Wordpress Exploit Gumblar .cn

May 12, 2009

Looks like there is another Wordpress exploit out there dubbed Gumblar .cn – I was actually made aware of it through a pingback from Growmap.com on their: Watch Out for Recent WordPress Gumblar PHP Exploit post.

These attacks are extremely time consuming to clean up, trust me I’ve had to do it before in the past. It’s not a quick or easy thing to have to deal with at all.

There is also an excellent explanation of Gumblar here: Gumblar .cn Exploit – 12 Facts About This Injected Script

Please proactively protect yourself against this exploit!

Update: I’m quoting a bit from Scansafe’s excellent Q&A about the exploit:

Is this a cross-site scripting (XSS) attack?

No. The compromises appear to be the result of stolen FTP credentials and direct manipulation of files on the Web server.

What is the intent of the malware distributed through the Gumblar compromised websites?

The malcode distributed via the compromised websites attempts to exploit PDF and Flash exploits in order to deliver malware that redirects infected users’ search engine results. In these particular attacks, the malcode appears to be targeting Internet Explorer users and Google search. In addition, the gumblar.cn malcode installs a backdoor that connects to 78.109.29.112 – an IP address of a known botnet command and control that has historically been associated with malware engaged in malicious redirections.

Reference blog post: http://blog.scansafe.com/journal/2009/5/8/google-serps-redirections-turn-to-bots.html

How do these malicious redirections work?

Similar to a man-in-the-middle attack, these redirections occur as a result of a man-in-the-browser attack. The malcode injects itself into the browser process, monitors the requests processed by the browser, and injects fraudulent traffic. In the case of the Google SERPs redirects, the malcode replaces legitimate Google SERPs results with links pointing to malicious or fraudulent websites.

Millions of websites have been compromised over the past year; what makes these particular compromises unique?

A typical series of website compromises reaches peak within the first week or so and subsequently begins declining in intensity as detection is added by signature vendors, user awareness increases, and website operators begin cleaning the affected sites. (This is why attackers are constantly pushing new waves of compromise).

In the gumblar.cn attacks, the opposite is occurring. As website operators attempt to clean up the original compromise or otherwise make changes to the original source code of the .htm, .php, and .asp pages on their sites, the gumblar.cn compromise is injected. The gumblar.cn mal-script appears to be dynamically generated and thus varies not only from site to site, but also from page to page on the same site. In addition, the resulting mal-script is heavily obfuscated, further hampering signature detection methods. As a result, the gumblar.cn compromises are increasing – up 188% from last week and a 61% increase from yesterday.

Here are some related articles I’ve written that might be helpful:

Wordpress Injection Attack

Blocking Spam with Wordpress

Wordpress Security Plugins

Best of Luck,

Dan

Reblog this post [with Zemanta]
Related Posts
  • 50 Twitter Tips for Conversion So here it is: Twitter.  It’s everywhere being hyped as the next great thing, but what can it do for your business? Like any emerging technology the uses are somewhat open ended and there are still many questions. A few things are absolutely certain: Twitter offers you an opportunity to......
  • Internet Marketing Tweet Digest 2009-05-31 I officially hate Rogers here in Canada. I am thinking of pulling all my company phones and services from them. Worst cust service ever. # @robmanne Hi Rob - I cannot DM you unless you are following me. in reply to robmanne # Yummy! Smoked Salmon with Marinated Onions......
Related Websites
  • Web Servers That Serve SEO - Step by Step. Its been known for a while that one of the ways new industries and trade bodies try to separate insiders from outsiders is through the creation of an industry-specific vernacular that is hard for outsiders...
  • Search Engine Optimization And Why You Gotta Use It? E-commerce may be a cut throat business. You have to arm yourself with the correct know-how and the tools to make your web site a cut higher than the rest. Each day, additional and additional sites are clambering to optimize...

Comments

3 Responses to “Wordpress Exploit Gumblar .cn”

  1. Vote -1 Vote +1Wordpress Backup Plugins by Dan Nedelko on May 15th, 2009 8:50 am

    [...] Wordpress Exploit Gumblar .cn [...]

  2. Vote -1 Vote +1Wordpress Exploit Gumblar cn by Dan Nedelko | Paid Surveys on June 3rd, 2009 9:40 am

    [...] Wordpress Exploit Gumblar cn by Dan Nedelko Posted by root 1 day 16 hours ago (http://dannedelko.com) Looks like there is another wordpress exploit out there dubbed gumblar cn i was may want to subscribe to my rss feed for current and unique internet marketing strategies surveillance privacy powered by twitter tools comment now name required email address Discuss  |  Bury |  News | Wordpress Exploit Gumblar cn by Dan Nedelko [...]

  3. Vote -1 Vote +1öykü on August 2nd, 2009 4:46 am

    Good solution, thanks

Join in on the Discussion! Comment Now: