GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Hacker alert: few blogs with wordpress 2.0.4 got hacked (https://gfy.com/showthread.php?t=737887)

Thumbking 05-30-2007 01:57 PM

Hacker alert: few blogs with wordpress 2.0.4 got hacked
 
So I was just about to update a few blogs and noticed that they were hacked....

It appears he only changed the title in them to let me know, but here is a warning to anyone else using wordpress 2.0.4...

this is what he put as a title "Hacked By Piratesgs[Turkish Hacker]"


http://www.google.ca/search?hl=en&q=...e+Search&meta=

u-Bob 05-30-2007 02:05 PM

that's why I don't use wordpress :)

Walrus 05-30-2007 03:13 PM

How do they do it? Any why is Wordpress so vulnerable?

tranza 05-30-2007 03:15 PM

Damn, I'm sorry to hear that...

Andiz 05-30-2007 03:23 PM

Quote:

Originally Posted by u-Bob (Post 12514662)
that's why I don't use wordpress :)

Stop using software in general if you are afraid for vulnerabilities

Quote:

Originally Posted by Walrus (Post 12515111)
How do they do it? Any why is Wordpress so vulnerable?

Go and check out the change logs and you can find a way.

Wordpress is open source. Everyone can take a look at the code. You could say that Wordpress is safer thanks to this. But this is an example of when things go wrong. Always update your blogsoftware is my advice :thumbsup

FightThisPatent 05-30-2007 03:26 PM

you may want to blow out the wp folder and reinstall.. while it may seem like they only changed the title, they could have dropped in some additional php code/files that could be used as proxies, server controlling functions, etc


Fight the slash and burn!

fris 05-30-2007 03:45 PM

prob cause they didnt delete the install and setup files

u-Bob 05-30-2007 03:50 PM

Quote:

Originally Posted by Andiz (Post 12515189)
Stop using software in general if you are afraid for vulnerabilities

It's not about being afraid of vulnerabilities, it's about not using software with a bad track record.

Thumbking 05-30-2007 04:03 PM

Quote:

Originally Posted by Fris (Post 12515324)
prob cause they didnt delete the install and setup files


I assure you this was deleted. :thumbsup

RawAlex 05-30-2007 04:39 PM

Here is the deal:

Wordpress has had many versions since 2.0.0 - almost every one of them had at least some sort of security patch or correction in it. You don't have to be the worlds brightest hacker to take a newer version, compare it to the older version, and see where the code changes have happened. The code is all out there in public and not encoded in any manner.

2.0.4 is old - something like 10 versions ago (now 2.2.0). Keep it up to date, and the issues are small.


All times are GMT -7. The time now is 09:26 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123