Feeds

Worm wiggles through weary WordPress

Spam-friendly malware spanks Scoble blog

5 things you didn’t know about cloud backup

Hackers are exploiting older installations of WordPress to distribute blog comment spam and disguise links to malware-contaminated sites.

The worm-based attack targets an older version of the popular blog publishing software. Although the worm attempts to hide its tracks, coding errors mean that links on a blog wind up getting broken following an attack, thus revealing something is wrong, as explained in a blog post by Wordpress here.

This particular worm, like many before it, is clever: it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts.

The tactics are new, but the strategy is not. Where this particular worm messes up is in the "clean up" phase: it doesn’t hide itself well and the blogger notices that all his links are broken, which causes him to dig deeper and notice the extent of the damage.

Bloggers are advised to update their software to the latest 2.8.4 version of WordPress. Applying an update might be a chore but it's far easier than fixing a hacked blog, as WordPress points out.

Among those hit by the latest attack was tech blogger Robert Scoble, who lost two months of blog entries as a result. Scoble was hit by a similar attack a couple of months ago, and is now considering a switch to different blogging software.

The Guardian notes that attacks against WordPress are getting more frequent, wondering aloud if security concerns might one day prompt users to move away from the open source PHP application, whose widespread use makes it a tempting target for hacking attacks. ®

Next gen security for virtualised datacentres

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.