www.purebasic.fr/blog infected with malware?!

Everything else that doesn't fall into one of the other PB categories.
c4s
Addict
Addict
Posts: 1981
Joined: Thu Nov 01, 2007 5:37 pm
Location: Germany

www.purebasic.fr/blog infected with malware?!

Post by c4s »

Looks like the PureBasic blog got infected with some kind of spam malware:
http://sitecheck.sucuri.net/results/www ... ic.fr/blog


Edit: (Currently) it doesn't seem to be harmful - just a few hidden spam links have been added. Still, the Wordpress installation got infected with unwanted code...
If any of you native English speakers have any suggestions for the above text, please let me know (via PM). Thanks!
User avatar
ts-soft
Always Here
Always Here
Posts: 5756
Joined: Thu Jun 24, 2004 2:44 pm
Location: Berlin - Germany

Re: www.purebasic.fr/blog infected with malware?!

Post by ts-soft »

PureBasic 5.73 | SpiderBasic 2.30 | Windows 10 Pro (x64) | Linux Mint 20.1 (x64)
Old bugs good, new bugs bad! Updates are evil: might fix old bugs and introduce no new ones.
Image
User avatar
Didelphodon
PureBasic Expert
PureBasic Expert
Posts: 450
Joined: Sat Dec 18, 2004 11:56 am
Location: Vienna - Austria
Contact:

Re: www.purebasic.fr/blog infected with malware?!

Post by Didelphodon »

hacked == hacked
Go, tell it on the mountains.
c4s
Addict
Addict
Posts: 1981
Joined: Thu Nov 01, 2007 5:37 pm
Location: Germany

Re: www.purebasic.fr/blog infected with malware?!

Post by c4s »

ts-soft wrote:Google shows no problems: http://safebrowsing.clients.google.com/ ... ic.fr/blog
So what? No need to give all your trust in the almighty / omniscient Google corporation...
Just take a look at the source code of purebasic.fr/blog (at the very bottom) to check it out for yourself.
If any of you native English speakers have any suggestions for the above text, please let me know (via PM). Thanks!
User avatar
Bisonte
Addict
Addict
Posts: 1335
Joined: Tue Oct 09, 2007 2:15 am

Re: www.purebasic.fr/blog infected with malware?!

Post by Bisonte »

WordPress version outdated: Upgrade required.
Maybe an update can help with security ...
PureBasic 6.21 (Windows x64) | Windows 11 Pro | AsRock B850 Steel Legend Wifi | R7 9800x3D | 64GB RAM | RTX 5080 | ThermaltakeView 270 TG ARGB | build by vannicom​​
English is not my native language... (I often use DeepL.)
User avatar
Kukulkan
Addict
Addict
Posts: 1422
Joined: Mon Jun 06, 2005 2:35 pm
Location: germany
Contact:

Re: www.purebasic.fr/blog infected with malware?!

Post by Kukulkan »

Hi,

I can not see any MALWARE distribution on the page source code. But I'm just wondering about the last block in the HTML source:

Code: Select all

<div style="left: -3565px; position: absolute; top: -4812px"><li>Buy Cheapest <a href="http://subcreators.com/blog/buy-no-prescription-periactin">buy no prescription periactin</a> Online Discount Online Pharmacy. Low Prices.</li>
<li>Buy Cheap <a href="http://mebelisirakov.com/purchase-dostinex-from-canada">purchase dostinex from canada</a> Online Best Online. 100% Satisfaction Guaranteed.</li>
<li>Buy Cheap <a href="http://mebelisirakov.com/india-online-pharmacies">india online pharmacies</a> Online Online Medical Shop. Cheap Online Pharmacy.</li>
<li>Buy Cheapest <a href="http://www.navegandoxlared.es/?p=35112">cheapest lotrisone pills</a> Now Best Prices. Pharmacy At The Best Price!</li>

(...)

<li>Buy Cheapest <a href="http://krischronicles.com/?p=36752">buy pills ephedraxin</a> Online Best Drugstore. Guaranteed Shipping.</li>
<li>Buy Cheap <a href="http://waxidermy.com/with-prescription-levitra-plus">with prescription levitra plus</a> Now Top Online Pharmacy Supplier. Best Internet.</li>
</div>
Looks like spamming... But maybe the WordPress template used by Fred is just a "bad" one ;-)

Kukulkan
c4s
Addict
Addict
Posts: 1981
Joined: Thu Nov 01, 2007 5:37 pm
Location: Germany

Re: www.purebasic.fr/blog infected with malware?!

Post by c4s »

I'm pretty sure that these spam links are new. So how did they get there? It seems that someone besides the PB team was able to manipulate the Wordpress installation...
If any of you native English speakers have any suggestions for the above text, please let me know (via PM). Thanks!
User avatar
Didelphodon
PureBasic Expert
PureBasic Expert
Posts: 450
Joined: Sat Dec 18, 2004 11:56 am
Location: Vienna - Austria
Contact:

Re: www.purebasic.fr/blog infected with malware?!

Post by Didelphodon »

as far as i know recently there have been published some new wordpress vulns. through january we have seen a massive attack on joomla websites due to new vulns. so its absolutely necessary to keep those CMSes up to date - including all of the other stuff like plugins and the like. regarding wordpress there is a new release 3.5.1 available - just for the sake of completeness.
Go, tell it on the mountains.
Fred
Administrator
Administrator
Posts: 18550
Joined: Fri May 17, 2002 4:39 pm
Location: France
Contact:

Re: www.purebasic.fr/blog infected with malware?!

Post by Fred »

I just updated wordpress and it seems all gone.
SFSxOI
Addict
Addict
Posts: 2970
Joined: Sat Dec 31, 2005 5:24 pm
Location: Where ya would never look.....

Re: www.purebasic.fr/blog infected with malware?!

Post by SFSxOI »

It wasn't suspicious to Google because Google doesn't count spam (like that shown above in this thread) as malicious content, because it actually isn't (and isn't malware if the links don't point to known malware content) and its more of an annoyance. Sucuri Site does include such spam in their consideration for exclusion, so it shows up with Sucuri Site and not Google.
The advantage of a 64 bit operating system over a 32 bit operating system comes down to only being twice the headache.
c4s
Addict
Addict
Posts: 1981
Joined: Thu Nov 01, 2007 5:37 pm
Location: Germany

Re: www.purebasic.fr/blog infected with malware?!

Post by c4s »

I just checked the blog and noticed that the spam links are again listed in the source code. My only explanation for this is that the bad guys somehow have access to the Wordpress installation - could be through the theme, a plugin, comment system or even ftp. Maybe this has to do with the recent down-times of the forum?!
If any of you native English speakers have any suggestions for the above text, please let me know (via PM). Thanks!
User avatar
Kukulkan
Addict
Addict
Posts: 1422
Joined: Mon Jun 06, 2005 2:35 pm
Location: germany
Contact:

Re: www.purebasic.fr/blog infected with malware?!

Post by Kukulkan »

I have to confirm. There is an additional div container full of spam links on the homepage. Best would be to change all admin passwords to that server...

Kukulkan
Post Reply