Security Threat: WordPress Under Attack . Update your WP Now!



As written by Lorelle Of WordPress  -

Otto42 of OttoDestruct, a key WordPress developer and supporter, reports that there is an “attack” on older versions of right now. The number of sites hit by this is growing every hour. Protect your WordPress blog now: UPDATE NOW!!!

Update your WordPress blog before you continue reading this post. That’s how critical this issue is.

There are two clues that your WordPress site has been attacked.

There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”

The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account, but Journey Etc. has a possible solution.

WordPress.com blogs are not impacted as they are up-to-date.

You must update your blog to it’s latest version : 2.8.4 to prevent such an attack , see that you reset all your Passwords for your WP dashboard , install the wp-security-scan plugin to scan for vulnerabilities in your WP . Change ALL passwords to a strong password immediately, including WordPress blog access for all users, database, FTP, control panels, everything.

Source : Link

You can leave a response, or trackback from your own site.
  • http://power-inside.blogspot.com PowerInside

    umm… your blog has a problem with images in each entry… everything seems garbled.. you think it can be fixed? and im using firefox 3

  • http://power-inside.blogspot.com PowerInside

    umm… your blog has a problem with images in each entry… everything seems garbled.. you think it can be fixed? and im using firefox 3