[{"data":1,"prerenderedAt":234},["ShallowReactive",2],{"i-lucide:menu":3,"i-lucide:arrow-up-right":8,"i-lucide:moon":10,"i-lucide:sun":12,"i-lucide:rss":14,"i-simple-icons:github":16,"i-simple-icons:linkedin":18,"post-\u002F2013\u002Fvictim-of-a-xss-attack-speaks":21,"surround-\u002F2013\u002Fvictim-of-a-xss-attack-speaks":221,"i-lucide:arrow-left":230,"i-lucide:arrow-right":232},{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":7},0,24,false,"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M4 5h16M4 12h16M4 19h16\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":9},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M7 7h10v10M7 17L17 7\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":11},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M20.985 12.486a9 9 0 1 1-9.473-9.472c.405-.022.617.46.402.803a6 6 0 0 0 8.268 8.268c.344-.215.825-.004.803.401\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":13},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"4\"\u002F>\u003Cpath d=\"M12 2v2m0 16v2M4.93 4.93l1.41 1.41m11.32 11.32l1.41 1.41M2 12h2m16 0h2M6.34 17.66l-1.41 1.41M19.07 4.93l-1.41 1.41\"\u002F>\u003C\u002Fg>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":15},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M4 11a9 9 0 0 1 9 9M4 4a16 16 0 0 1 16 16\"\u002F>\u003Ccircle cx=\"5\" cy=\"19\" r=\"1\"\u002F>\u003C\u002Fg>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":17},"\u003Cpath fill=\"currentColor\" d=\"M12 .297c-6.63 0-12 5.373-12 12c0 5.303 3.438 9.8 8.205 11.385c.6.113.82-.258.82-.577c0-.285-.01-1.04-.015-2.04c-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729c1.205.084 1.838 1.236 1.838 1.236c1.07 1.835 2.809 1.305 3.495.998c.108-.776.417-1.305.76-1.605c-2.665-.3-5.466-1.332-5.466-5.93c0-1.31.465-2.38 1.235-3.22c-.135-.303-.54-1.523.105-3.176c0 0 1.005-.322 3.3 1.23c.96-.267 1.98-.399 3-.405c1.02.006 2.04.138 3 .405c2.28-1.552 3.285-1.23 3.285-1.23c.645 1.653.24 2.873.12 3.176c.765.84 1.23 1.91 1.23 3.22c0 4.61-2.805 5.625-5.475 5.92c.42.36.81 1.096.81 2.22c0 1.606-.015 2.896-.015 3.286c0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":19,"hidden":20},"\u003Cpath fill=\"currentColor\" d=\"M20.447 20.452h-3.554v-5.569c0-1.328-.027-3.037-1.852-3.037c-1.853 0-2.136 1.445-2.136 2.939v5.667H9.351V9h3.414v1.561h.046c.477-.9 1.637-1.85 3.37-1.85c3.601 0 4.267 2.37 4.267 5.455v6.286zM5.337 7.433a2.06 2.06 0 0 1-2.063-2.065a2.064 2.064 0 1 1 2.063 2.065m1.782 13.019H3.555V9h3.564zM22.225 0H1.771C.792 0 0 .774 0 1.729v20.542C0 23.227.792 24 1.771 24h20.451C23.2 24 24 23.227 24 22.271V1.729C24 .774 23.2 0 22.222 0z\"\u002F>",true,{"id":22,"title":23,"body":24,"category":189,"comments":190,"date":203,"description":30,"excerpt":204,"extension":205,"image":204,"meta":206,"navigation":20,"path":207,"readingTime":208,"seo":209,"stem":210,"subtitle":204,"tags":211,"wordCount":219,"__hash__":220},"posts\u002F2013\u002Fvictim-of-a-xss-attack-speaks.md","Victim of a XSS Attack Speaks",{"type":25,"value":26,"toc":182},"minimark",[27,31,38,41,50,55,58,64,72,75,78,81,86,99,105,108,114,117,125,129,137,143,150,156,159,165,169,172],[28,29,30],"p",{},"Yesterday, my blog was hacked. I woke up at five am in the morning to write a new post and discovered the following:",[28,32,33],{},[34,35],"img",{"alt":36,"src":37},"Hacked webpage","\u002Fcontent\u002F2013\u002F02\u002Fhacked.png",[28,39,40],{},"Frack. Frack for the sake of the time it takes to fix this (I've discovered that time is a very valuable resource, especially in IT).",[28,42,43,44,49],{},"I'm not going to go into