Thousands of WordPress sites sucked into BlackHole

Researchers have discovered a spike in malware infecting thousands of WordPress websites that use a popular image tool.

The attacks came to light after French media outlet, The Poitou-Charentes Journal, began hosting on malicious code on its WordPress site.

Avast senior researcher Jan Sirmer found attackers had exploited weak FTP server authentication credentials and a vulnerability in the TimThumb image resizer to upload malicious PHP files to the site.

The attack used the BlackHole exploit kit, which redirected the website's visitors to an external malware-hosting site.

Researchers detected an additional 3,500 unique infected WordPress sites, which redirected visitors to malicious sites between Aug. 28 to 31. During September , the company blocked redirects from 2,515 WordPress sites, Sirmer said.

In total, some 151,000 users had been hit with the malicious redirect from other compromised WordPress sites.

"I expect October results will be similar,” Sirmer said. “The Poitou-Charentes Journal is just one part of a much bigger attack. These compromised sites are part of a network which redirected vulnerable users to sites distributing an array of malware.”

The vulnerability in the TimThumb resizer, identified in August, exists in the way the tool fetches images from websites like Flickr and Photobucket.

The utility runs only a partial check on hostnames, meaning hackers can upload and execute arbitrary code in the .php cache directory.

Sirmer recommended WordPress sites employ strong login credentials.

A fix is available for the TimThumb tool.

From: SC Magazine Australia

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.