NewStats: 3,261,951 , 8,175,633 topics. Date: Saturday, 31 May 2025 at 08:31 AM 3h111p

6z3e3g

Eben2marketer's Posts 1q5eu

Eben2marketer's Posts

(1) (3) (of 3 pages)

eben2marketer: 1:50pm On Sep 03, 2019
angry

2 Likes 1 Share

eben2marketer: 1:48pm On Sep 03, 2019
cheesy

1 Like 1 Share

eben2marketer: 1:44pm On Sep 03, 2019
cool

1 Like 1 Share

eben2marketer: 8:37pm On Sep 02, 2019
cool

1 Like 1 Share

eben2marketer: 5:00pm On Sep 02, 2019
grin
eben2marketer: 9:17am On Sep 02, 2019
cool
eben2marketer: 9:16am On Sep 02, 2019
A website hacking campaign, that has been ongoing since July, has morphed from redirecting browsers to sites containing dodgy adverts or malicious software into something that is potentially even more problematical. Mikey Veenstra, a researcher with the Defiant Threat Intelligence team, said that “the campaign has added another script which attempts to install a backdoor into the target site by exploiting an ’s session.”


In a warning posted to the WordFence security blog on August 30, Veenstra revealed that a malicious JavaScript dropped into compromised websites looks to “create a new with privileges on the victim’s site.” If a logged-in is identified as viewing the infected page, it then goes on to make an AJAX call via jQuery, one that creates a rogue .

“This AJAX call creates a named wpservices with the email [email protected] and the w0rdpr3ss,” Veenstra said, “with this in place, the attacker is free to install further backdoors or perform other malicious activity.”

Meanwhile, Veenstra stated that the plugins that are under attack currently had been identified as follows:

Bold Page Builder

Blog Designer

Live Chat with Facebook Messenger

Yuzo Related Posts

Visual CSS Style Editor


WP Live Chat

Form Lightbox

Hybrid Composer

All former NicDark plugins (nd-booking, nd-travel, nd-learning)

If you are a WordPress-powered website owner using any of these plugins, then you are advised to check you have the latest updated versions. Follow the links above to check on update status, as most of these have already been patched. However, Veenstra warned that “it’s reasonable to assume any unauthenticated XSS or options update vulnerabilities disclosed in the near future will be quickly targeted by this threat actor.”

Source: https://www.forbes.com/sites/daveywinder/2019/08/31/critical-backdoor-attack-warning-issued-for-60-million-wordpress-s/amp/

eben2marketer: 1:11pm On Sep 01, 2019
cheesy

1 Like 1 Share

eben2marketer: 6:07am On Sep 01, 2019
cool

1 Like 1 Share

eben2marketer: 3:02pm On Aug 31, 2019
eben2marketer: 11:57am On Aug 31, 2019
cheesy
eben2marketer: 11:30am On Aug 31, 2019
cheesy

1 Like 1 Share

eben2marketer: 7:19am On Aug 31, 2019
cool

1 Like 1 Share

eben2marketer: 8:57am On Aug 30, 2019
grin

1 Like 1 Share

eben2marketer: 4:45pm On Aug 29, 2019
shocked

1 Like 1 Share

eben2marketer: 3:45pm On Aug 29, 2019
shocked

1 Like 1 Share

eben2marketer: 3:33pm On Aug 29, 2019
shocked

1 Like 1 Share

eben2marketer: 1:07pm On Aug 29, 2019
grin

1 Like 1 Share

eben2marketer: 12:52pm On Aug 29, 2019
cool
eben2marketer: 12:52pm On Aug 29, 2019
grin

1 Like 1 Share

eben2marketer: 12:04pm On Aug 29, 2019
grin
eben2marketer: 10:03am On Aug 29, 2019
cool

1 Like 1 Share

eben2marketer: 3:22pm On Aug 28, 2019
shocked

1 Like 1 Share

(1) (3) (of 3 pages)

(Go Up)

Sections: How To . 11
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or s on Nairaland.