Author Topic: Website defacement  (Read 1788 times)

0 Members and 2 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Website defacement
« Reply #1 on: November 13, 2014, 07:18:09 PM »
This link blocked: -http://error.hostinger.eu/403.php  site listed as PHISH
led to: https://forum.avast.com/index.php?topic=142184.0
See vulnerabilities here: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.hostinger.co.uk
e.g.: Results from scanning URL: htxp://www.hostinger.co.uk/js/site.php
Number of sources found: 263
Number of sinks found: 17 -> this.domPosition.parent).prepend
could be attacked with "append('<iframe style="position: relative"...

pol
« Last Edit: November 16, 2014, 06:22:23 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Website defacement
« Reply #2 on: November 13, 2014, 10:46:53 PM »
Also scanned external link: https://asafaweb.com/Scan?Url=devweb.cum.ir%2FAZed.scriptso1.js
and http://jsunpack.jeek.org/?report=782aaf068ac79a1a3283721c1358faf9c3960af6
and Pop-Up code: htxp://dinbror.dk/bpopup
ajax.googleapis dot com/ajax/libs/jquery/1.6.2/jquery.min.js benign
[nothing detected] (script) ajax.googleapis dot com/ajax/libs/jquery/1.6.2/jquery.min.js
     status: (referer=wXw.hostinger.co.uk/?)saved 91556 bytes 7622c9ac2335be6dcd3ab8b47132e94089cef931
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     info: [decodingLevel=0] found JavaScript
     error: undefined function a.getElementsByTagName *
     suspicious:
* can be abused in Cross-site request forgery attack for load-balancer abuse.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!