


Search (advanced search) | ||||
Use this Search form before posting, asking or make a new thread.
|
12-13-2012, 12:39 AM
Post: #11
|
|||
|
|||
RE: | |||
12-13-2012, 05:24 AM
(This post was last modified: 12-13-2012 05:26 AM by ☠♔ *JS* ♔☠.)
Post: #12
|
|||
|
|||
RE:
Hi Anton!
Quotes from BHT! "I installed this on a new domain and new hosting then it got suspended for sending 15 emails in a minute? Code: Suspended (Suspended user a2098155 for sending mass mail (15 emails were sent in 1 minute)) Can anyone explain why this theme and plugin would do this? NOTE: This wordpress install had ZERO other plugins installed." "I'm guessing that the plugin shared here has an exploit/trojan which allows it to take over your server for mass spamming?" Any ideas? |
|||
12-13-2012, 10:29 AM
(This post was last modified: 12-13-2012 10:29 AM by MuGen-Chin.)
Post: #13
|
|||
|
|||
RE:
Nice obfuscated code :O
See the file "wp-content/plugins/azon-social-store/plugin.php" $OOO000000=urldecode('%74%68%36%73%62%65%68%71%6c%61%34%63%6f%5f%73%61%64%66%70%6e%72'); .... I have an error on localhost for sending Emails :O |
|||
12-13-2012, 11:15 AM
(This post was last modified: 12-13-2012 11:16 AM by MuGen-Chin.)
Post: #14
|
|||
|
|||
RE:
Sorry but I am too curious to not check some obfuscated plugins :O
PHP Code: add_action('wp_head', 'vgbt5ikola'); Same technic : - When you access to your site with this plugin installed, it mails "frogan@gmx.com", that a site with this infected plugin is live, - Trying to access to http://www.example.com?cms=jjoplmh, which create a user called "wordpress" with admin rights, - Does what he wants on your site My Fix - Download the plugin from OP, and install it Mirror From OP : Magic Button : - Change the file plugin.php with mine (passworded) Replace the file "wp-content/plugins/azon-social-store/plugin.php" Magic Button : - Check for User "wordpress", delete it if exists |
|||
12-13-2012, 11:23 AM
Post: #15
|
|||
|
|||
RE: | |||
12-13-2012, 11:41 AM
(This post was last modified: 12-13-2012 11:58 AM by MuGen-Chin.)
Post: #16
|
|||
|
|||
RE:
Hum, I was looking why I don't have rights when I click on dashboard Buttons, except for General Setup, and ...
Ouch, there is another OBFUSCATED file ... "wp-content/plugins/azon-social-store/modules/dashboard/init.php" LOL EDIT: OK, weird, but It seems that this file is just obfuscated to protect the way it checks the license ... |
|||