![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Beer Money Baron
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
|
Wordpress under attack
Update your old versions.
http://www.techcrunch.com/2009/09/05...-under-attack/
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
WINNING!
Industry Role:
Join Date: Oct 2002
Posts: 14,579
|
when are they not? when i check the access logs to the server, I see the attempts every single day.
People should just make sure they are always updated. Make it a priority if you want to make money on your websites. It's like a deliveryman who dont service his car.... keeping your infrastructure running sercurely should be #1. That means, it's something you do BEFORE reading/posting on forums, or busting a nut to a new Megan Fox picture |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Too lazy to set a custom title
Join Date: Dec 2006
Posts: 23,400
|
![]()
__________________
i like waffles |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
sex dwarf
Join Date: May 2002
Posts: 17,860
|
I wish I had more time.
If I did, I'd start work on a commercially oriented minimalistic blog script. Wordpress is great, but at the same time it's bloated and therefore fundamentally susceptible to vulnerabilities. Add the many thousands of plugins it supports to that, as well as how essential some of those plugins are for using it commercially, and you end up with a big fucking risk of holes.
__________________
/(bb|[^b]{2})/ |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Tell me about it Iv had two sites hacked in the last month one of which is a wordpress site The fucker defaced the homepage and changed all the passwords in the admin and in my cpanel The blog has now gone from a pr2 to a pr0
My sites were also listed on here http://zone-h.org/ If you go to the archive you can see how many sites are actually being hacked DEF KEEP YOUR SHIT UP TO DATE AND YOUR COMPUTER/S CLEAN IT WILL SAVE YOU A LOT OF HEADACHES .... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Too lazy to set a custom title
Join Date: Jun 2003
Location: Ottawa
Posts: 19,631
|
i made it so everytime i want to edit a page i have to change permissions. this seems to have stopped any kind of attack, so far.
__________________
you don't know you're wearing a leash if you sit by the peg all day.. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
WINNING!
Industry Role:
Join Date: Oct 2002
Posts: 14,579
|
I love the wordpress forums where people ask for help and link to their blog. And 2 days later they reply themself with something like
"I fixed the problem by CHMOD'ing the root to 777 - kthxbye" and then someone reply "ye, I had the same problem, and I did the same to fix it" |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Aug 2008
Location: Hollywood
Posts: 2,785
|
Or stay with 2.7.1 ?
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Beer Money Baron
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
|
Details how this hack works, looks to be a POST to /xmlrpc.php
http://wordpress.org/support/topic/307518 Still reading
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Posts: 1,605
|
Thanks for the tip. I just upgraded.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So Fucking Banned
Join Date: Aug 2008
Location: Just Blow Me
Posts: 10,551
|
this is fucked up
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Guest
Posts: n/a
|
I just deleted xmlrpc.php from all my blogs. Don't think it did anything I needed anyway.
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Too lazy to set a custom title
Industry Role:
Join Date: Feb 2003
Location: NJ
Posts: 13,337
|
Common sense dedicates you should always upgrade.
__________________
ISeekGirls.com since 2005 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2002
Location: Montreal, Quebec
Posts: 29,735
|
Quote:
I often mentionned those fuckers, but took the time to announce their url as : zone hyphen h dot org . ![]()
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time .... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Pay It Forward
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 77,246
|
always up 2 date here
__________________
TRUMP 2025 KEKAW!!! - The Laken Riley Act Is Law! DACA ENDED - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Industry Role:
Join Date: Sep 2005
Location: ICQ :: 34739932 :: Les Pays-Bas
Posts: 1,707
|
I don't understand people who do not upgrade, as soon as you login you can see if you need to upgrade, you can also subscribe to upgrade notices at wordpress.org and every upgrade is also announced at GFY ...
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Mar 2006
Posts: 2,526
|
Spammers love wordpress holes
![]()
__________________
Free the world |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Industry Role:
Join Date: Oct 2002
Location: West Hollywood
Posts: 227
|
I have spend way too much time and money on WordPress code customizations that end up needing to be recoded or tweaked all the time to keep up. Having to track down the coders that did previous work for me, etc. The constant upgrades are really a drag. Sure, simple straight forward WP installs are not that hard to upgrade, these days anyway, but I wish they could just stick with a stable safe version. I can't think of another script I use that needs that much attention.
__________________
SpookyCash: Original Alt/Gothic/Punk Niche Leaders |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Sick Fuck
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
|
Thanks for the heads up.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Too lazy to set a custom title
Join Date: Dec 2006
Posts: 23,400
|
Those people were using 2.6.x... man no wonder they were getting hacked.... how long ago was the 2.6 wordpress generation?
__________________
i like waffles |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
I help you SUCCEED
Industry Role:
Join Date: Nov 2003
Location: The Pearl of the Orient Seas
Posts: 32,195
|
Thanks, Brujah
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Sick Fuck
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
|
Just upgraded, and no problems
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
ICQ:649699063
Industry Role:
Join Date: Mar 2003
Posts: 27,763
|
Update it indeed. Well said.
__________________
Send me an email: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
. . .
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
|
__________________
__________________ Looking for a custom TUBE SCRIPT that supports massive traffic, load balancing, billing support, and h264 encoding? Hit up Konrad!
Looking for designs for your websites or custom tubesite design? Hit up Zuzana Designs Check out the #1 WordPress SEO Plugin: CyberSEO Suite |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Such Fun!
Industry Role:
Join Date: Feb 2008
Posts: 13,900
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |