Browse How To’s

Worm Attack Targets Unpatched And Older Wordpress Versions

In case you haven’t heard yet, there’s a worm that’s work­ing its way around old and unpatched ver­sions of Word­Press. Already it has infected some, includ­ing sites that belong to tech celebri­ties Robert Scoble and Andy Ihnatko.

Accord­ing to the Word­Press Blog, this worm is a clever one: it reg­is­ters a user, uses a secu­rity bug (fixed ear­lier in the year) to allow eval­u­ated code to be exe­cuted through the perma­link struc­ture, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hid­den spam and mal­ware into your old posts.

Every­one who owns or man­ages a Word­Press site is advised to upgrade to the lat­est ver­sion 2.8.4 since this, as well as the one before that, is immune to the worm.

How do you know you cur­rent ver­sion? Ver­sions 2.7 and later has a nag notice on the dash­board that tells you to upgrade. If you don’t see that nag notice, then you are using an even older ver­sion of Word­Press. Upgrade to the lat­est ver­sion here.

This recent inci­dent raised the ques­tion of whether Word­Press is a secure pro­gram. Tech­ni­cally, any soft­ware that is not not updated reg­u­larly is vul­ner­a­ble to hack attacks. So it’s a mat­ter of get­ting your site up-​​to-​​date as soon as the lat­est ver­sion becomes available.

I would also rec­om­mend con­duct­ing reg­u­lar back­ups to keep your data safe and secure.

To learn more about this issue by vis­it­ing the fol­low­ing links:

* http://​word​press​.org/​d​e​v​e​l​o​p​m​e​n​t​/​2​0​0​9​/​0​9​/​k​e​e​p​-​w​o​r​d​p​r​e​s​s​-​s​e​c​u​re/
* http://​lorelle​.word​press​.com/​2​0​0​9​/​0​9​/​0​4​/​o​l​d​-​w​o​r​d​p​r​e​s​s​-​v​e​r​s​i​o​n​s​-​u​n​d​e​r​-​a​t​t​a​ck/
* http://​www​.guardian​.co​.uk/​t​e​c​h​n​o​l​o​g​y​/​2​0​0​9​/​s​e​p​/​0​9​/​w​o​r​d​p​r​e​s​s​-​h​a​c​k​i​n​g​-​b​l​o​g​g​ing

To get more infor­ma­tion about the lat­est trends on Word­Press design, visit http://​10word​press​.com/

Related posts:

  1. Word­Press Blogs Attack and Hack
  2. Word­Press 2.9.2 Upgrade Secu­rity Fix
  3. Hack Attack: Just How Secure is Your Word­Press Blog?
  4. How to Detect and Pre­vent a Word­Press Spam Injec­tion Attack
  5. The­sis Theme is the best Word­Press SEO theme for Bloggers
Please register to be able to comment. Or, log in if you already have an account with us.

Leave a Reply




Motherboard Repair Guide * How To Repair Laptops * Hard Drive Repair Tips * SEO Tools * Money Online Tips * Wordpress Security Guide * Wordpress SEO Tools * Forum