Site Scripting Prevention

There is a wordpress site hosted at http://www.vibrantneo.org and is currently being cloned at http://vibrantneo.123productpages.com/ somehow . It is very strange that this particular domain ( http://www.123productpages.com ) seems to do this with A LOT content, but there are no messages on the Internet.

This service has not been selected. This was done without consent. I checked Firebug and the link to the source site server is not mentioned. Is this a malicious site? Why is there no discussion of this β€œservice” affecting others?

* UPDATE * It turns out that this 123productpages actually refers to the actual http://www.vibrantneo.org host files. For example: changing wp-config to invalid credentials will delete both sites.

Probably a Trojan. It is still confusing how this domain and its practice have not become more public. Hope this post finds its way to people with the same problem, as long as I pinpoint the point of failure.

* UPDATE # 2 * Thus, it seems like this is not as malicious as I suspected. Although still very unethical. It looks as simple as pulling content and changing all the links to their domain. All content is still hosted on a real server.

For example: http://blah.123productpages.com will reflect www.blah.com. Of course, they will have to "configure" this particular domain at their end. It seems.

My current fix involves adding a simple js snippet to check the encrypted psuedo domain and find out if it is a proper domain and redirected if it isn't.

The following is an example of blah.com. domain is just a domain, blah.com, shared by a simple 123 (of course, a more complex key can be created).

 <script type="text/javascript"> var u = top.location.toString(); var domain = 'b123l123a123h123.123c123o123o123m'.toString(); var domain_decrypted = domain.replace(/123/gi, ''); if (u.indexOf(domain_decrypted) == -1) { top.location = 'http://' + domain_decrypted; } </script> 
+4
source share
2 answers

If you publish content in a public manner, you can clear it. You can spend time looking for traffic that looks like it came out of a scraper and then blocks this IP address, but this is a tedious game with a cat and a mouse.

My advice was to accept this as the reality of posting content on the Internet and move on.

+3
source

Maybe you can send 123productpages.com a fax prohibiting them from copying your content?

Here is their contact information according to whois:

WhoIs Check for 123productpages.com:

= - = - = - =

Registered Through: DomainPeople, Inc.

Domain Name: 123productpages.com

Contact Registrar: WhoisProtector Inc. WhoisProtector 123productpages.com () Fax: 100 N Riverside, Suite 800 Chicago, IL 60606 US

Administrative Contact: WhoisProtector Inc. WhoisProtector 123productpages.com ( 123productpages.com@WhoisProtector.com )
+1.3129947654 Fax: 100 N Riverside, Suite 800 Chicago, IL 60606 US

Technical Contact: WhoisProtector Inc. WhoisProtector 123productpages.com ( 123productpages.com@WhoisProtector.com )
+1.3129947654 Fax: 100 N Riverside, Suite 800 Chicago, IL 60606 US

Status: Blocked

Name servers: ns1.publishergateway.net ns2.publishergateway.net Creation date: June 28, 2009 18:47:26 Expiration date: June 28, 2013 18:47:00

+1
source

All Articles