Author Topic: Clever parking not blocked? Mirai abuse detected...  (Read 961 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33940
  • malware fighter
Clever parking not blocked? Mirai abuse detected...
« on: July 20, 2020, 01:05:06 AM »
This not being blocked: hxtps://www.onamae.com/service/parking/?btn_id=parking_clever_parking_20151106
as -http://www.onamae.com/parking.html?_d=150.95.255.38 however is being blocked by uMatrix...
landing at -http://www.onamae.com/?banner_id=645_dfltweb"
Retire.js
jquery   1.12.4.min   Found in -https://www.onamae.com/common/js/jquery-1.12.4.min.js<br>Vulnerability info:
Medium   2432 3rd party CORS request may execute CVE-2015-9251   
Medium   CVE-2015-9251 11974 parseHTML() executes scripts in event handlers   
Low   CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution   
Medium   Regex in its jQuery.htmlPrefilter sometimes may introduce XSS

Should an adblocker block this - Because of the following filter

IP -150.95.255.38

Blocked as found in: http://sanyalnet-cloud-vps.freeddns.org/mirai-ips.txt

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!