Thread Tools Display Modes
11-10-13, 04:30 PM   #1
Kreelor
A Firelord
 
Kreelor's Avatar
Join Date: Feb 2008
Posts: 495
JavaScript Exploit attempt on forum

I just now encountered this JavaScript Exploit attempt while I was trying to upload an image (using the "Manage Attachments" option on the Carbonite user's forum.

Just thought I'd let you know.
Attached Thumbnails
Click image for larger version

Name:	Forum-JavaScript-Exploit-Detection.jpg
Views:	118
Size:	72.9 KB
ID:	7938  
  Reply With Quote
11-10-13, 09:15 PM   #2
Vlad
A Molten Giant
 
Vlad's Avatar
AddOn Author - Click to view addons
Join Date: Dec 2005
Posts: 793
The minified jquery script might trigger obfuscation warnings, but in reality it's just code that is purposefully made as compact as possible to save bandwidth.

I'd consider this a false-positive response from AVG and I wouldn't worry about it.

The only thing the admins can do is check and make sure their jquery file is not compromised - something I highly doubt.
__________________
Profile: Curse | Wowhead
  Reply With Quote
11-10-13, 09:23 PM   #3
Dolby
PPAP
 
Dolby's Avatar
WoWInterface Admin
Join Date: Feb 2004
Posts: 2,341
Thanks, just landed back home from BlizzCon. I will double check everything tonight. Most likely a false positive.

Last edited by Dolby : 11-10-13 at 09:34 PM.
  Reply With Quote
11-10-13, 10:19 PM   #4
Dolby
PPAP
 
Dolby's Avatar
WoWInterface Admin
Join Date: Feb 2004
Posts: 2,341
Yup, everything looks good code wise and even virus total is happy...

https://www.virustotal.com/en/url/19...is/1384143335/

Google says we are clean too...

http://www.google.com/safebrowsing/d...winterface.com

If you get the alert again make sure your virus defs are being updated because if its getting a false positive on that it should be going off on a lot of other sites since its standard jQuery
  Reply With Quote
11-11-13, 05:55 PM   #5
Phanx
Cat.
 
Phanx's Avatar
AddOn Author - Click to view addons
Join Date: Mar 2006
Posts: 5,617
I had to laugh at this one. If "obfuscated JavaScript" qualifies as an "exploit" then the majority of the websites on the Internet should be triggering warnings, since "obfuscation" is a pretty standard part of code minification, which is a pretty standard part of optimizing your website to load as quickly as possible.
__________________
Retired author of too many addons.
Message me if you're interested in taking over one of my addons.
Don’t message me about addon bugs or programming questions.
  Reply With Quote

WoWInterface » Site Forums » Site help, bugs, suggestions/questions » JavaScript Exploit attempt on forum


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off