Wordpress 2.1.1 Release Compromised by Cracker
Posted by
Zonk
on Sat Mar 03, 2007 01:34 AM
from the not-my-emo-comments-and-angsty-statements dept.
from the not-my-emo-comments-and-angsty-statements dept.
GrumpySimon writes "The recent 2.1.1 release of the popular blog software Wordpress was compromised by a cracker who made it easier for to execute code remotely. This is interesting because the official release was quietly and subtly compromised, and has been in the wild for a few days now. There's no word on if any affected sites have been compromised, but anyone running Wordpress is urged to upgrade to 2.1.2 immediately, and admins can check their logs for access to 'theme.php' or 'feed.php', and query strings with 'ix=' or 'iz=' in them."
This discussion has been archived.
No new comments can be posted.
Wordpress 2.1.1 Release Compromised by Cracker
|
Log In/Create an Account
| Top
| 48 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
PHP and certificates (Score:2)
(http://netapps.com.au/)
Makes me wonder if the PHP VM could do a hash of the application code and compare that with a certificate from the source of the application. I know that the injected code in this case would have been certified, but it would make it easier to identify sites which had not been upgraded.
Made it easier for ... (Score:3, Insightful)
Key Details (Score:5, Informative)
(http://www.hyperborea.org/journal/ | Last Journal: Tuesday September 11, @05:30PM)
From the article, and from some comparisons I did on the downloads:
I still had the tar archive of 2.1.1 from when I grabbed it the day of the release, so I compared its contents to the 2.1.2 archive. The two files mentioned in the announcement, feed.php and theme.php, aren't any different, confirming that the initial release was unaffected. That's also where I saw the changes for that XSS bug.
Cracker (Score:1, Redundant)
Also update your.. (Score:2, Informative)
(http://www.skintube.com/)
This is always a major concern for OSS projects (Score:2, Insightful)
OSS releases should be GPG signed by now, unless the attacker can compromise the key we're then left with tampering in the repository.
Suggestion:GPG! (Score:1)
(http://makarevitch.org/ | Last Journal: Saturday December 17 2005, @10:44AM)
- have a well-signed and published (on the keyservers) GnuPG (GPG) key
- do only transfer/store the private key on absolutely sure boxes, and only if it is strictly necessary
- keep a backup of the private key in an ultra safe place
- give a copy of the revocation certificate to a few very good friends
- publish the public key on a good keyserver
Then sign every archive published, let the file be mirrored everywhere... and the hell with the polluters! For now most users will not verify the signature but at least a few of them will do, and with time a growing number will join.What about Wordpress mu? (Score:2)
(http://www.fiestyturtles.com/ | Last Journal: Tuesday October 23, @09:07PM)
Doesn't matter, WP can't handle heavy loads. (Score:1)
Re:Damn crazy crackahs. (Score:5, Funny)
(http://www.atomjax.com/)
I thought the politically-correct term for "cracker" was "caucasian-american"?
Re:Damn crazy crackahs. (Score:1, Troll)
Re:Damn crazy crackahs. (Score:1)
(http://themebot.com/)