Monthly Archives: August 2011

TimThumb.php Attacks – Now Being Used for Blackhat Spam SEO and Might Break Your Site

We have been talking a lot lately about the Timthumb.php vulnerability and the importance of updating that script as soon as possible. Sites that didn’t update it are getting compromised very easily. We explained it in more detail here: Mass … Read more


Posted in hacked, malware, malware_updates, spam, vulnerability, wordpress | Tagged , , , , , | 13 Comments

TimThumb.php attacks – Now using googlesafebrowsing dot com

We have been talking a lot lately about the Timthumb.php vulnerability and the importance of updating the script as soon as possible. Sites that didn’t update it are getting compromised very easily. We explained it in more detail here: Mass … Read more


Posted in hacked, malware, malware_updates, vulnerability, wordpress | Tagged , , , , | 5 Comments

Mass Infection of WordPress Sites Due to TimThumb ( counter-wordpress dot com )

Many people are asking us about this “counter-wordpress.com” type of malware, so we will post some details here. Our scanner has been identifying it for a while, so if you think your site is compromised, just check it in there. … Read more


Posted in hacked, malware, malware_updates, vulnerability, wordpress | Tagged , , , , | 26 Comments

Attacks Against Timthumb.php in the Wild – List of Themes and Plugins Being Scanned

We are seeing large scale attacks against the vulnerable timthumb.php script in the wild. Thousands of sites are getting compromised and if you have it in your WordPress site, you better get it fixed right now! After a few days … Read more


Posted in hacked, malware, malware_updates, vulnerability, wordpress | Tagged , , , , | 15 Comments

WordPress sites with .htaccess hacked

The TimThumb.php vulnerability is causing a lot of WordPress sites to get compromised with the superpuperdomain.com and superpuperdomain2.com remote JavaScript injection. However, that’s not all that it is doing. On many of the sites we are analyzing, the .htaccess file … Read more


Posted in hacked, htaccess, malware, malware_updates, wordpress | Tagged , , , , | 20 Comments

TimThumb.php Vulnerability Not Only Affecting Themes – Plugins too

The Timthumb.php vulnerability is being used in the wild to hack and infect thousands of WordPress sites. Hopefully everyone is checking their themes and updating the script to make sure it is not vulnerable. This is wishful thinking. Unfortunately, the … Read more


Posted in hacked, malware, malware_updates, plugin, wordpress | Tagged , , , , , | 4 Comments

Non-Stop Attacks Against osCommerce – Time to Take Action

The malware attacks against osCommerce sites are still going at full force and the site owners have to take action to secure and update their sites as soon as possible. Think about that, with so many valuable targets (online stores) … Read more


Posted in hacked, malware, malware_updates, oscommerce, vulnerability | Tagged , , , , | 1 Comment

Update to the Superpuperdomain2.com malware

Just a quick update to the Superpuperdomain2.com/Superpuperdomain.com malware infection that has been affecting thousands of WordPress sites with the vulnerable timthumb.php script. You can read more about it here: http://blog.sucuri.net/2011/08/wordpress-sites-hacked-with-superpuperdomain2-com.html But now the attackers are also adding the following code … Read more


Posted in hacked, malware, malware_updates, vulnerability, wordpress | Tagged , , , | 3 Comments

WordPress Sites Hacked with Superpuperdomain2.com

A few days ago we posted about a series of attacks that were happening against WordPress sites running the vulnerable timthumb.php script. We detected thousands of sites compromised with it and now are are seeing a small change in the … Read more


Posted in hacked, malware, malware_updates, vulnerability, wordpress | Tagged , , , , | 7 Comments

WordPress Sites Hacked with Superpuperdomain dot com (Attacking Timthumb.php)

We are seeing a large number of WordPress sites compromised with a malicious JavaScript loading from superpuperdomain.com/count.php. That JavaScript redirects visitors that were going to the WordPress site to fake search engines. This is what shows up at the bottom … Read more


Posted in malware, malware_updates, wordpress | Tagged , , | 3 Comments