Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

CNET: WordPress blogs falling prey to worm (makes itself an admin, uses JavaScript to hide itself)

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
Amerigo Vespucci Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-05-09 08:00 PM
Original message
CNET: WordPress blogs falling prey to worm (makes itself an admin, uses JavaScript to hide itself)
WordPress blogs falling prey to worm

by Jennifer Guevin

A worm is circulating that can post malware and spam to some WordPress blogs using outdated versions of the blogging software, according to a post by Matt Mullenweg, founding developer of WordPress.

The worm can be tough to catch, as Mullenweg explains: "it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts."

The vulnerability allowing the attack was discovered August 11, at which point WordPress encouraged users to upgrade to version 2.8.4. However, many people have yet to upgrade, and reports online indicate the worm is making dubious progress by the hour.

The worm does not affect the current version 2.8.4 and the one prior to it. And it only affects people who host their own WordPress blog. Blogs hosted on WordPress.com are unaffected.

Users can find upgrade links and instructions here: http://codex.wordpress.org/Upgrading_WordPress

WordPress has also posted an FAQ for people who think their blog has been hacked: http://codex.wordpress.org/FAQ_My_site_was_hacked

http://news.cnet.com/8301-1009_3-10345900-83.html?part=rss&subj=news&tag=2547-1_3-0-5
Printer Friendly | Permalink |  | Top
Deja Q Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-05-09 08:03 PM
Response to Original message
1. Isn't Wordpress owned by, you guessed it, MICROSOFT?
When will that amateurish organization go under? Anyone else constantly putting out sub-par crap usually gets run out of town...
Printer Friendly | Permalink |  | Top
 
Irreverend IX Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-05-09 08:18 PM
Response to Reply #1
3. Yes, Microsoft is well known for promoting open-source PHP-based applications. nt
Printer Friendly | Permalink |  | Top
 
rocktivity Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-05-09 08:15 PM
Response to Original message
2. I got that worm on a Wordpress site I'm still assembing
Edited on Sat Sep-05-09 08:19 PM by rocktivity
Twice recently, someone "joined" the site without my permission. I got a bunch a weird URLS under my footer. I'll check the header for weird javascripts, too.


rocktivity

Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 03:59 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC