website statistics

1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading...

Experiencing any troubles of disturbances on your WordPress site? Back in January, hundreds of websites, based on WordPress 3.2.1 ended up being compromised. Back then, the problem revolved around a mysterious attacked who uploaded an HTML page to the standard Uploads folder, thus enabling the page to redirect the user to the Phonix Exploit Kit. At least four hundred sites were reportedly affected.


This time, research blog Sucuri is reporting another issue. They noticed that all the compromised sites they encountered and running under WordPress had something in common – namely a plug-in named ToolsPack ( ./wp-content/plugins/ToolsPack/ToolsPack.php). The designer of the software advertises it this way: “Supercharge your WordPress site with powerful features previously only available to WordPress.com users. core release. Keep the plug-in updated!”

But a closer in PHP inspection reveals the script doesn’t offer anything, and is actually a pretty neat trick. Turns out that the plug-in is a tunnel that allows attackers to get in and execute any cod eon your site. If you happen to find this plug-in installed on your system, remove it ASAP!

How did you end up having something like this in your PHP? Well, on some analyzed sites Sucuri.net found that the plug-in was eased in via a wp-admin, which basically means stolen passwords. On other sites it turned out there was another backdoor adjacent to the initial tunnel.

Just removing the plug-in won’t solve much. You need to do a full security check. Submit your website for a few official review. You might also want to scan your files, update everything you can update and last but not least, change the passwords.

Source

Buy Cheapest Related Product From Amazon.com


Graphene – The Wonder Material Of Tomorrow’s Computers

[Tutorial] How To Jailbreak Your 2nd Generation Apple TV For Extra Functionality
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On February 22, 2012(4 years, 6 months ago.)

You May Also Like:

What Do You Think?

Leave a Reply




Loading Facebook Comments ...

FTC Disclosure: Some of the links of this website are "affiliate links." This means if you click on the link and purchase the item, we will receive an affiliate commission.


Recent Search

Recent Tutorials

Check out this tutorial to know how to install Apple watchOS 3 beta certificate on your Apple Watch and start enjoying the new version.
If you are trying to jailbreak iPhone, iPad or iPod on iOS 9.2 - 9.3.3 without using a computer or Apple ID, then check this video tutorial.
Pokemon Go users are complaining about the crashing and server issues. Check out the tutorial to solve error problems and thanks us later.
Turning off Wi-Fi Assist is a great way to save mobile data since it automatically starts using cellular data when Wi-Fi signal is poor .
If you want to secure your SIM card from others using it, then check out this tutorial to know how to set up the SIM Pin code on your iPhone.
CiderTV is a great alternative to control Apple TV from the Notification Center. Check out this tutorial to set up CiderTV on your iPhone.
Are you annoyed by the split screen mode on the iPhone 6 Plus or 6s Plus? Check out this quick tutorial to turn off split screen feature.
If you could not wait to installed the iOS 10 beta version on you iPhone and now struggling for the errors, then this tutorial is for you.
Siri might not understand the question you asked. But you can use Siri by editing the text that you asked & it will give an updated answer.
Perhaps, you are new Apple user and you might have no idea how to change name of your iPhone. Check out this tutorial to change the name.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook