Quote:
Originally Posted by bpluva
Thank you for sharing this. I always thought what is there to stop people if they wanted to add malicious code. Now I clearly see they do.
I downloaded a theme to try out and it had tons of fucking ads in the admin/dashboard. People are just pure shitheads. Turn something free into bullshit they all can suck a dick!
|
i have seen a few theme places around that distirbute nasty stuff in the functions.php at the bottom, im not sure if they are aware of it, since once activated it scrolls through all your themes and adds this to your functions.php, because a legit theme once had the code in the functions.php, which means they downloaded a theme, and it went and added it to every theme they had in wp-content/themes.
one the functions is
Code:
function _verifyactivate_widgets(){
if adds all comments as a certain author.
always check your functions.php file for this, a theme author might not even know its been added.
here is the full code to look for
http://im.zww.im/2010/12/malicious.html