TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How botnets are created with hijacked Worpess, fake Flash downloads and Node.js

102 pointsby Sujanover 9 years ago

8 comments

joshfraserover 9 years ago
I have a Wordpress plugin with ~100k active installs. Recently I've started getting emails from people wanting to buy the plugin from me. I'm assuming they want it for a botnet or other nefarious purposes. I'm not sure if Wordpress have stepped up their monitoring of plugins or not, but in past there was little oversight of the plugins and adding a direct backdoor to those 100k servers would be trivial, not to mention the millions of people that could be reached via JavaScript injection.
评论 #10616306 未加载
评论 #10618563 未加载
评论 #10620041 未加载
评论 #10615750 未加载
JoblessWonderover 9 years ago
This is the whole reason Sucuri [1] exists and blew up in popularity shortly after it launched. If you are running Wordpress, I&#x27;d definitely recommend Sucuri.<p>If you don&#x27;t have a paid plan, at least run the free scan once a month or more to make sure you weren&#x27;t hit by anything. I don&#x27;t mind Wordpress as a CMS, but it is a <i></i>constant<i></i> target. Constant. And nothing looks worse than having &quot;Cheap Canadian Viagra&quot; at the bottom of your corporate website.<p>[1] <a href="https:&#x2F;&#x2F;sucuri.net&#x2F;" rel="nofollow">https:&#x2F;&#x2F;sucuri.net&#x2F;</a>
评论 #10616884 未加载
评论 #10615766 未加载
评论 #10615679 未加载
评论 #10615641 未加载
评论 #10617026 未加载
eljamonover 9 years ago
tl;dr <i>Someone hacks WordPress websites and includes strange .js files that a) lead to fake Flash downloads that install a botnet on your PC and b) abuse your browser to get URLs from a Google search.</i>
评论 #10615181 未加载
paxtonabover 9 years ago
I wonder if the point of the botnet is to get SERPs from Google? They stopped letting you know quite a bit of information about keyowrds, rankings, etc. a while ago.<p>Seems like there is lots of potential for blackhat SEO with this type of botnet.
评论 #10615030 未加载
评论 #10614966 未加载
P4u1over 9 years ago
The domain hosting one of the files seemed too legit to me, so I checked and it&#x27;s an actual website of a Brazilian company,<a href="http:&#x2F;&#x2F;cjccontabil.com.br&#x2F;" rel="nofollow">http:&#x2F;&#x2F;cjccontabil.com.br&#x2F;</a>, seems whoever built the website got a WP (free I assume)theme from somewhere which happened to include this malicious file(&#x2F;wp-content&#x2F;themes&#x2F;Hermes&#x2F;main1.js). I guess folks are downloading free stuff and hosting them at their websites without inspecting the content of all files, so if you think you&#x27;re safe by just making sure your system is injection-proof, think again, are you using some theme or plugin downloaded from somewhere on the web and if so have you checked every single file included?
评论 #10616277 未加载
heyalexejover 9 years ago
Wow, this one infected at least 1.000+ sites according to Meanpath¹.<p>[1] <a href="http:&#x2F;&#x2F;meanpath.com&#x2F;f&#x2F;j5LK9K" rel="nofollow">http:&#x2F;&#x2F;meanpath.com&#x2F;f&#x2F;j5LK9K</a>
评论 #10616889 未加载
NickHaflingerover 9 years ago
How botnets are created with hijacked Worpess, fake Flash downloads, Node.js and Microsoft Windows ..
Ianvdlover 9 years ago
This is why you disable flash and run NoScript.
评论 #10615471 未加载