All the latest UK technology news, reviews and analysis

WordPress warns of smart worm attack on blogs

by Iain Thomson

06 Sep 2009

Be the first to comment

  • Tweet this
WordPress
The current WordPress 2.8.4 is immune to the worm

Blogging software firm WordPress has warned of a worm spreading among users by exploiting an old security vulnerability.

The company said that the worm has been identified only because of flaws in its design.

"This particular worm, like many before it, is clever: it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at the user's page," warned the company in a blog post.

"It then attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts."

However, the worm's design means that it breaks links on a user's page, alerting them to the fact that something is wrong.

The current WordPress 2.8.4 is immune to the worm, and users are being urged to upgrade as soon as possible.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Procurement/P2P Transformation Consultant

Premier Consulting Firm - Procurement/P2P Transformation...

IT Strategy and Transformation Professional

Premier consulting firm - IT Strategy and Cloud Consulting...

C# Developer- Shropshire, West Midlands

Software developer/ C# developer, (ASP.NET, C#, MVC...

Oracle Developer/ Programmer- Forms, Reports, PL-SQL

Oracle Developer/ Programmer- Oracle ebusiness suite...

To send to more than one email address, simply separate each address with a comma.