Go Back   Netpond ™ > Webmaster Forums and Resources > Blogging Forum
Register FAQ Calendar Radio and TV NP Shop Search Today's Posts Mark Forums Read

Blogging Forum Blogging Discussion Forum, links and tools.

Dating
Easy Date White Label Voyeur, Fetish Megasite, Niche sites
Reply
 
LinkBack Thread Tools Display Modes
Old 06-08-2008, 05:49 PM   #1 (permalink)
erots
future is now
 
erots's Avatar
 
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
Upgrade your Wordpress, I really mean it!

Making a thread because it really seems widespread and I don't want people to get a wrong impression about Wordpress.

Apparently there is a hack that redirects all your Google and possibly also Yahoo traffic, you can only notice it by looking at your stats.

Unlike some people try to make us believe, it is not caused by a exploit that affects all the versions of Wordpress but only the older ones.

The idea that it affects all seems to have born in the minds of people who have no idea about how software works. After deleting their old Wordpress and uploading the latest one they still got hacked and figured all versions were affected... this is not true because you also need to clean it from your database!

This is the original thread
http://www.netpond.com/blogging-foru...idespread.html

This is the official solution
Did your WordPress site get hacked?

This is for laughing at wankers
WordPress › Support » Wordpress Hacked and Redirected ... Again

As a side note, I remember pam wasn't satisfied with the new image uploader of Wordpress. Turns out it didn't work very well with my favourite browser either so I just found a way to disable it. So this is for you pam if you don't already have it and for anyone else who has a problem with image uploading with Wordpress 2.5.1

WordPress › No Flash Uploader « WordPress Plugins

Now go here to download latest Wordpress
WordPress › Blog Tool and Weblog Platform
__________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now!
Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved
erots is offline   Reply With Quote Send a private message to erots
Old 06-08-2008, 05:52 PM   #2 (permalink)
diablom
Be HONEST if You want some RESPECT
 
diablom's Avatar
 
Join Date: Jan 2008
Location: Lithuania
Posts: 1,737
Points: 19,182
Send a message via ICQ to diablom Send a message via Skype™ to diablom
I have never upgraded wp before. If I upgrade wordpress on existing blog with 50+ posts, is there a chance they will be deleted or somehow broken?
diablom is offline   Reply With Quote Send a private message to diablom
Old 06-08-2008, 06:14 PM   #3 (permalink)
erots
future is now
 
erots's Avatar
 
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
Quote:
Originally Posted by diablom View Post
I have never upgraded wp before. If I upgrade wordpress on existing blog with 50+ posts, is there a chance they will be deleted or somehow broken?
You should really make backups before you upgrade. If you are lazy like me then at least do MySQL backups. Your posts are in MySQL database, fuck the files... well template is important thing from the files but you seriously got to fuck up when you manage to destroy it somehow by upgrading. Only thing I can think of is that you delete it.

There is a small chance that your theme doesn't work very well with newest Wordpress or some other minor things but they are all very easy to fix and there is a 97% chance that this doesn't happen to you
__________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now!
Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved
erots is offline   Reply With Quote Send a private message to erots
Old 06-08-2008, 09:27 PM   #4 (permalink)
Hentaikid
Yep, I made this animation myself
 
Hentaikid's Avatar
 
Join Date: Apr 2004
Posts: 10,170
Points: 3,533
Also disable the plugins before upgrading, the only time I've had a problem was upgrading an older blog with a lot of plugins, some no longer worked and interfered with the site
Hentaikid is offline   Reply With Quote Send a private message to Hentaikid
Old 06-08-2008, 09:37 PM   #5 (permalink)
pam
Those with the biggest egos are insecure
 
pam's Avatar
 
Join Date: Jan 2003
Location: near Cape Cod, Massachusetts
Posts: 9,147
Points: 1,196
I upgraded a blog with at least a thousand posts (3 years old) and had no issues. I've upgraded about a dozen others with no issues, all plugins work, but I also don't use many plugins.

Erots, thanks, the issue with the uploader gives me those blue lines, and I have to mouse over them to get rid of them ... I'll check out your plugin
__________________
Quote:
Originally Posted by Baldbastard
If your making money from USA based sponsors, then play by USA rules.


pam is offline   Reply With Quote Send a private message to pam
Old 06-08-2008, 09:55 PM   #6 (permalink)
fsudirectory
I get paid(hopefully) to watch porn
 
Join Date: May 2007
Posts: 1,275
Points: 4,225
Well from reading that WP Forum, it seems that the issue lays with a plugin that has been exploited.

Seems the easiest "quick fix" would be to overwrite your plugin dir with fresh ones you know arent compromised
fsudirectory is offline   Reply With Quote Send a private message to fsudirectory
Old 06-09-2008, 02:39 AM   #7 (permalink)
AbsolutePorn
www.TripleX-Studios.com
 
AbsolutePorn's Avatar
 
Join Date: May 2005
Location: SEO and Plugins Install on BLOGS - 8$
Posts: 17,043
Points: 2,455
Send a message via ICQ to AbsolutePorn Send a message via MSN to AbsolutePorn
All my blogs are up to date (around 150)
__________________
Make some money...
Shemale Profit
New Shemale Program... Personal Ratio: 1:127
AbsolutePorn is offline   Reply With Quote Send a private message to AbsolutePorn
Old 06-09-2008, 03:00 AM   #8 (permalink)
BadWolf
Not a Jedi.....yet.
 
