Prototype.js exploitable and iFrame javascript suspicious...

Re: Website: wXw.golfclubdb.com
Status: Site Potentially Harmful. Immediate Action is Required.
Web Trust: Blacklisted (10 Blacklists Checked): Indicates that a major security company (such as Google, McAfee, Norton, etc) is blocking access to your website for security reasons. Blacklisted: http://safeweb.norton.com/report/show?url=golfclubdb.com
See: https://app.webinspector.com/public/reports/55671654
Re: http://killmalware.com/www.golfclubdb.com/ gives it the all green.
Consider: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.golfclubdb.com%2Fcgi-sys%2Fsuspendedpage.cgi+
Attack vector: https://www.cvedetails.com/vulnerability-list/vendor_id-6541/Prototypejs.html

iFrame check: Suspicious -http://fwdssp.com/?dn=referer_detect&pid=5pol4f2o4

Javascript check: Suspicious

0"> <iframe width=“100%” height=“100%” frameborder=“0” scrolling=“auto” marginwidth=“0” src="-http://fwdssp.com/?dn=referer_de

Earlier treated here: https://forum.avast.com/?topic=182672.0

  • blocked by Bitdefender TrafficLight as part of a PHISHing attempt.
    List of iframes included
    htxp://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4

Webmaster please contact Hostgator.com :o → http://toolbar.netcraft.com/site_report?url=http://fwdssp.com
via

var abp=abp||false;var scripts=document.getElementsByTagName("script");var script=scripts[scripts.length-1];if(script){var query=script.src.replace(/^[^\?]+\??/,"").split("&");var params={};for(var i=0;i<query.length;i++){var param=query[i].split("=");params[param[0]]=param[1]}if(params["ch"]==1)abp=true;else if(params["ch"]==2)abp=abp&&false};

polonus (volunteer website security analyst and website error-hunter)