Author Topic: End of lifetime webshop CMS upgraded but still vulnerable and a PHISH...  (Read 915 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Detected via Maltiverse through searching for Apple phishing;
High risk site: https://www.magereport.com/scan/?s=https://www.mahoganyusa.com/index.php/
End-of-life Outdated CMS version with various patches,
has vulnerabilities for CMS Magento as it being underMagento 2.3.2/2.2.9/2.1.18

Website has CMS: Magento 2.1.15-2.1.17/2.2.6-2.2.8 (so vulnerable, should be patched) ;
Powered by: PHP 7.0.33 (vulnerable PHP version)

Detected: 6 dead links:
Status   URL   Source link text
404 Not Found    hxtps://www.mahoganyusa.com/pub/static/version1569960712/frontend/Pearl/weltpixel_custom/en_US/WeltPixel_DesignElements/fonts/Simple-Line-Icons.woff2   style: @font-face
404 Not Found   hxtps://www.mahoganyusa.com/pub/static/version1569960712/frontend/Pearl/weltpixel_custom/en_US/WeltPixel_DesignElements/css/imports/shortcodes/AjaxLoader.gif   style: .brand-carousel .owl-item.loading
404 Not Found   htxps://www.mahoganyusa.com/pub/static/version1569960712/frontend/Pearl/weltpixel_custom/en_US/images/pattern.png   style: #page-title.page-title-pattern
404 Not Found   htxps://www.mahoganyusa.com/pub/static/version1569960712/frontend/Pearl/weltpixel_custom/en_US/images/parallax/parallax-bg.jpg   style: #page-title.page-title-parallax
404 Not Found   hxtps://www.mahoganyusa.com/pub/static/version1569960712/frontend/Pearl/weltpixel_custom/en_US/css/owl.video.play.png   style: .owl-carousel.products .owl-video-play-icon
404 Not Found   hxtps://www.mahoganyusa.com/pub/static/version1569960712/frontend/Pearl/weltpixel_custom/en_US/Itoris_StoreLoginControl/image/refresh.gif   style: .form-list .reload-captcha

Linting gave 947 improvement recommendations: https://webhint.io/scanner/e898784a-4fd5-4075-a082-19eec8647230

Moreover site is blacklisted: https://sitecheck.sucuri.net/results/https/www.mahoganyusa.com
Website blacklisted as a PHISH: https://www.phishtank.com/phish_detail.php?phish_id=5860525

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!