Jump to content
begood

New attack today against Wordpress

Recommended Posts

Posted

Update 2: Simple clean up solution: Sucuri Security: Simple cleanup solution for the latest Wordpress hack

Update 1: Note that we are not blaming Wordpress here. I am assuming that if the problem was on Wordpress itself, the number of infected sites would be much much bigger. Maybe a plugin is vulnerable or someone stole lots of passwords. Also, all the hacked sites were on shared hosts, no one so far on a private server.

We are seeing multiple reports today of Wordpress sites (running their latest version) getting compromised. The initial reports today were restricted only to Dreamhost, but now we are seeing the same pattern on blogs hosted at GoDaddy, Bluehost, Media temple and other places.

So, it doesn't look like something specific to a hosting company. The only thing in similar is that all of them are on shared servers.

All those sites had this javascript added to their pages:

Which came from a long base64 encoded string added to their footer.php file (or on all the PHP files in some cases).

You can get more information about the encoded string here (and the final decoded code):

Sucuri Security

One thing very interesting that is becoming a trend is that the malware is also hiding from Google. This causes the site to do not get blacklisted, making it harder for the owner to notice.

People are talking on the forums already:

WordPress › Support 2.9.2 site hacked

http://www.webhostingtalk.com/showthread.p..

http://collabtive.o-dyn.de/forum/view..

How are they getting hacked? We have no clue yet... We can only restrict to a few issues:

  1. Stolen FTP/WP password
  2. Bug on Wordpress
  3. Bug on some Wordpress plugin
  4. Brute force attack against the passwords

Send us more information if you know something.

The guys from WP security lock did a good thread on the issue. You can read here

Sucuri Security: New attack today against Wordpress

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...