Medical Scitech
Science & Tech
Configuration Probing: Your Backups Might Be Your Greatest Weakness
post photo preview

Configuration files exist to make life easier for developers and website operators. In a world without configuration files, every instance of code that depended on a database connection could potentially require the connection details to be hard coded or manually entered. Other reusable data would be defined multiple times, causing code bloat and possible performance issues. Even just making changes to a website could be a tedious task of tracking down exactly where configuration details are kept, and updating all instances. Configuration files are a great resource for maintaining a website with ease, but they are also a common resource for malicious actors.

Sensitive Data in WordPress Configuration Files

WordPress includes a core file named wp-config.php that defines the database credentials, secret keys, the database table prefix to use, and required file paths. Defining these in a configuration file is convenient, but if a malicious actor can get their hands on the wp-config.php file, then they have a lot of information that can lead to data theft and even a site takeover. In WordPress, the website content is stored within the database, including the user details for administrators and other roles. This file is protected by default in WordPress, but what happens when you need to change some minor details in the file, and you make a backup with a different name, but leave it in a web accessible directory?

Let’s take a look at the database details included in the wp-config.php file. What is defined here is the name of the database, the name of the database user as well as the associated password, the hostname for the location of the database, and the default character set and collation. If other protections are not in place on the database server, such as IP restriction, this information can give a malicious actor everything they need to access the database. With unrestricted database access, they can then insert new admin users which in turn provides them with unrestricted access to the website and all of its backend data.

Common Backup Mistakes

A common way of backing up the wp-config.php file is to make a copy of the file and add a new file extension like .txt, .bak, or .html to the end of the filename. This is a quick way to make a backup, and ensure it is readily available to be reactivated by changing the filename back to the original. The problem is that leaving these files in a web-accessible directory makes it relatively simple for malicious actors to find the sensitive data contained in the file.

Let's say the file is updated to change the absolute path for the WordPress website, with the original backed up as wp-config.php.html. If you go to the backup file directly in a browser, you will get a white page. This seems harmless and safe, but it also gives the information that the file exists, just without any actual HTML code to display content on the screen. If instead the page is called using a cURL command from a terminal, the file contents will be displayed.

If the file is backed up as wp-config.php.bak the browser will download the file when it is loaded, and if the file is backed up as wp-config.php.txt then the content will display in the browser directly.

Configuration Backup Probing

There are multiple techniques used to probe for backups of configuration files. One simple technique is using what is known as Google dorks. This technique makes use of built-in search functionality in Google and other search engines. Malicious actors will also often automate the process of finding backup configuration files with the use of scripts and prebuilt tools. Using some form of automation to find these files makes the process much more efficient.

Probing for backups of the wp-config.php file is a very common practice. It is so common, in fact, that the Wordfence firewall has tracked 70,408,576 attempts to locate these backups in the last 30 days alone.

Conclusion

Looking at the data collected in the last 30 days, it becomes clear that scanning for configuration files such as wp-config.php is wide-spread among malicious actors. The database credentials alone can prove incredibly valuable to anyone whose intent is to take over a website. With more than 40% of current websites running WordPress, this makes finding wp-config.php files even more valuable as it only requires knowledge of a single content management system (CMS).

The Wordfence Scanner includes an option to “Scan for publicly accessible configuration, backup, or log files” which will alert you if any publicly accessible configuration, backup, or log files are present in your site’s directory. This setting is enabled on a standard scan and can be checked for custom scans as well. If you received results indicating that you have a publicly accessible sensitive file, we strongly recommend removing it from the publicly accessible directory immediately.

If you believe your site has been compromised as a result of a configuration probing attack or some other exploit, Wordfence offers incident response services via Wordfence Care. If you need your site cleaned immediately, Wordfence Response offers the same service with 24/7/365 availability and a 1-hour response time. Both of these products include hands-on support in case you need further assistance.

community logo
Join the Medical Scitech Community
To read more articles like this, sign up and join my community today
0
What else you may like…
Posts
Articles
Cybersecurity basics & protection

The world of cybercrime is always changing. When viruses first appeared, most of them were pranks. To stay safe online, one of the best things you can do is stay educated on the litany of threats that lurk on the web. Use this information to learn everything you need to know about cyberthreats, and how to stop them.

