Posts

Showing posts with the label Security Installers

 CCTV Smart Systems Twitter

This Months Best Cought On CCTV

P.A.S. Fork v. 1.0 — A Web Shell Revival

Image
A PHP shell containing multiple functions can easily consist of thousands of lines of code, so it’s no surprise that attackers often reuse the code from some of the most popular PHP web shells, like WSO or b374k. After all, if these popular (and readily available) PHP web shells do the job, there’s no need to code an entirely new tool. Instead of completely writing a new PHP shell, attackers are simply masking or cloaking the pre-existing code by using a variety of different obfuscation techniques to avoid detection. Continue reading P.A.S. Fork v. 1.0 — A Web Shell Revival at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2020/10/p-a-s-fork-v-1-0-a-web-shell-revival.html via Security Installers

R_Evil WordPress Hacktool & Malicious JavaScript Injections

Image
We often see hackers reusing the same malware, with only a few new adjustments to obfuscate the code so that it is more difficult for scanning tools to detect. However, sometimes entirely new attack tools are created and deployed by threat actors who don’t want to rely on obfuscating existing malware. Confusing Name – R_Evil vs REvil REvil is a group of ransomware (primarily) that has targeted several high-profile victims throughout 2020 — but are probably most well known for their ransomware attack against Travelex, which netted them a $2.3 million ransom payout . Continue reading R_Evil WordPress Hacktool & Malicious JavaScript Injections at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2020/10/r_evil-wordpress-hacktool-malicious-javascript-injections.html via Security Installers

Web Professional Security Survey 2020

Image
According to recent statistics, the web design industry in the United States is now worth more than $40 billion each year. It’s why our annual survey of agencies and web pros is so eagerly anticipated — and we hope you’ll participate in the Sucuri Web Professional Security Survey 2020. If you provide services like website development or online marketing, your insights will be invaluable. You can help shape a better experience for your peers and yourself, as these unique challenges become the subject of meaningful discussions around the world. Continue reading Web Professional Security Survey 2020 at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2020/07/sucuri-web-professional-security-survey-2020.html via Security Installers

Throwback Threat Thursday: JCE Vulnerability

Image
Despite WordPress’ market share completely overshadowing other CMS’, Joomla (previously known as Mambo) has still managed to retain its position as the second most popular CMS. In fact, even with a decreasing market share in the overall CMS landscape, there are still well over a million live websites using Joomla to manage their digital content. As a result, this large installation size makes Joomla an attractive target when it comes to malicious users targeting vulnerabilities. Continue reading Throwback Threat Thursday: JCE Vulnerability at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/10/throwback-threat-thursday-jce-vulnerability.html via Security Installers

The Cost of a Hacked Website – Survey

Image
As part of our commitment to the website security community, we want to know the true impacts of a website compromise from the owner’s perspective. If you are a business that has dealt with any type of website attack, your participation in this six-minute survey will help us improve our services and support website owners like yourself. START SURVEY NOW Be on the lookout for our results summary later this summer! Continue reading The Cost of a Hacked Website – Survey at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/07/the-cost-of-a-hacked-website-survey.html via Security Installers

.htaccess Injector on Joomla and WordPress Websites

Image
During the process of investigating one of our incident response cases, we found an .htaccess code injection. It had been widely spread on the website, injected into all .htaccess files and redirecting visitors to the http[:]//portal-f[.]pw/XcTyTp advertisement website. Taking a Look at the .htaccess Injector Code Below is the code within the ./modules/mod_widgetread_twitt/ index.php file on a Joomla website. This code is responsible for injecting the malicious redirects into the .htaccess files: This code is searching for an .htaccess file. Continue reading .htaccess Injector on Joomla and WordPress Websites at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/htaccess-injector-on-joomla-and-wordpress-websites.html via Security Installers

Slimstat: Stored XSS from Visitors

Image
The WordPress Slimstat plugin, which currently has over 100k installs, allows your website to gather analytics data for your WordPress website. It will track certain information such as the browser and operating system details, plus page visits to optimize the website analytics. Versions below 4.8.1 are affected by an unauthenticated stored XSS on the administrator dashboard. Timeline 2019/05/16: Initial disclosure 2019/05/20: Patch released (4.8.1) 2019/05/21: Blog post released Details This vulnerability allows a visitor to inject arbitrary JavasScript code on the plugin access log functionality, which is visible both on the plugin’s access log page and on the admin dashboard index —‚ the default page shown once you log in. Continue reading Slimstat: Stored XSS from Visitors at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/slimstat-stored-xss-from-visitors.html via Security Installers

