Author Topic: Cleansed site still vulnerable....  (Read 944 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Cleansed site still vulnerable....
« on: October 04, 2016, 01:08:59 AM »
Result
The address you entered is unnecessarily exposing the following response headers which divulge its choice of web platform:

Server: Apache/2.2.15 (CentOS)
Configuring the application to not return unnecessary headers keeps this information silent and makes it significantly more difficult to identify the underlying frameworks.

-http://korstroiavto.ru/
Detected libraries:
jquery - 1.11.1 : (active1) -http://code.jquery.com/jquery-latest.min.js
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
(active) - the library was also found to be active by running code
1 vulnerable library detected

See the vulnerable yandex.com script: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fkorstroiavto.ru%2F

Results from scanning URL: //api-maps.yandex.ru/services/constructor/1.0/js/?sid=RVchbMEFC2O3eXv7PBZxiaFfMBYhZ1Pa&id=map
Number of sources found: 43
Number of sinks found: 19

Re: F-Status: https://observatory.mozilla.org/analyze.html?host=korstroiavto.ru

Insecure IDs-tracking: This website is insecure.
50% of the trackers on this site could be protecting you from NSA snooping. Tell -korstroiavto.ru to fix it.

Identifiers | All Trackers
 Insecure Identifiers
Unique IDs about your web browsing habits have been insecurely sent to third parties.

9940318601464818997 -Yandex yandexuid

 Tracking IDs could be sent safely if this site was secure.
 Tracking IDs do not support secure transmission.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!