<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Computer Worm Attacks Not Updated WordPress Blogs</title> <atom:link href="http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sun, 12 Feb 2012 00:34:28 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: Diamonds For Sale</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-1363185</link> <dc:creator>Diamonds For Sale</dc:creator> <pubDate>Thu, 01 Sep 2011 05:09:03 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-1363185</guid> <description>Thank you so much for providing individuals with an exceptionally wonderful possiblity to read from this blog. It is usually so kind and also full of a good time for me personally and my office friends to visit the blog on the least three times every week to see the latest issues you have. And indeed, I’m certainly satisfied with all the remarkable things you serve. Certain 2 facts on this page are unequivocally the best we have all had.</description> <content:encoded><![CDATA[<p>Thank you so much for providing individuals with an exceptionally wonderful possiblity to read from this blog. It is usually so kind and also full of a good time for me personally and my office friends to visit the blog on the least three times every week to see the latest issues you have. And indeed, I’m certainly satisfied with all the remarkable things you serve. Certain 2 facts on this page are unequivocally the best we have all had.</p> ]]></content:encoded> </item> <item><title>By: energy healing los angeles</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-1347405</link> <dc:creator>energy healing los angeles</dc:creator> <pubDate>Wed, 15 Jun 2011 19:38:37 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-1347405</guid> <description>I have seen many post like this in my life but this is the best among all of them.I want more post from here like it.Thanks a lot for sharing this post with us.</description> <content:encoded><![CDATA[<p>I have seen many post like this in my life but this is the best among all of them.I want more post from here like it.Thanks a lot for sharing this post with us.</p> ]]></content:encoded> </item> <item><title>By: joon</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-1290653</link> <dc:creator>joon</dc:creator> <pubDate>Sun, 02 Jan 2011 09:18:12 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-1290653</guid> <description>I recently came across your blog and have been reading along. I thought I would leave my first comment. Nice post!</description> <content:encoded><![CDATA[<p>I recently came across your blog and have been reading along. I thought I would leave my first comment. Nice post!</p> ]]></content:encoded> </item> <item><title>By: customize computer</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-1289087</link> <dc:creator>customize computer</dc:creator> <pubDate>Fri, 31 Dec 2010 15:04:56 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-1289087</guid> <description>thanks for yor information..
a computer worm is danger</description> <content:encoded><![CDATA[<p>thanks for yor information..<br
/> a computer worm is danger</p> ]]></content:encoded> </item> <item><title>By: Fit PC</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-1138843</link> <dc:creator>Fit PC</dc:creator> <pubDate>Fri, 23 Jul 2010 23:32:00 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-1138843</guid> <description>This is why it&#039;s so important to keep everything updated.Always check to see if there are problems to fix or unwanted intruders like worms.</description> <content:encoded><![CDATA[<p>This is why it&#8217;s so important to keep everything updated.Always check to see if there are problems to fix or unwanted intruders like worms.</p> ]]></content:encoded> </item> <item><title>By: eazyshare</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-884428</link> <dc:creator>eazyshare</dc:creator> <pubDate>Fri, 18 Sep 2009 19:20:05 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-884428</guid> <description>thx posting</description> <content:encoded><![CDATA[<p>thx posting</p> ]]></content:encoded> </item> <item><title>By: digitalmind computers</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-882010</link> <dc:creator>digitalmind computers</dc:creator> <pubDate>Mon, 14 Sep 2009 04:45:18 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-882010</guid> <description>Worms are really not good to hear.I hope this problem will be fix and will not happen again.Security must be much higher for the blogs.</description> <content:encoded><![CDATA[<p>Worms are really not good to hear.I hope this problem will be fix and will not happen again.Security must be much higher for the blogs.</p> ]]></content:encoded> </item> <item><title>By: Lee</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-880570</link> <dc:creator>Lee</dc:creator> <pubDate>Fri, 11 Sep 2009 03:51:17 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-880570</guid> <description>I always have problems with computer security. ArrgH! they&#039;re always a pain...</description> <content:encoded><![CDATA[<p>I always have problems with computer security. ArrgH! they&#8217;re always a pain&#8230;</p> ]]></content:encoded> </item> <item><title>By: Un nuevo gusano puede poner en peligro tu blog con WordPress &#124; Moyeja.net - Escencia Relativa</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-879971</link> <dc:creator>Un nuevo gusano puede poner en peligro tu blog con WordPress &#124; Moyeja.net - Escencia Relativa</dc:creator> <pubDate>Thu, 10 Sep 2009 05:11:31 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-879971</guid> <description>[...] Vía &#124; gHacks [...]</description> <content:encoded><![CDATA[<p>[...] Vía | gHacks [...]