Home User CP Browse Members Calendar Register Today!  
Get New posts Faq / Help?
   

Not A Member Yet? Register today and become part of the community.

Go Back   Profuse Host Forum > World Wide Web > Programming / Scripting / Coding Forum

Programming / Scripting / Coding Forum Discussion HTML, C++, PHP, CGI, JSP, perl etc

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-05-2007, 05:36 AM
Ryan56
Status: Offline
Member
 
Join Date: Aug 2006
Posts: 58
Ryan56 is on a distinguished road
Default Security problems in Wordpress open-source blogging platform 2.1.1 upgrade now

Users who have downloaded the 2.1.1 version of the open-source blogging platform WordPress should upgrade all files to 2.1.2 immediately, since they could include a security bug injected by a cracker who gained user-level access to one of the servers that powers wordpress.org, according to a release posted on WordPress' site on Friday. WordPress received a note on the project's security mailing address Friday morning regarding "highly exploitable code," the release said. After investigating the issue, the WordPress developers found that the 2.1.1 download had been modified from its original site. The Web site was taken down immediately for further forensic analysis.

"It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file," the release continued. "We have locked down that server for further forensics." At this point it looks like the 2.1.1 download was the only thing affected by the attack. The attacker(s) modified two files to include code that would allow for the remote PHP execution. "This is the kind of thing you pray never happens, but it did and now we're dealing with it as best we can," the release continues. Not all downloads of 2.1.1 were affected, but WordPress declared the entire version dangerous. Several WordPress developers worked through the night to release a new version, 2.1.2, that includes minor updates and entirely verified files.
Reply With Quote

  #2 (permalink)  
Old 02-08-2008, 07:29 AM
joseph0829
Status: Offline
Senior Member
 
Join Date: Jan 2008
Posts: 186
joseph0829 is on a distinguished road
Default

i really want to update my current version of wordpress, v2.3.2, with its new release,v2.3.3, but i have doubts when updating it, because im afraid of loosing my posts though I know it was stored on my database but, i really dont know the whole process
__________________
Come and vist my blog: http://www.josephsator.info and also please do some comments of some of my posts. Thanks! thanks!
Reply With Quote

  #3 (permalink)  
Old 02-08-2008, 09:32 AM
snoop1990
Status: Offline
Senior Member
 
Join Date: Dec 2007
Location: Germany (in a small town)
Posts: 356
snoop1990 is on a distinguished road
Default

Quote:
Originally Posted by joseph0829
because im afraid of loosing my posts though I know it was stored on my database but, i really dont know the whole process
Then just backup your hole blog ! I am not sure if there is any script available to do so, but in general you just have to compress all the files in your wordpress folder. (you can do that by using the cpanel file manager) Then store all your files to your computer or any other backup drive.

Also save all your database entries using the phpadmin located in cpanel (cpanel/databases) and save the databases to an file.

Then check your backup if everything works and then upgrade, this is the secure way for all of you who do not want to risk any thing. But in general an wordpress upgrade do not touch the database, it only might cause some incompatibility with custom made layouts.

For more information just contact the wordpress support center, because I am not that familiar with wordpress.

Regrades Snoop1990
Reply With Quote

Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Which Blogging Software is best flickall SEO - Search Engine Optimization 6 03-17-2008 10:23 PM
Free source celeb photo's? flickall Web Graphic, Design, Digital Images 10 03-08-2008 05:25 AM
How to build blogging page on a site? flickall SEO - Search Engine Optimization 4 12-08-2007 10:51 AM
open source for all alsemany Programming / Scripting / Coding Forum 5 04-11-2007 07:39 AM
xchat (Open source) liammpease Programming / Scripting / Coding Forum 1 01-31-2006 09:10 PM


All times are GMT -7. The time now is 05:48 AM.

Skin Design By vBSkinworks



Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.

Sponsored by Web Hosting


Profuse Solutions LLC

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80