Hacking from a Wordpress comment email is it possible?

Discussion in 'Security' started by goy, Dec 3, 2010.

  1. #1
    I got this spam in my WP comments

    peeticrack@gmail.com /* <![CDATA[ */ (function(){try{var s,a,i,j,r,c,l=document.getElementById("__cf_email__");a=l.className;if(a){s='';r=parseInt(a.substr(0,2),16);for(j=2;a.length-j;j+=2){c=parseInt(a.substr(j,2),16)^r;s+=String.fromCharCode(c);}s=document.createTextNode(s);l.parentNode.replaceChild(s,l);}}catch(e){}})(); /* ]]> */
    PHP:
    It was placed in the email, there was no www and the comment look ok.

    What does this "code" do?
     
    goy, Dec 3, 2010 IP
  2. blackvps

    blackvps Peon

    Messages:
    29
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #2
    It looks pretty pointless, is your WP patched to the latest version?
     
    blackvps, Dec 6, 2010 IP
  3. SysAssist

    SysAssist Peon

    Messages:
    10
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    It's a function used for email address obfuscation. Nothing dangerous.
    Patching your WP to the latest version is highly recommended anyway :)
     
    SysAssist, Dec 6, 2010 IP
    goy likes this.
  4. goy

    goy Well-Known Member

    Messages:
    1,010
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    130
    #4
    Ahh i thought it was that but i did not know. I never seen they put it there before. Thanks
     
    goy, Dec 19, 2010 IP
  5. shubhamblogger

    shubhamblogger Peon

    Messages:
    18
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    quite tough question. I would like to respond quickly.
     
    shubhamblogger, Dec 20, 2010 IP
  6. mukhtaronlineservices

    mukhtaronlineservices Peon

    Messages:
    56
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I also have no any idea about it.
     
    mukhtaronlineservices, Feb 6, 2011 IP
  7. goy

    goy Well-Known Member

    Messages:
    1,010
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    130
    #7
    it is already answered

    It's a function used for email address obfuscation. Nothing dangerous.
     
    goy, Feb 10, 2011 IP