Online Services

Category: Security

  • Expired Domain Leads to WordPress Plugin Redirects

    Expired Domain Leads to WordPress Plugin Redirects

    Expired Domain Leads to WordPress Plugin Redirects

    A malicious redirect is a snippet of code used by attackers with the intention of redirecting visitors to another site; a very common tactic seen in compromised websites.

    These redirects often take visitors to phishing, malware, or advertising sites with the intention of capturing sensitive user data, distributing malware and backdoors, or generating advertisement impressions.

    We’ve written before about how attackers use expired domains to redirect visitors to malware and ads, or how domains used in abandoned plugins are registered by hackers.

    Continue reading Expired Domain Leads to WordPress Plugin Redirects at Sucuri Blog.

  • Which Wordfence Firewall Rules Are Most Effective?

    Part of the threat intelligence work we do at Wordfence is to constantly analyze the performance of our own firewall rules to determine what is effective and to identify existing and emerging attack trends. Today I’d like to share with you some of the data that we are seeing. If you are curious which attacks our firewall most commonly blocks, and which firewall rules are most effective, you’re going to enjoy this blog post.

    Tracking Our Most Effective Firewall Rules

    For this analysis, we took attack data from June 24 to August 22 (two days ago). We calculated the total number of attacks that each firewall rule blocked in the Wordfence firewall. Then we represented that visually, and labeled the rules that were blocking the most attacks.

    You can see this data represented below:

    This is a stacked chart that shows what percentage of attacks each rule blocked, by day. The total number of attacks represented in this chart over the two-month period is 202,765,759. You read that correctly: over two hundred and two million unique attacks across the sites we protect. Wordfence protects over 2 million websites, which is why this number is so high.

    Each stacked area on the chart above represents a firewall rule in the Wordfence firewall that is blocking attacks. There are a large number of rules, and many of them block a low number of attacks, so they are compressed into a single line. The rules that block more attacks occupy a greater area.

    As you can see, our “directory traversal” rule blocks a large proportion of attacks. These are simplistic attacks that are very popular among unsophisticated attackers. For this reason, we see a lot of them, and they generate a lot of volume on the chart.

    Our SQL injection rule is also a workhorse. That is the orange rule second from the bottom. The Wordfence firewall includes a SQL “lexer and parser.” That means that Wordfence can understand SQL the way a database interpreter does, and it can make intelligent decisions about whether incoming SQL is malicious or not. As you can see, that rule blocks a large number of attacks.

    Emerging Attacks Blocked by Malware Scan Integration

    One of the most powerful rules in the Wordfence firewall that blocks a large number of emerging attacks is our malware scanner rule. I’ve marked the rule in bright yellow in the chart above, and labeled it “Scanner blocked malware.” In September of last year, the Wordfence team released a new version of the Wordfence firewall that integrates our malware scan with the firewall. That means that in addition to our regular firewall rules, Wordfence uses its malware scan logic to examine incoming requests.

    Wordfence currently has 4,628 free and premium malware scan signatures in production. Those are all signatures that identify a unique malware variant or family of malware. By integrating malware scanning into our firewall, it is as though we released over 4,000 distinct firewall rules simultaneously. It has massively improved the detection capability of the Wordfence firewall.

    As you can see from the chart above, the malware scan blocks a significant number of attacks. But the real benefit from this firewall-scan integration is that it blocks sophisticated attacks.

    For our Premium Wordfence customers, when we release a new malware signature in real time, we also add it to the malware scan. Additionally, we also put the rule into production on your firewall and use it to identify and block the newest attacks.

    Premium IP Blacklist Owns the Stats

    Wordfence also includes an IP Blacklist which is available only to our premium customers. Our systems track attacks in real time, and we use attack source data to create an IP blacklist, which we update throughout the day. As our algorithms have improved, the number of IP addresses on the blacklist has expanded, and the list now blocks a very large proportion of attacks.

