💎 Fed’s first rate cut since 2020 set to trigger market. Find undervalued gems with Fair ValueSee Undervalued Stocks

More Than 300 Drupal Sites Cryptojacked

Published 05/08/2018, 02:37 PM
Updated 05/08/2018, 03:01 PM
 More Than 300 Drupal Sites Cryptojacked

What do the sites of the San Diego Zoo, the government of Chihuahua, Mexico, Lenovo, UCLA, and DLink have in common?

According to a discovery made by independent security researcher Troy Mursch, they’re all mining cryptocurrencies using their visitor’s computers unintentionally. He also discovered something else they shared that could explain how they all fell so easily to these attacks.

“While these [...] sites have no relation to each other, they shared a common denominator—they [...] are using an outdated and vulnerable version of the Drupal content management system. After I analyzed the IoCs, I was able to locate over 300 additional websites in this cryptojacking campaign. Many discovered were government and university sites from all over the world,” he wrote.

Although Drupal is not as wildly popular as WordPress, millions of sites still use the CMS for various purposes, ranging from institutional presentations to e-commerce sites. The latest version of the software should protect against this, but Mursch warns that this protection is not retroactive for sites that have already been affected by cryptojacking.

“The Drupal security team has prepared a FAQ which documents the risk level and mitigation steps. Note that installing the update won’t retroactively ‘unhack’ your website and you may need to take further remediation steps,” he added.

Finding the Coinhive script manually may be difficult because it is obfuscated by the hackers that implement it. Instead, website owners will have to go through their code line-by-line to look for references to CoinHive, “vuuwd.com/t.js,” or any JavaScript that was added when problems appeared.

Less than a month ago, SANS dean of research Johannes B. Ullrich found signs that Drupal sites started getting hit with cryptocurrency mining exploits.

In his investigation, the attack came in the form of a downloader that would mine using the server’s computer as opposed to the client’s and used a referrer in its request from popular Chinese search engine Baidu.

We’re unsure what’s making hackers look at Drupal as a new favorite destination, but it may have to do with the fact that they’ve been crowded out by other cryptojackers. In that case, cryptocurrencies like Monero may have driven hackers into a frenzy and competing with each other for territory on exploitable websites.


This article appeared first on Cryptovest

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.