Didim Today

Altinkum Didim Akbuk Local News

Wednesday, May 23rd

Last update06:54:29 AM GMT

You are here: Technology Open Sources WordPress 2.8.5: Hardening Release

WordPress 2.8.5: Hardening Release

E-mail Print PDF
Wordpress 2.8.5

WordPress 2.8.5 has officially been tagged and is now available for download and you will be able to update via your admin panel. If you don’t see the upgrade notes in your administration panel already, give it a few hours and upgrade when it becomes available. This release has been dubbed a security hardening release meaning, more preventive measures have been taken to secure WordPress. Get more secure everyday and we not that spammer dont like Wordpress due security issues.

Worthy of note though is an issue that was addressed dealing with a trackback spam denial of service attack which was discussed on the WP-Hackers mailing list the other day. This exploit takes advantage of the WP-Trackback.php file which would exhaust a servers resources when used.

This has specifically been addressed in 2.8.5. Thanks goes out to Steve Fortuna for releasing a fix to this 0 day exploit. The release also contains a few bug fixes as well. The headline changes in this release are: A fix for the Trackback Denial-of-Service attack that is currently being seen.

Removal of areas within the code where php code in variables was evaluated. Switched the file upload functionality to be whitelisted for all users including Admins. Retiring of the two importers of Tag data from old plugins.

We would recommend that all sites are upgraded to this new version of WordPress so as to ensure that you have the best available protection.

If you think your site may have been hit by one of the recent exploits and you would like to make sure that you have cleared out all traces of the exploit then we would recommend that you take a look at the WordPress Exploit Scanner.

This is a plugin which searches the files on your website, and the posts and comments tables of your database for anything suspicious. It also examines your list of active plugins for unusual filenames. Source - web blog tools reported online.

Dowload your latest Wordpress 2.8.5 here, by visiting this link now.

To update your Wordpress site all you need to do is wait for update message on top of the screen or go to upgrade link under the tools.

BLOG COMMENTS POWERED BY DISQUS
Share/Save/Bookmark