Showing posts with label Hack Wordpress. Show all posts
Showing posts with label Hack Wordpress. Show all posts

Sunday, 1 March 2015

Security Firm Warns Of Hype About WordPress Leak


An American security company has warned the hyping of leaks in the content management system WordPress. Following are reports on various websites about a leak in a WordPress plug-in which more than one million websites were exposed to risk.

The vulnerability was in the plugin called WP Slim Stat. Via the leak would be a "blind" SQL Injection attack are possible.Allows an attacker could read information from the database. According to security firm WhiteFir design these types of vulnerabilities are not used in automated attacks, which most WordPress sites have to deal with. In addition, the leak at the time of news coverage already patched.

"The chances that the leak is abused are quite small compared to a vulnerability that affects PHP files can be uploaded to a website, which will surely be attacked," said the IT security officer. The company also criticizes said plurality of more than 1 million Web sites. The plug-in in question has been downloaded over 1 million times, but downloads does not mean that there are as many websites with the plug-in.

In the case of WordPress are namely also updates to plugins counted as a download. The number of actual users is therefore much lower than the number of downloads. According WhiteFir Design have also the media the opportunity to harm the security of WordPress sites. Users should keep their plugins namely always up-to-date, especially since developers do not always mention that they have remedied vulnerabilities.

Wednesday, 11 February 2015

Chanitor Trojan: "Maleficent Microsoft Volume Licensing Spreading Malware"


Several companies have recently received an email from the Microsoft Volume Licensing Service Center (VLSC) comes appeared and attempts to spread via a clever trick JavaScript malware. Through the VLSC companies to manage their Microsoft licenses. The message that goes around is very similar to the emails that sends Microsoft normally on the VLSC and a personalized salutation. According to the e-mail recipients may register via the attached link for the VLSC.

The link actually points to a hacked WordPress server. Using JavaScript, however, the real-VLSC Microsoft Web site shown where users can log in. However, there is simultaneously a zip file provided that the hacked WordPress server originates.This seems like the file from the Microsoft Web sites originates, although the hacked WordPress server is listed at the download location.

Offered zip file contains another .scr file is a Trojan horse. This "Chanitor Trojan" then connects to the Tor network. According to Cisco, the malware at the time was that the e-mails were detected around 9 out of 57 virus scanners on VirusTotal.

Hashesh:

1b147fc9d5342ca0fa59207d366ec4fb  (VLSC Microsoft.zip)

6266dc7f68e98b3a52908a7e2b5fe4eb (Volume_Licensing_Service_Center_details_7834892334.scr)