Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum
Register Blogs FAQ Social Groups CalendarHelp Desk

Reply
 
LinkBack Thread Tools
Old 11-13-2009, 02:20 PM   #1
HyperActive Warrior
War Room Member
 
hmigroupllc's Avatar
 
Join Date: May 2006
Location: Washington DC, USA
Posts: 142
Thanks: 0
Thanked 24 Times in 19 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Yahoo to hmigroupllc
Default Warning: You must Upgrade Your WP Blog Now

I don't usually send out any threads like this, but Wordpress released an upgrade today that is specifically to stop a malicious iframe file from being injected into your server via WP.

It has happened to two of my marketing blogs the past two days.

I highly encourage you to do the upgrade immediately, or your blog web pages could disappear.

What happens is a "fake" index file is placed on your server with an iframe to a blank script.

This same code is also injected into other files.

You really need to do this upgrade.

Thanks

Wayne Sharer

How Start a Flow of Quality Website Traffic You Can't Stop
hmigroupllc is offline   Reply With Quote
Old 11-13-2009, 02:22 PM   #2
Advanced Warrior
 
Join Date: Jul 2006
Location: St.Petersburg, Florida
Posts: 771
Thanks: 43
Thanked 43 Times in 41 Posts
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Default Re: Warning: You must Upgrade Your WP Blog Now

Thanks for the heads up! I use 2.8.4 at the moment.I usually wait a month before upgrading because some of the plugins I use will necessarily not work after the upgrade.

Tom Lindstrom
Sign up for my FREE 6-Day niche marketing mini-course now and discover step-by-step how to build a profitable niche business in 30 days or less!
tommen is offline   Reply With Quote
Old 11-13-2009, 02:30 PM   #3
The Ethical Marketer
War Room Member
 
Michael Oksa's Avatar
 
Join Date: May 2006
Location: Wisconsin, USA
Posts: 6,058
Thanks: 1,750
Thanked 3,025 Times in 1,340 Posts
Social Networking View Member's Twitter Profile 
Contact Info
Send a message via Yahoo to Michael Oksa
Default Re: Warning: You must Upgrade Your WP Blog Now

Thank you, Wayne.

I know it takes a while for some of my plug-ins to catch up to new versions of WP. But I would rather be without a plug-in or two for a little while than to have my site wiped out. That's my take on it anyway.

All the best,
Michael

Michael Oksa is online now   Reply With Quote
Old 11-13-2009, 02:33 PM   #4
Watching you...
War Room Member
 
Istvan Horvath's Avatar
 
Join Date: Dec 2008
Location: Waterdown, Ontario, Canada
Posts: 5,984
Blog Entries: 2
Thanks: 1,575
Thanked 2,719 Times in 1,656 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to Istvan Horvath
Default Re: Warning: You must Upgrade Your WP Blog Now

To be honest, the 2.8.6 was released yesterday and the two issues addressed by this newest version have nothing to do with injection:
Quote:
2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.
The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations.
Source: WordPress › Blog WordPress 2.8.6 Security Release

In the first half of the year we are supposed to work for the taxman. I think that's a mistake.
Help me to get rid of the taxman ASAP - thanks! (You, too, should make less mistakes!)


Istvan Horvath is online now   Reply With Quote
Old 11-13-2009, 02:33 PM   #5
Systematic Warrior
War Room Member
 
jazbo's Avatar
 
Join Date: Oct 2009
Location: Norfolk, England.
Posts: 1,906
Blog Entries: 9
Thanks: 35
Thanked 298 Times in 217 Posts
Social Networking View Member's Twitter Profile 
Default Re: Warning: You must Upgrade Your WP Blog Now

Wordpress, dont ya love it.

jazbo is offline   Reply With Quote
Old 11-13-2009, 02:34 PM   #6
J Bold
War Room Member
 
redicelander's Avatar
 
Join Date: Jul 2008
Location: Walla Walla
Posts: 2,612
Blog Entries: 10
Thanks: 665
Thanked 507 Times in 311 Posts
Social Networking View Member's Twitter Profile 
Default Re: Warning: You must Upgrade Your WP Blog Now

That sucks. What number upgrade is this? You talking about 2.8.5?

redicelander is offline   Reply With Quote
Old 11-13-2009, 02:43 PM   #7
HyperActive Warrior
War Room Member
 
hmigroupllc's Avatar
 
Join Date: May 2006
Location: Washington DC, USA
Posts: 142
Thanks: 0
Thanked 24 Times in 19 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Yahoo to hmigroupllc
Default Re: Warning: You must Upgrade Your WP Blog Now

Well, this isn't about twisting and turning meanings and words. My host says that the Wordpress Fix issued today will stop the injections.

Whether or not it is specifically to do with the specific insecurity really doesn't matter.

I would do the upgrade, and argue semantics later.

Have a great day.

Wayne Sharer

How Start a Flow of Quality Website Traffic You Can't Stop
hmigroupllc is offline   Reply With Quote
Old 11-13-2009, 02:52 PM   #8
TheRichJerksNet
Guest
 
Posts: n/a
Default Re: Warning: You must Upgrade Your WP Blog Now

No thanks I will stay with my secured 2.6.5 version .. This is the problem, every time a update is released people go running to install it instead of waiting.

This is why you should secure your own blog and stop doing all those freaking updates just for those cool new features. Personally I find 2.8 with many issues and have found it even less user friendly than what wordpress was before.

James
  Reply With Quote
Old 11-13-2009, 02:57 PM   #9
Watching you...
War Room Member
 
Istvan Horvath's Avatar
 
Join Date: Dec 2008
Location: Waterdown, Ontario, Canada
Posts: 5,984
Blog Entries: 2
Thanks: 1,575
Thanked 2,719 Times in 1,656 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to Istvan Horvath
Default Re: Warning: You must Upgrade Your WP Blog Now

Quote:
Originally Posted by hmigroupllc View Post
Well, this isn't about twisting and turning meanings and words.
Quote:
Originally Posted by hmigroupllc View Post
[...] argue semantics later.
What can I do... I am linguist as my basic profession. I do care about the words and meaning .

In the first half of the year we are supposed to work for the taxman. I think that's a mistake.
Help me to get rid of the taxman ASAP - thanks! (You, too, should make less mistakes!)


Istvan Horvath is online now   Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
blog, upgrade, warning

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 10:41 AM.