<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Mashable - The Social Media Guide - Latest Comments in WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.disqus.com/</link><description>Internet and Technology News - Mashable is the world’s largest blog focused exclusively on Web 2.0 and Social Networking news. With more than 5 million monthly pageviews, Mashable is the most prolific blog reviewing new Web sites and services, publishing breaking news on what’s new on the web.</description><atom:link href="https://mashable.disqus.com/wordpress_responds_to_attack_8220please_upgrade8221/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 26 Oct 2009 02:06:02 -0000</lastBuildDate><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-21015419</link><description>&lt;p&gt;Obviously you don't live in the Real World and I'll give you an example with probably one of the most enterprisey plugins there is - HyperDB, which got updated last month from supporting "up to 2.6" to "up to 2.8" (yes, it's skipped 2.7), which happened a few months after 2.8 got released. HyperDB is a plugin developed and used at &lt;a href="http://WordPress.com" rel="nofollow noopener" target="_blank" title="WordPress.com"&gt;WordPress.com&lt;/a&gt; by Automattic folks themselves, so, if this is not a trustworthy plugin, then I'm really lost!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nikolay Kolev</dc:creator><pubDate>Mon, 26 Oct 2009 02:06:02 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-17774966</link><description>&lt;p&gt;Olá, apenas para testar esta maneira de comentario&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">rui</dc:creator><pubDate>Tue, 29 Sep 2009 11:04:01 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16900616</link><description>&lt;p&gt;Do I have to do anything at all?  All I wanted to do was go on Glenn Becks site and respond to a comment.  I don't have a word press site.  Actually I'm not familiar with any of this. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Name</dc:creator><pubDate>Fri, 18 Sep 2009 18:43:04 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16375999</link><description>&lt;p&gt;2.8.4a is the most recent version for WPMulti-User not regular WP. And no, I had no problem upgrading WPMU nor WP to latest versions. Just make sure you have regular backups of your databases. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mercime</dc:creator><pubDate>Thu, 10 Sep 2009 17:05:47 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16097241</link><description>&lt;p&gt;Yes you must upgrade because there is an exploit using a specially crafted URL which will hack into your Admin Account!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Free Wii Points</dc:creator><pubDate>Mon, 07 Sep 2009 11:36:42 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16091773</link><description>&lt;p&gt;You can do an export and re-import to a new installation&lt;br&gt;&lt;a href="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/" rel="nofollow noopener" target="_blank" title="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/"&gt;http://lorelle.wordpress.co...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">milkfish</dc:creator><pubDate>Mon, 07 Sep 2009 08:06:19 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16090620</link><description>&lt;p&gt;My goodness, that is a brilliant point................and Pinky says..."n...o..t".&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tatesjourney</dc:creator><pubDate>Mon, 07 Sep 2009 06:51:01 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16078279</link><description>&lt;p&gt;You've heard of it? It's only hosting like 70 accounts so I'd be surprised. But I know the owner and he always used Wordpress. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">resuni</dc:creator><pubDate>Sun, 06 Sep 2009 19:28:38 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16072166</link><description>&lt;p&gt;That is good to hear Matt, I do however like that you are very honest and you did say the truth, that's why I keep using Wordpress and of course, I don't think there any other blog software that's better. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">zedomax</dc:creator><pubDate>Sun, 06 Sep 2009 15:54:25 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16070986</link><description>&lt;p&gt;I was hacked and have upgraded.  Also went into SQL and found the culprit Admin and deleted them as well plus fixed my permalinks.  One thing I can't do however is delete this plugin &lt;a href="http://guff.szub.net/2005/01/27/add-link-attribute/" rel="nofollow noopener" target="_blank" title="http://guff.szub.net/2005/01/27/add-link-attribute/"&gt;http://guff.szub.net/2005/0...&lt;/a&gt; else it shuts down my whole blog.  My guess is that this plugin is the backdoor in for this hack.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tawnya Sutherland</dc:creator><pubDate>Sun, 06 Sep 2009 15:05:21 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16065193</link><description>&lt;p&gt;Is there any fix for those of us who were hacked with the old version???&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tawnya Sutherland</dc:creator><pubDate>Sun, 06 Sep 2009 13:27:29 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16064696</link><description>&lt;p&gt;Yes if money could buy security Windows (and OS X) would never have any security updates.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt Mullenweg</dc:creator><pubDate>Sun, 06 Sep 2009 13:09:28 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16064523</link><description>&lt;p&gt;I'm not sure who you contacted or talked to, but the current version of WordPress &lt;em&gt;is&lt;/em&gt; completely secure. If you're on the current version you should be fine.