Online Services

Blog

  • SQL Injection Vulnerability in WP Statistics

    SQL Injection Vulnerability in WP Statistics

    SQL Injection Vulnerability in WP Statistics

    As part of a vulnerability research project for our Sucuri Firewall, we have been auditing popular open source projects looking for security issues.

    While working on the WordPress plugin WP Statistics, we discovered a SQL Injection vulnerability. This plugin is currently installed on 300,000+ websites.

    Are You at Risk?

    This vulnerability is caused by the lack of sanitization in user provided data. An attacker with at least a subscriber account could leak sensitive data and under the right circumstances/configurations compromise your WordPress installation.

    Continue reading SQL Injection Vulnerability in WP Statistics at Sucuri Blog.

  • The 2017 WordPress Security Half-Time Report

    2017 has been a remarkable year so far for Wordfence and our customers. We are about halfway through the year at this point, so I’d like to give you an update on some of the incredible innovation and progress at Wordfence in 2017.

    Our company’s top priority is to secure our customers’ websites from attackers. Our goals are to prevent an attack before it can occur, and to provide the best detection capability available to help you find and fix security problems and malware on your website. To fulfill this objective, we need to innovate constantly on several fronts. This year, we have improved the performance of our security products, improved detection capability, introduced a completely new service that expands beyond the WordPress universe, and published continual cutting-edge research to help you better understand the threats you are facing.

    As a result, the team at Wordfence has been terrifically busy this year, and the items I mention below only include the highlights of their many impressive achievements so far. The Wordfence security plugin for WordPress has received 13 updates this year as of this writing, or an average of an update every two weeks. To get an idea of the rapid pace of innovation at Wordfence, look at the most recent 13 releases in our change log and how much has gone into each one.

    Plugin Release Highlights in the First Half of 2017

    First, a Strong Focus on Security Innovation

    January 12: We released an improvement to brute force login reporting, tracking brute-force attempts to wp-login.php and XMLRPC separately so that we could better identify attackers and attack types. We also improved the performance of brute force attack reporting.

    January 26: We launched a robust Dashboard for Wordfence to give you a clear overview of your security posture. This release also included a menu redesign to help you navigate the Wordfence user interface more easily.

    February 7: This release changed the way we block IPs: we switched to blocking them at the Wordfence WAF (Firewall) level to virtually eliminate the performance impact that blocked IPs have when accessing your site.

    February 23: We improved the Wordfence firewall’s ability to inspect incoming form submission requests for malicious content.

    March 9: This was a big milestone. We launched the Wordfence IP Blacklist for our Premium customers. The blacklist is a real-time list of IPs that are attacking WordPress sites right now. It is continually updated and continually pushed out to our customers. This release dramatically improved the protection that our Premium customers receive.

    Next, We Focused on Performance

    March 23: We improved the performance of the Wordfence malware scanner when handling very large files. We also improved Wordfence compatibility with various caching systems.

    April 5: We reduced the memory usage of the overall scan and reduced its network bandwidth usage.

    April 25: We further improved the performance of Wordfence on large multisite installations.

    May 17: We optimized the malware signature scan to improve speed when scanning your site for malicious files.

    June 1: We further reduced the overall memory usage and peak memory usage of the malware scanner.

    Now, A Shift Back to Security Improvement and Innovation

    June 15: We added a brand new capability to the Wordfence scan, letting you know if you are using any plugins that have not been updated in two or more years. It also alerts you if a plugin you are using has been removed from the WordPress.org plugin repository. The scan also includes any vulnerability info related to an outdated plugin or one that has been removed from the official WordPress repository. This helps you ensure that the plugins you are using are well-maintained and vulnerability-free.

    Major Customer Service Improvements

    January 9: Wordfence added Paypal support to our checkout. This was by popular request, and intended to better support our international customers.

    January 26: Our site cleaning team lowered the price for site cleanings from $179 per site to $149 per site. When the site cleaning team told me they wanted to do this in early January, I was very surprised and, of course, overjoyed. They explained that their operations had become so efficient that they could lower the price to the $149 level. When you consider that a site cleaning includes a Wordfence Premium license worth $99, that is a huge value.

