Security Exploit Added in Wordpress 2.1.1 by a cracker!!!

Discussion in 'Security' started by techie007, Mar 3, 2007.

  1. #1
    Hey Guys,

    If you have download wordpress 2.1.1 in past 3-4 days then upgrade it to 2.1.2 immediately. I just came to know right now, so i have done that, you too do it. If you are using fantastico then you should have downloaded 2.1.1, as i did the same. Your files may include a security exploit added by the cracker. Check the below update:

    http://wordpress.org/development/2007/03/upgrade-212/

    If you are a web host or network administrator, block access to “theme.php” and “feed.php”, and any query string with “ix=” or “iz=” in it. If you’re a customer at a web host, you may want to send them a note to let them know about this release and the above information.

    Let me know if you require any help in doing so. I upgraded it using Shell access, which is the easiest way i could see..

    Thanks,
     
    techie007, Mar 3, 2007 IP
    WebGeek182 likes this.
  2. WebGeek182

    WebGeek182 Active Member

    Messages:
    510
    Likes Received:
    28
    Best Answers:
    0
    Trophy Points:
    95
    #2
    Thanks for the info! Will upgrade right away and will inform others.
     
    WebGeek182, Mar 4, 2007 IP
  3. GADOOD

    GADOOD Peon

    Messages:
    1,745
    Likes Received:
    241
    Best Answers:
    0
    Trophy Points:
    0
    #3
    It would be nice if they actually apologized, wouldn't it?

    Pete
     
    GADOOD, Mar 4, 2007 IP
  4. WebGeek182

    WebGeek182 Active Member

    Messages:
    510
    Likes Received:
    28
    Best Answers:
    0
    Trophy Points:
    95
    #4
    LOL...yes. :)
     
    WebGeek182, Mar 4, 2007 IP
  5. techie007

    techie007 Peon

    Messages:
    261
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #5
    my pleasure, i am happy that i was successful passing the msg to DP friends :)
     
    techie007, Mar 5, 2007 IP
  6. ma0

    ma0 Peon

    Messages:
    218
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I wrote about it 2 days ago on a post.
    I'll tell you something:
    1. if people care to read what's written on Dashboard your post could have been useless.
    2. if DP readers care to read "Security" you did a good job by posting this info.

    The problem is that not everyone read this group.
     
    ma0, Mar 5, 2007 IP
  7. ma0

    ma0 Peon

    Messages:
    218
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #7
    I've added a post about it under "Blogging", this time with the right Title :)

    Better to spam a bit just to be sure everyone knows about it.
     
    ma0, Mar 5, 2007 IP
  8. agnivo007

    agnivo007 Peon

    Messages:
    4,290
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    0
    #8
    agnivo007, Mar 5, 2007 IP
  9. Louis11

    Louis11 Active Member

    Messages:
    783
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    70
    #9
    Thanks for calling him a 'cracker' :)
     
    Louis11, Mar 6, 2007 IP
  10. techie007

    techie007 Peon

    Messages:
    261
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Thanks ma0, for correcting my mistake.. i really appreciate that, i will be specific in choosing the category so that all are updated.

    agnivo007, you posted on 3rd march and i think i did on the same day! I don't know what i did wrong by alerting all. If you already know abt it then it is good but i thought of sharing this with all as now a days a lot of people use wordpress.
     
    techie007, Mar 6, 2007 IP
  11. agnivo007

    agnivo007 Peon

    Messages:
    4,290
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    0
    #11
    he he nothing bad...
     
    agnivo007, Mar 19, 2007 IP
  12. Dediwebspace

    Dediwebspace Active Member

    Messages:
    469
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    55
    #12
    Only just found out the hard way :/
     
    Dediwebspace, Mar 23, 2007 IP