BadWolf's Avatar
 
Join Date: Jan 2006
Location: the twilight zone
Posts: 5,824
Points: 805
Quote:
Originally Posted by fsudirectory View Post
Well from reading that WP Forum, it seems that the issue lays with a plugin that has been exploited.

Seems the easiest "quick fix" would be to overwrite your plugin dir with fresh ones you know arent compromised
Yes, but unless you upgrade couldn't the plugin be exploited again?
BadWolf is offline   Reply With Quote Send a private message to BadWolf
Old 06-09-2008, 07:04 AM   #9 (permalink)
gedeon
splogmaster
 
gedeon's Avatar
 
Join Date: Jan 2008
Location: Hungary
Posts: 1,763
Points: 1,090
Send a message via ICQ to gedeon Send a message via Skype™ to gedeon
And what's up with the uploads folder? It has 777 chmod, and I don't wanna change it, cuz I'm using external programs to update my blogs. Is this a risky folder?
__________________
LIVE Porn - Weekly shows on every wednesday - promte it till it's new
How I'm gonna make $375 monthly with webcams? learn more here
379764547
gedeon is offline   Reply With Quote Send a private message to gedeon
Old 06-09-2008, 07:55 AM   #10 (permalink)
pam
Those with the biggest egos are insecure
 
pam's Avatar
 
Join Date: Jan 2003
Location: near Cape Cod, Massachusetts
Posts: 9,147
Points: 1,196
Quote:
Originally Posted by gedeonbacsi View Post
And what's up with the uploads folder? It has 777 chmod, and I don't wanna change it, cuz I'm using external programs to update my blogs. Is this a risky folder?
I changed all upload directories to 755 and can still upload pics with no problems when using 2.5.1
__________________
Quote:
Originally Posted by Baldbastard
If your making money from USA based sponsors, then play by USA rules.


pam is offline   Reply With Quote Send a private message to pam
Old 06-09-2008, 08:10 AM   #11 (permalink)
erots
future is now
 
erots's Avatar
 
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
Some people say that you should never chmod 777 but it is kind a half truth. 777 means full access to owner, your group and others. With some hosts you can do fine with 755(5 means read and execute) but lot of them need at least 775 or 777.

What really "full access to others" means is not that everyone can change your files directly over internet. It means that people who are on the same server with you could potentially modify, upload or delete your files. In shared hosting space this only happens when somebody is compromised and they know full path to your files(not very likely).

Another thing that is more likely is that your scripts get compromised, then it could also be possible for the hacker to edit your files with 777 permissions. BUT, this is also possible with those good hosts where you can manage with 755 permissions, because all the files and processes are united, although it seems much safer than the guys who need to use 775 or 777 it really is not.

The difference: If you can manage with chmod 755:

This means that files you upload with FTP belong to your user also the files you upload thru Wordpress upload function in example. They all belong to your user

If you need chmod 775:

This means that files uploaded thru FTP belong to you but files uploaded thru Wordpress upload function belong to some other user, usually it is user: nobody. Why you need 775 is that user nobody DOESN'T HAVE PERMISSIONS to make new files to upload folder, so you need to chmod the upload folder to that. Only difference of 775 and 777 is that sometimes user "nobody" doesn't belong to the same usergroup as you.

So in conclusion, although hosts that don't need chmod 775 or 777 for upload dirs but just 755 seem to be configured "right" for some people, the first ones are actually much safer BECAUSE you only need to change permissions for this one directory and well maybe you configuration files too. When you are using hosts that need chmod 755 then it means that compromised script can modify and upload files to all the directories you own.

Now about is it risky or not.. upload folder, well.. they can put big files there and maybe overwrite your stuff but thats about it, also it would be extremely annoying to change permissions of that directory each time you want to upload a file there. Configuration files that are with such permissions or main files like index.php and what not are much more a threat.

But we forgot one thing - this really becomes a problem when you are already compromised. Most of the attacks come a lot later when the patch has been given out and some bad guys have finally found out what they patched and start their campaign.

So update your stuff
__________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now!
Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved
erots is offline   Reply With Quote Send a private message to erots
Old 06-09-2008, 08:11 AM   #12 (permalink)
rogue
Guest
 
Posts: n/a
Points: 0 [Check]
Quote:
Originally Posted by fsudirectory View Post
Well from reading that WP Forum, it seems that the issue lays with a plugin that has been exploited.