    May 4: The site cleaning team then went even further and launched our Site Security Audit service. Our customers have been asking for this service for a long time, and the package the team put together is exceptional. Along with the comprehensive security auditing service, it includes a 90-day guarantee and a free Wordfence Premium license for just $149 per site.

    May 16 was a big day for us. We launched Gravityscan.com, which scans any website for malware and vulnerabilities. Gravityscan is a completely new kind of scanner that performs a deep scan of any website to discover security problems that may make your site vulnerable to being hacked, and also checks if you have already been hacked. The team had worked on Gravityscan for about a year prior to launch. It is phenomenally high-performing, very easy to use and free. Gravity continues to grow at a terrific pace and already has thousands of daily users performing security scans on their websites.

    Highlights From the Blog in the First Half of 2017

    January 12: We blogged about a highly effective Gmail phishing campaign that was affecting even experienced online users. The campaign used a data URI to throw up a fake login screen and steal Google credentials. On January 18, Google reached out to us and provided information on what actions they had taken to fix the issue, and we posted a follow-up.

    Early February was a dark time for many WordPress site owners. A major vulnerability was found in the WordPress core which allowed attackers to exploit the WordPress JSON API to easily deface WordPress sites. A security company disseminated details about the vulnerability, and the exploits began almost immediately.

    February 9: We covered the story in a blog post titled “A Feeding Frenzy to Deface WordPress Sites.” We hadn’t seen an attack this bad before or since.

    February 10: We posted a follow-up showing a 26% growth in defacements within 24 hours. This was an early indication of how widespread and severe the impact of this attack would be. Wordfence added protection for our Premium customers in real-time as this attack emerged.

    February 13: We published research showing how WordPress was used as a command and control server for some of the malware used in the 2016 election hacks.

    February 23: We wrote about a catastrophic data leak that Cloudflare experienced. The Cloudflare system had inadvertently mixed sensitive data across sites and visitors. A visitor to one site would accidentally receive data destined for a visitor viewing a completely different site.

    March 1: We published a report on a criminal organization we code-named Jersey Shore. This organization was attacking and infecting WordPress sites and using them to market counterfeit sports apparel.

    March 17: We came out in support of end-to-end encryption on the Web. We recommended that website owners move away from cloud-based WAFs that intercept traffic and decrypt it. Instead, we suggested that site owners allow users to have a completely secured connection from their browser to the destination web server without intercepting traffic.

    April 10: We published a report identifying thousands of vulnerable and infected home routers at ISPs around the world that were attacking WordPress websites. We identified over 10,000 IP addresses in Algeria alone that were attacking WordPress. We posted a followup the next day providing a tool that users could use to check if their router is vulnerable.

    April 14: We published a report showing how attackers were able to register a domain that looked identical to a legitimate domain and use it for phishing . The technique exploited the way web browsers render unicode domains. We included an example where we registered our own demo version of a domain called ‘epic.com’ that looked identical to the real epic.com and could be used for phishing.

    April 20: We published a fun post that included over 50 tools for security analysts. These tools were curated by our team during a technology-sharing call, and they use many of those same tools in their day-to-day work.

    May 10: We published research that included 22 abandoned WordPress plugins still listed on the WordPress repository, each of which had significant security vulnerabilities.

    May 12: We wrote about WannaCry, also called WannaCrypt, as the story was unfolding in real-time. We published the story on within hours of the attack first emerging to give our users early warning. By the following Monday, it had become a major story in the media.

    The Next Half of 2017 Will Be Extraordinary

    Writing this blog post has been a helpful exercise for me personally. We are so busy at Wordfence that we don’t often take a step back and look at how far we have come, or how quickly we are moving. Writing this post has given me a tangible sense of how quickly the team is moving.

    I am continuously looking for ways to improve our organization, our practices and our business processes. Looking at what we have achieved in the first 6 months of this year, I am left with a sense that we have a small (38+ people) but nimble, adaptive and fast-moving team that is doing a fine job of serving our customers.

