For those of you who do not check your Wordpress Dashboard religiously, Wordpress 2.1.1 is “Dangerous”. If you downloaded the files recently, Wordpress 2.1.1 “may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately”.


Advertise With Us

Matt said

This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.

Scary stuff indeed.

Get Wordpress 2.1.2 here, but before you upgrade, review how to backup your Wordpress database. Be sure to manually backup the following manually by copying the files to your desktop before you upgrade:

  • /wp-content folder
  • wp-config.php
  • .htaccess files before you upgrade

Mac users, when you download your backup copy of your .htaccess file to your desktop for a backup, you will need to use this code to see your .htaccess. Open up a Terminal and type

defaults write com.apple.finder AppleShowAllFiles TRUE
killall Finder

This tells finder to show hidden files. To switch back to your standard view, in Terminal type

defaults write com.apple.finder AppleShowAllFiles FALSE
killall Finder

"Wordpress 2.1.1 Unsafe - Upgrade Now Or Your Blog May Die!" by Tommy was published on March 2nd, 2007 and is listed in Wordpress.

Follow comments via the RSS Feed | Leave a comment | Trackback URL

Comments on "Wordpress 2.1.1 Unsafe - Upgrade Now Or Your Blog May Die!": 1 Comment

  1. alltags-tagebuch v2005.07.1088 german do wrote,

    tjrq irlqxy bjodutw

Leave Your Comment

Subscribe without commenting

Click Screenshots To Enlarge

  • Wordpress Theme Skin for Shifter - Over It (Glass)
  • Change between thin, wide and full width layouts without destroying your site structure.
  • Wordpress Theme Skin for Shifter - Over It (Light)
  • Choose between single or double sidebars and then shift sidebar width or position with the flip of a switch.
  • Wordpress Theme Skin for Shifter - Lizard (Dark)
  • One, two or three column layouts have never been easier.
  • Wordpress Theme Skin for Shifter - Brown
  • 15 skins let you choose the end look for your site without destroying the structure of your perfect layout.
  • Wordpress Theme Skin for Shifter - News Red
  • Shifter makes designing your site easier, faster and more enjoyable - all with the flip of a switch!

Wearing the Basic Skin for Shifter by Buzzdroid