Australian IT JOBS : Sydney IT jobs, UNIX jobs, Linux jobs, Java jobs, ASP jobs Linux.conf.au Linux.conf.au
Technology news and Jobs arrow Information Technology News arrow Attacker adds backdoor to WordPress blog software
Attacker adds backdoor to WordPress blog software PDF Print E-mail
Written by Stephen Withers   
Wednesday, 07 March 2007
If you downloaded the WordPress blogging software last week, be sure to upgrade to version 2.1.2. An unknown attacker modified two of the files in version 2.1.1, opening up a back door allowing remote execution of code.

The attacker managed to get user-level access to one of the wordpress.org servers, and took advantage of that to modify the software available for download.

"This is the kind of thing you pray never happens, but it did and now we’re dealing with it as best we can," founder Matt Mullenweg wrote in a statement posted on the WordPress web site. "Although not all downloads of 2.1.1 were affected, we’re declaring the entire version dangerous," he added.

Measures are being taken to prevent a repeat of the incident.

According to Symantec security response engineer Masaki Suenaga, "a user who visits a Web page on a server containing the hacked WordPress software is not at risk, so long as the server has not been compromised by other malicious threats downloaded by the back door."{moscomment}


Get stories like this delivered daily - FREE - subscribe now
When you subscribe get a 12 months license for LiveProject
Valued at $99 USD


LiveWire - Desktop alerts Download the FREE iTWire desktop alert widget LiveWire - Desktop alerts


Del.icio.us!
 
< Prev   Next >
Contact , Register , Advertise with iTWire , Links , Register , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging
Industry Releases , Submit your release now , Start submitting to iTWire , How to post video