MDDHosting Forums: [Important] Keeping your Script Installations up to date is critical! - MDDHosting Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

[Important] Keeping your Script Installations up to date is critical! WordPress, PHPBB, vBulletin, WHMCS, IPB, Drupal, Joomla, etc...

#1 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 11 July 2011 - 10:29 AM

It is extremely important that you keep any and all script installations in your account up to date such as WordPress, Drupal, vBulletin, etc... When these pieces of software are updated by their developers, more often than not, security patches are included and exploits are closed. This particular notice is concerning outdated WordPress installations.

Across our network over the last week we have seen a large number of outdated WordPress installations that have been compromised for the purpose of uploading a phishing site and/or a spam script. Phishing is a serious issue and is something that we take very seriously. We've audited our servers and server security both internally and externally and have determined that the security issue lies with the outdated WordPress installations themselves and not a server-wide issue. The latest WordPress version as of this post is 3.2.

We ask that you, at this time, do please check all scripts that you have installed in your account to ensure that they are up to date. With WordPress it is as simple as logging into your WordPress dashboard as you will see a notice at the top letting you know if there is a new version available. For updating WordPress you can reference this short guide: Updating WordPress (Text Tutorial) or this video tutorial: Updating WordPress (Video Tutorial).

Do keep in mind that by not updating your software installations you risk your account being used without your permission by hackers and other malicious users and that you could end up with your account suspended due to malicious misuse of your account. We do realize that this misuse would not be intentional or even conducted by yourself, however, we cannot allow our services to be used knowingly or not for illegal purposes.

As of this post here are the statistics for our standard Shared and Reseller servers. Keep in mind that these are just WordPress installations alone.

Echo Server:
Total Installations: 1351
Out-of-date Installations: 1257 (93%)

Fresco Server:
Total Installations: 1068
Out-of-date Installations: 932 (87%)

Gemini Server:
Total Installations: 702
Out-of-date Installations: 513 (73%)
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#2 User is offline   fshagan 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 10-January 11

Posted 11 July 2011 - 10:55 AM

Wow, I'm surprised at the number of outdated Wordpress installations. Some might be the last version (3.2 came out on July 4), but still ...

I updated all my customer's installations on the 4th. Wordpress is one of the easiest to update, as your video tutorial shows. Just click a link. I think some programs still require you to download files and FTP them into your account, and that encourages procrastination. I moved my customers to Wordpress for that reason, and recommend SMF as a forum software (it is as easy to update).
0

#3 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 11 July 2011 - 10:58 AM

View Postfshagan, on 11 July 2011 - 10:55 AM, said:

Wow, I'm surprised at the number of outdated Wordpress installations. Some might be the last version (3.2 came out on July 4), but still ...
The installations considered up-to-date are all 3.2.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#4 User is offline   kuemerle5 

  • Member
  • PipPip
  • Group: Clients
  • Posts: 70
  • Joined: 18-October 09
  • Gender:Male

Posted 11 July 2011 - 06:14 PM

I am probably as shocked as fshagan is at the number. There's really no reason why your WordPress install should be out of date as it is pretty much the easiest platform to update on. You seriously click one button and it does everything else for you. Unbelievable...
0

#5 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 11 July 2011 - 07:02 PM

View Postkuemerle5, on 11 July 2011 - 06:14 PM, said:

I am probably as shocked as fshagan is at the number. There's really no reason why your WordPress install should be out of date as it is pretty much the easiest platform to update on. You seriously click one button and it does everything else for you. Unbelievable...
A lot of our customers have responded to the email with things like these:

Quote

I didn't realize it didn't keep itself up to date.

Quote

I thought I was supposed to leave that alone.

Quote

I didn't want it to quit working.

Needless to say, they all know to do it now.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#6 User is offline   kuemerle5 

  • Member
  • PipPip
  • Group: Clients
  • Posts: 70
  • Joined: 18-October 09
  • Gender:Male

Posted 11 July 2011 - 07:06 PM

Well, hopefully they continue to keep their platforms updated. Don't want any of that hacking nastiness affecting other people. Wouldn't it be fairly isolated though because isn't everyone's cPanel 'home' directory readable/writable/executable by only the account owner (and root)?
0

#7 User is offline   SnakEyez 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 17
  • Joined: 11-December 10

Posted 11 July 2011 - 07:11 PM

That's a scary statistic but not surprising. And it's not just about keeping the script up to date, but also the mods and extensions of those scripts up to date. Sometimes those can be forgotten.
0

#8 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 11 July 2011 - 07:24 PM

View Postkuemerle5, on 11 July 2011 - 07:06 PM, said:

Well, hopefully they continue to keep their platforms updated. Don't want any of that hacking nastiness affecting other people. Wouldn't it be fairly isolated though because isn't everyone's cPanel 'home' directory readable/writable/executable by only the account owner (and root)?
Yes, barring some major server issue an exploited account would have little to no effect on other accounts. Accounts using 777 permissions could very well end up with their data modified via a perl script or something similar but php wouldn't be able to access them even with 777 due to php_open_basedir.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#9 User is offline   kuemerle5 

  • Member
  • PipPip
  • Group: Clients
  • Posts: 70
  • Joined: 18-October 09
  • Gender:Male

Posted 11 July 2011 - 07:32 PM

View PostMikeDVB, on 11 July 2011 - 07:24 PM, said:

Yes, barring some major server issue an exploited account would have little to no effect on other accounts. Accounts using 777 permissions could very well end up with their data modified via a perl script or something similar but php wouldn't be able to access them even with 777 due to php_open_basedir.


