Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-30-2007, 01:57 PM   #1
Thumbking
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Canadabis
Posts: 1,067
Hacker alert: few blogs with wordpress 2.0.4 got hacked

So I was just about to update a few blogs and noticed that they were hacked....

It appears he only changed the title in them to let me know, but here is a warning to anyone else using wordpress 2.0.4...

this is what he put as a title "Hacked By Piratesgs[Turkish Hacker]"


http://www.google.ca/search?hl=en&q=...e+Search&meta=
Thumbking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 02:05 PM   #2
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
that's why I don't use wordpress
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 03:13 PM   #3
Walrus
Confirmed User
 
Join Date: May 2005
Location: USA
Posts: 2,150
How do they do it? Any why is Wordpress so vulnerable?
Walrus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 03:15 PM   #4
tranza
ICQ: 197-556-237
 
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
Damn, I'm sorry to hear that...
__________________
I'm just a newbie.
tranza is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 03:23 PM   #5
Andiz
Confirmed User
 
Andiz's Avatar
 
Join Date: Feb 2006
Posts: 2,594
Quote:
Originally Posted by u-Bob View Post
that's why I don't use wordpress
Stop using software in general if you are afraid for vulnerabilities

Quote:
Originally Posted by Walrus View Post
How do they do it? Any why is Wordpress so vulnerable?
Go and check out the change logs and you can find a way.

Wordpress is open source. Everyone can take a look at the code. You could say that Wordpress is safer thanks to this. But this is an example of when things go wrong. Always update your blogsoftware is my advice
Andiz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 03:26 PM   #6
FightThisPatent
Confirmed User
 
Join Date: Aug 2003
Location: Austin, TX
Posts: 4,090
you may want to blow out the wp folder and reinstall.. while it may seem like they only changed the title, they could have dropped in some additional php code/files that could be used as proxies, server controlling functions, etc


Fight the slash and burn!
__________________

http://www.t3report.com
(where's the traffic?) v5.0 is out! |
http://www.FightThePatent.com
| ICQ 52741957
FightThisPatent is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 03:45 PM   #7
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
prob cause they didnt delete the install and setup files
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 03:50 PM   #8
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
Quote:
Originally Posted by Andiz View Post
Stop using software in general if you are afraid for vulnerabilities
It's not about being afraid of vulnerabilities, it's about not using software with a bad track record.
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 04:03 PM   #9
Thumbking
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Canadabis
Posts: 1,067
Quote:
Originally Posted by Fris View Post
prob cause they didnt delete the install and setup files

I assure you this was deleted.
Thumbking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-30-2007, 04:39 PM   #10
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
Here is the deal:

Wordpress has had many versions since 2.0.0 - almost every one of them had at least some sort of security patch or correction in it. You don't have to be the worlds brightest hacker to take a newer version, compare it to the older version, and see where the code changes have happened. The code is all out there in public and not encoded in any manner.

2.0.4 is old - something like 10 versions ago (now 2.2.0). Keep it up to date, and the issues are small.
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.