don't know jack about this kind of stuff, but I thought I would throw that out there since its working for me. Oh, I also get the normal site from my kindle. Have you tried your phone?

User avatar
ulriggribbons
steve albini likes it
Posts: 398
Joined: Sun Oct 26, 2003 7:50 pm
Location: Seattle, WA

Post by ulriggribbons » Thu Mar 01, 2012 1:00 pm

Jules says a typo was made in one of the nameservers, and it will take a bit to repropogate. Give it some time...

juniorexploder
audio school
Posts: 8
Joined: Tue Jan 26, 2010 9:01 pm
Location: Indianola, Washington

Post by juniorexploder » Thu Mar 01, 2012 1:36 pm

You can access GS via their IP address...but I believe it's read only....I tried to post an ad...no go.

here's the IP

http://176.56.59.10/board/

eh91311
buyin' a studio
Posts: 803
Joined: Wed May 07, 2003 7:38 am
Location: NW Los Angeles

Post by eh91311 » Thu Mar 01, 2012 1:57 pm

I'm blocked when using gearslutz.com, using IP address# direct works but I can't log in, read only confirmed.

User avatar
Scodiddly
genitals didn't survive the freeze
Posts: 3981
Joined: Wed Dec 10, 2003 6:38 am
Location: Mundelein, IL, USA
Contact:

Post by Scodiddly » Thu Mar 01, 2012 5:25 pm

Recycled_Brains wrote:Reason number 1,974,234 to not bother with GS.
8)

Pro Jules
studio intern
Posts: 25
Joined: Wed May 07, 2003 10:38 am
Location: North London, UK

Post by Pro Jules » Sat Mar 03, 2012 6:53 am

Hi TapeOp peeps

Sorry for being off-line on Thurs 1st March!

What happened?

Gearslutz changed web hosts back in June 2011 and the migration went well. During this migration an error was made when the nameservers were configured. One of the nameservers was misspelled and under normal circumstances this would have not caused any issues other than slightly less resilience in the DNS infrastructure.

On 1 March 2012 a hacker noticed this domain exploit and registered the misspelled domain name. They used this domain typo to redirect approximately 1/3rd of visitors to a "branded" web page that makes money off page clicks. Our web host corrected the misspelling as soon as it was identified at 7am GMT.

Why was this not resolved sooner?
The hacker used a domain name with a time to live (TTL) of one day. This TTL means that any forum users who were redirects to this branded web page would have it cached for 24 hours.

Was I hacked?
The aim of this hack was to make money from the hyper link clicks rather than compromise end users PCs and Macs. But to be on the safe side the techs at our server company scanned the web page - and confirmed no viruses or snide scripts. Your computer is clean!

Will this happen again?
No. The changes we've made are permanent and will stop this from happening again. We will also be moving our domain registration to our web hosting provider so any future updates will be handled automatically to prevent any further typos.

The end result was a typo over a year old caused the site to be inaccessible for 1/3rd of its visitors and boring wait until the DNS propagated.

Sorry for the interruption in service!

if you are still getting the bogus site here is a link that tells you how to flush your DNS http://www.tech-faq.com/how-to-flush-dns.html

Thanks

Jules
GS Admin
Jules
Gearslutz.com admin

Post Reply

Who is online

Users browsing this forum: digitaldrummer, drumsound and 142 guests