URL param abuse or hacked site?

https://fjoelner.dk/process.asp?aktion=RESETRELINK&gotourl=//33313m.com/113fjoelnerdkpuF651

Warning! the link leads to malware, virus, pron or similar through a series of redirects.

This is an URL grabbed from Google SERP. I’ve come across quite a few of these. Mostly from asp.NET sites. You can find more examples (using other params) by simply googling “inurl:33313m.com”. I have a small list of redirect target sites if anyone is curious to take a look themselves.

I don’t really know how it works, but it looks to me like the “attacker” might be spamming inlinks to this URL (with params) that then performs a redirect. Is that so? Or is the site itself hacked?

Some time ago several groups did something similar with WP sites using the URL query param. Obviously, they could not redirect, but they did get them indexed with some keywords, which might have been a part of the some SEO campaign. Is this the same, just with redirects?

I’m just a curious noob, please enlighten me!

submitted by /u/C0ffeeface
[link] [comments]

April 2, 2023
Read More >>