{"id":40997,"date":"2021-10-26T12:20:06","date_gmt":"2021-10-26T17:20:06","guid":{"rendered":"https:\/\/webirix.com\/?p=40997"},"modified":"2022-02-08T07:03:43","modified_gmt":"2022-02-08T13:03:43","slug":"que-es-anonymousfox","status":"publish","type":"post","link":"https:\/\/webirix.com\/en\/que-es-anonymousfox\/","title":{"rendered":"What is AnonymousFox?"},"content":{"rendered":"<h4>WHAT IS ANONYMOUSFOX?<\/h4>\n<p>Anonymousfox is a vulnerability of WordPress and different CMS with which vulnerable plugins can be exploited and thus gain access to the files of your cPanel account.<br \/>\nWhile this is not a problem that affects the integrity of the server on which it is hosted or that it can grow horizontally to spread between accounts on the same server, it is possible that it will attack different accounts independently.<\/p>\n<h4>WAY TO ATTACK<\/h4>\n<p>cPanel has a file called .contactemail in which an email is stored in plain text and with this the client has the opportunity to recover their panel password in case they forget it.<\/p>\n<p>Anonymousfox will scan your entire site for out-of-date plugins or vulnerable CMS, finding any will use this same vulnerability to upload suspicious files and \/ or directories such as smtpF0X or F0xAutoConfig and other named Fox related accounts or directories in the directory of a user.<br \/>\nThese uploaded files will modify the content of .contactemail and replace your email with someone else, after this a series of commands will be generated to recover the cPanel password and receive it later via email.<\/p>\n<h4>SECURE YOUR SITE<\/h4>\n<p>There are many types of CMS, so we will only focus on the most used in WordPress.<br \/>\nSecuring a WordPress site seems like a complicated task, but in reality any standard user will be able to do it, here are a few steps which could help:<\/p>\n<h4>1. DISABLE THE EXECUTION OF PHP FILES IN NON-NECESSARY DIRECTORIES<\/h4>\n<p>Enter the directory, create a .htaccess and enter the following information:<br \/>\n&lt;Files *.php&gt;<br \/>\ndeny from all<br \/>\n&lt;\/Files&gt;<\/p>\n<p>The directories in which php should not be executed are:<br \/>\n\/ wp-includes<br \/>\n\/ wp-content \/ uploads<\/p>\n<p>&nbsp;<\/p>\n<h4>2. BLOCK ACCESS TO YOUR OWN .HTACCESS FILE<\/h4>\n<p>To achieve this step, you will only have to add the following lines to your own htacces file:<br \/>\n&lt;Files .htaccess&gt;<br \/>\norder allow, deny<br \/>\ndeny from all<br \/>\n&lt;\/Files&gt;<\/p>\n<h4>3. DISABLE XMLRPC.PHP THROUGH THE .HTACCESS FILE<\/h4>\n<p>The xmlrpc.php file is only used for unencrypted RPC communication, in case your WordPress does not need it you will have to deactivate it from your htacces as follows:<br \/>\n&lt;Files xmlrpc.php&gt;<br \/>\nOrder Allow, Deny<br \/>\nDeny from all<br \/>\n&lt;\/Files&gt;<\/p>\n<p>I hope this information is useful, receive a warm greeting!<\/p>","protected":false},"excerpt":{"rendered":"<p>WHAT IS ANONYMOUSFOX? Anonymousfox is a vulnerability of WordPress and different CMS with which vulnerable plugins can be exploited and thus gain access to the files of your cPanel account. Although this is not a problem that affects the integrity of the server on which it is hosted or that can grow horizontally for ...<\/p>","protected":false},"author":27,"featured_media":40998,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-40997","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"jetpack_featured_media_url":"https:\/\/webirix.com\/wp-content\/uploads\/2021\/10\/logo.png","_links":{"self":[{"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/posts\/40997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/comments?post=40997"}],"version-history":[{"count":5,"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/posts\/40997\/revisions"}],"predecessor-version":[{"id":41004,"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/posts\/40997\/revisions\/41004"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/media\/40998"}],"wp:attachment":[{"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/media?parent=40997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/categories?post=40997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/webirix.com\/en\/wp-json\/wp\/v2\/tags?post=40997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}