Author Topic: SE visitors redirects chain detected? Asiatic Pump Network  (Read 1490 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
SE visitors redirects chain detected? Asiatic Pump Network
« on: November 29, 2014, 01:29:34 AM »
Re: ] 亚洲泵网-中国水泵行业知名权威门户网站-B2B电子商务平台
See: https://www.virustotal.com/en/url/c62249e1fc27cdc63563118f3da6f51e40392c652514fe72a5838fafe23c6ac7/analysis/1417219718/
where it is missed as here: http://sitecheck.sucuri.net/results/lcpump.com
Quttera's detect: http://quttera.com/detailed_report/lcpump.com & killmalware:
SE visitors redirects
Chain of redirects found:
to: htxp://www.asiapump.cn
15 sites infected with redirects to this URL
to: htxp://beng.liuti.cn
This however is not adding to hosting security: http://sameip.net/ip223.4.156.154
Test vectors http://sameip.net/ip223.4.156.154 & VisualSVN Server - SSL Subject: commonName=WHZD011555Url=beng.liuti.cn
Excessive Header Warning and Clickjacking Warning: https://asafaweb.com/Scan?Url=beng.liuti.cn
Warnings: http://www.dnsinspect.com/lcpump.com/1417220596
http://www.site-scan.com/eng/show_headers.php?REQUEST=GET&URL=http://lcpump.com&MODIFIED=0

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: SE visitors redirects chain detected? Asiatic Pump Network
« Reply #1 on: November 29, 2014, 01:39:30 AM »
Some additional vulnerability spotted:

Site is also more vulnerable to Ddos attacks, because we see: Operation is not valid due to the current state of the object.
(for this see the info from the asafaweb scan results - -http://beng.liuti.cn/ (POST 1,001 params) (exeeded total params).
This error occurs when form fields are very large in numbers.
By default, the maximum value of MaxHttpCollection is 1000.
Can be remedied by
Code: [Select]
<appSettings>
    <add key="aspnet:MaxHttpCollectionKeys" value="2001" />
 </appSettings>
Info Credits go to CodeProject's Sarvesh Kumar Gupta,

polonus
« Last Edit: November 29, 2014, 01:41:17 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!