Top

Wordpress 2.3.3 Hidden Links Injection Exploit and How To Not Let It Happen To You

March 21, 2008


A friend yesterday running the latest version of had some links injected in his . I know he is very technical and knows what he is doing so started making me a little paranoid. I started search for 2.3.3 links and as you can see there is a ton of people claiming to be running the latest and greatest version yet getting links inserted in there posts. People are also inserting iframes. Its actually pretty effective if you think about it… How would you notice links in old posts?

First I want to say I have never seen any evidence of a fresh 2.3.3 install of .

The most likely comes from either a previous exploitable file still existing in your install directory or from someone who has already hijacked your admin . You see there were some wicked exploits in earlier versions that allowed people to your admin which authenticates you (keep me logged in).

So what to do…. well if you have 2.3.3 and you are getting owned regularly here is what you need to do.

1) Make a new fresh install of and copy over your must have files… like themes, plugins (MAKE SURE THEY ARE UP TO DATE) , images, wp-config.php

2) change your password right away. In case someone has a old hash of your password.

If you have been following the proper upgrade instructions (minus changing the admin pass) on the you should have been doing this the whole time… ya I know I was not either.

If you are a nerd like me you might want to use which is super dope and is a better and easier way to keep up to date if you know how to use . Here are the instructions for that

Anyway security wise out of the box most web servers are not going to help you find out the root of the . Most of these are requests and unless you are specifically logging them of have mod_security installed …. there is no log anywhere of any request to your web other then one happened.

Thanks to donncha ocaoimh for answering my ;)

this helps anyone who is having there 2.3.3 getting owned.

Source

LittleBigPlanet Finishing Up Alpha Phase

March 20, 2008

drbsexvdzs.jpg
According to a recent on , the highly anticipated will be finishing up the phase of testing soon.

“We’ve been slaving away pushing toward the stage of its cycle. Basically, this means all the cool stuff we said will be in there should be playable, even if it isn’t pretty enough to release. The seems to change every day at the moment and it is very exciting to be able to sit down and play what feels more and more like a complete .”

is a PS3 based which encourages players to create their own levels and objects and to then share this fully customizable environment with friends. It is expected to be released sometime September.

here

Bottom