Avast WEBforum

Other => General Topics => Topic started by: polonus on April 25, 2010, 10:49:37 PM

Title: WordPress hack analysis..
Post by: polonus on April 25, 2010, 10:49:37 PM
Hi malware fighters,

In the light of the manifold recent hacks of reputable sites, let us show some light on the malicious use of the "eval" and "write document" commands, not really necessary in malicious scripts, but let us analyse such an attack according to the info via this link:
http://www.sourcesec.com/Lab/wordpress-hacked.html
and
http://www.sitepoint.com/blogs/2005/02/27/eval-is-dead-long-live-eval/

So keep your in-browser protection up with NoScript and RequestPolicy extensions installed inside the Mozilla browser
and do not click these links without being protected by the avast shields,

polonus