• Home
  • Lifestream
  • Contact me
 
Blue Orange Green Pink Purple

WordPress Virus requires all blogs to upgrade for security

Posted in Blogging, Diggable, Featured, Internet. on Sunday, September 6th, 2009
Sep 06
 

If you haven’t heard already, the WordPress community is abuzz about a new “clever” worm that is making the rounds and wreaking havoc on many WordPress installations. The nasty bug may automatically attack any WP-powered blog version prior to 2.8.3 — and I know many, many people are running 2.7 or lower. WordPress founder, Matt Mullenweg, posted on WordPress.org the importance of keeping your WP installation secure.

Panda attack!

Right now there is a worm making its way around old, unpatched versions of WordPress. This particular worm, like many before it, is clever: it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts. [via ma.tt]

I, myself, have numerous installations that were vulnerable up until a few hours ago. The work involved in upgrading can sometimes be overwhelming, depending on the number of custom scripts and outdated plugins that have not been recently updated by the author. I have been very comfortable with 2.7.x installations and haven’t seen the need to upgrade, until today.

Don’t wait — upgrade now.

I’m sending out an email to all friends, family and clients to encourage them to upgrade to the latest 2.8.4 version of WordPress without delay. I am burning the midnight oil and will make myself available this entire extended weekend, so don’t hesitate to contact me if you need help with upgrading.

Personally, I’m happy to announce that all my blogs are patched and ready to face the dangerous world of malicious scripts and malware that plague the digital age.

So, why am I posting this on both my blog and via Posterous?

Only to point out that if you stick to using hosting solutions, like Posterous, to take care of your blogging and other social networking tasks — you are free to spend your time focusing on developing content and browsing the Internet as if nothing dangerous is happening. But, don’t take that statement to the bank, as just a few days ago I read how Brian Mastenbrook basically infiltrated the inner-workings of Twitter and 37 Signal’s hosted Basecamp solution, due to code falling through the cracks of Ruby on Rails.

Do you need help upgrading your WordPress installation? Drop me a line!

If you need to upgrade to the latest version of WordPress for your blog and are having difficulty, I’m open to inquiries and would be happy to take a look. I am offering WordPress Upgrade Support at a discounted rate, for a limited time. Click here to contact me via e-mail.

Share and Enjoy:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • StumbleUpon
  • Twitter

2 Comments

  1. Michael on September 6th, 2009
    Follow me on Twitter!

    This article was viewed 50+ times within the first couple minutes of being posted!

    Looks like a lot of people are possibly unaware of this situation.

    Have you upgraded your WordPress installation? Did you hit any snags?

    Post your experience in the comments.

  2. Best Wordpress Permalink Structure | Michael Bubbo on September 6th, 2009

    [...] WordPress blogs with version 2.8.3 or below. Check out this post I wrote detailing the situation: WordPress Worm Attack for more info. Share and [...]



Leave a Reply




Michael Bubbo

  • Subscribe and Follow
    Subscribe to RSS via FeedburnerFollow me on Twitter!My Facebook Profile!My LinkedIn Profile!Subscribe to my FriendFeed!
    My status  Call me on Skype     Reserve my time
     Call me! Click and Google will connect you
  • Subscribe to my blog updates via e-mail:
  • Follow me on Twitter!



      Chianti Cucina on #Yelp: Chianti just opened in Novato and it is a welcomed change to the foodscape we've become acc... http://bit.ly/94sKap Follow me on Twitter!


      @GoWalla Really like the look of the site! Glad to see Jason involved w/ such an innovative idea. I'd love an ipod btw. http://gowal.la/gift Follow me on Twitter!


      I've gotta say, some amazing deals available for Black Friday. Even I'm tempted...even Halo ODST for 50% off? Come on! http://bit.ly/6mPpoG Follow me on Twitter!

  • Recommended Stuff
      BasecampEep!ShopifyWooThemes
      Virtual Office Phone!E-junkie Shopping Cart and Digital Delivery
      Online InvoicingAWeber - Email Marketing Made Easy
      Looking for an audience? ADVERTISE HERE
  • Photo Stream
  • Categories
    • Blogging
    • Diggable
    • Featured
    • Internet
    • Lifestream
    • Reviews
    • Social Media
    • Startups
  • Recent Posts
    • WordPress Virus requires all blogs to upgrade for security
    • Startup Review: TheRentables.com
    • Exclusive Beta: SU.PR – Stumble Upon’s Traffic Booster
    • Inspirational Book: Where the Hell is Matt?
    • Best Wordpress Permalink Structure
    • Twitter Followers increased by 20% in less than 24 hours
  • Archives
    • September 2009
    • July 2009
    • June 2009
    • May 2009
    • January 2009
    • December 2008
  • Search



Subscribe to RSS via Feedburner Subscribe in a reader



  • Home
  • Lifestream
  • Contact

© Copyright 2003-2010 Michael Bubbo. All rights reserved.
Contact me if you have questions about this blog design.

Back to Top

Send me a message


Send me a copy

View my contact details