Ta kontakt med oss

WORDPRESS

Kreditkortsstjälare riktar sig till WordPress-betalningsplugin-program

Publicerad

Kreditkortsstjälare riktar sig till WordPress-betalningsplugin-program

Card Not Present Fraud
,
Fraud Management & Cybercrime

MageCart Operators Hide Infection in Legitimate Payment Processing Software

Image: Shutterstock

Hackers have repurposed credit card-stealing malware to attack WordPress websites that use a popular e-commerce plug-in to capture and steal payment card details, security researches warn.

See Also: LIVE Webinar | Stop, Drop (a Table) & Roll: An SQL Highlight Discussion

Attackers are deploying modified MageCart malware against WordPress websites that use the WooCommerce shopping cart plug-in, says website security firm Sucuri. WordPress plug-in developers Barn2 calculate that more than 40% of “all known online stores” use the plug-in.

An “overwhelming majority” of credit card-skimming malware that Sucuri finds on compromised e-commerce environments target WooCommerce. The modified MageCart injects PHP code into a plug-in file that facilitates the handling of payment data to Authorize.net, a popular Visa-owned payment gateway often used in conjunction with WooCommerce. The injected code checks whether web traffic from infected websites contains a string for payment card numbers. If it does, it dumps an encrypted copy of the card number into a .jpg file for later downloading.

“Dumping stolen credit card info to an image file is an old trick that we have identified attackers doing for quite a few years,” Sucuri writes.

Se även  Hackare injicerar kreditkortsstöldare i betalningsbehandlingsmoduler

The vulnerabilities in question don’t originate with WooCommerce or Authorize.net, Sucuri says, and instead highlight the importance of good website security.

The modified MageCart malware also injects JavaScript into the payment gateway code to capture data such as cardholder name, address, phone number and postal code – data that increases the value of stolen payment card data on the black market.

The malware emulates the WordPress Heartbeat API to evade detection, Sucuri says.
MageCart derives its name from its original target, the Magento e-commerce platform. Hackers have used it to breach British Airways, unsecured Amazon Web Services cloud storage accounts and jewelry chain Claire’s.

Sucuri says it found the modified MageCart malware after a client received a warning from their bank that their website had been identified as potentially compromised since cards used legitimately on the client website had later been used fraudulently.

“If malicious actors compromise an environment they can tamper with existing controls,” irrespective of a plug-in’s security controls, Sucuri says.



Källlänk

Håll ett öga på vad vi gör
Bli först med att få de senaste uppdateringarna och exklusivt innehåll direkt till din e-postinkorg.
Vi lovar att inte spamma dig. Du kan avbryta prenumerationen när som helst.
Ogiltig e-postadress

WORDPRESS

Anpassade temadesigner blev precis enklare – WordPress.com Nyheter

Publicerad

Anpassade temadesigner blev precis enklare – WordPress.com Nyheter

Patterns, colors, fonts, and more. Our new homepage design tool guides you through making your creative vision a reality.

Whether you want a simple blog that highlights recent posts, a visually stunning portfolio, or an online home for your small business, your website should be just as unique as you are. That’s why we’re excited to introduce a new site design tool that guides you through the process of creating a memorable custom homepage. 

Our designers have put together a library of hundreds of patterns, colors, and fonts that you can mix and match for whichever distinctive vibe you’re going for. 

Try it out today by clicking the button below:

Create your own design

When you create a new site at WordPress.com, you’ll now find the option to start from a Blank Canvas. This is where you become the designer (with a little help from us): We’ll guide you through decisions on layout, colors, fonts, and more. No matter your goals for your site, we have the building blocks to help you turn your creative vision into reality. 

Pick the perfect palette 

Paint your patterns with the click of a button, applying custom color palettes to your entire page via our global styles feature. Our simple tools allow you to take the artistic lead on your site. Are you Blueberry Sorbet? Midnight Citrus? Perhaps a moody Charcoal? We have dozens of colorful options to set a mood that works for you and your audience.

Se även  Hackare injicerar kreditkortsstöldare i betalningsbehandlingsmoduler

Find a fitting font

Whether something stately and classic or sleek and modern, the typeface you use sets the tone for everything you’re trying to do with your site. Our thoughtful and engaging one-click font pairings will have you feeling like an expert typographer in no time.

