13, February 2012

Wordpress : Another security problem.... - webmaster forum

 
Webdigity webmaster forums
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Wordpress : Another security problem....
« previous next »
Pages: [1] Print
Instabuck - The easy way to sell digital products online

Author Topic: Wordpress : Another security problem....  (Read 3951 times)
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5778
46265 credits
Members referred : 3



« on: Mar 06, 2007, 04:22:17 pm »

It looks like wordpress has hacking problems again...

This time it looks like someone intruded in their servers and replaced the official download of the 2.1.1 version with a hacked one.

Sounds bad for a software that already loses its reputation.

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6691
34714 credits
Members referred : 374


It's time to use PHP5!


« Reply #1 on: Mar 06, 2007, 05:10:39 pm »

nice software!

maybe I should use blogger...


Last blog : A new Wordpress theme for our blog
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5778
46265 credits
Members referred : 3



« Reply #2 on: Sep 09, 2007, 03:05:11 pm »

As there are so many security updates for wordpress, I guess it could be better to post to this thread instead of opening a new one.

So, for another time WP has some security issues Smiley

http://wordpress.org/development/2007/09/wordpress-223/

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
aka J Love
Community Supporter ?
Bill Gates is my home boy
*****
Gender: Male
Posts: 886
1148 credits
Members referred : 4



« Reply #3 on: Oct 02, 2007, 01:12:04 am »

ya this is why i left wordpress almost over a year ago.. i had some security problems with it and haven't trusted it since.. its what inspired me to just do my own thing


Last blog : phpHaze 1.59.1 in Development
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6691
34714 credits
Members referred : 374


It's time to use PHP5!


« Reply #4 on: Oct 02, 2007, 07:20:54 am »

I have 4 WP blogs (and no time to post enough Smiley)

the time savings because of the great features are bigger than doing an upgrade ones in some time. In my opinion every software has security issues. @Method.
Maybe you need to to stop trusting windows too, they have much bigger issues Smiley


Last blog : A new Wordpress theme for our blog
Global Moderator
Internet Junkie
*****
Gender: Male
Posts: 1807
9006 credits
Members referred : 6



« Reply #5 on: Oct 02, 2007, 10:45:40 am »

I agree with Olaf, the security issues are not really a big issue if you keep your software up to date.


Last blog : Are You Stumbling Yet?
aka J Love
Community Supporter ?
Bill Gates is my home boy
*****
Gender: Male
Posts: 886
1148 credits
Members referred : 4



« Reply #6 on: Oct 02, 2007, 05:29:12 pm »

stop trusting windows as my personal machine? LOL and then use what, Linux or something [ROFL]? sure windows has its own security problems, and wordpress, but we are talkin about an internet application, not an operating system Wink wordpress has more security problems than it has good features in my opinion

and as far as "keeping it upto date for security reasons" goes,  how often do they release a security patch anyway?


Last blog : phpHaze 1.59.1 in Development
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6691
34714 credits
Members referred : 374


It's time to use PHP5!


« Reply #7 on: Oct 02, 2007, 09:44:18 pm »



and as far as "keeping it upto date for security reasons" goes,  how often do they release a security patch anyway?

still have the time for blog posts!


Last blog : A new Wordpress theme for our blog
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5778
46265 credits
Members referred : 3



« Reply #8 on: Oct 03, 2007, 01:43:48 am »

WP is a very good CMS. In fact is one of the best. Now regarding those security wholes, don't think that they are simple as an SQL injection, and in most cases they are not a threat for most sites. But in the bottom line I think it is better to update some good software instead of developing such a thing (and believe me WP is a really huge project)

As for windows, it is true that we should start using linux, especially now that is very easy to be used (plus windows apps can run too)

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
aka J Love
Community Supporter ?
Bill Gates is my home boy
*****
Gender: Male
Posts: 886
1148 credits
Members referred : 4



« Reply #9 on: Oct 03, 2007, 06:17:42 am »

linux running windows apps eh? now you've caught my attention. Vista cant even run some Xp apps! lol Cool


Last blog : phpHaze 1.59.1 in Development
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6691
34714 credits
Members referred : 374


It's time to use PHP5!


