Showing posts with label Hacking Wordpress Sites. Show all posts
Showing posts with label Hacking Wordpress Sites. Show all posts

Thursday, 26 November 2015

Linux Ransomware Demanding $ 999 For Decryption



A new variant of ransomware that on Linux web servers has provided asking $ 999 for decrypting the encrypted files, but Russian victims to their files free of charge by cyber criminals leave decrypt.

Linux.encoder such as ransomware is called, has provided on WordPress websites and web shops running on Magento. The attackers know exactly how to get in is still not clear. Once active Linux.encoder encrypts all kinds of files on the server. Initially the early ransomware $ 50 to decrypt the files, but that rose to $ 500. However now discovered variant asks $ 999 for decryption and wants victims to pay within seven days.

In addition, the creators seem to make an exception for Russian victims, reports anti-malware company Malwarebytes. In one case was discovered there a Russian message. This states that if a Russian website, the files can be decrypted free. According Malwarebytes find the attacks probably is automated and may countrymen of the attackers who inadvertently website is encrypted in this way recover their files free of charge.

Saturday, 19 September 2015

Thousands Of Hacked WordPress Sites Spread Malware


Attackers have managed to hack thousands of WordPress sites and use them for distributing malware, including the website of a US security. Before that warns security firm Sucuri. It would now go to 6,000 contaminated sites.

The attacks on the WordPress websites began two weeks ago. The hacked sites placed code that visitors unnoticed a page with the Nuclear-exploitkit late charge. This exploitkit is using known vulnerabilities in Adobe Flash Player and Internet Explorer users have not patched. Among the hacked WordPress sites are among other Coverity's website, a company dealing with security software.

How the attackers access to the WordPress sites managed to get has not been determined yet, but the attackers seem to create vulnerabilities in WordPress plugins use. Not just forget owners of WordPress flocking to update the software on their website, including updates to installed plug-ins will be forgotten. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use.

Friday, 18 September 2015

Increase In Brute Force Attacks Against WordPress Sites


WordPress sites get more and more to do with brute force attacks, in which it tries to log in using common passwords on the website. According to figures from security firm Sucuri that brute force attacks keep on WordPress websites.

According to Daniel Cid Sucuri his brute force attacks is still one of the main reasons why websites are hacked. "If you have you have to do with brute force attempts to make an unsecure login page", he tells. Administrators of a WordPress website can according to Cid take various measures against these types of attacks, such as setting captchas, only allowing certain IP addresses (IP whitelisting) and two-factor authentication.

Other WordPress administrators say that the attacks can be prevented simply by changing the URL of the login page and block in the .htaccess / IIS configuration. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use. Regular security reports about large numbers of WordPress sites that have been hacked and used to spread malware.

Wednesday, 16 September 2015

WordPress Vulnerabilities Take Over Attacker's Website


The administrators of WordPress have released a security update for the content management system which fixes three vulnerabilities. Through the vulnerabilities an attacker could take over the website, as reported to the Computer Emergency Readiness Team of the US government.

These include two cross-site scripting vulnerabilities and a leak that allows users without sufficient rights privépostings could publish and could make sticky. Furthermore there are 26 non-security-related bug fixes. Users are advised to go to WordPress 4.3.1 upgrade. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use.Recently, it was revealed that millions of websites who use WordPress running a vulnerable version. This means they can be hacked and used to spread malware.

Monday, 7 September 2015

Millions Of WordPress Websites Vulnerable To Hackers


WordPress is by far the most popular content management system (CMS) on the Internet, but many administrators forget to update the software or use vulnerable plug-ins, allowing millions of websites are at risk of being taken over. The Danish security Heimdal Security warns that the looks of hacked WordPress websites that distribute ransomware on the rise.

The websites are malicious code placed that visitors unnoticed to a page with the Neutrino-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player, Adobe Reader and Internet Explorer users have not patched. In case the attack is successful, the Tesla Crypt-ransomware placed on the computer, mainly computer games-related data encrypted. Next, there to decrypt the files to be paid.