</p> ]]></content:encoded> </item> <item><title>By: Fery</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-879686</link> <dc:creator>Fery</dc:creator> <pubDate>Wed, 09 Sep 2009 14:54:04 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-879686</guid> <description>it happened to me. The intruder created new administrator inside my WP, but it could be deleted, should I update my WP?</description> <content:encoded><![CDATA[<p>it happened to me. The intruder created new administrator inside my WP, but it could be deleted, should I update my WP?</p> ]]></content:encoded> </item> <item><title>By: Un nuevo gusano puede poner en peligro tu blog con WordPress</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878905</link> <dc:creator>Un nuevo gusano puede poner en peligro tu blog con WordPress</dc:creator> <pubDate>Mon, 07 Sep 2009 18:18:16 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878905</guid> <description>[...] &#124; gHacks        0 comentarios Escribe un comentario &#8595;  Guardado en: Webmasters, Wordpress Etiquetas: [...]</description> <content:encoded><![CDATA[<p>[...] | gHacks        0 comentarios Escribe un comentario &darr;  Guardado en: Webmasters, WordPress Etiquetas: [...]</p> ]]></content:encoded> </item> <item><title>By: Blogs &#8211; video blogs &#124; Know Marketing Blog</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878890</link> <dc:creator>Blogs &#8211; video blogs &#124; Know Marketing Blog</dc:creator> <pubDate>Mon, 07 Sep 2009 17:31:33 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878890</guid> <description>[...] Computer Worm Attacks Not Updated Wordpress Blogs6 Sep 2009 by Martin &#160;A computer worm is currently in the wild that is attacking unpatched Wordpress blogs. Unpatched meaning blogs that have not been updated by their administrators. &#8211; [...]</description> <content:encoded><![CDATA[<p>[...] Computer Worm Attacks Not Updated WordPress Blogs6 Sep 2009 by Martin &nbsp;A computer worm is currently in the wild that is attacking unpatched WordPress blogs. Unpatched meaning blogs that have not been updated by their administrators. &#8211; [...]</p> ]]></content:encoded> </item> <item><title>By: Un gusano ataca blogs de Wordpress sin actualizar &#124; Malavida Blog</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878765</link> <dc:creator>Un gusano ataca blogs de Wordpress sin actualizar &#124; Malavida Blog</dc:creator> <pubDate>Mon, 07 Sep 2009 06:37:23 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878765</guid> <description>[...] Fuente: Ghacks [...]</description> <content:encoded><![CDATA[<p>[...] Fuente: Ghacks [...]</p> ]]></content:encoded> </item> <item><title>By: Daniel Sydnes</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878758</link> <dc:creator>Daniel Sydnes</dc:creator> <pubDate>Mon, 07 Sep 2009 05:39:01 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878758</guid> <description>WordPress.com hosted blogs are NOT affected.
Automattic regularly updates their application.  Since they control what plugins and themes can be used, their attack surface and regression testing is a constant, known quantity.
Automattic also uses intrusion protection systems and web application firewalls.  This helps them recognize attacks in real-time and dynamically shield against them.</description> <content:encoded><![CDATA[<p>WordPress.com hosted blogs are NOT affected.</p><p>Automattic regularly updates their application.  Since they control what plugins and themes can be used, their attack surface and regression testing is a constant, known quantity.</p><p>Automattic also uses intrusion protection systems and web application firewalls.  This helps them recognize attacks in real-time and dynamically shield against them.</p> ]]></content:encoded> </item> <item><title>By: Mithun John Jacob</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878749</link> <dc:creator>Mithun John Jacob</dc:creator> <pubDate>Mon, 07 Sep 2009 04:52:12 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878749</guid> <description>Does this worm affect sites hosted on wordpress.com ?</description> <content:encoded><![CDATA[<p>Does this worm affect sites hosted on wordpress.com ?</p> ]]></content:encoded> </item> <item><title>By: Computer Worm Attacks Not Updated Wordpress Blogs &#171; New Emerging Technologies for Netbook Mobile Phones Laptops Gadget and Gizmos</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878741</link> <dc:creator>Computer Worm Attacks Not Updated Wordpress Blogs &#171; New Emerging Technologies for Netbook Mobile Phones Laptops Gadget and Gizmos</dc:creator> <pubDate>Mon, 07 Sep 2009 04:03:28 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878741</guid> <description>[...]  [...]</description> <content:encoded><![CDATA[<p>[...]  [...]</p> ]]></content:encoded> </item> <item><title>By: Wordpress non aggiornati a rischio - The New Blog Times</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878740</link> <dc:creator>Wordpress non aggiornati a rischio - The New Blog Times</dc:creator> <pubDate>Mon, 07 Sep 2009 03:31:51 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878740</guid> <description>[...] spiega Ghacks.net. In particolare, osservare la presenza di scritte come &#8220;eval&#8221; e &#8220;base64_decode&#8221;, utilizzate per occultare allo sguardo il vero obbiettivo delle manipolazioni. [...]</description> <content:encoded><![CDATA[<p>[...] spiega Ghacks.net. In particolare, osservare la presenza di scritte come &#8220;eval&#8221; e &#8220;base64_decode&#8221;, utilizzate per occultare allo sguardo il vero obbiettivo delle manipolazioni. [...]</p> ]]></content:encoded> </item> <item><title>By: Daniel Sydnes</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878711</link> <dc:creator>Daniel Sydnes</dc:creator> <pubDate>Mon, 07 Sep 2009 00:53:51 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878711</guid> <description>@Rarst:
That shouldn&#039;t have happened.  Check your file permissions.