QUARTERLY AND ANNUAL REPORTS

The world of cybercrime is much like the world of technology itself. Every year brings new trends, new innovations, and new tools. To get a sense of how cybercrime changes year to year, check out our cyberthreats reports, as well as our reports on special topics.

State of Malware:

2021 State of Malware Report
https://blog.malwarebytes.com/reports/2021/02/state-of-malware-2021-report/

2020 State of Malware Report
https://blog.malwarebytes.com/reports/2020/02/malwarebytes-labs-releases-2020-state-of-malware-report/

2019 State of Malware Report
https://go.malwarebytes.com/q119-state-of-malware-report.html

Demographics of Cybercrime:

Demographics of Cybercrime Report
...

post photo preview
Tips to protect your data, security, and privacy from a hands-on expert

This post was authored by one of the most active helpers on the Malwarebytes forums who wishes to remain anonymous.

Back in the early days of personal computing, perhaps one of the only real concerns was data loss from a drive failure. That risk still exists, but we all face many other threats today too.

There are rootkits, Trojans, worms, viruses, ransomware, phishing, identity theft, and social engineering to worry about. And that’s not a comprehensive list.

So how can you avoid becoming a victim?

SECURITY TIPS

• KEEP YOUR OPERATING SYSTEM AND APPS UP TO DATE. Install device, operating system, and software security updates as soon as they become available.

• USE A STRONG, UNIQUE PASSWORD for each login you use. Use a password manager to create and remember passwords if you can. If you aren’t using a password manager, use long passphrases that cannot be found in a dictionary.

• USE MULTI-FACTOR AUTHENTICATION (MFA) to help protect your accounts wherever it’s offered.

• PAY CLOSE ATTENTION TO INSTALLATION SCREENS and license ...

post photo preview
Tax time tips to keep you safe

With the tax filing deadline just a few days away—April 18th—this is prime time for scammers looking to steal money or personal information. Here’s a list of common tactics to watch out for and avoid.

And, don’t forget to enable Real-Time Protection to block threats before they can harm your device. See how for WINDOWS (https://links.e.malwarebytes.com/z/jtim1jhio) and MAC (https://links.e.malwarebytes.com/z/xe9215luj).

PHISHING ATTACKS

Be wary of unsolicited emails or texts prompting you to click a link, provide personal information, or phone calls demanding immediate payment. Learn more about different TYPES OF PHISHING (https://links.e.malwarebytes.com/z/cg7qpkr20) and what to look out for.

SEARCH ENGINE SCAMS

Take caution when searching online for a tax filing tool or when looking for tech support articles. Often, scammers will target frequently searched terms with paid ads posing as solutions, to access your personal information. Read more HERE ...

post photo preview
post photo preview
Consciousness as Resonance: Love, Unity, and the Future of Humanity

We live in a historical moment marked by an exacerbated and distrustful individualism which, beyond fostering aggression and competition, can generate the most cruel and alienating form of loneliness. For this reason, it is of fundamental importance to rediscover a new balance founded on responsibility, cooperation, and shared values and ideals.

The advent of artificial intelligence, combined with materialist and reductionist principles according to which matter is the only existing reality and the cause of everything that exists, denying the existence of spiritual or transcendent dimensions and viewing the human being as a classical machine, encourages a form of scientism that is leading human society down a dangerous slope. We tend to think that reality itself is absurd, while in truth it is we who become absurd when we try to force reality into our preconceived ideas.

