Don't envy Google and its fun Logos! Now, have some fun with your own set of exclusive Holiday/Themed Logos
 

Wordpress 2.1.1 Dangerous, Upgrade Now!

written by John Chow on March 2nd, 2007

This just came in across the Wordpress dashboard. Thanks to Nick Mercer for emailing me about it as well.

Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation: This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.

It vital that you upgrade to Wordpress 2.1.2 now. Don’t wait, just do it! Then again, if you upgraded to 2.1.1 before the cracker got in and hacked the codes, you should be OK, but why take the chance?

Tweet This Tweet This Post!
English flagItalian flagKorean flagChinese (Simplified) flagChinese (Traditional) flagPortuguese flagGerman flagFrench flagSpanish flagJapanese flagArabic flagRussian flagGreek flagDutch flagBulgarian flagCzech flagCroatian flagDanish flagFinnish flagHindi flagPolish flagRomanian flagSwedish flagNorwegian flagCatalan flagFilipino flagHebrew flagIndonesian flagLatvian flagLithuanian flagSerbian flagSlovak flagSlovenian flagUkrainian flagVietnamese flag
By N2H
  1. See, I knew being slow with upgrades would come in handy :shock:

  2. Oh man! Thanks for the heads up John!

    I’m backing up may database as we speak (or, as I type)!

  3. Good thing I checked your blog first, I was about to download WordPress 2.1.1 for setting up another blog.
    Thanks for the heads up, I think I’ll wait a bit.

    Das Brain
    MoneyAccumulator.com

  4. Phew..I was just about to update today. I didn’t have time and had a few plugins that I wasn’t sure would work in 2.1.1. I’m glad I waited now :)

  5. Boy … talk about a devious backdoor exploit! You’re a champ for posting this to your blog … imagine how many professional and amateur bloggers alike have vulnerable sites right now but don’t know it.

    Scary indeed.

  6. Done… although I did so earlier today before you posted this blog, but thanks for the info. because I was unaware of the exploit!

  7. :!: Did anyone else noticed that Firefox’s spell check works in the rich text editor again?! :!:

  8. allways the hackers :cry: ! thanks for the warning

  9. One of the main reasons I don’t immediately upgrade to new versions of software. I usually allow things to go “mainstream” before performing upgrades because no matter how much testing (we’ll in this case it wasn’t because of lack of testing) when software is released, people are bound to experience more problems if they exist once the software is streamlined to consumers.

  10. Wow that’s not good.

    I hope they included my JavaScript spacing fix with 2.1.2. :mrgreen:

  11. I was just finishing my post on The Secret Truth About The Plugins Security when I found out about Wordpress 2.1.1.
    That’s why I never rush to upgrade to a new version as soon as it’s been released.

  12. Eli

    Thanks for posting this John, I check your RSS feed first :)

    I did happen to upgrade one of my sites to 2.1.1 just last a few nights ago… so I’m just going to upgrade all of them to 2.1.2 now.

  13. Shit happens I suppose but this is a major blow to the credibility of the folks at Wordpress. :oops: :oops: Who’s to say that their servers are not further compromised or that the currently released version 2.1.2 isn’t in fact a release that was compromised along with the announcement asking users to upgrade? Put that in your pipe and smoke it.

    I’m going back to notepad local…unplugging from my router. :mrgreen: :mrgreen:

    • “major blow to the credibility of the folks at Wordpress”

      How? They got hacked! It’s not like they put the malicious code in there.

      • Exactly, they got hacked and the download release for version 2.1.1 was compromised with malicious code added to it. Why do you think they are urging everyone to upgrade so urgently?

        This is a wordpress ‘red-alert’. It doesn’t get anymore urgent than this. Any one of us running version 2.1.1 could very well be running the modified version and be wide open to whoever has the knowledge and the desire to mess up your site.

        This begs the question, what was the nature of this malicious code and what does it allow this individual to do?

        Also, even after we upgrade to 2.12, there is always the possibility that the evildoers have already messed up your wordpress db and added in some other malicious code. I haven’t seen any mention of this yet and the only way to be sure would be to go through your tables individually….yeah right.

        • Tomorrow it will come out with a new version and more bugs – thus the life of the internet.

        • I agree that it is a little hard to believe which story is the real thing. Like what you may suggest, the story to upgrade once again may be put up by the hacker.

          I believe, give WP sometime and they may explain how it happens, what it does and the measures that they are taking to prevent it.

          Besides the point, there will always be smarter people lurking around in the corners of the world, and it would be hard to beat all the crackers out there.

        • there is always the possibility that the evildoers have already messed up your wordpress db and added in some other malicious code

          While it’s a possibility, I’m sure the Wordpress crew is checking their server logs and patching any holes!

    • yeah they have a major blow there.I hope they come out with something good

  14. I just spread the word on my blog Thanks for the pointer.

  15. May be prudent for folks to change passwords for their Wordpress db (update wp-config.php accordingly of course) and perhaps even existing WP user passwords.

  16. Yea I got hacked since last night. To be exact, it was 18 hours ago. Was spending the past hour trying to reinstall WP, and restoring my blog entries. What a wastage of time! grr..

  17. Wow. Good thing I never moved onto that version!

  18. I didn’t have to worry about version 2.1.1, since I never got around to it this week, but I upgraded to 2.1.2 anyway. I was surprised that DreamHost got around to adding it to their one click installs so quickly. As an added bonus, their interface got a facelift in the past few days as well. Kudos to DreamHost, I highly recommend them!

  19. Most sites aren’t big enough people are even going to worry about hacking them – it’s just a matter of how so many people try to ruin it for those who make their living off the internet.

  20. Adam F

    Thanks for letting me know

  21. thanks for the warning, I’ve got to update mine ASAP

  22. Hi, I’d just like to point you towards my article on Upgrading WordPress via Shell for those who have SSH access to their accounts.

  23. Jez

    Really glad you posted this, I recently did an install for a friend with a download taken at this time, nasty stuff, easily upgraded fortunately

  24. LOL.. “the Root of All Evil himself” :lol:

  25. You cannot run no more from your new nickname john :D “Root Of All Evil” AKA “ROAE” or “John, The ROAE”

  26. I wonder if we can SEO those keywords to have johnchow.com come to a number one spot.

  27. I am gamed too as well. So.. who else is starting one? :grin:

  28. well, if you wanted to start one, all you would have to do is make that the link: The Root Of All Evil

Trackbacks

  1. Upgrade Immediately to Wordpress 2.1.2! | Stephen Fung DOT NET - March 2, 2007 at 2:58 pm
  2. The Flow of Consciousness » Upgrade immediately to Wordpress 2.1.2 - March 2, 2007 at 4:20 pm
  3. links for 2007-03-03 | On Influence and Automation - March 2, 2007 at 5:26 pm
  4. Firefox 2’s Spell Check Working In Wordpress 2.1.2! | Samanathon.com - March 2, 2007 at 5:29 pm
  5. Wordpress 2.1.1 Security Exploit at Clever Start - March 3, 2007 at 3:01 am
  6. Wordpress 2.1.1 Dangerous you might be exploited at mscholars blog - March 3, 2007 at 3:51 am
  7. DropsTech.org - March 3, 2007 at 7:27 am
  8. My Satellite Tracking Blog » WP 2.1.2 and Blog Adiction - March 3, 2007 at 3:09 pm
  9. Nomadishere : Seeker of Truth » Blog Archive » links for 2007-03-06 - March 6, 2007 at 3:36 pm