🔰 الأستاذ فاضل عباس اوغلو 🔰
Open in Telegram
قناة متخصصة لنشر الأمور البرمجية وكل ما يتعلق تكنولوجيا المعلومات والامن السيبراني
Show more418
Subscribers
-324 hours
-57 days
+16430 days
Posts Archive
خبر مهم لمستخدمي #WordPress
يعرض البرنامج المساعد WordPress Advanced Custom Fields XSS + 2M موقع للهجمات
وأشار الباحثون إلى أن المشكلة قابلة للاستغلال بغض النظر عما إذا كانت منافذ إدارة cPanel (2080 ، 2082 ، 2083 ، 2086) معرضة خارجيًا أم لا. أفاد الباحثون أن المشكلة قابلة للاستغلال أيضًا لاستهداف مواقع الويب على المنفذين 80 و 443 إذا كانت تدار بواسطة cPanel.
يمكن للمهاجم استغلال المشكلة لاختطاف جلسة cPanel لمستخدم شرعي وتنفيذ أنشطة ضارة ، بما في ذلك تحميل قذيفة ويب والحصول على تنفيذ الأوامر.
WordPress Advanced Custom Fields plugin XSS exposes +2M Sites to Attacks
The researchers pointed out that the issue is exploitable regardless of whether or not the cPanel management ports (2080, 2082, 2083, 2086) are exposed externally. The researchers reported that the issue is also exploitable to target websites on ports 80 and 443 if they are being managed by cPanel.
The attacker can exploit the issue to hijack a legitimate user’s cPanel session and carry out malicious activities, including uploading a web shell and gaining command execution.
@OgluF
دفعت إدارة عمدة مقاطعة سان برناردينو 1.1 مليون دولار فدية
على الرغم من أن مكتب التحقيقات الفيدرالي وهيئات إنفاذ القانون يوصون دائمًا بعدم دفع فدية في هذه الهجمات ، في هذه الحالة ، اختارت الإدارة الدفع على الأرجح لأنه لم يكن لديهم طريقة أخرى لاستعادة الأنظمة المشفرة أو لتجنب الكشف عن البيانات الحساسة.
قال كليفورد نيومان ، مدير مركز USC لأمن أنظمة الكمبيوتر ، لصحيفة Los Angeles Times: "إذا كنت تدفع من خلال عملة مشفرة ، فأنت لا تعرف لمن تدفعها". "يمكن أن يكون كيانًا خاضعًا للعقوبات ، سواء كانت إيران ، أو كوريا الشمالية ، أو منظمة إرهابية".
San Bernardino County Sheriff’s Department Paid a $1.1M Ransom
Despite the FBI and law enforcement bodies always recommend not paying ransom in these attacks, in this case, the department opted to pay likely because they had no other way to recover the encrypted systems or to avoid the disclosure of sensitive data.
“If you’re paying through cryptocurrency, you don’t know who you’re paying it to,” Clifford Neuman, the director of USC’s Center for Computer Systems Security, told the Los Angeles Times. “It could be a sanctioned entity, whether it’s Iran, whether it’s North Korea, whether it’s a terrorist organization”.
@OgluF
