Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > WordPress 2.3.3 Invaded by Wily JavaScript

    Scores of reports flooded the Internet about WordPress 2.3.3 being hacked and exploited by a certain automated JavaScript (JS) that led users to links to various sites, which also contain the script.

    WordPress users and visitors reported to have encountered a phishing attempt (a wily one, too) wherein users were prompted to register to the blog first as a requirement before they could leave a comment. Note though that most of these sites do not require any registration. And such sites with open registration in their WordPress blogs were very much vulnerable as these are purported to be the very target of this exploit.

    Once the vulnerability has been exploited, the script then creates the folder named 1 in the users wp-contents folder. This script then populates the created folder with a list of various spammy Web page links that are mostly related to adult sites and gambling sites. The page links were found to contain the JS script, as well.

    In this blog post, the author made an analogy on the g.js script file, which was common to all affected pages. The body of the said .JS code contained the following strings:

    G.JS Code
    Figure 1

    Upon closer inspection, one can easily make out the Web site address http://www.preservesitecolorado.org. As of this writing, the site looked bare (see Figure 2), unlike the one described in the blog where the site showed a brief overview about the company/organization and contact information. PreserveSiteColorado.Org was purported to be hosted in China (1)(2)(3)(4)(5).

    PreserveSiteColorado.Org Web Site
    Figure 2

    Hackers also flooded affected pages with links pointing to other infected sites in the comments section of the blog, consequently defacing the page itself. Below is a screenshot sample of the said defacement:

    Screenshot of Defaced site due to Comment Spamming
    Figure 3

    I attempted to search for affected pages myself with Google using the search string inurl:wp-content/1/ (see Figure 4). To date, there are now 21,800 pages purportedly affected by the exploit. If using the search string allinurl:wp-content/1 (see Figure 5), there are now 22,500 pages…and possibly rising. Note also that Google does not flag these pages as something that could potentially harm a system. Though that is the case, not clicking on any of them is still the wise course of action.

    Google Index Results for [inurl:wp-content/1/]
    Figure 4

    Google Index Results for [allinurl:wp-content/1]
    Figure 5

    As of this writing, a fix for this vulnerability has yet to be issued by WordPress. (You may, however, find this and this useful.) As a workaround, users may want to close their registration feature. Also, be wary of third-party plug-ins you install in your blog sites.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    3 Responses to “WordPress 2.3.3 Invaded by Wily JavaScript”

    Trackbacks

    1. » Wordpress 2.5 is here, hurry to upgrade!!!! » Xavier Media Blog
    2. » Wordpress 2.5 is out, upgrade today! » The Antivirus blog
    3. j4f::logs - Wordpress2.5へアップグレードした


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice