FESTINGERVAULT - Backdoor infected plugins

Status
Not open for further replies.

w001y

Newbie
Joined
Mar 31, 2021
Messages
42
Reaction score
14
Well, first of all, I'm not an expert, I guess like the average festingervault user. But I am certain that these people have infected plugins.

I've been making and maintaining websites for years in an amateur way. There are some sites where I have bought the original plugins.

But 2 times that I have installed festingervault plugins, the site has been hacked. It's a shame because their customer service is good, although many times they "update" plugins and the supposed update doesn't work, you have to install like 3 previous versions to make it work.

Anyone else with this problem?
 
To be more precise I am referring to the gravity forms plugin and its addons. Also gravity perks. The installation cost me a total reset of the site and I had to pay 180usd to have it fixed.
 
To be more precise I am referring to the gravity forms plugin and its addons. Also gravity perks. The installation cost me a total reset of the site and I had to pay 180usd to have it fixed.

We are sorry to read that your website got hacked. Feel free to send me a PM and I will be happy to investigate why your website got hacked.
Have you installed Wordfence or a different plugin to scan your themes and plugins?
You can rest assured that all of our themes and plugins are originally purchased.
It sounds like your website got hacked differently as all our themes and plugins are 100% safe to use. MOD EDIT: Sellers cannot claim any of their products or services are 100% safe to use.
 
Last edited by a moderator:
Never had any problem at all with Deleted member 752298
Me neither, but with the plugins I downloaded from their website...

cap0.PNG

We are sorry to read that your website got hacked. Feel free to send me a PM and I will be happy to investigate why your website got hacked.
Have you installed Wordfence or a different plugin to scan your themes and plugins?
You can rest assured that all of our themes and plugins are originally purchased.
It sounds like your website got hacked differently as all our themes and plugins are 100% safe to use.
Of course, that's why I create this thread, don't think I hate you or want to give you bad publicity. In fact I have the lifetime account bought...cap0.PNG
 
I get my Nulls from a free and public source which seems to be trusted by thousands (not allowed to talk about it here). And a site can still get hacked.

And I always scan donwloads in a number of ways and compare to original files.

I tested the scanners against infected plugins and they always show up with prompts that they are infected. So the method works (at least sufficiently).

Only problem I had was when nulls weren’t updated with the latest security patches. Wordpress is an easy target for even the dumbest hackers out there, hence they can get hacked if bugs aren’t fixed timely enough. At least that’s what I think what happened the few times a hack was occured soon after a clean null installation.

Haven’t used festingers vault and no idea whether his nulls do or don’t contain malware but it does seem a bit unfare to jump to that kind of conclusion.
 
Me neither, but with the plugins I downloaded from their website...

View attachment 326324
what is the code of the result?, the difference, the malicious code itself?
False positives are a thing
and also, if you tamper with files, it will also show up even if the tampering is to stop the verification of the key.
since that's literally what wordfence does, it checks your files against the original
 
I get my Nulls from a free and public source (not allowed to talk about it here which seems to be trusted by thousands.

And I always scan them in a number of ways and compare to original files.

I tested the scanners against infected plugins and they always show up with prompts that they are infected. So the method works (at least sufficiently).

Only problem I had was when nulls weren’t updated with the latest security patches. Wordpress is an easy target for even the dumbest hackers out there, hence they can get hacked if bugs aren’t fixed timely enough. At least that’s what I think what happened the few times a hack was occured soon after a clean null installation.

Haven’t used festingers vault and no idea whether his nulls do or don’t contain malware but it does seem a bit unfare to jump to that kind of conclusion.
How can you compare with the original files if you haven't bought them? I'm interested in this topic because many times I want to test the plugin before buying it and the only solution is to get it nulled...

what is the code of the result?, the difference, the malicious code itself?
False positives are a thing
and also, if you tamper with files, it will also show up even if the tampering is to stop the verification of the key.
since that's literally what wordfence does, it checks your files against the original
Several scans were done, every time I installed a plugin or addon I ran wordfence. A month ago it did not give any alert. Today this... after checking google it comes up with several links that have nothing to do with my site.

This has already happened 2 times, the first was with the plugin Compilanz, the second with gravity forms + addons.
 
Several scans were done, every time I installed a plugin or addon I ran wordfence. A month ago it did not give any alert. Today this... after checking google it comes up with several links that have nothing to do with my site.

This has already happened 2 times, the first was with the plugin Compilanz, the second with gravity forms + addons.
Never mind, if you ain't going listen then there no point.
 
Never mind, if you ain't going listen then there no point.
I'm reading you, but you don't need to be sherlock homes. 2 years without problems with the site. A plugin is installed, problems. Site restarted. You wait 2 months. Installed again. Problems...
 
Here is the VirusTotal report for that file:
https://www.virustotal.com/gui/file/2226c83c4835f2ca30794b39e83b6613c07903d68606227703f1688ce07cdd6c/
I also installed the referred Gravity Forms plugin on a brand new staging domain:

View attachment 326327

And ran a test with WordFence:

View attachment 326328

If you are willing to send me a PM I am happy to check it out for you.
Then it must have been with one of the addons, I have installed several addons. When wordfence has given the alert I have immediately deleted the plugins, I contact you by DM.
 
Then it must have been with one of the addons, I have installed several addons. When wordfence has given the alert I have immediately deleted the plugins, I contact you by DM.

Please read my comment here:
You can rest assured that all of our themes and plugins are originally purchased.
It sounds like your website got hacked differently as all our themes and plugins are 100% safe to use.

Feel free to send me a DM with access to your website and we are happy to help you out.
 
Ah yes,
I get a heart attack tonight after eating a salad, it's 100% the salads fault.
Got it.
Well, it's not the same thing. If your intention was to show your unconditional support, your task is over. Thanks for your contribution
 
Status
Not open for further replies.
Back
Top