<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Kevin Deldycke &#187; log</title> <atom:link href="http://kevin.deldycke.com/tag/log/feed/" rel="self" type="application/rss+xml" /><link>http://kevin.deldycke.com</link> <description>Free software engineer &#38; wannabe videomaker</description> <lastBuildDate>Fri, 03 Feb 2012 19:08:27 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>WordPress 2.2 Security Hole: Identity Theft</title><link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/</link> <comments>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comments</comments> <pubDate>Thu, 07 Jun 2007 15:22:51 +0000</pubDate> <dc:creator>Kev</dc:creator> <category><![CDATA[English]]></category> <category><![CDATA[Apache]]></category> <category><![CDATA[Blog]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[log]]></category> <category><![CDATA[security]]></category> <category><![CDATA[Server]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[WordPress]]></category><guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/</guid> <description><![CDATA[I&#8217;m running 4 WordPress blogs, for me and my friends. All of them are updated to latest version of WordPress as soon as a new one is available. One of them, Maomium, was hacked last night. Someone created a user &#8230; <a href="http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description> <content:encoded><![CDATA[<p>I&#8217;m running 4 WordPress blogs, for me and my friends. All of them are updated to latest version of WordPress as soon as a new one is available.</p><p>One of them, <a href="http://maomium.com">Maomium</a>, was hacked last night. Someone created a user account on it then stole my admin identity to post content. As soon as I discovered the hack, I&#8217;ve put the blog down and changed all passwords which may have been exposed to the hacker (database, etc&#8230;).</p><p>Before the hack happened, my apache log show me that a person was looking for blogs powered by WordPress 2.2 and open to registration:</p><pre class="brush: bash; title: ; notranslate">
123.76-136-217.adsl-dyn.isp.belgacom.be www.maomium.com - [07/Jun/2007:00:51:55 +0200] &quot;GET /category/wordpress/ HTTP/1.1&quot; 200 2960 &quot;http://www.google.be/search?hl=fr&amp;q=%22powered+by+wordpress+2.2%22+Register&amp;btnG=Rechercher&amp;meta=&quot; &quot;Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.8.1.4) Gecko/20070515 Firefox/2.0.0.4&quot;
</pre><p>This person was my hacker. As you can see he&#8217;s a belgian guy and his broadband provider is <a href="http://selfcare.belgacom.net/index.html?l=private:internet:security:notify&#038;a=hacking_skynet">Belgacom, to which I sent an abuse request</a>. He register himself as <a href="http://waryas.skynetblogs.be">Waryas</a> with his <code>myv4you@hotmail.com</code> email. I know that, thanks to the email WordPress send me each time someone register. Then <a href="http://www.google.fr/search?q=myv4you%40hotmail.com">google told me</a> that <a href="http://www.coolforum.net/forum/detail.php?forumid=1&#038;id=17468&#038;p=1#29054">this hack was not his first</a>.</p><p>If you want to disect his behaviour, you can <a href='http://kevin.deldycke.com/wp-content/uploads/2007/06/wordpress-22-register-new-user-hack.txt' title='wordpress-22-register-new-user-hack.txt'>download my apache log</a>.</p><p>This event show us that the WordPress vulnerablility regarding guest account registration is still there. So the <a href="http://www.4null4.de/174/wp-users-disable-guest-account-registration-immediately/">advice given by CountZero</a> <strong>must</strong> be applied !</p> ]]></content:encoded> <wfw:commentRss>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/feed/</wfw:commentRss> <slash:comments>20</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 2/12 queries in 0.005 seconds using apc
Object Caching 510/521 objects using apc

Served from: kevin.deldycke.com @ 2012-02-08 03:55:06 -->
