Author Topic: Problem blocking my site because of HTML: Iframe-inf  (Read 2096 times)

0 Members and 1 Guest are viewing this topic.

Offline elkooora

  • Newbie
  • *
  • Posts: 2
Problem blocking my site because of HTML: Iframe-inf
« on: June 04, 2020, 06:22:48 PM »
Problem blocking my site because of HTML: Iframe-inf
https://elkooora.com/
https://yallashoot-live.today/
http://dawsha-tv.com/

The problem only appears inside the articles
Please help me to solve this problem
« Last Edit: March 07, 2021, 03:38:24 AM by elkooora »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Problem blocking my site because of HTML: Iframe-inf
« Reply #1 on: June 04, 2020, 07:19:20 PM »
« Last Edit: June 04, 2020, 07:21:50 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Problem blocking my site because of HTML: Iframe-inf
« Reply #2 on: June 04, 2020, 11:01:31 PM »
I get a  301 Moved Permanently now -> https://aw-snap.info/file-viewer/?protocol=secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=e2xrXV1dfXwuXl1tYA%3D%3D~enc
Then URLs that redirect found in: -https://ar.elkooora.com/

1: -http://view.vzaar.com/ -> -https://www.dacast.com/?from=vzaar
DOM-XSS scan results: Results from scanning URL: -http://view.vzaar.com/
Number of sources found: 40
Number of sinks found: 442
&
Results from scanning URL: -https://www.dacast.com/wp-content/plugins/add-to-any/addtoany.min.js?ver=1.1
Number of sources found: 41
Number of sinks found: 17

Another domain on that same IP address is unavailable because of legal restrictions:
-https://studenti.win/tema/arte/ Access from your country is restricted, please try again later.

Shared query link: https://websniffer.cc/?url=https://ar.elkooora.com/
I do not see that particular site uri blocked by avast's.

Consider: https://sitereport.netcraft.com/?url=https://ar.elkooora.com

SRC scan: HTML
-ar.elkooora.com/
45,195 bytes, 743 nodes

Javascript 7   (external 3, inline 4)
INLINE: (function() { let alreadyInsertedMetaTag = false function __insertDappDete
1,238 bytes

INLINE: (function(s,u,z,p){s.src=u,s.setAttribute('data-zone',z),p.appendChild(s);})(doc
193 bytes

-iclickcdn.com/​tag.min.js
INLINE: /*! jQuery v2.1.1 | (c) 2005, 2014 jQuery Foundation, Inc. | jquery.org/license
226,453 bytes

-ar.elkooora.com/​g4z4lagmnbj
INLINE: (function(d,z,x,s,e,o){s.src='//'+d+'/tag.min.js';x.open('GET','//'+d+'/apu.php?
427 bytes

-graizoah.com/​tag.min.js
CSS 6   (external 4, inline 2)
-ptoushoa.com/​styles.css?aHR0cHM6Ly92aWF0ZXBpZ2FuLmNvbS9hcHUucGhwP3pvbmVpZD0zMzM2Njc5
INJECTED

-ptoushoa.com/​bootstrap.css?aHR0cHM6Ly92aWF0ZXBpZ2FuLmNvbS9hcHUucGhwP3pvbmVpZD0zMzM2Njc5
INJECTED

INLINE: @media print {#ghostery-purple-box {display:none !important}}
61 bytes INJECTED

-ar.elkooora.com/wp-content/themes/Final/​style.css
INJECTED

-kit-pro.fontawesome.com/releases/v5.12.0/css/​pro.min.css
INJECTED

INLINE: :root #AdsDiv {display:none !important;}
40 bytes INJECTED -> compare: -https://pastebin.com/59SsDvva

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!