• I was reading a nice review/comparison between WP and Blogger this morning on Lockergnome, and the author’s site (http://peterbarbosa.com/ – linked in the article) has apparently been hacked.

    From what I can tell, he’s using the latest WP (version 1.5), although I know nothing of his underlying configuration.

    Is there a known security problem here?

    Doesn’t look good to someone like me who is looking for new weblog software 🙁

Viewing 15 replies - 1 through 15 (of 18 total)
  • Moderator James Huff

    (@macmanx)

    Volunteer Moderator

    There are no known security issues with v1.5.

    *And* until we know it was not just a case of some jerk figuring out the password to his account…

    pezastic

    (@pezastic)

    Let’s hope that’s the case. I just saw that Blog CMS was hacked.

    Kafkaesqui

    (@kafkaesqui)

    This was not a case of WordPress security (not directly, that is):

    http://peterbarbosa.com/archives/2557/server-hacked/

    davestinner

    (@davestinner)

    “The hacker got into WordPress by accessing a admin account.. I accidently left a WP admin account open.. please do not do this at home.”

    jonimueller

    (@jonimueller)

    What does that mean, “I left a WP admin account open”? Does he mean he had the WP console up on the screen and then wandered away from the computer?

    Moderator James Huff

    (@macmanx)

    Volunteer Moderator

    Exactly.

    vkaryl

    (@vkaryl)

    Well, then, unless “he” works in a corp environment the size of MS/Redmond, he ought to by goddess KNOW who hacked him, right? Or at least the 2 or 3 most likely snarkers.

    Kafkaesqui

    (@kafkaesqui)

    If you followed the link I placed above, you’d read this:

    “…just to let the hacker I know, I have the IP address, and I will be contacting the ISP for the damage they have done.”

    So it’s unlikely the culprit wandered by Peter’s desk during lunch.

    dawg

    (@dawg)

    just kinda curious why is this late February stuff rearing it’s ugly head today?

    vkaryl

    (@vkaryl)

    Tried, kafka, but timed out….

    Kafkaesqui

    (@kafkaesqui)

    dawg: Scroll up to pezastic’s note about BlogCMS. I imagine after hearing that, he went a-searchin’ and stumbled over this thread.

    dawg

    (@dawg)

    Yeah I did go back and see who brought it up! Thanks

    pezastic

    (@pezastic)

    You got it. After reading about BlogCMS, I wondered if WP had any problems of its own. I can see now that it’s A-OK!

    jinsan

    (@jinsan)

    with regards to BlogCMS it was punBB that was hacked rather than BlogCMS itself. Personally I think BlogCMS is a piece of crap, but it looks moderately good out of the box, it’s when you start playing with it reality dawns quickly. punBB was updated and the problem was resolved.

Viewing 15 replies - 1 through 15 (of 18 total)
  • The topic ‘WordPress site hacked’ is closed to new replies.