Author Topic: JS Clickjack infection warning shown ONLY by Avast  (Read 3537 times)

0 Members and 1 Guest are viewing this topic.

rickvidallon

  • Guest
JS Clickjack infection warning shown ONLY by Avast
« on: November 07, 2013, 04:37:02 AM »
I have Avast Pro on every machine in my house.  Using Google Chrome over WIN 7 I am getting a harmful webpage warning. HOWEVER every other web developer I have asked to test the website outside my state says the page loads fine with no warning using Norton or Panda protection.

I also tried viewing over Proxy (hidemyass) and Avast still throughs the warning.

I checked the hosting root space, home page file, HTaccess and configuration files and there are no signs of infection.

I have attached a snap shot of the warning here and would appreciate any helpful feedback.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
« Last Edit: November 07, 2013, 08:44:44 AM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: JS Clickjack infection warning shown ONLY by Avast
« Reply #2 on: November 07, 2013, 09:03:56 AM »
Hi rickvidalton,

Web development may be "overly" fine at the site (see remarks about Blackhat SEO spam),
but the server the site is hosted on might have sloppy management and insecure configuration.

1. It does not look an X-frame-Options header was returned from that server, so you were and are indeed vulnerable to clickjacking.
2. Cookie not flagged as HttpOnly, site vulnerable to XSS attack.
3. Furthermore too excessive header info flagged.
A lot of hosting firms are in the game just for the money involved and security is not exactly their first priority so to say.
Especially where hundreds of sites are being hosted on one and the same IP (risks of being generally blacklisted by malware on other domains).

Your site has links to a site involved in black hat SEO Spam like the Hide-Me campaign, avast is one of the av-solutions to detects this spam fraud!

Site is infected: infected

guage="javascript"> function dnnviewstate() { var a=0,m,v,t,z,x=new array('9091968376','88879181928187863473749187849...

Problem with website software -> Web application version: CMS: joomla! 1.5 - open source content management
Joomla Version 1.5.18 - 1.5.26 for: htxp://www.villageshopskingsmill.com//media/system/js/caption.js
Joomla Version 1.5.18 to 1.5.26 for: htxp://www.villageshopskingsmill.com//language/en-GB/en-GB.ini

Link checks to be made:
Please check this list for unknown links on your website:

hxtp://www.plimun.com/  -->  'web design' -> black hat SEO read: http://productforums.google.com/forum/#!topic/webmasters/yy3eFINipW8
making a joke of penguin and Google -> hxtp://forum.joomla.org/viewtopic.php?t=795946 (flagged as with JS:HideMe-j[Trj] - Hide-Me SEO Spam
link credits go to poster mike1971hk on Google Product Forums.
htxp://www.visionefx.net/  -->  'visionefx design'  OK

polonus
« Last Edit: November 07, 2013, 09:06:38 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: JS Clickjack infection warning shown ONLY by Avast
« Reply #3 on: November 07, 2013, 10:27:22 AM »
Norman lab confirms infection and have added detection as HideLink.B


Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5604
  • Spartan Warrior
Re: JS Clickjack infection warning shown ONLY by Avast
« Reply #4 on: November 07, 2013, 10:33:20 AM »
Possible to link to Norman here?
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: JS Clickjack infection warning shown ONLY by Avast
« Reply #5 on: November 07, 2013, 11:49:50 AM »
Possible to link to Norman here?
you mean The Analysis result?

that is not possible since i have access directly to Normans online analysis tool ( Norman Shark Malware Analyzer G2)  http://normanshark.com   where you need a browser certificate and logg in password

but i can copy and paste
Quote
-----
This case has now been closed.
If the problem is not resolved please add further comments to the case.

Files:
sample.txt: HideLink.B

-----
« Last Edit: November 07, 2013, 01:51:48 PM by Pondus »

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5604
  • Spartan Warrior
Re: JS Clickjack infection warning shown ONLY by Avast
« Reply #6 on: November 07, 2013, 12:59:12 PM »
OK.

Thanks for the link to Norman.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801