WordPress Attack Underway: Users Must Upgrade

Status
Not open for further replies.

CHR

Design matters
Nov 28, 2002
8,951
8,442
113
Anaheim
www.avantegardens.com
State / Prov
CA
From Mashable:WordPress Attack Underway: WordPress Users Must Upgrade [ALERT]


If you’re running a self-hosted WordPress () blog that isn’t up-to-date (version 2.8.4), you’re advised to upgrade immediately to the latest version of the software to avoid an ongoing attack. Users of WordPress.com hosted blogs are not affected.

The warning comes from Lorelle on WordPress after it was discovered that a nasty attack is exploiting security holes in previous versions of the blogging software, creating a new “hidden” Administrator account and getting right down to the database level. These attacks are said to be “growing by the hour”. Lorelle writes:
There are two clues that your WordPress site has been attacked.
There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”
The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account.
All users are advised to upgrade to the latest version of WP, while those already affected are in for a trying weekend: you’ll likely need to export your all your content with the built-in XML WordPress export, uninstall and reinstall WordPress and re-import the content. It’s a nasty attack that goes all the way into the database, so exporting the database will result in exporting the hacked code too.


For those unaffected: upgrade today. For those affected: the WordPress community is here to help.
Been seeing horror stories on Twitter. This is an urgent upgrade.
 
Those of us with Strider sites with blogs, will this be done for us?
never mind... using 2.8.4... Thanks
 
The good news is that upgrading WordPress is easy. Just click on Upgrade in the Tools menu on the sidebar. It's automatic!

Ryan
 
Status
Not open for further replies.