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt Mullenweg</dc:creator><pubDate>Sun, 06 Sep 2009 13:08:21 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16063209</link><description>&lt;p&gt;Windows has millions of dollars invested in it, and it's still the #1 target ;)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Iliyan Petrov</dc:creator><pubDate>Sun, 06 Sep 2009 12:18:42 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16046721</link><description>&lt;p&gt;The most recent verison is 2.8.4a. I've heard that upgrading to that version will lead to me losing the admin rights. Is that true? Did anyone have any problems after upgradation?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AP</dc:creator><pubDate>Sun, 06 Sep 2009 03:47:58 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16045259</link><description>&lt;p&gt;I recently updated my blog.  I was worried about this.  Ahead of the game! :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mybrutegame</dc:creator><pubDate>Sun, 06 Sep 2009 01:45:06 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16041420</link><description>&lt;p&gt;This has got to be one of the dumbest comments I've ever read on Mashable.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert Basil</dc:creator><pubDate>Sat, 05 Sep 2009 22:30:07 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16038404</link><description>&lt;p&gt;Don't use plugins that aren't actively supported by their developer.  If your blog is relying on plugins that are effectively dead, you aren't exactly thinking ahead as far as the future of your site.  ALL cms and blog platforms are going to have security vulnerabilities.  Thats why new versions are released. WordPress is ready for the enterprise, otherwise organizations such as CNN, New York Times and the NFL wouldn't be using it. Be smart about the plugins you use and you won't run into this problem.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carl Hancock</dc:creator><pubDate>Sat, 05 Sep 2009 20:57:15 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16036893</link><description>&lt;p&gt;My site was hacked about a month ago because of lack of upgrade.  My site was unknowingly selling every kind of precription drug know to man virtually overnight.  Google de-listed me for vital keywords, had to clean site and re-submit, and I had to spend hundreds of dollars getting things fixed and now hundreds of dollars for ongoing maintenance protection because of fear of getting hit again.  Lots of lost business too.  I also was hesitant to upgrade, thinking it was no big deal.  If I had to do it all over again, I would have upgraded!  What a f(*+)+# nightmare.  &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ananymous</dc:creator><pubDate>Sat, 05 Sep 2009 19:45:49 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16036081</link><description>&lt;p&gt;Sure, if you have disabled user registrations, that takes care of 99% of the worms out there.  Of course, Wordpress is a free software, that's why it's very vulnerable, there's not millions of dollars invested in it and it's not a huge team of developers.  You can't blame them but there's ways to protect it by using encrypted passwords and disabling user registrations, which are pointless to visitors for most blogs anyways.  I am not upgrading btw, I am already protected. :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">zedomax</dc:creator><pubDate>Sat, 05 Sep 2009 19:30:05 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16035763</link><description>&lt;p&gt;Thanks for that, Zedomax. While we’ve now upgraded (with extreme difficulty, because the upgrade process takes hours and not the minutes that Wordpress claims), I have disabled user registrations on one of our installations.&lt;br&gt;   Like you, I always have huge problems getting these software companies to believe me, then months down the line I get proved right.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jack Yan</dc:creator><pubDate>Sat, 05 Sep 2009 19:20:36 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16034611</link><description>&lt;p&gt;You're probably right&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew Wong</dc:creator><pubDate>Sat, 05 Sep 2009 18:34:21 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16034428</link><description>&lt;p&gt;Oh! so I should be feeling not secure now?!!&lt;br&gt;my setup is not complicated, I hink it can handle the upgrade, I will go for it! &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hesham Zebida</dc:creator><pubDate>Sat, 05 Sep 2009 18:28:25 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16033415</link><description>&lt;p&gt;The best way to not get attacked this vulnerability is to disable user registrations, which most of you don't need anyways.  According to Matt on the new worm:&lt;/p&gt;&lt;p&gt;"it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts."&lt;/p&gt;&lt;p&gt;I've already gotten this worm 2 months ago, it's been going on for awhile now, FYI.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">zedomax</dc:creator><pubDate>Sat, 05 Sep 2009 17:57:50 -0000</pubDate></item><item><title>Re: WordPress Responds to Attack: &amp;#8220;Please Upgrade&amp;#8221;</title><link>http://mashable.com/2009/09/05/wordpress-please-upgrade/#comment-16033368</link><description>&lt;p&gt;Oh god, I had this problem couple weeks ago and contacted Wordpress, they said their software was completely secure as far as they were concerned.  Now the truth comes out after I lost a bunch of money.  I mean all of my 20+ blogs were getting hacked like it was Sunday breakfast or something.  Next time, please listen to the bloggers Wordpress security team, I don't bs.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">zedomax</dc:creator><pubDate>Sat, 05 Sep 2009 17:55:19 -0000</pubDate></item></channel></rss>