|
|
|||||||
| Register | FAQ | Calendar | Radio and TV | NP Shop | Search | Today's Posts | Mark Forums Read |
| Blogging Forum Blogging Discussion Forum, links and tools. |
![]() |
![]() |
![]() |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
future is now
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
|
Upgrade your Wordpress, I really mean it!
Making a thread because it really seems widespread and I don't want people to get a wrong impression about Wordpress.
Apparently there is a hack that redirects all your Google and possibly also Yahoo traffic, you can only notice it by looking at your stats. Unlike some people try to make us believe, it is not caused by a exploit that affects all the versions of Wordpress but only the older ones. The idea that it affects all seems to have born in the minds of people who have no idea about how software works. After deleting their old Wordpress and uploading the latest one they still got hacked and figured all versions were affected... this is not true because you also need to clean it from your database! This is the original thread http://www.netpond.com/blogging-foru...idespread.html This is the official solution Did your WordPress site get hacked? This is for laughing at wankers WordPress › Support » Wordpress Hacked and Redirected ... Again As a side note, I remember pam wasn't satisfied with the new image uploader of Wordpress. Turns out it didn't work very well with my favourite browser either so I just found a way to disable it. So this is for you pam if you don't already have it and for anyone else who has a problem with image uploading with Wordpress 2.5.1 WordPress › No Flash Uploader « WordPress Plugins Now go here to download latest Wordpress WordPress › Blog Tool and Weblog Platform __________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now! Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved |
|
|
|
|
|
#3 (permalink) | |
|
future is now
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
|
Quote:
There is a small chance that your theme doesn't work very well with newest Wordpress or some other minor things but they are all very easy to fix and there is a 97% chance that this doesn't happen to you ![]() __________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now! Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved |
|
|
|
|
|
|
#5 (permalink) |
|
Those with the biggest egos are insecure
Join Date: Jan 2003
Location: near Cape Cod, Massachusetts
Posts: 9,147
Points: 1,196
|
I upgraded a blog with at least a thousand posts (3 years old) and had no issues. I've upgraded about a dozen others with no issues, all plugins work, but I also don't use many plugins.
Erots, thanks, the issue with the uploader gives me those blue lines, and I have to mouse over them to get rid of them ... I'll check out your plugin |
|
|
|
|
|
#6 (permalink) |
|
I get paid(hopefully) to watch porn
Join Date: May 2007
Posts: 1,275
Points: 4,225
|
Well from reading that WP Forum, it seems that the issue lays with a plugin that has been exploited.
Seems the easiest "quick fix" would be to overwrite your plugin dir with fresh ones you know arent compromised |
|
|
|
|
|
#9 (permalink) |
|
splogmaster
|
And what's up with the uploads folder? It has 777 chmod, and I don't wanna change it, cuz I'm using external programs to update my blogs. Is this a risky folder?
__________________
LIVE Porn - Weekly shows on every wednesday - promte it till it's new How I'm gonna make $375 monthly with webcams? learn more here 379764547
|
|
|
|
|
|
#11 (permalink) |
|
future is now
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
|
Some people say that you should never chmod 777 but it is kind a half truth. 777 means full access to owner, your group and others. With some hosts you can do fine with 755(5 means read and execute) but lot of them need at least 775 or 777.
What really "full access to others" means is not that everyone can change your files directly over internet. It means that people who are on the same server with you could potentially modify, upload or delete your files. In shared hosting space this only happens when somebody is compromised and they know full path to your files(not very likely). Another thing that is more likely is that your scripts get compromised, then it could also be possible for the hacker to edit your files with 777 permissions. BUT, this is also possible with those good hosts where you can manage with 755 permissions, because all the files and processes are united, although it seems much safer than the guys who need to use 775 or 777 it really is not. The difference: If you can manage with chmod 755: This means that files you upload with FTP belong to your user also the files you upload thru Wordpress upload function in example. They all belong to your user If you need chmod 775: This means that files uploaded thru FTP belong to you but files uploaded thru Wordpress upload function belong to some other user, usually it is user: nobody. Why you need 775 is that user nobody DOESN'T HAVE PERMISSIONS to make new files to upload folder, so you need to chmod the upload folder to that. Only difference of 775 and 777 is that sometimes user "nobody" doesn't belong to the same usergroup as you. So in conclusion, although hosts that don't need chmod 775 or 777 for upload dirs but just 755 seem to be configured "right" for some people, the first ones are actually much safer BECAUSE you only need to change permissions for this one directory and well maybe you configuration files too. When you are using hosts that need chmod 755 then it means that compromised script can modify and upload files to all the directories you own. Now about is it risky or not.. upload folder, well.. they can put big files there and maybe overwrite your stuff but thats about it, also it would be extremely annoying to change permissions of that directory each time you want to upload a file there. Configuration files that are with such permissions or main files like index.php and what not are much more a threat. But we forgot one thing - this really becomes a problem when you are already compromised. Most of the attacks come a lot later when the patch has been given out and some bad guys have finally found out what they patched and start their campaign. So update your stuff ![]() __________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now! Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved |
|
|
|
|
|
#13 (permalink) |
|
I get paid(hopefully) to watch porn
Join Date: May 2007
Posts: 1,275
Points: 4,225
|
Well the only real way to find the plugin is to
1) know your hacked 2) turn off random plugins till you realize which it is or just clean the entire DIR and hope not to get hacked again until someone else figures out whats going on. |
|
|
|
|
|
#16 (permalink) |
|
splogmaster
|
I'm using the program "BlogPost" (written by Twan) and it need's the 777 chmod. If I'm with 775 or 755 I can't upload images to this folder. Setting the chmods every upload would be so annoying. However, the other files and dirs are 755 and 644 and the WP is 2.5.1. Hope I'm cool with those options.
__________________
LIVE Porn - Weekly shows on every wednesday - promte it till it's new How I'm gonna make $375 monthly with webcams? learn more here 379764547
|
|
|
|
|
|
#17 (permalink) |
|
future is now
Join Date: Jan 2006
Location: Elbonia
Posts: 3,928
Points: 405
|
There are probably different people behind this, all of them using the same exploit. Some of them make the code hide in index.php, some of them have made the script to pick random plugins. Some of them hide in wp-includes... etc.
The smartest ones of them respawn themselves to your Wordpress files when you haven't cleaned up the database, so it could also be in your database. The official site should pretty much let you know about all the techniques how to clean it up. __________________
Use the bailout to make money HustlerCash gets lot of attention right now because of the adult industry bailout, so start using the buzz to make sales now! Everything you need to know about making money and living a coke free life Oprah and Vin Diesel approved |
|
|
|
|
|
#19 (permalink) |
|
Blog Automation Software, Check My Sig!
|
did they made it so an upgrade fixes the issue finally? Last few days i was hearing everyone is being updating and still getting compromised?
__________________
![]() #1 Mass Blogging Script: Blogs Organizer | #1 Mass RSS Feeder Script Blogs Automater #1 Multidomain Hardlink Trade Script : Links Organizer | #1 Blog Posts Builder Script: Gallery Scraper Complete List of Affiliate RSS Feeds! | A-B-C Blog Linktrades |
|
|
|
|
|
#20 (permalink) |
|
http://wm.4pleasure.biz/
|
Possible fix:
http://www.netpond.com/adult-webmast...-hack-fix.html __________________
![]() 4pleasure.biz livecam affiliate program - Up to $100 PPS - 30% real lifetime revenue share - up to $1.25 per free join - 10% lifetime webmaster referral Contact 4pleasure.biz affiliate support on ICQ : 366641197 |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
![]() |
![]() |