Fake WordPress site releasing backdoored code

Thursday, November 6th, 2008

Biggs is the editor of TechCrunch Gadgets. Biggs has written for the New York Times, InSync, USA Weekend, Popular Mechanics, Popular Science, Money and a number of other outlets on technology and wristwatches. He is the former editor-in-chief of Gizmodo.com and lives in Bay Ridge, Brooklyn. You can Tweet him here and G+ him here. Email him directly at john@techcrunch.com. → Learn More

Don’t mistype “wordpress.org” because you could end up downloading compromised code. Some hackers have set up www.wordpresz.org. The code sends cookie contents to a hacked program hosted on wordpresz.org and could expose passwords and other identifying information.

UPDATE – Looks dead now.

The backdoored pluggable.php file attempts to send the stolen data to wordpresz.org/tuk.php which is still accepting cookies if the requests are properly formatted. The spoof is a nearly perfect combination of social engineering, typosquatting and the natural EstDomains connection as the domain registrar, nearly perfect in the sense that they couldn’t duplicate the whole WordPress.org potentially raising suspicion at the end user’s end.

The site is on the same IP address as a fake pharmacy site, proving that scammers always ring twice.

Sponsored Ads

blog comments powered by Disqus

Sponsored Ads

Sponsored Ads

Events

Crunchies Awards
January 31, 2012
Davies Symphony Hall
San Francisco CA
Learn MoreBuy Tickets