Time to Upgrade Your WordPress Blogs

February 6, 2008 by PatB |

Yesterday, WordPress released a new version of their popular blogging software in response to a security issue. Apparently, there is a concern about the parsing of the xml remote procedure call. It seems specially crafted requests could allow anonymous, unauthenticated users to edit posts or even potentially defaceĀ a blog.

The bad guys would likely use this exploit to distribute malware or bomb Google with false information, thus driving hits to malware-hosting sites, and spreading botnets.WordPress also wanted to remind everyone to change site passwords regularly, and software updates or upgrades are good reminders to make that important, internal security change.More on this here at WordPress’ Dev Page.

On another note, has anyone else seen the enormous spike in blogspam over the past few days? The amount of spam I see has more than tripled.

Most of the spam comments were designed to pull search engine hits away from authentic, reputable Web sites (such as auto dealers) to new sites hosting malware. This represents a shift in tactics employed by phishers.

In light of this, you may want to exercise caution when visiting sites resulting from search requests. If you haven’t already done so, download and use McAfee’s SiteAdvisor utility. It is free and will validate search results, ensuring the sites you want to visitĀ are not malicious before you click on them. It keeps me from visiting sketchy sites every day.

You Might Also Like:

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • bodytext
  • StumbleUpon
  • Fark
  • Reddit
  • Technorati
  • Mixx
  • Pownce
  • Slashdot
  • TwitThis

Did you enjoy this post? If so, subscribe to the geeksaresexy RSS feed.

RSS feed | Trackback URI

2 Comments »

Comment by Kiltak
2008-02-06 11:34:34

Same here.. Akismet gobbles around 300 spams per day right now… about twice as much as I receive usually…

 
2008-02-06 11:58:11

[...] I have details over at Geeks Are Sexy. [...]

 
Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

| [GAS] Privacy Policy |