*shudder*

*quickly executes some derivation of 'chmod -R 755 happy_place' into SSH* lolPosted Image
0

#10 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 11 July 2011 - 07:38 PM

View Postkuemerle5, on 11 July 2011 - 07:32 PM, said:

*shudder*

*quickly executes some derivation of 'chmod -R 755 happy_place' into SSH* lolPosted Image

Replace {$user} with your username:
        chown -R ${user}.${user} /home/${user}
        chown ${user}.nobody /home/${user}/public_html
        chown -R ${user}.mail /home/${user}/etc
        chown ${user}.nobody /home/${user}/.htpasswds/
        echo "Fixing folder permissions for account: ${user}"
        find /home/${user}/public_html/ -type d -exec chmod 755 {} \;
        echo "Fixing file permissions for account: ${user}"
        find /home/${user}/public_html/ -type f -exec chmod 644 {} \;

Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#11 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 11 July 2011 - 08:54 PM

Updated Statistics
Echo Server:
Total Installations: 1351
Out-of-date Installations as of original post: 1257 (93%)
Out-of-date Installations as of this post: 1216 (90%)

Fresco Server:
Total Installations: 1068
Out-of-date Installations as of original post: 932 (87%)
Out-of-date Installations as of this post: 881 (82%)

Gemini Server:
Total Installations: 702
Out-of-date Installations as of original post: 513 (73%)
Out-of-date Installations as of this post: 462 (66%)
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#12 User is offline   fshagan 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 10-January 11

Posted 11 July 2011 - 09:11 PM

Pretty good response in a short period of time, Mike. I think its a good, proactive approach. you've taken.

As SnakEyez said, it includes more than just the core script ... and in Wordpress, I would add in the theme you use as well. There is at least one exploit that uses older themes and replaces the "index.php" pages with a foreign language page and the notice "YoU HaVe bEeN HaCkeD!" (along with irritating music). That experience has led me to be more careful about the themes I install as well.

BTW - how do you determine which versions are on disk (I'm thinking of my VPS). Are you just searching for files older than a certain date, or is there a function that reports the version number of the installs?
0

#13 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 11 July 2011 - 09:12 PM

View Postfshagan, on 11 July 2011 - 09:11 PM, said:

BTW - how do you determine which versions are on disk (I'm thinking of my VPS). Are you just searching for files older than a certain date, or is there a function that reports the version number of the installs?

updatedb
locate wp-includes/version.php | grep -v virtfs | xargs grep "wp_version = " 2>/dev/null | wc -l
locate wp-includes/version.php | grep -v virtfs | xargs grep "wp_version = " 2>/dev/null | grep -v " = '3.2'" | wc -l

This will output all WordPress installations and then all out-dated WordPress Installations (just the counts).
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#14 User is offline   fshagan 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 10-January 11

Posted 12 July 2011 - 11:02 PM

Thanks for that linux juju!

WP is releasing 3.2.1 already, although I haven't seen it in my control panels yet:

Quote

After more than a million downloads of WordPress 3.2, we’re now releasing WordPress 3.2.1 into the wild. This maintenance release fixes a server incompatibility related to JSON that’s unfortunately affected some of you, as well as a few other fixes in the new dashboard design and the Twenty Eleven theme. If you’ve already updated to 3.2, then this update will be even faster than usual, thanks to the new feature in 3.2 that only updates files that have been changed, rather than replacing all the files in your installation.

0

#15 User is offline   kuemerle5 

  • Member
  • PipPip
  • Group: Clients
  • Posts: 70
  • Joined: 18-October 09
  • Gender:Male

Posted 13 July 2011 - 01:18 PM

Just saw this article on Softpedia. Could mean much less headaches for web hosting companies and it's just plain awesome: http://news.softpedi...es-211386.shtml
0

#16 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 14 July 2011 - 04:47 PM

View Postkuemerle5, on 13 July 2011 - 01:18 PM, said:

Just saw this article on Softpedia. Could mean much less headaches for web hosting companies and it's just plain awesome: http://news.softpedi...es-211386.shtml
Very nice, but I wonder how many will disable the automatic updates due to wanting to continue running outdated plugins and themes that don't work on the newer versions.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#17 User is offline   kuemerle5 

  • Member
  • PipPip
  • Group: Clients
  • Posts: 70
  • Joined: 18-October 09
  • Gender:Male

Posted 14 July 2011 - 05:11 PM

*sigh* You gotta love those plugins and themes that practice poor coding techniques and are never updated by their authors. I feel the WordPress plugin database is too fragmented and many of the plugins tailor to unneeded niche functionality. You can basically replicate a WordPress install and probably 10-15 plugins in Drupal with the core modules and a few, very well supported third party modules. I guess I would compare this situation to the iOS App Store and Android's Market. iOS apps (Drupal plugins) all act similar, look familiar, interact with iOS the way Apple intended, and generally are given more care from their authors. Android's apps (comparable to WordPress plugins), however, are sometimes fragmented in appearance, the manner in which they interact with the Android OS can vary greatly, and could just be sandbox type or proof-of-concept projects that won't be updated regularly by the author.

It's a problem that WordPress has yet to address but I feel it's an important one. They can code the WordPress core perfectly but as long as people are using outdated, insecure plugins, that will be the weak link in the chain.
0

#18 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 14 July 2011 - 06:13 PM

I couldn't agree more.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users