Answer the question
In order to leave comments, you need to log in
Is share.pluso.ru stealing cookies?
Found suspicious actions after installing the pluso widget
in the head, a couple of scripts are added
kitbit.net/kb.js
t.insigit.com/assets/dct.js
the second reception is obfuscated and mentions cookies.
Are thousands of sites infected?
Answer the question
In order to leave comments, you need to log in
Yes. On Habré there was more than one article on this topic. They steal cookies, soapboxes, phones, overwrite cookies, etc. In principle, what else to expect when you insert js code from third parties on your domain? It's like letting Tajiks into an apartment to wash the windows, knowing only the phone number of their chief, and go on vacation.
For several years already :)
And there were scandals and investigations.
The owners of the service do not disdain to earn money like this.
I found advice to put instead of pluso, which deals with such dirty tricks, sharing from Yandex. Doesn't he do that?
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question