Author Topic: Hacked and defaced website with 80% insecure tracking!  (Read 1308 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33918
  • malware fighter
Hacked and defaced website with 80% insecure tracking!
« on: October 12, 2016, 02:43:05 PM »
See: http://www.UnmaskParasites.com/security-report/?page=portalsrodowiskowy.pl
Flagged: http://killmalware.com/portalsrodowiskowy.pl/#
Scripts running on defaced website: Scanner output:
Scanning -http://portalsrodowiskowy.pl ...
Script loaded: -https://s.ytimg.com/yts/jsbin/www-embed-player-vflXaV-QK/www-embed-player.js
Script loaded: -https://s.ytimg.com/yts/jsbin/player-en_US-vfl-E2vny/base.js
Script loaded: -https://static.doubleclick.net/instream/ad_status.js
Script loaded: -https://www.google.com/js/bg/JcB8v8_JdKtIhZ9y6LIjdAD-EV-EzPAX1QHCbClfXjk.js
Site report: http://toolbar.netcraft.com/site_report?url=http://portalsrodowiskowy.pl
Reversed DNS address: htxp://brynczak1983.e-kei.pl/  100% insecure IDs tracking: t least 5 third parties know you are on this webpage.

 -www.kei.pl
 -shaaaaaaaaaaaaa.com  (on my personal comp).
 -static.kei.pl
 -default.kei.pl
-brynczak1983.e-kei.pl  -brynczak1983.e-kei.pl

 Tracker could be tracking safely if this site was secure.
 Tracker does not support secure transmission.

Tracking on hacked and defaced website: Unique IDs about your web browsing habits have been insecurely sent to third parties.

-22b1e6cdcb030061||t=1446647139|et=730|cs=002213fd48ece89652be8d3085  Google id
 --www.google.com nid

Defaced website has CORS  protection but an invalid certificate chain: ->  https://observatory.mozilla.org/analyze.html?host=

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!