The Register® — Biting the hand that feeds IT

Comments on: Fake site punts Trojanised WordPress

automatic updating ... at last 

Posted Thursday 6th November 2008 18:53 GMT

Thumb Up

> Also in the upcoming 2.7 release of WordPress we are including a built-in upgrade mechanism within WordPress which will allow people to upgrade automatically with ease.

At last! This has been one of the remaining few pains of using Wordpress.

It's only bloggers 

Posted Friday 7th November 2008 05:22 GMT

Thumb Down

Move along, there's nothing to see here....

Automatic Updating... erm, you can do it now... 

Posted Friday 7th November 2008 07:50 GMT

Download this plugin : http://techie-buzz.com/wordpress-plugins/wordpress-automatic-upgrade-12-release.html

When an update is available it lets you know, a few clicks and it does it all for you. Very nice plugin, I believe it's this one that's being used in 2.7

In that case 

Posted Friday 7th November 2008 09:29 GMT

Linux

Doesn't The Register use WordPress? So should I stop reading The Register online? Na, joking.

Bots and Hacks Still expoitable 

Posted Friday 7th November 2008 19:11 GMT

Thumb Up

More on Wordpress 2.6.2 and 2.6.3 exploits.

Malicious damage can be caused by exploits from JadenAveBot used by PSI; hosted by Cogentco. The trick is writing exclusions in the robot.txt

****User-agent: Bad bot

Disallow: / cgi-bin /

Disallow: / images /

Disallow: / tmp /

Disallow: / private /

Disallow: /wp-content /

Disallow: /wp-admin /

User-agent: Snapbot

Disallow: / cgi-bin /

Disallow: / images /

Disallow: / tmp /

Disallow: / private /

Disallow: /wp-content /

Disallow: /wp-admin /

User-agent: ShopWiki

Disallow: / cgi-bin /

Disallow: / images /

Disallow: / tmp /

Disallow: / private /

Disallow: /wp-content /

Disallow: /wp-admin /

User-agent: Voyager

Disallow: / cgi-bin /

Disallow: / images /

Disallow: / tmp /

Disallow: / private /

Disallow: /wp-content /

Disallow: /wp-admin /

User-agent:JadynAveBot

Disallow: / cgi-bin /

Disallow: / images /

Disallow: / tmp /

Disallow: / private /

Disallow: /wp-content /

Disallow: /wp-admin /****

another trick is to excluded websites using PHP Script and htaccess files to work together to ban sites and user defined ranges to limit access to wordpress sites.

Webcast: Jumpstart your Application Security initiatives