According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use. The latest WordPress version 4. This version is used by 79.9% of WordPress sites. 20.1% running on WordPress version 3 or older. The latest version of WordPress 3 appeared on November 20, 2014 and fixed it several security vulnerabilities. Also, version 4 have been different versions appeared, in part because of vulnerabilities.

In the 79.9% which WordPress uses 4 can therefore which users are still running a vulnerable version. Each month WordPress websites are 409 million people read. According Heimdal Security is therefore important that WordPress administrators to install available updates, both for their own website as the safety of their visitors.

Sunday, 23 August 2015

Thousands Of Hacked WordPress Sites Spread Ransomware


In recent weeks attackers have hacked more than 2600 unique WordPress sites and provide malicious code that attempt to infect visitors with ransomware. The hacked WordPress sites are all running version 4.2 of the software or older, says security firm Zscaler.

The attack on the WordPress sites consists of several steps. First, the site is accepted in full. So the attackers add a Webshell, and steal the credentials of the administrator. Is then added an iframe to the website that visitors to the WordPress site unnoticed a page with the Neutrino-exploitkit late charge. The iframe code only to users of Internet Explorer is shown. A cookie will prevent victims of the iframe code are offered several times.

To infect users makes the Neutrino-exploitkit using a malicious Flash file. In case Flash Player not installed on the computer, the user is offered an old Flash installation file, and the malicious file is loaded. Do not know how the installer will install exactly Zscaler allows the analysis of the attack.

In case the attack is successful, the ransomware CryptoWall-installed on the computer. This ransomware encrypts files on the computer and asks users a certain amount for decrypting. According to analyst John Mancuso WordPress remains an attractive target for cyber criminals. WordPress is a very popular free content management system used by more than 60 million websites, including about 23% of the Top 10 million websites on the internet.

Friday, 3 April 2015

WordPress Sites Lead To Infectious Pirate Bay Clone


Researchers at Malwarebytes have different hacked WordPress sites discovered that send visitors unnoticed into a clone of the popular torrent site The Pirate Bay. Since then attempts to spread malware in Adobe Flash Player through a recently patched leak.

The website has been set up through "The Open Bay Project", an initiative that allows anyone with minimal technical knowledge can make a "copy" of the Pirate Bay online. The website features the Nuclear-exploitkit. This exploitkit abuse of a vulnerability in Flash Player that Adobe was patched by the end of January. In the case of visitors to the WordPress sites miss this update, they can become infected by a banking Trojan.

This is a Trojan horse that attempts to steal money from online bank accounts. WordPress sites are also not up-to-date and prove an outdated version of the rotating RevSlider plugin. Recently it was announced that there are thousands of WordPress sites using a vulnerable version of this plug-in have been hacked.

Friday, 27 March 2015

Thousands Hacked WordPress Sites Spread Malware


In recent weeks, thousands of hacked WordPress sites which are then used to distribute malware. It also involves several Dutch websites including nummeriban.nl , hoofdpijncentra.nl and the website of Dries Roelvink. That leaves the Dutch security researcher Yonathan Klijnsma today know.

Fiesta Exploit Kit Gate
On the hacked WordPress sites is an iframe placed visitors, without this, have, to a exploitkit forward. This exploitkit uses known vulnerabilities in Adobe Flash Player, Adobe Reader and Java to infect users. However, if users use the latest version of these plug-ins they run no risk. "There are thousands of websites that contain this iframe at this time. From the data I have is about 3,000 websites, but this is probably only a fraction" says Klijnsma.

In case the attack, there can be all kinds of malware installed successfully, including ransomware encrypts files that sorts to Trojan specifically designed to steal money from online bank accounts. According Klijnsma the WordPress sites hacked through a leak in the RevSlider plugin. This is a known vulnerability for which an update is available. Webmasters have not rolled out the update. Owners of a WordPress site then also be advised to both the content management system as installed plug-ins to keep up-to-date.