COZY Campus Adult Webmaster Forums

 
 
 


Go Back   COZY Campus Adult Webmaster Forums > Cozy Discussion

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 04-25-2008, 11:54 PM
sunfunbill's Avatar
sunfunbill sunfunbill is offline
Bilinda the lil bitch!
 
Join Date: Mar 2003
Location: Lesbian fun house
Posts: 5,364
Exclamation Security alert for WP!!!

OK, it's late, i'm tired. But this is important.
There is a security hole in wp that has been infected by something. I read it on the wp forum while trying to install wp 2.5.1.

Here is the thread:
http://wordpress.org/support/topic/168964?replies=30

Once I read it, I checked my files and yes, 3 of my blogs have been hacked. No one knows what is going on. If you don't have wp 2.5, but on the bottom where your version is, it says 2.5, you've been hacked.

I noticed that a few weeks ago. This all happened on the 12 or so. Read the above thread, I bet most have been hacked.

Fucking hackers! Going to bed now.
__________________
Lover Cash Gay, teen, tranny & more dating, high converting!
Visit my Orlando Vacation site, Orlando Inside!
My site Crossdresser Playground CD/TV/TS community
Reply With Quote
  #2  
Old 04-26-2008, 01:49 AM
mynameisjim's Avatar
mynameisjim mynameisjim is offline
World's Dumbest Genius
 
Join Date: Dec 2006
Posts: 1,306
People should check this.

But to be honest, every version of Wordpress has some pretty big security holes.

But even without wordpress, I'm shocked by how many sites are hacked and the owners don't even know it. I would always notice it on other people's sites then last week it was even on one of mine before I got it cleaned up. With mine, they injected a bunch of links in the blogroll but since I almost never look at the front page of that blog, I never noticed it.
Reply With Quote
  #3  
Old 04-26-2008, 07:33 AM
balls_deep's Avatar
balls_deep balls_deep is offline
Amish Pornstar
 
Join Date: Oct 2006
Location: Central PA
Posts: 3,549
Send a message via ICQ to balls_deep
Good info bill, I was hacked about a week ago and that's exactly what the bottom of wordpress said.

The code seems to be inserted in the wordpress files not the template, so writing over it with a new version fixed the problem.

you can also hand check for inserted code as well, Mine was inserted at the end of my html page all the way on the right after a bunch of white space used to hide the code.
__________________
Reply With Quote
  #4  
Old 04-26-2008, 08:07 AM
sunfunbill's Avatar
sunfunbill sunfunbill is offline
Bilinda the lil bitch!
 
Join Date: Mar 2003
Location: Lesbian fun house
Posts: 5,364
Hey balls. It also says your database gets infected and new plugins are inserted in your wp-options table. I tried to get into mine, but something is blocking me.

I have let ATCI know, they are working on it. So today will be shot doing this. Also, if you go to "manage your post" you see the author of each post. With this, that field is blank, you can't see any author.

Mine has that. It say it collects all your usernames including your database names. I would look around a bit more for stuff. And change your username in wp.
__________________
Lover Cash Gay, teen, tranny & more dating, high converting!
Visit my Orlando Vacation site, Orlando Inside!
My site Crossdresser Playground CD/TV/TS community
Reply With Quote
  #5  
Old 04-26-2008, 04:06 PM
sunfunbill's Avatar
sunfunbill sunfunbill is offline
Bilinda the lil bitch!
 
Join Date: Mar 2003
Location: Lesbian fun house
Posts: 5,364
Well, it looks like the whole server is infected, and I bet all of them are. Think of all the hundreds of splogs, using old versions and never being looked at again by the webmaster.

Those things are full of viruses, thousands of little bombs out there!

Not sure what they will do now, my sites are off.
__________________
Lover Cash Gay, teen, tranny & more dating, high converting!
Visit my Orlando Vacation site, Orlando Inside!
My site Crossdresser Playground CD/TV/TS community
Reply With Quote
  #6  
Old 04-26-2008, 04:16 PM
sunfunbill's Avatar
sunfunbill sunfunbill is offline
Bilinda the lil bitch!
 
