![]() | | ||||||||
| | #1 | |
| NetPassiveIncome.com War Room Member Join Date: Mar 2005 Location: Long Beach, CA, USA.
Posts: 439
Thanks: 14
Thanked 27 Times in 17 Posts
|
Just want to give you guys a heads up for those who run Wordpress blogs: Wordpress MySQL Injection - Permalink hack %&({${eval(base64_decode($_SERVER[HTTP_REFERER] Thanks, Steve For your convenience, I'm copying & pasting my blog post here (images won't come through): Quote:
| |
| | ||
| | |
| | #2 |
| John Burnette War Room Member Join Date: Aug 2007 Location: S.E. USA
Posts: 1,049
Thanks: 659
Thanked 208 Times in 175 Posts
|
Hi, There was somebody else that posted this problem earlier: Help! My Blog Posts Now Have Weird Code on the URL Really stinks. Thread does have some additional info. Thanks, John |
| | |
| | |
| | #3 | |
| A Penny Saved War Room Member Join Date: Jun 2009 Location: The Land of Ahhhs
Posts: 156
Thanks: 67
Thanked 30 Times in 22 Posts
| Quote:
The article shows how to clean it up, but doesn't mention a fix. Thanks for posting this, Steve. EDIT: Heh, Steve posted his entire post above, making this post redundant. Move along! | |
| | ||
| | |
| | #4 |
| Program Owner Join Date: Aug 2009 Location: Ft. Lauderdale, FL
Posts: 13
Thanks: 0
Thanked 0 Times in 0 Posts
| |
|
I Want Your Insurance Agent Traffic! - affiliate.IAIMS.com I Also Wholesale High-Quality, Exclusive Insurance Leads - www.IAIMS.com Insurance Agent Internet Marketing Systems (IAIMS) | |
| | |
| | #5 |
| Internet Infopreneur War Room Member Join Date: Apr 2008 Location: , , .
Posts: 1,405
Blog Entries: 4 Thanks: 631
Thanked 1,630 Times in 601 Posts
|
An article explaining this in more detail: Old WordPress Versions Under Attack Lorelle on WordPress A way to get rid of the 'hidden' admin: Wordpress Permalink & Rss problems If you need to do a complete re-install: How To Completely Clean Your Hacked WordPress Installation | Smackdown! Apparently, the hack is deep and may affect your database itself, allowing for future attacks. I took the advice in the first article and did a complete deletion and reinstall of my blog, after backing up the content and then imported it back into the new install. It's a pain - but better safe than sorry, right? All success Dr.Mani |
| Learn Information Marketing at the Infopreneur Blog | Sign up to our FREE Infopreneur Ezine Connect on G+ | Buy 'Think, Write & Retire!' | Get FREE Content For Your Blog or Ezine! ![]() | |
| | |
| | #6 | |
| Warrior Member Join Date: Aug 2008
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
| Quote:
From testing that has been done it does not look like fresh installs of 2.8.4 are subject to the specific vulnerabilities that are being used in this set of exploits. -Michael | |
| | ||
| | |
| | #7 |
| HyperActive Warrior Join Date: Feb 2009 Location: Cincinnati, OH, USA
Posts: 323
Thanks: 68
Thanked 37 Times in 31 Posts
|
That is one reason you need to have ALL your tsql code in a business layer so that the hackers cannot inject anything into the code to do stuff like this. Any of you who are coders should know what I am talking about. If you are doing sites for clients please make sure that there are at least 2 layers between the surfers and the actual tsql functionality. You should be running a data validation layer and a communications layer to protect your WP and databases from any kind of injection attacks.
|
| | |
| | #8 |
| HyperActive Warrior Join Date: Jul 2007 Location: across the universe
Posts: 347
Thanks: 7
Thanked 23 Times in 21 Posts
|
correct me if I'm wrong but mysql injection prevention should be done by the web host - first line of defence although it wouldn't surprise me if your web host says it's a wordpress problem like they usually do.
|
| | |
| | #9 | ||
| Senior Warrior Member War Room Member Join Date: Apr 2006 Location: , , USA.
Posts: 2,431
Thanks: 40
Thanked 155 Times in 148 Posts
| Quote:
Quote:
If you rented a place to live and something you installed broke, would you blame the landlord? | ||
| | |||
| | |
| | #10 |
| Active Warrior Join Date: Jul 2009
Posts: 31
Thanks: 3
Thanked 1 Time in 1 Post
|
But I would say thanks to thread poster it was informative and some problem solved for me
|
| | |
| | |
| | #11 |
| Don't think about rabbits War Room Member Join Date: Nov 2005 Location: ...between my left and right ear.
Posts: 768
Blog Entries: 1 Thanks: 38
Thanked 69 Times in 53 Posts
|
Thanks for the heads up...I'm sure there will be another update soon to patch this hole. |
|
Interested in how to publish with SEO in mind and also into the Social Media space? It's merging and I'll have another updated product out on this soon. - Sean Mitchell For now you can checkout Social Search Exposed | |
| | |
![]() |
|
| Tags |
| and% or, attack, injection, latest, mysql, wordpress, wordpress hack, wordpress injection |
| Thread Tools | |
| |
![]() |