Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum
Register Blogs FAQ Social Groups CalendarHelp Desk

Reply
 
LinkBack Thread Tools
Old 09-06-2009, 06:48 PM   #1
Active Warrior
 
Join Date: Mar 2009
Posts: 81
Thanks: 3
Thanked 7 Times in 6 Posts
Default Wordpress Mass Attack .. update now, it's urgent!

There has been a mass attack. A lot of wordpress blogs were hacked yesterday.. I think everyone should check their blogs now, because you might not even know that your blog is hacked.

Here's a quick guide how to find out if you have been hacked.

0. Look at your permalinks. If there is a string attached like the one below, you have been hacked:
PHP Code:
/month/year/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. 
1. Go to your Wordpress Admin Site
2. Under "Users" -> "Authors & Users" you will find all users, click on "Administrators".
3. Pay attention closely. If you see another name there (for a second only) you might have been hacked. Verify the number of administrators at the top. Remember the name of the unknown admin. In my case it was something like "EarnestCummingham".

4. Go to your PHPMyAdmin site and open the table "wp_usermeta".
5. Locate "EarnestCummingham" or a user with "wp_user_level" = "10".
6. Delete the user
7. Upgrade your wordpress blog to 2.8.4 (secure)

How to make your blog even more secure?
8. Read the full article at WebmasterWeblog.com

I hope this helps some people.. maybe you have been hacked and don't even know it .. that kinda scares me. A lot of people will not notice this and the hackers will then get what they want .. simply disgusts me
sOliver is offline   Reply With Quote
Old 09-06-2009, 09:39 PM   #2
Senior Warrior Member
War Room Member
 
RebeccaL's Avatar
 
Join Date: Jun 2005
Location: NSW, Australia
Posts: 2,981
Thanks: 166
Thanked 156 Times in 58 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Default Re: Wordpress Mass Attack .. update now, it's urgent!

I have quite a number of outdated blogs and none have been hacked. So I dont know if this is an over reaction, or if Im just lucky...

RebeccaL is offline   Reply With Quote
Old 09-06-2009, 11:47 PM   #3
I am not a cowboy
War Room Member
 
SteveJohnson's Avatar
 
Join Date: Apr 2007
Location: Caldwell, Idaho, USA.
Posts: 1,644
Thanks: 235
Thanked 491 Times in 341 Posts
Social Networking View Member's Twitter Profile 
Contact Info
Send a message via Yahoo to SteveJohnson Send a message via Skype™ to SteveJohnson
Default Re: Wordpress Mass Attack .. update now, it's urgent!

Quote:
Originally Posted by RebeccaL View Post
I have quite a number of outdated blogs and none have been hacked. So I dont know if this is an over reaction, or if Im just lucky...
You're just lucky. They haven't found you yet. They will.

If you're unwilling or unable to upgrade, be sure to do periodic backups that you can fall back on. Some of the earlier hacks and attacks were so pervasive that it required manually going through each post...

this area under construction
SteveJohnson is offline   Reply With Quote
Old 09-06-2009, 11:47 PM   #4
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: Wordpress Mass Attack .. update now, it's urgent!

These attacks have been going on for awhile now. Nothing new - just getting very frequent since January.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 09-07-2009, 06:45 AM   #5
Senior Warrior Member
War Room Member
 
bgmacaw's Avatar
 
Join Date: Aug 2008
Location: Atlanta GA Metro Area, USA.
Posts: 3,643
Blog Entries: 5
Thanks: 311
Thanked 925 Times in 644 Posts
Social Networking View Member's Twitter Profile 
Default Re: Wordpress Mass Attack .. update now, it's urgent!

Is this one of those many hacks that only work if the WP registration and/or remote posting has been left open?

I did some searching around but I couldn't find any answers to how the hack works. All I could find are panicky blog and forum posts saying upgrade to a version of WordPress that doesn't work right with several plugins I use on my older WP sites.

bgmacaw is offline   Reply With Quote
Old 09-07-2009, 07:05 AM   #6
HyperActive Warrior
War Room Member
 
Join Date: Dec 2008
Posts: 189
Thanks: 35
Thanked 107 Times in 12 Posts
Default Re: Wordpress Mass Attack .. update now, it's urgent!

Quote:
Originally Posted by bgmacaw View Post
Is this one of those many hacks that only work if the WP registration and/or remote posting has been left open?

I did some searching around but I couldn't find any answers to how the hack works. All I could find are panicky blog and forum posts saying upgrade to a version of WordPress that doesn't work right with several plugins I use on my older WP sites.
Frank,

It appears the only real solution is upgrading. You can read all about the attacks here, including a post by Matt from Wordpress: Techmeme: I don't feel safe with Wordpress, hackers broke in and took things (Robert Scoble/Scobleizer)
utproducts is offline   Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
attack, mass, update, urgent, wordpress

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 07:37 PM.