Worm Attack Targets Unpatched And Older WordPress Versions

Attack Unpatched And Versions

In case you haven’t heard yet, there’s a worm that’s working its way around old and unpatched versions of WordPress. Already it has infected some, including sites that belong to tech celebrities Robert Scoble and Andy Ihnatko.

According to the WordPress Blog, this worm is a clever one: “Iit registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts.”

Everyone who owns or manages a WordPress site is advised to upgrade to the latest version – 2.8.4 – since this, as well as the one before that, is immune to the worm.

How do you know you current version? Versions 2.7 and later has a nag notice on the dashboard that tells you to upgrade. If you don’t see that nag notice, then you are using an even older version of WordPress. Upgrade to the latest version here.

This recent incident raised the question of whether WordPress is a secure program. Technically, any software that is not not updated regularly is vulnerable to hack attacks. So it’s a matter of getting your site up-to-date as soon as the latest version becomes available.

I would also recommend conducting regular backups to keep your data safe and secure.

To learn more about this issue by visiting the following links:

* http://WordPress.org/development/2009/09/keep-WordPress-secure/
* http://lorelle.WordPress.com/2009/09/04/old-WordPress-versions-under-attack/
* http://www.guardian.co.uk/technology/2009/sep/09/WordPress-hacking-blogging

To get more information about the latest trends on WordPress design , visit http://10WordPress.com/

default Worm Attack Targets Unpatched And Older Wordpress Versions

At WordCamp NYC 2009 Brad Williams gives a lightning talk on methods of securing a WordPress installation. Baruch College NYC Nov 15 2009. www.strangework.com More vids: www.isoc-ny.org ISOC_NY 1686-26
Video Rating: 0 / 5

Find More WordPress Security Articles


15 Responses to “Worm Attack Targets Unpatched And Older WordPress Versions”

  1. Kyo~!! says:

    I kind of agree with one of the other answers. It depends on how deep your dreaming or how heavy your sleeping. I remember thinking of someone that I used to like all the time and I ended up having a dream about them but I couldn't tell if I had control of the dream. Sometimes it can also depend on if something or someone has been on your mind for a while and you end up having a dream about them.

  2. parche says:

    you just drink it down one shot, you barely feel it. Oh, you mean the dance not the one at the bottom of a tequila bottle right?????

  3. All these versions are really saying the same thing but to different groups of people who prefer different 'styles' of writing. The King James Version (KJV) which is also called the Authorized Versions (AV) is written in something like Shakespearean English. No-one in English speaking countries speaks like the people of Shakespeare's day spoke so there are many people who do not find that version easy to read.

    If you are not familiar with that style of English I would suggest you buy a copy of the New International Version (NIV). If you are in America you might prefer the [...]

  4. kyonowski says:

    The story of Dylan's “Blood On The Tracks” has been told many times–essentially, he re-recorded a bunch of songs on the album after a promo containing the original versions was released. Rumors of Columbia releasing a deluxe version of the album have floated around for years. Will it ever happen?

    (Interestingly, the “alternate versions” of these “Blood On The Tracks” cuts included on the 1991 “Bootleg Series Vol. 1-3″ boxed set were not the same alternate versions found on this promo, but alternate versions of those alternate versions.)

  5. I'll be 40 in 3 mos. It was at 35 that I too started feeling older. However that does not have to be a bad thing. I have maybe 12 or 15 gray hairs and I am not plucking them or dying them. I feel that I have earned them. They are my trophies that show others that I have endured the trials of life and I'm still alive to tell about them. And I am finding that their are actually younger women out there that want me to share my "wisdom" with them.
    Yes, I feel the effects of [...]

  6. polairre says:

    Your news reports keep referring to “Thwarted” attempt to blow up the plane bound for Detroit. That attack was not thwarted. It failed. Thwarting the attack would have meant the terrorist would never been allowed on plane.

    The attack was not thwarted. It happened. Fortunately it was unsuccessful.

    Please stop mischaracterizing the attack has having been avoided.

  7. My company’s network team trying to explain why they are running 5 year old unpatched IOS: “We don’t upgrade on a whim. We do it slowly”

  8. solt says:

    Best new little feature in OS X Lion: hold down a vowel and the accentuated versions pop up, no need to open “Special Characters…” WOOT

  9. ranglander says:

    Dating is when your just getting to know the person, and not officially going out with them.. In a relationship is when you call them your boyfriend/girlfriend and its serious.

  10. mach says:

    The Metro look is spreading throughout the company faster than the Melissa virus on a room full of unpatched PCs. What started with the Zune has spread to Windows Phone and Windows. Now it’s made its way to the company’s PowerPoint presentations too.

  11. I’m guessing EA aren’t happy with the console version, bit weird to be just hading out the PC version. Don’t worry that the console versions

  12. Microsoft released only four new security bulletins for November’s Patch Tuesday, but the main concern is that the zero day flaw exploited by the Duqu worm is not addressed by any of them.

  13. you can't tell when lumines and gta are patched or unpatched. you also have to be under firmware 3.50 to downgrade which most people aren't. and also you have to have a magic memory stick for it to downgrade (not upgrade) to 1.50. and all the new lumines and gta are patched so it won't downgrade anyway.

  14. guers says:

    OMIGOSH so many birthdays for Cosmic Gate & Emma Hewitt when they come to Club Glow! Time to make kandi and make dreams come true.

  15. Most languages have that. Sometimes it is hard to understand kids these days, especially with the way texting distorts everything and the way they take on particularly bad grammar patterns, when they do know better.