BleepingComputer.com: Wordpress 2.1 Appears To Be Hacked

Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Wordpress 2.1 Appears To Be Hacked Copyright Wordpress

#1 User is offline   fozzie 

  • aut viam inveniam aut faciam
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 3,516
  • Joined: 14-November 06
  • Gender:Male
  • Location:Ossendrecht/The Netherlands

Posted 05 March 2007 - 10:21 AM

Quote

Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation: This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.


Here is the whole article by Wordpress
Posted Image
Free antivirus : AVG Free Free Anti-spyware AVG Anti Spyware
Free Firewall :Zone Alarm Ccleaner Ad aware & Manual
SpybotS&D&Manual Free Handy programs

#2 User is offline   JoshT 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 115
  • Joined: 25-February 07

Posted 05 March 2007 - 01:37 PM

Hahaha...

That's the way to do it.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users