Skip to main content

Attackers Tried To Grab WordPress Configuration Files From Over a Million Sites

What is a WordPress website?

The WordPress website is any website that uses WordPress as its CMS (content management system). WordPress enables both the back of the website (the interface where the user logs in to make changes or add new content) and the frontend (the visible part of the website your visitors see on the web).

Wordpress Blogging Website - Free image on PixabayHere are a few examples of the types of websites you can build with WordPress:

    Blog - A blog is a special kind of website dedicated to sharing ideas, photos, reviews, tutorials, recipes and much more. Blogs usually feature newly published content.
    E-commerce Website - An e-commerce website allows you to sell goods or services online and collect payments through an online payment system. You can download and install the WordPress e-commerce plugin to extend the default functionality of WordPress to have an online store on your website.
 
1-    Business website - Many businesses will benefit from having an online presence in the form of their website. If your business needs a website for customers to learn about your company and what to offer, WordPress is a great option. Customers can contact you, request a discount, arrange an appointment and much more.
  
2-  Membership Website - The membership website allows you to place content behind paywall or account login. To access pages or posts, users must sign in or pay for content. WordPress can also manage affiliate websites with additional plugins.
  
3-  Portfolio website - Showcase your art, design skills and more with a portfolio website built into WordPress.
  
4-  Forum website - The forum website can be a useful place for users to ask questions or share advice. Believe it or not, most forum websites work on WordPress.
  
5-  Event Website - Hosting the event? WordPress makes it easy for you to share your event details and sell tickets.
  
6-  E-learning website - Students can take online courses, track their progress, download resources and much more from the e-learning website. With a special type of plugin called WordPress LMS plugin, you can offer online tutorials from the WordPress website.
  
7-  Wedding Website - Share the details of your big day with a wedding website built into WordPress. With a variety of WordPress wedding themes, you can find a website quickly and easily.


The new campaign is to exploit similar information addresses, targeting most of the attacks and targeted sites. The campaign also attacks approximately 1,000,000 new sites that were not included in previous XSS campaigns, ”said Wordfence analyst Ram Gall.


The purpose of this latest campaign was to download a WP-config-PHP file, which contains information, meeting details, verification keys and salt.


"A hacker with access to the current file can gain access to site information, wherever the website's content and users store it," Gall said above.

He did not say that plugins and themes were invaded by the attackers, but it does say that almost all of the threats became themes or plugins designed to allow file downloads by reading the contents of the requested file with an excessive thread and popping up as a downloadable attachment.


Comments

Popular posts from this blog

Netwalker Goes After College of Nurses' Data in Ontario

T he cybercrime Netwalker team is guilty of extracting information from the Ontario Nursing College on ransomware attacks. A screenshot of information allegedly removed by the school has been posted on the Netwalker site, where the name of the school has been added to the number of injured people in the group. In a heated statement released yesterday, the school saw that it was affected by network security but did not indicate what had happened. The proclamation reads: "The College of the Nurses of Ontario (CNO) is currently pursuing normal operations following a network security incident. With the never-ending release of this episode on September 8, CNO found a way to prevent this incident and took over network protection. in a far-reaching legal examination. " As a result of this episode, the various administrations provided by the CNO are not easily accessible, including the public Register Find a Nurse, the Nursing Rehabilitation Center and the entrance gate. The CNO sai...

6 new Google Chrome flaws allow remote phone hacking | | Update Chrome or use BRAVE Browser

Cybersecurity experts have revealed the discovery of six security issues in Google Chrome, one of the world's most popular Internet browsers. Successful exploitation of these traits can create many vicious situations. Below is a brief description of the reported vulnerabilities, in addition to their scores and tracking keys according to the Common Vulnerability Scoring System (CVSS). CVE-2020-6493: This is a back-end risk that exists due to an error in the Google Chrome Web authentication feature.  A threatening actor can redirect victims to a malicious website to help them become vulnerable and create a code of opposition to the program. This error scored 7.7/10, so it is considered a serious difficulty. CVE-2020-6494: This risk exists due to insufficient confirmation of user inclusion in the Google Chrome payment item. Threatening actors can create a specially designed website, trick the victim into visiting it and lying about its contents. This is a very serious mistake, as it s...

Google deletes Indian App that Deletes Chinese Apps

  Google has deleted associate app from the Play Store that offered to delete mechanical man computer code related to China. The app, created by Jaipur, India-based developer One bit AppLabs , purported to scan mechanical man phones for any apps with links to China. It used marketing research to spot apps from a named list and would then supply users the prospect to wipe them from the user’s phone. Demos found on-line showed it deleting TikTok, the favored electronic communication app owned by Chinese developer ByteDance, and UC Browser, developed by Alibaba-owned UCWeb . It additionally additionally reportedly deleted the app for the Zoom videoconferencing service, that the Munk School’s subject workplace discovered was causation secret writing keys to Chinese servers.   Remove China Apps, an app that has been popular in India in recent weeks and does exactly what its name implies, has been removed from the Play Store. The best app in India, downloaded more th...