Most Popular Stories
Events
- Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - CIO Healthcare Summit
March 11-14 — Scottsdale, AZ
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Enterprise Portals: Harnessing Portal Power
- Whitepaper: Mobile Device Management Buyer's Guide: An Insider's View of the Market
- The Data Center in Your Future
- The Shortcut Guide to Secure, Managed File Transfer
- Results of a Survey on DevOpsTrends
New worm attacks unpatched WordPress blogs
A new worm targeting WordPress blogs is currently on the move, according to reports. This new worm affects self-hosted WordPress blogs using a vulnerability that was detected in August; so users who have updated to the current version of WordPress 2.8.4 will not be affected.
What is of particular concern here is its evasiveness and difficulty to remove. According to a blog post by Matt Mullenweg, founding developer of WordPress, "This particular worm...is clever." He elaborated on how the worm registers a user, then leverages on the aforementioned security bug to allow evaluated code to be executed and make itself an admin.
It doesn't end there, though: The worm makes proactive use of JavaScript in order to stay invisible on the WordPress user page, and goes "quiet"--even while it inserts hidden spam and malware into old posts.
For more on this story:
- check out this article at CNET News
Related Stories
- Unidentified hackers infiltrate WordPress plugins with 'cleverly disguised' backdoors
- Wordpress.com bit by 'extremely large' DDoS attack
- Microsoft release security advisory about remote DLL flaw
- WordPress 3.0 blogging software has been released
- Serious flaw discovered in Microsoft IIS
- Vista exploits for sale
- Wikipedia used to distribute malicious code
- Spam on the rise, botnets to blame
- Juniper crams security into appliances
- IBM researchers take AXE to computer security
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




