<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>drew3000 &#187; hackers</title>
	<atom:link href="http://drew3000.net/tag/hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://drew3000.net</link>
	<description>A burgeoning online Rancho Ponderosa</description>
	<lastBuildDate>Thu, 29 Jul 2010 21:18:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Older versions of WordPress under attack</title>
		<link>http://drew3000.net/2009/09/22/older-versions-of-wordpress-under-attack/</link>
		<comments>http://drew3000.net/2009/09/22/older-versions-of-wordpress-under-attack/#comments</comments>
		<pubDate>Tue, 22 Sep 2009 12:40:55 +0000</pubDate>
		<dc:creator>yours truly</dc:creator>
				<category><![CDATA[Technophillia]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://drew3000.net/?p=1840</guid>
		<description><![CDATA[To quote Lorelle: Update your WordPress blog before you continue reading this post. That’s how critical this issue is. &#8220;Otto42 of OttoDestruct, a key WordPress developer and supporter, reports that there is an “attack” on older versions of WordPress right now. The number of sites hit by this is growing every hour. Protect your WordPress [...]]]></description>
			<content:encoded><![CDATA[<p>To quote <a href="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/">Lorelle</a>: Update your WordPress blog before you continue reading this post. That’s how critical this issue is.</p>
<blockquote><p>&#8220;Otto42 of OttoDestruct, a key WordPress developer and supporter, reports that there is an “attack” on older versions of WordPress right now. The number of sites hit by this is growing every hour. Protect your WordPress blog now: UPDATE NOW!!!&#8221;</p></blockquote>
<p>I sort of have a habit of looking up subscribers to my blog. Thankfully there are not that many of them, so it&#8217;s pretty easy. When there&#8217;s a new one, I just google it. Two new ones were &#8220;<span class="mh-plaintext"><a href='http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=k_iX8HWENmb-uvI37JwNIjFCdaBULkVsrzl0SBcb1_M=' onclick="window.open('http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=k_iX8HWENmb-uvI37JwNIjFCdaBULkVsrzl0SBcb1_M=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="The email you can see, if you can answer these riddles three!">OBSCURED EMAIL ADDRESS</a></span>&#8221; and &#8220;<span class="mh-plaintext"><a href='http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=gmcZFro6A8Y4YNwpXMNK0dbLEddVFJJ_8bV29u4cnDU=' onclick="window.open('http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=gmcZFro6A8Y4YNwpXMNK0dbLEddVFJJ_8bV29u4cnDU=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="The email you can see, if you can answer these riddles three!">OBSCURED EMAIL ADDRESS</a></span>.&#8221; Googling these resulted in a slew of warnings on a hack exploit that exists in WordPress installs older than 2.8.4. which can allow nasty things like permalinks being changed to direct people elsewhere, as <a href="http://arabcrunch.com/2009/09/arabcrunch-and-wordpress-under-attack.html/comment-page-1">ArabCrunch</a> points out. <span id="more-1840"></span></p>
<p>Apparently, on older WordPress installs a hacker signs themselves up as a subscriber to follow comments, but can then do some sort of kung fu that changes their status to &#8220;administrator.&#8221;</p>
<p>If you&#8217;re operating a WordPress site, check for the following users:</p>
<ul>
<li> <span class="mh-plaintext"><a href='http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=n6i-HkRHJXdKmFnFh4zW3Z3rrqhX87lLLdT0m0Kf3HI=' onclick="window.open('http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=n6i-HkRHJXdKmFnFh4zW3Z3rrqhX87lLLdT0m0Kf3HI=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="The email you can see, if you can answer these riddles three!">OBSCURED EMAIL ADDRESS</a></span></li>
<li><span class="mh-plaintext"><a href='http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=zNektDIV7g0mFdhF_OpGVcsjc0mD6miDmBUR4-xSvKo=' onclick="window.open('http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=zNektDIV7g0mFdhF_OpGVcsjc0mD6miDmBUR4-xSvKo=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="The email you can see, if you can answer these riddles three!">OBSCURED EMAIL ADDRESS</a></span></li>
<li><span class="mh-plaintext"><a href='http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=HN8hi_oEqTheMWxg5MwB_VJLSViQ5vDG31HuRbXHuGI=' onclick="window.open('http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=HN8hi_oEqTheMWxg5MwB_VJLSViQ5vDG31HuRbXHuGI=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="The email you can see, if you can answer these riddles three!">OBSCURED EMAIL ADDRESS</a></span></li>
<li><span class="mh-plaintext"><a href='http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=k_iX8HWENmb-uvI37JwNIjFCdaBULkVsrzl0SBcb1_M=' onclick="window.open('http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=k_iX8HWENmb-uvI37JwNIjFCdaBULkVsrzl0SBcb1_M=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="The email you can see, if you can answer these riddles three!">OBSCURED EMAIL ADDRESS</a></span></li>
<li><span class="mh-plaintext"><a href='http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=gmcZFro6A8Y4YNwpXMNK0dbLEddVFJJ_8bV29u4cnDU=' onclick="window.open('http://mailhide.recaptcha.net/d?k=01ZhdDTYDbMiFQVPM7o8Chgg==&amp;c=gmcZFro6A8Y4YNwpXMNK0dbLEddVFJJ_8bV29u4cnDU=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="The email you can see, if you can answer these riddles three!">OBSCURED EMAIL ADDRESS</a></span></li>
</ul>
<p>Fortunately, I had upgraded shortly after 2.8.4 came out because I&#8217;m sort of unnaturally fixated on keeping d3 on the bleeding edge whether it breaks this blog or not, so they weren&#8217;t able to run the exploit. But even if these addresses aren&#8217;t in your subscribers list, upgrade now.</p>
<p><strong>Post-upgrade tips:</strong></p>
<ul>
<li>Be sure to not use the default admin user name.</li>
<li>Change your password.</li>
</ul>
<p>I think this was what was affecting the previous version of <a title="cpb" href="http://committeetoprotectbloggers.org/">The Committee to Protect Bloggers</a> website a while back, but I didn&#8217;t know what the deal was so simply uninstalled everything, wiped it and re-installed using the latest version of WP. But it sounds like it&#8217;s much more wide spread.</p>
<p><strong>Links:</strong></p>
<ul>
<li><a href="http://wordpress.org/development/2009/09/keep-wordpress-secure/" target="_blank">keep wordpress secure.</a></li>
<li><a href="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/" target="_blank">WordPress Vesrions under Attack</a></li>
<li><a href="http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/" target="_blank">How to clean up your hacked WP installation.</a></li>
<li><a href="http://www.journeyetc.com/2009/09/04/wordpress-permalink-rss-problems/" target="_blank">WP Permalink RSS problems.</a></li>
</ul>
<p><strong>Further advice:</strong> <a href="http://ocaoimh.ie/did-your-wordpress-site-get-hacked/">Holy Shmoly!</a> and <a href="http://www.mydigitallife.info/2008/06/10/wordpress-hack-recover-and-fix-google-and-search-engine-or-no-cookie-traffic-redirected-to-your-needsinfo-anyresultsnet-golden-infonet-and-other-illegal-sites/">My Digital Life</a></p>
<p><strong>Further note to the hacker(s) responsible:</strong> Do go and play in traffic.</p>
]]></content:encoded>
			<wfw:commentRss>http://drew3000.net/2009/09/22/older-versions-of-wordpress-under-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
