• I’ve been running a small personal blog site for the better part of 10 years, and have never had any security-related problems. Last year I converted over to WordPress, currently updated to 2.0.4. Today when I pulled up my site, I saw this page:

    http://steveperkins.net/index-old.php

    I immediately figured this was because I got lazy and left my theme files writable, so I could edit from from the admin interface (that feature should just be removed, it’s asking for trouble!). I restored the “index.php” from backup to my theme directory, and set everything there to read-only again.

    However, I did some further poking around and found that the “index.php” files had been overwritten for the themes that I was not using… even though those files were NOT set with writable permissions! I’m not sure how that happened. Are there any known issues with 2.0.4 that could be exploited to overwrite theme files?

Viewing 3 replies - 1 through 3 (of 3 total)
  • It would be really good if you can figure out what they’ve done. Do you have your apache logs? It should reveal some details.

    Also, it might not have been wordpress that they got in through. It could have been an insecure plugin, or some other add on, or perhaps it was some other way entirely. I’d really like to know. If I was you, I would not consider my site secure at all until I determined what happened, and was sure there are no ‘droppings’ left behind by your hacker friend.

    I’m sorry but what are we supposed to see with Index-old?

    Does anyone have a screen shot?

    I guess he’s changed it. It had the usual hacked by blah blah crap on it. Still doesn’t provide any info on what happened by itself.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Security hole with 2.0.4?’ is closed to new replies.