Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-07-2009, 07:21 PM   #1
kektex
Confirmed User
 
Industry Role:
Join Date: Mar 2005
Location: elkektex at gmail
Posts: 1,813
Upgrade Wordpress NOW

For those of you who have been putting off upgrading your blogs, now is the time to do it.
There's a wp worm doing the rounds inserting spam links and stuff.Apparently it's pretty efficient and the number of compromised WP installs is growing at an alarming rate.

http://lorelle.wordpress.com/2009/09...-under-attack/

http://www.journeyetc.com/uncategori...-rss-problems/
kektex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-07-2009, 07:33 PM   #2
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
those hackers!
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-07-2009, 07:42 PM   #3
kektex
Confirmed User
 
Industry Role:
Join Date: Mar 2005
Location: elkektex at gmail
Posts: 1,813
Fris, since you are the wp ninja I've been meaning to ask you something:
Is there any way to upgrade several blogs on various hosts automatically?

I've been thinking of installing WP Mu since I mostly use the same plugins on all my blogs and it might be easier to just use a single wpmu installation instead of going in and updating each one individually.

Is this a good idea?
kektex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-07-2009, 10:25 PM   #4
Joshua G
dumb libs love censorship
 
Industry Role:
Join Date: Jul 2008
Posts: 8,198
whats the point of updating if...

Reports are that this attack impacts ALL versions of WordPress up to 2.8.3 and 2.8.4, the most recent release.
Joshua G is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-07-2009, 10:29 PM   #5
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
I think we can insert a timeline pic here....

__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 12:53 AM   #6
pornocruto
Confirmed User
 
Join Date: Jan 2009
Posts: 1,308
Quote:
Originally Posted by sharphead View Post
I think we can insert a timeline pic here....

__________________

Promote EXTREME porn
Earn EXTREME $$$$
Only @ cash.pornocruto.es
pornocruto is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 02:04 AM   #7
TheDA
Confirmed User
 
Industry Role:
Join Date: May 2006
Posts: 4,665
Quote:
Originally Posted by kektex View Post
For those of you who have been putting off upgrading your blogs, now is the time to do it.
There's a wp worm doing the rounds inserting spam links and stuff.Apparently it's pretty efficient and the number of compromised WP installs is growing at an alarming rate.

http://lorelle.wordpress.com/2009/09...-under-attack/

http://www.journeyetc.com/uncategori...-rss-problems/
What are you supposed to upgrade to? That first link has people saying that 2.8.4 got exploited too!

Last edited by TheDA; 09-08-2009 at 02:07 AM..
TheDA is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 02:06 AM   #8
Voodoo
♥ ♦ ♣ ♠
 
Voodoo's Avatar
 
Industry Role:
Join Date: Sep 2002
Posts: 10,591
Why not just change your version number to a non-existent one, and move your admin directory?
__________________

"I'm selflessly supporting the common good, but only coincidentally looking out for No.1."
Voodoo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 03:26 AM   #9
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
remove_action('wp_head', 'wp_generator');
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 06:17 AM   #10
kektex
Confirmed User
 
Industry Role:
Join Date: Mar 2005
Location: elkektex at gmail
Posts: 1,813
Quote:
Originally Posted by TheDA View Post
What are you supposed to upgrade to? That first link has people saying that 2.8.4 got exploited too!
Hehe that obviously wasn't there when I posted this. When I read that site, it said that only versions prior to 2.8.4 were vulnerable.

This sucks.
kektex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 06:30 AM   #11
CaptainHowdy
Too lazy to set a custom title
 
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,567
Damm ........
CaptainHowdy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 06:37 AM   #12
The Duck
Adult Content Provider
 
The Duck's Avatar
 
Industry Role:
Join Date: May 2005
Location: Europe
Posts: 18,243
htaccess password protect your admin area.
__________________
Skype Horusmaia
ICQ 41555245
Email [email protected]
The Duck is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 07:02 AM   #13
Screwed Up
Confirmed User
 
Screwed Up's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: African Planet
Posts: 1,118
Quote:
Originally Posted by The Duck View Post
htaccess password protect your admin area.
What he said. And disallow any ip but your own...
Screwed Up is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 07:05 AM   #14
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
ya best way is to use htaccess in your admin area

http://www.wptavern.com/top-5-wordpr...ly-dont-follow
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 08:55 AM   #15
evildick
Guest
 
Posts: n/a
Quote:
Originally Posted by kektex View Post
Hehe that obviously wasn't there when I posted this. When I read that site, it said that only versions prior to 2.8.4 were vulnerable.

