WordPress 2.1.1 Dangerous

If you have downloaded WordPress 2.1.1 sometimes between Feb. 27 and Mar. 2, 2007, your blog may have a security exploit added by a cracker who hacked wordpress.org servers:

This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.

Fix if you're running version 2.1.1: upgrade to 2.1.2 immediately.

Leave a comment

More or less related entries

mensuelles Archives

Recent Entries

  • On Apple Safari's use of justified text in Reader

    On my professional blog, a take on Apple Safari's use of justified text in Reader....

  • Curated computing

    Perhaps the most pernicious proposition of the “everything must be open” crusade is the notion that curation is bad and anti-freedom. Soldiers of this crusade...

  • Death by Apple, the obsolescence of Flash

    Flash was created during the PC era – for PCs and mice. Flash is a successful business for Adobe, and we can understand why they...

  • Ogg (and Mozilla) objections

    Ogg objections by Måns: When challenged, three types of reaction are characteristic of the Ogg campaigners. On occasion, these people will assume an apologetic tone,...

  • Paris Web 2010 — Call for speakers

    (Disclaimer: I manage the communication for Paris Web, this is a copy of the official call for speakers.) Hello all, Paris Web is a French...