Sublime directory Surf the web anonymous Pagerank Monitor


Wordpress : Another security problem....

Nikolas
Tue 6 March 2007, 04:22 pm GMT +0100
It looks like wordpress has hacking problems again...

This time it looks like someone intruded in their servers and replaced the official download of the 2.1.1 version with a hacked one.

Sounds bad for a software that already loses its reputation.

olaf
Tue 6 March 2007, 05:10 pm GMT +0100
nice software!

maybe I should use blogger...

Nikolas
Sun 9 September 2007, 03:05 pm GMT +0200
As there are so many security updates for wordpress, I guess it could be better to post to this thread instead of opening a new one.

So, for another time WP has some security issues :)

http://wordpress.org/development/2007/09/wordpress-223/

Meth0d
Tue 2 October 2007, 01:12 am GMT +0200
ya this is why i left wordpress almost over a year ago.. i had some security problems with it and haven't trusted it since.. its what inspired me to just do my own thing

olaf
Tue 2 October 2007, 07:20 am GMT +0200
I have 4 WP blogs (and no time to post enough :))

the time savings because of the great features are bigger than doing an upgrade ones in some time. In my opinion every software has security issues. @Method.
Maybe you need to to stop trusting windows too, they have much bigger issues :)

Mind_nl
Tue 2 October 2007, 10:45 am GMT +0200
I agree with Olaf, the security issues are not really a big issue if you keep your software up to date.

Meth0d
Tue 2 October 2007, 05:29 pm GMT +0200
stop trusting windows as my personal machine? LOL and then use what, Linux or something [ROFL]? sure windows has its own security problems, and wordpress, but we are talkin about an internet application, not an operating system ;) wordpress has more security problems than it has good features in my opinion

and as far as "keeping it upto date for security reasons" goes,  how often do they release a security patch anyway?

olaf
Tue 2 October 2007, 09:44 pm GMT +0200


and as far as "keeping it upto date for security reasons" goes,  how often do they release a security patch anyway?

still have the time for blog posts!

Nikolas
Wed 3 October 2007, 01:43 am GMT +0200
WP is a very good CMS. In fact is one of the best. Now regarding those security wholes, don't think that they are simple as an SQL injection, and in most cases they are not a threat for most sites. But in the bottom line I think it is better to update some good software instead of developing such a thing (and believe me WP is a really huge project)

As for windows, it is true that we should start using linux, especially now that is very easy to be used (plus windows apps can run too)

Meth0d
Wed 3 October 2007, 06:17 am GMT +0200
linux running windows apps eh? now you've caught my attention. Vista cant even run some Xp apps! lol 8)

olaf
Wed 3 October 2007, 07:20 am GMT +0200
I think Nick is telling that windows apps can be used on linux

Nikolas
Wed 3 October 2007, 10:16 am GMT +0200
You can run windows apps to linux with the help of wine :)

olaf
Wed 3 October 2007, 10:28 am GMT +0200
cool name "Wine"!

from their website:
Quote
however Wine can optionally use native Windows DLLs if they are available.

will say with wine I can run dll's on my linux webserver?

Nikolas
Wed 3 October 2007, 10:39 am GMT +0200
Yes it is possible, but not for all apps.

But I know that applications like Photoshop can run with Wine

purple
Mon 30 June 2008, 08:17 pm GMT +0200
A question here, if someone hacks your wordpress blog, is it that they can redirect your earning to their payment systems. What really is the danger?

aaron_s
Tue 1 July 2008, 06:19 am GMT +0200
You should never want anyone to "hack" you no matter what the side effects.  A  lot of times they'll use the site to provide more links to their site - or to embed spyware.  Either way, you own the site, no one else should put content on there as a matter of principle.  Its like this:  if a homeless man moves into your living room but doesn't steal anything, is it ok for him to come in and stay uninvited?

samiotis
Tue 1 July 2008, 06:23 am GMT +0200
Redirecting your earnings would require a hacker to implement his own e.g. Goggle id into your site, that's not likely to happen. More likely is that a hacker will place links and other codes like i-frames in your site to increase his own traffic and ping rate or even spy on your member information.

WordPress has become much more reliable since the start of this threat. I wonder if anybody had some security issues since the upgrade to 2.5.1 ?? It has become very quiet in this section.

classylady
Wed 19 November 2008, 08:29 pm GMT +0100
WP is a very good CMS. In fact is one of the best. Now regarding those security wholes, don't think that they are simple as an SQL injection, and in most cases they are not a threat for most sites. But in the bottom line I think it is better to update some good software instead of developing such a thing (and believe me WP is a really huge project)

As for windows, it is true that we should start using linux, especially now that is very easy to be used (plus windows apps can run too)

I'm in agreement with every facet of the above post.  Although WP has been known to be hit more times than similar platforms such as Blogger, it's only because of it's continued popularity and the multitudes of people migrating towards it.  It's a lot like people using Windows.  Hacker IMHO have a keen interest in making sure that if they're going to put in the time and effort to hack into something, they might as well hit the machines that are in most use regarding the one thing society needs most to survive:  Currency.  As far as a Linux Machine:  Wouldn't that be grand, huh?  Personally, I think that if someone were smart enough to make a "dumbed up" version of Fedora or Ubuntu that is 100% GUI (with the option of CLI in a sort of "advanced" install) would yield more "mainstream" computer users to try it out.  Yes, I realize that with the addition of the Fedora 9 it brings the masses that much closer to that goal, but hopefully with what I've been reading about 10...well, we'll see.

Archive for SMF v1.00 by N.P. Valid XHTML 1.0 Transitional