This sucks.
There are people reporting that their 2.84 versions are being hacked with this, but it appears they are just people that had older versions that were already hacked, then they just upgraded over top of the hacked site (they may or may not have known it was hacked already), which was too late.
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 09:15 AM   #16
Davy
Confirmed User
 
Davy's Avatar
 
Industry Role:
Join Date: Apr 2006
Location: Germany
Posts: 4,323
Show me a link to a hacked wordpress site or it didn't happen...
__________________
---
ICQ 14-76-98 <-- I don't use this at all
Davy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 09:19 AM   #17
~Ray
visit hardlinks.org
 
~Ray's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Las Vegas , Nv >>> [email protected] or icq 94994627 anytime
Posts: 18,362
just turn off the 777 settings after you finish editing your blog. Then nothing can be modified. Lots of peeps forget to do that.
~Ray is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 09:19 AM   #18
VforVendetta
Confirmed User
 
VforVendetta's Avatar
 
Join Date: Mar 2006
Posts: 2,526
Thanks for the advise
__________________
Free the world
VforVendetta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 09:28 AM   #19
Tjeezers
Webmaster
 
Tjeezers's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: BP4L - NL/RO
Posts: 16,572
Quote:
Originally Posted by fris View Post
ya best way is to use htaccess in your admin area

http://www.wptavern.com/top-5-wordpr...ly-dont-follow
I was one of the dumb people who dont give a jerk about security
Until i got flipped years ago by it..You need to feel to believe i think.

Stop acting like your blind, and follow those 5 simple steps to disappear from the eye of the bad one. You dont want your shit to be hacked I am SURE!!!!!!!!!!


DO THOSE TIPS!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
__________________
Enroll in the SWAG Affiliate Asian Live Cam Program and get 9 free quality linkbacks from my network!
Wanna see how old school I am? Look at this! All my Cam Review Sites are here!
Tjeezers is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 09:31 AM   #20
Tjeezers
Webmaster
 
Tjeezers's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: BP4L - NL/RO
Posts: 16,572
PS i Use the Admin Redirect
I have asked many to access it, they only see my main site
Their IP is not allowed to come even close to what is called ADMIN

This is one of the best basic " Safe your own ass " things you can do
Takes you 5 minutes to upload one file to your wp-admins


PS i thank GFY for making me aware of those issues more. Turning a blind eye here is not so easy when you want to make some money. Props to Fris!
__________________
Enroll in the SWAG Affiliate Asian Live Cam Program and get 9 free quality linkbacks from my network!
Wanna see how old school I am? Look at this! All my Cam Review Sites are here!
Tjeezers is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 09:40 AM   #21
ilbb
Confirmed User
 
ilbb's Avatar
 
Industry Role:
Join Date: May 2005
Location: EU - Czech republic
Posts: 3,025
I've script that checks CRC of my PHP files every 15minutes.
ilbb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 10:16 AM   #22
tranza
ICQ: 197-556-237
 
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
Quote:
Originally Posted by sharphead View Post
I think we can insert a timeline pic here....

I always laugh when I see this...
__________________
I'm just a newbie.
tranza is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 10:20 AM   #23
NoWhErE
Too lazy to set a custom title
 
NoWhErE's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Canada
Posts: 10,383
I suck at HTACCESS, could someone post the code for the admin area?
__________________
skype: lordofthecameltoe
NoWhErE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2009, 11:35 AM   #24
Sunny
Confirmed User
 
Sunny's Avatar
 
Join Date: Feb 2007
Posts: 1,981
but please be careful!! first back up your data and then upgrade your wp script
Sunny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.