WP theme recommendation: Hackers aim at Tatsu WordPress plug-in vulnerabilities and launch millions of attacks. The main attack methods of hackers include

One year ago (2023-11-25) Chief Editor
4 minutes
two hundred and eighty-eight
zero

It is reported that hackers are taking advantage of the remote code execution vulnerability CVE-2021-25094 in the Tatsu Builder plug-in on the WordPress website to launch attacks on a large scale.

Tatsu Builder is a popular plug-in, which provides powerful template editing function and is integrated in the web browser. About 100000 websites have installed the plug-in.

The target vulnerability CVE-2021-25094 was discovered by Vincent Michel, an independent researcher. Vincent publicly disclosed this vulnerability and the proof of concept (PoC) vulnerability utilization code on March 28, 2022. This vulnerability allows remote attackers to execute arbitrary code on servers that use outdated plug-ins (all versions before 3.3.12).

The vendor released a patch in version 3.3.13, and urged users to update the application by email on April 7, 2022.

Wordence, which provides security solutions for WordPress plug-ins, has been monitoring the current attacks. The wave of large-scale attacks began on May 10, 2022, and reached its peak four days later. It is still in progress. Although patches have been available since early April, researchers estimate that 20000 to 50000 websites are still running vulnerable versions of Tatsu Builder.

Number of websites attacked

Attack details

Wordence reported that its customers had suffered millions of attacks, and the company stopped as many as 5.9 million attack attempts on May 14, 2022. In the following days, the number of attacks declined, but vulnerability utilization remained at a high level.

Attacks detected and blocked by Wordence

Threat participants try to inject malware dropper into the "wp content/uploads/typehub/custom/" directory subfolder to make it a hidden file. The Dropper is named ". sp3ctra_XO. php", and the MD5 hash value is 3708363c5b7bf582f8477b1c82c8cbf8.

Extended file checking skipped hidden files

Wordence reported that more than one million attacks only came from three IP addresses: 148.251.183 [.] 254, 176.9.117 [.] 218 and 217.160.145 [.] 62. Website administrators should add these IP addresses to the block list. To avoid the attack risk, it is recommended that all users of the Tatsu Builder plug-in upgrade it to version 3.3.13.

Chris Olson, CEO of The Media Trust, a mobile and network security company Said: "When it comes to network security, most organizations seldom consider their websites. Tatsu vulnerabilities show us why this is wrong. Websites play a key role in marketing and revenue generation. They are increasingly becoming the target of hackers and the source of risk for customers and temporary visitors."

Olsen pointed out that as a preventive measure, anyone who manages the organization's website should regularly maintain it, including updating plug-ins and security patches. "If it runs WordPress or other open source CMS that heavily relies on third-party code, it should be even more so, because these are the main drivers of risk."

This article is written by: Chief Editor Published on Software Development of Little Turkey , please indicate the source for reprinting: //hongchengtech.cn/blog/586.html
Kuke_WP editor
author

Related recommendations

1 year ago (2024-02-20)

Multi store system management - store management design, how to do multi store system design scheme

Store management is an important part of the e-commerce platform. The platform administrator manages store information, goods, orders, settlement methods and other contents through the store management function. The author of this paper analyzes the design of store management in multi merchant system management. Let's have a look. 1、 Introduction The store management is an important part of the e-commerce platform. The platform administrator manages the store through
seven hundred and twenty
one
1 year ago (2024-02-19)

Sitecore: What major functions does a high-quality and powerful content management system need to have?

An appropriate content management system (CMS) is an urgent task for enterprises to maintain competitiveness through digital upgrading and transformation. Now 90% of enterprise website building and development uses CMS, which can easily create excellent customer experience in all channels, help enterprises attract new customers, retain old customers and turn existing customers into loyal customers, expand market share and increase revenue
three hundred and seventy-six
zero
1 year ago (2024-02-18)

The combination and application of content management system and marketing technology, and the combination and application of content management system and marketing technology

B2B content marketing hopes to deliver valuable content to customers at their own stage in a timely manner during their purchase journey. Such as brand and solution related content in the cognitive stage, industry cases in the consideration stage and user confidence building stage, in-depth service introduction in the purchase stage, etc. These contents include images, videos, web pages, white papers
three hundred and fifteen
zero
1 year ago (2024-02-18)

In the second quarter, 648 websites were interviewed by the national network information system according to law, 56 websites were suspended from updating, and the spirit of the national network information work conference was ppt

According to the data released by "Cybertrust China", in the second quarter, the national Cybertrust system continued to strengthen administrative law enforcement, standardize administrative law enforcement, and investigate and deal with all kinds of illegal cases according to law. Original title: In the second quarter, 648 websites were interviewed by the national online trust system in accordance with the law, 56 websites were suspended from updating, and the TechWeb news on July 30 was released according to "online trust China"
three hundred and ten
zero
1 year ago (2024-02-17)

Introduction and recommendation of ten free cms website building systems, and ten free defective software

It is particularly important to choose a easy-to-use cms website building system for website management and maintenance. We will choose different website building systems according to different website types, but the load, security, ease of use, versatility and subsequent development of the program are all basic criteria for everyone to choose a website building system. According to the webmaster station ranking and aleax ranking, the top 1
three hundred and seventy-five
zero
1 year ago (2024-02-17)

What are the advantages of Shanghai cms website?, How to build a website for cms

Original title: What are the benefits of building a website by Shanghai cms? Before the advent of cms, we usually found a website production company to carry out customized development. It can also be said that in fact, these website production companies also have their own formed website construction system, but it is not available for users to download. What we are talking about now is a website construction system that can be downloaded to build websites
three hundred and twenty-two
one

comment

0 people have participated in the review

Scan code to add WeChat

contact us

WeChat: Kuzhuti
Online consultation: