WP Exploit

OK, I did warn everyone that I was closing registration and though I was going to try not to delete the entire user list, I might have to do that. Well, I am going to have to do it and will be doing so later this evening. Someone, most likely someone who has a registered account at Just Orb, has been adding malicious code to my posts. Only three in the last year, but thankfully one of the posts was on the front page today, and Ekim noticed and informed me. Thank you, Ekim!

Apparently there is some exploit in Wordpress that allows this to happen, and even upgrading to the newest version doesn’t fix it. As much as I am loath to stop using Wordpress, it looks like I will be investigating other blogging software. Unless you are a blogger, you cannot know how much it sucks to have to change software. It really, really sucks. Trust me.

No matter what comes next, there is likely to be a big mess around Just Orb for a while, and I do apologize for having to delete my user list. As it is now, I don’t believe I will be opening registration up again, as it seems like that will either lead to some asshole signing up and doing crappy stuff to my site again, or we would all have to jump through hoops in order for me to only let people sign up that I want to sign up. I don’t know what I am going to do about that yet. We’ll see, I guess.

I just thought I would give everyone a heads up that there’s going to be some turmoil at Just Orb, that there’s been a hacking incident, and that I am trying to stay on top of things. I really don’t have time to deal with all this, but I suppose I will find the time, won’t I? This is not what I needed to have happen on a day that was going rather well … aside from the morning aphids and ants issue.

Anyway, if you use Wordpress, you might want to search your posts from within Dashboard for “noscript” and “iframe” and wp-stats.php” in case someone has done it to your site as well. After I have found some good links talking about this issue, I will post them. Right now though, I need to go have some cookies and milk and play with my cats.

Spacer Bar

2 Responses to “WP Exploit”

  1. on 10 Jul 2008 at 5:17 pm Piper

    I can’t say I won’t miss the occasional secret post but I can certainly understand your reasons.

  2. on 10 Jul 2008 at 5:22 pm Orb

    Well, you’re over at LJ, so you’ll still get the inside scoop when there is one.