Wednesday, August 12, 2009

Infosec Island Admin


Another security release for Wordpress was released yesterday (version 2.8.4) which patches a rather annoying security flaw discovered with all prior versions. By sending a specially crafted URL as an unauthenticated user to your WP blog, and attacker can essential reset your admin password and lock you out of your blog.

The attack is as simple as:[]=

And *BOOM* your out. 

The good news is if you are running a fairly recent version of WP, you can upgrade automatically in your WP admin panel, but clicking the "Upgrade Now" prompt...takes all of 5 seconds. 

