Warning to all WordPress Users – Hack Attack Underway: WordPress Users Must Upgrade to (version 2.8.4)
Posted on September 6, 2009 by by Valeri
Reports are coming out from Mashable and Lorelle on WordPress about a hack attack on all websites using WordPress as their blogging application. Everyone has been asked to upgrade to (version 2.8.4).
“Otto42 of OttoDestruct, a key WordPress developer and supporter, reports that there is an “attack” on older versions of WordPress right now. The number of sites hit by this is growing every hour. Protect your WordPress blog now: UPDATE NOW!!!” Lorelle on WordPress
There are two clues that your WordPress site has been attacked.
There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”
The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account, but Journey Etc. has a possible solution.
To prevent this form of attack, update your WordPress site IMMEDIATELY to the latest version. Change ALL passwords to astrong password immediately, including WordPress blog access for all users, database, FTP, control panels, everything.
So I guess I was almost right when I said hackers are trying to attack popular blogs…!!
Tweet




