Looks like Win20 went down… I’ll be working to turn off ASP, PHP and ASP.net on the sites that aren’t using them as well. They seem to all be turned on by default. Looks like most of this stuff was caused by black hat SEO services.
Yes win20 went down thats what I posted about in status forum, ran a chkdsk and got it back up.
At this point, I’ve gone through and turned off all unnecessary languages on accounts - moving over to a Server2008 server seems simple enough but somehow I’m dreading implications with SSL certificates etc. and those short-term headaches which I can’t deal with at the moment.
WE can move the SSL for you, it isn’t a dread ![]()
I’ve just learned a bit more tonight and how some of this is happening, I think I have a brick to throw in their face, but not going to say till I have deployed on all services.
I’d be interested in hearing more about how’s this is occurring for sure. Especially if it is something that I need to correct on my end or learn about. A brick in their face would be too kind!
So Jodo moved all my affected sites to 2008 and Jodo helped clean the sites. Thank you!
I also manually cleaned all files, ran diffs to make sure any changes were removed and I even uploaded complete sites and clean files from local backups but Google is still saying they suspect hacking on the affected sites and, starting today new sites. I’ve looked thru the sites and files again and can’t find any cloaking, hacking, link insertions, changes, etc… I also submitted reconsiderations for several of the initially affected sites and most were approved, but now I’m getting suspected hacking notices again? Seriously frustrating… Any ideas?
Keep checking the logs to see if there is unusual traffic that might point you to something you missed. I found Google Analytics sometimes useful to show a file that was getting a high number of hits where it shouldn’t be.
IMHO Google are as much to blame for directing search results to pages they say are hacked, and then not telling you what exactly the problem is. They do occasionally answer emails and give more information, but their response is pretty spotty.
Let me know the domains again that are saying this? (PM if needed)
BTW we have seriously stepped up the removal/quarantine of any virus/malware. We added that to the TOS over a year ago, but we’d been to slack on scans, we are now doing nightly scans and live scans with a few exceptions, and moving any suspect files to quarantine.
And yes google has been frustrating with the ‘malware’ and ‘hacking’ alerts when they give you little to no detail, and it can be subdomains of subdomains or even wildcard DNS entries.
I’ve tried to connect to win38 and win39 using Webdav and it won’t work using Windows web folders or NetDrive. Has anyone else had success with this?
WebDAV needs some setup and we are testing it, we have some limited success but not complete. I never realized webDAv was such a pain!