WordPress Alert

by Mitch on September 5, 2009

The following information is for Wordpress users that are on a self-hosted site.  All wordpress users that aren’t currently using version 2.8.4 are advised to upgrade.  For the last couple days, I’ve been reading plenty of other sites that have been talking about the Wordpress attack. And the most comprehensive one is on Lorelle.  I recommend that you take note of the post.  Incase you don’t read it , I will post a couple excerpts here.

“Here is what you need to know right now.

  1. UPDATE NOW! Reports are that this attack impacts ALL versions of WordPress up to 2.8.4, the most recent release.
  2. What Version Am I Using? If you are using a WordPress version after 2.7, the nag screen on the WordPress Administration Panels will alert you to upgrade. If you are using an older version, upgrade now.
  3. Use a WordPress Plugin for Protection: Do not rely upon a WordPress Plugin to protect you. There are many reports of Plugins that will “help” in the comments. While they might help in other ways, please upgrade now. That is the only solution if your site has not been impacted.
  4. WordPress is Not Secure: WordPress is incredibly secure and monitored constantly by experts in web security. This attack was well anticipated and so far, WordPress 2.8.4 is holding. If necessary, WordPress will immediately release a update with further security improvements. WordPress is used by governments, huge corporations, and me, around the world. Millions of bloggers are using WordPress.com. Have faith they are working overtime to monitor this situation and protect your blog. wordpress-logo
  5. Fear of Upgrading: This attack is serious enough to overcome all your fears of updating. If older WordPress Plugins are holding you back, update them to the latest version or replace them with new. If your Theme might break, contact the Theme author and update or replace it. There are thousands of free Themes to choose from, probably some better than what you are using. If you are using a recent version of WordPress, updating is as easy as clicking a couple buttons. If you are using an older version, download the most recent version and upgrade now.
  6. Other Issues? Whatever your issue is that keeps you from updating WordPress, get over it and update now to protect your site.

There are two clues that your WordPress site has been attacked.

There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode

($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”

The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account, but Journey Etc. has a possible solution.

WordPress.com blogs are not impacted as they are up-to-date. Only versions prior to WordPress 2.8.4 are impacted.”

To prevent a Wordpress attack do the following.

  • Change Wordpress password to a strong password.
  • Change your database password
  • Change your control panel password
  • Change all of your passwords.

Notice the patern?

If you have any further concerns, you can contact me or another wordpress professional to update your site and/or fix your site if it’s been hacked.

I notice this is your first time visiting, you may want to subscribe to my RSS feed. Thanks for visiting!

{ 1 comment… read it below or add one }

testing September 15, 2009 at 10:07 am

testing gravitor

[Reply]

Leave a Comment

CommentLuv Enabled

Previous post:

Next post: