DrupalSecuritySpam

Wordpress blog hack rampage

I received an abnormal high number of signals and messages from people abandoning their Wordpress blogs,

because of their hacks, just like Fridaynite did .

It appears to me that simply because there are so many vulnerable Wordpress installations out there, it became a promising goal

to hack Wordpress installs and

  • inject some HTML code (for links)
  • inject WHOLE POSTS into the wordpress archives (backdated)
  • put in some cookie-stuffing code in to overwrite affiliate links’ credits

I’m very sure there are some blackhat tools out there to auto-search and auto-hack wordpress blogs… and if it’s not ready, it’s in the making… there’s gold to be made with this (illegal) tactic and Google is already aware of that, as Matt Cutts (Google’s “insider”) stated that

Matt Cutts wrote:

2008 will be the year that hacking and search engine optimization (SEO) collide in a major way.

well, since I heard that Wordpress DOES NOT have a dedicated security team (like Drupal does, who “pester” me almost daily with their updates) I’m very happy having made the strategic decicision for Drupal back in 2005 …

Anyway, what’s left to do is check thru all your wordpress installations on a regular basis and decide to

Which route will you take?

Average rating
(1 vote)

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Similar entries