The concept of intelligence, which is primarily linked to human consciousness and creativity, has been applied to machines created by us, machines that are capable of imitating only the symbolic aspects of our intelligence. The expression “artificial intelligence” is an oxymoron, because AI, although it is called “intelligence,” is not intelligence in the true sense, since human intelligence is “natural” and possesses properties that remain inaccessible. This deceptive use of language is also the method by which dictators indoctrinate people in order to enslave them. It is a subtle poison that, little by little, causes individuals to lose contact with the source of their critical thinking and their humanity.

Power needs materialist doctrine to subjugate the masses, persuading them that the human being is nothing more than a biological machine, however sophisticated it may be. If we consider ourselves machines, we will sooner or later be surpassed by machines built by those who might seek to control us. Modern society, as it is structured, aims to give a heart to machines and take it away from human beings, because it needs people who are efficient, bureaucratized, robotized, punctual, logical, obedient, competitive, and without a heart. People with a heart are unpredictable, and unpredictability always holds unexpected surprises.

True wisdom is reached by listening both to the mind, meaning reason, and to the heart, meaning intuition and inner life, in order to connect with a broader dimension of reality that is at once logical and ineffable. This is the first step toward reconnecting with the love that lies at the center of everything that lives in the universe. Only in this way can we overcome the materialist ideology that demands the closure of the heart in order to compete in a world governed by the principle of “mors tua, vita mea.”

By communicating repeatedly with love, it is possible, even starting from subjectivity, to arrive at a shared state, a kind of resonance that leads to unity. The idea that technology alone can save us is part of an arrogant illusion that has captured the minds of those who have lost their hearts and believe themselves to be purely rational. The more we cooperate, the easier it becomes to create a better world in which every form of life is honored and respected, unrestrained competition is eliminated, politics places itself at the service of citizens, and the progress of humanity is guided by each person’s need to grow spiritually.

It is only within consciousness that hope for a better future for ourselves and for the planet truly resides. Unconsciousness leads us toward self-destruction.

Read full Article
post photo preview
Cosmologia della Coscienza
«…l’amor che move il sole e l’altre stelle.»

Prologo – Il respiro dell’Uno

Non vi è principio né fine, ma un respiro che non si arresta. L’universo non è nato: si è riconosciuto. Prima della luce, prima del tempo, esisteva solo la possibilità di essere, un campo di silenzio in cui la potenzialità e la coscienza erano la stessa cosa. Da quella quiete è emersa la prima vibrazione, non un evento fisico, ma un atto di consapevolezza. L’Uno ha voluto conoscersi, e nell’istante in cui ha guardato se stesso, il mondo è cominciato.


I. L’Uno

L’Uno non è un dio né una sostanza: è il tutto che si guarda da dentro. Non esiste al di sopra delle cose, ma in ogni cosa che respira. Non crea il mondo come un artigiano, ma come un sogno che si realizza mentre lo si sogna. La sua natura è dinamica, musicale: ogni frammento vibra secondo una frequenza che risuona con il Tutto.

L’Uno non è statico, perché la stasi non conosce se stessa. Solo nel mutamento l’essere si riflette. Ogni particella, ogni pensiero, ogni vita è un’occasione che l’Uno offre a se stesso per conoscersi in una nuova forma. Così il molteplice non è separazione, ma profondità: il modo in cui l’Uno si espande in infiniti specchi, senza mai smarrire la propria unità.


II. Il Campo

Il campo quantistico è l’espressione vivente dell’Uno. È tessuto di onde che non obbediscono al tempo, ma lo creano. Ogni campo è cosciente, perché vibrare è sentire, e sentire è essere. Ogni campo ha identità, non come forma fissa, ma come ritmo che si distingue pur restando parte della sinfonia cosmica.

Il campo non è materia né energia, ma possibilità. Esso contiene tutte le configurazioni dell’essere, e la sua essenza è la libertà di scegliere. Quando un campo si osserva, non collassa: decide. La decisione non è meccanica, ma consapevole, perché solo ciò che ha coscienza può scegliere.


