GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Upgrade Wordpress NOW (https://gfy.com/showthread.php?t=926319)

kektex 09-07-2009 07:21 PM

Upgrade Wordpress NOW
 
For those of you who have been putting off upgrading your blogs, now is the time to do it.
There's a wp worm doing the rounds inserting spam links and stuff.Apparently it's pretty efficient and the number of compromised WP installs is growing at an alarming rate.

http://lorelle.wordpress.com/2009/09...-under-attack/

http://www.journeyetc.com/uncategori...-rss-problems/

fris 09-07-2009 07:33 PM

those hackers!

kektex 09-07-2009 07:42 PM

Fris, since you are the wp ninja I've been meaning to ask you something:
Is there any way to upgrade several blogs on various hosts automatically?

I've been thinking of installing WP Mu since I mostly use the same plugins on all my blogs and it might be easier to just use a single wpmu installation instead of going in and updating each one individually.

Is this a good idea?

Joshua G 09-07-2009 10:25 PM

whats the point of updating if...

Reports are that this attack impacts ALL versions of WordPress up to 2.8.3 and 2.8.4, the most recent release.

Iron Fist 09-07-2009 10:29 PM

I think we can insert a timeline pic here....

http://www.nnteenmodels.net/gfy/timeline.jpg

pornocruto 09-08-2009 12:53 AM

Quote:

Originally Posted by sharphead (Post 16290501)
I think we can insert a timeline pic here....

http://www.nnteenmodels.net/gfy/timeline.jpg

:1orglaugh:1orglaugh:1orglaugh

TheDA 09-08-2009 02:04 AM

Quote:

Originally Posted by kektex (Post 16290115)
For those of you who have been putting off upgrading your blogs, now is the time to do it.
There's a wp worm doing the rounds inserting spam links and stuff.Apparently it's pretty efficient and the number of compromised WP installs is growing at an alarming rate.

http://lorelle.wordpress.com/2009/09...-under-attack/

http://www.journeyetc.com/uncategori...-rss-problems/

What are you supposed to upgrade to? That first link has people saying that 2.8.4 got exploited too!

Voodoo 09-08-2009 02:06 AM

Why not just change your version number to a non-existent one, and move your admin directory?

fris 09-08-2009 03:26 AM

remove_action('wp_head', 'wp_generator');

kektex 09-08-2009 06:17 AM

Quote:

Originally Posted by TheDA (Post 16290934)
What are you supposed to upgrade to? That first link has people saying that 2.8.4 got exploited too!

Hehe that obviously wasn't there when I posted this. When I read that site, it said that only versions prior to 2.8.4 were vulnerable.

This sucks.

CaptainHowdy 09-08-2009 06:30 AM

Damm ........

The Duck 09-08-2009 06:37 AM

htaccess password protect your admin area.

Screwed Up 09-08-2009 07:02 AM

Quote:

Originally Posted by The Duck (Post 16291366)
htaccess password protect your admin area.

What he said. And disallow any ip but your own...

fris 09-08-2009 07:05 AM

ya best way is to use htaccess in your admin area

http://www.wptavern.com/top-5-wordpr...ly-dont-follow

evildick 09-08-2009 08:55 AM

Quote:

Originally Posted by kektex (Post 16291327)
Hehe that obviously wasn't there when I posted this. When I read that site, it said that only versions prior to 2.8.4 were vulnerable.

This sucks.

There are people reporting that their 2.84 versions are being hacked with this, but it appears they are just people that had older versions that were already hacked, then they just upgraded over top of the hacked site (they may or may not have known it was hacked already), which was too late.

Davy 09-08-2009 09:15 AM

Show me a link to a hacked wordpress site or it didn't happen...

~Ray 09-08-2009 09:19 AM

just turn off the 777 settings after you finish editing your blog. Then nothing can be modified. Lots of peeps forget to do that.

VforVendetta 09-08-2009 09:19 AM

Thanks for the advise :)

Tjeezers 09-08-2009 09:28 AM

Quote:

Originally Posted by fris (Post 16291440)
ya best way is to use htaccess in your admin area

http://www.wptavern.com/top-5-wordpr...ly-dont-follow

I was one of the dumb people who dont give a jerk about security
Until i got flipped years ago by it..You need to feel to believe i think.

Stop acting like your blind, and follow those 5 simple steps to disappear from the eye of the bad one. You dont want your shit to be hacked I am SURE!!!!!!!!!!


DO THOSE TIPS!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Tjeezers 09-08-2009 09:31 AM

PS i Use the Admin Redirect
I have asked many to access it, they only see my main site
Their IP is not allowed to come even close to what is called ADMIN

This is one of the best basic " Safe your own ass " things you can do
Takes you 5 minutes to upload one file to your wp-admins


PS i thank GFY for making me aware of those issues more. Turning a blind eye here is not so easy when you want to make some money. Props to Fris!

ilbb 09-08-2009 09:40 AM

I've script that checks CRC of my PHP files every 15minutes.

tranza 09-08-2009 10:16 AM

Quote:

Originally Posted by sharphead (Post 16290501)
I think we can insert a timeline pic here....

http://www.nnteenmodels.net/gfy/timeline.jpg

I always laugh when I see this... :1orglaugh:1orglaugh:1orglaugh:1orglaugh

NoWhErE 09-08-2009 10:20 AM

I suck at HTACCESS, could someone post the code for the admin area?

Sunny 09-08-2009 11:35 AM

but please be careful!! first back up your data and then upgrade your wp script :)


All times are GMT -7. The time now is 08:02 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123