W97M/Downloader Malware Dropper Served from Compromised Websites

Image
W97M/Downloader is part of a large banking malware operation that peaked in March 2016. Bad actors have been distributing this campaign for well over a year, which serves as a doorway to Vawtrak and Dridex banking trojans. This malware campaign targets a wide array of users via their operating system and browser to deliver the appropriate payload. W9M/Downloader Malware Campaign W97M/Downloader is a specially-crafted Microsoft Word document that, when opened, silently executes a malicious macro that connects to multiple remote servers to download and display additional components. Continue reading W97M/Downloader Malware Dropper Served from Compromised Websites at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/w97m-downloader-malware-dropper-served-from-compromised-websites.html via Security Installers

Who is Responsible for the Security of Your Website?

Image
On a daily basis at Sucuri, we hear things like: “My host takes care of my website security.” “I have never been hacked, so why should I care?” Or here’s a personal favorite: “I’ll take care of it if (when) it happens.” Let’s be honest, no one wants to think about the possibility of their site being hacked. I have been in the website security industry for a few years now and have seen so many horror stories it’s unreal. Continue reading Who is Responsible for the Security of Your Website? at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/who-is-responsible-for-the-security-of-your-website.html via Security Installers

Persistent Cross-site Scripting in WP Live Chat Support Plugin

Image
During a routine research audits for our Sucuri Firewall, we discovered an Unauthenticated Persistent Cross-Site Scripting (XSS) affecting 60,000+ users of the  WP Live Chat Support  WordPress plugin. Current State of the Vulnerability Though this security bug has been fixed in the 8.0.27 release, it can be exploited by an attacker without any account in the vulnerable site. We are not aware of any exploit attempts currently using this vulnerability. Continue reading Persistent Cross-site Scripting in WP Live Chat Support Plugin at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/persistent-cross-site-scripting-in-wp-live-chat-support-plugin.html via Security Installers

WordPress Plugin Give – Stored XSS for Donors

Image
​​Give is a WordPress plugin which allows users to setup a donation page on a website. It currently has 60k installs. ​​During a recent audit of the plugin, we found a severe vulnerability which allows donors to inject arbitrary code on an administrative page. ​​If you are using a version lower than 2.4.7, you should update immediately. ​​When creating a donation, all of the arguments are sanitized as text fields, but this method does not take into consideration where the variables are reflected. Continue reading WordPress Plugin Give – Stored XSS for Donors at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/wordpress-plugin-give-stored-xss-for-donors.html via Security Installers

Multiple Vulnerabilities in the WordPress Ultimate Member Plugin

Image
The Ultimate member plugin version 2.0.45 and lower is affected by multiple vulnerabilities, among them is a critical vulnerability allowing malicious users to read and delete your wp-config.php file, which can lead to a complete website takeover. All of our clients behind our website firewall are already protected, and are not at risk. The three vulnerabilities have the following DREAD score: Arbitrary file read and delete: 8.4 Admin dashboard XSS: 7.4 User Profile XSS: 6.8 Disclosure / Response Timeline: 2019/05/07 : Initial disclosure 2019/05/08 : Partial patch released (2.0.45) 2019/05/10 : Complete patch released (2.0.46) File Leak and Delete If an admin added a File upload or Image upload input field on one of the forms (such as on the user profile), the user can use it to download any file of the server. Continue reading Multiple Vulnerabilities in the WordPress Ultimate Member Plugin at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/multipl...

