Segera Upgrade WordPress Anda
Saya menerima kiriman email dari hosting tempat blog ini ditempatkan yang kira-kira berbunyi begini:
The following is a notice for those clients who use WordPress on their accounts. Normally we post vulnerability notices in our blog; however, we are aware that a large number of our clients use WordPress.
If you’re running a WordPress blog that isn’t up-to-date (older than version 2.8.4), you’re advised to upgrade immediately to the latest version of the software to avoid an ongoing attack.
The warning comes from Lorelle on WordPress after it was discovered that a nasty attack is exploiting security holes in previous versions of the blogging software, creating a new “hidden” Administrator account and getting right down to the database level. These attacks are said to be “growing by the hour”. Lorelle writes:
There are two clues that your WordPress site has been attacked.
There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFER ER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”
The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account.
All users are advised to upgrade to the latest version of WordPress immediately. If you’re installing a WordPress from fantastico please update immediately from fantastico in your cpanel account.
Saya yang awalnya paling malas mengupgrade wordpress karena begitu seringnya berganti versi akhirnya terpengaruh juga. Eh..ternyat mengupgrade wordpress ke versi 2.8.4 relatif lebih mudah dibanding versi-versi sebelumnya.
Jadi silahkan segera upgrade wordpress Anda ke versi terbaru jika tidak ingin sibuk membenahi blog Anda akibar dari ulah tangan-tangan jahil.
It is also easy to backup and transfer all your websites from one server to another server if you have cPanel installed-*”