Showing posts with label Wordpress Sites. Show all posts
Showing posts with label Wordpress Sites. Show all posts

Monday, 9 October 2017

WordPress Sites Vulnerable By Leak Into Postman SMTP Plug-In



Over 100,000 WordPress sites are vulnerable due to a vulnerability in the Postman SMTP plug-in, and a developer security update is not yet available. Postman is an SMTP mailer that helps send emails generated by the WordPress site.

The plug-in is vulnerable to reflected cross-site scripting, which allows an attacker to steal the content of cookies from, for example, the administrator, according to security company White Fir. Due to the unpatched vulnerability, WordPress decided to remove the plug-in from the database with available plug-ins on WordPress.org . Meanwhile, GitHub has published a patched version of Postman, but it has not been developed by the original author. The original developer would have been informed about the problem.

Thursday, 9 April 2015

FBI Warns Of Attacks On WordPress sites


The FBI has warned webmasters attacks on WordPress sites by supporters of IS terror. It comes to news organizations websites, businesses, religious institutions, government agencies and foreign governments that were recent months.

According to the FBI, the attacks are anything but certainly not refined and complex, but they can be disruptive and costly, for example because of the cost for the repair of compromised systems. The attackers use vulnerabilities in all kinds of plug-ins for WordPress, the popular content management system used for tens of millions of websites. Through these leaks can attackers to take over the websites, for example, customize the content and install malware.

The American investigative late warning to webmasters know that the attackers are not members of IS. "These individuals are relatively simple methods that hackers use to exploit vulnerabilities and use of IS the name to get more recognition than otherwise could be achieved through the underlying offense." To prevent the attacks succeed webmasters get the advice system, WordPress plugins and other installed software to keep up-to-date.

Tuesday, 30 December 2014

CTB (Curve Tor Bitcoin) Locker Ransomware - Specifically Aimed at Dutch Internet Users

Critroni Malware
Researchers have discovered a new variant of a particular ransomware which now specifically aimed at Dutch Internet users. It involves CTB Locker, which stands for Curve Tor Bitcoin, which for the first time in mid-July appeared and encrypts files for ransom.

CTB Locker, called Microsoft Critroni, stands out because of the methodology used. Thus, the ransomware uses the Tor network to communicate with infected computers. Instead of the file to use Tor.exe, as is done by other malware, the maker of CTB Locker has the code of Tor made part of the ransomware code.



Where ransomware also strikes a different path to the encryption used. Most ransomware uses a combination of AES and RSA encryption to encrypt the files of victims. CTB-Locker uses an asymmetric cryptographic protocol known as ECDH (Elliptic Curve Diffie-Hellman). Another new development for the first time at the CoinVault-ransomware was seen is the free decrypt files. Let CoinVault victims one file free decrypt, CTB Locker decrypts free five files.

Bitcoin Address
The ransomware is distributed through hacked WordPress sites. On the websites of malicious code is placed that uses vulnerabilities. However, it is unknown to what vulnerabilities it exactly. In the case, the attack is successful is CTB-Locker placed on the system and will encrypt the ransomware existing files. Security Researcher ' JuK 'of the blog Malware Do not Need Coffee discovered the latest version, which also supports Italian alongside Dutch.


MD5: 10f0eaa794f48ad0b15034e0683cb15f