    The following chart shows you what percentage of total attacks the Wordfence Premium blacklist blocks when we combine the data.

    The blue in the above chart represents the total percentage of attacks the Wordfence Premium IP blacklist blocks. The stacked charts below the blue area represent attacks that all other firewall rules block. This chart is for the same period, June 24 to August 22, 2017.

    The total attacks we logged for the period above is 725,248,603. A total of 202,765,759 attacks that our firewall rules blocked. A total of 464,007,181 attacks were blocked by the Premium blacklist.

    Keep in mind that Wordfence Premium blocks every request from a blacklisted IP. That helps explain why the number of requests we blocked from known bad IPs is so high. Here are a few of the kinds of requests from blacklisted IPs that we block:

    • We prevent them from visiting your home page and detecting WordPress.
    • Blacklisted IPs get blocked from all content, comments and comment-posting.
    • We block them from attempting a brute force attack.
    • We block them from accessing XMLRPC.
    • They are completely blocked from crawling your site.
    • We prevent them from accessing any PHP script in your WordPress installation directly, even if they try to bypass WordPress.

    When you upgrade to Wordfence Premium, you receive new malware scan rules in real time. As I explained above, these are also used in the Wordfence firewall. You also receive new firewall rules in real time. But one of the biggest benefits that many users are not even aware of is that Wordfence Premium enables the Wordfence IP Blacklist in your firewall. And as you can see, this blocks a large number of attacks – it blocks attackers from even accessing your site.

    Wordfence Free Is Awesome. Premium Is Next-Level.

    My personal goal for several years has been to make Wordfence “so good that you are crazy if you aren’t using it to protect your site.” Today I can say with confidence that our team has achieved that goal. If you aren’t using the free version of Wordfence to protect your site, you are missing out on the best available free protection for WordPress.

    With Wordfence Premium, we have taken that protection to the next level with real-time scan signatures, real-time firewall rules and the extremely effective real-time IP blacklist.

    As always, you are most welcome to post your comments below, and I will be around to reply where needed.

    Mark Maunder – Wordfence Founder/CEO.

    Special thanks to Wordfence team members Dan Moen, for producing the data behind this post, and Andie La-Rosa for editing.

    The post Which Wordfence Firewall Rules Are Most Effective? appeared first on Wordfence.

  • Dreamhost is Under DDoS Attack

    Dreamhost is currently experiencing a DDoS attack. I am updating this post in real-time as the situation unfolds. Last update was at 10:46am PST. ~Mark Maunder

    Their team posted this tweet 20 mins ago.

    I’ll be posting updates here as the situation progresses. Their engineers are clearly working the problem.

    You can find their status page at https://www.dreamhoststatus.com/ – currently it says the following are affected:

    Dedicated Servers, DreamPress 2, Remixer, Shared Hosting, Virtual Private Servers (VPS), Webmail.

    Their team detected the attack at 9:20am PST and mitigation started at 10:20am PST.

    Dreamhost has recently been in the news for fighting a US Department of Justice request for the IP addresses of all visitors to a website that they host.

    The DDoS appears to be unrelated to the DoJ request above. It looks like it may be an Anonymous attack targeting the Dreamhost DNS to try to take a white supremacist website called ‘punishedstormer dot com’ offline. The website came online today and is hosted at Dreamhost.

    What is Being Attacked

    Dreamhost currently host an extremist website called punishedstormer. The site’s DNS is also hosted by dreamhost. That means that if you try to access the site, your computer or device contacts Dreamhost’s servers and asks for the IP address so that it can connect.

    The attackers have launched a massive amount of traffic targeting Dreamhost’s DNS servers so that the website they want to take down becomes inaccessible.

    You can see the DNS servers that are being used for the target website in this screen capture:

    As you can see, the servers ns1, 2 and 3 at dreamhost.com are responsible for handing out the IP address of anyone looking up punishedstormer’s address. These are being targeted, possibly along with other DNS servers at dreamhost.

