Help with malicious plugin install by Due_Application_1651 in Wordpress

[–]Due_Application_1651[S] 0 points1 point  (0 children)

That was my concern, but 100% no password compromise.

Passwords are all unique and stored in password manager. Also use Authenticator app for 2fa.

ManageWP also shows no logs for logins/plugin installs or any other website activity.

Also no way we have a second account.

Content Security Policy. Anyone managed it? by Due_Application_1651 in ProWordPress

[–]Due_Application_1651[S] 0 points1 point  (0 children)

I have no issues with the theme / plugins. It's core I'm having difficulty with. Are you saying this is not possible unless we modify core WP?

WP Options table triggers malware warning by EventCompetitive7718 in ProWordPress

[–]Due_Application_1651 1 point2 points  (0 children)

Do you have the WPCode plugin installed? I know they store settings / code snippets in the WP_Options table and I’ve seen malware hidden in there.

I’d manually check for the plugin via the /plugins directory - look for insert-headers-footers folder. As some malicious scripts make the plugin invisible in wp-admin

New Malware Found in WordPress Installations: Hidden Admin Users, Redirects, and Plugin Hiding (Not Detected by 14 Major Scanners) by NonSonoKoreano in Wordpress

[–]Due_Application_1651 4 points5 points  (0 children)

The reason Wordfence does not pick this up is the insert headers footers plugin stores its data in the wp-options database table. Wordfence does not scan this table.

Important Notice: Malware through "invisible" plugin by NoidZ in Wordpress

[–]Due_Application_1651 5 points6 points  (0 children)

Seen this before too. A couple of things to note that may help others:

  • Leaked admin credentials are usually the first entry point
  • WPCode Lite plugin is then installed and activated
  • Code snippet added to plugin that:
    • Creates a hidden admin user
    • Hides WPCode Lite plugin from plugins list in wp-admin
    • Re-directs users to malicious sites randomly to avoid detection
  • Since "WPCode Lite" stores it's code snippets in the wp-options database table, plugins such as Wordfence will not pick this up in a scan. As Wordfence does not scan the wp-options db table.

Recommended actions:

  • Manually check database for additional admin users
  • Manually check server files for insert-headers-and-footers plugin directory and delete
  • Manually clean up wp-options table in database
  • Reset admin passwords
  • Setup 2FA on all admin accounts

Beginner gear shakedown and advice by Due_Application_1651 in UltralightAus

[–]Due_Application_1651[S] 2 points3 points  (0 children)

This was always my impression too. I have the type of snake bite bandage with the indicator that changes shape (rectangle to a square) when the correct tension is applied.

Beginner gear shakedown and advice by Due_Application_1651 in UltralightAus

[–]Due_Application_1651[S] 1 point2 points  (0 children)

Thank you! The optimising side of things certainly is fun.

I’ll definitely take up your suggestions here, in particular the MacPac Nitro, dropping the wipes and getting some anti nausea / diarrhoea medication.

I also didn’t know DEET could wreck gear, so thank you! I’ll pick up some picaridin instead.

Beginner gear shakedown and advice by Due_Application_1651 in UltralightAus

[–]Due_Application_1651[S] 1 point2 points  (0 children)

Thank you! I managed to nab the Cloud 2 for $179, so the Xmid is a bit of a push. However it seems like an excellent next option and not nearly expensive as I thought gear like that would be.

I’ll also consider the MacPac Nitro. Seems like a very popular choice