WordPress Under Attack: Reason to Upgrade to 2.8.4

If you haven’t yet upgraded to the latest version of WordPress 2.8.4, then it is bout time you did. Self-hosted WordPress installs prior to this version is under attack and the potential damage to its users is high. Matt writes,

Right now there is a worm making its way around old, unpatched versions of WordPress. This particular worm, like many before it, is clever: it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts. [source]

Lorelle enumerates some symptoms to know if your site has been affected by the worm:

There are two clues that your WordPress site has been attacked.

There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”

The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account, but Journey Etc. has a possible solution.

See Also
AI Dental Platform

WordPress.com blogs are not impacted as they are up-to-date. Only versions prior to WordPress 2.8.4 are impacted.

Upgrade now!

Picture of Jayvee Fernandez

Jayvee Fernandez

Jayvee Fernandez has done his rounds in blog postings. He served as Technology Channel Editor for b5Media Inc and has founded the leading blog advertising and word of mouth network called BlogBank in the Philippines. And now, he's gone full circle, landing back with The Blog Herald, the resource that gave him his first blogging job in 2005.

RECENT ARTICLES

TRENDING AROUND THE WEB

4 zodiac signs only very resilient people can date

4 zodiac signs only very resilient people can date

Parent From Heart

7 signs you’re on the path to financial independence in your retirement years—even if you started late

7 signs you’re on the path to financial independence in your retirement years—even if you started late

Global English Editing

Neuroscientists say these 8 daily habits rewire your brain for lasting happiness

Neuroscientists say these 8 daily habits rewire your brain for lasting happiness

Ideapod

4 Zodiac signs who are most likely to do what they think is right, regardless of what others say

4 Zodiac signs who are most likely to do what they think is right, regardless of what others say

Parent From Heart

8 behaviors of workaholics who crave balance but act like they love the grind, according to psychology

8 behaviors of workaholics who crave balance but act like they love the grind, according to psychology

Global English Editing

People who are too nice in their younger years usually struggle with these 10 things as they age

People who are too nice in their younger years usually struggle with these 10 things as they age

Global English Editing