This was probably not part of the attack. The attack simply redirects incoming requests to another site. If your site was affected, you wouldn't have had any sign ups because your site would have been redirecting to the bogus site before it even reaches your page.
Comments
This was probably not part of the attack. The attack simply redirects incoming requests to another site. If your site was affected, you wouldn't have had any sign ups because your site would have been redirecting to the bogus site before it even reaches your page.
I was thinking more of something like someone was attempting to exploit a vulnerability in the signup form.
I just saw this exact conversation a month ago.
Serious Deja Vu.