Site menu:

 

FV Overview

Regions

San Francisco
North Bay
East Bay
South Bay

Topics


On this date at Frisco Vista

Search Posts:

Navigate Site

Subscribe

rss feed button

Recent Posts

Most posts appear early weekday mornings.

Hacked

This blog was hacked into, briefly, yesterday morning; little harm was done.

It’s important to plug vulnerabilities, which can exist in themes or plugins, older versions of Wordpress, or improper configurations. My mistake may have been in being careless about updating my application and plugins.

Another possible vulnerability was the Democracy plugin. It enables you to host polls via WordPress. But because it in effect gives users a degree of writing permission it opens a little gate that might be exploited. It’s cool, but I never used it much, and I’ve deactivated Democracy on all my blogs. If I need to run a poll I’ll just host it offsite, like B in the D. I also followed Matt Cutt’s advice and created a blank index file for the plugins directory so as not to leak information about the plugins that are active.

Here are some helpful links:

I might not have this absolutely clamped down yet, but it’s certainly tighter than it was.

Comments

Pingback from BlogSecurity » Blog Archive » Frisco Vista blog hacked
Time: January 24, 2008, 12:14 am

[...] Vista’s WordPress blog ran into some security problems. His experience can be read here.     Enjoy the article? Please take a second to: Digg it! | StumbleUpon it! [...]