Best Blackhat Forum

Full Version: Simey69's Warning To Everyone. Please READ this!!!
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4 5 6 7 8
http://bestblackhatforum.com/Thread-GET-...n-Business

The person who has been posting all their free themes has shown to have some viruses after scanning with virustotal? I have check most of his postings and he never give us the viriustotal check and count? I wonder why?

Please someone check and let us know.
Thanks for the Red Alert ! Will keep an eye for such fools.
Oh yeah... be careful with this social.png which isn't an image... is a php script (you can change the file extension from .png to .php and open to view code... there you'll find the malicious code... just 29 lines of code...
(02-28-2015 12:28 PM)joy99 Wrote: [ -> ]http://bestblackhatforum.com/Thread-GET-...n-Business

The person who has been posting all their free themes has shown to have some viruses after scanning with virustotal? I have check most of his postings and he never give us the viriustotal check and count? I wonder why?

Please someone check and let us know.

Yeah me too, very interested in that user. I never use his shares even why some of them were very important to me, but as i have seen he neither replies to all the other users.

I dont like it but still keeping an eye on him.
bump!

Take an action admin!
Simey69, thank you for keeping us aware on this thread.
Rep+ add
Some help based on my own experiences: if an uploaded theme has no original source specified i take a quick look to
Code:
http://www.wplocker.com/
. Very frequently i can find the theme uploaded there the same day as it uploaded here with exact matching version numbers. In this cases i think we better avoid the new share.
Beware new malware script case found here :
Code:
http://bestblackhatforum.com/Thread-GET-LATEST-KLEO-v-3-0-6-Next-level-Premium-WordPress-Theme?pid=1586246#pid1586246

detail malware :
Code:
http://www.davirro.org/pirated-wordpress-plugins-are-commonly-infected-with-heavily-obfuscated-viruses/
https://gist.github.com/vladimirlukyanov/2addcfdb1bfe7e5f7000#file-wordpress-gfx-plugins-malware-php

how to fix :
Just delete the codes after if (!function_exists('wp_en_one')) { .
or
Code:
http://vzemisite.com/virus-glues_it-fixed/2015/09/25/
Thanks for the information simey69!
Checking. Thanks!
Pages: 1 2 3 4 5 6 7 8
Reference URL's