Recently my blog that runs Newspaper theme was hacked several times: database was modified, login account was changed… I use Dreampress service from Dreamhost and after a while, they came with the issue: the Revolution Slider plugin that comes with the theme is a vulnerable plugin! I am posting their message to me about it that says Revolution Slider version 4.6 fix the problem. I wonder if the latest Newspaper version fix that with a newer version of Rev Slider also?
Thanks.
————————————————————————
Hello,
Thanks for writing.
I found that you have the vulnerable plugin “revslider” (Revolution
Slider) installed here:
/home/wp_xv8mei/…../wp-content/plugins/revslider
This has a file disclosure vulnerability that could allow a hacker to
read your wp-config.php file. This would give them access to your MySQL
database, which in turn would give them access to your WordPress
dashboard, which in turn would give them access to your WordPress theme
and plugin files, which they could then edit and add malicious code to.
That malicious code could then be used to infect the rest of your site.
Here’s the relevant log:
179.178.117.187 – – [28/Aug/2014:09:21:57 -0700] “GET
/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
HTTP/1.1” 200 3300
“http://blog.inurl.com.br/5a046effaaf2c5fa9eceb38473cd62a7”
“0xSCANNER-INURL_blog.inurl.com.br-Flock/9.5 (Ubuntu 3.1; da;)”
179.178.117.187 – – [28/Aug/2014:09:22:00 -0700] “GET
/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
HTTP/1.1” 200 3300 “-” “curl/7.26.0”
179.178.117.187 – – [28/Aug/2014:09:22:03 -0700] “GET
/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
HTTP/1.1” 200 3302 “-” “curl/7.26.0”
The developer recently fixed that vulnerability as of version 4.6. They
didn’t announce it as a security update but we tested it to confirm. So
make sure to update it now.
To test the exploit, visit the following URL:
http://…../wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
If the vulnerability is still active, visiting this URL will download a
file named “admin-ajax.php” to your computer. This file will actually
contain the code from your “wp-config.php” file.
(…)
Note that for those who want to fast-track it, you can buy a licensed copy of RevSlider. (I don’t know if this is necessary; I just happened to have bought it a little while back to keep it constantly updated, so I guess I lucked out)
The version included with the theme update today has newer version.
Version 4.6 SkyWood (25th August 2014)
NEW FEATURES
â˘Option to disable each video on mobile
â˘Option to disable Pan Zoom on Mobile
â˘Option to disable Parallax on Mobile
â˘Randomized Animation from the Selected Animations available now
â˘New Offset option for the Scroll Below Function
â˘New Option to set Slider Min Height – Content will be vertical centered in case content container is smaller then min height of Slider
â˘New Loop Options for HTML5 Videos: none, loop and stop Slider Timer or Loop till Progress Bar reaches the End
CHANGES
â˘Alternative First Slide wins now, even if Random Slides is enabled
â˘Vimeo, YouTube and HTML5 Video can be added now via options on demand instead of preadding iFrames. This will avoid Preloads delays, and slow site loadings
â˘Using now tp-videolayer class for Videos to identificate Video Layers better
â˘Class “current-sr-slide-visible” added to the Slide “li” tag which is currently Visible
â˘Swipe Engine Change
â˘Swipe Treshold Option Default 75 – The number of pixels that the user must move their finger by before it is considered a swipe.
â˘Swipe Min Finger Default 1 – Min Finger (touch) used for swipe
â˘Drag Block Vertical Default false – Scroll Auto below Slider on Vertical Swipe on Slider
BUGFIXES
â˘YouTube Force Rewind fix
â˘YouTube Mute in Second Loop fix
â˘Added backwards compatibility for inline CSS with WordPress versions under 3.7
â˘Ken Burns Dotted Overlay was not visible
â˘IE8 Console Group Issue – Slider was not visible in IE8
â˘Looping Issues if Slides has been manually hanged after Loop Stopped
â˘Browser Tab Change -> Broken ELements fixed. Option for Slide Change on Blur Tab / Browser also available.
â˘Navigation Style Preview1- Preview4 Styling issues
â˘Power2 Error at some Animation
â˘Mouse Over on Loaded PArallax Slider issue – Slider will always play parallax effect, even if Mouse was already hovering the slider at laod
â˘IE8 and other Old MObile Devices Fall Back on simple Transitions. CAn be forced now
â˘HTML5, YouTube and Vimeo Video Playback fixes
@mmcmsp
BTW: the version of the Themepunch Revolution Slider plugin which was included with Newspaper 4 was “Version 4.3.8 SkyWood”; and themepunch says the vulnerability only existed in version 4.1.4 and older (which is the version included with Newspaper 3), so obviously those of you updating your themes need to remember to install the updated PLUGINS which come bundled with the theme.
Can you confirm the version of the plugin which was hacked; supposedly the last 29 versions of the plugin have been secure.
If you’re using a more recent version, you should definitely contact themepunch to make them aware of the issue to help others from being hacked also.
-
This reply was modified 11 years by
simchris.
@neotrope
I don’t know the version because when this happened I just installed the latest version of Rev Slider 4.6 replacing the old one. My Newspaper theme is 3.5 BUT I remember when I did the latest theme update I didn’t install the themes again…. so it’s probably an old version…
Thanks!
