1Likes -
1 Post By Raymond
-
The Specialist *
WordPress plugins Trojanised, spotted, fixed !!!!
WordPress just announced that the source code of three plugins for its popular blog-hosting software was maliciously modified. Plugins consist of add-in modules which you install on your WordPress server in order to implement additional functionality, instead of writing all the needed code yourself.
Where you might use a DLL with a Windows program - for example, to add a feature such as SSL support or an edit control into an existing application - you'd use a plugin with WordPress.
DLLs are usually written in a language such as C or C++ and compiled into native machine code; WordPress plugins are generally written in a mixture of JavaScript, PHP, HTML and CSS.
According to WordPress, the modified plugins were Trojanised to include backdoors. this attack doesn't affect you or your users unless:
* You run your own installation of the WordPress platform.
* You use one of these plugins: AddThis, WPtouch, or W3 Total Cache.
* You updated your installed copy of one of those plugins in the past 48 hours from wordpress.org. More & Source
.
I don't need to know everything, I just need to know where to find it, when I need it. 
-
Experienced User
Love me , Hate me but you just can't Ignore me 
-
The Specialist *
No prob
.
-
Administrator
This is indeed scary since W3 Total Cache was recently updated around the time when it was trojanised.
I redownloaded the package and compared byte to byte, fortunately not affected.
-
The Specialist *
Similar Threads
-
By INDRANIL in forum Spyware/Viruses
Replies: 10
Last Post: 09-12-2011, 11:17 AM
-
By Mark in forum General Forum
Replies: 11
Last Post: 02-10-2009, 07:34 AM
Tags for this Thread
All times are GMT +8. The time now is 09:49 AM.