Technology news and Jobs arrow Information Technology News arrow Attacker adds backdoor to WordPress blog software
Attacker adds backdoor to WordPress blog software E-mail
by Stephen Withers   
Wednesday, 07 March 2007
If you downloaded the WordPress blogging software last week, be sure to upgrade to version 2.1.2. An unknown attacker modified two of the files in version 2.1.1, opening up a back door allowing remote execution of code.

The attacker managed to get user-level access to one of the wordpress.org servers, and took advantage of that to modify the software available for download.

"This is the kind of thing you pray never happens, but it did and now we’re dealing with it as best we can," founder Matt Mullenweg wrote in a statement posted on the WordPress web site. "Although not all downloads of 2.1.1 were affected, we’re declaring the entire version dangerous," he added.

Measures are being taken to prevent a repeat of the incident.

According to Symantec security response engineer Masaki Suenaga, "a user who visits a Web page on a server containing the hacked WordPress software is not at risk, so long as the server has not been compromised by other malicious threats downloaded by the back door."{moscomment}
Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter