Latest Entry:
Home » » » » » » WordPress Plugins containing Backdoor distributed via phishing emails

WordPress Plugins containing Backdoor distributed via phishing emails

Updated by Admin on Thursday, 5 December 2013 | 23:02

What would you do when you receive an email offering Pro version of Wordpress plugin for free, if you are a WordPress user? Don't get tempted by such kind of emails, they also give malicious code for free!

Sucuri reported about a phishing emails asking their clients to download Pro-version of "All in one SEO Pack" WordPress plugin.  The email claims that the plugin is $79.00 worth and giving it for free.

"You have been chosen by WordPress to take part in our Customer Rewarding Program.  You are the 23rd from 100 uniques winners." The phishing email reads.

The download link provided in the email is not linked to WordPress plugin store, it is linked to a zip file hosted in a compromised website.

Security researchers at Sucuri analyzed the plugin and found out that it is modified with a Backdoor which gives attackers full access to the server.

The malicious code in the plugin replaces the index.php file with the malicious code retrieved from the attacker's server.  So, when user visit the site, they either redirected to SPAM sites or to Exploit kits where it will infect the visitor's system.


Dated: Thursday, December 5, 2013


Share this entry :

0 comments:

Speak up your mind

Tell us what you're thinking... !

 
Quick Links: Home | About | Disclaimer | Terms and Conditions | Privacy Policy | Copyrights | Advertisement | Contact Us
PathLabStudy® does not provide medical advice, diagnosis or treatment. See additional information.
Downloading and printing of any website content for educational purposes are allowed.
For any other purpose copy of any content from this site page without permission is extremely prohibited.
This site does not store any files on its own server.
PathLabStudy® is not responsible for the content of external internet sites.
Copyright: © PathLabStudy, 2012 - . All rights reserved worldwide. Establish on April 26, 2012.
Website Development by Dayyal Anand (Lab Technologist and Website and HTML Developer).
Website Development by Dayyal Anand. Powered by PathLabStudy®