Newsletter:

Skip Navigation LinksHome > News > Security > Exploit code implanted into blog software

Exploit code implanted into blog software

By Shaun Nichols
6 March 2007 08:22AM
Tags: exploit | code | implanted | blog | software

Attackers break into server and inject malware into software update.

Attackers have injected exploit code into the downloadable software for the WordPress blogging service.

The company has issued an update that repairs the vulnerability.

The open source Wordpress software allows users to set up and push out postings to a blog. Although online bloggin services such as Blogger.com, Typepad or Wordpress.com allow users to publish blog postings directly from a browser windows, client software offers users more flexibility.

Hackers early last week broke into Wordpress' download server and embedded their attack code into the 2.1.1 update of the open source application. The malware opened up a backdoor on infected systems that would allow an attacker to execute code and install software.

WordPress founding developer Matthew Mullenweg on a company blog said that the infected software was offered to users for 3-4 days as an official WordPress download before the company was alerted of the breach.

"This is the kind of thing you pray never happens," said Mullenweg.

"But it did and now we’re dealing with it as best we can."

Security vendor Symantec claimed that it had notified fewer than 50 attacks exploiting the backdoor. The firm rated the threat as "low-level" beacuse of its limited reach and easy removal.

WordPress said that though not all downloads of version 2.1.1 were affected, the company is recommending that all users upgrade to version 2.1.2 of the software. WordPress also recommends that administrators hosting WordPress blogs prevent access to the "theme.php" and "feed.php" files that are infected by the attack.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 




Product Reviews

Star Rating
Blink is an endpoint security product that functions as a network protector.
Star Rating
EndPointSecurity installs a small footprint agent on the machine.
Star Rating
GuardianEdge Device Control is a component of the more robust GuardianEdge Data Protection Platform.
Star Rating
Lumension offers a pair of products, Sanctuary Application Control and Sanctuary Device Control, that work in...
Star Rating
First, it is important to note that unlike previous versions of ZENworks, Novell ZENworks Endpoint Security...
Product Reviews now available on iTnews.com.au

TopTopics
(2995) -  telstra
(2952) -  microsoft
(2052) -  network
(1892) -  broadband
(1728) -  apple
(1628) -  security
(1530) -  mobile
(1109) -  internet
(1106) -  data
(1084) -  blackberry
(1061) -  intel
(988) -  ibm
(943) -  researchers
(838) -  windows
(812) -  vmware