Hi there,
The kidslug backdoor is mostly utilized by a series of automated malware attack platforms. What they do is target installs of WordPress with weak passwords or with out of date copies of specific types of plugins, particularly ones like Revslider. After gaining access through an existing security bug, they implant the code above to help out put the php superglobal $globals. For them they’d want to put it on a frontend file and our tracking file would be an easy place to do that because it outputs on the frontend
In this case, MonsterInsights itself was never hacked, they just used the plugin editor system built into WordPress. On the contrary, due to it’s popularity and use in many high traffic (Fortune 500 sites) MonsterInsights regularly undergoes complete security audits both internal and external.
We recommend websites use a WAF like Sucuri (they can also help clean up and investigate this type of thing) that can block a lot of the automated WordPress attacks automatically, and to enforce strong passwords for WordPress accounts.
-Chris
Thanks for the quick response. I like your plugin, and will reinstall it once our site is cleaned and secured.
Not a problem!
If you’d like a checklist we recommend to have something to help follow, our company also runs WPBeginner and we maintain a comprehensive checklist of essential tasks to perform to keep your site secure that we update every few months: http://www.wpbeginner.com/wordpress-security/
-Chris
-
This reply was modified 8 years, 2 months ago by
chriscct7.
– wp.org double posted the above reply –
-
This reply was modified 8 years, 2 months ago by
chriscct7.
Hello Chriscct7 and twellibaum
Have you guys found a way to stop them using the plugin editor system built into WordPress?
We are also being plagued by this $globals hack with kidslug and another one that Wordfence picks up (can’t remember what the other is called)
Would luuuuuve to stop these guys!
Thanks.
I was hacked yesterday and MonsterInsights was installed and I then got this message from WP
Warnings:
* The Plugin “Google Analytics for WordPress by MonsterInsights” needs an upgrade (6.2.6 -> 7.0.6).
https://ww.wp.xz.cn/plugins/google-analytics-for-wordpress/#developers
!!!! Also two other files installed xxx.php and db.php
So be warned………….
BTW I went to apply your code for wp-config and it was already there………. so obviously doesn’t work.
-
This reply was modified 7 years, 11 months ago by
goatherd999.