In the course of what was referred to as a program cleanup investigation, researchers at Sucuri uncovered that hackers have been exploiting a PHP script in a high quality WordPress topic to deliver spam. “While many themes include electronic mail operation, this specific one particular was troublesome since the script was penned without the need of any stability checks or immediate entry prevention,” Sucuri Remediation Group Lead Rodrigo Escobar wrote in a site. “Without the right stability capabilities in place, this script can conveniently be exploited to abuse options and deliver mass electronic mail spam.” The script, which employs facts from Post parameters to deliver electronic mail and is made to perform in the topic, can stand alone as effectively, “bypassing all stability checks in other topic data files,” Escobar reported. He extra that the concern had been exploited by attackers “for really a while” and have been equipped “to deliver as many e-mails as they would like, only constrained by the server’s configurations.” This write-up initially appeared at scmagazineuk.com
Supply hyperlink Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)
Related
In the course of what was referred to as a program cleanup investigation, researchers at Sucuri uncovered that hackers have been exploiting a PHP script in a high quality WordPress topic to deliver spam.
“While many themes include electronic mail operation, this specific one particular was troublesome since the script was penned without the need of any stability checks or immediate entry prevention,” Sucuri Remediation Group Lead Rodrigo Escobar wrote in a site. “Without the right stability capabilities in place, this script can conveniently be exploited to abuse options and deliver mass electronic mail spam.”
The script, which employs facts from Post parameters to deliver electronic mail and is made to perform in the topic, can stand alone as effectively, “bypassing all stability checks in other topic data files,” Escobar reported. He extra that the concern had been exploited by attackers “for really a while” and have been equipped “to deliver as many e-mails as they would like, only constrained by the server’s configurations.”
This write-up initially appeared at scmagazineuk.com