Subscribe now! It looks like this is your first time visiting jeffmilner.com. If you like what you see, click here to subscribe! Add to Google

 
 

Wordpress 2.1.1 is “Dangerous”

March 4th, 2007

One of the dangers of upgrading too quickly when using open source software is that sometimes bugs aren’t noticed until wide spread usage allows for many more people to put it to the test.

Bugs haven’t been too much trouble lately, but a couple of days ago it was discovered that at least some of the downloads of WordPress 2.1.1 had an exploit written into them by a malicious PHP scripter.

This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.

More details from Wordpress.

Leave a Reply

If you'd like a fancy picture to appear with your comment, upload one at en.gravatar.com.