« Reply #10 on: Oct 03, 2007, 07:20:41 am »

I think Nick is telling that windows apps can be used on linux


Last blog : A new Wordpress theme for our blog
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5778
46265 credits
Members referred : 3



« Reply #11 on: Oct 03, 2007, 10:16:25 am »

You can run windows apps to linux with the help of wine Smiley

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6691
34714 credits
Members referred : 374


It's time to use PHP5!


« Reply #12 on: Oct 03, 2007, 10:28:17 am »

cool name "Wine"!

from their website:
Quote
however Wine can optionally use native Windows DLLs if they are available.

will say with wine I can run dll's on my linux webserver?


Last blog : A new Wordpress theme for our blog
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5778
46265 credits
Members referred : 3



« Reply #13 on: Oct 03, 2007, 10:39:26 am »

Yes it is possible, but not for all apps.

But I know that applications like Photoshop can run with Wine

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Sandwich Artist
*
Posts: 25
170 credits
Members referred : 0


« Reply #14 on: Jun 30, 2008, 08:17:39 pm »

A question here, if someone hacks your wordpress blog, is it that they can redirect your earning to their payment systems. What really is the danger?
Community Supporter ?
Hunky Junky Monky Man!
**
Gender: Male
Posts: 68
436 credits
Members referred : 0


Schwa?


« Reply #15 on: Jul 01, 2008, 06:19:15 am »

You should never want anyone to "hack" you no matter what the side effects.  A  lot of times they'll use the site to provide more links to their site - or to embed spyware.  Either way, you own the site, no one else should put content on there as a matter of principle.  Its like this:  if a homeless man moves into your living room but doesn't steal anything, is it ok for him to come in and stay uninvited?
Small Business Internet Marketing
Alice in WindowsLand
****
Gender: Male
Posts: 225
142 credits
Members referred : 0

More than just a Webmaster


« Reply #16 on: Jul 01, 2008, 06:23:09 am »

Redirecting your earnings would require a hacker to implement his own e.g. Goggle id into your site, that's not likely to happen. More likely is that a hacker will place links and other codes like i-frames in your site to increase his own traffic and ping rate or even spy on your member information.

WordPress has become much more reliable since the start of this threat. I wonder if anybody had some security issues since the upgrade to 2.5.1 ?? It has become very quiet in this section.


Last blog : How to Setup Wordpress - A 51 Step Guide
Cyberpunk Wannabe
*
Gender: Female
Posts: 43
262 credits
Members referred : 0


« Reply #17 on: Nov 19, 2008, 08:29:35 pm »

WP is a very good CMS. In fact is one of the best. Now regarding those security wholes, don't think that they are simple as an SQL injection, and in most cases they are not a threat for most sites. But in the bottom line I think it is better to update some good software instead of developing such a thing (and believe me WP is a really huge project)

As for windows, it is true that we should start using linux, especially now that is very easy to be used (plus windows apps can run too)

I'm in agreement with every facet of the above post.  Although WP has been known to be hit more times than similar platforms such as Blogger, it's only because of it's continued popularity and the multitudes of people migrating towards it.  It's a lot like people using Windows.  Hacker IMHO have a keen interest in making sure that if they're going to put in the time and effort to hack into something, they might as well hit the machines that are in most use regarding the one thing society needs most to survive:  Currency.  As far as a Linux Machine:  Wouldn't that be grand, huh?  Personally, I think that if someone were smart enough to make a "dumbed up" version of Fedora or Ubuntu that is 100% GUI (with the option of CLI in a sort of "advanced" install) would yield more "mainstream" computer users to try it out.  Yes, I realize that with the addition of the Fedora 9 it brings the masses that much closer to that goal, but hopefully with what I've been reading about 10...well, we'll see.
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=6175
Tags : wordpress security vurnerabillity Bookmark this thread : Digg Del.icio.us Dzone more....

Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Wordpress : Another security problem....
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Feb 13, 2012, 08:19:40 pm





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!






Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2012 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.