Best Blackhat Forum

Full Version: How to detect Malicious code in nulled or Free WordPress Themes and Plugins
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4
AWESOME TUT sahydian Than you for your time and effort
This is a great and 'SAFE' Tutorial. Thank you Sahydian!
Great info, but tell me how to erase that backlinks and codes?

I have iThemes Security Pro installed and add you rec. GOTMLS also TAC
is that enough?
I found TrojanDownloader.JS.avhq in one of my themes, how to delete this?

thanks
great tips. thanks for the share
(10-24-2016 09:15 PM)Kimi25 Wrote: [ -> ]Great info, but tell me how to erase that backlinks and codes?

I have iThemes Security Pro installed and add you rec. GOTMLS also TAC
is that enough?
I found TrojanDownloader.JS.avhq in one of my themes, how to delete this?

thanks

If you don't know programming your best bet is to change themes or just buy the legit theme - I would definitely get rid of that one real quick though.
A good post, but I have one issue with it - the inclusion of Virustotal.

Don't get me wrong - I use virustotal often - but it is not a php scanner, it detects PC viruses - so I feel that including it perpetuates a myth we see here all the time - "here is a plugin - and look it's safe - here is the virustotal."
Thanks OP
Thank for sharing great article
Great info thank you
Reps added
Jetpack plugin from the Wordpress team has Bruteprotect included. Wordfence is #1 security plugin and it scans EVERYTHING, including image files and files outside WP install (in Settings). AIO WP Security I avoid because if you change your login url it's difficult to access WP admin.

Yes, backups are good but NEVER install plugins or scripts that were shared or stolen because depending on the type of malware you are infecting ALL sites on a server, not just your own. I always buy from developer before installing scripts.
Pages: 1 2 3 4
Reference URL's