6 ms·
The main goal of the high-ranking templates seems to be to add links to specific sites (to boost their PageRank). Those links are unobfuscated for the search bo
by jmah 16y ago
The main goal of the high-ranking templates seems to be to add links to specific sites (to boost their PageRank). Those links are unobfuscated for the search bots, with the encoded JS serving to replace them for humans. So mortenjorck's suggestion would still apply.
However, including any JavaScript is arbitrary exploitation, but perhaps there's less of an incentive once the Google-bombing aspect is removed.
- damncabbage 16y agoIt's less javascript than PHP you've got to worry about; that javascript obfuscation article was a nice example of how much you can mangle a language to hide things. For example, in your Wordpress template, put the following snippet in: <?php echo urldecode('%68%74%74%70%3A%2F%2F%67%6F%6F%67%6C%65%2E%63%6F%6D'); This will display "http://google.com http://google.com on your page. Okay. So how about looking for urldecode (a perfectly useful function, with uses not restricted to hacking)? <?php $f=chr('117').chr('114').chr('108').chr('100').chr('101').chr('99').chr('111').chr('100').chr('101'); echo $f('%68%74%74%70%3A%2F%2F%67%6F%6F%67%6C%65%2E%63%6F%6D'); ... And so on, ad infinitum. Looking for particular sequences (%68%74%74%70%3A%2F%2F --> http:// http://)? Add numbers together at run-time. Looking for a block of these together? Spread them out, or construct them from innocuous-looking things. It's a game you're not going to win.
- cookiecaper 16y agoIt shouldn't be that hard to run a search on a rendered page automatically. Assuming someone is embedding a URL in what ultimately becomes plaintext, then it should be easy to look for suspicious links on the final rendering. There's still JS obfuscation, but that would at least exclude most PHP-based obfuscation.
- nbpoole 16y agoThat's completely untrue :P You're assuming that there is some supreme Rendering Engine which maps code to a single canonical output. In reality, every browser renders things slightly differently and a malicious script would take advantage of that (while rendering things "normally" for the scanner). See also: cloaking (http://en.wikipedia.org/w/index.php?title=Cloaking&oldid=408912417 http://en.wikipedia.org/w/index.php?title=Cloaking&oldid...)
- cookiecaper 16y agoYou're right of course, but again, the scanner would not go after sophisticated or complex attacks, but naive attacks implemented by posers. It's just a matter of time before everything we currently consider "secure" is cracked; I reckon that eventually they'll have computers that can bruteforce 2048-bit encryption keys (and I've seen all of the theoretical calculations about the computing power needed to do that, so we don't need to repeat that here) in a day or less. That doesn't mean we shouldn't make the best of what we have at our disposal, whether that's encryption or detection techniques to catch at least some bad guys.
- mnutt 16y agoBy the time you've rendered the page, it's already too late. In rendering the page you're running the untrusted code. Wordpress themes are a double-edged sword--Wordpress became what it is today because of the flexibility that themes provide, but it comes at a cost. Other theming engines traded flexibility for security, and as a result aren't nearly as popular.