Online Services

Category: Security

  • SQL Injection Vulnerability in Ninja Forms

    SQL Injection Vulnerability in Ninja Forms

    As part of our regular research audits for our Sucuri Firewall, we discovered an SQL Injection vulnerability affecting the Ninja Forms plugin for WordPress, currently installed on 600,000+ websites. Vulnerability Disclosure Timeline: August 11th 9:35 am, 2016 – Initial report to the Ninja Forms team August 11th 2:49 pm, 2016 – Public release of version…

    The post SQL Injection Vulnerability in Ninja Forms appeared first on Sucuri Blog.

  • 404 to 301 Plugin Considered Harmful

    404 to 301 Plugin Considered Harmful

    Yesterday we received a site cleaning request where one of our customers was seeing spammy links, Payday Loans in this case, injected into their WordPress website page content. The links were only appearing when the site was visited by a search engine crawler. This is common when a site has been hacked.

    An extract from the customer communication with personal info removed:

    We look after a clients website [website removed] and believe that has been compromised.

    Specifically, the issue is that when google or bing’s search bots crawl the site, they see some text injected into the top of the homepage. I have been using a user agent switcher to verify it’s presence but it was first spotted when we did a pagespeed test here: [removed] and it showed in their ‘preview’ screengrab on the desktop view.

    This text seems isn’t always present and when it is there it’s only on the home url (not actually the page eg. if you visit [page removed] it doesn’t appear).

    [snip]

    For reference, the block of injected text appears under the site header (navigation etc.) and also in the body of our exit-intent popup:

    Make Ends Meet With Payday Loans

    It is often very easy to face any financial emergency if you have adequate money to pay for them. But, this can seem all too impossible if you often live from one paycheck to another. How will you be able to pay for your urgent financial emergencies? Most often than not, you can’t. Face the reality, when your job is unable to pay for your financial emergencies, it is best to turn to payday loan providers out there.

    [rest of content removed including link to payday loans site]

    Screen Shot 2016-08-16 at 10.59.59 AMIt turns out that this is not a hacked site. It is content that is injected by a plugin called 404 to 301 plugin which has 70,000 active installs and has a 4.5 star review from 56 reviewers. When you install the plugin it asks you to agree to a long agreement which includes parts of the GNU general public license. But at the end it also includes the following text (you have to scroll down to find it):

     

    Third Party Text Links

    Third party text networks supply text for display in 404 to 301. These networks may collect your visitors’ IP addresses, in native or hashed forms, for purposes of controlling the distribution of text links. 404 to 301 collects anonymous aggregated usage statistics.

    By clicking the button here below, you agree to the terms and conditions and give permission to place text links on your website when search engine crawlers access it. Your website’s layout, performance and interaction with human visitors should not be altered or affected in any way. Please note that this feature can be deactivated at any time under 404 to 301 Setting > Help & Info > Plugin Information > Disable UAN, without affecting any other feature available in 404 to 301.

    404 to 301 – Copyright © 2016.

    I’m reasonably sure that no sane webmaster would agree to:

    1. Cloaking, which is specifically banned by Google and will result in a search engine penalty.
    2. Allowing ads to be inserted into their site over which they have no editorial control, including PayDay loan ads.

    We are contacting the WordPress plugin repository maintainers who will likely remove the plugin by the time you read this post. Now that you’re fully informed, we suggest you make up your own mind about whether or not you want to keep this plugin installed if you have it on your site.

    As always we welcome your comments. Please note: We have disabled comments on this post due to the inflammatory nature of some of the comments we’re receiving.

    All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement.

    The post 404 to 301 Plugin Considered Harmful appeared first on Wordfence.

  • Analyzing and Cleaning Hijacked Google SEO Spam Results

    Analyzing and Cleaning Hijacked Google SEO Spam Results

    Blackhat SEO spam comes in many forms, and one of the most nefarious is hijacked search results. This happens when search engines crawl and display unwanted content in the title and description of infected web pages. The negative impact to the infected website cannot be understated. This harms the website’s reputation with visitors and will…

    The post Analyzing and Cleaning Hijacked Google SEO Spam Results appeared first on Sucuri Blog.

  • This Week’s Top 20 Attacked Themes and Who is Attacking Them

    This Week’s Top 20 Attacked Themes and Who is Attacking Them

    Today we’re publishing statistics on the attacks we are seeing on themes across the WordPress ecosystem. The Wordfence Firewall provides us with attack telemetry across a large number of sites that we protect. The data we’re sharing today is based on the following high level metrics:

    • An analysis of 15,949,826 total attacks across the past 7 days – from Monday August 1st to Monday August 8th (yesterday) on sites that Wordfence protects.
    • Attacks on 519,592 unique Wordfence customer websites.
    • Attacks originating from a total of 72,896 unique IPs. 

