Go Back   Webmaster Forums UK SEO SEM Webmaster Community Forum - UKWW > General > General Webmaster Talk > Blogs and blogging > Word Press Forum
Register FAQ Members List Downloads Calendar Today's Posts Webmaster Resources Webmaster Blogs
 
 

Word Press Forum Word Press is the most popular free self hosted blogging software. We are compiling resources bloggers will find useful for their Word Press Blogs, add word press resources you have created or use some of the one other members created.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-27-2008, 06:39 AM
Senior Member
 
Join Date: Mar 2008
Location: Bucharest, Romania
Posts: 266
Default New WordPress exploit

In simple words: this exploit creates a new folder (/wp-content/1/) in which it puts spamming html files.
You can read more here: New Wordpress 2.3.3 Exploit/Vulnerability - Adds Spam Directory /wp-content/1/ | Smackdown!
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 03-27-2008, 06:53 AM
brokencode's Avatar
Junior Member
 
Join Date: Mar 2008
Posts: 28
Send a message via Yahoo to brokencode
Default

Thanks for the info. I found that folder already installed in some wp blogs I have
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 03-27-2008, 07:12 AM
Senior Member
 
Join Date: Mar 2008
Location: Bucharest, Romania
Posts: 266
Default

Have you find any sollution for that exploit?
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #4 (permalink)  
Old 03-27-2008, 08:06 AM
Senior Member
 
Join Date: Jan 2006
Posts: 799
Default

Thanks for the info. I had no problems untill now.
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 03-27-2008, 08:24 AM
rhyswynne's Avatar
Senior Member
 
Join Date: Nov 2007
Posts: 438
Default

I've double checked it and have not noticed anything.

Could the "put blank index.html files in directories" fix work?
__________________
Enjoy Retro Games? Why not join my Retro Gaming Forum?

Single? Join Our Dating Site For Bloggers
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 03-31-2008, 08:49 PM
Senior Member
 
Join Date: Mar 2008
Posts: 78
Default

I hate exploits. but i love wordpress anyways . Any solutions so far?
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #7 (permalink)  
Old 04-01-2008, 05:05 PM
xhan's Avatar
Design Photo & Graphics Admin
 
Join Date: Jan 2008
Location: London/Kent
Posts: 510
Send a message via AIM to xhan
Default

one of my hostees had a file remv.php added to her wp directory - look out for that, It got my account suspended :S
__________________
Blog | Portfolio | Twitter

Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 04-01-2008, 05:10 PM
Senior Member
 
Join Date: Mar 2008
Location: Bucharest, Romania
Posts: 266
Default

No sollutions yet, not that I could find..
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 04-01-2008, 06:00 PM
Junior Member
 
Join Date: Feb 2008
Posts: 9
Default

I think, you have to update your wordpress blogs to last version 2.5.5, that's the only solution I know actually. Before updating, modify your mysql password and FTP password and look for files that are not yours on your FTP.

What I don't understand is why some wordpress blogs have the issue and others not...
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #10 (permalink)  
Old 04-01-2008, 08:27 PM
xhan's Avatar
Design Photo & Graphics Admin
 
Join Date: Jan 2008
Location: London/Kent
Posts: 510
Send a message via AIM to xhan
Default

it just depends if you come up on a hackers radar or not.

Theres sites out there listing all the hacks done by x person. My sites on one - grrr angry!
__________________
Blog | Portfolio | Twitter

Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
Reply

Bookmarks



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Webmaster Resources
 
The Forum Rules
Forum Rules - MUST READ
 
Site Of the Month
BizzFace
Nominate site of the month
 
Tag Cloud
add url ad link affiliate program article directory banklogins blog blogs casino links exchange ccv cell phone chinese electronics chocolates computer memory customer opinions diamond directory domain parking ecommerce employment flv player forums free directory list fresh gifts google google news google xistence graphic design hacking health job portal script link link building techniques link directory link exchange logo design memory upgrade micropayment monetise site niche online jobs without inves online job without invest pagerank 1 website part time jobs part time jobs from home paypal product ratings product reviews product tests program promotion sandbox sell cvv shopping sms billing smtp software testing services speed ppc review spread spectrum submit url terminator transfers user reviews video games web design webdevelopment solution web directory without inves online jobs without invest online job xhtml

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 04:08 PM.

UK Webmaster World Forums - Internet marketing, web development, domain names, SEO contest and discussuons.
Subscribe to our feeds   Subscribe to our feeds

Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0