Join Date: Mar 2003
Location: Lesbian fun house
Posts: 5,364
To anyone who thinks they got rid of this by deleting a few lines, your wrong. It is in your database, your upload folder and images if you use that, anything you have set at 777.

It adds a user you cannot see, in the wp-options table in your database.
__________________
Lover Cash Gay, teen, tranny & more dating, high converting!
Visit my Orlando Vacation site, Orlando Inside!
My site Crossdresser Playground CD/TV/TS community
Reply With Quote
  #7  
Old 04-26-2008, 06:31 PM
Cozy Monica's Avatar
Cozy Monica Cozy Monica is offline
Campus Moderator
 
Join Date: Dec 2002
Location: Canada
Posts: 4,730
Something to note is that it isn't just the old versions of WP... the article you linked to Bill says that it applies to version 2.5 as well, and I see that WP has just released 2.5.1. I don't know if that fixes up this latest hole or not.
Reply With Quote
  #8  
Old 04-26-2008, 06:36 PM
sunfunbill's Avatar
sunfunbill sunfunbill is offline
Bilinda the lil bitch!
 
Join Date: Mar 2003
Location: Lesbian fun house
Posts: 5,364
2.5.1 is suppose to fix 70 holes. I hope that was one of them, all of mine now are 2.5.1.

Now I'm a real believer in keeping it updated. But wp is still full of holes. Funny thing is, this virus does not seem to do anything. Which makes you think it is trying to get into as many as it can before it does,,, something!
__________________
Lover Cash Gay, teen, tranny & more dating, high converting!
Visit my Orlando Vacation site, Orlando Inside!
My site Crossdresser Playground CD/TV/TS community
Reply With Quote
  #9  
Old 04-28-2008, 10:18 AM
Cozy Monica's Avatar
Cozy Monica Cozy Monica is offline
Campus Moderator
 
Join Date: Dec 2002
Location: Canada
Posts: 4,730
Yes, a lot of viruses just get in there and spread.... they just sit dormant until a certain date, and then BAM!

WordPress does have a lot of holes... large open source scripts usually do. However, it's still the best free script out there for such things, in my opinion.

This, however, is why we drive our hosts absolutely nuts, because we all use scripts like this, and don't know a lot about them. It means that things are left wide open to attack and they end up struggling to fix things for us when it all goes wrong.
Reply With Quote
  #10  
Old 04-29-2008, 07:57 PM
SinSational's Avatar
SinSational SinSational is offline
Registered User
 
Join Date: Oct 2004
Location: Boston, MA
Posts: 1,147
Send a message via ICQ to SinSational Send a message via AIM to SinSational
Quote:
Originally posted by Cozy Monica
This, however, is why we drive our hosts absolutely nuts, because we all use scripts like this, and don't know a lot about them. It means that things are left wide open to attack and they end up struggling to fix things for us when it all goes wrong.
on behalf of all hosts, thanks for acknowledging this.

__________________
ICQ# 273099174 - monthly specials - FIRST MONTH FREE - 100% Referrals - chris@ for details
Virtual from $14.95/month, Dedicated from $199.95/month
Dual-Core Xeon > 20Mbps @ $399.95 | 50Mbps @ $699.95 | 75Mbps @ $999.95
Reply With Quote
  #11  
Old 04-29-2008, 08:00 PM
Cozy Monica's Avatar
Cozy Monica Cozy Monica is offline
Campus Moderator
 
Join Date: Dec 2002
Location: Canada
Posts: 4,730
Quote:
Originally posted by SinSational
on behalf of all hosts, thanks for acknowledging this.

I have programming experience, so I can imagine how frustrating it is as the administrator in such situations!
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 06:14 PM.

Support our Cozy adult webmaster forum Sponsors:

Porn Reviews
Honest Porn Reviews
Stroke King Blue Design Studios
Blue Design Studios
  Adult Reviews
Adult Reviews

Pussy Cash FTVCash Etu-Cash Traffic Cash Gold GJ Servers
AdXpansion        

 

CozyFrog.com  |   CozyFlash.com  |   Friends & Links
© 2002-10 CozyCampus.com | Adult Forums for Webmasters! | 18+ ONLY!
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.