Seems the easiest "quick fix" would be to overwrite your plugin dir with fresh ones you know arent compromised
which plug-in?
....
  Reply With Quote Send a private message to rogue
Old 06-09-2008, 08:25 AM   #13 (permalink)
fsudirectory
I get paid(hopefully) to watch porn
 
Join Date: May 2007
Posts: 1,275
Points: 4,225
Well the only real way to find the plugin is to
1) know your hacked
2) turn off random plugins till you realize which it is

or just clean the entire DIR and hope not to get hacked again until someone else figures out whats going on.
fsudirectory is offline   Reply With Quote Send a private message to fsudirectory
Old 06-09-2008, 08:29 AM   #14 (permalink)
rogue
Guest
 
Posts: n/a
Points: 0 [Check]
you mean it can be any plug-in, not one in particular?
  Reply With Quote Send a private message to rogue
Old 06-09-2008, 08:48 AM   #15 (permalink)
fsudirectory
I get paid(hopefully) to watch porn
 
Join Date: May 2007
Posts: 1,275
Points: 4,225
Yea, from what Ive read, no one has nailed it down
fsudirectory is offline   Reply With Quote Send a private message to fsudirectory
Old 06-09-2008, 09:01 AM   #16 (permalink)
gedeon
splogmaster
 
gedeon's Avatar
 
Join Date: Jan 2008
Location: Hungary
Posts: 1,763
Points: 1,090
Send a message via ICQ to gedeon Send a message via Skype™ to gedeon
Quote:
Originally Posted by pam View Post
I changed all upload directories to 755 and can still upload pics with no problems when using 2.5.1
I'm using the program "BlogPost" (written by Twan) and it need's the 777 chmod. If I'm with 775 or 755 I can't upload images to this folder. Setting the chmods every upload would be so annoying. However, the other files and dirs are 755 and 644 and the WP is 2.5.1. Hope I'm cool with those options.
__________________
LIVE Porn - Weekly shows on every wednesday - promte it till it's new
How I'm gonna make $375 monthly with webcams? learn more here
379764547
gedeon is offline   Reply With Quote Send a private message to gedeon
Old 06-09-2008, 11:21 AM   #17 (permalink)
erots
future is now
 
erots's Avatar
 
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
Quote:
Originally Posted by rogue View Post
you mean it can be any plug-in, not one in particular?
There are probably different people behind this, all of them using the same exploit. Some of them make the code hide in index.php, some of them have made the script to pick random plugins. Some of them hide in wp-includes... etc.

The smartest ones of them respawn themselves to your Wordpress files when you haven't cleaned up the database, so it could also be in your database. The official site should pretty much let you know about all the techniques how to clean it up.
__________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now!
Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved
erots is offline   Reply With Quote Send a private message to erots
Old 06-09-2008, 12:26 PM   #18 (permalink)
rogue
Guest
 
Posts: n/a
Points: 0 [Check]
and the only way to know if you've been compromised is if your stats no longer show any SE traffic?
  Reply With Quote Send a private message to rogue
Old 06-09-2008, 02:33 PM   #19 (permalink)
kaktusan
Blog Automation Software, Check My Sig!
 
kaktusan's Avatar
 
Join Date: May 2004
Location: Right behind You :)
Posts: 4,962
Points: 177,471
Send a message via ICQ to kaktusan Send a message via AIM to kaktusan
did they made it so an upgrade fixes the issue finally? Last few days i was hearing everyone is being updating and still getting compromised?
__________________


#1 Mass Blogging Script: Blogs Organizer | #1 Mass RSS Feeder Script Blogs Automater
#1 Multidomain Hardlink Trade Script : Links Organizer | #1 Blog Posts Builder Script: Gallery Scraper
Complete List of Affiliate RSS Feeds! | A-B-C Blog Linktrades
kaktusan is offline   Reply With Quote Send a private message to kaktusan
Old 06-09-2008, 06:26 PM   #20 (permalink)
seeandsee
http://wm.4pleasure.biz/
 
seeandsee's Avatar
 
Join Date: Jul 2005
Location: ICQ: 231 414 913
Posts: 20,139
Points: 3,995
Send a message via ICQ to seeandsee Send a message via AIM to seeandsee Send a message via Yahoo to seeandsee
Possible fix:
http://www.netpond.com/adult-webmast...-hack-fix.html
__________________

4pleasure.biz livecam affiliate program - Up to $100 PPS - 30% real lifetime revenue share - up to $1.25 per free join - 10% lifetime webmaster referral
Contact 4pleasure.biz affiliate support on ICQ : 366641197
seeandsee is online now   Reply With Quote Send a private message to seeandsee
Reply


Thread Tools
Display Modes


Netpond Resources
Resource Directory Tutorials & Articles Webmaster Tools Netpond News
 
Netpond Resources
LustDollars Vidz.com PussyCash EasyDate
Fetish Hits Cyberwurx NaughtyAmerica Fuck You Cash
British Porno 21 Sextury Cash HD Pays Internext Expo
Free Porn Paradise TrafficCashGold Rabbits Reviews Ukash
Titan Bucks AEE Webcams.com StarCash
Reality, celeb Live Sex Cams
All times are GMT -4. The time now is 01:25 PM.


Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
vBCredits v1.4 Copyright ©2007, PixelFX Studios