-
Website
http://blog.cre8asite.net/bwelford/ -
Original page
http://blog.cre8asite.net/bwelford/2008/02/wordpress-blog-hacked/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
AndyBeard
1 comment · 4 points
-
Mountain View SEO
2 comments · 1 points
-
BrianChappell
1 comment · 1 points
-
affordable seo
1 comment · 1 points
-
Tamar Weinberg
1 comment · 5 points
-
-
Popular Threads
Best regards from Spain
Thanks
Much of what I have learned about this was through other blogs and forums dealing with PHP security - the backup advice is still one of the most important though - being lazy can be very costly.
I believe the most major flaw was a recent version which had a XSS cross site scripting hole.
Lesson learned? Update as soon as updates arrive!
Peter
BTW a really informative site that I have now bookmarked !! Lots of good stuff in here no doubt !!
Since, there appears to be no testing body or accredited body which must certify or at least look at a plugin, is it not far more likely that a would be hacker would use a plugin to do something subtle but virus like, as that is an obvious potential hole?
If there are thousands of programming hands reviewing wordpress standard code, but almost no one reviewing plugins which are in fact php code that could be malicious, why would we not all put more concentration/discussion on this area?
I use 4-5 plugins and prior to this discussion never suspected that perhaps they could be problematic. But now, I will check google to see if anyone else is complaining about any of them.
Greetings from Nederland
matt