30K WordPress Blogs Infected With the Latest Malware Scam
alphadogg writes with an excerpt from an article over at Network World: "Almost 30,000 WordPress blogs have been infected in a new wave of attacks orchestrated by a cybercriminal gang whose primary goal is to distribute rogue antivirus software, researchers from security firm Websense say. The attacks have resulted in over 200,000 infected pages that redirect users to websites displaying fake antivirus scans. The latest compromises are part of a rogue antivirus distribution campaign that has been going on for months, the Websense researchers said."
websites displaying fake antivirus scans
I didn't know McAfee had started targeting Web blogs now.
"That's the way to do it" - Punch
gaia ~ # find /srv/www/ -type d -name "ToolsPack"
gaia ~ #
Why do they always focus on the crap that's left behind when they analyses these things? I want to know how they managed to get that stuff on those servers so I can check my own. Was is an old and vulnerable WordPress or was it some 0-day they used? For some reason they always focus on the effects and not on the causes.
Is it just a popularity/contrast thing, or does wordpress seem to be popping up a lot recently for security holes in their web servers?
I work for the Department of Redundancy Department.
"The Websense ThreatSeeker Network has detected a new wave of mass-injections of a well-known rogue antivirus campaign"
... moving on ...
How exactly are these sites infected in the first place?
"The page looks like a Windows Explorer window with a "Windows Security Alert" dialogue box in it"
Ahh so - nothing to read here
AccountKiller
The block 194.28.112.0/22 is simply all evil (I've documented it here in the past), there's no reason to send traffic to it at all, blocking it is a good option.
Never email donotemail@WeAreSpammers.com
Why bother using 0day exploits and payload droppers when the best infector is sitting right in front of the PC?
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Anyone else continuing to have a problem when you type your password that it shows instead of ******? My password is ilikegirrlz See, it did it again!
Looks like the exact kind of research vs. malware that I love to find online - the kind that lists the bogus IP ranges &/or bad hosts/domains involved also...
* This, in turn, leads to more valid entries for protection vs. such machinations online via addition to my custom HOSTS file with 0.0.0.0 blocking applied to each of them!
APK
P.S.=> See subject-line, & once more thanks - I truly do appreciate it! apk
Are you an idiot? The article is talking about WORDPRESS - a web application! Windows isn't involved!
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
IF so , where can I get it?
Yes, you WOULD come along and decide to use the hosts file to block entire IP ranges. Which, of course, would require hundreds or thousands of entries, rather than a single firewall rule.
By the way, the hosts file won't even work to block IP addresses (on current versions of Windows at least). It only works for host names. I.e. "0.0.0.0 google.com" blocks http://google.com/ (but http://74.125.225.136/ still loads the Google website), while "0.0.0.0 74.125.225.136" simply doesn't do anything (both http://google.com/ and http://74.125.225.136/ load perfectly fine).
When all you have is a hammer...
he's probably just auto-posting anti-MS fud and pro-Android/Google to build karma. Watch his comment become insightful soon.
Most of my WP installs were infected because I am a slack ass. Here are the high level steps I took to solve the problem:
I may be missing something - again, I'm a slackass. Anyone else have other advice for our admin-challenged friends besides "get a real software package"?
By the way, I was trying to lock down one of my WP installs to only allow authed users access to posts. However, WP does not put the assets for post - usually in wp-content/uploads - behind the auth wall. It's just out there for the whole world to see. It was a simple fix to rewrite the .htaccess config for this directory to redirect to an auth script, but still it still shocks me how insecure this app is.
You're right no one would ever want to involve Windows with their Wordpress install. The year of Windows on the server will never come.
I want this account deleted.
BTW: why is Adobe allowed to - by default - check the box on their flash updates to also install Norton on the victims computer? How many trusting civilians (think: grandmothers) end up with borked computers with conflicting AV programs solely due to corporate greed? I'm willing to bet this check box (if it even appears) is NOT checked by default in the EU market. Man, I miss government FOR the people...
"By the way, the hosts file won't even work to block IP addresses (on current versions of Windows at least)." - by Anonymous Coward on Wednesday March 07, @12:29PM (#39276505)
Proof vs. your misunderstanding my post is RIGHT here:
"Alexander Peter Kowalski says:
May 1, 2011 at 1:51 AM
@JG: Thatâ(TM)s when using firewall rules tables (either software ones OR router based firewalls) to block out IP addresses." - FROM -> http://technologytosoftware.com/block-website-access-on-windows.html
Eat it, boy...
* So, "as-per-my-usual"? I absolutely DUST /. 'naysayers', easily... &, with backing proof!
