Warning: Wordpress Spam/Crack Exploit (version 2.2.1).

Like I said in my last post, I haven’t been blogging for 2.5 months. When I brought up my blog today in Safari, I noticed a link to one of those really unseemly internet gambling sites (as opposed to the more above board ones that don’t have an “I’m scamming you” aura). I didn’t put this link in place, so obviously I was more than a bit concerned. Someone had to have done it, so I went in and looked at my registered user list. Using google to check the email addresses, every one of them checked out, except for one: johnsmithuswe@gmail.com. When I googled it, I found this and this. Ominous.

Long story short, this is some sort of bot that will either delete or modify your blog in adverse ways. Be sure and check for it under the email addresses listed in the articles (especially if you’re getting a lot of extra spam comments or otherwise strange things are happening) and blast it out if it’s there. WP 2.2.2 is a security update, so I’m guessing (hoping) it closes whatever holes allowed this behavior.

I’m just glad my blog didn’t get taken over by porn peddlers. I spend a lot of time trying to get my family to read this thing, and now the signature for most of my email messages contains a link here. Including email I send to my former professors. Eek.

[tags]wordpress, security, exploit, bot, spam, hack, crack, security update, update[/tags]

2 Responses to “Warning: Wordpress Spam/Crack Exploit (version 2.2.1).”


  1. 1 Leighton

    I am happy to see that at least one of my blog posts has helped someone :)

  2. 2 endymion84

    Indeed it did. It was one of the top five results on Google when I searched for the email address above. I was quite glad to find it, as I was starting to get a bit wigged out at the thought that I’d have to reinstall my entire WP setup or something equally drastic.

    Thanks for registering! I hope you find other things on here interesting. :)

Leave a Reply

You must login to post a comment.




Close
E-mail It