War Room

Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Featured Warrior Special Offer...
"Members Of The *War Room* Discover Secrets To Immediate Success!"
Reply
 
LinkBack Thread Tools
Old 09-06-2009, 06:48 PM   #1
Active Warrior
 
Join Date: Mar 2009
Posts: 63
Thanks: 3
Thanked 2 Times in 2 Posts
Default Wordpress Mass Attack .. update now, it's urgent!

There has been a mass attack. A lot of wordpress blogs were hacked yesterday.. I think everyone should check their blogs now, because you might not even know that your blog is hacked.

Here's a quick guide how to find out if you have been hacked.

0. Look at your permalinks. If there is a string attached like the one below, you have been hacked:
PHP Code:
/month/year/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. 
1. Go to your Wordpress Admin Site
2. Under "Users" -> "Authors & Users" you will find all users, click on "Administrators".
3. Pay attention closely. If you see another name there (for a second only) you might have been hacked. Verify the number of administrators at the top. Remember the name of the unknown admin. In my case it was something like "EarnestCummingham".

4. Go to your PHPMyAdmin site and open the table "wp_usermeta".
5. Locate "EarnestCummingham" or a user with "wp_user_level" = "10".
6. Delete the user
7. Upgrade your wordpress blog to 2.8.4 (secure)

How to make your blog even more secure?
8. Read the full article at WebmasterWeblog.com

I hope this helps some people.. maybe you have been hacked and don't even know it .. that kinda scares me. A lot of people will not notice this and the hackers will then get what they want .. simply disgusts me

CPAProxy.com - Preview Any Affiliate Page
CPA-Networks.info - CPA Network Reviews (Newbie must-read)
CPA Templates - Increase your conversions by 20%
sOliver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-06-2009, 09:39 PM   #2
Senior Warrior Member
War Room Member
 
RebeccaL's Avatar
 
Join Date: Jun 2005
Location: NSW, Australia
Posts: 2,874
Thanks: 160
Thanked 142 Times in 50 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Default Re: Wordpress Mass Attack .. update now, it's urgent!

I have quite a number of outdated blogs and none have been hacked. So I dont know if this is an over reaction, or if Im just lucky...

RebeccaL is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-06-2009, 11:47 PM   #3
I am not a cowboy
War Room Member
 
SteveJohnson's Avatar
 
Join Date: Apr 2007
Location: Caldwell, Idaho, USA.
Posts: 467
Thanks: 11
Thanked 59 Times in 41 Posts
Social Networking View Member's Twitter Profile 
Contact Info
Send a message via Yahoo to SteveJohnson Send a message via Skype™ to SteveJohnson
Default Re: Wordpress Mass Attack .. update now, it's urgent!

Quote:
Originally Posted by RebeccaL View Post
I have quite a number of outdated blogs and none have been hacked. So I dont know if this is an over reaction, or if Im just lucky...
You're just lucky. They haven't found you yet. They will.

If you're unwilling or unable to upgrade, be sure to do periodic backups that you can fall back on. Some of the earlier hacks and attacks were so pervasive that it required manually going through each post...

Some days you're the pigeon, some days you're the statue...
SteveJohnson is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-06-2009, 11:47 PM   #4
Politically Incorrect
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
Social Networking View Member's Twitter Profile 
Default Re: Wordpress Mass Attack .. update now, it's urgent!

These attacks have been going on for awhile now. Nothing new - just getting very frequent since January.

Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO

HeySal is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-07-2009, 06:45 AM   #5
Senior Warrior Member
War Room Member
 
bgmacaw's Avatar
 
Join Date: Aug 2008
Location: Atlanta GA Metro Area, USA.
Posts: 1,767
Blog Entries: 3
Thanks: 62
Thanked 295 Times in 236 Posts
Social Networking View Member's Twitter Profile 
Default Re: Wordpress Mass Attack .. update now, it's urgent!

Is this one of those many hacks that only work if the WP registration and/or remote posting has been left open?

I did some searching around but I couldn't find any answers to how the hack works. All I could find are panicky blog and forum posts saying upgrade to a version of WordPress that doesn't work right with several plugins I use on my older WP sites.

Product Reviews | Earn Online Cash | Social Bookmarking Money
Free WordPress Themes: Boring Memo | Dateless Mini-Site | Info Magazine
Keyword Based Content Generation: Blog Content Wizard
Discount Templates, Graphics and Scripts: Templates for Website [Warrior Discount Code: WF102009]
bgmacaw is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-07-2009, 07:05 AM   #6
HyperActive Warrior
War Room Member
 
Join Date: Dec 2008
Posts: 198
Thanks: 42
Thanked 84 Times in 11 Posts
Default Re: Wordpress Mass Attack .. update now, it's urgent!

Quote:
Originally Posted by bgmacaw View Post
Is this one of those many hacks that only work if the WP registration and/or remote posting has been left open?

I did some searching around but I couldn't find any answers to how the hack works. All I could find are panicky blog and forum posts saying upgrade to a version of WordPress that doesn't work right with several plugins I use on my older WP sites.
Frank,

It appears the only real solution is upgrading. You can read all about the attacks here, including a post by Matt from Wordpress: Techmeme: I don't feel safe with Wordpress, hackers broke in and took things (Robert Scoble/Scobleizer)
qkz283 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
attack, mass, update, urgent, wordpress

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 10:28 PM.