HomeSecurityWordpress Joomla websites at risk from hidden SWF

WordPress Joomla websites at risk from hidden SWF

swf

Hundreds of websites using WordPress or Joomla content management systems (CMS) have been attacked for five months with a malicious SWF file containing a hidden iframe. This script is used to redirect the browser to a new site that has an exploit kit and infects the unsuspecting visitor's computer.

SWF files are used to create applications that can run in Adobe Flash Player . As a result, older versions of the Player are vulnerable to attacks that exploit their weaknesses.

This activity was detected in early November, and initially websites written in Joomla were considered most at risk. Recently, attacks on WordPress websites have also come to the fore.

The Flash file, which is one pixel, is added to the “images/banners/” folder, with a name of three random characters and a number.

Peter Gramantik, a senior security researcher at Sucuri, says that based on the similarities (variable names, encoding, logic, and UserAgent state), he noticed that the attack is ongoing, although in recent recordings it appears to be coming from a different location than the November attacks.

A fairly large number of websites have been attacked in this way, reaching several thousand. The comforting thing is that in recent records, a fairly large number of attacks have been dealt with by anti-virus programs, which seem to detect the malicious Flash file. Virus Total shows that 23 out of 57 programs were able to detect the malware.

Gramantik, however, says that the malware is constantly evolving, so we should expect new versions of it very soon.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS