CONTAINS MALWARE! Or creates a tunnel for malware injection
-
I’ve discovered that more than a dozen self-hosted WordPress-powered blogs have been compromised with malware and malicious code injection through the BackWPUp plugin (latest and previous two versions at least).
Below is a small segment of the malware scan report delivered by my host, Rackspace, for the WordPress sites on my dedicated servers. The entire report is 3879 lines long.
If you use this plugin, I strongly encourage you to ask your host to run a scan on your site(s).
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/WindowsAzure/ServiceManagement/Models/HostedService.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Guzzle/Parser/Url/UrlParserInterface.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Guzzle/Common/Collection.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/wp-cufon/wp-cufon.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Aws/Common/Exception/ExceptionFactoryInterface.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/OpenCloud/OpenCloud/Base/Base.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/SwiftMailer/dependency_maps/message_deps.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/OpenCloud/OpenCloud/Base/Exceptions/MetadataUpdateError.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Guzzle/Http/Message/HeaderComparison.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Aws/S3/Model/Grant.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/Aws_v1/utilities/mimetypes.class.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/WindowsAzure/Table/Models/Filters/ConstantFilter.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Aws/S3/Enum/Protocol.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Guzzle/Service/Command/Factory/CompositeFactory.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/PEAR/Console/Getopt.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Guzzle/Parser/UriTemplate/UriTemplate.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/WindowsAzure/ServiceBus/Models/ReceiveMode.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site01.com/web/content/wp-content/plugins/backwpup/sdk/SwiftMailer/classes/Swift/CharacterReader/GenericFixedWidthReader.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/SwiftMailer/classes/Swift/Mime/EncodingObserver.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/WindowsAzure/Common/Internal/InvalidArgumentTypeException.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/Aws/Aws/S3/Exception/MalformedXMLException.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
https://www.site02.com/web/content/wp-content/plugins/backwpup/sdk/OpenCloud/OpenCloud/Base/Exceptions/JsonError.php CLOUDSITES.PHP.Mailer.020.UNOFFICIAL
- The topic ‘CONTAINS MALWARE! Or creates a tunnel for malware injection’ is closed to new replies.