1 October 2018
Mass attack on sites with the WordPress engine
The network identified an automated mass attack, hitting sites developed on WordPress, which is used by about 30% of the ten million largest sites. During the attack, sites with an unrefined engine are affected, while various previously exploited vulnerabilities are exploited during malicious activity, both in the WordPress engine itself and in plug-ins to it.
During the attack in JavaScript files with the extension .js, in php-files with themes and plug-ins WordPress, as well as in the entry from the table wp_posts in the WordPress database, substitution of malicious insertion is performed. The code is substituted both in the clear form and the call form "eval (String.fromCharCode (....))" With a chaotic set of digits. When executing this block, the output of the block is the script download code from ads.voipnewswire.net, examhome.net, cdn.allyouwant.online, uustoughtonma.org, ejyoklygase .tk or mp3menu.org. All WordPress users are advised to make sure that the site engine and installed plugins are updated to the latest version.
There are several manifestations of malicious activity, the most notable of which is the redirection of the user who came to the site to third-party fraudulent resources. For example, redirecting to pages of fictitious messages about virus detection from technical support, trying to force a user to install a Trojan program, phone or specify the parameters of their account.
In addition, many misinterpret these warnings, taking them for penalties. "My clients see warnings from Google Search Console and are nervous. How do I disable it or bypass it? ": Write confusing users. However, such messages Google sends out since 2009, these are simple reminders about the need to update, addressed to operators of popular CMS (WordPress, Joomla, Drupal), registered in Google Search Console. There is nothing terrible in them. But after the frightened users flooded the forums with questions, Google representatives acknowledged that the reminder text should be made "more specific and less confusing".
0
0
Comments
Facebook improves connectivity in the African region with an undersea internet cable
7 November 2021Can blind spots be avoided when monitoring DCs?
3 November 2021Influence of automation in DC on engineering personnel
30 October 2021The frequency of accidents in DC has decreased and the sum of damage has increased significantly
26 October 2021
How to avoid mistakes when choosing a hosting
How to avoid mistakes when choosing a hosting
Chinese manufacturer Loongson will enter the market ..
Chinese manufacturer Loongson will enter the market with 16-core processor in 2020
Please sign-in to comment here