• Welcome to the DeeperBlue.com Forums, the largest online community dedicated to Freediving, Scuba Diving and Spearfishing. To gain full access to the DeeperBlue.com Forums you must register for a free account. As a registered member you will be able to:

    • Join over 44,280+ fellow diving enthusiasts from around the world on this forum
    • Participate in and browse from over 516,210+ posts.
    • Communicate privately with other divers from around the world.
    • Post your own photos or view from 7,441+ user submitted images.
    • All this and much more...

    You can gain access to all this absolutely free when you register for an account, so sign up today!

url2SHORT.INFO

Thread Status: Hello , There was no answer in this thread for more than 60 days.
It can take a long time to get an up-to-date response or contact with relevant users.

baiyoke

Well-Known Member
Nov 13, 2011
485
84
58
Hi webbie.

On many occasions in the past two months, on many different computers, when entering through goggle (searching "deeperblue.com"), I get instantly redirected to "url2SHORT.INFO", a webpage that I cannot close, unless I use ctrl+alt+delete and end all open windows.

It ONLY happens when I want to visit deeperblue.com. Sometimes it happens, sometimes it doesn't...

On a few (2 or 3) occasions it has happended after I entered the site, but was moving around, perhaps doing login (not sure).

Any idea what's going on???

Thanx
 
I think the vBSEO module of the DB forum has a vulnerability that can be exploited in this way. I found some related info here: Security issue - vBulletin SEO Forums

Needs to be fixed anyway, but I wonder why you access the forum through Google. Simply bookmark it, and you can access it quickly without having to go through Google.
 
I get directed to the same site occasionally when I try to access a forum post from the google RSS reader...
 
Needs to be fixed anyway, but I wonder why you access the forum through Google. Simply bookmark it, and you can access it quickly without having to go through Google.

Yeah I can do that... And I kind of wondered the same thing myself... Really had to think there... :)... well, it's because I'm used to using the drop-down adress-bar as my shortcut/"bookmark", but other people sometimes using my computer keep messing up the history because of "privacy"/deleted history/whatever... that deletes some (but not all) of the adresses... ... So I just got a (bad) habbit of using google quickly whenever it's not in the adress-bar, because google is my startpage... And because I'm new to this site, and could not remember if it was deeperdiving, deeperblue, deepersomething in the beginning, so I always googled (it a bit too many times ha ha...).

I've bookmarked it now, but if using a different computer it shows up again... Allthough I could just type the adress in directly instead I guess...

I'll deal with it from here, but I'm also thinking about people trying to visit deeperblue.com for the first time, and never coming back because of that...
 
Last edited:
I haven't been able to replicate the issue. Can someone post the EXACT steps they take to reproduce this.
 
Nevermind - was able to replicate. Am working on trying to secure against this.
 
I believe this has been patched now. If anyone sees any suspicious activity around this sort of thing please let me know ASAP.
 
  • Like
Reactions: Kars
Ivo - I think the question was if it was due to XSS rather than asking what XSS is :)

There was a vulnerability in one of the plugins that we run on this forum so i've taken steps to get that patched, add tracking and security aspects for the vector and will keep an eye on it.
 
Yes :) I didn't manage to see it before Stephan patched it so was just curious to find out if the exploit was due to XSS
 
FYI ther's still a vulnerability... Just got redirected to myfilestore.com, and when trying to close page, a pop-up tells me I have won something... I'm not able to close page, only if using ctrl+alt+delete.

I googled deeperblue from a friends computer, and clicked on second link: "forum".
 
Correct - looks like there is a separate vulnerability that has been identified. Trying to figure out the vector and close it down.
 
DeeperBlue.com - The Worlds Largest Community Dedicated To Freediving, Scuba Diving and Spearfishing

ABOUT US

ISSN 1469-865X | Copyright © 1996 - 2024 deeperblue.net limited.

DeeperBlue.com is the World's Largest Community dedicated to Freediving, Scuba Diving, Ocean Advocacy and Diving Travel.

We've been dedicated to bringing you the freshest news, features and discussions from around the underwater world since 1996.

ADVERT