5, September 2008

Wordpress worm - webmaster forum

 
Webdigity webmaster forums
This forum shares its ad revenue with its members!
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  PhP
Topic: Wordpress worm
« previous next »
Pages: [1] Print

Author Topic: Wordpress worm  (Read 1272 times)
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2173
5036 credits
Members referred : 2


Venture Skills - New Media & IT group


« on: Aug 01, 2007, 01:54:55 PM »

Might be time to think about upgrading your  wordpress sites as over 7 security flaws have been found in wordpress 2.2.1 enough that some one has actually created the first Wordpress Worm http://paymentblogger.com/2007/08/01/wordpress-blues-solved-with-a-worm/ Visit through proxy

It uses XSS to "patch" your PHP files to fix the hole but how long before some one else develops a more nefarious one, if your not familiar with the idea of XSS attacks then this article may help http://ventureskills.wordpress.com/2007/05/30/cross-site-scripting-a-pointless-seo-tactic/ Visit through proxy

Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO Visit through proxy alternatively for Social media optimisation take a look at the Venture Skills Blog Visit through proxy

Last blog : Its all in the mp3s
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 8037
41179 credits
Members referred : 3



« Reply #1 on: Aug 01, 2007, 02:06:18 PM »

I don't get it. Wordpress mentions nothing on this problem at their blog....

BTW do you know if version 2.2 is vulnerable?

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2173
5036 credits
Members referred : 2


Venture Skills - New Media & IT group


« Reply #2 on: Aug 01, 2007, 02:19:59 PM »


Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO Visit through proxy alternatively for Social media optimisation take a look at the Venture Skills Blog Visit through proxy

Last blog : Its all in the mp3s
What's HTML?
****
Gender: Male
Posts: 402
2430 credits
Members referred : 2



« Reply #3 on: Aug 01, 2007, 03:33:44 PM »

Nikolas,
I don't think they want to make a big fuss about the vulnerabilities,
since they don't want people to get ideas about attacking other wordpress sites ...


Last blog : SeoDigger: Free Keyword Research tool
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6307
38662 credits
Members referred : 374


It's time to use PHP5!


« Reply #4 on: Aug 01, 2007, 04:16:27 PM »

most of the vulnerabilities are only if the attacker has admin rights...


Last blog : Is your website is down? Know before your visitors do!
Novice Spammer
***
Posts: 103
552 credits
Members referred : 0



« Reply #5 on: Aug 02, 2007, 12:52:35 PM »

most of the vulnerabilities are only if the attacker has admin rights...
What do you mean. Is it possible to get admin rights for anyone or do they need to have the admin password to use the vulnerabilities or do you mean that admins with too low security on their passwords are easy targets?

I have about 7 blogs I need to upgrade so I guess I better start today Cheesy

/Andreas
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6307
38662 credits
Members referred : 374


It's time to use PHP5!


« Reply #6 on: Aug 02, 2007, 12:58:56 PM »

most of the vulnerabilities are only if the attacker has admin rights...
What do you mean. Is it possible to get admin rights for anyone or do they need to have the admin password to use the vulnerabilities or do you mean that admins with too low security on their passwords are easy targets?

I have about 7 blogs I need to upgrade so I guess I better start today Cheesy

/Andreas

the hacker needs admin rights...


Last blog : Is your website is down? Know before your visitors do!
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2173
5036 credits
Members referred : 2


Venture Skills - New Media & IT group


« Reply #7 on: Aug 02, 2007, 01:06:31 PM »

not in all cases though Wink however the worm works by getting an admin to click the link and therefore give the admin rights.

Now a malicious worm would say send a trackback to you, you see it in the stats what do you do?
So having a strong password in this scenario won't help

Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO Visit through proxy alternatively for Social media optimisation take a look at the Venture Skills Blog Visit through proxy

Last blog : Its all in the mp3s
Novice Spammer
***
Posts: 103
552 credits
Members referred : 0



« Reply #8 on: Aug 02, 2007, 09:23:51 PM »

Thanks for the warning. I have upgraded all my blogs now (at least the once using wordpress Cheesy )

/Andreas
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2173
5036 credits
Members referred : 2


Venture Skills - New Media & IT group


« Reply #9 on: Aug 06, 2007, 09:45:01 AM »

http://wordpress.org/development/2007/08/wordpress-222-and-2011/ Visit through proxy
Official upgrade announced and ready to download Cheesy

Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO Visit through proxy alternatively for Social media optimisation take a look at the Venture Skills Blog Visit through proxy

Last blog : Its all in the mp3s
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6307
38662 credits
Members referred : 374


It's time to use PHP5!


« Reply #10 on: Aug 06, 2007, 10:00:58 AM »

http://wordpress.org/development/2007/08/wordpress-222-and-2011/ Visit through proxy
Official upgrade announced and ready to download Cheesy

do you checked if all problems are fixed with this update?


Last blog : Is your website is down? Know before your visitors do!
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=6970
Tags : xss wordpress Bookmark this thread : Digg Del.icio.us Dzone more....

Topic sponsors:
Get a permanent link here for $1.99!


Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  PhP
Topic: Wordpress worm
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Sep 05, 2008, 07:46:45 AM





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!


Forum Statistics
Total Posts: 36.290
Total Topics: 7.476
Total Members: 3.897
Tutorials : 56
Resources : 143
Designs : 220
Latest Member: FlorianHofmann

20 Guests, 4 Users online :

14 users online today:



Readers

Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2008 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.