Author Topic: Is this service secure or just devious data slurping?  (Read 1098 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Is this service secure or just devious data slurping?
« on: May 17, 2020, 02:38:18 PM »
What is the site and service (do not go there):
htxps://scatteredsecrets.com/
Insecure bootstrap.js - Bootstrap, script - 3.3.7
4.3
GHSA-3MGP-FX93-9XV5
Low severity vulnerability that affects bootstrap
4.3
GHSA-PJ7M-G53M-7638
Moderate severity vulnerability that affects bootstrap
4.3
GHSA-FXWM-579Q-49QQ
Moderate severity vulnerability that affects Bootstrap.Less, bootstrap, and bootstrap.sass
4.3
GHSA-4P24-VMCR-4GQJ
Low severity vulnerability that affects bootstrap
4.3
GHSA-PH58-4VRJ-W6HR
Low severity vulnerability that affects bootstrap
4.3
GHSA-WH77-3X4M-4Q9G
Moderate severity vulnerability that affects bootstrap and bootstrap-sass
4.3

About hosting: https://www.shodan.io/host/104.27.170.137
Tracking and privacy related implications: https://webcookies.org/cookies/scatteredsecrets.com/30473261?456253
Twitter connection - inline code
Quote
/* a.onclick = */
if (!window.__cfRLUnblockHandlers) return false;
window.open('htxps://twitter.com/intent/tweet?text=Find%20Your%20Hacked%20Passwords%20at%20ScatteredSecrets.com!', 'twitter', 'resizable,height=260,width=370');
return false;
facebook link:
Quote
/* a.onclick = */
if (!window.__cfRLUnblockHandlers) return false;
window.open('htxps://www.facebook.com/sharer/sharer.php?u=scatteredsecrets.com', 'facebook', 'resizable,height=260,width=370');
return false;

Content Security Policy bypasses: -errorcdnjs.cloudflare.com
cdnjs.cloudflare.com is known to host Angular libraries which allow to bypass this CSP.
-erroross.maxcdn.com
-oss.maxcdn.com is known to host Angular libraries which allow to bypass this CSP.

I for one would not go there nor register,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Is this service secure or just devious data slurping?
« Reply #1 on: May 17, 2020, 02:54:34 PM »
scatteredsecrets.com/about

What is Scattered Secrets?
Scattered Secrets is a password breach notification and prevention service. By using Scattered Secrets, you can drastically reduce the risk that hackers will be able to hijack or takeover your accounts.