Hackers using hacked WordPress & Joomla sites to drop malware

By Waqas
Apparently, the malware attack is carried out by Russian speaking hackers. The IT security researchers at Zscaler have discovered a sophisticated malware campaign targeting websites based on WordPress and Joomla content management system (CMS)… Continue reading Hackers using hacked WordPress & Joomla sites to drop malware

What to Do When the Botnet Comes Knocking

“It was a cold and windy night, but the breeze of ill omen blowing across the ‘net was colder. The regular trickle of login attempts suddenly became a torrent of IP addresses, all trying to break into the back-end of the Joomla site I host. I poured another cup of …read more

Continue reading What to Do When the Botnet Comes Knocking

Why object injection doesn’t work but payload is stored along with session cookies on Joomla 2.5.11 unpatched?

I have read and understand object injection from this question. Then I wanted to test the security issue behind Joomla CMS Object injection through serialization.

TEST MACHINE

xammp 1.7.3 for windows
Apache/2.2.14 (Win32) … Continue reading Why object injection doesn’t work but payload is stored along with session cookies on Joomla 2.5.11 unpatched?

Support for PHP 5.6.x Ends in 2 Months, Millions of Websites at Risk

Did you know that nearly 80% of all websites run on PHP? More particularly, “PHP is used by 78.9% of all the websites whose server-side programming language we know”, as revealed by W3Techs statistics. This fact alone makes PHP security…R… Continue reading Support for PHP 5.6.x Ends in 2 Months, Millions of Websites at Risk