    As always, we will continue to improve and innovate. I expect the second half of 2017 will have challenges in store for our customers and the security community, but the Wordfence team is well-equipped to respond rapidly and ensure that our customers receive the best available protection for their websites.

    Mark Maunder – Wordfence Founder & CEO

    The post The 2017 WordPress Security Half-Time Report appeared first on Wordfence.

  • PSA: Petya Ransomware Affecting Critical Systems Globally: Here’s What to Do.

    Updated 3:19PM Pacific Time: A method to ‘vaccinate’ yourself against this ransomware variant has been found. I have posted details towards the end of the post along with a batch file you can run. It is as simple as creating the file C:Windowsperfc and marking it read-only.

    Update 2 at 7pm PST on Tuesday: It appears that the initial infection many have come from a company called MeDoc that was breached. Their systems were infected and they then pushed out an update, spreading the infection. MeDoc are disputing the allegation. Sources: Talos quoted on ZDNetForbes and FireEye.

    This is a public service announcement from Wordfence due to the widespread and severe nature of this attack. A major ransomware attack targeting Microsoft Windows systems is affecting companies and systems, many of them critical, on a global scale.

    What We Know

    A new ransomware variant is spreading quickly across the globe at the time of this writing. There is no consensus yet in the security research community, so the following information is provisional in nature:

    The ransomware has been dubbed “Petya.” It likely spreads by using two separate exploits. You don’t need to click on anything or take any action. This can spread into your system through the network. That is why it is having such a wide impact and why it is important that you update your system to protect yourself.

    For the technically minded: This ransomware is exploiting a vulnerability in Microsoft Office when handling RTF documents (CVE-2017-0199). It also exploits a vulnerability in SMBv1 which is the Microsoft file-sharing protocol. This second vulnerability is described in Microsoft security bulletin MS17-010.

    The ransomware has affected a large number of companies, organizations and government entities on an international scale. The following is a screenshot of the ransomware page you are confronted with once your files are encrypted:

    Colin Hardy has provided a behavioral analysis of Petya, which includes a video demonstration of the malware in action:

    What To Do

    If you have not done so already, you should immediately install the MS17-010 patch from Microsoft.

    If you currently run an unpatched Windows system, you may not have time to patch it before you are infected. Consider shutting down your machine, if feasible, and leaving it off the network until there is consensus in the research community on what this exploits and how to protect against it.

    If you are technically able to, we recommend you block network access to port 445 on your Windows workstations. You may also want to monitor traffic to that port if you are a security professional.

    Keep an eye on the Microsoft Security Response Center where they will hopefully release formal guidance soon.

    Update your anti-virus definitions and run a scan on your system. You can find out which anti-virus products are detecting the current variant of Petya on this VirusTotal page. I’ve linked to one of the files involved in the infection. The page shows which AV vendors are currently detecting this file. The green check marks mean the file is not detected by that AV vendor (it’s counterintuitive).

    Who This Has Affected So Far

    • A Ukrainian state power company and Kiev’s main airport were among the first to report issues.
    • The Chernobyl nuclear power plant has had to monitor radiation levels manually after they were forced to shut down the Windows systems that their sensors had been using.
    • Antonov aircraft has reported being affected.
    • Copenhagen-based shipping company Maersk is experiencing outages in multiple IT systems and across multiple business units.
    • Food giant Modelez, which makes Oreo and Toblerone, has also been hit.
    • Netherlands-based shipping company TNT was also hit.
    • French construction company St. Gobain has been affected.
    • Pharmaceutical company Merck says they have systems affected.
    • Law firm DLA Piper was hit.
    • Heritage Valley Health System, a US hospital operator, has also been hit.
    • Kiev’s metro system has stopped accepting payment cards because they were affected.

    The list is long and growing; the above just a snapshot.

    Strong Incentive for Attackers

    Many are reporting the belief that the South Korean hosting company that paid attackers a $1M ransom a week ago to recover their data have created a huge incentive for future ransomware attacks.

