Author Topic: Vulnerabilities on website software and unknown malware?  (Read 1309 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33910
  • malware fighter
Vulnerabilities on website software and unknown malware?
« on: December 06, 2015, 10:18:48 PM »
See: Warning Directory Indexing Enabled
In the test we attempted to list the directory contents of the uploads and plugins folders to determine if Directory Indexing is enabled. This is an information leakage vulnerability that can reveal sensitive information regarding your site configuration or content.

/wp-content/uploads/ enabled -> https://www.virustotal.com/nl/url/b04eaf17b708a55c8276ee459db83426c2f7163772e8cbb9147a49a8213a378c/analysis/1449436236/
Blacklisted links 49...No detections here: https://sitecheck.sucuri.net/results/www.walkileaks.com
Various instances of malware detected: http://urlquery.net/report.php?id=1449436524380
Detected libraries:
jquery-migrate - 1.2.1 : -http://www.walkileaks.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery - 1.11.3 : (active1) [http://www.walkileaks.com/wp-includes/js/jquery/jquery.js?ver=1.11.3
(active) - the library was also found to be active by running code
1 vulnerable library detected

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!