Score:0

Strange redirect text in page cache entries

mz flag

My Drupal site is having some redirect malware issues. I suspected some strange redirects and tried to catch redirects by caching them through Nginx. Below is the output of one redirect.

Page https://www.test.com/officialsite doesn't exist on the site. No URL redirect with this value.

However, visiting https://www.test.com/officialsite produces a redirect loop because it leads back to Nginx instead of hitting Drupal which would have possibly redirected it elsewhere as a result of malware.

What I have done:

  • Checked all files (no changes - we manage the codebase via a Git repository)
  • Checked Variables and System Tables and can't find anything unless I am not looking for correct
  • Running Drupal 7 up to date

And running out of ideas!


Sorry can't enclose it in code as it loses formatting.

^E^@^@^@^@^@^@^@¯Ô d^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@ÿÿÿÿÿÿÿÿ/à<9c>d^@^@^@^@<8b>Ù¾B^@^@g^AJ^B^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@ KEY: /officialsiteGET ^A^F^@^A^@Û^E^@Status: 301 Moved Permanently^M X-Drupal-Cache: HIT^M Link: https://www.test.com/officialsite; rel="canonical"^M Location: https://www.test.com/officialsite^M Content-type: text/html; charset=UTF-8^M ^M

unusedspoon avatar
aq flag
My guess is your site has been hacked and the malicous code is trying to redirect your users elsewhere. If your code is in a git repository doing a "git diff" on the live server will likely show lots of altered code
Jaypan avatar
de flag
Looks pretty hacked to myself as well.
JM John avatar
mz flag
Are you sure? Is it not gzipped?
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.