Go Back   5 Star Affiliate Marketing Forums > SEO, Blogging & Internet Marketing Forums > RSS Marketing & Blogging Forums

RSS Marketing & Blogging Forums Bloggers ask your blogging questions here

Reply
 
Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-09-2009, 12:06 AM
minstrel's Avatar
5 Star Administrator
 
Join Date: Jan 2009
Location: So Can
Posts: 1,661
Exclamation WordPress Install File Poses Security Risk

Important Security Fix for WordPress
By Jeff Starr
Tuesday, May 5, 2009

Quote:
The other day, my server crashed and Perishable Press was unable to connect to the MySQL database...

The problem that I painfully discovered when my server crashed is that WordPress does not always display the default page for all database-related issues. Apparently, if the database is missing entirely, WordPress assumes that it has not yet been installed and loads the Installation Page.

Yikes! This is exactly what happened when my server crashed, MySQL was unavailable, and the WordPress Installation Page was displayed to over 100 visitors while I scrambled to resolve the issue.

During the event, there were several attempts to assume control of my site through the Installation Page. Fortunately, I was working on the site (via FTP, cPanel, phpMyAdmin, and so on) during the attacks, and was able to terminate an inevitable hostile takeover...

It happened to me, and it could happen to you
To me, this scenario represents an enormous security risk for all currently available versions of WordPress (up to 2.8 at the time of this writing). If WordPress serves up the Installation Page the next time your database goes down, anyone could easily gain full control of your entire server...

A temporary solution, until WordPress does it better
After restoring full functionality to my site, deleting multiple “Hello world!” posts and “About” pages, and removing the newly added Administrator, it was time to prevent this situation from happening again. The easiest way to do this involves deleting, blocking, or modifying the wp-admin/install.php file, which contains the script that generates the Installation Page.
See full post for additional measures
Reply With Quote
  #2 (permalink)  
Old 05-09-2009, 10:21 AM
Linda Buquet's Avatar
5 Star President & Community Leader
 
Join Date: Jun 2005
Location: So Cal
Posts: 12,132
Default

Scary stuff! Thanks for the warning David.
__________________
Linda Buquet :: Affiliate Recruiting, Promotion & PR

The free forum support we provide is made possible by all the 5 Star programs at the
top of the right sidebar & in the directory below. Please visit & support our merchants.


5 Star Affiliate Blog :: 5 Star Affiliate Directory

5 Star Affiliate Marketing Blog
Reply With Quote
  #3 (permalink)  
Old 05-09-2009, 10:39 AM
Linda Buquet's Avatar
5 Star President & Community Leader
 
Join Date: Jun 2005
Location: So Cal
Posts: 12,132
Default

My blog developer is working on my blog this weekend and I told him about this.
Luckily he had just read this and already deleted my install file!
He rocks!
__________________
Linda Buquet :: Affiliate Recruiting, Promotion & PR

The free forum support we provide is made possible by all the 5 Star programs at the
top of the right sidebar & in the directory below. Please visit & support our merchants.


5 Star Affiliate Blog :: 5 Star Affiliate Directory

5 Star Affiliate Marketing Blog
Reply With Quote
  #4 (permalink)  
Old 05-09-2009, 12:32 PM
5 Star Member
 
Join Date: Jul 2008
Location: Dallas
Posts: 72
Default

Yes thanks for that post!
Very useful tip. Will have to do the same to all my other sites.
Reply With Quote
  #5 (permalink)  
Old 05-09-2009, 12:58 PM
Linda Buquet's Avatar
5 Star President & Community Leader
 
Join Date: Jun 2005
Location: So Cal
Posts: 12,132
Default

imwebdev is my Wordpress guru and helps me with pretty much anything I need as far as CSS or development of any kind. He's very fast and dependable!!!
__________________
Linda Buquet :: Affiliate Recruiting, Promotion & PR

The free forum support we provide is made possible by all the 5 Star programs at the
top of the right sidebar & in the directory below. Please visit & support our merchants.


5 Star Affiliate Blog :: 5 Star Affiliate Directory

5 Star Affiliate Marketing Blog
Reply With Quote
  #6 (permalink)  
Old 05-09-2009, 02:13 PM
minstrel's Avatar
5 Star Administrator
 
Join Date: Jan 2009
Location: So Can
Posts: 1,661
Default

That's good to know, Linda. Hi, imwebdev!

One additional caution: Now that WordPress has its own built-in auto-upgrade feature, since they don't warn you to remove the install file after upgrading as for example vBulletin does, we're going to have to remember to delete install.php via FTP after every upgrade.
Reply With Quote
  #7 (permalink)  
Old 05-10-2009, 08:53 AM
5 Star Member
 
Join Date: Jul 2008
Location: Dallas
Posts: 72
Default

Hi Minstrel!

Yes we will have to ensure it is secured after the auto updates!

If I find any more helpful word press security tips, I will let you know.
Reply With Quote
  #8 (permalink)  
Old 05-10-2009, 09:47 AM
minstrel's Avatar
5 Star Administrator
 
Join Date: Jan 2009
Location: So Can
Posts: 1,661
Default

One blog I follow is WordPress - BlogSecurity
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are Off
Refbacks are Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Panda Software is now Panda Security. 7/30/2007. James Nardell 5 Star Affiliate Program News 6 08-11-2007 04:18 PM
Panda Security presents its new 2008 product line with megadetection. 7/31/2007. James Nardell 5 Star Affiliate Program News 1 08-06-2007 03:24 PM


All times are GMT -7. The time now is 12:48 PM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO © 2009, Crawlability, Inc.
©2005 - 2009 Linda Buquet - 5 Star Affiliate Programs