5, December 2008

A New WordPress Virus - webmaster forum

 
Webdigity webmaster forums
This forum shares its ad revenue with its members!
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  PhP
Topic: A New WordPress Virus
« previous next »
Pages: [1] Print

Author Topic: A New WordPress Virus  (Read 440 times)
Google dot what?
*
Posts: 2
16 credits
Members referred : 0


« on: Sep 13, 2008, 03:07:29 PM »

Recently, we have accidentally discovered in our blog posts a new dangerous viral activity based on an advertising script that exploits the security leaks of WordPress platform. This type of attack could be also present in the tens of millions of online WordPress blogs.

The virus actions upon WordPress platform by inserting a .PHP file in the root of the installation directory and then it connects to the database. On a successful connection various blog posts are modified with long lists of spam links masked with CSS. (the visitors cannot see them, but the search engine robots index those links). As a consequence, you will have to manually check all of your posts and remove the link after the .PHP file removal. The most simple solution to check the affected posts is to create an xml file of RSS feeds from all of your posts and view them in an RSS reader. The entire article is available here http://www.downloadtube.com/blog/2008/09/12/a-new-powerful-virus-could-affect-millions-of-wordpress-blogs/ Visit through proxy.
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6486
39748 credits
Members referred : 374


It's time to use PHP5!


« Reply #1 on: Sep 14, 2008, 10:54:50 AM »

I think this virus is for stupid WP users, if you download a plugin outside the WP site you should aways check the files.



Last blog : Just a better Internet portal provided by Google
Google dot what?
*
Posts: 2
16 credits
Members referred : 0


« Reply #2 on: Sep 14, 2008, 04:52:59 PM »

I think this virus is for stupid WP users, if you download a plugin outside the WP site you should aways check the files.



It is true, but from our information the virus was not determined by a plugin. It was determined by an attack (SQL injection).
Community Supporter ?
I am a fanatic. So?
*****
Gender: Male
Posts: 589
5476 credits
Members referred : 0


www.dg9.org


« Reply #3 on: Sep 16, 2008, 08:56:57 AM »

Any active site (php and such) will have vulnerabilities and wordpress as one could be affected by this... So altogether, sites can suffer from injection attacks, it's up to the webmaster to sift through logs and see vulnerabilities and insecure scripts or codes...

http://www.dg9.org Visit through proxy , Just Visit...
Partners:
http://www.resume-fix.com Visit through proxy , Free Resumes

Last blog : Archos: Where are you?
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6486
39748 credits
Members referred : 374


It's time to use PHP5!


« Reply #4 on: Sep 16, 2008, 09:30:18 AM »

He is talking about SQL injections, I know the WP code and I'm sure that this is not true (maybe he is looking for some visitors for his blog post)


Last blog : Just a better Internet portal provided by Google
My name is Bong, James Bong
*
Posts: 10
64 credits
Members referred : 0


« Reply #5 on: Oct 12, 2008, 10:43:48 PM »

Well WordPress recently released a new version so this may have been one of the exploits fixed.

Also, MySQL injections are nothing new, but the older bugs have been fixed by now for the most part. I just hope the latest version is secure, as for malicious plugins. You should only download the ones found in the official site or the ones mentioned in well known sites. Although some lesser known plugins might actually be good and safe, but unless you're experienced it might not be wise to take chances.
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=8006
Tags : wordpress wordpress virus wordpress security flaws Bookmark this thread : Digg Del.icio.us Dzone more....

Topic sponsors:
Get a permanent link here for $1.99!


Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  PhP
Topic: A New WordPress Virus
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Dec 05, 2008, 10:07:01 AM





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!


Forum Statistics
Total Posts: 37.995
Total Topics: 7.685
Total Members: 4.470
Tutorials : 56
Resources : 143
Designs : 220
Latest Member: srinivasarao

25 Guests, 5 Users online :

10 users online today:



Readers

Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2008 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.