APK
P.S.=> Epic fail on your part troll... &, it certainly looks like you have to "eat your words", AND, take your 'facepalm' b.s. right back @ yourself, lol!
... apk
"By the way, the hosts file won't even work to block IP addresses (on current versions of Windows at least)." - by Anonymous Coward on Wednesday March 07, @12:29PM (#39276505)
CORRECTION troll: HOSTS NEVER COULD BLOCK IP ADDRESSED BASED ATTACKS ON ANY FORM OF WINDOWS (or other OS'), you utter fool...
* It's no small wonder you post as AC trying to 'goad/harass' me, but to no avail... you're my "AC stalker troll" and you've eaten your b.s. SO MANY TIMES vs. myself? It's not even funny anymore...
APK
P.S.=> Lastly, & perhaps MOST importantly? If you're going to be stupid enough to try to "take me on" & especially on hosts files?? Realize, I practically "wrote the book" on them... I love this part best though, seeing as I can "hit you over your blunt skull with it":
"When all you have is a hammer..." - by Anonymous Coward on Wednesday March 07, @12:29PM (#39276505)
Yea, lol... letting you whack yourself over the head with it TWICE here? Priceless... lol!
...apk
At least Norton tries to provide a working removal tool at no charge. The only problem I've found is that it's made deliberately inaccessible to blind users (with a CAPTCHA) so that malware doesn't automatically run it on every computer that it tries to infect.
And I was looking for a blog hoster this week, and specifically at WordPress. Anyone got a list of free blog hosters (moving away from blogspot)?
now we need to go OSS in diesel cars
Any idea which versions of Wordpress is being targeted and/or which vulnerability? The quoted articles look more like commercials for Websense.
sigaar
I posted far earlier SPECIFIC statements of myself noting you cannot block IP addresses using HOSTS files here:
"Alexander Peter Kowalski says:
May 1, 2011 at 1:51 AM
@JG: That's when using firewall rules tables (either software ones OR router based firewalls) to block out IP addresses." - FROM -> http://technologytosoftware.com/block-website-access-on-windows.html
Eat it, boy... There's FAR EARLIER PROOF that in regards to HOW to use hosts files, I understand them, completely.
You? LOL, you don't have the intelligence to EVER get the best of me, hence why you post as "AC", because you're weak/lame, and you KNOW it.
* Face it, troll - you lose/fail. Also note, I stated the word "valid" in my original reply?
Clue: The ONLY VALID things you can block in a hosts file, are host-domain names, & my FAR EARLIER QUOTE from above notes this... you can't win.
APK
P.S.=> Your other "blunder" here:
http://news.slashdot.org/comments.pl?sid=2712357&cid=39277339
Utterly hilarious - trying to say diff. versions of Windows could block IP addresses using HOSTS files! LOL... apk
http://news.slashdot.org/comments.pl?sid=2712357&cid=39277339
Wordpress is the vector.
Fscking moron.
So? The article is talking about the vector, not the payload.
Fscking moron.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
Blame this, blame that. Guess what, the problem is what you see in the mirror when you look in one. Learn your shit!
Show us I was blocking ip addresses with hosts explicitly. I never said that and I produced evidence I know better (where I even corrected a fellow named JG about it) and I showed literal proof of it.
You incorrectly inferred it. Learn to read.
LOL, You on the other hand made a gigantic blunder stating different versions of Windows could do that here:
"By the way, the hosts file won't even work to block IP addresses (on current versions of Windows at least)." - by Anonymous Coward on Wednesday March 07, @12:29PM (#39276505)
FROM -> http://news.slashdot.org/comments.pl?sid=2712357&cid=39277339
You lose troll: There never WAS a version of Windows, or any other OS, that could block IP addresses with a hosts file.
Hell - You won't even face me under your registered account and that tells the tale perfectly showing you are indeed, weak and a trolling little coward, so calling me "arrogant douche"? Makes me laugh.
See subject-line above, lol... it's YOU!
Yes, you WOULD come along and decide to use the hosts file to block entire IP ranges. Which, of course, would require hundreds or thousands of entries, rather than a single firewall rule. by Anonymous Coward on Wednesday March 07, @12:29PM (#39276505)
See subject. Can't be done\incorrect. You said it, apk didn't. Apk posted proof from long ago he knows this, despite your trolling, your own statement buries you right there.
hosts file can speed up access to his favorite websites by placing the ip address to domain-host name equation into them for his favorite sites avoiding possibly downed or compromised DNS servers (dns poisoning attacks and other known dns issues) as well as plusses for anonymity by the avoidance of DNS request logs or even dns block lists\dnsbls. Firewalls can't, and yet hosts can block out known bad host domains in them (which are the majority of what malware makers use versus ip addresses because domainnames are recyclable). Hosts offer that level of "defense in depth", but also speed gains (adbanner blocking most of all). I've read his posts on that here and elsewhere and apk's absolutely correct on that and has taken on naysayers here for years winning every time versus they. He illustrates both how hosts files are superior to DNS and adblock alone (both have big shortcomings, especially since adblock 'souled out' and doesn't block all ads anymore) and, how they compliment them as well as overcoming their shortcomings.
