How botnets are created with hijacked Worpess, fake Flash downloads and Node.js
betamode.de
betamode.de
We have automated scanning systems for suspicious code commits. If they occur, me and a few others get an email for manual review of the problem. Additionally, many others get every commit and set up their own scanning tools to see what's happening, as it happens.
When something-bad™ happens, then we can close a plugin (block it from being downloaded or found in searches), revert changes or otherwise manually adjust any aspect of the plugin, and if necessary, push updates for it to any WordPress installs that have it.
Realistically, bad actors are not generally a problem for the plugins system. I can count on one hand the number of times this has occurred to the point where we'd need to actually push code. The real problem we're fighting is accidental security issues. While WordPress core is quite secure, plugins have much less eyes on the problem, and a lot of plugin developers are relatively new coders. Things like simple SQL injections still pop up from time to time in plugins, and that's a big problem.
So, the security issues with with plugins repository is not really about some malicious person out there. Malicious people tend to be dumb spammers. They're easy to spot and protect against, because they're only after the low hanging fruit. What we mostly try to find are the things that good coding practices would protect against, because not everybody uses good coding practices. Those tend to be harder to scan for on an automatic basis.
Btw: still wearing my Torbit shirt sometimes ;)
And awesome! Really happy to hear you're still enjoying your Torbit shirt.
I have almost 500k plugin installs, I'd sell my plugin for that amount if I knew it was going to a legit company!
If you don't have a paid plan, at least run the free scan once a month or more to make sure you weren't hit by anything. I don't mind Wordpress as a CMS, but it is a constant target. Constant. And nothing looks worse than having "Cheap Canadian Viagra" at the bottom of your corporate website.
On top of the security plugin, I added an .htaccess rule to only allow access to the admin login and the entire wp-admin subfolder from within their office. They have a static IP and were OK with only having access from within the office so this worked well for them. This pretty much ended all of the attacks. I probably wouldn't rely on this as the only protection, but it definitely has been a great piece of their overall security plan. The code to do that is here:
It was stopping the attacks - it was just that the attacker would try 10 password attempts, then get blocked by the plugin and trigger the alert message. Then the attacker would switch IPs and try 10 more. One morning they had gotten a ton of messages and I found about 250k login attempts in the security logs. So the plugin was doing it's job, but it's better now that the attacks don't even make it that far. In fact you can't even hit a page within the wp-admin folder which is nice in case some type of zero-day exploit surfaces on a file within that area.
Apache:
# Allow access to wp-admin/admin-ajax.php
<Files admin-ajax.php>
Order allow,deny
Allow from all
Satisfy any
</Files>
Nginx: location /wp-admin/admin-ajax.php {
allow all;
}Moral of the story, don't rely on just a plugin, or a tutorial for your WP security.
Do you have any samples? One of the biggest reasons for this is if it's endpoint malware, versus website malware. Two very different things as you might know. Regardless, would love some samples if you any.
Tony
@perezbox - you might want to mention that in your HN Profile. :)
(Obviously asking for my former employer... the haven't understood or fixed the problem yet.)
At least the pages I looked today at aren't recognized by this external tool. Only green checkmarks, also the "List of scripts included" doesn't see the 2 scripts added dynamically by the injected code in the post.
The Wordpress plugin would probably do a better job.
Can we get a list of the domains you scanned that weren't recognized?
Thanks
What you're referring to is Conditional Malware. We actually do very well with that, but there are no 100% solutions. There are also things that are hard, like Defacements and environments used for Phishing Lures..
All great points
Seems like there is lots of potential for blackhat SEO with this type of botnet.
I agree that it does seem like quite a bit of effort for an undetermined purpose though...
Almost all of the compromised accounts I've dealt with over the years were the result of outdated WordPress or plugin installs, where an exploit was used to upload a file to one of the commonly known writeable directories: plugins, uploads, or themes.
Most of those cases could have been prevented if the owner would have kept their installs up to date, which makes these issues so frustrating to deal with.