November 9, 2008
4:00 am

If you mistype WordPress.org as Wordpresz.org, you’ll land at fake site, distributing 2.6.4 — purposely backdoored in order to steal the content of cookies from those who’ve installed it, potentially leading to to hijacking of their WordPress blogging platforms for malicious purposes. Not only is the fake domain registered several days ago, but also, it’s sharing IP (209.160.33.108) with a fake online pharmacy - livepills.com.

The backdoored pluggable.php file attempts to send the stolen data to wordpresz.org/tuk.php which is still accepting cookies if the requests are properly formatted. The spoof is a nearly perfect combination of social engineering, typosquatting and the natural EstDomains connection as the domain registrar, nearly perfect in the sense that they couldn’t duplicate the whole WordPress.org potentially raising suspicion at the end user’s end.

Full Article

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« Open Source Google Android OS ‘jailbroken’WordPress 2.7 Core Update Host Compatibility »
Feed Icon

Subscribe via RSS or email: