Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Wordpress 2.1.1

views
     
TSSubKi||er
post Mar 3 2007, 11:50 AM, updated 19y ago

Newbie
******
Senior Member
1,654 posts

Joined: Jan 2003
From: Miri City, Sarawak. Mood: Missing someone~



I'm not very sure where this should go but if its un-appropriate here, please move it for me. Thanks

If any bloggers are running Wordpress 2.1.1 currently, please upgrade to the latest version for your safety.

QUOTE
Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation: This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.


It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.


Quoted from Wordpress.org

Upgrade : http://wordpress.org/download/
Hunz
post Mar 3 2007, 04:06 PM

znuh
******
Senior Member
1,238 posts

Joined: Nov 2004
From: Penang


Ohh yeah, got that info from my host too.
I'm still using 2.0.5.
I don't know if I should upgrade mine. =/
etsuko
post Mar 3 2007, 04:49 PM

Spaced out person
Group Icon
Elite
4,210 posts

Joined: Jan 2003
From: Malaysia


I think version 2.0 aren't that much affected however there are bugs in it too. Though not that critical i suppose. Can see their history revisions. smile.gif
shockw@ve
post Mar 6 2007, 06:51 PM

d[-_-]b
Group Icon
VIP
1,889 posts

Joined: Jan 2003
QUOTE(Hunz @ Mar 3 2007, 07:06 PM)
Ohh yeah, got that info from my host too.
I'm still using 2.0.5.
I don't know if I should upgrade mine. =/
*
You should be upgrading to 2.0.9 at the very least if you do not want to upgrade to the newer 2.1.x as there has been fixes to various security vulnerabilities. Upgrading to 2.1.x though is more if you want the new features it has to offer. smile.gif
OKLY
post Mar 6 2007, 06:59 PM

The Penguin Vader
Group Icon
Staff
12,090 posts

Joined: Dec 2004
From: Malaysia


They recommend to upgrade to 2.1.2 if you are currently using 2.1.1 because of security issue. If you weren't using 2.1.1, you can still stay with your current version.
destfull
post Mar 7 2007, 08:54 PM

Brain for Creativity
******
Senior Member
1,063 posts

Joined: Jul 2005



haha.. why they release new version almost every week... i'm not gonna upgrade it if not because of fantastico tongue.gif

 

Change to:
| Lo-Fi Version
0.0141sec    0.92    5 queries    GZIP Disabled
Time is now: 20th December 2025 - 09:27 AM