Jump to content

Recommended Posts

Posted (edited)

If I search for parentmail, click on the Google link, it sits like this for ages:

1.png

 

 

Note the URL loading at the bottom.

 

After a few minutes it times out and loads this:

 

2.png

 

 

We only get this the first time we load the page, every subsequent page refresh it goes straight to the proper site. I've so far tested this on: our simsserver, a Windows 10 desktop even a brand new imaged Windows 10 PC, with me as the first logged in user.

 

Can anyone replicate this?? (you might need to try a PC without and adblocker on).

 

If it's them, they obviously need telling, but I also want to make sure it's not us! (AV isn't picking anything up, and there are no plugins loaded).

Edited by elsiegee40
Posted

Does this happen if you go in fresh as it were and browse directly to the url rather than using google?

Basically some malware on sites can only trigger when coming from certain sites like google to make it harder for the site owner to pick up.

Posted
Does this happen if you go in fresh as it were and browse directly to the url rather than using google?

Basically some malware on sites can only trigger when coming from certain sites like google to make it harder for the site owner to pick up.

 

It definitely happens going through Google. I've just remoted into another school and it's also happening from that school.

 

I'd ring them, but there's no point, you just go around in circles in their automated menus and then get a message to email!

Posted

Clearing cookies and reloading the site causes the site to redirect on the next refresh, and for adverts to start popping up again.

 

I'm pretty much 100% that they've had their site hacked!

Posted (edited)

I just tried my end and I can see several URL calls in the dev tools that are very suspicious.

 

Most of them end with /i.php?ver=5.5.1 and I currently see 5 domains which I wouldnt expect to be part of parentmail. I am not posting the full urls directly as it may lead to links to them.

Edited by ZeroHour
  • Thanks 1
Posted
Just tried and same thing happened. Slow page load and then add redirect when clicking on a menu item.

 

I just tried my end and I can see several URL calls in the dev tools that are very suspicious.

 

Most of them end with /i.php?ver=5.5.1 and I currently see 5 domains which I wouldnt expect to be part of parentmail. I am not posting the full urls directly as it may lead to links to them.

 

Cheers both. I eventually got through to their sales line and I've let them know.

  • Thanks 2
Posted (edited)
Just tested it and yup, I'm seeing it too.

Someone has a problem! Big problem!

 

I was at a school when I noticed it, and they obviously want to know if there's a GDPR breach they need to be aware of and should report.

 

If there is, someone definitely has a big problem because it's going to be half the schools in the country!

Edited by Cazale
Posted (edited)

Here is what's happening when I visit it in Firefox in private browsing mode, via a Google Search. You have to click to trigger it.

Not... good....

 

Edited by paulkerton
  • Thanks 3
Posted

I suspect the front page may be using Wordpress with the backend a different system once you buy it. There was a big Wordpress plug-in exploit a couple of weeks ago and it affected a HUGE amount of sites potentially if not ninja pitched.

If the systems are separate than hopefully customer data is safe and secure so it would be a lesser incident then.

  • Thanks 1
Posted (edited)
I suspect the front page may be using Wordpress with the backend a different system once you buy it. There was a big Wordpress plug-in exploit a couple of weeks ago and it affected a HUGE amount of sites potentially if not ninja pitched.

If the systems are separate than hopefully customer data is safe and secure so it would be a lesser incident then.

 

I agree. By coincidence, a lot of what we do (when we're not looking after schools) is picking apart hacked Wordpress sites and then offering managed hosting for them, and this looks like an out-of-date plugin or an old vulnerable Wordpress version. It was probably done by a bot, but they need to work out exactly how compromised their data is, because of course, the data is all integrated into the web frontend when you're signed in (which hopefully isn't WordPress based).

 

If they kept their Wordpress privileges/database separate from the school data it may be fairly limited in extent, but who wants to bet on that being the case?

 

Until we know that extent, it remains a GDPR concern, and the problem is, half the schools in the country upload their SIMS data to them.

Edited by Cazale
Posted (edited)
I suspect the front page may be using Wordpress with the backend a different system once you buy it. There was a big Wordpress plug-in exploit a couple of weeks ago and it affected a HUGE amount of sites potentially if not ninja pitched.

If the systems are separate than hopefully customer data is safe and secure so it would be a lesser incident then.

You're correct, it's WordPress.

Their backend is custom built. They're both on different IP addresses too so hopefully there's no link between any databases. :-)

Edited by Edu-IT
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...