SlideShare une entreprise Scribd logo
1  sur  2
Télécharger pour lire hors ligne
FBI Issues PSA: ISIL Defacements Exploiting WordPress
Vulnerabilities by @mattsouthern
The Federal Bureau of Investigation (FBI) has issued a public service announcement about
continuous website defacements occurring as a result of a vulnerability in the WordPress content
management system.
The FBI reports these defacements are being carried out by individuals sympathetic to the Islamic
State in the Levant (ISIL) a.k.a. Islamic State of Iraq and al-Shams (ISIS).
"The defacements have affected Web site operations and the communication platforms of news
organizations, commercial entities, religious institutions, federal/state/local governments, foreign
governments, and a variety of other domestic and international Web sites."
Only websites running on the WordPress content management system are vulnerable to these
particular exploits. Since the attackers are using "relatively unsophisticated" methods to gain access
to WordPress sites, the defacements are apparently easy to fix, but can certainly cause a disruption
to business operations.
Although easy to fix, it is a serious issue because the vulnerability could result in an attacker taking
full control over a website.
If your website has been targeted, the FBI recommends taking the following actions:
Review and follow WordPress guidelines:
Identify WordPress vulnerabilities using free available tools such as
Update WordPress by patching vulnerable plugins:
Run all software as a non-privileged user, without administrative privileges, to diminish the effects
of a successful attack
Confirm that the operating system and all applications are running the most updated versions
Since websites being attacked are compromised through vulnerabilities in WordPress plugins, one
way to protect yourself from an attack is to keep your plugins updated.
Accoring to WordPress securing blog Sucuri, the top 2 plugins currently being exploited are:
RevSlider (Version 4.2), and GravityForms (Version v1.8.20). Note that only older versions of these
plugins are being exploited, so if you have the latest versions installed you should be protected.
In addition, there have also been attacks reported against several other plugins, including FancyBox,
Wp Symposium, Mailpoet and others. Attackers are said to be exploiting anything they can get their
hands on, so the best course of action is to update everything.
Matt Southern is the lead news writer at Search Engine Journal. His passion for helping people in all
aspects of online marketing flows through in the expert articles he contributes to many well
respected publications across the web. Contact him via his website if you'd like him to write for you.
Latest posts by Matt Southern (see all)

Contenu connexe

En vedette

Transferencias relacion ganar ganar
Transferencias relacion ganar ganarTransferencias relacion ganar ganar
Transferencias relacion ganar ganarmeymeymaymay
 
April 9, 2015 Meetup: A deep dive into site maps and wireframes
April 9, 2015 Meetup: A deep dive into site maps and wireframesApril 9, 2015 Meetup: A deep dive into site maps and wireframes
April 9, 2015 Meetup: A deep dive into site maps and wireframesMickey Mellen
 
Mathew Knowles: Get Heard
Mathew Knowles: Get HeardMathew Knowles: Get Heard
Mathew Knowles: Get HeardMathew Knowles
 
Flinch Packaging - Concepts
Flinch Packaging - ConceptsFlinch Packaging - Concepts
Flinch Packaging - ConceptsPete Oliva
 
Mercado de oficinas Bogotá, 2014 T4 - Colliers
Mercado de oficinas Bogotá, 2014 T4 - ColliersMercado de oficinas Bogotá, 2014 T4 - Colliers
Mercado de oficinas Bogotá, 2014 T4 - ColliersWorld Office Forum
 
Drupal 8 + Symfony 2 = une équipe gagnante
Drupal 8 + Symfony 2 = une équipe gagnanteDrupal 8 + Symfony 2 = une équipe gagnante
Drupal 8 + Symfony 2 = une équipe gagnanteVanessa David
 
The Perils of Clinical Trial Budgeting
The Perils of Clinical Trial BudgetingThe Perils of Clinical Trial Budgeting
The Perils of Clinical Trial BudgetingPerficient
 
Historia de la educación en españa
Historia de la educación en españaHistoria de la educación en españa
Historia de la educación en españaloreni3
 
Las Escuelas Y Teorías Gerenciales
Las Escuelas Y Teorías GerencialesLas Escuelas Y Teorías Gerenciales
Las Escuelas Y Teorías GerencialesFabianny Fuenmayor
 
Tipos de conexiones para los dispositivos
Tipos de conexiones para los dispositivosTipos de conexiones para los dispositivos
Tipos de conexiones para los dispositivosJanis Maldonado
 
Por qué podemos verder 500 envasadoras anual
Por qué podemos verder 500 envasadoras anualPor qué podemos verder 500 envasadoras anual
Por qué podemos verder 500 envasadoras anualMin Wei Chen
 
THE FALSE ISLAMIC PROPHETS
THE FALSE ISLAMIC PROPHETSTHE FALSE ISLAMIC PROPHETS
THE FALSE ISLAMIC PROPHETSRbbi Mudassar
 

En vedette (16)

