Spacequad AntiSpam Services Free SpamFilter Enterprise License Giveaway!
Click to hide Left Block
Welcome to Spacequad AntiSpam Services
   

WordPress wp-content exploit

Over the last few days we have noticed an increase of 10, 000 spam posting attempts by spammers trying to post gambling and ring tones spam.  A great majority of this (99%) was due to an exploit in the wordpress software.  This exploit allows a spammer to gain access to the wp-content directory and upload what ever they want.  The directory that the spammer has chosen to create is /wp-content/1/.  After making that directory, they upload an archive and unzip it so to speak.  Within this newly created and unpacked directory contents is several html file and a java script file.



What has made this so popular in the last six to eight months since it was discovered, why hasn't WordPress dev team figured out how these spammers are doing this in the first place.  Having access to this level of a web site from the outside with a public url, is utterly stupid and just asking for trouble.  If the developers were at all thinking, they would have made this /wp-content/ and all the other directories after it, below the public_html structure so it cannot be accessed except thru a script and with security.  There is really no good reason that the public should ever have this kind of access to those directories and files.  Even with the best intentions being made, to make life easier for the plugins, this could have been done differently. 

 

For those that are reading this, we hope the best for you and your web site.  If you are tired of constantly seeing security issues with WordPress, we invite you to move over to Geeklog.  Geeklog can be made to look just like your WordPress site did, and you wont have the security issues you do now.  There is even a converter for this if you export your database to MT and then save it.  The script has all the directions in the archive on how to do this.  We have a copy of it here on our site, so you can download it.  We hope this will help everyone that migrates over and keeps people from continuously having a headache.

Trackback

Trackback URL for this entry: http://www.spacequad.com/trackback.php/wordpresswp-contentexploit

No trackback comments for this entry.
WordPress wp-content exploit | 2 comments | Create New Account
The following comments are owned by whomever posted them. This site is not responsible for what they say.
WordPress wp-content exploit
Authored by: Michael Brusletten onThursday, April 03 2008 @ 10:49 PM EDT

After two days now, the spammer who has been sending out a great deal of the junk thru WordPress exploits, is still oblivious to the take down of their hosting sites.  To bad...too sad!  Their sites that host the images and redirects was actually taken down a day after this they started spamming.  Sure is nice to report and get these services shut down that the spammer has worked so hard at trying to hide themselves.

Even the sites like Google, Yahoo and MSN that the spammers tried to use, well, those linked redirected sites and images were taken down now.  So for us, its a cat and mouse game.  The only thing is...we bite back and have them shut down.  So, to put this into retrospect, its costing them big time money to constantly get new domains and hosting sites.

---
You have the right to say whatever wish.
But just as you may not open my door to say it, you also may not put it in my email box. Your Spam stops at my firewall!

WordPress wp-content exploit
Authored by: Anonymous onThursday, April 17 2008 @ 08:16 AM EDT

STOPPING IN TO SAY HELLO TO A GOOD FRIEND! WHAT A BEAUTIFUL PAGE. THANK YOU FOR ALL YOUR KINDNESS.