WordPress 2.1.1 Hacked
It appears that a hacker found a weakness in WordPress’s online security and poisoned their source code with a backdoor. WordPress has released 2.1.2. Only those who downloaded the previous version in the past few days are likely exposed, but everyone should upgrade if they get a chance.
From WordPress.org here:
This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.
It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.
WordPress is a non-profit organization, and they are really good at using the community to help secure their software. However, maybe they should have a fund drive to purchase an Intrusion Prevention System?
id disagree with a couple of the statements but i do think hes still a soft tyranny and will be until the end of the show…