    This will affect the availability of any website and domain that is using Dreamhost DNS services.

    What to Do

    If you host your website at dreamhost, you may not be affected by this attack if you host your DNS with another provider. If you host it with Dreamhost, it is likely that you are affected.

    Unfortunately there is not much you can do. If you move your DNS away from Dreamhost, it will take up to 48 hours for the update to propagate around the Internet. Dreamhost will probably have this situation resolved in the next few hours. So the best advice may be to sit tight until their engineers are able to filter out the DDoS traffic and bring their systems back up.

    Email Also Affected

    It is worth noting that if your domain’s DNS is handled by Dreamhost, then your email deliverability may be affected. Emails that are sent to you may be bounced back to the sender. If you are expecting an urgent email, we recommend that you contact the sender directly and let them know your email may be temporarily unavailable.

    Once this service disruption ends, you may want to let your contact list know that your email may have been temporarily unavailable due to an attack on your email DNS hosting provider.

    Update at 11:22am PST: Dreamhost are reporting that they are beginning to mitigate the attack.

     

    Update at 12:36pm PST: Dreamhost is reporting all services are restored and operational, although they show many services in a ‘degraded’ state. You can find out more information on their status page.

    The post Dreamhost is Under DDoS Attack appeared first on Wordfence.

  • PSA: 4.8 Million Affected by Chrome Extension Attacks Targeting Site Owners

    This is a public service announcement from the Wordfence team regarding a security issue that has a wide impact. During the past 3 months, eight Chrome browser extensions were compromised and the attacker used them to steal Cloudflare credentials and serve up malicious ads.

    This post discusses exactly what happened, how to protect yourself and what the wider implications are of this supply chain attack.

    How the Chrome Extensions Were Compromised

    In June, July and August, developers of the following Chrome extensions had their login credentials stolen through a phishing attack. The extensions affected are:

    • Web Developer – Versions 0.4.9 affected
    • Chrometana – Version 1.1.3 affected
    • Infinity New Tab – Version 3.12.3 affected
    • CopyFish  – Version 2.8.5 affected
    • Web Paint – Version 1.2.1 affected
    • Social Fixer 20.1.1 affected
    • TouchVPN appears to have been affected but the version is unclear
    • Betternet VPN also appears to have been affected but no version was provided

    Based on total installs for these extensions, the attackers targeted a total of 4.8 million users. The developers of these Chrome extensions all had their account credentials compromised. They received an email that looked like this:

    The link in the email used the bit.ly URL shortener to redirect the developer to a fake login page which harvested their credentials and allowed the malicious actor to take control of the chrome extension developer’s account.

    How the Attackers Modified Affected Chrome Extensions

    Once the attackers had access to modify the code in these Chrome extensions and release new code, they made a change that injected their own malicious Javascript into the extensions. The new code looked like this:

    The code injects Javascript from the attacker’s own domain into the victim’s browser. The victim here is someone who is using the Chrome web browser and has one of these extensions installed.

    This allows an attacker to perform any action as the victim. This includes accessing any website the victim is signed into and modifying the content of any web page that the victim views. Once an attacker has control of one of your Chrome extensions, they own your web browser.

    How Cloudflare Credentials Were Stolen

    Once a victim installed a compromised Chrome extension, the extension would steal Cloudflare credentials if the victim has a Cloudflare account. The extension did this by making a request to a URL on Cloudflare to get an API key.

    Once the attacker’s compromised extension gets the API key, it sends that and the user email to the attacker website. The code that does this is shown below:

    Why Cloudflare Credentials Were Stolen

    Once the attacker has a site owner’s Cloudflare credentials, they can perform a variety of malicious actions. This includes modifying a website’s DNS entry to point the site at the attacker’s own server. The API call they would make to do this is the “Update DNS record” function in the Cloudflare API.

