Check your Wordpress installation
March 21st, 2008 by Andreas from Xavier MediaIf you’re using Wordpress you should make sure that you’re using the latest version (at the moment 2.3.3) and that you’ve removed all the old files so no one can take advantage of a security leak in the old files. Shoemoney.com is reporting that people claim to have hidden links (or even iframes) injected into their latest installations of Wordpress.
Shoemoney.com says:
First I want to say I have never seen any evidence of a fresh 2.3.3 install of Wordpress.
The issue most likely comes from either a previous exploitable file still existing in your Wordpress install directory or from someone who has already hijacked your admin cookie. You see there were some wicked exploits in earlier versions that allowed people to hijack your admin cookie which authenticates you (keep me logged in).
So the advice is to always keep your installations up to date, change passwords regularly and to remove old files used in previous version of your installation. This is not only true for Word press, but for all installations on your server like for example phpBB.
A good idea is also to keep a backup on your database at some other location then your current server. Wordpress got a few good plugins that can email your database to you on a daily basis, or if you can you should setup so your web server is sending a backup of your entire site to some remote FTP account.
Popularity: 10% [?]

No related posts







March 31st, 2008 at 5:48 pm
[...] I reported in the Antivirus blog Shoemoney.com reported that people had had their blogs “hacked”, but it was uncertain [...]
April 26th, 2008 at 8:02 am
[...] sure you upgrade your phpBB forumsManipulated ratings at eBay?Welcome to the antivirus blogCheck your Wordpress installationWordpress 2.5 is out, upgrade today!Hosting companies watch out!Security fix for [...]
July 2nd, 2008 at 2:39 am
think upgrading is the best option to keep you system secure
wsdcents last blog post..EzMigration