Facebook reviews by long-term WPX customers

  Back

Why 'Nulled' (Cracked/Pirate) Plugins & Themes are Forbidden on WPX Hosting

It has come to our attention that some of our customers have attempted to use 'nulled' (cracked/pirated) plugins and themes on WPX Hosting - this is grounds for immediate and permanent non-refundable termination of hosting accounts, as per our Terms of Service.

Most of these have hidden, malicious backdoor scripts.

That is why nulled plugins & themes are FORBIDDEN on WPX Hosting.

Some commercial plugins and themes can be found for free on seemingly good looking websites where it seems safe to download for free. Nothing on these legitmate-looking websites appears to suggest that the plugins or themes offered there are infected with a very powerful backdoor script called 'CryptoPHP'.  

What this CryptoPHP can do:

After being installed on a webserver, the backdoor has several options of being controlled which include command and control server communication, mail communication as well as manual control.

Backdoors of this type are mainly used for illegal search engine optimization, also known as Blackhat SEO. The backdoor is a well-developed piece of code and dynamic in its use. The capabilities of the CryptoPHP backdoor include:

  • Integration into popular content management systems like WordPress, Drupal and Joomla.
  • Public key encryption for communication between the compromised server and the command and control (C2) server.
  • Backup mechanism in place against C2 domain takedowns by using email communication.
  • Manual control of the backdoor besides the C2 communication.
  • Remote updating of the C2 server list.
  • Ability to update itself.

When installed it can actually integrate itself deep into your website and use its functions, code and database. It can add additional administrator user, add/delete/modify the content of the website, change your websites settings and anything you can or can’t imagine.

So we HIGHLY recommend to ONLY use plugins from TRUSTED SOURCES.

Here is a list of some of the websites that distribute plugins with CryptoPHP backdoor:

nulled domains list

The following websites host the actual plug-in and theme files used for direct download:

nulled domains list2

 

If you have installed a nulled plugin or theme from one of these websites, it is very likely that your website could be infected with CryptoPHP.

What you need to do at least is delete the dangerous plugins/themes, check whether you have an additional admin user added and ensure that all your websites look like they should for search engines.

You can do that from Google Webmasters Tools > Fetch as Googlebot .

 

For more detailed information on this tread check this document CryptoPHP-Whitepaper-FoxSRT