Author Topic: Webzilla insecurity from Singapore?  (Read 1077 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34058
  • malware fighter
Webzilla insecurity from Singapore?
« on: May 08, 2017, 06:55:09 PM »
Found to be hacked:
Quote
File name: /author/admin/index.html

[[<a href='htxp://www.webzilla.sg/servicessolutions/mrx-htm/'>Hacked By Zedan-Mrx</a>]]

See: http://urlquery.net/report.php?id=1494259233063  Outdated Word Press detected!
Warning Directory Indexing Enabled
In the test we attempted to list the directory contents of the uploads and plugins folders to determine if Directory Indexing is enabled. This is an information leakage vulnerability that can reveal sensitive information regarding your site configuration or content.

/wp-content/uploads/ enabled
/wp-content/plugins/ enabled
Directory indexing was tested on the /wp-content/uploads/ and /wp-content/plugins/ directores. Note that other directories may have this web server feature enabled, so ensure you check other folders in your installation. It is good practice to ensure directory indexing is disabled for your full WordPress installation either through the web server configuration or .htaccess.

F-status: https://observatory.mozilla.org/analyze.html?host=www.webzilla.sg

Retirable jQuery library: http://retire.insecurity.today/#!/scan/5619faca092b62d875e200697400ff5bdca729eaaf72df2b2437b9f652b72f30

OK here: https://sritest.io/#report/a5b9e469-983c-4b35-a286-593eed708a0e

See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.webzilla.sg

polonus
« Last Edit: May 08, 2017, 07:12:51 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!