5 ms·
Timeline: 2021-09-22: Jetpack Scan team discovers the dropper and back door in the FotoGraphy theme, and tries to contact vendor about the initial finding. 20
by Helithumper 5y ago
Timeline:
2021-09-22: Jetpack Scan team discovers the dropper and back door in the FotoGraphy theme, and tries to contact vendor about the initial finding.
2021-09-27: Confirm presence of dropper + back door in all current free plugins and themes downloaded from vendors website.
2021-09-28: Confirm that dropper + back door is not present on downloads from wordpress.org
2021-09-29: Trying to contact vendor again, with updates on new findings.
2021-10-14: Escalated to WordPress plugins team to try to obtain contact with the vendor.
2021-10-15: Compromised extensions are removed from the vendor’s site.
2021-10-16: Response from vendor
2022-01-17: Most plugins have been upgraded to new versions, themes have been pulled from WordPress.org.
2022-01-18 Public disclosure
- zzleeper 5y agoThat's really pathetic, to put it mildly. Three weeks between initial contact and removal of compromised themes. Four months until public disclosure.
- smoe 5y agoPublic disclosure by the people that found the backdoor. I couldn't find any disclosure about it by AccessPress themselves between 15. October when they pulled the compromised themes and plugins to now.
- freebreakfast 5y agoThriveThemes still hasn't released a disclosure on an attack from March 2021.[0] This seems to be par for the course among theme developers. 0. https://www.wordfence.com/blog/2021/03/recently-patched-vulnerability-in-thrive-themes-actively-exploited-in-the-wild/ https://www.wordfence.com/blog/2021/03/recently-patched-vuln...
- benatkin 5y agoI never download from anywhere but wordpress.org and a lot of others don't, and that wasn't attacked, so I disagree that it's "pathetic".
- IncRnd 5y agoThat's not the timeline. It was a single day from contact to removal of compromised plugins. According to the article, the issue was that the vendor's contact form didn't work, not that the vendor didn't quickly remove the plugins. You are also confusing plugins with themes. They are not exactly the same.
- jcun4128 5y ago> vendor's contact form didn't work Had this happen recently to a site. The SMTP password was set wrong and I don't know how many months/years this form just failed to submit but no one was aware of it... was for a landing page type site.
- john-doe 5y ago> The attack was discovered by researchers at Jetpack, the creators of a security and optimization tool for WordPress sites. It’s a deceitful way to present it. Jetpack and WordPress are the same company.
- monkey_monkey 5y agoIt's not deceitful at all. Anyone who's in the WP ecosystem understands this. Jetpack is part of Automattic. Automattic's main thing is wordpress.com (the hosted platform). Automattic and WP.org are not the same thing even though ( as with many open source projects that have commercial implications) the lines are somewhat blurred. Presenting this as "deceitful" is really quite the over-reaction.
- john-doe 5y agoIf the lines are somewhat blurred, you can understand my initial confusion, not being “in the WP ecosystem” myself.
- monkey_monkey 5y agoSure. but perhaps think about the use of emotive words like "deceitful" when you don't fully understand what's going on?
- john-doe 5y agoEnglish as third language, so let’s say I didn’t realise it was such a strong word.
- Kye 5y agoEnglish is a mess. Deceitful implies intention. Qualifiers help. "Unintentionally misleading" fits better. It's like the difference between manslaughter (whoopsiedeath) and murder (intentional).
- 5y ago
- hanniabu 5y agoSo isn't the reasonable deduction here that the vendor was responsible for this given it was present on their website but not on the plugins through Wordpress? They probably didn't have the back door on the wordpress plugins because those would face a higher scrutiny than the ones on their site. Finally they get caught and go silent, but then when wordpress knows they finally respond because they know the jig is up and are trying to save face.
- dannyw 5y agoI don't think that's a reasonable deduction, it seems like the contact form on the vendor's website didn't work. That could possibly be compromised by the attacker.
- ehnto 5y agoI think the more reasonable deduction is that the vendor's website was compromised, and that's where the attacker was able to introduce new files.