Jump to content

Potentially hijacked banner destination URL


IvorD

Recommended Posts

I'm posting to see if anyone has experienced anything as curious as the following:

We received an alert from the Google Search Console about an invalid redirection. (I vetted the message to ensure it was legitimate.) The link they supplied was a Revive ad link from our server with legitmate zone and banner IDs but an incorrect destination URL:

https://SITE/adserver/www/delivery/ck.php?oaparams=2__bannerid=16__zoneid=13__cb=bf7c125ee0__oadest=http://asmilingmalice.tumblr.com%22%3EBeautiful

whereas the correct (& current) ad link is:

https://SITE/adserver/www/delivery/ck.php?oaparams=2__bannerid=16__zoneid=13__cb=d44ce9c8e3__oadest=http%3A%2F%2Fwww.freekibblekat.com%2F

Apart from being the incorrect URL, the bogus one includes "> (quote, greater-than) before the "Beautiful", like it was scraped incorrectly from somewhere.

I've been back through several months of nightly database backups and can find no evidence of the banner record with the bogus URL and the database is correct today. I've reviewed all of the banner destination links both visually to see that they are as intended and programmatically to checked they can be visited (and found a few that no longer work).

I found no modified source files. I've upgraded from 4.1.4 to 4.2.1 anyway to ensure a fresh set of source files.

So I'm currently stumped about how this one destination URL could have been tampered with, apparently temporarily, and would be very interested in similar experiences or insights into what might have transpired. Any ideas?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...