Post by m.w » Fri Oct 02, 2020 12:17 pm

Some of the customers have noted that on mobile they are getting these spam redirects while they are browsing my site. I've attached a couple of samples. Can somebody help me to identify the cause and possible solutions to this. Since this is a new issue that I've not seen or tackled with before I'm at a loss where to start. Any help is appreciated.

Attachments

WhatsApp Image 2020-10-01 at 9.46.08 AM.jpeg

WhatsApp Image 2020-10-01 at 9.46.08 AM.jpeg (53.43 KiB) Viewed 1067 times

WhatsApp Image 2020-09-30 at 10.15.59 PM.jpeg

WhatsApp Image 2020-09-30 at 10.15.59 PM.jpeg (28.89 KiB) Viewed 1067 times


m.w
Newbie

Posts

Joined
Fri Jan 17, 2020 7:59 am

Post by sw!tch » Fri Oct 02, 2020 12:48 pm

Link to your site?

Backup and learn how to recover before you make any changes!


Active Member

Posts

Joined
Sat Apr 28, 2012 2:32 pm

Post by paulfeakins » Fri Oct 02, 2020 6:21 pm

m.w wrote:
Fri Oct 02, 2020 12:17 pm
Some of the customers have noted that on mobile they are getting these spam redirects while they are browsing my site. I've attached a couple of samples. Can somebody help me to identify the cause and possible solutions to this. Since this is a new issue that I've not seen or tackled with before I'm at a loss where to start. Any help is appreciated.
Contact Astra.

UK OpenCart Hosting | OpenCart Audits | OpenCart Support - please email info@antropy.co.uk


User avatar
Legendary Member

Posts

Joined
Mon Aug 22, 2011 11:01 pm
Location - London Gatwick, United Kingdom

Post by m.w » Mon Oct 05, 2020 7:13 pm

sw!tch wrote:
Fri Oct 02, 2020 12:48 pm
Link to your site?
oshadhi.my

m.w
Newbie

Posts

Joined
Fri Jan 17, 2020 7:59 am

Post by IP_CAM » Mon Oct 05, 2020 8:07 pm

That must be the weirdest coded Journal Theme extension I've ever seen. :crazy:
It's possibly some Journal Darknet Download, containing some nasty Code ....

My Github OC Site: https://github.com/IP-CAM
5'600 + FREE OC Extensions, on the World's largest private Github OC Repository Archive Site.


User avatar
Legendary Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland

Post by letxobnav » Mon Oct 05, 2020 8:24 pm

Maybe tell those customers to stop downloading crap on their mobile phones.
There is nothing to suggest this comes via your site.

PS. I would reconsider the moving balls on every page request, hyper annoying.

Crystal Light Centrum Taiwan
Extensions: MailQueue | SUKHR | VBoces

“Data security is paramount at [...], and we are committed to protecting the privacy of anyone who is associated with our [...]. We’ve made a lot of improvements and will continue to make them.”
When you know your life savings are gone.


User avatar
Expert Member

Posts

Joined
Fri Aug 18, 2017 4:35 pm
Location - Taiwan

Post by m.w » Tue Oct 06, 2020 12:05 pm

letxobnav wrote:
Mon Oct 05, 2020 8:24 pm
Maybe tell those customers to stop downloading crap on their mobile phones.
There is nothing to suggest this comes via your site.

PS. I would reconsider the moving balls on every page request, hyper annoying.
That was my first suggestion. But the clients insisted I look for some bad code or suspicious files. I want to cover my bases so I was looking for any way this could be a problem from the site.
They have since gotten more specific with me indicating it to only happen on this https://oshadhi.my/index.php?route=prod ... ct_id=1160 page. But so far I have not been able to replicate the issue using any of my devices. They have currently disabled the product as the promotion was over.

EDIT: I hate incomplete information. So they were linking to the above mentioned page via an FB post. And they were using a URL shortner as well. And the first time I clicked on it I got redirected to the spam page as well. So I'm gonna conclude that this is either an issue with the URL shortner or FB itself or a combination of both.

m.w
Newbie

Posts

Joined
Fri Jan 17, 2020 7:59 am
Who is online

Users browsing this forum: Amazon [Bot] and 4 guests