Malicious Plugin Used to Encrypt WordPress Posts

http://feedproxy.google.com/~r/sucuri/blog/~3/KfFfwCGn5Tg/malicious-plugin-used-to-encrypt-wordpress-posts.html During a recent cleanup, we found an interesting malicious WordPress plugin, “WP Security”, that was being used to encrypt blog post content. The website owner complained of a newly installed and activated plugin on their website that was rendering their original content unreadable. The plugin encrypted posts with the ‘AES-256-CBC’ method by using the […] More info: http://feedproxy.google.com/~r/sucuri/blog/~3/KfFfwCGn5Tg/malicious-plugin-used-to-encrypt-wordpress-posts.html

DSA-4491 proftpd-dfsg – security update

Tobias Maedel discovered that the mod_copy module of ProFTPD, aFTP/SFTP/FTPS server, performed incomplete permission validation forthe CPFR/CPTO commands. More info: https://www.debian.org/security/2019/dsa-4491

WordPress File Permissions: A Guide to Securing Your Website

https://ithemes.com/wordpress-file-permissions/WordPress file permissions and ownership play an integral role in the overall security of your WordPress website, which is why you should be sure to get them right. In this post, we’ll cover all you need to know about WordPress file permissions. Whether you’re a blogger or business owner, the simplicity of WordPress means that […] More info: https://ithemes.com/wordpress-file-permissions/
Translate »