/?pid=6891

Updated:02:47 AM EST Feb 28


this is ggmania.com subsite WordPress blogs falling prey to worm - TechAmok

WordPress blogs falling prey to worm - [briefly]
03:32 AM EDT - Sep,08 2009 - (1 comments)

ZDNet warns of a worm that is circulating that can post malware and spam to some WordPress blogs using older versions of the software. If you use WordPress, make sure you update to the latest version:
The worm can be tough to catch, as Mullenweg explains: "it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts."

last 10 comments:

(03:34 AM EDT - Sep,08 2009) - admin
if you are lazy to upgrade, here's a workaround:

Basically, all you need to do is replace some text in your wp-login.php
file. Just go in there and change:


[code:1:32d73ca6dc]

if ( empty( $key ) )

[/code:1:32d73ca6dc]

to

[code:1:32d73ca6dc]

if ( empty( $key ) || is_array( $key ) )
[/code:1:32d73ca6dc]

Now if someone tries to reset your password using this exploit,
they will get slapped down with the message
"Sorry, that key does not appear to be valid."

Add your comment (free registrationrequired)

Short overview of recent news articles

Feb,28 2026 Pentagon Blacklists Anthropic Over AI Safeguards; OpenAI Secures
Feb,27 2026 Have RAM and GPU Prices Peaked?
Feb,27 2026 Zoom 'Update' Trap: Fake Site Infects 1,437 Users with Spyware in
Feb,27 2026 Stop WASTING Money on Fancy RAM
Feb,27 2026 Drunk AI robot
Feb,26 2026 AirSnitch Exposes Critical Flaw: Wi-Fi Client Isolation Broken in
Feb,26 2026 Revolutionary Ultrasonic Knife Hits Kitchens: C-200 Vibrates for
Feb,26 2026 Apple Scores Historic NATO Security Clearance: iPhone and iPad First
Feb,26 2026 Kali Linux Goes AI-Powered: Claude Now Runs Your Pen Tests in Plain
Feb,26 2026 Resident Evil Requiem - Stunning on PS5 Pro + PS5/Xbox Series X|S
Feb,26 2026 Samsung Galaxy S26 Ultra Flexes Hardware Muscle Over iPhone 17 Pro
Feb,26 2026 The Galaxy S26 Ultra has a 'wow' feature with video Lock
Feb,26 2026 I built the most BORING PC possible... and here is why it's
Feb,26 2026 Micron Blasts GDDR7 as Gaming Bottleneck While Nvidia's RTX 50
Feb,26 2026 UK Tightens Grip on Streaming Giants: Age Verification Now Mandatory
Feb,25 2026 Samsung Previews New AI Features Ahead of Flagship Phone Launch
Feb,25 2026 China's DeepSeek Bars Nvidia and AMD from New AI Model, Boosts
Feb,25 2026 Avast Impersonation Scam: Fake Site Tricks Users into Handing Over
Feb,25 2026 Microsoft Pulls the Plug: Windows Server 2016 and 2016-Era Windows
Feb,25 2026 I Scrapped 13 MACHINES to Prove a Point: STOP BUYING These Brands!
Feb,25 2026 How Stealthy was the 7zip Malware and how to spot it?
Feb,25 2026 Microsoft Drops Fresh Non-Security Boost for Windows 11 24H2 and
Feb,24 2026 Game-Changer: ASML's 1kW EUV Upgrade Promises 50% Chip Production
Feb,24 2026 This Outstanding Cooling Technology Might Have No Future
Feb,24 2026 AMD Strix Halo 395 vs Intel Panther Lake - Real Benchmarks
Feb,24 2026 Anthropic published a blog post saying Claude can modernize COBOL
Feb,24 2026 WhatsApp Goes Beyond 2FA: Extra Password Layer Makes Accounts Nearly
Feb,24 2026 Google Chrome Gets February 23 Security Boost with 3 High Fixes
Feb,23 2026 Stargate Stalls: OpenAI's $500B Dream Hits Roadblocks as $14B 2026
Feb,23 2026 Google Crushes Cyber Threats: Blocks 1.75 Million Bad Apps and Bans
Feb,22 2026 Bitcoin Miner Bitdeer Sells Everything: Treasury Hits Zero in AI
Feb,22 2026 HW News - More Valve RAM Shortages, Tariffs Ruling, AI Causes PS6
Feb,22 2026 Microsoft's Deep Integration of Copilot in Windows 11 Raises
Feb,22 2026 Elon Musk Confirms X Money Now Live in Internal Beta for Employees,
Feb,22 2026 Scream (1996) Flashback Review
Feb,22 2026 PayPal Confirms Major Breach: SSNs, Emails, and More Exposed from
Feb,22 2026 Does Freezing Help Delidding? 9850X3D Delid & Overclocking Test
Feb,22 2026 Microsoft is phasing out the custom primary password feature in its
Feb,21 2026 Everyone is Buying the Wrong Dash Cam! (2026)
Feb,20 2026 Big Brother on Discord: Leaked Code Shows Age Verification Runs You
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs