Javascript-based WYSIWYG Editor TinyMCE Determined To Be the Source of Vulnerability Causing ‘in’ Hack Exploitation

anti spam






TOKYO (MacHouse) – It’s been 4 weeks since we first reported the systematic exploitation of websites where a folder titled ‘in’ is installed with spam pages inside. We were never interested in seeking the source of vulnerability common in the victimized websites. What appears to be source of vulnerability, however, is open-source software called TinyMCE.

So what exactly is TinyMCE? According to its website (http://tinymce.moxiecode.com), it’s open-source software creating a Javascript-based WYSIWYG editor. (See Screenshot 01.) Screenshot 02 shows an example of a WYSIWYG editor shown at developer’s website.





TinyMCE Javascript vulnerability hack WYSIWYG editor
Screenshot 01 – Source: tinymce.moxiecode.com
  TinyMCE Javascript vulnerability hack WYSIWYG editor
Screenshot 02 – Source: tinymce.moxiecode.com
  TinyMCE Javascript vulnerability hack WYSIWYG editor
Screenshot 03 – Source: tinymce.moxiecode.com






This software contains folders in the following order: jscripts > tiny_mce> plugins. (See Screenshot 03.) It appears that the cyber scrum group installs folders inside this ‘plugins.’ (See Screenshot 04.)






TinyMCE Javascript vulnerability hack WYSIWYG editor
Screenshot 04 – Source: MacHouse





References:

7 New Websites Victimized in the ‘in’ Hack Exploitation
University of Arizona College of Education Among More Than 48 Websites Victimized in the ‘in’ Hack Exploitation
University of Oxford, Education Department Website, Among Victims of ‘IN’ Exploitation Leading to Child Porn Website
Multiple Website Hacks Leading to Porn Website with Child Pornography Part 2
Multiple Website Hacks Leading to Porn Website with Child Pornography Part 1

This entry was posted in Internet security and tagged , . Bookmark the permalink.

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comment spam protected by SpamBam

Notify me of followup comments via e-mail. You can also subscribe without commenting.