Author Topic: Word Press website kicking up emotet & heodo malware...  (Read 974 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Word Press website kicking up emotet & heodo malware...
« on: October 17, 2019, 04:56:28 PM »
Re: https://urlhaus.abuse.ch/url/246015/
see mixed content errors etc.: https://www.whynopadlock.com/results/0f37a8d9-e81d-44df-903e-14b52aaa22a0
Excessive server info proliferation: Web Server:
Apache/2.4.39 (cPanel) OpenSSL/1.0.2r mod_bwlimited/1.4 Phusion_Passenger/5.3.7
with a host of vulnerabilities: https://www.shodan.io/host/216.10.247.126
Site blacklisted by Spamhaus: https://sitecheck.sucuri.net/results/astrologervarun.com/wp-admin/
Phusion Passenger 5.3.7 vulnerable to race privelage escalation.
Hints found through linting: https://webhint.io/scanner/4549d020-9631-496c-aad7-da487491302f
specifically towards improved security:
https://webhint.io/scanner/4549d020-9631-496c-aad7-da487491302f#category-security

polonus (3rd party cold recon website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!