[Plugin: WP-DONATORS] WARNING CONTAINS TROJAN!
-
It appears this plugin is a trojan which creates a back door revealing php_info, your donation log file, plus it injects Google Ads into the page.
This functionality is ‘encrypted’ in a self-unpacking method using gzip, base64, serialize and rot13, 10-levels deep in function.php. If you change the eval to htmlspecialchars, and run in a browser – you will see the next command. Repeat 10 times, until you see the final code, containing both the legitimate ‘flag’ rendering alongside some questionable GET parameter handling.
I’ve seen malware use these techniques so was surprised to see them in an open source plugin.
Unless Eric can explain this, I’d be very cautious of hosting this plugin.
- The topic ‘[Plugin: WP-DONATORS] WARNING CONTAINS TROJAN!’ is closed to new replies.