Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

November 27th, 2012, 12:54 GMT · By

BLOG

Piwik.org Hacked, Attacker Adds Malicious Code to Installation Files

SHARE:

Adjust text size:


Piwik.org hacked Enlarge picture - Piwik.org hacked
Piwik.org, the official website of the free software web analytics system for PHP/MySQL webservers, has been hacked. The attacker planted a piece of malicious code inside the .zip file containing Piwik 1.9.2.

According to Piwik representatives, the incident affects only users who updated or installed Piwik 1.9.2 on November 26, between 15:43 UTC and 23:59 UTC.

Customers who believe they might be impacted are advised to check for a piece of malicious code at the end of the Loader.php file located in the Core directory. If the code is present, they must back up config.ini.php, delete the Piwik directory, and download a clean version from piwik.org.

Apparently, the hacker has gained access to the company’s servers by leveraging a vulnerability in a WordPress plugin.

“The website Piwik.org is running WordPress and got compromised, because of a security issue in a WordPress plugin. As far as we know, the Piwik software does not have any exploitable security issue,” the Piwik team wrote.

Fortunately, since the website doesn’t track any web analytics data from users, no personal or sensitive data has been obtained by the attacker.

Piwik is currently working on implementing new mechanisms to avoid such incidents from occurring in the future.

The web analytics system is currently utilized by over 320,000 websites. It's preferred by many webmasters because of its privacy features and the control it offers over the analytics data.

Piwik is available for download here
FILED UNDER:
hacked
incident
Piwik

TELL US WHAT YOU THINK:

1,990 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Nationwide Hacked, Customer Details Compromised

BitSoup Hacked, Attackers Claim They’ve Alerted Authorities of Wrongdoings

Faulty CSS Leads Users to Believe Kaspersky Site Was Hacked

Details of 700 Students Leaked from Syrian Virtual University

Pakistani Google, Yahoo!, Apple, eBay, PayPal Sites Hacked (Updated)

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM