Author Topic: TrojWare.JS.Iframeinject.AJ detected here?  (Read 1889 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
TrojWare.JS.Iframeinject.AJ detected here?
« on: March 06, 2016, 11:34:33 PM »
Re: https://www.virustotal.com/en/url/13918511fd24d4c4090af4d6d2a4a90793307f847abb3f5e4be6a40909af9902/analysis/
"The malware entry is cached and may not reflect the current status of the domain".
Wordpress Version 4.1 based on: -http://healthyfoodbank.org/wp-includes/js/autosave.js
WordPress Version
4.3.3
Version does not appear to be latest 4.4.2 - update now.

WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

jetpack 2.5.2   latest release (3.9.2) Update required
http://jetpack.me
Plugins are a source of many security vulnerabilities within WordPress installations, always keep them updated to the latest version available and check the developers plugin page for information about security related updates and fixes.

Warning User Enumeration is possible  :o
The first two user ID's were tested to determine if user enumeration is possible.

ID   User                   Login
1   mafoundation   mafoundation
2      None
It is recommended to rename the admin user account to reduce the chance of brute force attacks occurring. As this will reduce the chance of automated password attackers gaining access. However it is important to understand that if the author archives are enabled it is usually possible to enumerate all users within a WordPress installation.

-http://healthyfoodbank.org
Detected libraries:
jquery-migrate - 1.2.1 : -http://healthyfoodbank.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery.prettyPhoto - 3.1.3 : (active1) -http://healthyfoodbank.org/wp-content/themes/elegance/lib/scripts/prettyphoto/js/jquery.prettyPhoto.js?ver=2.3
Info: Severity: high
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6837&cid=3
Info: Severity: high
https://github.com/scaron/prettyphoto/issues/149
https://blog.anantshri.info/forgotten_disclosure_dom_xss_prettyphoto
jquery - 1.11.3 : (active1) -http://healthyfoodbank.org/wp-includes/js/jquery/jquery.js?ver=1.11.3
(active) - the library was also found to be active by running code
2 vulnerable libraries detected

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: TrojWare.JS.Iframeinject.AJ detected here?
« Reply #2 on: March 06, 2016, 11:53:56 PM »
Thanks, Pondus, that means we are being protected. A shame the website has not been cleansed or been made more secure yet.
Loads of websites and website admins/owners should prosper with a mssp that would take care of securely managing their website when they apparently are not capable to do it themselves nor those they hired to do so.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!