{"id":943,"date":"2024-03-09T20:31:03","date_gmt":"2024-03-09T18:31:03","guid":{"rendered":"https:\/\/techlance.ddns.net\/?p=943"},"modified":"2024-03-09T20:31:57","modified_gmt":"2024-03-09T18:31:57","slug":"hyokkays-muuttaa-tuhansia-verkon-kayttajia-salasanoja-murtavaan-bottiverkkoon","status":"publish","type":"post","link":"https:\/\/techlance.ddns.net\/en\/hyokkays-muuttaa-tuhansia-verkon-kayttajia-salasanoja-murtavaan-bottiverkkoon\/","title":{"rendered":"Hy\u00f6kk\u00e4ys muuttaa tuhansia verkon k\u00e4ytt\u00e4ji\u00e4 salasanoja murtavaan bottiverkkoon"},"content":{"rendered":"<p>Hy\u00f6kk\u00e4\u00e4j\u00e4t ovat muuntaneet satoja hakkeroiduja sivustoja, jotka k\u00e4ytt\u00e4v\u00e4t WordPress-ohjelmistoa, komento- ja ohjauspalvelimiksi, jotka pakottavat vierailijoiden selaimet suorittamaan salasanan murtamisen hy\u00f6kk\u00e4yksi\u00e4.<\/p>\n\n\n\n<p>Verkossa suoritettu haku hy\u00f6kk\u00e4yksen suorittavasta JavaScriptist\u00e4 paljasti, ett\u00e4 se oli is\u00e4nn\u00f6ity 708 sivustolla t\u00e4m\u00e4n postauksen ilmestyess\u00e4 Arsilla, kasvua 500 sivustosta kahden p\u00e4iv\u00e4n takaa. Denis Sinegubko, tutkija, joka havaitsi kampanjan, sanoi tuolloin n\u00e4hneens\u00e4 tuhansia vierailijoiden tietokoneita suorittamassa skripti\u00e4, mik\u00e4 sai ne ottamaan yhteytt\u00e4 tuhansiin verkkotunnuksiin yrityksen\u00e4 arvata niill\u00e4 olevien k\u00e4ytt\u00e4j\u00e4tunnusten salasanoja.<\/p>\n\n\n\n<p>&#8221;N\u00e4in tuhannet vierailijat sadoilla tartunnan saaneilla verkkosivustoilla tiet\u00e4m\u00e4tt\u00e4\u00e4n ja samanaikaisesti yritt\u00e4v\u00e4t murtaa tuhansien muiden kolmannen osapuolen WordPress-sivustojen salasanoja&#8221;, Sinegubko kirjoitti.<\/p>\n\n\n\n<p>Attackers have transformed hundreds of hacked sites running WordPress software into command-and-control servers that force visitors\u2019 browsers to perform password-cracking attacks. A web search for the JavaScript that performs the attack showed it was hosted on 708 sites at the time this post went live on Ars, up from 500 two days ago. Denis Sinegubko, the researcher who spotted the campaign, said at the time that he had seen thousands of visitor computers running the script, which caused them to reach out to thousands of domains in an attempt to guess the passwords of usernames with accounts on them. \u201cThis is how thousands of visitors across hundreds of infected websites unknowingly and simultaneously try to bruteforce thousands of other third-party WordPress sites,\u201d Sinegubko wrote.<\/p>\n\n\n\n<p><a href=\"https:\/\/arstechnica.com\/security\/2024\/03\/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet\/\">https:\/\/arstechnica.com\/security\/2024\/03\/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Hy\u00f6kk\u00e4\u00e4j\u00e4t ovat muuntaneet satoja hakkeroiduja sivustoja, jotka k\u00e4ytt\u00e4v\u00e4t WordPress-ohjelmistoa, komento- ja ohjauspalvelimiksi, jotka pakottavat vierailijoiden selaimet suorittamaan salasanan murtamisen hy\u00f6kk\u00e4yksi\u00e4. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9],"tags":[15],"class_list":["post-943","post","type-post","status-publish","format-standard","hentry","category-security","tag-tietoturva"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/943","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/comments?post=943"}],"version-history":[{"count":0,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/943\/revisions"}],"wp:attachment":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/media?parent=943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/categories?post=943"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/tags?post=943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}