Author Topic: Site no longer blacklisted - still vulnerable CMS etc.  (Read 1217 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Site no longer blacklisted - still vulnerable CMS etc.
« on: March 04, 2016, 12:29:15 AM »
Recently flagged by Google Safebrowsing because of GoDaddy abuse.
Clean MX flags: https://www.virustotal.com/en/url/c2ea963ab0ca0ed4e3bad679a1d5ab0ac1ca66d577204e051cf310c8d6a2cc1a/analysis/1457046878/

WordPress issues: WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

tmls_testimonials   
contact-form-7 4.4   latest release (4.4)
http://contactform7.com/
Plugins are a source of many security vulnerabilities within WordPress installations, always keep them updated to the latest version available and check the developers plugin page for information about security related updates and fixes.

jQuery retirable code: -http://thehomesalon.in
Detected libraries:
jquery-migrate - 1.2.1 : -http://thehomesalon.in/wp-includes/js/jquery/jquery-migrate.min.js?ver=f4f5812aaab0279f9a18dc4f0a29cc76
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery - 1.8.1 : -https://ajax.googleapis.com/ajax/libs/jquery/1.8.1/jquery.min.js
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery - 1.11.3 : -http://thehomesalon.in/wp-includes/js/jquery/jquery.js?ver=f4f5812aaab0279f9a18dc4f0a29cc76
2 vulnerable libraries detected

SRI tag issues: https://sritest.io/#report/07150910-813c-4736-a4e7-c9541eba522e

Vulnerable for instance: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fa.optnmnstr.com%2Fapp%2Fjs%2Fapi.min.js%3Fver%3Df4f5812aaab0279f9a18dc4f0a29cc76

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!