Avast WEBforum

Other => Viruses and worms => Topic started by: polonus on September 28, 2016, 12:50:48 PM

Title: Partly cleansed defaced website still vulnerable....
Post by: polonus on September 28, 2016, 12:50:48 PM
See: http://killmalware.com/trikot-bvb.de/#
Hacker's signature still found: -https://aw-snap.info/file-viewer/?tgt=http%3A%2F%2Ftrikot-bvb.de%2F&ref_sel=GSP2&ua_sel=ff&fs=1
See: http://fetch.scritch.org/%2Bfetch/?url=http%3A%2F%2Ftrikot-bvb.de%2F&useragent=Fetch+useragent&accept_encoding=

Insecure IDs tracking: This website is insecure.
75% of the trackers on this site could be protecting you from NSA snooping. Tell trikot-bvb.de to fix it.
 All trackers
At least 4 third parties know you are on this webpage.

 -Google
 -Google
 -shaaaaaaaaaaaaa.com
-trikot-bvb.de -trikot-bvb.de

 Tracker could be tracking safely if this site was secure.
 Tracker does not support secure transmission.

Re: http://toolbar.netcraft.com/site_report?url=http://trikot-bvb.de
Vuln: http://retire.insecurity.today/#!/scan/5be489bf66d5269ceddbfc7571ed79f3ef086496d1f45942ef0290c2be7a8607
OK- A-Status: https://sritest.io/#report/8178dab8-d7f6-4343-a72c-198af8c4f2bf

jQuery non-conflict: error: undefined variable jQuery
     error: undefined function jQuery.noConflict
Quote
1.Check for the order for js inclucded

2.Check for the jQuery URL loaded properly

3.Check for any other version of jquery used in the website and disable it
Quote info credits: StackOverflow's Chris Barlow.

Errors for the retirable jQuery code:
Quote
script
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     info: [decodingLevel=0] found JavaScript
     error: line:3: SyntaxError: invalid flag after regular expression:
          error: line:3: filter(function(){return this.name&&!this.disabled&&(this.checked||/select|textarea/i.test(this.nodeName)||/text|hidden|password|search/i.test(this.type))}).map(function(E,F){var G=o(this).val();return G==null?null:o.isArray(G)?o.map(G,function(I,H){r
          error: line:3: ^
source:  jsunpack analysis. Controller suffix should be removed as it is not valid JS.

polonus (volunteer website security analyst and website error-hunter)