Wordpress Exploit and Dreamhost

Added : http://trac.wordpress.org/changeset/5570 not a patch but a fix

If you have the last unpatched wordpress 2.2 there is a problem in the xml-rpc module, people if they have a valid username and password can use an SQL Injection exploit. The common usage has been adding hidden links into the template was control of your blog has been lost to the bad guys

Also Dreamhost leaked 3500 FTp username and passwords, so IF you have WP or hosted on dreamhost.

a) Check you source code for hidden links that aren’t your ;)
b) Check the HTaccess file for any odd entries, like a 310 to Bad guys site on you ranking pages
c) Check your robots.txt… yes some idiots thinks it funny to hack you server and block all spiders !!
d) Check for proxy scripts that may have been installed on your server

DaveN

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • Sphinn
  • Live
  • StumbleUpon
  • Facebook
  • Google
  • Reddit
  • Technorati

5 Comments | Leave a comment »

  1. 1. Adam | June 7th 2007 @ 10:09 am

    What’s the deal with this? Is there a new version of wordpress that fixes the exploit or does it only effect versions prior 2.2?

  2. 2. gabs | June 7th 2007 @ 12:18 pm
  3. 3. Steve Johnson | June 8th 2007 @ 12:40 am

    This is why I only use http://www.made2own.com for all of my hosting needs. Made2Own takes security very seriously, and their support is incredible. You huys should definitely give them a look.

  4. 4. Bill | June 8th 2007 @ 9:41 pm

    Thanks for mentioning this–I’ll definitely take a look at all of my WP installations.

  5. 5. Mylo | January 31st 2008 @ 11:36 pm

    thanks for this useful article it will help me on my WP installations.

Leave a Reply

required

required, hidden

smx

Start with £50 credit in your new Yahoo! Search Marketing account for a limited period only.

+ Advertise Here