Skip to main content

Nimbusec Website Security Monitor Issue Types (Short)

MALWARE WEB SHELL APPLICATION TLS CONTENT BLACKLIST

REPUTATION

CONFIG





Malware
NameEventDescription
Malwaremalware Malicious code fragments are found on a Web page. Typical examples would be, amongst others, credit card skimmers, crypto miners or tech scams.
SEO-Spamseospam If changes on a website are detected while acting as 'googlebot' instead of the default browser agent a warning for suspicious behavior is created
Web Shell
Web Shellwebshell

Malicious code patterns are found in source files based on behaviour patters and signature database of the Nimbusec server agent

Application
CMSOutdated VersionApplicationcms-version An application running on an outdated verrsion has been found on the website
CMSVulnerable VulnerableApplicationcms-vulnerable An application with a possible vulnerability has been found on the website
CMS Tamperedcms-tampered Core file of WordPress change and are only generated by Nimbusec's server agent. However, Nimbusec cannot not distinguish between legitimate and malicious changes.
TLS
TLS Protocoltls-protocol Unsafe TLS protocol allowed in configuration
TLS Ciphersuite tls-ciphersuiteUnsafe TLS cipher allowed in configuration
TLS Sigalgtls-sigalg Outdated hash algorithm was used in the creation of the certificate
TLS Notrust tls-notrustUntrasted root certificate
TLS Hostnametls-hostname Hostname or alternative name does not match the certificate
TLS Expirestls-expires The TLS certificate will expire soon or has already expired
TLS Legacy tls-legacySymantec legacy certificate in use
TLS Misconfigured Chaintls-misconfigured-chain The received certificate chain was incomplete or misconfigured
TLS Revoked Cert tls-revoked-certThe certificate was revoked
No HTTPS Redirectno-https-redirect HTTP website does not redirect to HTTPS
Content
Defacementdefacement The visual appearance of a website was changed to distribute social, political or just for fun messages to the visitor
Content Violationcontent-violation Changes of the content of a Web page are detected. These change may be intended by the website owner or may be the result of a malicious attack. However, Nimbusec does not distinguish between legitimate and malicious changes.

Blacklist

Blacklistblacklist The domain which is subject to review is found on blacklists monitored by Nimbusec
Reputation
Configuration
opendir config-opendirWhen a web server’s directory listing is enabled, anyone can browse the contents of folders (e.g., `/files/`) instead of being restricted to specific pages.
php Error config-phperrorWhen PHP error messages are shown directly to users instead of being logged securely.
public config config-publicApache status pages are checked for public accesibillity.
Security Header configconfig-secheads

Will be shown if SHR rating is grade "D" or lower.
(missing or improperly configured HTTP security headers, such as Content-Security-Policy, Stricy-Transport-Security or X-Frame-Options)

Deprecated Headerconfig-header-deprecated


Text
SRI Missingsri-missing
SRI Invalidsri-invalid
Hijack Linkhijack-link
Hijack Resourcehijack-resource