GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Wordpress under attack (https://gfy.com/showthread.php?t=925917)

Brujah 09-05-2009 05:33 AM

Wordpress under attack
 
Update your old versions.
http://www.techcrunch.com/2009/09/05...-under-attack/

Machete_ 09-05-2009 05:40 AM

when are they not? when i check the access logs to the server, I see the attempts every single day.

People should just make sure they are always updated. Make it a priority if you want to make money on your websites.

It's like a deliveryman who dont service his car.... keeping your infrastructure running sercurely should be #1.

That means, it's something you do BEFORE reading/posting on forums, or busting a nut to a new Megan Fox picture

Iron Fist 09-05-2009 05:48 AM

http://www.nnteenmodels.net/gfy/wordpress-fail.jpg

Libertine 09-05-2009 05:49 AM

I wish I had more time.

If I did, I'd start work on a commercially oriented minimalistic blog script.

Wordpress is great, but at the same time it's bloated and therefore fundamentally susceptible to vulnerabilities. Add the many thousands of plugins it supports to that, as well as how essential some of those plugins are for using it commercially, and you end up with a big fucking risk of holes.

halfpint 09-05-2009 05:52 AM

Tell me about it Iv had two sites hacked in the last month one of which is a wordpress site The fucker defaced the homepage and changed all the passwords in the admin and in my cpanel The blog has now gone from a pr2 to a pr0

My sites were also listed on here http://zone-h.org/ If you go to the archive you can see how many sites are actually being hacked


DEF KEEP YOUR SHIT UP TO DATE AND YOUR COMPUTER/S CLEAN IT WILL SAVE YOU A LOT OF HEADACHES ....

BlackCrayon 09-05-2009 05:55 AM

i made it so everytime i want to edit a page i have to change permissions. this seems to have stopped any kind of attack, so far.

Machete_ 09-05-2009 06:01 AM

I love the wordpress forums where people ask for help and link to their blog. And 2 days later they reply themself with something like

"I fixed the problem by CHMOD'ing the root to 777 - kthxbye"

and then someone reply

"ye, I had the same problem, and I did the same to fix it"

Robocrop 09-05-2009 06:06 AM

Or stay with 2.7.1 ? :)

Agent 488 09-05-2009 06:11 AM

http://wordpress.org/support/topic/307660

Brujah 09-05-2009 06:22 AM

Details how this hack works, looks to be a POST to /xmlrpc.php
http://wordpress.org/support/topic/307518

Still reading

18teens 09-05-2009 06:57 AM

Thanks for the tip. I just upgraded.

LoveSandra 09-05-2009 07:01 AM

this is fucked up :(

evildick 09-05-2009 07:18 AM

I just deleted xmlrpc.php from all my blogs. Don't think it did anything I needed anyway.

TheSenator 09-05-2009 07:20 AM

Common sense dedicates you should always upgrade.

directfiesta 09-05-2009 11:23 AM

Quote:

Originally Posted by halfpint (Post 16280950)
Tell me about it Iv had two sites hacked in the last month one of which is a wordpress site The fucker defaced the homepage and changed all the passwords in the admin and in my cpanel The blog has now gone from a pr2 to a pr0

My sites were also listed on here xxxxxxx If you go to the archive you can see how many sites are actually being hacked


DEF KEEP YOUR SHIT UP TO DATE AND YOUR COMPUTER/S CLEAN IT WILL SAVE YOU A LOT OF HEADACHES ....

Nice... giving a backlink so they can see in their stats who links to them ...

I often mentionned those fuckers, but took the time to announce their url as :

zone hyphen h dot org .
:2 cents:

brassmonkey 09-05-2009 11:30 AM

always up 2 date here

closer 09-05-2009 04:19 PM

I don't understand people who do not upgrade, as soon as you login you can see if you need to upgrade, you can also subscribe to upgrade notices at wordpress.org and every upgrade is also announced at GFY ...

VforVendetta 09-05-2009 04:36 PM

Spammers love wordpress holes :)

ForrestBlack 09-05-2009 04:43 PM

I have spend way too much time and money on WordPress code customizations that end up needing to be recoded or tweaked all the time to keep up. Having to track down the coders that did previous work for me, etc. The constant upgrades are really a drag. Sure, simple straight forward WP installs are not that hard to upgrade, these days anyway, but I wish they could just stick with a stable safe version. I can't think of another script I use that needs that much attention.

Dirty Dane 09-05-2009 05:37 PM

Thanks for the heads up.

Iron Fist 09-05-2009 06:40 PM

Those people were using 2.6.x... man no wonder they were getting hacked.... how long ago was the 2.6 wordpress generation?

$5 submissions 09-05-2009 06:44 PM

Thanks, Brujah

Dirty Dane 09-05-2009 07:14 PM

Just upgraded, and no problems :)

fatfoo 09-05-2009 07:22 PM

Update it indeed. Well said.

d-null 09-06-2009 12:00 AM

Quote:

Originally Posted by sharphead (Post 16280944)

:1orglaugh:thumbsup

Si 09-06-2009 07:37 AM

Quote:

Originally Posted by sharphead (Post 16280944)

:1orglaugh

Happens all the time! :mad:

Agent 488 09-06-2009 08:19 AM

http://2.bp.blogspot.com/_otfwl2zc6Q...s400/siren.gif


All times are GMT -7. The time now is 04:02 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123