    This is an example request showing how the user email and API key is used in Curl from the command line to update a DNS record:

    At this time we have no reports of websites having their traffic redirected by the attacker. They may have collected credentials for a future attack.

    Attackers Engaged in Malvertising

    In addition to stealing Cloudflare credentials, the attackers engaged in ‘malvertising’. The malicious Chrome extension code served up ads belonging to the attacker.

    They did this by hijacking ads from well known ad networks and replacing those ads with their own ads. Most of the substitutions occurred for ads being served from adult websites.

    Many of the ads were a fake alert telling the browser owner they need to repair their PC. They were then redirected to an affiliate program which the attacker profited from.

    How to Protect Yourself

    1. Even the Pros get Phished

    Lesson number one from this attack is that, as we have reported in the past, even those of us who are seasoned online professionals can fall victim to a phishing or spear phishing attack. Make absolutely sure that if you receive an email, you verify the origin and think before you click or download.

    1. Never click on a link if you don’t recognize a sender.
    2. Never click a link in an email and sign in to a service. Instead, if you are presented with a sign-in page, go back to the email and look at the email sender including their domain and look at the URL of the link you clicked very carefully.
    3. Never download an attachment in an email and open it unless you verify the sender. Even then, considering asking your sender to use a service like Google Docs that doesn’t require you to download attachments.

    2. Get rid of browser extensions you don’t need

    Lesson two is that browser extensions sometimes get hacked. When they do, it can be a catastrophe for you. If you don’t absolutely have to have a browser extension, get rid of it.

    Alternatively, deactivate extensions until you need them. Then activate them, use the extension and deactivate it again. This isn’t ideal, but it will reduce your risk if an extension is compromised for a few days.

    That screenshot utility? If you don’t use it daily, dump it. That quote-of-the-day extension? Ditch it if you don’t need it.

    In 2010, Chrome hit 10,000 extensions. Today, 7 years later, they probably have well over 100,000 extensions available for the Chrome browser. That many extensions create a large attack surface for malicious actors. Make sure you minimize your risk by removing those you don’t use.

    Supply Chain Attacks on the Rise

    The NotPetya ransomware attacks we reported on recently started with an accounting firm in Ukraine, a company called M.E. Doc, having their software distribution system compromised. This allowed an attacker to distribute ransomware out to customers of M.E. Doc.

    This kind of attack is known as a supply chain attack – when an attacker targets an upstream provider of hardware or software, compromises their systems, and infects their customers.

    This attack on the developers of Chrome Extensions is another example of a supply chain attack in action.

    If you are a developer, it is important to be aware that as these attacks become more popular, you are more likely to be targeted because you are a gateway to infecting a much larger group of people: your customers.

    Attacks targeting site owners are also a supply chain attack. You supply your large audience with content. By controlling your website and serving up a browser exploit, an attacker can take control of a large number of workstations in a single attack.

    As site owners it is our responsibility to be more cautious than most when it comes to our security. We have an obligation to our customers and site visitors to stay secure.

    Sources

    Thanks to Risky Biz and Pat Gray who alerted me to this attack on his podcast this morning. We’re a sponsor of Risky Biz which is an awesome security podcast that I highly recommend you subscribe to if you are in the security industry.

    Also thanks to Catalin Cimpanu over at Bleeping Computer who reported on this yesterday. As always doing a great job.

    And then Kafeine at Proofpoint has covered this story in detail. I have borrowed images in the post above from Proofpoint, so thanks to them for that and the excellent research.

    And PhishMe has written about how the Chrome Extension authors were phished. (Nice booth at Black Hat guys! We paid you a visit while our team was there last month.)

    Share To Help Secure Our Community

    If you are a website owner, please share this public service announcement with your community to help create awareness of these kinds of supply chain attacks that target developers and website owners.

    The post PSA: 4.8 Million Affected by Chrome Extension Attacks Targeting Site Owners appeared first on Wordfence.