Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-05-2008, 03:14 PM   #1
Speedy26
Confirmed User
 
Join Date: Apr 2001
Location: MI
Posts: 950
Wordpress known security issues?

Hello,

I just installed the lastest copy of Wordpress, are there any major security issues I need to know about?

Thanks
__________________
http://www.amberscash.com webmaster {at} crazynakedchick [dot] com
Speedy26 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2008, 07:20 PM   #2
Jdoughs
Confirmed User
 
Jdoughs's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Great White North
Posts: 5,794
Keep it and all plug-ins updated, and that should keep you free of 99% of issues.

Every script or extra thing you add to it only makes it weaker. Wordpress as a community is pretty on top of anything that happens to the code or exploits.

When you see the notice to update, check all your blogs and update them.
__________________
LinkSpun - Premier Adult Link Trading Community - ICQ - 464/\281/\250
Be Seen By New Webmasters/Affiliates * Target out webmasters/affiliates based on niches your sites are for less than $20 a month.
AmeriNOC - Proudly hosted @ AmeriNOC!
Jdoughs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2008, 08:50 PM   #3
teg0
Confirmed User
 
teg0's Avatar
 
Join Date: Jan 2006
Location: Gringo in Puerto Rico
Posts: 4,204
I know of one exploit, but haven't reported it quite yet.

A less obvious security issue is free themes. I know it seems like I'm just saying that because I sell themes, but I'm not. The reason free themes are bad is because people find one that looks good, download it, install it, see it run and think it was a success. However, I'm seeing more and more examples of people sneaking code into free themes that get distributed. Code designed to force hardlinks to show up or to steal traffic. Some others more malicious. This is the main security risk that wordpress can't really fix, other than having a database of clean themes with a md4 hash.
teg0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2008, 08:52 PM   #4
Angry Jew Cat - Banned for Life
(felis madjewicus)
 
Industry Role:
Join Date: Jul 2006
Location: In Mom & Dad's Basement
Posts: 20,368
Quote:
Originally Posted by teg0 View Post
I know of one exploit, but haven't reported it quite yet.

A less obvious security issue is free themes. I know it seems like I'm just saying that because I sell themes, but I'm not. The reason free themes are bad is because people find one that looks good, download it, install it, see it run and think it was a success. However, I'm seeing more and more examples of people sneaking code into free themes that get distributed. Code designed to force hardlinks to show up or to steal traffic. Some others more malicious. This is the main security risk that wordpress can't really fix, other than having a database of clean themes with a md4 hash.
http://wordpress.org/extend/plugins/tac/ solution to this problem, works great. scan your themes before activating them.
Angry Jew Cat - Banned for Life is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2008, 08:55 PM   #5
teg0
Confirmed User
 
teg0's Avatar
 
Join Date: Jan 2006
Location: Gringo in Puerto Rico
Posts: 4,204
Quote:
Originally Posted by Angry Jew Cat View Post
http://wordpress.org/extend/plugins/tac/ solution to this problem, works great. scan your themes before activating them.
I knew about that, but its a joke. Took me less than 5 minutes to trick it with some known theme exploits.
teg0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2008, 08:57 PM   #6
Angry Jew Cat - Banned for Life
(felis madjewicus)
 
Industry Role:
Join Date: Jul 2006
Location: In Mom & Dad's Basement
Posts: 20,368
Quote:
Originally Posted by teg0 View Post
I knew about that, but its a joke. Took me less than 5 minutes to trick it with some known theme exploits.
well, nothing id going to top going through each .php file manually, but this works quite well as is for catching most embedded code in wordpress themes that i've come across thus far...
Angry Jew Cat - Banned for Life is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2008, 09:57 PM   #7
Azoy?
Confirmed User
 
Join Date: Aug 2005
Posts: 2,178
Quote:
Originally Posted by Speedy26 View Post
Hello,

I just installed the lastest copy of Wordpress, are there any major security issues I need to know about?

Thanks
All software made by humans have security issues.
Some are not known yet but all have em.
__________________
Azoy? is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2008, 11:36 PM   #8
sam from montreal
Confirmed User
 
Join Date: Nov 2003
Location: QC
Posts: 296
1 - keep all things updated http://wordpress.org/extend/plugins/...matic-upgrade/
2 - change admin username for something stronger with PHPMyAdmin, and use strong password
3 - use TAC as others said and security scan http://wordpress.org/extend/plugins/wp-security-scan/
4 - don't use the fantastico WP installer... its sucks
5 - always RTFM!
__________________
SEO r0ck st@r

Giving tips 107776092 [email protected]
sam from montreal is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-06-2008, 12:42 AM   #9
nickutis
Confirmed User
 
Join Date: Dec 2002
Posts: 719
Protect wp-login.php with htaccess, so only your IP can access it.. Increases the security alot. And of course, take all the steps mentioned in this thread
nickutis is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-06-2008, 02:18 AM   #10
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
http://www.noupe.com/how-tos/wordpre...and-hacks.html
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.