    That has resulted in this new spate of attacks affecting systems globally.

    Coverage of This Story

    Update 3:19pm PST: A Vaccine has been Found

    In the past couple of hours researchers have found a ‘vaccine’ against having your files encrypted by this new variant of Petya. They discovered that if a file exists, the encryption routine will not run.

    Amit Serper who found this had their findings confirmed by other security researchers.

    To vaccinate a machine against this ransomware, simply create a file called perfc in the C:Windows folder and mark it read only. The following batch file courtesy of BleepingComputer will do the job for you:

    https://download.bleepingcomputer.com/bats/nopetyavac.bat

    This post in BleepingComputer also includes instructions on how to create the file manually if you would prefer to do that. Once this file is created, the encryption routine for this specific ransomware variant will not run and encrypt your files.

    Help Keep the Community Safe

    We recommend you let your friends and family know about this fast spreading campaign as a matter or urgency to help them stay safe.

    The post PSA: Petya Ransomware Affecting Critical Systems Globally: Here’s What to Do. appeared first on Wordfence.

  • WSO Shell: The Hack Is Coming From Inside The House!

    Imagine that one day you discover that a burglar has broken into your home and attempted to make off with your big-screen TV. Fearing for your safety, you immediately contact local law enforcement, and they promptly apprehend the criminal. But to your horror, as they drag the burglar away in handcuffs, they have an additional shocking revelation: the burglar has not only been living in the basement of your home for months, entirely undetected by you, but he’s also converted your basement into an elaborate base for all of his criminal operations.

    You, of course, are both shocked and appalled! How could you not have noticed a nefarious criminal had hijacked your whole residence right under your nose? And how much damage have they already done, unbeknownst to you, all while secretly living under your own roof?

    That’s a lot like what it’s like when an attacker compromises your website and quietly installs a malicious web shell, taking over and executing all kinds of malicious scripts and behavior: your website has been broken into, hackers have made themselves at home on your server, your bandwidth and storage space have been stolen, and you’re none the wiser.

    The Wordfence team has seen thousands of malicious scripts from hackers attempting to compromise the millions of sites that we protect. But there’s one particularly invasive script that, once it makes its way onto your website, acts exactly like the burglar in the above scenario, living in your site’s “basement” and allowing the attacker to wreak havoc almost completely undetected indefinitely: the WSO web shell.

    What Is a Web Shell?

    A web shell is a script that runs on a web server, much like WordPress or any other PHP code. It allows the user to do things as if they were logged in to the server directly. It’s like a server administration tool: it lets the user view or edit files, work with databases, and even run programs. Web shells created by hackers usually have additional malicious features, such as sending spam or automatically defacing a website.

    Web shells are not inherently a type of attack or an exploit. Rather, they’re a tool used to manipulate a site after it’s already been broken into. We talk a lot about the different kinds of exploits and why they put your site at risk, but the truth is that security vulnerabilities and exploits are merely the first step in any successful hack. The goal is to break into your website, and then use a script to take over your site and wreak all sorts of havoc via your server.

    That, in a nutshell, is exactly what the WSO web shell does. It takes over your site for the hacker’s own purposes without you ever realizing it’s there.

    What’s “Special” About WSO?

    WSO is a favorite web shell among hackers because of its particularly powerful set of features.

    • Password protection
    • Server information disclosure
    • File management features like uploading, downloading, or editing files, creating directories, browsing through directories, and searching for text in files
    • Command-line console
    • Database administration
    • PHP code execution
    • Encoding and decoding text input
    • Brute-force attacks against FTP or database servers
    • Installation of a Perl script to act as a more direct backdoor on the server

    Once they’re installed on a website, web shells are notoriously difficult to remove, in large part because hackers often place multiple copies of a web shell all over a site to try to retain access even if some of their malware is removed.

    WSO is designed to be used via a web browser, and it has a pretty simple user-friendly interface, making it very easy for any would-be hacker to learn and put to use.

