Okay, I went to Google's webmaster tools (good god, they get into fucking everything--it's exhausting), and they think alt.buffistas.net is infected and buffistas.org isn't which would be a cute achievement, since they are exactly the same unless someone's hijacked the DNS.
Which I'm assuming Suela would notice if we'd all been replaced by Russian mobster AIs.
So I've submitted that URL for a review. We'll see what happens.
If it's the same problem I had with my iStrata hosted server it's based on a Plesk exploit. The attacker users Plesk to insert some evil JavaScript into index.html files. It could be that the more complex setup of b.org defeats the script.
I ended up changing all the control panel account passwords and applying two patches and I think that's taken care of it. I didn't see any new accounts or cron jobs and the security scan came up clean.
I think [link] pretty much covers what you'd need to do.
Russian mobster AIs would not, I think, be capable of earworming Dana with five musicals simultaneously.
We already dealt with the Plesk exploit. I can't think why one of the URLs would be showing anything to do with it and not the other.
Unless there are two Plesk exploit malware issues?
There are two. I had patched the first one right after you patched b.org but never heard about the second.
In plesk, check Server -> Action Log and see if any of the CP logins look fishy.
Does b.org have an index.html? I'd assumed not, since it's dynamically generated. The only thing the hacker did on my server was mess with various domain's index.html files.
There is one (it's a server down page--I yank index.php in that case), but it's kashrut like pesach.
And I got no explanation for that urge to express. I'm gonna get some chocolate.
I'm gonna get some chocolate.
Finally, a sentence I understand!
Search by date appears to be broken from my text-only browser. There should be two examples in the access log from my IP address about five minutes ago, user-agent 'w3m', and leading to fatal errors. I tried to search Beep Me and Natter.
Hello. I'm really not a technical person, but I think there's something wrong with the display here (I refreshed the page several times. Didn't help): [link]