store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue Jun 18, 2013 12:46 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 
Author Message
 Post subject: Wordpress sites under attack
Unread postPosted: Sat Sep 05, 2009 5:11 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Aug 05, 2008 5:01 pm
Posts: 111
Can you make a rule to prevent this kind off attack?

Otto42 of OttoDestruct, a key WordPress developer and supporter, reports that there is an “attack” on older versions of WordPress right now. The number of sites hit by this is growing every hour. Protect your WordPress blog now: UPDATE NOW!!!

Update your WordPress blog before you continue reading this post. That’s how critical this issue is.


Here is the link to this issue:

http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/


Top
 Profile  
 
 Post subject: Re: Wordpress sites under attack
Unread postPosted: Sat Sep 05, 2009 5:52 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3263
Location: Chantilly, VA
We'll look into it right away.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Wordpress sites under attack
Unread postPosted: Sat Sep 05, 2009 6:12 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3263
Location: Chantilly, VA
You may already be protected from this, we put put a JITP some time ago for the wordpress priv escalation and admin reset attacks (http://www.darknet.org.uk/2009/08/wordp ... t-exploit/). Of course, details are hard to come by for what this attack is so we will continue to research it.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Wordpress sites under attack
Unread postPosted: Sat Sep 05, 2009 6:45 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3263
Location: Chantilly, VA
Yep, this looks like the priv escalation attack we already put out a JITP for several weeks ago. In fact, I now have the attack payload and we will put out some other sigs to catch the post exploit worm for folks that may be way behind the curve.

In short, if you are running ASL you are already protected from this and have been for weeks. :-)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Wordpress sites under attack
Unread postPosted: Sun Sep 06, 2009 11:44 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 715
Location: Sweden
God I love ASL!


Top
 Profile  
 
 Post subject: Re: Wordpress sites under attack
Unread postPosted: Mon Sep 07, 2009 3:18 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jan 15, 2008 3:57 am
Posts: 478
Location: Netherlands
Thx Mike! :)

_________________
best regards,

http://hosting.ber-art.nl
Professional Secure Linux Plesk Hosting


Top
 Profile  
 
 Post subject: Re: Wordpress sites under attack
Unread postPosted: Mon Sep 07, 2009 10:05 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3263
Location: Chantilly, VA
Our pleasure. And as always, just let us know what you need!

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group