    The “Theme Slug” below is a term used in WordPress parlance. It refers to the unique directory name that is created in the wp-content/themes/ directory for the theme when it is installed. This uniquely identifies themes in the WordPress ecosystem. To find out more about the theme, simply Google the ‘slug’.

    The table shows the total attacks we recorded on that theme across all sites, the number of IPs that launched an attack on the theme and the number of unique sites that we recorded attacks for that targeted that theme. To be clear, that is not the number of sites actually running the theme. It’s simply the number of sites where someone tried to attack the theme, whether it was installed or not.

    We explain why most of these themes are being attacked and what the “Bulk Disclosed” column means below the table.

    Theme Slug Total attacks Unique IPs attacking Unique sites attacked Vulnerability Type Bulk Disclosed
    churchope 172,782 2,055 63,115 LFI X
    mTheme-Unus 163,644 2,303 90,803  LFI
    lote27 135,948 1,922 60,638 LFI X
    SMWF 121,725 1,466 85,228 LFI X
    markant 118,962 1,399 83,418 LFI X
    felis 118,437 1,431 81,800 LFI X
    MichaelCanthony 114,503 1,389 79,059 LFI X
    TheLoft 113,990 1,387 78,644 LFI X
    parallelus-mingle 105,648 1,568 54,279  LFI
    urbancity 96,810 1,678 56,952 LFI X
    trinity 89,603 1,410 52,326 LFI X
    authentic 82,692 1,817 37,312 LFI X
    parallelus-salutation 73,025 1,628 35,886  LFI
    elegance 68,928 1,009 21,726  LFI
    awake 68,424 1,031 21,323  LFI
    antioch 63,174 1,365 26,243 LFI X
    modular 62,470 990 19,770 LFI
    epic 53,903 925 17,400 LFI X
    infocus 52,739 989 19,942  LFI
    Newspapertimes_1 50,707 943 29,297  LFI

     

    Who is attacking these themes?

    Back in December, 2014 a researcher bulk disclosed a large number of WordPress theme vulnerabilities. The disclosure includes a script that targets a single site and tries to exploit vulnerabilities in a large number of themes. The vulnerabilities it tries to exploit are all file inclusion vulnerabilities.

    In the comments at the top of the script that was disclosed, the researcher also includes an example of how to use the script with the powerful INURLBR scanner which he also wrote. This allows attackers and presumably other researchers to bulk find and exploit WordPress sites by trying to exploit the theme vulnerabilities disclosed.

    This is the example included in the disclosure:

    ./inurlbr.php --dork 'inurl:/wp-content/themes/' -q 1,6 -s save.txt 
    
       --comand-all "php exploit.php _TARGET_"

    In the statistics we’ve released above, all the themes marked with an X are included in the bulk disclosure that was made and which included the inurlbr exploit example. So we think what is happening is that so called “script kiddies” (unsophisticated hackers) are grabbing the researcher’s original example from December 2014 and trying to exploit old vulnerabilities in themes.

    All these exploits are being blocked by the Wordfence firewall. It’s also likely that many, possibly all of the themes have now fixed this vulnerability, although we recommend that if you use any of these themes you verify with your vendor that your current version contains no vulnerabilities.

    The INURLBR scanner has evolved since it was first released in July 2014 into a powerful tool that allows attackers to bulk locate and exploit WordPress websites and sites using other CMSs. The scanner includes:

    • Support for a huge range of search engines to “Google dork” and find targets for attack.
    • Bulk exploiting of targets once found.
    • The ability to use proxies to hide where queries and exploits are coming from.
    • The ability to rotate proxies to constantly change IP.
    • Ability to hide behind Tor.
    • It can send vulnerable sites to an IRC channel, presumably for botnet integration.
    • It includes many other features like regex matching/extraction and more.

    It’s possible that many users of INURLBR are using the original bulk disclosure to test INURLBR before launching more sophisticated attacks. That may explain why those original themes are dominating our top 20 list of exploited themes.

    At Wordfence we constantly mine attack data to discover how to better protect our customers. Upgrade to Wordfence Premium today to receive real-time firewall rule updates, premium support and much more.

    We encourage you to comment and share this data with the larger WordPress community.

    The post This Week’s Top 20 Attacked Themes and Who is Attacking Them appeared first on Wordfence.