Showing posts with label Wordpress Websites. Show all posts
Showing posts with label Wordpress Websites. Show all posts

Tuesday, 1 December 2015

Linux Ransomware Encrypts 3000 Websites



In recent weeks there have been the ransomware which it has provided encrypted hit 3,000 websites on Linux web servers. This places the Russian anti-virus company Doctor Web, which relies on weather data from Google. It is called ransomware Linux.encoder.

Attackers behind ransomware deliberately set WordPress websites and online stores using Magento. Through a still unknown vulnerability know the attackers to gain access to the Web server that hosts the website and then perform Linux.encoder.This ransomware, which additional duties require encrypts all kinds of files, and then asks one bitcoin, what with the current exchange rate is 349 euros. It is unknown how many webmasters have finally paid the ransom.

F-Secure reported in early November, about 36 people had paid, which at that time corresponded to an amount of 12,000 euros. Due to an error encrypted files can be decrypted without paying. The Romanian anti-virus company BitDefender has developed a free decryption tool for victims. From examination of the virus fighter shows that an early version of ransomware already was distributed on August 25 of this year and then seven people paid the ransom.

Tuesday, 24 November 2015

New Ransomware Variant Linux Uses OpenSSL



Researchers have discovered a new variant of ransomware that encrypts Linux web servers.Linux.Encoder.2, as this variant is called, however, appeared earlier than Linux.Encoder.1 where early November was warned. The second would be used in September and October.

The attackers deliberately set WordPress websites and web shops running on Magento. The attackers know exactly how to enter, according to the Russian anti-virus company Doctor Web is not yet known. Once access to the server is obtained encrypted files and victims get a message that they have to pay. A difference between the first and second variant is the use of OpenSSL instead of PolarSSL. Why the creators of the ransomware SSL library has changed is unknown.

Like the first variant the second variant can also be decrypted so that victims do not have to pay. However, the decryption tools are not removing the infected server to the shell script. Thus, the attackers can infect the server. Victims are advised to call the police, do not change the contents of encrypted directories and not to delete files from the server.

Sunday, 15 November 2015

WordPress Websites Frequent Target Of Attacks


WordPress websites are this year more often been the target of attacks than in previous years and are attacked more frequently than other applications. According to a report (pdf) from security firm Imperva. Researchers at the company looked at attacks against websites and web applications. Then it appears that content management systems (CMS) are attacked three times more often than non-CMS applications.

However, when it came to WordPress 3.5 more attacks. Furthermore, WordPress was seven times more often the target of spam and Remote File Inclusion- (RFI) attacks than non-CMS applications. The problem of WordPress is according to Imperva that all plug-ins and extensions for CMS are developed without security to play a role there. This creates ever new vulnerabilities. In addition, WordPress also based on the PHP programming language, according to the security company.