{"id":8403,"date":"2015-02-26T20:13:04","date_gmt":"2015-02-27T01:13:04","guid":{"rendered":"http:\/\/www.techwalls.com\/?p=8403"},"modified":"2015-02-26T20:13:04","modified_gmt":"2015-02-27T01:13:04","slug":"web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers","status":"publish","type":"post","link":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/","title":{"rendered":"Web analytics plugin vulnerability exposes millions of WordPress sites to hijackers"},"content":{"rendered":"<p>A web analytics plugin has been one of the most useful tools for keeping tabs with how your website is performing and making decisions based on the data it provides. But when things go bad, it could also bring tremendous damage to your site.<!--more--><\/p>\n<p>Marc-Alexandre Montpas, a security researcher, discovered a vulnerability in the WP-Slimstat plugin that could potentially expose your website to the manipulative techniques of malicious hackers through SQL injection attacks. Based on the number of downloads for this plugin, more than a million websites are now susceptible to a complete takeover by the bad actors due to this vulnerability.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8407\" src=\"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg\" alt=\"wordpress-hijacked\" width=\"492\" height=\"325\" srcset=\"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg 492w, https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked-300x198.jpg 300w\" sizes=\"auto, (max-width: 492px) 100vw, 492px\" \/><\/p>\n<p>Once an attacker perpetrates several SQL injection attacks, he could then view sensitive information from your website\u2019s database usernames, hashed passwords and secret keys. This WP-Slimstat vulnerability also makes it easy for a hijacker to determine the value of what key this plugin uses to log data transmitted and received from the user.<\/p>\n<p>By just guessing the key\u2019s value, everything else will follow smoothly. This essentially makes the secrecy of the WordPress secret key, well, a little less secretive.<\/p>\n<p>Here\u2019s what is happening under the hood. The plugin\u2019s installation timestamp is being shielded in the key as a hashed version to keep it safe from eavesdroppers. Meaning, the key contains the data about when the plugin was installed in your website.<\/p>\n<p>Even the least tech savvy guy will know how to find out this data by juts looking into the home page\u2019s archive. That\u2019s what makes it easy for hijackers to take advantage of this plugin vulnerability.<\/p>\n<p>Once this information is obtained, the hacker can then pair the key with timestamps that come from the WP-Slimstat in order to carry out the SQL injection attack. This is made even worse by the fact that SQL attacks are nothing new to attackers as they are only meant to query a database using questions answerable by true or false values. For the WP-Slimstat vulnerability, all a hijacker needs to do is brute force the website\u2019s timestamps in order to extract the exact string of characters that are based from the site\u2019s home page.<\/p>\n<p>Good thing is, the plugin has been updated in order to address this issue. So those websites that still use the older version of the plugin remain vulnerable to SQL injection attacks. It is highly advisable for them to update to the latest version of the plugin because of the severe consequences this vulnerability might bring upon your site.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A web analytics plugin has been one of the most useful tools for keeping tabs with how your website is performing and making decisions based on the data it provides. But when things go bad, it could also bring tremendous damage to your site.<\/p>\n","protected":false},"author":89,"featured_media":8407,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[9],"tags":[52,387,28],"class_list":{"0":"post-8403","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"tag-news-2","9":"tag-security","10":"tag-wordpress","11":"entry"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Web analytics plugin vulnerability exposes millions of WordPress sites to hijackers<\/title>\n<meta name=\"description\" content=\"A web analytics plugin has been one of the most useful tools for keeping tabs with how your website is performing and making decisions based on the data it provides.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Guest Authors\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/\",\"url\":\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/\",\"name\":\"Web analytics plugin vulnerability exposes millions of WordPress sites to hijackers\",\"isPartOf\":{\"@id\":\"https:\/\/www.techwalls.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg\",\"datePublished\":\"2015-02-27T01:13:04+00:00\",\"dateModified\":\"2015-02-27T01:13:04+00:00\",\"author\":{\"@id\":\"https:\/\/www.techwalls.com\/#\/schema\/person\/440f216965cffca997e53e754f489c84\"},\"description\":\"A web analytics plugin has been one of the most useful tools for keeping tabs with how your website is performing and making decisions based on the data it provides.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#primaryimage\",\"url\":\"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg\",\"contentUrl\":\"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg\",\"width\":492,\"height\":325},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.techwalls.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"News\",\"item\":\"https:\/\/www.techwalls.com\/news\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Web analytics plugin vulnerability exposes millions of WordPress sites to hijackers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.techwalls.com\/#website\",\"url\":\"https:\/\/www.techwalls.com\/\",\"name\":\"TechWalls\",\"description\":\"Technology News | Gadget Reviews | Tutorials\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.techwalls.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.techwalls.com\/#\/schema\/person\/440f216965cffca997e53e754f489c84\",\"name\":\"Guest Authors\",\"url\":\"https:\/\/www.techwalls.com\/author\/guestauthor\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Web analytics plugin vulnerability exposes millions of WordPress sites to hijackers","description":"A web analytics plugin has been one of the most useful tools for keeping tabs with how your website is performing and making decisions based on the data it provides.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/","twitter_misc":{"Written by":"Guest Authors","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/","url":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/","name":"Web analytics plugin vulnerability exposes millions of WordPress sites to hijackers","isPartOf":{"@id":"https:\/\/www.techwalls.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#primaryimage"},"image":{"@id":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg","datePublished":"2015-02-27T01:13:04+00:00","dateModified":"2015-02-27T01:13:04+00:00","author":{"@id":"https:\/\/www.techwalls.com\/#\/schema\/person\/440f216965cffca997e53e754f489c84"},"description":"A web analytics plugin has been one of the most useful tools for keeping tabs with how your website is performing and making decisions based on the data it provides.","breadcrumb":{"@id":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#primaryimage","url":"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg","contentUrl":"https:\/\/www.techwalls.com\/wp-content\/uploads\/2015\/02\/wordpress-hijacked.jpg","width":492,"height":325},{"@type":"BreadcrumbList","@id":"https:\/\/www.techwalls.com\/web-analytics-plugin-vulnerability-exposes-millions-wordpress-sites-hijackers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.techwalls.com\/"},{"@type":"ListItem","position":2,"name":"News","item":"https:\/\/www.techwalls.com\/news\/"},{"@type":"ListItem","position":3,"name":"Web analytics plugin vulnerability exposes millions of WordPress sites to hijackers"}]},{"@type":"WebSite","@id":"https:\/\/www.techwalls.com\/#website","url":"https:\/\/www.techwalls.com\/","name":"TechWalls","description":"Technology News | Gadget Reviews | Tutorials","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.techwalls.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.techwalls.com\/#\/schema\/person\/440f216965cffca997e53e754f489c84","name":"Guest Authors","url":"https:\/\/www.techwalls.com\/author\/guestauthor\/"}]}},"_links":{"self":[{"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/posts\/8403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/users\/89"}],"replies":[{"embeddable":true,"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/comments?post=8403"}],"version-history":[{"count":0,"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/posts\/8403\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/media\/8407"}],"wp:attachment":[{"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/media?parent=8403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/categories?post=8403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.techwalls.com\/wp-json\/wp\/v2\/tags?post=8403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}