ampproject / ampproject/amphtml

Persistent Access to AMP Pages After Main Subdomain Suspension Due to Hacking Incident

Open
#39,870 4 comments 0 reactions 1 assignee Claimed by @erwinmombay View on GitHub
needs sizing P1: High Priority Stale Type: Bug
Dominant language
JavaScript
Stars
14.9k
Forks
4.1k
PR merge metrics
No merged PRs in 30d

Description

### Description

The subdomain `**https://rektorika.syekhnurjati.ac.id/**` of the educational site IAIN Syekh Nurjati Cirebon in Indonesia has been compromised and used to create automated doorway pages for online gambling—a practice illegal in Indonesia. These pages were automatically generated using PHP techniques, resulting in a significant number of pages (over 36,100 results) being indexed by Google.

The hosting and registrar parties have resolved the issue by blocking access to the compromised subdomain. However, the AMP pages created by the subdomain are still active and redirect to a separate domain (`**cdn-dsfd3653uad4wi34osegjkhef-gfgfere-fseweergftaavas.xyz**`), which continues to serve online gambling content, accessible on mobile devices though inaccessible from desktop browsers.

Request for assistance: We seek help in **detaching** or **disconnecting the AMP** service from both the compromised subdomain and the domain it redirects to. Efforts to remove outdated content through Google's own features have been undermined by the hackers' persistent access to Google Search Console, allowing them to **cancel the page removal**. The gambling content remains accessible to users in Indonesia, causing ongoing concern.

![image](https://github.com/ampproject/amphtml/assets/154322142/a4fd5eba-e2ac-4664-a275-d91440c349c1)
![image](https://github.com/ampproject/amphtml/assets/154322142/bc470862-12af-4a1c-bb98-cc8618bcb3a9)

### Reproduction Steps

1. Access Page from a mobile device using google search and type query "slot site:rektorika.syekhnurjati.ac.id" or just go to URL: https://www.google.com/search?q=slot%20site:rektorika.syekhnurjati.ac.id.
2. Notice that AMP pages redirecting to `cdn-dsfd3653uad4wi34osegjkhef-gfgfere-fseweergftaavas.xyz` are still active and can be accessed.
3. Verify that the content served via AMP is related to online gambling.

### Relevant Logs

```shell
Not applicable, as this is an issue of unauthorized access and content serving.
```

### Browser(s) Affected

Chrome

### OS(s) Affected

All mobile operating systems accessing the AMP pages

### Device(s) Affected

All mobile devices

### AMP Version Affected

Not specific to an AMP version, as the issue lies with unauthorized AMP page accessibility

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.