Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-05-2009, 05:33 AM   #1
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
Wordpress under attack

Update your old versions.
http://www.techcrunch.com/2009/09/05...-under-attack/
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 05:40 AM   #2
Machete_
WINNING!
 
Industry Role:
Join Date: Oct 2002
Posts: 14,579
when are they not? when i check the access logs to the server, I see the attempts every single day.

People should just make sure they are always updated. Make it a priority if you want to make money on your websites.

It's like a deliveryman who dont service his car.... keeping your infrastructure running sercurely should be #1.

That means, it's something you do BEFORE reading/posting on forums, or busting a nut to a new Megan Fox picture
Machete_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 05:48 AM   #3
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 05:49 AM   #4
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
I wish I had more time.

If I did, I'd start work on a commercially oriented minimalistic blog script.

Wordpress is great, but at the same time it's bloated and therefore fundamentally susceptible to vulnerabilities. Add the many thousands of plugins it supports to that, as well as how essential some of those plugins are for using it commercially, and you end up with a big fucking risk of holes.
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 05:52 AM   #5
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Tell me about it Iv had two sites hacked in the last month one of which is a wordpress site The fucker defaced the homepage and changed all the passwords in the admin and in my cpanel The blog has now gone from a pr2 to a pr0

My sites were also listed on here http://zone-h.org/ If you go to the archive you can see how many sites are actually being hacked


DEF KEEP YOUR SHIT UP TO DATE AND YOUR COMPUTER/S CLEAN IT WILL SAVE YOU A LOT OF HEADACHES ....
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 05:55 AM   #6
BlackCrayon
Too lazy to set a custom title
 
BlackCrayon's Avatar
 
Join Date: Jun 2003
Location: Ottawa
Posts: 19,631
i made it so everytime i want to edit a page i have to change permissions. this seems to have stopped any kind of attack, so far.
__________________
you don't know you're wearing a leash if you sit by the peg all day..
BlackCrayon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 06:01 AM   #7
Machete_
WINNING!
 
Industry Role:
Join Date: Oct 2002
Posts: 14,579
I love the wordpress forums where people ask for help and link to their blog. And 2 days later they reply themself with something like

"I fixed the problem by CHMOD'ing the root to 777 - kthxbye"

and then someone reply

"ye, I had the same problem, and I did the same to fix it"
Machete_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 06:06 AM   #8
Robocrop
Confirmed User
 
Robocrop's Avatar
 
Industry Role:
Join Date: Aug 2008
Location: Hollywood
Posts: 2,785
Or stay with 2.7.1 ?
Robocrop is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 06:11 AM   #9
Agent 488
Registered User
 
Industry Role:
Join Date: Feb 2006
Posts: 22,511
http://wordpress.org/support/topic/307660
Agent 488 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 06:22 AM   #10
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
Details how this hack works, looks to be a POST to /xmlrpc.php
http://wordpress.org/support/topic/307518

Still reading
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 06:57 AM   #11
18teens
Confirmed User
 
Industry Role:
Join Date: Dec 2002
Posts: 1,605
Thanks for the tip. I just upgraded.
18teens is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 07:01 AM   #12
LoveSandra
So Fucking Banned
 
Join Date: Aug 2008
Location: Just Blow Me
Posts: 10,551
this is fucked up
LoveSandra is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 07:18 AM   #13
evildick
Guest
 
Posts: n/a
I just deleted xmlrpc.php from all my blogs. Don't think it did anything I needed anyway.
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 07:20 AM   #14
TheSenator
Too lazy to set a custom title
 
TheSenator's Avatar
 
Industry Role:
Join Date: Feb 2003
Location: NJ
Posts: 13,337
Common sense dedicates you should always upgrade.
__________________
ISeekGirls.com since 2005
TheSenator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 11:23 AM   #15
directfiesta
Too lazy to set a custom title
 
directfiesta's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: Montreal, Quebec
Posts: 29,735
Quote:
Originally Posted by halfpint View Post
Tell me about it Iv had two sites hacked in the last month one of which is a wordpress site The fucker defaced the homepage and changed all the passwords in the admin and in my cpanel The blog has now gone from a pr2 to a pr0

My sites were also listed on here xxxxxxx If you go to the archive you can see how many sites are actually being hacked


DEF KEEP YOUR SHIT UP TO DATE AND YOUR COMPUTER/S CLEAN IT WILL SAVE YOU A LOT OF HEADACHES ....
Nice... giving a backlink so they can see in their stats who links to them ...

