Theme Lab

  • Contact
  • Advertise
  • About
  • Sitemap
  • Resources
  • Forums
  • Tutorials
  • Free Themes
  • Home

Subscribe


Search Our Archives

Article Categories

  • bbPress (1)
  • Free Theme Releases (58)
  • Ported Themes (40)
  • Site News (15)
  • Theme Lab Showcase (1)
  • WordPress Community (6)
  • WordPress News (5)
  • WordPress Plugins (11)
  • WordPress Tutorials (26)

Recent Themes

  • WP Garden - Free WordPress Theme
  • Green and Brown - Free WordPress Theme
  • Orbital - Free WordPress Theme
  • Choice - Free WordPress Theme
  • SummerBreeze - Free WordPress Theme

Recent Tutorials

  • Add Gravatar Support to Your WordPress Comments
  • Make a Sitemap Page For Your WordPress Blog
  • Easily Add Videos to Your WordPress Blogs
  • How To Make a WordPress Privacy Policy
  • You Don’t Need a Blog On Your Front Page

Tag Cloud

asides Ben Swift black blue bright brown classy clean colorful dark DemusDesign edg3 elegant featured post FreeCSS glossy gold gray green Hive Designs khaki left sidebar light minimalistic Nuvio one column orange pink purple Rambling Soul red right sidebar silver simple sleek Snapp Happy Styleshout SymiSun tan Templatefusion three columns two columns white Writeside yellow

WordPress Security Alert - Vulnerability in 2.3.3

posted in WordPress News 4 Comments

I just stumbled upon this post about an exploit which allows a hacker/spammer to inject links and HTML into your WordPress installation. If you see a /wp-content/1/ directory in your FTP, you have likely been affected. Over 9000 other WordPress blogs are in the same boat.

Google results for wp-content/1/ exploit

As you can see, ringtones, gambling, the usual spammy stuff. I’m not going to directly link to these results as some of these links have been reported to be malware-infested. Definitely not a good idea to visit them. Google will likely penalize you if these spam links on your exploited site are crawled, so you should delete this directory ASAP along with all files under it if you see it.

As of yet, no official word from WordPress developers on this vulnerability has been released. Until then, it’s best to use good security practices (which should apply to all websites, not just WordPress-powered ones). Password protect your directories, don’t publish the version of the script you’re using, disable indexes on WordPress core directories - to name a few. I’ll be posting some general WordPress security tips up on Theme Lab soon.

Note: More information available on this WordPress.org support topic, where the exploit was initially reported.

  • Subscribe to RSS
  • E-mail
  •  
  • By: Leland on Mar. 24
  • Bookmark and Share

Shawn says:

posted on March 24, 2008 6:09 pm

Thanks for the heads up. Really informative and great content. The tips should help many avoid this problem.

livecrunch says:

posted on March 24, 2008 11:46 pm

I also wrote about it at
http://www.bontb.com/2008/03/wp-content1-trojan-virus-for-wordpress-bloggers/

ill keep posting what i find out

Anto says:

posted on March 25, 2008 10:11 am

Nice find. Hopefully they’ll get round to sorting it. Im sure they know about it now tho.

luca says:

posted on March 29, 2008 2:44 am

i saw your post and thought i’d give this issue some importance, because i also use wordpress and a friend told me he got hacked.
so i wrote this article about the issue
http://websecurity.ro/blog/2008/03/28/wordpress-233-probably-a-0day-exploit/

Leave a Comment

Name:*

Email:*

Website:

Comment:


Sponsors

Free wordpress themes Revolution Theme PowerTheme XHTML Valid Advertise Here

Featured Theme

WP Multiflex 5
WP Multiflex 5

Top Downloaded

  • Transmission (4,249 hits)
  • Colourise (2,178 hits)
  • WP SymiSun (1,979 hits)
  • WP Multiflex 5 (1,960 hits)
  • Simply AIO (1,398 hits)

Blogroll

  • Free CSS Templates
  • Free Photoshop Brushes
  • iPeterBrown
  • Make Money Blogging
  • Rambling Soul
  • Ty’s Blogging Tips
  • UK2 Web Hosting and Blog
  • WordPress Design
  • wpPotential
  • XHTML Valid
  • Vote for us as at Favelets
All material copyright © 2008 Theme Lab.
Powered by WordPress | Terms of Service | Privacy Policy