Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security The Internet

Survey Finds Most WordPress Blogs Vulnerable 82

BlogSecurity writes "Security analyst David Kierznowski shocked bloggers yesterday with a survey showing that 49 out of the 50 WordPress blogs he checked seem to be running exploitable versions of the widely used software. He said, 'The main concern here is the lack of security awareness amongst bloggers with a non-technical background, and even those with a technical background.' Mr Kierznowski also uncovered recent vulnerabilities in WordPress plugins that ship by default with the software, adding: 'WordPress users developing plugins must be aware of the security functions that WordPress supports, and ensure that these functions are used in their code.'"
This discussion has been archived. No new comments can be posted.

Survey Finds Most WordPress Blogs Vulnerable

Comments Filter:
  • by iknownuttin ( 1099999 ) on Thursday May 24, 2007 @01:13PM (#19256093)
    So, how's a huge problem? If anything, some blogs need to be hacked to have some decent content on them!
  • by Ynot_82 ( 1023749 ) on Thursday May 24, 2007 @01:25PM (#19256331)
    Open Source Software - Pointing out gaping-security-holes-that-you-can't-do-much-about -until-the-software-is-updated-in-a-week's-time-by -some-volunteer-on-the-friendly- community-forum-of-said-software you mean that OSS?
  • by speculatrix ( 678524 ) on Thursday May 24, 2007 @04:23PM (#19259205)

    at my previous job there had been a programmer who used the same password for *everything*, and I do mean everything... from the mysql logins (both "root" and regular webapp), web site logins, shell accounts and the ssh passwords needed to move data around!

    I discovered he had a blog site, and guess what, his standard password worked on that too, both to login as him and as admin. Whilst tempted, I neither added nor deleted anything on his site, but I *did* go occasionally go through his blog posts and correct his spelling and grammar! He must have noticed because after many months of occasionally tweaking his content, the login finally stopped working. Yes, I'm talking about you, "smurphy" :-)

Work without a vision is slavery, Vision without work is a pipe dream, But vision with work is the hope of the world.

Working...