New Guide on the Sucuri Referral Program

Image
Referral programs and affiliate marketing opportunities can be found on many web-based company sites, however, often they’re overlooked. Commonly people consider these programs as something that they, “should leave to the professionals”. We designed our new Referral Program Guide to give clear insight into affiliate marketing for both beginners and long-term affiliates.  You don’t need to be an affiliate pro. We treat every member of our program the same–whether you refer hundreds of customers per month or one per year. Continue reading New Guide on the Sucuri Referral Program at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/new-guide-on-the-sucuri-referral-program.html via Security Installers

Free Website Security Consultation for GoDaddy Pros

Image
Sucuri is partnering with GoDaddy Pro to make the internet more secure, one website professional at a time. Developers, designers, agencies, and freelancers now have an exclusive avenue to level up security knowledge and differentiate their businesses from the competition. GoDaddy Pro helps web developers and designers save time and money while managing multiple websites. The free membership includes extensive training materials, automation of routine maintenance tasks, and consolidated client management tools. Continue reading Free Website Security Consultation for GoDaddy Pros at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/free-website-security-consultation-godaddy-pro.html via Security Installers

Persistent XSS via CSRF in WP Meta and Date Remover

Image
During regular research audits for our Sucuri Firewall (WAF), we discovered a Cross Site Request Forgery (CSRF) leading to a persistent Cross Site Scripting vulnerability affecting 70,000+ users of the WP Meta and Date Remover plugin for WordPress. Disclosure / Response Timeline: April 30 – Initial contact attempt May 07 – Patch is live Are You at Risk? This vulnerability requires some level of social engineering to be exploited. Continue reading Persistent XSS via CSRF in WP Meta and Date Remover at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/persistent-xss-via-csrf-in-wp-meta-and-date-remover.html via Security Installers

Replica Spam on Poorly Maintained ASP Site

Image
Although the majority of sites we work on are powered by PHP, we still have clients whose sites use other programming languages. The other day we cleaned an ASP site where we found a web.config file (the ASP.NET version of .htaccess) with these instructions: <configuration>    <system.webServer>        <defaultDocument enabled="true">            <files>                <clear />                <add value=" view.asp " />                <add value=" Default.asp " />                <add value=" index.htm " />     ...

Cronjob Backdoors

Image
Attackers commonly rely on backdoors to easily gain reentry and maintain control over a website. They also use PHP functions to further deepen the level of their backdoors. A good example of this is the shell_exec function which allows plain shell commands to be run directly through the web application, providing attackers with an increased level of control over the environment. Backdoor in Cron While investigating a client with repeated website infections, we came across a scenario where a cron job was being used to reinfect the site. Continue reading Cronjob Backdoors at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/cronjob-backdoors.html via Security Installers

How Stolen Ecommerce Data is Sold on the Darknet

Image
We have recently published posts regarding banking malware and some of the ways it uses compromised websites to infect victim’s devices (smartphones, computers, POS terminals). Now let us look into some of the methods that cybercriminals use to monetize stolen information like bank accounts, credit cards, and personal information. Infected Ecommerce Website to Darknet Markets It’s important to note that one of the most popular topics discussed among cybercriminals is their opsec (operations security). Continue reading How Stolen Ecommerce Data is Sold on the Darknet at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/05/how-stolen-ecommerce-data-is-sold-on-the-darknet.html via Security Installers

Insufficient Privilege Validation in WooCommerce Checkout Manager

Image
Due to the poor handling of a vulnerability disclosure, a new attack vector has appeared for the WooCommerce Checkout Manager WordPress plugin and is affecting over 60,000 sites. If you are using this plugin, we recommend that you update it to version 4.3 immediately. As we’ve seen some exploit attempts occurring in the wild, we feel it is a good time to describe what the issue is. Current State of the Vulnerability This arbitrary file upload vulnerability was made public a few weeks ago and has recently been patched. Continue reading Insufficient Privilege Validation in WooCommerce Checkout Manager at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/04/insufficient-privilege-validation-in-woocommerce-checkout-manager.html via Security Installers

Typo 3 Spam Infection

Image
Here at Sucuri most of the malware that we deal with is on CMS platforms like: WordPress, Joomla, Drupal, Magento, and others. But every now and then we come across something a little different. Blackhat SEO Infection in Typo3 Just recently, I discovered a website using the Typo3 CMS that had been infected with a blackhat SEO spam infection: Typo3 CMS Before I begin, according to websitesetup.org, Typo3 is currently the 8th most widely used CMS platform on the web, so I’m surprised I had never seen an infection with this software before, but it looks like over half a million websites on the web use Typo3. Continue reading Typo 3 Spam Infection at Sucuri Blog. from Sucuri Blog https://blog.sucuri.net/2019/04/typo-3-spam-infection.html via Security Installers

CCTV Installations