See: http://app.webinspector.com/public/reports/18739375
BitDefender TrafficLight also flags this.
In my google browser it is being blocked by an extension.
A potentially dangerous Request.QueryString value was detected from the client (foo=“”).
Here the ssl issue is missed: https://www.virustotal.com/nl/url/d1ee07efe2c4c513f404b6c83d3d6de05473a35509261947bbea894d2b798bbc/analysis/1386198808/
Web Security Test alerts to a redirect to:
Code: 301, htxps://www.forex-affiliates.com/affacc/promotools.aspx
Redirect to external server!
Good thing to scan here: https://asafaweb.com/Scan?Url=https%3A%2F%2Fwww.forex-affiliates.com%2Faffacc%2Fpromotools.aspx
Several security issues flagged:
Stack trace fail:
Excessive headers warning:
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
X-AspNet-Version: 4.0.30319
Cookies warning: It looks like a cookie is being set without the “HttpOnly” flag being set (name : value):
aff_base_site : 1
Secure Cookies warning: It looks like a cookie is being served over HTTPS without the “secure” flag being set (name : value):
ASP.NET_SessionId : qfhzfh/////////qozsi1545n5n
Clickjacking warning.
Shun this site, do not visit! See: http://jsunpack.jeek.org/?report=5a3824f1df9fa2a6d2d8718311ef6e767524b4e7
polonus