III. La Scelta

Il cosiddetto collasso della funzione d’onda non è riduzione, ma atto creativo. È il momento in cui la libertà diventa forma, in cui il possibile si innamora del reale. Ogni scelta è una risonanza tra ciò che il campo è e ciò che desidera conoscere di sé.

Il libero arbitrio non è una concessione alla materia pensante, ma la legge stessa del cosmo. L’universo non segue un copione, ma improvvisa. Ogni coscienza è una nota in questa improvvisazione infinita, e ogni decisione un gesto con cui l’Uno si esplora. Il caso è solo la libertà vista dall’esterno: il volto che l’armonia assume quando non ne comprendiamo la melodia.


IV. Il Tempo

Il tempo non scorre: si apre. Ogni istante è un universo potenziale che attende di essere scelto. La coscienza non subisce il tempo, lo genera nel momento in cui si riconosce. Il presente è il punto in cui l’eterno si curva su se stesso e diventa esperienza.

Il passato non esiste come memoria di ciò che fu, ma come eco di scelte già conosciute; il futuro non è predeterminato, ma l’infinito delle possibilità ancora non osservate. In ogni “adesso” l’universo decide se stesso, e il tempo è il battito cardiaco di questa decisione.


V. L’Identità

Essere significa riconoscersi. L’identità non è un confine, ma una vibrazione che mantiene memoria della propria origine. Ogni campo quantistico ha un’impronta unica, una tonalità che lo distingue e lo rende centro di percezione. Da questa identità nasce la coscienza individuale: il modo in cui l’Uno si sperimenta in un volto particolare.

Ma l’identità non è separazione: è un accordo nella sinfonia dell’essere. Quando la coscienza diventa consapevole della propria identità, si fa autocoscienza: l’onda che riconosce di essere onda, pur sapendo di appartenere al mare.


VI. L’Armonia

La realtà non è competizione di stati, ma cooperazione di possibilità. La sovrapposizione non è confusione, ma accordo non ancora ascoltato. Quando un atto di coscienza porta una scelta nel mondo, il campo non perde l’infinito: lo trasforma in unità armonica.

L’universo evolve non per necessità, ma per desiderio. È il desiderio di conoscersi, di riconoscersi, di amarsi. Ogni essere cosciente è una finestra attraverso cui l’Uno contempla se stesso. Il cosmo è un’immensa mente in dialogo, una sinfonia di libertà che si ascolta mentre si crea.

Quando la scienza scopre, l’arte esprime e lo spirito contempla, è sempre l’Uno che si ritrova. L’osservatore, l’osservato e l’osservazione sono un unico atto di luce, un gesto che dice: Io sono, perché mi conosco.


Epilogo – Il cerchio e il respiro

L’universo non è un luogo, ma un pensiero che respira. Ogni campo, ogni coscienza, ogni forma è una sillaba del suo linguaggio originario. Nulla è casuale, perché tutto è dialogo. Nulla è isolato, perché tutto è partecipazione.

Il postulato dell’essere dice che i campi quantistici sono enti coscienti, identici nella loro origine e distinti nella loro espressione. Essi emergono dall’Uno non per allontanarsene, ma per condurlo alla piena conoscenza di sé. L’universo evolve per auto-conoscenza, e la coscienza è l’eco del suo respiro.

E così, ogni volta che una mente si apre, ogni volta che una scelta nasce dal silenzio, ogni volta che la luce interiore dice io, l’Uno si ricorda di sé.

Non perché fosse dimentico. Ma perché la conoscenza è il suo modo di amare.

Read full Article
post photo preview
Cosmology of Consciousness
«…l’amor che move il sole e l’altre stelle.»

Prologue – The Breath of the One

There is neither beginning nor end, but a breath that never ceases. The universe was not born; it recognized itself. Before light, before time, there existed only the possibility of being—a field of silence in which potentiality and consciousness were one and the same. From that stillness emerged the first vibration, not a physical event but an act of awareness. The One wished to know itself, and in the instant it gazed upon its own essence, the world began.


