Prevent WordPress Hacking

Sha June 27, 2007 15

If you’ve not upgrade to WordPress v2.2.1, please do so immediately.

There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked.

The hackers search for blogs with v2.2 keyword string and did their worse.

You have two options to upgrade

Option #1

disable-registration.jpg

Disable the guest account under ‘Dashboard > Options > General > Membership > Untick Anyone can register’

This will temporarily hold out on the necessary full upgrade at the moment


Option #2

  • Important to upgrade fully. Download v2.2.1
  • v2.2.1 upgrade doesn’t change the database, it’s more of the core files (40 plus of it) that need changing
  • With How to Spoter guide, I upgraded the core files. Here’s my compilation of v2.2.1 WordPress files (781KB, 46 files, 3 folders) that need to be changed. I used and upgraded my WordPress with no problems. Hope it helps
  • Disclaimer: I take no responsibility of any upgrade screw-ups, make sure you made backups plus deactivate your plugins before the upgrade. Although I didn’t deactivate for my upgrade, yours might need it, just in case

15 Comments »

  1. Tommy Chieng June 27, 2007 at 10:25 am - Reply

    I think the best way is to upgrade because it fixes the security bugs.

    • Uncle Sha June 29, 2007 at 10:03 pm - Reply

      yeah my exact sentiments

  2. yanni June 27, 2007 at 12:26 pm - Reply

    im waiting for my fantastico to update on the version 2.2.1, lembab seh.. dulu selalu cepat, and with just one click, my wp version is automatically upgrade.

    now… i have waited for like months…..

    • Uncle Sha June 29, 2007 at 10:04 pm - Reply

      err i dun think they will, keke

      you tunggu la … :-p

  3. marina June 27, 2007 at 2:49 pm - Reply

    Oh my goodness. I didnt know that! I just upgraded to 2.2 via fantastico a couple of days ago. Needed to fix the banner and stat codes and what-nots.

    Thanks for the post Sha, if not, I wouldnt be aware of this.

  4. katak June 27, 2007 at 2:58 pm - Reply

    This is serious shit man… damn those people who crack up the codes..

    • Uncle Sha June 29, 2007 at 10:10 pm - Reply

      yeah! nothing better to do

  5. Faddy June 27, 2007 at 4:28 pm - Reply

    holy macaroni! i lagi tak pernah update… hahah. die, something new to learn hahahaa.

    • Uncle Sha June 29, 2007 at 10:11 pm - Reply

      make backups before upgrade ok!

  6. fil June 27, 2007 at 4:59 pm - Reply

    a ah.. uncle sha.. amacam nak upgrade ni?!?!

    • katak June 27, 2007 at 5:42 pm - Reply

      Hi,

      I think if you have some form of panel administration of your site, you can choose via Fantastico scripts upgrade or ask your service provider to upgrade it for you :-)

    • Uncle Sha June 29, 2007 at 10:14 pm - Reply

      yes as katak said, via fantistico or by ftp (more harder, i did this as i dun trust auto upgrade)

  7. dee June 28, 2007 at 8:17 am - Reply

    Uncle sha, u’re going to ketawa at me like orang giler man.. I don’t have mozilla and I’m only on safari. THATS why I cant post entries=(
    SO SAD=(

    • Uncle Sha June 29, 2007 at 10:16 pm - Reply

      ler you staying at kampung eh?

Leave A Response »

*

Comment moderation is enabled. Your comment may take some time to appear.