Hello all, we’ve been hacked…
This morning I woke up to check my email and then the status of my multiple blogs. Right away I saw an email telling me that the recent San Diego photowalk announcement had been modified. Well, this can’t be…since I am the only one who can publish and modify posts after they are published. I immediately knew something was wrong.
So, I shot over to my administration panel for this blog. WHAT! The title had been changed! I quickly loaded the site in another tab and freaked out. I saw a blog post saying that I had been hacked and it included some really lame graphics claiming the hacking victory.
With some super-sleuthing I found the details of the intrusion and quickly began the repair process. I notified a couple of blogging friends, Raoul and Brian, and they provided some sound wisdom to help me complete the repair, and fix the broken part of my security.
I discovered that the failure was in my using the simple plugin that allowed us to have a basic forum, right here on the blog. If you’ve used the forum, then you know that it’s not full featured, but useful. So, I’ve disabled and deleted the plugin and the software. This deletion also included the entire forum. Sorry.
However, I went ahead and installed the very sound and secure phpBB forum software. Much like Wordpress, it rocks! There’s nothing there, and it looks like a basic install, but it’s there. Feel free to head over there, register, and post a topic for discussion.
Comments
Comment from trevorcarpenter
Time: January 29, 2008, 1:05 pm
Thanks Wolfy!
Comment from Tim
Time: January 29, 2008, 3:17 pm
You should subscribe to BlogSecurity. I’m pretty sure that is the exploit they posted about on the 22nd:
http://blogsecurity.net/wordpress/wp-forum-174-sql-injection/
Wolfman – They use a Google search for the plugin name and version that is exploitable. So if your site isn’t popular that doesn’t mean they won’t come knocking.
Comment from trevorcarpenter
Time: January 29, 2008, 3:36 pm
Thanks Tim. Ashamedly, I may have read that somewhere else, and not done anything. Security warnings are only as good as your response to the information.
Lesson learned.
Applying the lesson, I have upgraded every pending plugin upgrade, on all my blogs.
Comment from Wolfman-K
Time: January 29, 2008, 1:04 pm
Wow, I think you need to look at this as a compliment. Hackers don’t bother unless a site is popular enough that their work will be noticed.
Good work on the cleanup tho.