    It seems to strike a good balance between simplicity and capability, since it’s one of the most popular web shells out there. In fact, despite the simple browser interface, we see a lot of hackers using it simply to execute malicious PHP code on websites. In theory, that’s something that a hacker could accomplish more easily with a very small amount of code:

     

    But hackers seem to like and trust WSO so much that they want it on their compromised websites anyway.

    A whole ecosystem has sprung up in the hacker community around WSO shell, with hackers developing secondary tools that support its execution and use. For example, there’s a tool to build a customized version of the shell with only the features you want.

    We’ve also seen a tool to manage multiple sites infected with it, making it that much easier for even entry-level hackers to take over a large number of websites relatively easily.

    History

    For such a ubiquitous tool, WSO’s origins remains something of an unsolved mystery.

    WSO apparently stands for “web shell by oRb.” It was first seen in hacker communities between 2008 and 2009. The earliest mention we could find was a thread in a Russian hacking forum in January of 2009 by a user named oRb, which the script has since been named after.

    That thread was used to announce a major update to the script, though, so that probably wasn’t the first release of WSO. But Google searches for “WSO Shell” started to pick up soon after.

    oRb continued to post updates and new versions of the script until late 2010, when they released version 2.5. That remains the most popular version, though some hackers have released variations since then (and not always out of altruism toward other hackers – some releases include hidden code to notify the author where they’re installed, thereby causing multiple levels of infiltration and damage).

    The WSO shell is widely used by countless hackers all over the world, with the community of users who prefer it as a web shell growing every day.

    In January of this year, for example, we published research about the ChickenKiev or ‘CK’ botnet which uses WSO as part of its operation.

    Each new iteration is intended to make it easier and easier for hackers to take over websites and do whatever they want after that. The laziness of hackers in this regard can’t be overstated. For example, one of the first lines in the WSO shell sets the password required to use it:

    $auth_pass = "63a9f0ea7bb98050796b649e85481845";

    Specifically, this sets the password to the word ‘root.’ Our WAF has blocked hundreds of attempts to upload WSO to websites we protect – all trying to execute with this simple no-brainer default password.

    How Wordfence Blocks WSO

    We have been monitoring and blocking WSO shell hijacking attempts for some time, and as a direct result, we’ve developed a few powerful ways of making sure every website we protect is safe from this aggressive invasion.

    Wordfence protects your site from exploitation using WSO shell in the following ways:

    • Wordfence will detect and block any attempt to upload WSO shell. The Wordfence WAF scans all requests to your website to look for malicious code using our custom-designed malware signatures, which are continuously updated. The WAF, once installed on your site, will detect any attempt to upload WSO shell – and immediately block it.
    • Wordfence’s malware scanner will detect the presence of WSO shell on your filesystem if an attacker manages to find some other way to install it. You will be instantly alerted if WSO shell is found lurking anywhere on your server.
    • Wordfence also blocks attempts to run WSO shell commands, so that even if a hacker manages to get past the first two defenses, it’s a moot point: WSO shell commands simply won’t work on your site.

    How to Tell If WSO Shell Is Lurking on Your Website

    We have two incredibly easy ways that you can use to determine if WSO shell is secretly lying in wait on your website:

    1. If you have Wordfence installed, simply run a scan. If the results come back clean, you almost certainly don’t have WSO shell on your site.
    2. If you don’t have Wordfence installed, or if you use another content management system like Joomla or Drupal, simply use Gravityscan to scan your website. (Important: make sure you have the Gravityscan Accelerator installed.) Gravityscan will scour your website’s entire filesystem, and your scan results should let you know if you have WSO shell installed anywhere.

    Conclusion

    Because of its low barrier of entry, WSO shell is one of the most popular and most malicious tools used by hackers to infect websites. Having WSO shell installed on your website can a dangerous liability for you and your business.

    Of course, the best defense is a good offense, and using Wordfence or Gravityscan, you can not just block and easily detect its presence and keep your site safe from any would-be attackers – you can also make certain that they never break into your “home” on the web in the first place.

    The post WSO Shell: The Hack Is Coming From Inside The House! appeared first on Wordfence.