website statistics

New WordPress ToolsPack Plug-in Based Exploit Causing Issues

When do you use Facebook?

View Results

Loading ... Loading ...
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading ... Loading ...

Experiencing any troubles of disturbances on your WordPress site? Back in January, hundreds of websites, based on WordPress 3.2.1 ended up being compromised. Back then, the problem revolved around a mysterious attacked who uploaded an HTML page to the standard Uploads folder, thus enabling the page to redirect the user to the Phonix Exploit Kit. At least four hundred sites were reportedly affected.


This time, research blog Sucuri is reporting another issue. They noticed that all the compromised sites they encountered and running under WordPress had something in common – namely a plug-in named ToolsPack ( ./wp-content/plugins/ToolsPack/ToolsPack.php). The designer of the software advertises it this way: “Supercharge your WordPress site with powerful features previously only available to WordPress.com users. core release. Keep the plug-in updated!”

But a closer in PHP inspection reveals the script doesn’t offer anything, and is actually a pretty neat trick. Turns out that the plug-in is a tunnel that allows attackers to get in and execute any cod eon your site. If you happen to find this plug-in installed on your system, remove it ASAP!

How did you end up having something like this in your PHP? Well, on some analyzed sites Sucuri.net found that the plug-in was eased in via a wp-admin, which basically means stolen passwords. On other sites it turned out there was another backdoor adjacent to the initial tunnel.

Just removing the plug-in won’t solve much. You need to do a full security check. Submit your website for a few official review. You might also want to scan your files, update everything you can update and last but not least, change the passwords.

Source

Buy Cheapest Related Product From Amazon.com


Graphene – The Wonder Material Of Tomorrow’s Computers

[Tutorial] How To Jailbreak Your 2nd Generation Apple TV For Extra Functionality
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On February 22, 2012(1 year, 3 months ago.)

Recent Search

Recent Tutorials

This tutorial will show how to use S.M.A.R.T. (Self Monitoring Analysis and Reporting Technology) to continuously collect information on health of your equipment.
In this tutorial I'll show you how you can easily protect yourself from any kind of security breaks that may occur through Java.
Today Apple enabled "Two Step Verification" for iCloud And Apple ID. But the process is not that simple. But no worry, here we have made a step by step tutorial.
Cant remember your iPhone passcode? Here I will show you some workaround on what to do and how to recover and restore for every possible scenario.
This tutorial will show you how to perform the Winapp2.ini installation inside CCleaner and how to use it under Windows operating system.
With app called AD Sound Recorder, you can record any stream that passes through your sound card or speakers and in this tutorial I will show you how to do that.
If you want to have Boxee app inside your Apple TV, in this tutorial we will show you how to install XBMC and Boxee using Windows on your Apple TV.
This tutorial will show you how to transfer PS3 Saved Game Files from your PC to your PS3 game console.
Adding videos from external sources such as internet, more specifically from YouTube, is a great solution to enhance a presentation; in this tutorial I will show you the procedure.
If you are one of new comers to Windows Phone 8, like me, in this tutorial I will walk you through the process to update your Windows Phone 8 device.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook