Nu har ransomware nått även WordPress och ramlar du över en plugin ute på nätet som lovar guld och gröna skogar och som heter WP Security så se upp – det kan vara ett program som låser och krypterar dina inlägg.
WP Security finns inte på WordPress så du hittar den inte via den interna funktionen för att installera tillägg. WP Security måste laddas ned och installeras manuellt.
During a recent cleanup, we found an interesting malicious WordPress plugin, “WP Security”, that was being used to encrypt blog post content. The website owner complained of a newly installed and activated plugin on their website that was rendering their original content unreadable.
The plugin encrypted posts with the ‘AES-256-CBC’ method by using the openssl_encrypt function, whoch made it impossible to decrypt without proper keys. This is the first time we’ve seen a plugin target specific blog posts on a website, but it’s possible that we’ll see this more often in the coming months.
Inlägg
WP Security krypterar bara enskilda inlägg, inte webbplatsen i övrigt.
“This is the first time we’ve seen a plugin target specific blog posts on a website, but it’s possible that we’ll see this more often in the coming months,” Sucuri researcher Kasimir Konov said in a blog posting on Monday. “The website owner(s) complained of a newly installed and activated plugin on their website that was rendering their original content unreadable.”


0 kommentarer