Avast community forum
Home
Help
Search
Login
Register
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Website given as safe, but full of insecurity and so vulnerable...
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: Website given as safe, but full of insecurity and so vulnerable... (Read 1051 times)
0 Members and 1 Guest are viewing this topic.
polonus
Avast Überevangelist
Probably Bot
Posts: 33900
malware fighter
Website given as safe, but full of insecurity and so vulnerable...
«
on:
January 19, 2017, 12:24:35 AM »
Where it was given as basically safe:
https://issafe.co/bokshaber.net
Looking more scrupulously and when we perform a WordPress security scan,
we will find: js_composer plug-in (is it still being supported?).
We have Warning User Enumeration is possible
The first two user ID's were tested to determine if user enumeration is possible.
ID User Login
1 None bokshaber
2 None burak
Retirable jQuery:
http://retire.insecurity.today/#!/scan/0d935df22701e03bc3709be2154b4ab35dd4372a9521c978228c537e47165bbb
Three warnings via an asafaweb scan:
https://asafaweb.com/Scan?Url=bokshaber.net
F-F-X-status:
https://observatory.mozilla.org/analyze.html?host=bokshaber.net
Insecure IDs tracking: This website is insecure.
87% of the trackers on this site could be protecting you from NSA snooping. Tell -bokshaber.net to fix it.
Identifiers | All Trackers
Insecure Identifiers
Unique IDs about your web browsing habits have been insecurely sent to third parties.
-Google id
-www.google.com nid
-www.bokshaber.net phpsessid
4fg51oXXXXX19vm2gqtle167v6 -bokshaber.net phpsessid
polonus (volunteer website security analyst and website error-hunter)
Logged
Cybersecurity is more of an attitude than anything else. Avast Evangelists.
Use NoScript, a limited user account and a virtual machine and be safe(r)!
Print
Pages: [
1
]
Go Up
« previous
next »
Avast WEBforum
»
Other
»
Viruses and worms
(Moderators:
Maxx_original
,
misak
) »
Website given as safe, but full of insecurity and so vulnerable...