September 6th, 2009 by Mayank Agarwal

4 Comments Share

wordpress attack WordPress Under Attack, Upgrade To 2.8.4 ASAPStatutory Warning : If you have not upgraded your WordPress hosted blog to version 2.8.4 then do it right away. WordPress versions below 2.7 are highly venerable to this attack. Matt Mullenweg founder of Wordpress has responded in the WordPress Blog saying

“Right now there is a worm making its way around old, unpatched versions of WordPress. This particular worm, like many before it, is clever: it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts.”

How to check whether your blog is attacked ?

1). Addition of keywords like “eval” and “base64_decode” in your permalinks.

2). An additional Administrator is created. Check your dashboard for an unknow user.

Read this blog by Lorelle on how to secure your blog and what to do if it has already been attacked. Check out the Follow-Up section for a step by step guide to secure your blog.

___________________________________________________________________________

Follow-Up

Step 1 : Create a backup of your database

Step 2 : Create a backup of your WordPress Site

Step 3 : Upgarde to version 2.8.4

Story Follow-Up

Scobleizer: I don’t feel safe with Wordpress, hackers broke in and took things by Robert Scoble

Mashable!: WordPress Responds to Attack: “Please Upgrade” by Pete Cashmore

TechCrunch: Security Threat: WordPress Under Attack by Daniel Brusilovsky

TECH.BLORGE.com: WordPress blogs under serious attack; immediate upgrades the only defense by Sean P. Aune

Discussion @ friendfeed

(Image credit - Developer Tutorials)

  • Share/Bookmark

4 Responses to “WordPress Under Attack, Upgrade To 2.8.4 ASAP”


  1. discodaug

    4 months ago

    Hi,

    thanks for the great quality of your website, every time i come here, i’m amazed.

    I would like to suggest you to come and try the true black hattitude.
    you’ll find a lot of tricks related to the black hattitude,

    You can buy some black hattitude, rent black hattitude, steal black hattitude, or find
    the ultimate black hattitude on our sites ofblack hattitude.

    have a nice day,

    John McCormick

    black hattitude

    you’ll find here also some good black hattitude

    Reply

  2. drlemon

    2 months ago

    SEE! LOOK AT THE OTHER COMMENT!!! EVERYONE IS AT RISK! if you search black hattitude spam on google, you will find that A WHOLE F***ING LOT OF PEOPLE have had the same problem.

    Reply

    • Mayank Agawal
      (Twitter: @ mayank25may )

      2 months ago

      Yep.. I dont know how this guy made thru the spam filter… Think Wordpress spam filter will catch this kind of spam soon.

      Reply

1 Trackbacks For This Post

  1. WordPress Under Attack, Upgrade To 2.8.4 ASAP Says:

    [...] the original post here: WordPress Under Attack, Upgrade To 2.8.4 ASAP Comments0 Leave a Reply Click here to cancel [...]

Leave a Reply