Online Services

Blog

  • Vulnerability in WordPress Core: Bypass any password protected post. CVSS Score: 7.5 (High)

    The WordPress Core team have just released WordPress version 4.5.3 which is a maintenance and security release. The release went out less than 2 hours ago.

    WordPress allows you to create posts that are protected by a password and only users with that password can then gain access to the post.

    On May 3rd we disclosed a vulnerability in WordPress Core to the Core team that allowed any user with an unprivileged account to bypass the password protection WordPress provides. Anonymous attackers are able to exploit this vulnerability and gain access to password protected posts on websites where registration is open.

    The CVSS score of this vulnerability is 7.5 (High) for websites with open registration, because no privileges are required in that case to exploit the vulnerability. On websites with closed registration the CVSS score is 6.5 (Medium) because low privileges are required to exploit the vulnerability.

    The WordPress team responded on May 6th and acknowledged the vulnerability.

    On May 31st they asked for an extension.

    Today, June 21st they released a fix for this vulnerability which is included in WordPress core version 4.5.3 which is a maintenance and security release.

    Note that if you run Wordfence Premium, you have been protected against this attack since May 3rd which is when we disclosed this to the WordPress core team. We included a rule in the Wordfence Firewall that was obfuscated which prevented it from being reverse engineered the moment we disclosed it to the vendor.

    At the time of this writing the official announcement credits “Dan Moen” who is our chief marketing officer and who sent the email to the WP Core team. It is in fact the Wordfence Research Team who found this vulnerability. Credit specifically goes to Pan Vagenas who discovered the attack and to Ryan Britton, Matt Barry and Matt Rusnak for validating the vulnerability and developing and testing the firewall rule that we have been using to protect our customers from this attack. Nice work guys! We’ve reached out to the WordPress Core team to correct the omission.

    We will not be releasing a proof of concept at this time, but we may release one in future to help other firewall vendors add protection to their products which will help the broader community stay safe.

    Full timeline:

    • May 3rd: We released a firewall rule to our Premium customers that protected against this vulnerability being exploited.
    • May 3rd: On the same day we disclosed the vulnerability to the WordPress core team.
    • May 6th: The WP core team acknowledged the vulnerability.
    • May 31st: The WP core team asked for an extension which we granted.
    • June 3rd: The free community edition of Wordfence received protection against the exploit.
    • June 21st: WordPress 4.5.3 was released which includes a fix for this vulnerability.

    The post Vulnerability in WordPress Core: Bypass any password protected post. CVSS Score: 7.5 (High) appeared first on Wordfence.

  • Vulnerability in EWWW Image Optimizer plugin. Severity 9.6 (Critical)

    We disclosed a critical remote code execution vulnerability in the EWWW Image Optimizer plugin to the author yesterday morning. He responded very quickly and published a fix this morning. The plugin is very popular with over 300,000 active installs, according to wordpress.org.

    Wordfence Senior Developer Sean Murphy discovered the Remote Command Execution vulnerability which an attacker can exploit on multisite WordPress installations to gain complete control of a WordPress site. Sean is the same researcher who discovered the critical security hole in Freshdesk that affected thousands of Freshdesk corporate customers, which we announced last month.

    The vulnerability can be exploited in a number of ways including creating a backdoor or taking a site down altogether. To learn more about what hackers do with compromised websites, check out our blog post from April.

    Severity: 9.6 (Critical)

    CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

    What to do

    If you are running the Premium version of Wordfence and have the firewall enabled you are already protected. We added a firewall rule that protects against this vulnerability yesterday morning.

    Free Wordfence users running the vulnerable version of the EWWW plugin should update to version 2.8.5 immediately. 

    The post Vulnerability in EWWW Image Optimizer plugin. Severity 9.6 (Critical) appeared first on Wordfence.

  • WP Mobile Detector Vulnerability Being Exploited in the Wild

    WP Mobile Detector Vulnerability Being Exploited in the Wild

    ***Update: The WP Mobile Detector plugin has been patched to address the vulnerability. Please update as soon as possible, patched version is 3.6, latest version is 3.7. For the last few days, we have noticed an increasing number of websites infected without any outdated plugin or known vulnerability. In most cases it was a porn…

    The post WP Mobile Detector Vulnerability Being Exploited in the Wild appeared first on Sucuri Blog.

  • Wordfence Forensic Team and Site Cleaning Officially Launches

    Wordfence Forensic Team and Site Cleaning Officially Launches

    Today we are proud to officially announce the formation of the Wordfence Forensic Team and the launch of our site cleaning services. I’d like to take a moment and explain why we went into this business, the unique approach that Wordfence takes to repairing hacked sites and in conducting forensic analysis and investigation – and why this is great for Wordfence customers.

    What is Wordfence Site Cleaning?

