What is the name of the domain?
What is the error number?
sem erro
What is the error message?
Redirecionamento para pagina fake
What is the issue you’re encountering
I’m facing a very serious and urgent issue regarding the redirection of all websites under our management via Cloudflare. Whenever any of our domains are accessed, visitors are automatically redirected to this URL: https://java-update.pob.la This page is clearly a phishing attempt, prompting users to “update Java.” It has absolutely no connection with any of our websites or services. The same behavior occurs even on sites hosted on completely separate servers, which strongly suggests the redirect is happening at the Cloudflare level (possibly via DNS or some injected malicious rule). I have already reviewed: • The origin servers and applications (no changes or signs of compromise). • All Page Rules, Transform Rules, and Redirects in Cloudflare. • DNS records and cache settings. • Website source code and HTTP headers. Everything appears to be normal, but the redirection persists. I would greatly appreciate the community’s help (or even someone from the Cloudflare team) to: 1. Confirm whether similar incidents are affecting other domains. 2. Suggest any further steps for investigation. 3. Check if there has been any recent breach or compromise within our Cloudflare account that might allow this kind of attack. If needed, I can share affected domains and screenshots via private message.
What steps have you taken to resolve the issue?
I have already reviewed:
• The origin servers and applications (no changes or signs of compromise).
• All Page Rules, Transform Rules, and Redirects in Cloudflare.
• DNS records and cache settings.
• Website source code and HTTP headers.
Everything appears to be normal, but the redirection persists.
I would greatly appreciate the community’s help (or even someone from the Cloudflare team) to:
1. Confirm whether similar incidents are affecting other domains.
2. Suggest any further steps for investigation.
3. Check if there has been any recent breach or compromise within our Cloudflare account that might allow this kind of attack.
If needed, I can share affected domains and screenshots via private message.
What are the steps to reproduce the issue?
Acessar o site, as vezes redireciona as vezes nĂŁo