Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: jockspin.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 04 Jun 2014 23:51:05 GMT
Pragma: no-cache
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.4.25
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://jockspin.com/>; rel=shortlink
Set-Cookie: PHPSESSID=c81f70f6ad60b612d7d2d13ea797d735; path=/
X-Pingback: http://jockspin.com/xmlrpc.php
X-Powered-By: PHP/5.4.25
GET / HTTP/1.1
Host: jockspin.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Wed, 04 Jun 2014 23:51:05 GMT
Pragma: no-cache
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.4.25
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://jockspin.com/>; rel=shortlink
Set-Cookie: PHPSESSID=c81f70f6ad60b612d7d2d13ea797d735; path=/
X-Pingback: http://jockspin.com/xmlrpc.php
X-Powered-By: PHP/5.4.25
Second query (visit from search engine):
GET / HTTP/1.1
Host: jockspin.com
Referer: http://www.google.com/search?q=jockspin.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: jockspin.com
Referer: http://www.google.com/search?q=jockspin.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.jockspin.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Wed, 04 Jun 2014 23:51:04 GMT Pragma: no-cache Location: http://jockspin.com/ Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.4.25 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=bd9105b732bae336ffbe9ea1f7c9d1b9; path=/ X-Pingback: http://jockspin.com/xmlrpc.php X-Powered-By: PHP/5.4.25 | clean |
http://jockspin.com/ | 200 OK Content-Length: 91114 Content-Type: text/html | clean |
http://jockspin.com/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: application/javascript | clean |
http://jockspin.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.google.com/recaptcha/api/js/recaptcha_ajax.js?ver=3.9.1 | 200 OK Content-Length: 116695 Content-Type: text/javascript | clean |
http://jockspin.com/wp-content/plugins/theme-my-login/modules/recaptcha/js/recaptcha.js?ver=3.9.1 | 200 OK Content-Length: 653 Content-Type: application/javascript | clean |
http://jockspin.com/wp-content/themes/suffusion/scripts/suffusion.js?ver=3.9.2 | 200 OK Content-Length: 19860 Content-Type: application/javascript | clean |
http://www.jockspin.com/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Wed, 04 Jun 2014 23:51:10 GMT Pragma: no-cache Location: http://jockspin.com/test404page.js Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.4.25 Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=0ade5918b02f4764cf51877f6cf9bf65; path=/ X-Pingback: http://jockspin.com/xmlrpc.php X-Powered-By: PHP/5.4.25 | clean |
http://jockspin.com/test404page.js | 404 Not Found Content-Length: 104585 Content-Type: text/html | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19916 Content-Type: text/javascript | clean |
http://jockspin.com/wp-content/plugins/wp-carousel/js/jcarousel.min.js?ver=3.9.1 | 200 OK Content-Length: 15417 Content-Type: application/javascript | clean |
http://jockspin.com/wp-content/plugins/wp-carousel/js/jquery.nivo.slider.js?ver=3.9.1 | 200 OK Content-Length: 24490 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=jockspin.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://jockspin.com/
Result: jockspin.com is not infected or malware details are not published yet.
Result: jockspin.com is not infected or malware details are not published yet.