The current models of Windows in mainstream release, are indeed, Windows 7 + Windows Server 2008 (R2 iirc on the latter but that's just a nitpick & certainly NOT XP as you stated, & now you're trying to "mince words", lol). You fail as usual:
Windows XP is NOT as current as Windows 7, or Windows Server 2008, period.
* Sorry, but I am here to "blow you away" yet again, as usual in this exchange: Per my subject-line above, did you *THINK* I was going to let a devious little wannabe 'smart' weasel like YOU, do that to ME? LOL, guess again...
APK
P.S.=> Above ALL else here, however? Your AC stalking of myself is pitiful, and shows us you do NOT have much confidence in yourself - &, the rest of my replies here do the rest, easily (plus, your taking 3 days to come up with what everyone KNOWS is a line of bullshit on your part? Not too convincing, since the CURRENT MODELS OF WINDOWS ARE NOT Windows XP, pal)... apk
Windows Server 2008 (R2 iirc on the latter...
How many times do I have to repeat myself, you stupid troll?
Windows Server 2008 is NOT THE SAME VERSION of the Windows Server operating system as Windows Server 2008 R2. And that is not a minor nit pick. It is a COMPLETELY different release of the Windows Server operating system. If it was an update, they would have released another SERVICE PACK, like they had already released SP2 for Windows Server 2008, so if you wanted to nit pick you could say that Windows Server 2008 SP2 is a different edition of the Windows Server 2008 OS. But Windows Server 2008 R2 is a different version, as you can see here in this list, straight from Microsoft: http://support.microsoft.com/ph/1163#tab13
Windows Server 2008 R2 (All Editions)
Windows Server 2008 (All Editions)
Windows Server 2003 R2 (All Editions)
Windows Server 2003 (All Editions except Computer Cluster Edition)
Windows Server 2003 Compute Cluster Edition
THEY ARE DIFFERENT OPERATING SYSTEMS. The list does not show any the service packs (different editions of the same OS), because they are NOT different operating systems, but it DOES list R2 separately, because IT IS A DIFFERENT OS. Windows Server 2008 is NOT the "most recent version", Windows Server 2008 R2 is.
The only reason it has the same year? Microsoft released two different versions in one year. The first one was Windows Server 2008. The next one was the 2nd released version (R2) in that year (2008): Windows Server 2008 R2.
Windows XP is NOT as current as Windows 7, or Windows Server 2008, period.
AS CURRENT? So now you admit that IT IS CURRENT (as I said it is), it is just not AS CURRENT as Windows 7. Changing the goalposts? Yes I think so. QED, bitches. Windows XP is a current Microsoft operating system and will be until its end of extended support on April 8 2014.
And Windows Server 2008 is not AS CURRENT as Windows Server 2008 R2. You fail yet again.
You said Windows XP is a current build. It's not and that's that! U FAIL.
You said Windows XP is a current build.
No I didn't, you fucking liar.
I never said that you could block IP addresses using hosts. YOU DID.
I never said that Windows XP is a current build. THAT IS A BLATANT LIE.
I said that Windows XP is a current version. AND IT IS.
Windows XP is in extended support by Microsoft until 2014 and there are hundreds of thousands of computers which are running fully up-to-date, patched, and CURRENT copies of the XP version of Windows.
You're a liar and a dishonest scumbag.
Proof otherwise on ip addresses in hosts files from apk was posted here http://news.slashdot.org/comments.pl?sid=2712357&cid=39277275 from long ago.
Current version(s) of Windows are not XP: Everyone knows taht. It is merely being supported still. Windows 7 & Windows Server 2008 are current models (and their updates like SRVR2).
You fail, you know it, grow up and accept it.
Windows XP has not been sold since June 30, 2008. On October 22, 2010, you will not be able to purchase new computers that already have Windows XP installed on them.
http://www.ehow.com/facts_6876358_buy-copy-windows-xp.html
It is not a current build of Windows idiot. Everyone knows that except you, but then, you DO know that too, don't you? You're just being a trolling waste of life, otherwise you wouldn't do your ac stalking posts would you. Of course not. It is fun making you look stupid though.
