Results for "wordpress"
Wordpress Plugin Easy Comment Uploads Vulnerability
Wordpress as you might know is one of the most widely used blogging platforms, As a reason of which it has became the favorite target of hackers. Wordpress itself is quite secure, however the plugins make it unsecure resulting in hack attacks, data loss etc, when they are created the developers do not think of the security or do not know how to write the secure code, hence skipping lots of necessary checks making the plugins vulnerable to attacks like SQLInjetion, Remote File inclusion etc.

One of those popular vulnerable plugin is Easy Comment Upload plugin, The version 0.61 and prior versions are affected with Arbitrary File Upload Vulnerability. The plugin fails to check the upload file type as a reason of which it can be exploited by uploading a Phtml file.


Easy Comment Upload plugin

Wordpress Plugin Easy Comment Uploads Vulnerability

There are thousands of wordpress blogs still vulnerable to this attack. The vulnerability can be fixed by updating the wordpress easy comments plugin to version 0.71.

If you want to know more about Protecting your wordpress blog from hackers you can refer the following posts, If you still think your blog is vulnerable drop me an email and I will perform a security assessment on your blog. via | rafayhackingarticles

takecy 1/20/2012
Avast Warns WordPress flaw
Avast Warns WordPress flaw
Security firm Avast is advising webmasters to scan sites and update log-in credentials following the discovery of a malware attack targeting the WordPress publishing platform.

The attack exploits a vulnerability in an image plug-in for WordPress, allowing an attacker to access a site and use the platform to distribute malware payloads and harvest FTP log-in credentials for users and administrators.

Jan Sirmer, senior virus lab researcher at Avast, said that a flaw in the TimThumb image plug-in allows the attackers to infect sites running WordPress with a malicious PHP file.

The attack is believed to be conducted through a commercially available toolkit called BlackHole, and redirect users to sites that attempt to install malware.

Sirmer warned that in some cases the attack had gone unnoticed by administrators because the sites were hosted by third-party service providers.

Avast urged administrators to scan their own systems, and to visit their sites with PCs running anti-virus software to detect possible infections on hosted pages.

"WordPress is not immune to exploitation, a fact driven by its overall popularity and the wide number of available versions," Sirmer said.

"Stronger log-in and password keys, alone or together with two-factor authentication, are options that system administrators should use when working with third-party IT managers." via paketstromsecurity

takecy 11/01/2011
WordPress 3.1.3 and 3.2 Beta 2 Released
H-Online : The WordPress.org development team has released version 3.1.3 of its open source blogging and publishing platform; this is a maintenance and security update to WordPress 3.1 released in late February. According to the developers, the stable update features security hardening and taxonomy query hardening, and prevents the sniffing out of user names of non-authors by using canonical redirects.

WordPress 3.1.3 also introduces clickjacking protection in modern browsers on admin and login pages. In the event of an import not completing, the old import files will be cleaned up automatically. Other changes include media security fixes and improved file upload security.

At the same time, the developers also published a second beta of version 3.2 of WordPress. The latest beta adds support for Google's Chrome Frame in the admin area. The developers say that the admin area is now "less ugly" in Internet Explorer 7 (support for IE6 was dropped in the previous beta) and that the blue admin colour scheme is now ready for testing. jQuery 1.6.1 is now being bundled and users are advised to test any JavaScript that uses jQuery. Release candidate versions are planned for June, followed by a final version "by the end of the month".

As previously noted by the developers, version 3.2 of WordPress has new system requirements: PHP 5.24 and MySQL 5.0. As with all development releases, use on production sites is not advised. Users testing the release are asked to provide feedback and report any bugs that they find in the forums, mailing lists, over IRC on irc.freenode.net #wordpress-dev or directly into the WordPress Trac.

More details about both the latest stable version and development versions can be found in the announcement news post; information specific to the stable version is in the 3.1.3 change log. WordPress 3.1.3 and 3.2 Beta 2 (direct download) are available to download from the project's web site. Alternatively, 3.1.x users can update automatically via the Dashboard > Updates menu in the site admin area. WordPress is licensed under the GNU General Public Licence (GPL).
 

Unknown 5/26/2011