Wordpress templates from HireWordPressExperts.com have hidden code in an image

      Home » Websites & software » Wordpress templates from HireWordPressExperts.com have hidden code in an image

Wordpress templates from HireWordPressExperts.com have hidden code in an image

One of the most underhand ways of creating malware is to write code into an image itself, that runs when called on. One example popped this week, regarding the themes from http://hirewordpressexperts...

They added some hidden code inside their wordpress themes to track which sites are using them (and track the users as well). However, their tracking server went offline and every site using it got this error on the sidebar:
... Quote:
Surprisingly "this" string was found from image file wp.gif. Soon I discovered that functions.php file tried to include wp.gif file into source code. Wp.gif file was adding additional code into get_footer function.


The solution? Beware of themes from other websites, that could be infected with hidden code.

More on the topic ...

 http://blog.sucuri.net/2010...

 http://blog.huilaaja.net/20...

Good debate on the topic

 http://www.reddit.com/r/net...
By netchicken: posted on 2-6-2010








Wordpress templates from HireWordPressExperts.com have hidden code in an image | [Login ]
Powered by XMB
Privacy Policy