Nimbusec Website Security Monitor Issue Types (Short)
Malware
| Malware |
Malicious code fragments are found on a Web page. Typical examples would be, amongst others, credit card skimmers, crypto miners or tech scams. |
| SEO-Spam |
If changes on a website are detected while acting as 'googlebot' instead of the default browser agent a warning for suspicious behavior is created |
Web Shell
ContentApplication
DefacementCMS Version |
TheAn visualapplication appearancerunning ofon aan websiteoutdated wasverrsion changedhas tobeen distributefound social, political or just for fun messages toon the visitorwebsite |
ContentCMS ViolationVulnerable |
ChangesAn ofapplication the content ofwith a Webpossible pagevulnerability arehas detected.been Thesefound change may be intended byon the website |
owner
ormayCMS beTampered
theCore resultfile of
aWordPress maliciouschange attack.and are only generated by Nimbusec's server agent. However, Nimbusec
doescannot not distinguish between legitimate and malicious changes.
Reputation
Blacklist
The domain which is subject to review is found on blacklists monitored by Nimbusec
Suspicious Link
Suspicious resources, based on blacklists monitored by Nimbusec, are embedded (but not loaded) on a Web page. A typical example of this type of event would be a link (a-tag) which points to a suspicious domain found in the Nimbusec blacklist.
Suspicious Request
A suspicious resource, based on blacklists monitored by Nimbusec, is actively loaded by a Web page. A typical example of this type of event would be a JavaScript source which points to a suspicions domain.
TLS
| TLS Protocol |
Unsafe TLS protocol allowed in configuration |
| TLS Ciphersuite |
Unsafe TLS cipher allowed in configuration |
| TLS Sigalg |
Outdated hash algorithm was used in the creation of the certificate |
| TLS Notrust |
Untrasted root certificate |
| TLS Hostname |
Hostname or alternative name does not match the certificate |
| TLS Expires |
The TLS certificate will expire soon or has already expired |
| TLS Legacy |
Symantec legacy certificate in use |
| TLS Misconfigured Chain |
The received certificate chain was incomplete or misconfigured |
| TLS Revoked Cert |
The certificate was revoked |
| No HTTPS Redirect |
HTTP website does not redirect to HTTPS |
ApplicationContent
CMS VersionDefacement |
AnThe applicationvisual runningappearance onof ana outdatedwebsite verrsionwas haschanged beento founddistribute onsocial, political or just for fun messages to the websitevisitor |
CMSContent VulnerableViolation |
AnChanges applicationof withthe content of a possibleWeb vulnerabilitypage hasare beendetected. foundThese onchange may be intended by the website |
owner or CMSmay Tamperedbe Corethe fileresult of
WordPressa changemalicious and are only generated by Nimbusec's server agent.attack. However, Nimbusec
cannotdoes not distinguish between legitimate and malicious changes.
Blacklist
Blacklist
The domain which is subject to review is found on blacklists monitored by Nimbusec
Reputation
Suspicious Link
Suspicious resources, based on blacklists monitored by Nimbusec, are embedded (but not loaded) on a Web page. A typical example of this type of event would be a link (a-tag) which points to a suspicious domain found in the Nimbusec blacklist.
Suspicious Request
A suspicious resource, based on blacklists monitored by Nimbusec, is actively loaded by a Web page. A typical example of this type of event would be a JavaScript source which points to a suspicions domain.