Wordpress does its usual trick

Ah, just when you thought WP had outgrown its massive, public security problems – surprise!

Happily, for anyone who knows anything, updating looks like this:

svn sw http://svn.automattic.com/wordpress/tags/2.8.4

However – this BS is still pretty inexcusable. I’ll be leaving WP “soon”. Unfortunately, since writing one’s own blog software is very much a hobby project, it’s been delayed a few times – but crap like this certainly inspires me to get it done soon.

update: Matt Mullenweg sez:

I’m not clairvoyant and I can’t predict what schemes spammers, hackers, crackers, and tricksters will come up with in the future to harm your blog

Matt, we’ve disagreed in the past, but I’m with you 100% on that one.

update 2: ooh, a blog I host – not this one, but a friend’s – was hacked. No risk to anywhere else of course; I am paranoid about security at the best of times and when it comes to WP I don’t take any chances. But still, interesting. The hack inserts a script to hide the new hostile administrator from you in the Users section; never seen that before. Happily, a quick visit to the web developer toolbar in FF got rid of that, and the user is now deleted, and there don’t seem to be any other effects. I don’t see anything weird in an SQL dump either. Currently debating if it’s worth nuking the site and redoing or just sitting it out until all these blogs get moved to another server anyway, which is imminent.

Tags: security, wordpress

2 Responses to “Wordpress does its usual trick”

  1. Matt Says:

    What I do for most of my sites is switch them to a stable branch and just have svn up run on cron, I find this works better than tags because they’ll get fixes within hours of them being committed.

  2. Sho Says:

    Yeah I know matt, you replied to me on HN (my new account, old one got banned for some reason). I do that too. Although I think I’m going to start enforcing your cron trick on any sites under my control.

    Still, while respecting your considerable accomplishments, I wish you would take more responsibility for the WP platform. Yes I know it’s free but you can’t wave these defects away as “you got what you paid for” anymore. How many tens of thousands of sites have been hacked this time? You have got to take this shit more seriously. Hire some freaking penetration testers already.

Leave a Reply