Sublime directory Surf the web anonymous Pagerank Monitor


Wordpress worm

ventureskills
Wed 1 August 2007, 12:54 pm GMT +0200
Might be time to think about upgrading your  wordpress sites as over 7 security flaws have been found in wordpress 2.2.1 enough that some one has actually created the first Wordpress Worm http://paymentblogger.com/2007/08/01/wordpress-blues-solved-with-a-worm/

It uses XSS to "patch" your PHP files to fix the hole but how long before some one else develops a more nefarious one, if your not familiar with the idea of XSS attacks then this article may help http://ventureskills.wordpress.com/2007/05/30/cross-site-scripting-a-pointless-seo-tactic/

Nikolas
Wed 1 August 2007, 01:06 pm GMT +0200
I don't get it. Wordpress mentions nothing on this problem at their blog....

BTW do you know if version 2.2 is vulnerable?

ventureskills
Wed 1 August 2007, 01:19 pm GMT +0200
http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm/
I believe it effects all versions in particular 2.2.1 which is the latest :)

GiorgosK
Wed 1 August 2007, 02:33 pm GMT +0200
Nikolas,
I don't think they want to make a big fuss about the vulnerabilities,
since they don't want people to get ideas about attacking other wordpress sites ...

olaf
Wed 1 August 2007, 03:16 pm GMT +0200
most of the vulnerabilities are only if the attacker has admin rights...

bylla
Thu 2 August 2007, 11:52 am GMT +0200
most of the vulnerabilities are only if the attacker has admin rights...
What do you mean. Is it possible to get admin rights for anyone or do they need to have the admin password to use the vulnerabilities or do you mean that admins with too low security on their passwords are easy targets?

I have about 7 blogs I need to upgrade so I guess I better start today :D

/Andreas

olaf
Thu 2 August 2007, 11:58 am GMT +0200
most of the vulnerabilities are only if the attacker has admin rights...
What do you mean. Is it possible to get admin rights for anyone or do they need to have the admin password to use the vulnerabilities or do you mean that admins with too low security on their passwords are easy targets?

I have about 7 blogs I need to upgrade so I guess I better start today :D

/Andreas

the hacker needs admin rights...

ventureskills
Thu 2 August 2007, 12:06 pm GMT +0200
not in all cases though ;) however the worm works by getting an admin to click the link and therefore give the admin rights.

Now a malicious worm would say send a trackback to you, you see it in the stats what do you do?
So having a strong password in this scenario won't help

bylla
Thu 2 August 2007, 08:23 pm GMT +0200
Thanks for the warning. I have upgraded all my blogs now (at least the once using wordpress :D )

/Andreas

ventureskills
Mon 6 August 2007, 08:45 am GMT +0200
http://wordpress.org/development/2007/08/wordpress-222-and-2011/
Official upgrade announced and ready to download :D

olaf
Mon 6 August 2007, 09:00 am GMT +0200
http://wordpress.org/development/2007/08/wordpress-222-and-2011/
Official upgrade announced and ready to download :D

do you checked if all problems are fixed with this update?

Archive for SMF v1.00 by N.P. Valid XHTML 1.0 Transitional