Author Topic: CMS issues and website defaced....  (Read 1096 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34052
  • malware fighter
CMS issues and website defaced....
« on: November 13, 2015, 07:04:31 PM »
See: http://killmalware.com/jillgreenleaf.com/#  &  http://toolbar.netcraft.com/site_report?url=http://jillgreenleaf.com
Missed: https://www.virustotal.com/nl/url/49377df6d0a914e1b76130c53bb9cfd89a3337bb69e7f5626b30680c53b410fb/analysis/#additional-infoindex.html
Severity:   Malicious
Reason:   Detected malicious PHP content
Details:   Website Potentially DefacedWordPress Version
3.9.9Warning Directory Indexing Enabled
In the test we attempted to list the directory contents of the uploads and plugins folders to determine if Directory Indexing is enabled. This is an information leakage vulnerability that can reveal sensitive information regarding your site configuration or content.

/wp-content/uploads/ enabled
Version does not appear to be latest 4.3.1 - update now.

Alsoconsider: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fjillgreenleaf.com%2Fwp-content%2Fthemes%2FDivi%2Fjs%2Fmasonry.js%3Fver%3D2.0  with key vulnerability layers detected here....

polonus



Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!