Guy 0 Posted February 18, 2018 Share Posted February 18, 2018 Not sure what is happening .I have been subscribed to "The Real News Network" for many years and recently my ESET antivirus shows up every time I try to open this web site stating that they have blocked the entry due to a trojan .The web site is delivered to my email account but even if I try to open the web site on line the same message . This first started with the site display on my screen all to one side of my screen , no way to correct. I have tried to alert the web site of same to no avail .Is the site possibly down or / and anyone openning this website without antivirus protection downloading a trojan ? Any comments would be appreciated Link to comment Share on other sites More sharing options...
itman 1,755 Posted February 18, 2018 Share Posted February 18, 2018 (edited) Appears the web site server has an infected WordPress plug-in: https://blog.sucuri.net/2015/03/inverted-wordpress-trojan.html . You can contact them to check out their web site. Also the malware is not exclusive to WordPress: Quote I should mention that although this malware is supposed to work on WordPress sites (WP-specific brute-force protection, paths and filenames, ability to generate doorways using current WP-theme, etc.) it will work just as well on other PHP sites that use index.php as a default index file. Edited February 18, 2018 by itman Link to comment Share on other sites More sharing options...
Guy 0 Posted February 18, 2018 Author Share Posted February 18, 2018 Thank you for the reply.I will contact Word Press . Link to comment Share on other sites More sharing options...
Administrators Marcos 5,290 Posted February 19, 2018 Administrators Share Posted February 19, 2018 I would recommend reading https://blog.sucuri.net/2017/02/joomla-security-pornography-spam-campaign-in-the-wild.html, especially the part Joomla 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object-injection attacks and execute arbitrary PHP code via the HTTP user-agent header. It was first exploited in December 2015 and is still happening today. If you have not updated your Joomla site since then, you are likely already compromised. We have a new guide on how to clean a hacked Joomla site that you can follow. Link to comment Share on other sites More sharing options...
Guy 0 Posted February 19, 2018 Author Share Posted February 19, 2018 Thank you .I do not have a web site and am not very knowledgeable in this world. I just serf the web with an interest in geopolitics especially .I comment on same when and if I can contribute to the conversation . Is it possible that my word press account is compromised? Why is it that there is only one of the websites that I visit that is giving problems in the display on my screen > Website is The Real News Network .All others are coming through properly. Confused. Link to comment Share on other sites More sharing options...
Administrators Marcos 5,290 Posted February 19, 2018 Administrators Share Posted February 19, 2018 2 minutes ago, Guy said: Is it possible that my word press account is compromised? It has nothing to do with your account since you wrote that you are not an owner of the website that was blocked. Simply the website you visited was compromised and an admin or owner of the website should clean it and take measures to prevent further reinfection. You as a person with no relation to the website cannot do anything about it but give a heads-up to admins of the website. Link to comment Share on other sites More sharing options...
Guy 0 Posted February 19, 2018 Author Share Posted February 19, 2018 Thank you Marcos .I have sent an email to them making them aware of this.I have not received any reply at this time so I don't even know if they have received it and the phenomena is still the same as tried to connect this morning and the trojan message is displayed automatically indicating that my eset is working properly. I am a novice in this world and I appreciate your help. Link to comment Share on other sites More sharing options...
Recommended Posts