Transferencias relacion ganar ganar
Transferencias relacion ganar ganarTransferencias relacion ganar ganar
Transferencias relacion ganar ganar
 
April 9, 2015 Meetup: A deep dive into site maps and wireframes
April 9, 2015 Meetup: A deep dive into site maps and wireframesApril 9, 2015 Meetup: A deep dive into site maps and wireframes
April 9, 2015 Meetup: A deep dive into site maps and wireframes
 
Mathew Knowles: Get Heard
Mathew Knowles: Get HeardMathew Knowles: Get Heard
Mathew Knowles: Get Heard
 
Flinch Packaging - Concepts
Flinch Packaging - ConceptsFlinch Packaging - Concepts
Flinch Packaging - Concepts
 
Mercado de oficinas Bogotá, 2014 T4 - Colliers
Mercado de oficinas Bogotá, 2014 T4 - ColliersMercado de oficinas Bogotá, 2014 T4 - Colliers
Mercado de oficinas Bogotá, 2014 T4 - Colliers
 
Rupesh_Gosavi_CV_
Rupesh_Gosavi_CV_Rupesh_Gosavi_CV_
Rupesh_Gosavi_CV_
 
Drupal 8 + Symfony 2 = une équipe gagnante
Drupal 8 + Symfony 2 = une équipe gagnanteDrupal 8 + Symfony 2 = une équipe gagnante
Drupal 8 + Symfony 2 = une équipe gagnante
 
Modelo de datos
Modelo de datosModelo de datos
Modelo de datos
 
The Perils of Clinical Trial Budgeting
The Perils of Clinical Trial BudgetingThe Perils of Clinical Trial Budgeting
The Perils of Clinical Trial Budgeting
 
Historia de la educación en españa
Historia de la educación en españaHistoria de la educación en españa
Historia de la educación en españa
 
Las Escuelas Y Teorías Gerenciales
Las Escuelas Y Teorías GerencialesLas Escuelas Y Teorías Gerenciales
Las Escuelas Y Teorías Gerenciales
 
Tipos de conexiones para los dispositivos
Tipos de conexiones para los dispositivosTipos de conexiones para los dispositivos
Tipos de conexiones para los dispositivos
 
Por qué podemos verder 500 envasadoras anual
Por qué podemos verder 500 envasadoras anualPor qué podemos verder 500 envasadoras anual
Por qué podemos verder 500 envasadoras anual
 
FiRE esittely
FiRE esittelyFiRE esittely
FiRE esittely
 
THE FALSE ISLAMIC PROPHETS
THE FALSE ISLAMIC PROPHETSTHE FALSE ISLAMIC PROPHETS
THE FALSE ISLAMIC PROPHETS
 
Strategic alliance
Strategic allianceStrategic alliance
Strategic alliance
 

FBI Issues PSA: ISIL Defacements Exploiting WordPress Vulnerabilities by @mattsouthern

  • 1. FBI Issues PSA: ISIL Defacements Exploiting WordPress Vulnerabilities by @mattsouthern The Federal Bureau of Investigation (FBI) has issued a public service announcement about continuous website defacements occurring as a result of a vulnerability in the WordPress content management system. The FBI reports these defacements are being carried out by individuals sympathetic to the Islamic State in the Levant (ISIL) a.k.a. Islamic State of Iraq and al-Shams (ISIS). "The defacements have affected Web site operations and the communication platforms of news organizations, commercial entities, religious institutions, federal/state/local governments, foreign governments, and a variety of other domestic and international Web sites." Only websites running on the WordPress content management system are vulnerable to these particular exploits. Since the attackers are using "relatively unsophisticated" methods to gain access to WordPress sites, the defacements are apparently easy to fix, but can certainly cause a disruption to business operations. Although easy to fix, it is a serious issue because the vulnerability could result in an attacker taking full control over a website. If your website has been targeted, the FBI recommends taking the following actions: Review and follow WordPress guidelines: Identify WordPress vulnerabilities using free available tools such as Update WordPress by patching vulnerable plugins: Run all software as a non-privileged user, without administrative privileges, to diminish the effects of a successful attack Confirm that the operating system and all applications are running the most updated versions Since websites being attacked are compromised through vulnerabilities in WordPress plugins, one way to protect yourself from an attack is to keep your plugins updated. Accoring to WordPress securing blog Sucuri, the top 2 plugins currently being exploited are:
  • 2. RevSlider (Version 4.2), and GravityForms (Version v1.8.20). Note that only older versions of these plugins are being exploited, so if you have the latest versions installed you should be protected. In addition, there have also been attacks reported against several other plugins, including FancyBox, Wp Symposium, Mailpoet and others. Attackers are said to be exploiting anything they can get their hands on, so the best course of action is to update everything. Matt Southern is the lead news writer at Search Engine Journal. His passion for helping people in all aspects of online marketing flows through in the expert articles he contributes to many well respected publications across the web. Contact him via his website if you'd like him to write for you. Latest posts by Matt Southern (see all)