my opinions about the motivation or intentions of the attacker - suffice to say it'd be a scolding essay about ",[45,46,48],"a",{"href":47},"http:\u002F\u002Fwww.youtube.com\u002Fwatch?v=IHJVolaC8pw","maturity"," and what matters in life.",[51,52,54],"h2",{"id":53},"point-of-attack","Point of attack?",[28,56,57],{},"My initial thought was that the shared web server had been compromised. Up until this point I used a hosting provider who I had no faith in. The server had had unexpected downtimes (the longest spanning three to four days) and speed problems.",[28,59,60],{},[34,61],{"alt":62,"src":63},"Uptime report","\u002Fcontent\u002F2013\u002F02\u002Fuptime-report.png",[28,65,66,67,71],{},"I used a ",[45,68,70],{"href":69},"http:\u002F\u002Fwww.yougetsignal.com\u002Ftools\u002Fweb-sites-on-web-server\u002F","reverse IP checker tool"," to see if any of the other sites on the same machine were affected. About 10% were.",[28,73,74],{},"Server access logs looked normal - nothing like someone was attempting (and finally succeeding) a brute-force-ish approach. Wordpress file modification times and contents were fine, too.",[28,76,77],{},"The other possibility is of course the database. Unfortunately, I couldn't find the string anywhere. I run a network installation of wordpress and the other domains hosted on the same files, database, were fine - so the attack must be living on the database and only on tables associated with my blog.",[28,79,80],{},"I wrote a letter to the hosting provider, asking them to look into this from their end and to notify the other affected customers and went to work, deciding to deal with this later.",[82,83,85],"h1",{"id":84},"at-it-with-a-rested-head","At it with a rested head",[28,87,88,89,93,94,98],{},"Having narrowed down the location of the problem (the database), I Googled around and ",[45,90,92],{"href":91},"http:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fwebsite-repeatedly-hacked","found a similar topic on the WP forums",". It turns out the blog was working just fine - the HTML renders correctly and is transferred over HTTP (view source). Disabling Javascript fixes the problem. The logical conclusion? A ",[45,95,97],{"href":96},"http:\u002F\u002Fblog.sucuri.net\u002F2012\u002F10\u002Fwordpress-themes-xss-vulnerabilities-and-secure-coding-practices.html","XSS attack",".",[100,101,102],"blockquote",{},[28,103,104],{},"Cross-Site Scripting attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. Cross-site scripting (XSS) attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end-user.",[28,106,107],{},"The blog loads in the visitors browser, but contains a bit of Javascript that activates as soon as the page is rendered and replaces its content with something else. Looking at the page source, this was exactly the case:",[28,109,110],{},[34,111],{"alt":112,"src":113},"Hacked webpage source","\u002Fcontent\u002F2013\u002F02\u002Fhacked-blog-source.png",[28,115,116],{},"The blog engine had been tricked to store and then serve up a snipet of malicious code that transformed the appearance of the blog dramatically, making it practically useless.",[28,118,119,120,124],{},"The code that is injected via a XSS attack could be whatever - code that redirects you to a porn website; something that tries to invade your privacy or in this case, just some digital grafiti. The phrase \"Algerian to the core\" cannot be found from blog files or the database because ",[45,121,123],{"href":122},"http:\u002F\u002Fscriptasylum.com\u002Ftutorials\u002Fencode-decode.html","it is encoded"," and then