Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Advisories

May 18th, 2012, 08:38 GMT · By

Spammers Promote Fake Luxury Goods on Hijacked Joomla and WordPress Sites

SHARE:

Adjust text size:

Fake luxury goods
Enlarge picture
Security experts have found that a number of compromised WordPress and Joomla websites are used by spammers to advertise shady slimming pills and counterfeit luxury goods. The worst part is that the owners of these sites are most likely unaware of what’s going on.

Webmasters often fail to check their websites’ subdirectories for signs of malicious files and webpages, thus allowing cybercriminals to use the domain’s reputation to host their scams, Unmask Parasites reports.

Attackers often brute-force the admin passwords to gain access to a website’s backend. Once they’ve gained access, they inject a web shell into an existing plugin by utilizing the Theme Editor.

The web shell is leveraged to create a subfolder to which a WordPress installation package is uploaded. After obtaining the MySQL credentials from the wp-config.php or configuration.php files, depending on whether the site is Joomla or WordPress-based, the attacker is able to install his own theme and make a fully operational website.

These sites actually represent “doorways” that point unsuspecting visitors to malicious domains.

Experts discovered around 3,000 compromised websites that stored such doorway blogs. Reportedly, some of the blogs that advertise slimming and luxury goods were created in March 2012, but there were a few created a year ago.

Even more worrying is the fact that the hijacked sites don’t host only such doorway blogs, but also phishing pages that try to dupe internauts into handing over their online banking credentials and other sensitive information.

Webmasters are advised to keep in mind that their assets can always tempt cybercriminals and that’s why they must follow a number of basic rules to prevent unfortunate situations.

First of all, they must ensure that their systems are guarded by strong passwords that can’t be cracked by using brute-force attacks. Secondly, any changes made to the file system must be carefully monitored.

Google can also help to identify malicious third-party pages since usually they’re indexed, making them visible in simple searches. Google Webmaster Tools can also come in handy, since it can easily reveal if a shady-looking webpage records a lot of traffic.


1,979 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


High-Ranked Sites Blacklisted by Google After Being Hijacked

Notepad++ Site Compromised, Attackers Try to Steal Facebook Credentials

AVG Detects JavaScript Obfuscation on Panasonic Australia Blog (Updated)

Phishers to Hotmail Users: Your Account Has Been Blocked

Amnesty International UK Site Hijacked, Serves Ghost RAT

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM