Moloth - The M-Forums

You are not logged in.

#1 6/2/08 11:33 am

Russ
Virtual Deity
From: Ringgold, GA
Registered: 4/12/06
Posts: 9057
Website

Hacked again

Looks like WordPress was hacked again and every single .php and .html file was altered. I've been busy all morning restoring the site from the backup but it's taking a while. Forums are restored for the most part right now, some image attachments aren't in place yet but should be soon. Once everything's restored I'll see what needs to be done to patch WordPress.

Offline

 

#2 6/2/08 11:35 am

Moloth
In-tool-lectual
From: Sacramento, CA
Registered: 6/9/05
Posts: 8051
Website

Re: Hacked again

AH.

right at a domain transfer.. >_<


geez. 


in any case, thank you very much for your efforts, Russ!


-=The Believer is Happy; the Skeptic is Wise=-

http://miniprofile.xfire.com/bg/bg/type/1/moloth.png

Offline

 

#3 6/2/08 12:14 pm

Russ
Virtual Deity
From: Ringgold, GA
Registered: 4/12/06
Posts: 9057
Website

Re: Hacked again

Site's back up now, and I checked already and you seem to be using the latest WordPress version. I'll have to do some more investigating to see if I can find out exactly how it happened. But for now, it's bean time.

Offline

 

#4 6/2/08 1:38 pm

Russ
Virtual Deity
From: Ringgold, GA
Registered: 4/12/06
Posts: 9057
Website

Re: Hacked again

I think everything's ok, most likely most of the files were planted via RFI when the site was hacked pre-2.5.1, most of the timestamps on the files were before this morning.

Offline

 

#5 6/2/08 1:41 pm

Moloth
In-tool-lectual
From: Sacramento, CA
Registered: 6/9/05
Posts: 8051
Website

Re: Hacked again

weird. 

Is Wordpress really this unsecure?


-=The Believer is Happy; the Skeptic is Wise=-

http://miniprofile.xfire.com/bg/bg/type/1/moloth.png

Offline

 

#6 6/2/08 1:46 pm

Russ
Virtual Deity
From: Ringgold, GA
Registered: 4/12/06
Posts: 9057
Website

Re: Hacked again

Well like anything, it needs to be kept up to date with the latest releases.

http://wordpress.org/development/2008/04/wordpress-251/

Version 2.5.1 of WordPress is now available. It includes a number of bug fixes, performance enhancements, and one very important security fix. We recommend everyone update immediately, particularly if your blog has open registration. The vulnerability is not public but it will be shortly.

Offline

 

#7 6/2/08 2:03 pm

Cin
Collin's Groper
From: Insane Asylum
Registered: 6/10/05
Posts: 5632
Website

Re: Hacked again

"not public?"

Let me go check FARK.


"If you want a picture of the future, imagine a boot stamping on a human face - forever"
George Orwell

Offline

 

#8 6/7/08 12:53 am

spooki
M-F'er
From: Warner Robins, GA
Registered: 12/29/07
Posts: 939
Website

Re: Hacked again

It probably wasn't public when it was posted in April. wink

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2005 Rickard Andersson