Author Topic: Yandex blacklisted site - listed as suspicious by others!  (Read 855 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Yandex blacklisted site - listed as suspicious by others!
« on: November 22, 2015, 05:08:40 PM »
unknown_html   RIPE   PL   abuse at -upc.com.pl for -http://42.herber.pl/19vxi
Detected libraries:
jquery - 1.5.1 : (active1) -http://www.jdavisstudios.biz/radio/themes/org_fbc/jquery-1.5.1.min.js
Info: Severity: medium
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4969
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
(active) - the library was also found to be active by running code
1 vulnerable library detected
Quttera flags -42.herber.pl as malicious and blacklisted -> https://yandex.com/infected?l10n=en&url=42.herber.pl&redircnt=1448206873.1

Re: http://www.domxssscanner.com/scan?url=http%3A%2F%2F42.herber.pl%2Findex.php%3Fformat%3Dsimple%26action%3Dshorturl%26url%3D

links to URL shortener: http://yourls.org/

See redirect to: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.jdavisstudios.biz%2Fradio%2Fmodules.php%3Fname%3DYour_Account%26op%3Duserinfo%26username%3DMarlaObj9

Detected libraries:
jquery - 1.8.2 : (active1) -http://www.jdavisstudios.biz/scripts/jquery-1.8.2.min.js
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
(active) - the library was also found to be active by running code
1 vulnerable library detected

http://tiny_mce/tiny_mce.js is vulnerable to XSS attacks: http://sohua.xyz/questions/2538028/xss-attacks-in-jsp
-> {if(exec(func,this.executeCallback.arguments))return true;}}var  in code with 104 sources and 70 sinks found up..

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!