Cazale Posted September 14, 2020 Posted September 14, 2020 (edited) If I search for parentmail, click on the Google link, it sits like this for ages: Note the URL loading at the bottom. After a few minutes it times out and loads this: We only get this the first time we load the page, every subsequent page refresh it goes straight to the proper site. I've so far tested this on: our simsserver, a Windows 10 desktop even a brand new imaged Windows 10 PC, with me as the first logged in user. Can anyone replicate this?? (you might need to try a PC without and adblocker on). If it's them, they obviously need telling, but I also want to make sure it's not us! (AV isn't picking anything up, and there are no plugins loaded). Edited September 14, 2020 by elsiegee40
ZeroHour Posted September 14, 2020 Posted September 14, 2020 Does this happen if you go in fresh as it were and browse directly to the url rather than using google? Basically some malware on sites can only trigger when coming from certain sites like google to make it harder for the site owner to pick up.
Cazale Posted September 14, 2020 Author Posted September 14, 2020 Does this happen if you go in fresh as it were and browse directly to the url rather than using google? Basically some malware on sites can only trigger when coming from certain sites like google to make it harder for the site owner to pick up. It definitely happens going through Google. I've just remoted into another school and it's also happening from that school. I'd ring them, but there's no point, you just go around in circles in their automated menus and then get a message to email!
Cazale Posted September 14, 2020 Author Posted September 14, 2020 Clearing cookies and reloading the site causes the site to redirect on the next refresh, and for adverts to start popping up again. I'm pretty much 100% that they've had their site hacked!
ZeroHour Posted September 14, 2020 Posted September 14, 2020 (edited) I just tried my end and I can see several URL calls in the dev tools that are very suspicious. Most of them end with /i.php?ver=5.5.1 and I currently see 5 domains which I wouldnt expect to be part of parentmail. I am not posting the full urls directly as it may lead to links to them. Edited September 14, 2020 by ZeroHour 1
Cazale Posted September 14, 2020 Author Posted September 14, 2020 Just tried and same thing happened. Slow page load and then add redirect when clicking on a menu item. I just tried my end and I can see several URL calls in the dev tools that are very suspicious. Most of them end with /i.php?ver=5.5.1 and I currently see 5 domains which I wouldnt expect to be part of parentmail. I am not posting the full urls directly as it may lead to links to them. Cheers both. I eventually got through to their sales line and I've let them know. 2
ZeroHour Posted September 14, 2020 Posted September 14, 2020 Digging into those bad urls and I can see the JS which tries to load a .tk domain and the domain seems very very ad spammy.
paulkerton Posted September 14, 2020 Posted September 14, 2020 Just tested it and yup, I'm seeing it too. Someone has a problem! Big problem!
Cazale Posted September 14, 2020 Author Posted September 14, 2020 (edited) Just tested it and yup, I'm seeing it too. Someone has a problem! Big problem! I was at a school when I noticed it, and they obviously want to know if there's a GDPR breach they need to be aware of and should report. If there is, someone definitely has a big problem because it's going to be half the schools in the country! Edited September 14, 2020 by Cazale
paulkerton Posted September 14, 2020 Posted September 14, 2020 I've sent them this thread on a Twitter DM. Let's see. 3
psydii Posted September 14, 2020 Posted September 14, 2020 It passes as clean on VirusTotal. But I'm not about to visit it on my laptop. Has anyone got confirmation from ParentMail yet?
paulkerton Posted September 14, 2020 Posted September 14, 2020 (edited) Here is what's happening when I visit it in Firefox in private browsing mode, via a Google Search. You have to click to trigger it. Not... good.... Edited September 14, 2020 by paulkerton 3
Protec Posted September 14, 2020 Posted September 14, 2020 Does the same for me. Seems to know my rough location too as it says "Brad Jenkins from ...".
paulkerton Posted September 14, 2020 Posted September 14, 2020 Does the same for me. Seems to know my rough location too as it says "Brad Jenkins from ...". Probably pulling that from your IP address geolocation.
Cazale Posted September 14, 2020 Author Posted September 14, 2020 Seems to be working now? Nope, still not fixed. Did you remember to reset your cookies or use private browsing mode?
ZeroHour Posted September 14, 2020 Posted September 14, 2020 I suspect the front page may be using Wordpress with the backend a different system once you buy it. There was a big Wordpress plug-in exploit a couple of weeks ago and it affected a HUGE amount of sites potentially if not ninja pitched. If the systems are separate than hopefully customer data is safe and secure so it would be a lesser incident then. 1
Cazale Posted September 14, 2020 Author Posted September 14, 2020 (edited) I suspect the front page may be using Wordpress with the backend a different system once you buy it. There was a big Wordpress plug-in exploit a couple of weeks ago and it affected a HUGE amount of sites potentially if not ninja pitched. If the systems are separate than hopefully customer data is safe and secure so it would be a lesser incident then. I agree. By coincidence, a lot of what we do (when we're not looking after schools) is picking apart hacked Wordpress sites and then offering managed hosting for them, and this looks like an out-of-date plugin or an old vulnerable Wordpress version. It was probably done by a bot, but they need to work out exactly how compromised their data is, because of course, the data is all integrated into the web frontend when you're signed in (which hopefully isn't WordPress based). If they kept their Wordpress privileges/database separate from the school data it may be fairly limited in extent, but who wants to bet on that being the case? Until we know that extent, it remains a GDPR concern, and the problem is, half the schools in the country upload their SIMS data to them. Edited September 14, 2020 by Cazale
Edu-IT Posted September 14, 2020 Posted September 14, 2020 (edited) I suspect the front page may be using Wordpress with the backend a different system once you buy it. There was a big Wordpress plug-in exploit a couple of weeks ago and it affected a HUGE amount of sites potentially if not ninja pitched. If the systems are separate than hopefully customer data is safe and secure so it would be a lesser incident then. You're correct, it's WordPress. Their backend is custom built. They're both on different IP addresses too so hopefully there's no link between any databases. :-) Edited September 14, 2020 by Edu-IT 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now