Yesterday I learned that a worm has been attacking a number of WordPress blogs. If your blog hasn’t been attacked yet the easiest way to prevent an attack is to update your WordPress installation to the latest version – 2.84.
The worm seems to be attacking older installations, infecting posts with spam and malware that gets downloaded when readers visit them.
The WordPress Blog states that this worm does not affect the current version of the blog publishing software, which is 2.8.4, but the company is strongly recommending that users running older versions upgrade immediately.
The worm registers a user and leverages a security flaw in older versions to execute code through the permalink structure. It them makes itself an administrator and uses JavaScript to hide itself when blog readers visit a page. Meanwhile it has inserted spam and malware into older posts.
The worm fails to properly clean up after itself once it has infected a page, according to WordPress, and users may notice that their links are broken – a telltale sign that the worm has visited.
Four things you should do to protect your blog and it’s data from hackers and worms:
- WordPress is pretty good about watching out for security holes and making patches for them – hence the regular updates to their blogging software. For this reason, it’s wise to update your WordPress installation shortly after a new version comes out.
- It’s also wise to make sure that all of your plugins are up to date as well as they can have security holes as well.
- Another way to protect your blog is to not use the standard “admin” login. Create your own unique Admin login and change your password regularly. keep in mind that creating a complicated password with both capital and small letters as well as numbers will be harder to hack.
- Another safe practice is to backup your blog regularly. Backing up your blog is really quite easy to do, even if you’re a novice WordPress user. Just install the WordPress Database Backup plugin and you’ll be able to back up your blogs files and tables anytime you want and you can even schedule hourly, twice daily, daily or once weekly backups. Scheduled backups are e-mailed to you so you always have a fairly current copy of your sites files on your computer.
My husband and I have seventeen blogs between us, so I spent several hours yesterday updating plugins and updating the blogs to version 2.84. At least updating is really easy now with WordPress’ one click update. There’s no excuse not to update now – even if you do have a lot of blogs like my husband and I! Luckily our blogs weren’t too far behind and as far as I can tell haven’t been hit by this malicious worm.
