BlackHatCrew - Elite Blackhat SEO Webmaster Forum
 

Go Back   BlackHatCrew - Elite Blackhat SEO Webmaster Forum > Free 4 All > Webmaster Talk
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 05-09-2008, 06:32 PM   #1 (permalink)
poto
splogtastic
 
poto's Avatar
 
Join Date: Oct 2007
Posts: 1,212
Send a message via ICQ to poto
Default wordpress shortstat exploit

just a heads up for those of you with wp installs that might be using shortstat... apparently shortstat allows one to insert an iframe in the referral log...

Quote:
the minute you click on shortstat it redirects you to a page filled with ads to adultfriendfinder and the page is also loaded with viruses.
source: [SOLVED] If you run ShortStat, disable it NOW | JustJace.com

luckily I don't use shortstat, so no problems for me...

tbh, I think this exploit has the ability to produce greater potential damage than just some shitty malware installs... one could in theory use the iframe redirect to a fake wordpress login page asking the admin to re-enter the login and password... wonder how many wp installs one could gain access to that way? if one were so deviously inclined that is...
__________________
My Ratios :: My Blacklist
poto is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:18 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0