    If you have a hacked WordPress website, we have a team of highly trained forensic investigators that are ready to help. The service is simple: We’re charging $179 to rapidly get your website clean and back into production. This includes:

    • Cleaning the infection.
    • Investigating how the attackers gained entry.
    • Removing any malicious code, links or other content in your posts, pages, comments and source code.
    • Providing an in-depth report of the infection removal and investigation.
    • We provide a detailed checklist to protect your site from future attacks.
    • Your site cleaning includes a 1 year Wordfence Premium license to keep you safe, worth $59.

    Meet the Team

    One thing I’ve learned as a CEO is that we can best serve our customers by building a team of people who are world-class at what they do. We went out and found the best forensic investigators we could and added them to the core of our team. We started by bringing on board two senior experts in the field:

    resizeccColette Chamberland is one of our two Senior Security Analysts and is a Certified Hacking Forensic Investigator (CHFI) and Certified Ethical Hacker (CEH). She has over 5 years of hands-on forensic investigation experience. You’ll also recognize her name as the person who discovered one of the possible entry points in the Panama Papers breach. She brings a wealth of experience, leadership and knowledge and uses it to effectively lead and mentor our team.

    Brad HaasBrad Haas is our second Senior Security Analyst and joined us from STRATCOM (United States Strategic Command). He is an ISC2 CISSP, GIAC Certified Incident Handler (GCIH) and GIAC Certified Forensic Analyst (GCFA). Brad has over 7 years of forensic investigation experience and provides strong process and technical leadership in forensic investigations for our team along with a hands-on approach.

    Brad and Colette have been working hard at optimizing our site cleaning processes, policies and procedures to ensure customer data confidentiality, integrity and to get our customer sites back online and available as soon as possible.

    Our site cleaning team is now seven highly trained investigators and we continue to bring in more team members as quickly as we can. To recruit, evaluate and train site cleaners quickly and effectively, we decided to turn the challenge into a software problem. We have created a job application system that automatically creates an ‘infected’ virtual machine that our forensic investigator applicants need to clean as the very first step in their job application process. We then take our applicants who have scored well through a rapid evaluation process and if they are accepted into the team, we include excellent training and mentorship from our senior analysts. If you think you might be a good fit for the team we welcome you to apply.

    Why does Wordfence Clean Hacked Sites?

    Our business is to protect WordPress websites from hackers. That means we need to block known and unknown attacks using the Wordfence Firewall. It also means we need to be very good at detecting if a site has been compromised using Wordfence Scan. To be good at both of these things, we need to know how sites are compromised and what indicators of compromise (IOCs) or footprints a hacker leaves behind.

    The best way for us to get this data is to investigate sites that have recently been hacked. Internally we have a sophisticated process that turns the data we gather from hacked sites into what we refer to as our Threat Defense Feed or TDF. The TDF includes the firewall and scan rules that are the product of our forensic investigation efforts. This flows out to the Wordfence plugin in real-time, continually updating our scan and firewall capability to provide you the best protection available.

    What this means is that when you install Wordfence, you have a growing team of forensic investigators working hard to continually update Wordfence with the newest attacks that are occurring on the ground and to protect you from those attacks. The information gained from each hacked site we investigate is used to protect all of our customers from getting hacked using the same method. Furthermore, any footprints an attacker leaves behind are used to improve our scan capability so that we can provide an early warning should the worst case scenario occur.

    Early beach detection and blocking attacks on WordPress websites is what we do. With our forensic investigators constantly increasing the intelligence of Wordfence via the TDF, you have a system that provides the best WordPress protection available.

    Giving Back to the Community

    Most firewalls for WordPress are expensive. With Wordfence, you get the Threat Defense Feed if you’re a free or a paid customer. The only difference is that our Premium customers receive real-time updates while our free community customers are delayed by 30 days.

    As our forensic investigators analyze breaches and we build more intelligence into the TDF, that data flows out to all Wordfence users eventually and does an excellent job of keeping the WordPress community safer. When you choose to have your hacked website cleaned by the Wordfence team, know that the data from your site cleaning ultimately ends up helping to protect the WordPress community.

    Excellence in Customer Service

    I’m constantly surprised by how much positive feedback our customer service representatives and forensic team receives. Today is our official launch but we have actually been cleaning hacked WordPress sites since April 4th.

    Part of our focus at Wordfence, whether we’re providing support for our software or for forensic services, is to provide excellent customer service. Since we soft-launched our site cleaning service I’ve seen many customers who have gone from being frustrated about a hacked site to being overjoyed at how quickly and effectively our team has turned their site around.

    We knew that to provide the best service available for site cleaning, we would have to find the best people – and I’m very proud of our team’s technical ability along with their ability to serve and communicate with our customers and turn an unpleasant situation into a happy customer along with data that helps protect the broader community.

    Let’s Make WordPress and our Community Safer Together

    If you’ve been hacked, contact us immediately by visiting this page and our team will get right on it. We look forward to working with you to get your site repaired quickly and also ensuring that the rest of our community is protected from attacks that are similar to the one you experienced.

    The post Wordfence Forensic Team and Site Cleaning Officially Launches appeared first on Wordfence.