Mon, Apr 30 2012 21:11
bradley
Be careful on surfing.
http://www.bgr.com/2012/04/23/security-firm-identifies-origins-of-flashback-mac-virus/
On the news lately has been how Wordpress blogs have been used to infect Macs. On the wordpress side of the blog site (http://blogs.msmvps.com) we had an interesting event the other day.
We started getting reports from bloggers and readers that Eset,MSE and other virus engines kept alerting of a malicious javascript on the site.
Did multiple scans, did a Windows Online forensic analysis and found no malicious code actually "on" the box. What I did find was that it appeared that plug ins on the site appeared to be calling javascripts. It even appeared that possible googleapis were involved. We rebuilt the Wordpress side, leaving off all googleanalytics plug ins. And making sure that all timthumbs on the site were updated. Several themes from paid sites I downloaded still had vulnerable timthumb files in there.
But bottom line I'm not feeling warm and fuzzy. I put in a url blocker to block any .class urls called into the blog to ensure that if there's any plug ins had any malcious javascript they would be blocked. But the site had the latest wordpress. Bottom line, I'm not feeling warm and fuzzy that one can really secure a wordpress site. So be careful when surfing... EVEN on this web site.
Filed under: Security