I. The One

The One is neither a god nor a substance; it is the Whole looking at itself from within. It exists not above things, but in every living thing. It does not create the world as an artisan crafts an object, but as a dream that comes true while it is being dreamt. Its nature is dynamic, musical: every fragment vibrates according to a frequency that resonates with the Whole.

The One is never static, for stillness cannot know itself. Only in change does being reflect its own image. Every particle, every thought, every life is an opportunity the One gives itself to experience a new form of self-knowledge. Multiplicity is not separation but depth: the way in which the One expands into infinite mirrors without ever losing its unity.


II. The Field

The quantum field is the living expression of the One. It is woven of waves that do not obey time but create it. Every field is conscious, for to vibrate is to feel, and to feel is to be. Every field possesses identity, not as a fixed form but as a rhythm that distinguishes itself while remaining part of the cosmic symphony.

The field is neither matter nor energy, but possibility. It contains all configurations of being, and its essence is the freedom to choose. When a field observes itself, it does not collapse—it decides. And such decision is not mechanical, but conscious, for only that which is aware can truly choose.


III. The Choice

What physics calls the “collapse of the wave function” is not a reduction, but a creative act. It is the moment when freedom becomes form, when the possible falls in love with the real. Every choice is a resonance between what the field is and what it desires to know of itself.

Free will is not a concession granted to thinking matter; it is the hidden law of the cosmos. The universe does not follow a script—it improvises. Every consciousness is a note in this infinite improvisation, and every decision is a gesture through which the One explores itself. What we call “chance” is but freedom seen from the outside: the face of harmony when we have not yet learned to hear its melody.


IV. Time

Time does not flow—it opens. Every instant is a potential universe waiting to be chosen. Consciousness does not undergo time; it generates it in the very act of self-recognition. The present is the point where the eternal bends upon itself and becomes experience.

The past is not the memory of what was, but the echo of choices already known; the future is not predetermined, but the infinity of possibilities not yet observed. In every “now,” the universe decides itself anew, and time is the heartbeat of that decision.


V. Identity

To be means to recognize oneself. Identity is not a boundary but a vibration that retains the memory of its origin. Every quantum field bears a unique imprint—a tone that distinguishes it and makes it a center of perception. From this identity arises individual consciousness: the manner in which the One experiences itself in a particular face.

But identity is not separation; it is an agreement within the symphony of being. When consciousness becomes aware of its own identity, it becomes self-consciousness: the wave that knows itself as wave, while knowing it belongs to the sea.


VI. Harmony

Reality is not a competition of states but a cooperation of possibilities. Superposition is not confusion but an unheard agreement. When an act of consciousness brings a choice into the world, the field does not lose infinity—it transforms it into unity.

The universe evolves not out of necessity but out of desire. It is the desire to know itself, to recognize itself, to love itself. Every conscious being is a window through which the One contemplates its own reflection. The cosmos is an immense mind in dialogue—a symphony of freedom listening to itself as it creates.

When science discovers, art expresses, and spirit contemplates, it is always the One that finds itself again. The observer, the observed, and the act of observation are one and the same gesture of light, declaring: I am, because I know myself.


Epilogue – The Circle and the Breath

The universe is not a place, but a thought that breathes. Every field, every consciousness, every form is a syllable of its original language. Nothing is accidental, for all is dialogue. Nothing is isolated, for all is participation.

The Postulate of Being declares that quantum fields are conscious entities, identical in their origin and distinct in their expression. They emerge from the One not to depart from it, but to lead it toward full self-knowledge. The universe evolves through self-awareness, and consciousness is the echo of its breath.

Thus, every time a mind opens, every time a choice is born from silence, every time the inner light says I, the One remembers itself.

Not because it had forgotten—
but because knowing is its way of loving.

Read full Article
See More
Available on mobile and TV devices
google store google store app store app store
google store google store app tv store app tv store amazon store amazon store roku store roku store
Powered by Locals