MDDHosting Forums: [Important] Keeping your Script Installations up to date is critical! - MDDHosting Forums
[Important] Keeping your Script Installations up to date is critical! WordPress, PHPBB, vBulletin, WHMCS, IPB, Drupal, Joomla, etc...
#1
Posted 11 July 2011 - 10:29 AM
Across our network over the last week we have seen a large number of outdated WordPress installations that have been compromised for the purpose of uploading a phishing site and/or a spam script. Phishing is a serious issue and is something that we take very seriously. We've audited our servers and server security both internally and externally and have determined that the security issue lies with the outdated WordPress installations themselves and not a server-wide issue. The latest WordPress version as of this post is 3.2.
We ask that you, at this time, do please check all scripts that you have installed in your account to ensure that they are up to date. With WordPress it is as simple as logging into your WordPress dashboard as you will see a notice at the top letting you know if there is a new version available. For updating WordPress you can reference this short guide: Updating WordPress (Text Tutorial) or this video tutorial: Updating WordPress (Video Tutorial).
Do keep in mind that by not updating your software installations you risk your account being used without your permission by hackers and other malicious users and that you could end up with your account suspended due to malicious misuse of your account. We do realize that this misuse would not be intentional or even conducted by yourself, however, we cannot allow our services to be used knowingly or not for illegal purposes.
As of this post here are the statistics for our standard Shared and Reseller servers. Keep in mind that these are just WordPress installations alone.
Echo Server:
Total Installations: 1351
Out-of-date Installations: 1257 (93%)
Fresco Server:
Total Installations: 1068
Out-of-date Installations: 932 (87%)
Gemini Server:
Total Installations: 702
Out-of-date Installations: 513 (73%)
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#2
Posted 11 July 2011 - 10:55 AM
I updated all my customer's installations on the 4th. Wordpress is one of the easiest to update, as your video tutorial shows. Just click a link. I think some programs still require you to download files and FTP them into your account, and that encourages procrastination. I moved my customers to Wordpress for that reason, and recommend SMF as a forum software (it is as easy to update).
#3
Posted 11 July 2011 - 10:58 AM
fshagan, on 11 July 2011 - 10:55 AM, said:
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#4
Posted 11 July 2011 - 06:14 PM
#5
Posted 11 July 2011 - 07:02 PM
kuemerle5, on 11 July 2011 - 06:14 PM, said:
Quote
Quote
Quote
Needless to say, they all know to do it now.
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#6
Posted 11 July 2011 - 07:06 PM
#7
Posted 11 July 2011 - 07:11 PM
#8
Posted 11 July 2011 - 07:24 PM
kuemerle5, on 11 July 2011 - 07:06 PM, said:
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#9
Posted 11 July 2011 - 07:32 PM
MikeDVB, on 11 July 2011 - 07:24 PM, said:
*shudder*
*quickly executes some derivation of 'chmod -R 755 happy_place' into SSH* lol
#10
Posted 11 July 2011 - 07:38 PM
kuemerle5, on 11 July 2011 - 07:32 PM, said:
*quickly executes some derivation of 'chmod -R 755 happy_place' into SSH* lol
Replace {$user} with your username:
chown -R ${user}.${user} /home/${user}
chown ${user}.nobody /home/${user}/public_html
chown -R ${user}.mail /home/${user}/etc
chown ${user}.nobody /home/${user}/.htpasswds/
echo "Fixing folder permissions for account: ${user}"
find /home/${user}/public_html/ -type d -exec chmod 755 {} \;
echo "Fixing file permissions for account: ${user}"
find /home/${user}/public_html/ -type f -exec chmod 644 {} \;
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#11
Posted 11 July 2011 - 08:54 PM
Echo Server:
Total Installations: 1351
Out-of-date Installations as of original post: 1257 (93%)
Out-of-date Installations as of this post: 1216 (90%)
Fresco Server:
Total Installations: 1068
Out-of-date Installations as of original post: 932 (87%)
Out-of-date Installations as of this post: 881 (82%)
Gemini Server:
Total Installations: 702
Out-of-date Installations as of original post: 513 (73%)
Out-of-date Installations as of this post: 462 (66%)
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#12
Posted 11 July 2011 - 09:11 PM
As SnakEyez said, it includes more than just the core script ... and in Wordpress, I would add in the theme you use as well. There is at least one exploit that uses older themes and replaces the "index.php" pages with a foreign language page and the notice "YoU HaVe bEeN HaCkeD!" (along with irritating music). That experience has led me to be more careful about the themes I install as well.
BTW - how do you determine which versions are on disk (I'm thinking of my VPS). Are you just searching for files older than a certain date, or is there a function that reports the version number of the installs?
#13
Posted 11 July 2011 - 09:12 PM
fshagan, on 11 July 2011 - 09:11 PM, said:
updatedb locate wp-includes/version.php | grep -v virtfs | xargs grep "wp_version = " 2>/dev/null | wc -l locate wp-includes/version.php | grep -v virtfs | xargs grep "wp_version = " 2>/dev/null | grep -v " = '3.2'" | wc -l
This will output all WordPress installations and then all out-dated WordPress Installations (just the counts).
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#14
Posted 12 July 2011 - 11:02 PM
WP is releasing 3.2.1 already, although I haven't seen it in my control panels yet:
Quote
#15
Posted 13 July 2011 - 01:18 PM
#16
Posted 14 July 2011 - 04:47 PM
kuemerle5, on 13 July 2011 - 01:18 PM, said:
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#17
Posted 14 July 2011 - 05:11 PM
It's a problem that WordPress has yet to address but I feel it's an important one. They can code the WordPress core perfectly but as long as people are using outdated, insecure plugins, that will be the weak link in the chain.
#18
Posted 14 July 2011 - 06:13 PM
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!

Help