I often mentionned those fuckers, but took the time to announce their url as :

zone hyphen h dot org .
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT !

But I can't figure out how he can breathe or type , at the same time ....
directfiesta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 11:30 AM   #16
brassmonkey
Pay It Forward
 
brassmonkey's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 77,246
always up 2 date here
__________________
TRUMP 2025 KEKAW!!! - The Laken Riley Act Is Law!
DACA ENDED - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com
brassmonkey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 04:19 PM   #17
closer
Confirmed User
 
closer's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: ICQ :: 34739932 :: Les Pays-Bas
Posts: 1,707
I don't understand people who do not upgrade, as soon as you login you can see if you need to upgrade, you can also subscribe to upgrade notices at wordpress.org and every upgrade is also announced at GFY ...
__________________

HOT DOMAIN NAMES FOR SALE:
EUROPEAN: MACHO.FRKINKY.ESSEXTOONS.CO.UKDOT COMS: DJSEX.COMFAQBOX.COMWEBCAMSTV.COMSEXTWEET.COMPORNVOUCHER.COMGAYBF.COM | GAYBFF.COMGAYSEXDATE.COM | GAYSEXDATING.COM
closer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 04:36 PM   #18
VforVendetta
Confirmed User
 
VforVendetta's Avatar
 
Join Date: Mar 2006
Posts: 2,526
Spammers love wordpress holes
__________________
Free the world
VforVendetta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 04:43 PM   #19
ForrestBlack
Confirmed User
 
ForrestBlack's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: West Hollywood
Posts: 227
I have spend way too much time and money on WordPress code customizations that end up needing to be recoded or tweaked all the time to keep up. Having to track down the coders that did previous work for me, etc. The constant upgrades are really a drag. Sure, simple straight forward WP installs are not that hard to upgrade, these days anyway, but I wish they could just stick with a stable safe version. I can't think of another script I use that needs that much attention.
ForrestBlack is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 05:37 PM   #20
Dirty Dane
Sick Fuck
 
Dirty Dane's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
Thanks for the heads up.
Dirty Dane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 06:40 PM   #21
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
Those people were using 2.6.x... man no wonder they were getting hacked.... how long ago was the 2.6 wordpress generation?
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 06:44 PM   #22
$5 submissions
I help you SUCCEED
 
$5 submissions's Avatar
 
Industry Role:
Join Date: Nov 2003
Location: The Pearl of the Orient Seas
Posts: 32,195
Thanks, Brujah
$5 submissions is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 07:14 PM   #23
Dirty Dane
Sick Fuck
 
Dirty Dane's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
Just upgraded, and no problems
Dirty Dane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2009, 07:22 PM   #24
fatfoo
ICQ:649699063
 
Industry Role:
Join Date: Mar 2003
Posts: 27,763
Update it indeed. Well said.
__________________
Send me an email: [email protected]
fatfoo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-06-2009, 12:00 AM   #25
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
Quote:
Originally Posted by sharphead View Post
__________________

__________________

Looking for a custom TUBE SCRIPT that supports massive traffic, load balancing, billing support, and h264 encoding? Hit up Konrad!
Looking for designs for your websites or custom tubesite design? Hit up Zuzana Designs
Check out the #1 WordPress SEO Plugin: CyberSEO Suite
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-06-2009, 07:37 AM   #26
Si
Such Fun!
 
Industry Role:
Join Date: Feb 2008
Posts: 13,900
Quote:
Originally Posted by sharphead View Post


Happens all the time!
Si is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-06-2009, 08:19 AM   #27
Agent 488
Registered User
 
Industry Role:
Join Date: Feb 2006
Posts: 22,511
Agent 488 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.