APK
P.S.=> I must ask - how BADLY have I 'kicked your ass' here and on what particular technical topic that you insist on attempting to stalk & harass me by your ac stalkings of myself, hmmm? LOL! You're "geek angst" is showing, and I don't think you possess the intelligence to realize 1 simple fact: You will never have the intelligence to get the better of myself, ever... apk
Windows XP has not been sold since June 30, 2008. On October 22, 2010, you will not be able to purchase new computers that already have Windows XP installed on them.
http://www.ehow.com/facts_6876358_buy-copy-windows-xp.html [ehow.com]
It is not a current build of Windows idiot. Everyone knows that except you, but then, you DO know that too, don't you? You're just being a trolling waste of life, otherwise you wouldn't do your ac stalking posts would you. Of course not. It is fun making you look stupid though.
APK
P.S.=> I must ask - how BADLY have I 'kicked your ass' here and on what particular technical topic that you insist on attempting to stalk & harass me by your ac stalkings of myself, hmmm? LOL! You're "geek angst" is showing, and I don't think you possess the intelligence to realize 1 simple fact: You will never have the intelligence to get the better of myself, ever... apk
WINDOWS NEVER COULD BLOCK IP ADDRESSES IN HOSTS FILES IDIOT... period, on ANY VERSION OF WINDOWS, ever!
You said it could, right here, dolt:
"By the way, the hosts file won't even work to block IP addresses (on current versions of Windows at least)." - by Anonymous Coward on Wednesday March 07, @01:29PM (#39276505)
FROM -> http://news.slashdot.org/comments.pl?sid=2712357&cid=39276505
By the way:
What version of Windows did you test, dolt? XP...
(That's also you saying it was 'current' too, above, since you obviously tested that only, & it hasn't been sold by Microsoft since mid 2008!)
APK
P.S.=>
"You haven't." - by Anonymous Coward on Monday March 19, @08:29AM (#39401763)
Kicked your ASS? LMAO - Right: You did it FOR ME, above, in stating Windows could block IP addresses in HOSTS files @ all period (it never could moron, ever)... lol... apk
"You said that, not me:" - by Anonymous Coward on Wednesday March 21, @10:14AM (#39426949)
QUESTION#1: YOU DIDN'T SAY THIS? (in UTTER error, no questions asked)
"By the way, the hosts file won't even work to block IP addresses (on current versions of Windows at least)." - by Anonymous Coward on Wednesday March 07, @01:29PM (#39276505) FROM -> http://news.slashdot.org/comments.pl?sid=2712357&cid=39276505
?
CLUE: Windows NEVER, EVER COULD BLOCK IP ADDRESSES IN HOSTS FILES!
AND??
To back myself showing I knew that much, I even posted data I posted LONG AGO noting that, where I corrected others misconceptions on it.
---
"Alexander Peter Kowalski says:
May 1, 2011 at 1:51 AM
@JG: That's when using firewall rules tables (either software ones OR router based firewalls) to block out IP addresses." - FROM -> http://technologytosoftware.com/block-website-access-on-windows.html
---
(AND, I also said 'valid' in my init. reply here & attempts @ blocking ip addresses via hosts are NOT VALID, & again, I posted proof of my knowing that much)
APK
P.S.=>
"Show me a valid HOSTS file entry that blocks a "bogus IP address" with "0.0.0.0 blocking applied" to it. Show me or shut up." - by Anonymous Coward on Wednesday March 21, @10:14AM (#39426949)
I have already, a couple times, see above (from technologytosoftware.com )!
---
"You can't. It doesn't work.." - by Anonymous Coward on Wednesday March 21, @10:14AM (#39426949)
QUESTION#2: What did I say in the quote from long ago from technologytosoftware.com above regarding my correcting others on what you accuse ME of now?
Answer that... lol, I know you'll evade it.
---
"I tested it on a fully patched and up-to-date (i.e. current) copy of Windows XP." - by Anonymous Coward on Wednesday March 21, @10:14AM (#39426949)
Again - XP is NOT a current model Windows OS - CLUE/New NEWS/NewsFlash:
XP hasn't been sold by MS since mid 2008.
It's merely still supported, but it is NOT CURRENT!
E.G.-> The CURRENT versions of Windows are 7 &/or Server 2008 (R2 update too) - heck, Windows Server 2003's even newer than XP is for that matter also.
LOL, what you're saying is that for example, my 2006 Tiburon GT, though there are a lot out there, is the "current model sportscar" from Hyundai - clue: It's not, & not even sold by they anymore (2002-2009 iirc was its production run)... apk
"
I have already, a couple times, see above!
---