With the increasing popularity of WordPress as a blogging platform, hackers and spammers are targeting more and more WordPress blogs. Wordpress is a flexible and open platform. Everyone knows how it works, how it behaves! WordPress is written in PHP and the look of a WordPress blog is determined by the theme. So, we love to have a good theme!

Here comes the dirty hackers and spamers into the scene. They knows that bloggers loves free themes. So, they are using some free WordPress themes to do their dirty tricks. An embed malicious code in the theme can do anything!

GigaOm reports that some themes of Seattle-based designer Derek Punsalan has been modified by a site called WP-Sphere. When you download Punsalan’s theme from the WP-Sphere site, it contains some extra encrypted codes that he didn’t include. The code establishes a connection from the WordPress server to several sites wpssr.com, wpsnc.com, and wpsnc2.com, and allows the site operator to download an arbitrary piece of Javascript.

Imagine, what a single piece of code can do? So, be careful in downloading and installing free WordPress themes. Always use themes from reliable sources. Before installing a theme, try to scan the theme codes, if you know some codings! Stay in contact with the community. I don’t want you all to suffer like me!

 

 

Rate this:
2.5

Enjoyed this post? Please consider subscribing to EarnBlogger RSS Feed.


You Should Also Check Out These Posts: