Author Topic: Cleansed from a hack, stiil vulnerable with outdated CMS plug-ins etc.  (Read 1103 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33912
  • malware fighter
Yes my friend, this site just has survived and was cleansed from a hack: http://killmalware.com/dryckeskunskap.se/#
An Asafa webscan proofs the website is not secure with two warnings: https://asafaweb.com/Scan?Url=dryckeskunskap.se
A WP security scan produces vulnerable outdated WordPress plug-ins (where it says Update required)
: The following plugins were detected by reading the HTML source of the WordPress sites front page.

easy-sign-up   latest release (3.3.6)
http://www.beforesite.com/documentation/
gallery-plugin 3.02   latest release (4.3.7) Update required
http://bestwebsoft.com/products/
language-bar-flags 1.0.4   latest release (1.0.7) Update required
http://blog.meloniq.net/2011/11/28/language-bar-flags/
wysija-newsletters 1.1.5   latest release (2.6.18) Update required
http://www.mailpoet.com/

Warning User Enumeration is possible
The first two user ID's were tested to determine if user enumeration is possible.

ID   User   Login
1      None
2   None   redigera
Compromised sites will often contain embedded iframes that can also deliver malicious code to visitors of the web site. Check any discovered iframes and ensure they are legitimate.

-http://www.facebook.com/plugins/fan.php?id=142432452509546 &width=300&connections=0&stream=false&header=false&locale=sv_SE


See: -http://www.domxssscanner.com/scan?url=http%3A%2F%2Fdryckeskunskap.se
and
-http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.facebook.com%2Fplugins%2Ffan.php%3Fid%3D142432452509546+%26width%3D300%26connections%3D0%26stream%3Dfalse%26header%3Dfalse%26locale%3Dsv_SE
(javascript run through a minifier)...

polonus


Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!