<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>wordpress update | Matt Crawford</title>
	<atom:link href="https://mattcrawford.me/tag/wordpress-update/feed/" rel="self" type="application/rss+xml" />
	<link>https://mattcrawford.me</link>
	<description>Handyman &#124; Geek &#124; YouTuber</description>
	<lastBuildDate>Tue, 14 Jun 2022 23:48:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
<site xmlns="com-wordpress:feed-additions:1">176948450</site>	<item>
		<title>Over 67,000 Websites Defaced via Recently Patched WordPress Bug</title>
		<link>https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=over-67000-websites-defaced-via-recently-patched-wordpress-bug</link>
					<comments>https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/#respond</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Tue, 07 Feb 2017 18:39:15 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress update]]></category>
		<guid isPermaLink="false">https://g3k.xyz/?p=2613</guid>

					<description><![CDATA[<p>WordPress sites that haven&#8217;t been updated to the most recent version, v4.7.2, released last week, are under attack as four hacking groups are conducting mass defacement campaigns. According to web security firm Sucuri, who detected the attacks after details of the vulnerability became public last Monday, the attacks have been slowly growing, reaching almost 3,000 [&#8230;]</p>
The post <a href="https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/">Over 67,000 Websites Defaced via Recently Patched WordPress Bug</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p>WordPress sites that haven&#8217;t been updated to the most recent version, v4.7.2, released last week, are under attack as four hacking groups are conducting mass defacement campaigns.</p>
<p>According to web security firm Sucuri, who detected the attacks after details of the vulnerability became public last Monday, the attacks have been slowly growing, reaching almost 3,000 defacements per day.</p>
<p>Attackers are exploiting a vulnerability in the WordPress REST API, which the WordPress team fixed almost two weeks ago, but for which they <a href="https://www.bleepingcomputer.com/news/security/wordpress-team-fixed-a-zero-day-behind-everyones-back-and-told-no-one/" target="_blank" rel="noopener noreferrer">published public details last Monday</a>.</p>
<figure id="attachment_2614" aria-describedby="caption-attachment-2614" style="width: 800px" class="wp-caption alignnone"><a href="https://t3dus.com/wp-content/uploads/2017/02/Chart-exploit-attempts.png"><img fetchpriority="high" decoding="async" class="wp-image-2614 size-full" src="https://t3dus.com/wp-content/uploads/2017/02/Chart-exploit-attempts.png" width="800" height="526" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Chart-exploit-attempts.png 800w, https://mattcrawford.me/wp-content/uploads/2017/02/Chart-exploit-attempts-300x197.png 300w, https://mattcrawford.me/wp-content/uploads/2017/02/Chart-exploit-attempts-768x505.png 768w" sizes="(max-width: 800px) 100vw, 800px" /></a><figcaption id="caption-attachment-2614" class="wp-caption-text">Defacement attempts via REST API flaw over time (via Sucuri)</figcaption></figure>
<p>The vulnerability allows a remote attacker to craft an HTTP request that pings a REST API endpoint and alters titles and content on the user&#8217;s website.</p>
<p>Exploiting the flaw is trivial, and according to Sucuri, a few public exploits have been published online since last week.</p>
<h2>Over 67,000 websites defaced already</h2>
<p>Even if the vulnerability affects only WordPress 4.7.0 and 4.7.1 and the CMS has a built-in auto-update feature for security issues, many websites haven&#8217;t been updated.</p>
<p>Based on data collected from Sucuri&#8217;s honeypot test servers, four attackers have been busy in the past week trying to exploit the flaw.</p>
<table border="0" cellspacing="1" cellpadding="1">
<tbody>
<tr>
<td>Group name</td>
<td>IP</td>
<td>Estimated victims</td>
</tr>
<tr>
<td>w4l3XzY3</td>
<td>176.9.36.102<br />
185.116.213.71<br />
134.213.54.163<br />
2a00:1a48:7808:104:9b57:dda6:eb3c:61e1 (IPv6 address)</td>
<td>66,000</td>
</tr>
<tr>
<td>Cyb3r-Shia</td>
<td>37.237.192.22</td>
<td>500</td>
</tr>
<tr>
<td>By+NeT.Defacer</td>
<td>144.217.81.160</td>
<td>500</td>
</tr>
<tr>
<td>By+Hawleri_hacker</td>
<td>144.217.81.160</td>
<td>500</td>
</tr>
</tbody>
</table>
<p>Since the attacks have been going on for some days, Google has already started to index some of these defacements.</p>
<figure id="attachment_2615" aria-describedby="caption-attachment-2615" style="width: 967px" class="wp-caption alignnone"><a href="https://t3dus.com/wp-content/uploads/2017/02/Google-Results.png"><img decoding="async" class="wp-image-2615 size-full" src="https://t3dus.com/wp-content/uploads/2017/02/Google-Results.png" width="967" height="560" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Google-Results.png 967w, https://mattcrawford.me/wp-content/uploads/2017/02/Google-Results-300x174.png 300w, https://mattcrawford.me/wp-content/uploads/2017/02/Google-Results-768x445.png 768w" sizes="(max-width: 967px) 100vw, 967px" /></a><figcaption id="caption-attachment-2615" class="wp-caption-text">Defaced websites indexed by Google</figcaption></figure>
<p>Currently, the groups using the REST API flaw to deface websites are only doing it for public brand exposure, only altering page titles and their content by adding their own name.<br />
<a href="https://t3dus.com/wp-content/uploads/2017/02/Defaced-Site.png"><img decoding="async" class="size-full wp-image-2616" src="https://t3dus.com/wp-content/uploads/2017/02/Defaced-Site.png" alt="" width="967" height="537" srcset="https://mattcrawford.me/wp-content/uploads/2017/02/Defaced-Site.png 967w, https://mattcrawford.me/wp-content/uploads/2017/02/Defaced-Site-300x167.png 300w, https://mattcrawford.me/wp-content/uploads/2017/02/Defaced-Site-768x426.png 768w" sizes="(max-width: 967px) 100vw, 967px" /></a> One of the defaced sites</p>
<p>Sucuri&#8217;s CTO, Daniel Cid, <a href="https://blog.sucuri.net/2017/02/wordpress-rest-api-vulnerability-abused-in-defacement-campaigns.html" target="_blank" rel="nofollow noopener noreferrer">expects to see</a> professional defacers enter the fold, such as SEO spam groups that will utilize the vulnerability to post more complex content, such as links and images.</p>
<p>This types of defacements are used to boost the SEO ranking of other sites or promote shady products. Websites that suffer from SEO-targeted defacements also have their SERP (Search Engine Result Page) indicator affected and risk losing their reputation on search engines, which in turns drives down traffic to their site.</p>
<p>Website owners are advised to update to WordPress 4.7.2. as soon as possible in order to avoid losing visibility on Google due to this REST API security issue.</p>
<p>Source: <a href="https://www.bleepingcomputer.com/news/security/over-67-000-websites-defaced-via-recently-patched-wordpress-bug/">Bleeping Computer</a></p>The post <a href="https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/">Over 67,000 Websites Defaced via Recently Patched WordPress Bug</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/over-67000-websites-defaced-via-recently-patched-wordpress-bug/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2613</post-id>	</item>
	</channel>
</rss>
