11
Jun
2008
Posted by J. Angelo Racoma as Blogging Tips
Donncha gives WordPress users a reminder to upgrade our WordPress blogs in light of possible security risks. Donncha know you have to upgrade WP!? Okay, bad pun. At any rate, this is in view of well-publicized attacks last April which has probably left a lot of WordPress-powered blogs still vulnerable. I myself found that a good number of my personal blogs had been affected, with passwords saved on my root folder in clear text, extra admin-level users in the database, and some theme files modified.
Donncha recaps the possible symptoms of this particular hack (and possibly others, too), which include:
And the steps recommended to mitigate or at least minimize the risks are to:
To the untrained eye, most of these steps might not be too easy, but if you’ve been working on blogs for some time now, it won’t be too difficult to spot these problems. For me, perhaps the best way to mitigate the risks is by doing a full export of blog content, and comments, backing up media files and plugins wiping the entire hosting account clear, doing a fresh blog software install, and importing the content. The plugins and media files should then be added back, making sure you only put in the necessary plugins (i.e., don’t upload plugins that you won’t activate anyway), and media files that you have verified to be clean.
Do you like this article? Submit it to Blogosphere News!
6 Responses
Michael
June 11th, 2008 at 7:35 pm
1It’s amazing to me that people don’t keep their blogging software up to date, I know that it is a little stressful to do an upgrade but man is it worth it.
Gustavo Leig
June 11th, 2008 at 10:41 pm
2When you say Export, you mean a MySQLdump export?
importing means a mysql import?
J. Angelo Racoma
June 12th, 2008 at 3:20 am
3Gustavo, WordPress, for instance, has a built in export/import function, which you can use to export posts and comments from one blog and import to another (or to the same blog, with a fresh install). That’s an XML dump.
Gustavo Leig
June 12th, 2008 at 7:05 am
4Thank you Angelo,
I new that but I just got confused between the two methods your were mentioning. Do you believe that export/import through the wordpress admin has any advantage than doing from the mysqldump method?
thx again…
5001
June 12th, 2008 at 8:47 am
5we know that updating is important but is mysql method more advantage than this?
Jeffro2pt0
June 13th, 2008 at 3:12 pm
6Good sound advice. Generally, I keep my plugins and WordPress install up to date. It’s not really that hard of a process to update a WordPress installation. Hopefully, 2.6 brings us automatic core upgrade functionality
RSS feed for comments on this post
Leave a reply