By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
DIGITAL TRENDDIGITAL TREND
  • Tech Updates
  • Featured
  • Course
  • Tutorial
  • News
  • Technology
  • Mobiles
  • Spotrs
Search
© 2023 digitaltrend.in Company. All Rights Reserved.
Reading: Abandoned plugin is used to silently attack WordPress sites – DIGITALTREND
Share
Notification Show More
Latest News
Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND
07/06/2023
Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND
07/06/2023
iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND
06/06/2023
Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND
06/06/2023
iPad 10th generation 64 GB has almost R$ 1 thousand off on offer – DIGITALTREND
06/06/2023
Aa
DIGITAL TRENDDIGITAL TREND
Aa
  • Tech Updates
  • Mobiles
  • Programming
  • Hacking
  • Featured
  • Technology
  • Tools
  • About Us
  • Contact Us
  • Terms And Conditions
Search
  • Tech Updates
  • Mobiles
  • Programming
  • Hacking
  • Featured
  • Technology
  • Tools
  • About Us
  • Contact Us
  • Terms And Conditions
© 2022 digitaltrend.in Company. All Rights Reserved.
Join Whatsapp Group To get Daily Update.
DIGITAL TREND > Blog > Apps And Software > Abandoned plugin is used to silently attack WordPress sites – DIGITALTREND
Apps And Software

Abandoned plugin is used to silently attack WordPress sites – DIGITALTREND

SUPERMAN♥
SUPERMAN♥ 21/04/2023
Updated 2023/04/21 at 10:35 PM
Share
4 Min Read
SHARE


To the best deals,
no tail stuck

Contents
silent invasionSecurity measures

The advice that we should be wary of old or abandoned software is not far-fetched. Recent evidence of this comes from the Eval PHP. This is the name of a plugin for wordpress which hasn’t been updated since 2012 and is now being used to compromise websites.

Eval PHP compromises WordPress security (illustrative image: Vitor Pádua/DIGITALTREND)
Eval PHP compromises WordPress security (illustrative image: Vitor Pádua/DIGITALTREND)

Eval PHP allows a WordPress site administrator to add PHP code directly to pages or posts. The feature can be used to test functions or offer functionality to website visitors.

Because it is an old plugin and used for a very specific purpose, Eval PHP is little used today. But the digital security company anaconda noticed that, in recent weeks, several sites were being infected with a backdoor whose code is related to the plugin.

Sucuri found that at the end of March, Eval PHP reached a daily peak of 7,000 downloads. Prior to this, the plugin rarely recorded a single download per day. The company estimates that since then more than 100,000 downloads have been made.

silent invasion

Eval PHP didn’t become popular overnight. The number of downloads has skyrocketed simply because it comes unused by attackers, not site administrators.

It all starts when the attacker inserts malicious code into the “wp_posts” table in the WordPress database. For this, it uses a compromised administrator account, which is also used for the plugin to be installed.

Through the plugin, the code is injected into WordPress pages or posts. It is then enough for the attacker to access these links for the code to be executed. When this occurs, the backdoor is inserted into the root of the website.

Various malicious actions can be performed from there, such as spreading malware, capturing data and attacking other websites.

To prevent compromised pages and posts from being discovered, attackers save them as drafts. Thus, the links do not appear on the site’s public content list.

What makes this whole scheme different from other types of intrusions is that, as the malicious code is executed thanks to Eval PHP, it is more difficult for security mechanisms to track it.

To make matters worse, if the backdoor is removed, it can be inserted into the site again after simply accessing one of the compromised pages or posts.

Eval PHP has not been updated for over ten years (image: reproduction/Sucuri)
Eval PHP has not been updated for over ten years (image: reproduction/Sucuri)

Security measures

Avoiding the use of outdated software (here, plugins) is one of the ways to prevent intrusions. If Eval PHP was maintained, its maintainers would certainly find ways to prevent the plugin from being used to execute malicious code.

As in the case in question the plugin is installed by the attacker, not by the user, it would be up to the maintainers of the WordPress repositories to adopt preventive measures. On the other hand, it is difficult for them to monitor such a huge universe of plugins.

This is why supplementary measures must be taken by website administrators. Sucuri recommends:

  • keep the website resources up to date;
  • protect the WordPress admin panel with two-factor authentication to prevent unauthorized access;
  • have a regular backup service;
  • use firewalls to block bots and mitigate known vulnerabilities.

PHPpluginWordPress

You Might Also Like

Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND

Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND

iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND

Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND

iPad 10th generation 64 GB has almost R$ 1 thousand off on offer – DIGITALTREND

TAGGED: Abandoned, attack, DIGITALTREND, plugin, silently, sites, WordPress

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
SUPERMAN♥ 21/04/2023
Share this Article
Facebook TwitterEmail Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article DeepMind will help Google in the race against OpenAI for the future of AI – DIGITALTREND
Next Article WhatsApp announces function that saves temporary messages, if you let it – DIGITALTREND

Stay Connected

235.3k Followers Like
69.1k Followers Follow
11.6k Followers Pin
56.4k Followers Follow
136k Subscribers Subscribe
4.4k Followers Follow

Latest News

Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND
Apps And Software 07/06/2023
Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND
Artificial intelligence 07/06/2023
iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND
Artificial intelligence 06/06/2023
Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND
Artificial intelligence 06/06/2023

You Might also Like

Apps And Software

Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND

07/06/2023
Artificial intelligence

Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND

07/06/2023
Artificial intelligence

iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND

06/06/2023
Artificial intelligence

Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND

06/06/2023
//

We influence 20 million users and is the number one business and technology news network on the planet

DIGITAL TRENDDIGITAL TREND

© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.

Removed from reading list

Undo
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?