• I’ve seen an automated hack targeting this plugin in my 404 logs.
    The wp-symposium/server/php/index.php file provides an entry point for automatic malware injection – the attacker uploads code to the directory and then runs it.

    DO NOT USE THIS PLUGIN until this is is fixed!

    This is from my 404 log:

    2015-09-02 12:08:28	/wp-content/plugins/wp-symposium/server/php/index.php	Mozilla/5.0 (Windows NT 6.3; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0		94.153.10.149
    2015-09-02 12:08:28	/wp-content/plugins/wp-symposium/server/php/zpqSimONuzMcgD.php	Mozilla/5.0 (Windows NT 6.3; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0		94.153.10.149

Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)

The topic ‘Hackable’ is closed to new replies.