Edit with ease

Patterns? Check. Colors? Check. Fonts? Check. You’ve got the basics of your site set up. Now it’s time to harness the power of the Site Editor. Bring your page to life by adding images, content, products to sell, and more. As you get comfortable, continue to experiment by adding or removing patterns, playing with colors and fonts, and making your site look and feel exactly the way you want it to. 

Click below to get started with our DIY site assembler:

Läs mer 

Need some extra help? Our new Quick Launch course will guide you through what to include on a compelling homepage, and how to tie it together with our new DIY design assembler. Additionally, here’s a few more resources to get you started with designing on WordPress.com:


Join 99,266,292 other subscribers

Källlänk

Håll ett öga på vad vi gör
Bli först med att få de senaste uppdateringarna och exklusivt innehåll direkt till din e-postinkorg.
Vi lovar att inte spamma dig. Du kan avbryta prenumerationen när som helst.
Ogiltig e-postadress
Fortsätt läsa

WORDPRESS

Hur man filtrerar WooCommerce-produkter (steg-för-steg handledning)

Publicerad

Hur man filtrerar WooCommerce-produkter (steg-för-steg handledning)

Are you looking for a way to filter products by attribute in your WooCommerce store?Filtering your WooCommerce products by attribute makes it easier …

Källlänk

Se även  Nya WordPress.com-teman för januari 2023 – WordPress.com News
Håll ett öga på vad vi gör
Bli först med att få de senaste uppdateringarna och exklusivt innehåll direkt till din e-postinkorg.
Vi lovar att inte spamma dig. Du kan avbryta prenumerationen när som helst.
Ogiltig e-postadress
Fortsätt läsa

WORDPRESS

Grattis på 20-årsdagen, WordPress! Vi skulle inte vara här utan dig – WordPress.com Nyheter

Publicerad

Grattis på 20-årsdagen, WordPress! Vi skulle inte vara här utan dig – WordPress.com Nyheter

Above: Watch Matt Mullenweg, Mike Little, and Dries Buytaert — in conversation for the first time ever — discuss 20 years of WordPress as well as the future of open source.

On May 27, 2003, co-founders Matt Mullenweg and Mike Little announced that WordPress was available to the public. Their vision, as you can still read in their original post on WordPress.org, was to foster a means by which anyone could easily share and discuss their ideas with the world. 

What started as a humble open-source blogging platform is now the driving force behind over one-third of the internet’s most popular websites, including The New York Times, Salesforce, and Disney. But the non-profit WordPress project continues to further its mission of democratizing publishing for the entire world. Just as Version 0.7 was available as a free download under the General Public License (GPL) 20 years ago, WordPress remains free today — at Version 6.2 and counting. 

1685144732 780 Grattis på 20-årsdagen WordPress Vi skulle inte vara här utan dig
The original comment from WordPress co-founder Mike Little, which kickstarted the creation of a platform that would change the internet forever.

Automattic — the parent company of WordPress.com, Jetpack, Tumblr, and other web platforms and services — didn’t yet exist when Mike and Matt launched WordPress. But since its birth in 2005, the two organizations have worked hand in hand. Through the Five for the Future initiative, Automattic commits 5% of our company’s resources — including over 4,000 employee hours per week — to the open source WordPress project. In turn, we benefit from the amazing work they do in improving WordPress and ensuring the best possible experience for building and maintaining your website, no matter how small or large.  

Se även  Nexcess recension | TechRadar

It’s a symbiotic relationship for which we have a deep appreciation. The WordPress community often uses a saying that we love: “A rising tide lifts all boats.” A healthy and thriving WordPress project benefits all of us. 

So, to our friends in the WordPress open source community, we extend a heartfelt congratulations and thank you. Happy 20th anniversary! We can’t wait to see what the next two decades — and beyond — will bring. 


Join 99,190,255 other subscribers

Källlänk

Håll ett öga på vad vi gör
Bli först med att få de senaste uppdateringarna och exklusivt innehåll direkt till din e-postinkorg.
Vi lovar att inte spamma dig. Du kan avbryta prenumerationen när som helst.
Ogiltig e-postadress
Fortsätt läsa

Trendigt