decoded on runtime.",[51,126,128],{"id":127},"fixing-the-problem","Fixing the problem",[28,130,131,132,136],{},"A search for the encoded text in PMA quickly found the exploited record in the ",[133,134,135],"em",{},"wp_options"," table.",[28,138,139],{},[34,140],{"alt":141,"src":142},"XSS in PMA","\u002Fcontent\u002F2013\u002F02\u002Fpma.png",[28,144,145,146,149],{},"The attack had targeted a Widget and replaced its contents with a script. Looking under ",[133,147,148],{},"Appearance -> Widgets"," revealed that my previous widgets had been deleted and replaced with a Text Widget that served the malicious code.",[28,151,152],{},[34,153],{"alt":154,"src":155},"Hacked widget","\u002Fcontent\u002F2013\u002F02\u002Fhacked-widget.png",[28,157,158],{},"Delete the widget and suddenly everything works again. The blog name and character encoding (Settings -> Reading) also needed changing. The encoding was set to UTF-7.",[28,160,161],{},[34,162],{"alt":163,"src":164},"UTF-7 encoding","\u002Fcontent\u002F2013\u002F02\u002Futf.png",[51,166,168],{"id":167},"afterthoughts","Afterthoughts",[28,170,171],{},"I never learned the original point of entry - the \"how\" and \"where\" the attack entered my system. I put it down to having insecure versions of certain third party extensions and reset my security. The incident caused me quite a bit of inconvenience, but also gave the incentive to finally switch to a better hosting provider. As the morale of the story: don't assume your stuff is secure, ever. Have backups. Be paranoid. And teach your friends about this stuff, like I hope this post will do.",[28,173,174,175,178],{},"Read more: ",[45,176],{"href":177},"http:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fcalling-all-site-owners-hacked-by-walangkaji-badi-etc-need-some-help?replies=83",[45,179,177],{"href":177,"rel":180},[181],"nofollow",{"title":183,"searchDepth":184,"depth":184,"links":185},"",2,[186,187,188],{"id":53,"depth":184,"text":54},{"id":127,"depth":184,"text":128},{"id":167,"depth":184,"text":168},"Misc",[191,197],{"id":192,"author":193,"author_url":194,"date":195,"content":196},1207,"Artjom Kurapov","http:\u002F\u002Fkurapov.name","2013-02-24 01:03:42 +0200","Maybe its not the hosting, its your misconfiguration, or old Wordpress holes?",{"id":198,"author":199,"author_url":200,"date":201,"content":202},1208,"David","http:\u002F\u002Fsqroot.eu","2013-02-24 01:09:10 +0200","My Wordpress core is\u002Fhas been\u002Fwill be the latest, I upgrade relatively quick. Misconfiguration - quite possible. My strongest suspects are still 3rd party addons, tho: themes and plugins.","2013-02-10",null,"md",{},"\u002F2013\u002Fvictim-of-a-xss-attack-speaks","about 3 minutes",{"title":23,"description":30},"2013\u002Fvictim-of-a-xss-attack-speaks",[212,213,214,215,216,217,218],"security","vulnerability","hacking","xss","wordpress","spam","attack",698,"f8HCZbX7pN29c2dRD7ZkJYGz5T5E8YQYXlQbSMU2EAY",[222,226],{"title":223,"path":224,"stem":225,"children":-1},"Self-Lighting LED Lantern","\u002F2013\u002Fself-lighting-led-lantern","2013\u002Fself-lighting-led-lantern",{"title":227,"path":228,"stem":229,"children":-1},"A Bit Pissed About Kohana Affairs","\u002F2013\u002Fa-bit-pissed-about-kohana-affairs","2013\u002Fa-bit-pissed-about-kohana-affairs",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":231},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m12 19l-7-7l7-7m7 7H5\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":233},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 12h14m-7-7l7 7l-7 7\"\u002F>",1790886933103]