Best Blackhat Forum

Full Version: [ GET ] AppThemes – Classipress v.3.3.2
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
[Image: IDVm5kY.png]
ClassiPress is the original and most popular classified ads theme for WordPress. Our feature-rich theme was built for ease-of-use and tight integration with WordPress so you’ll be online and selling classified ads within minutes.
Demo
RGhost
]]<<</appthemes-classipress-v-3-3-2/]Mirror


+Rep Me If You Liked My Post Heart Cool Cool Cool
Thanks for share. Downloading and test
Good for testing purpose. You should buy it if you want to use it for your business.
I think this is the copy I downloaded that I decided to use. I downloaded about 3 different versions of v3.3.2 and found that a popular copy is floating around that includes a backdoor in it. This one did not have the backdoor :) So that is good.

I used Beyond Compare and compared the files/folders between this copy and another copy. The other copy had an extra "social.png" file in the images folder (both in the main and admin directories). Then in the functions.php file at the very bottom, it had an include to the social.png file, which you do not "include" images with php. So they are using the png file to hide php code. The code is then Obfuscated, and it appears it has to do with SSL keys and connections. So most likely, it is a back door. Other than that, there are no other differences.

This was just an warning to others who have downloaded, or are going to download, the ClassiPress theme. Look in the images folder and if you see "social.png" and in the functions.php file, the last line includes that social.png image.. then you have a backdoored version. You can easily remove the image and include code, and it will be cleaned. Just make sure you do the same in both locations, as it is also in the /admin folder too.

Again, this copy is clean and legit.

I do want to point out, that the 2 version of ClassiPress provided are redundant. There is the "classipress" and "classipress-dev" versions included. They appear to have tried to share also the "Dev" version. However, the ONLY difference between the regular and dev versions are the dev version includes the PSD files. Since there are NO PSD files provided in these nulled releases, the dev version is no different and is not of any use. So it makes no sense lol.

So to install this.. upload one of the folders (doesn't matter as they are both the same) to your themes folder. Or you can "zip" one of the folders up, and use the Wordpess theme install feature from your Wordpress backoffice.

Thanks for the clean share :)
(03-03-2014 09:14 AM)CyberPunk Wrote: [ -> ]I think this is the copy I downloaded that I decided to use. I downloaded about 3 different versions of v3.3.2 and found that a popular copy is floating around that includes a backdoor in it. This one did not have the backdoor :) So that is good.

I used Beyond Compare and compared the files/folders between this copy and another copy. The other copy had an extra "social.png" file in the images folder (both in the main and admin directories). Then in the functions.php file at the very bottom, it had an include to the social.png file, which you do not "include" images with php. So they are using the png file to hide php code. The code is then Obfuscated, and it appears it has to do with SSL keys and connections. So most likely, it is a back door. Other than that, there are no other differences.

This was just an warning to others who have downloaded, or are going to download, the ClassiPress theme. Look in the images folder and if you see "social.png" and in the functions.php file, the last line includes that social.png image.. then you have a backdoored version. You can easily remove the image and include code, and it will be cleaned. Just make sure you do the same in both locations, as it is also in the /admin folder too.

Again, this copy is clean and legit.

I do want to point out, that the 2 version of ClassiPress provided are redundant. There is the "classipress" and "classipress-dev" versions included. They appear to have tried to share also the "Dev" version. However, the ONLY difference between the regular and dev versions are the dev version includes the PSD files. Since there are NO PSD files provided in these nulled releases, the dev version is no different and is not of any use. So it makes no sense lol.

So to install this.. upload one of the folders (doesn't matter as they are both the same) to your themes folder. Or you can "zip" one of the folders up, and use the Wordpess theme install feature from your Wordpress backoffice.

Thanks for the clean share :)
Thanks a lot for useful information's. Cool
thnx alot for your review Cool Cool
(03-03-2014 09:14 AM)CyberPunk Wrote: [ -> ]I think this is the copy I downloaded that I decided to use. I downloaded about 3 different versions of v3.3.2 and found that a popular copy is floating around that includes a backdoor in it. This one did not have the backdoor :) So that is good.

I used Beyond Compare and compared the files/folders between this copy and another copy. The other copy had an extra "social.png" file in the images folder (both in the main and admin directories). Then in the functions.php file at the very bottom, it had an include to the social.png file, which you do not "include" images with php. So they are using the png file to hide php code. The code is then Obfuscated, and it appears it has to do with SSL keys and connections. So most likely, it is a back door. Other than that, there are no other differences.

This was just an warning to others who have downloaded, or are going to download, the ClassiPress theme. Look in the images folder and if you see "social.png" and in the functions.php file, the last line includes that social.png image.. then you have a backdoored version. You can easily remove the image and include code, and it will be cleaned. Just make sure you do the same in both locations, as it is also in the /admin folder too.

Again, this copy is clean and legit.

I do want to point out, that the 2 version of ClassiPress provided are redundant. There is the "classipress" and "classipress-dev" versions included. They appear to have tried to share also the "Dev" version. However, the ONLY difference between the regular and dev versions are the dev version includes the PSD files. Since there are NO PSD files provided in these nulled releases, the dev version is no different and is not of any use. So it makes no sense lol.

So to install this.. upload one of the folders (doesn't matter as they are both the same) to your themes folder. Or you can "zip" one of the folders up, and use the Wordpess theme install feature from your Wordpress backoffice.

Thanks for the clean share :)
annyone has the stipe plugin?
anybody RIP This :D thnx bro
Reference URL's