Thousands of WordPress sites sucked into BlackHole
Researchers have discovered a spike in malware infecting thousands of WordPress websites that use a popular image tool.
The attacks came to light after French media outlet, The Poitou-Charentes Journal, began hosting on malicious code on its WordPress site. Avast senior researcher Jan Sirmer found attackers had exploited weak FTP server authentication credentials and a vulnerability in the TimThumb image resizer to upload malicious PHP files to the site.
The attack used the BlackHole exploit kit, which redirected the website's visitors to an external malware-hosting site. Researchers detected an additional 3,500 unique infected WordPress sites, which redirected visitors to malicious sites between Aug. 28 to 31. During September , the company blocked redirects from 2,515 WordPress sites, Sirmer said.