Tag: security

  • Free Webinar On Locking Down WordPress

    Free Webinar On Locking Down WordPress

    As part of their Make Waves series, iThemes will be conducting a free webinar with Dre Armeda of Sucuri.net to discuss how to lock down a WordPress installation. In this webinar, viewers will learn how to reduce their risk of being attacked by hackers and malware threats. The webinar takes placed on Wednesday, April 25th…

  • VaultPress – Not An Option For Non-Profit MultiSite Installations?

    VaultPress – Not An Option For Non-Profit MultiSite Installations?

    VaultPress is a cool security service by Automattic, but if you take a look at the pricing and plans, some may think that this is the luxury line of data safekeeping. However, tons of people that have had to utilize the restoration feature of VaultPress say it’s worth every penny. Boles University.com has a non-profit…

  • BuddyPress 1.5.5 Released

    BuddyPress 1.5.5 Released

    It was announced earlier today that that BuddyPress 1.5.5 is now available for download. This is considered a maintenance release which addresses 14 issues, some of which are security related. Congrats to the team and I hope you had a blast at WordCamp Netherlands Paul Gibbs.

  • WP Plugin Authors The Target Of A Phishing Scam

    WP Plugin Authors The Target Of A Phishing Scam

    Plugin authors need to take serious notice of a recent phishing attack that is aimed specifically at plugin authors. Ipstenu, one of the volunteer WordPress.org support forum moderators has published a forum thread warning others that responding to the email wouldn’t be a good idea. The way in which this phishing attack works is pretty…

  • WordPress Not The Direct Cause Of Mass Site Attacks

    WordPress Not The Direct Cause Of Mass Site Attacks

    Sucuri has published more information regarding the compromising of at least 30,000 domains. Based on their research, they are ruling out the possibility that the attacks are taking advantage of a new vulnerability within the core of WordPress. The first question is how are these sites getting hacked? On all the cases we analyzed, they…

  • Sucuri Answers Your Malware Questions

    Sucuri Answers Your Malware Questions

    In what I think is a great service to anyone who operates a website, the security service Sucuri has started to publish articles containing answers to user submitted questions. In their latest installment, they answer some general questions such as why anyone would want to hack your site, what they gain by attacking a website,…

  • Absolute Privacy Plugin Back In The Repository

    Absolute Privacy Plugin Back In The Repository

    A few days ago, Sucuri mentioned that the Absolute Privacy plugin for WordPress contained a security vulnerability that would allow the ability to bypass the authentication mechanism and gain admin access to the application, that being WordPress. The plugin was subsequently pulled from the repository as there had not been any updates to fix the…

  • DreamHost Resets All FTP/Shell/VPS Account Passwords

    DreamHost Resets All FTP/Shell/VPS Account Passwords

    Knowing that a lot of people use DreamHost for their WordPress powered websites, it’s a bit unsettling to see that suspicious activity was detected within one of their databases and thus, passwords have been reset across FTP/Shell and VPS customer accounts. If you use DreamHost and have not been able to log-in recently, this may…

  • WordPress 3.3.1 Fixes Security Exploit

    WordPress 3.3.1 Fixes Security Exploit

    WordPress 3.3.1 was released last night and it addresses an important security issue discovered in WordPress 3.3. Along with the security fix, the release also fixes 15 issues that are outlined here. After I upgraded the Tavern website, I was a bit confused to see a number of things that were listed under the What’s…

  • Is Your WordPress Install Selling Handbags?

    Is Your WordPress Install Selling Handbags?

    If you administer a WordPress powered website, you might want to check the directory structure, especially the WP-Content/Upgrade and WP-Content/Uploads to see if you notice a folder called Tall. According to the folks at WPMU.org, one of their co-workers websites became a victim to an attack that involved an entirely new WordPress installation being installed…

  • Dre Armeda On WordPress End-User Security

    Dre Armeda On WordPress End-User Security

    From WordCamp Chicago 2011, Dre Armeda who is one of the guys behind the awesome security service/site Securi. His presentation contains a ton of information that all end users should take note of.

  • Naughty Plugins Caught And Removed From Repository

    Naughty Plugins Caught And Removed From Repository

    Siobhan McKeown has published a disturbing yet not out of the ordinary article that explains how a couple of plugins were recently added to the plugin repository that were using a version of J-Query from J-Query.org which after investigation proved to be a fake website. The purported J-Query file was actually propagating sites with CPA…

  • VaultPress Now Supports WordPress Multisite

    VaultPress Now Supports WordPress Multisite

    VaultPress has announced that the latest edition of the plugin now supports WordPress Multisite. This has been a killer feature that owners of large multisite installs have been waiting for. VaultPress will automatically backup each site that is installed within the network. However, it must be noted that only the Network’s main site will have…

  • bbPress 2.0.1 Released – Fixes Anonymous Security Bug

    bbPress 2.0.1 Released – Fixes Anonymous Security Bug

    bbPress has released version 2.0.1 which is considered a maintenance release. However, if you have anonymous posting enabled, you’ll want to upgrade as soon as possible as this release addresses an issue where anonymous posters could potentially be able to edit topics and replies. If upgrading from 2.0, try upgrading through the dashboard as you…

  • The Aftermath Of The TimThumb Vulnerability

    The Aftermath Of The TimThumb Vulnerability

    Sucuri Security has a great post that begins to review the aftermath of the massive exploitation of the TimThumb image re sizer script. According to their calculations, about a million pages have been compromised by the script but when filtering down their results for the past thirty days, there were over 200,000 results. The exploitation…