We use shared hosting delivered by Apache virtual hosts and mod_php.  We follow the &#039;File Permissions&#039; section in the &#039;Hardening WordPress&#039; article in the WP Codex:
http://codex.wordpress.org/Hardening_WordPress
Since we backup both the filesystem and databases nightly, I was able to use ComponentSoftware&#039;s CSDiff to recursively compare directories and MySQL dumps.
Our damage was limited to changes in the database:
- &#039;users_can_register&#039; was enabled in wp_options.
- &#039;permalink_structure&#039; was changed in wp_options.
- Additional &#039;rewrite_rules&#039; was added in wp_options.
- New administrator-level user created, with DHTML code in its &#039;first_name&#039; field to hide it in Users admin panel.
- WordPress Development RSS feed updated to remove security notice about 2.8.4 Security Release.
To detect which sites were hacked, I searched for &#039;/wp-admin//options-permalink.php&#039; in our server logs.  Since these are split up by virtual host, I used mlocate / slocate to find log file locations, then used xargs to feed them to zgrep for pattern matching:
locate access_log &#124; xargs zgrep -l &#039;wp-admin//options-permalink&#039;
Thanks for the tips regarding PHPIDS, WPIDS, WordPress Firewall Plugin, and .htaccess rules!  I tried AskApache Password Protect several months back but couldn&#039;t get it working.</description> <content:encoded><![CDATA[<p>@Rarst:</p><p>That shouldn&#8217;t have happened.  Check your file permissions.</p><p>We use shared hosting delivered by Apache virtual hosts and mod_php.  We follow the &#8216;File Permissions&#8217; section in the &#8216;Hardening WordPress&#8217; article in the WP Codex:</p><p> http://codex.wordpress.org/Hardening_WordPress</p><p>Since we backup both the filesystem and databases nightly, I was able to use ComponentSoftware&#8217;s CSDiff to recursively compare directories and MySQL dumps.</p><p>Our damage was limited to changes in the database:</p><p> &#8211; &#8216;users_can_register&#8217; was enabled in wp_options.</p><p> &#8211; &#8216;permalink_structure&#8217; was changed in wp_options.</p><p> &#8211; Additional &#8216;rewrite_rules&#8217; was added in wp_options.</p><p> &#8211; New administrator-level user created, with DHTML code in its &#8216;first_name&#8217; field to hide it in Users admin panel.</p><p> &#8211; WordPress Development RSS feed updated to remove security notice about 2.8.4 Security Release.</p><p>To detect which sites were hacked, I searched for &#8216;/wp-admin//options-permalink.php&#8217; in our server logs.  Since these are split up by virtual host, I used mlocate / slocate to find log file locations, then used xargs to feed them to zgrep for pattern matching:</p><p> locate access_log | xargs zgrep -l &#8216;wp-admin//options-permalink&#8217;</p><p>Thanks for the tips regarding PHPIDS, WPIDS, WordPress Firewall Plugin, and .htaccess rules!  I tried AskApache Password Protect several months back but couldn&#8217;t get it working.</p> ]]></content:encoded> </item> <item><title>By: Rarst</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878573</link> <dc:creator>Rarst</dc:creator> <pubDate>Sun, 06 Sep 2009 18:02:41 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878573</guid> <description>Tell me about it... My blog was recently hacked because some other blogger on server hadn&#039;t upgraded in forever and hacker went through him to hacking rest of server. :)
@Daniel Sydnes
To be fair 2.8 was major release to break stuff. However 2.8.X releases were security updates with very low probability of interferring with plugins and themes.
Obviously I do not have insight into your business, but if you provide thorough and extensive maintenance (that is not part of the initial deal) - it makes sense to charge for that.</description> <content:encoded><![CDATA[<p>Tell me about it&#8230; My blog was recently hacked because some other blogger on server hadn&#8217;t upgraded in forever and hacker went through him to hacking rest of server. :)</p><p>@Daniel Sydnes</p><p>To be fair 2.8 was major release to break stuff. However 2.8.X releases were security updates with very low probability of interferring with plugins and themes.</p><p>Obviously I do not have insight into your business, but if you provide thorough and extensive maintenance (that is not part of the initial deal) &#8211; it makes sense to charge for that.</p> ]]></content:encoded> </item> <item><title>By: Computer Worm Attacks Not Updated Wordpress Blogs - Local Tech Experts</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/comment-page-1/#comment-878541</link> <dc:creator>Computer Worm Attacks Not Updated Wordpress Blogs - Local Tech Experts</dc:creator> <pubDate>Sun, 06 Sep 2009 16:31:29 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060#comment-878541</guid> <description>[...] post:  Computer Worm Attacks Not Updated Wordpress Blogs  :browsing, companies, computer-work, entertainment, firefox, internet, linux, News, [...]</description> <content:encoded><![CDATA[<p>[...] post:  Computer Worm Attacks Not Updated WordPress Blogs  :browsing, companies, computer-work, entertainment, firefox, internet, linux, News, [...]</p> ]]></content:encoded> </item> </channel> </rss>
