Tag: security

  • New Company Releases Evil WordPress Plugin

    New Company Releases Evil WordPress Plugin

    Earlier today on Twitter, WordPress community member Travis Ballard @Ansimation published a link to a plugin that will have people thinking twice before they sign up to a WordPress based website. Ironically, it’s called WPEvil and saves passwords into plain text instead of hashes. One thing I’ve learned over the years is that passwords are…

  • Automattic Acquires CodeGarage

    Automattic Acquires CodeGarage

    Automattic or more aptly VaultPress, has acquired security company, CodeGarage. This is the first time I’ve ever heard about CodeGarage but they appear to be a VaultPress alternative. Looking over the pricing and plans for each service, I see that CodeGarage was definitely cheaper as you can monitor 5 websites for $25 a month while…

  • Security Hole In W3 Total Cache

    Security Hole In W3 Total Cache

    Over the past few days, I’ve read various posts regarding a security hole discovered in the popular W3 Total Cache plugin. According to a security bulletin published by Jason Donenfeld on Seclist.org, after installing the plugin from the WordPress plugin repository through the backend of WordPress, there are two avenues of attack left open. 1)…

  • Critical Update For WooThemes Customers

    Critical Update For WooThemes Customers

    As if WooThemes.com being attacked was not bad enough, there is also a critical security issue that’s been fixed in the latest release of the WooFramework. The issue dealt with the shortcode generator. The latest version (and most likely many previous versions) of the WooThemes WooFramework has a bug that allows any website visitor to…

  • Free Webinar On Locking Down WordPress

    Free Webinar On Locking Down WordPress

    As part of their Make Waves series, iThemes will be conducting a free webinar with Dre Armeda of Sucuri.net to discuss how to lock down a WordPress installation. In this webinar, viewers will learn how to reduce their risk of being attacked by hackers and malware threats. The webinar takes placed on Wednesday, April 25th…

  • VaultPress – Not An Option For Non-Profit MultiSite Installations?

    VaultPress – Not An Option For Non-Profit MultiSite Installations?

    VaultPress is a cool security service by Automattic, but if you take a look at the pricing and plans, some may think that this is the luxury line of data safekeeping. However, tons of people that have had to utilize the restoration feature of VaultPress say it’s worth every penny. Boles University.com has a non-profit…

  • BuddyPress 1.5.5 Released

    BuddyPress 1.5.5 Released

    It was announced earlier today that that BuddyPress 1.5.5 is now available for download. This is considered a maintenance release which addresses 14 issues, some of which are security related. Congrats to the team and I hope you had a blast at WordCamp Netherlands Paul Gibbs.

  • WP Plugin Authors The Target Of A Phishing Scam

    WP Plugin Authors The Target Of A Phishing Scam

    Plugin authors need to take serious notice of a recent phishing attack that is aimed specifically at plugin authors. Ipstenu, one of the volunteer WordPress.org support forum moderators has published a forum thread warning others that responding to the email wouldn’t be a good idea. The way in which this phishing attack works is pretty…

  • WordPress Not The Direct Cause Of Mass Site Attacks

    WordPress Not The Direct Cause Of Mass Site Attacks

    Sucuri has published more information regarding the compromising of at least 30,000 domains. Based on their research, they are ruling out the possibility that the attacks are taking advantage of a new vulnerability within the core of WordPress. The first question is how are these sites getting hacked? On all the cases we analyzed, they…

  • Sucuri Answers Your Malware Questions

    Sucuri Answers Your Malware Questions

    In what I think is a great service to anyone who operates a website, the security service Sucuri has started to publish articles containing answers to user submitted questions. In their latest installment, they answer some general questions such as why anyone would want to hack your site, what they gain by attacking a website,…

  • Absolute Privacy Plugin Back In The Repository

    Absolute Privacy Plugin Back In The Repository

    A few days ago, Sucuri mentioned that the Absolute Privacy plugin for WordPress contained a security vulnerability that would allow the ability to bypass the authentication mechanism and gain admin access to the application, that being WordPress. The plugin was subsequently pulled from the repository as there had not been any updates to fix the…

  • DreamHost Resets All FTP/Shell/VPS Account Passwords

    DreamHost Resets All FTP/Shell/VPS Account Passwords

    Knowing that a lot of people use DreamHost for their WordPress powered websites, it’s a bit unsettling to see that suspicious activity was detected within one of their databases and thus, passwords have been reset across FTP/Shell and VPS customer accounts. If you use DreamHost and have not been able to log-in recently, this may…

  • WordPress 3.3.1 Fixes Security Exploit

    WordPress 3.3.1 Fixes Security Exploit

    WordPress 3.3.1 was released last night and it addresses an important security issue discovered in WordPress 3.3. Along with the security fix, the release also fixes 15 issues that are outlined here. After I upgraded the Tavern website, I was a bit confused to see a number of things that were listed under the What’s…

  • Is Your WordPress Install Selling Handbags?

    Is Your WordPress Install Selling Handbags?

    If you administer a WordPress powered website, you might want to check the directory structure, especially the WP-Content/Upgrade and WP-Content/Uploads to see if you notice a folder called Tall. According to the folks at WPMU.org, one of their co-workers websites became a victim to an attack that involved an entirely new WordPress installation being installed…

  • Dre Armeda On WordPress End-User Security

    Dre Armeda On WordPress End-User Security

    From WordCamp Chicago 2011, Dre Armeda who is one of the guys behind the awesome security service/site Securi. His presentation contains a ton of information that all end users should take note of.