Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Critical WordPress Plugin Bug Helps Hackers Serve Malware on Over 100,000 Sites
wccftech.com ^ | 4 hours ago Dec 17, 2014 | by Shaikh Rafia

Posted on 12/17/2014 5:36:15 PM PST by Ernest_at_the_Beach

Researchers from Sucuri, a security firm, reported on Monday that vulnerabilities affecting a WordPress plugin are being used by hackers to compromise websites and spread malware to users’ computers. According to this report, exploiting a vulnerability in Silder Revolution, over 100,000 WordPress sites have been compromised so far. The code script planted on targeted sites loads a JavaScript malware hosted on a .ru domain.

Slider Revolution is a popular WordPress premium plugin helping users to create responsive sliders. The plugin vulnerabilities were used widely by remote attackers to download files from affected servers. The flaw in a local file inclusion (LFI) affected version 4.1.4 and earlier, and while it was patched by the developer, a large number of sites remain affected.

Here is how the attack happens:

Advertisements

Slider Revolution is being used by over thousands of websites. However, issue becomes bigger as the plugin is wrapped into a number of WordPress theme packages making site owners completely oblivious of the fact that their sites are open to targeted attacks.

Check WordPress security:

Wordpress security

In an effort to minimize impact on the larger internet, Google has already blacklisted over 11,000 websites affected by this soaksoak malware. However, WordPress websites admins can check the security of their sites by using free Sucuri scanner. The malware was first discovered by Sucuri in September, while it has been in works since February.

Complete report: Sucuri 


TOPICS: Computers/Internet; Conspiracy
KEYWORDS: maalware

1 posted on 12/17/2014 5:36:15 PM PST by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

fyi


2 posted on 12/17/2014 5:37:07 PM PST by Ernest_at_the_Beach
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

JavaScript is evil, this is just the proverbial “tip of the iceburg”.


3 posted on 12/17/2014 6:14:26 PM PST by SecondAmendment (Restoring our Republic at 9.8357x10^8 FPS)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

My hosting company notified us of this yesterday.


4 posted on 12/17/2014 6:43:25 PM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
It is vital to keep everything updated in WordPress. This is an excellent plugin; it enables easy construction of javascript/css animations.

Example: www.inhousetechies.com

5 posted on 12/17/2014 6:44:35 PM PST by Jeff Chandler (Doctrine doesn't change. The trick is to find a way around it.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson