Irish SEO,  Marketing & Webmaster Discussion

 

Wordpress Blog Hijacked?

This is a discussion on Wordpress Blog Hijacked? within the Search Engine Optimisation forums, part of the Online Marketing category; Not with this plugin. Pretty much anyone can hijack your username and password and take over your blog…not if you’re ...


Go Back   Irish SEO, Marketing & Webmaster Discussion > Online Marketing > Search Engine Optimisation

Register Forum Rules FAQDonate Members List Calendar Search Today's Posts Mark Forums Read


Notices

Reply

 

LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 27-06-2008, 10:06 AM
Frontpage User
 
Join Date: Jun 2008
Posts: 1
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
dravid will become famous soon enough
Default Wordpress Blog Hijacked?

Not with this plugin. Pretty much anyone can hijack your username and password and take over your blog…not if you’re using this wp plugin.

Last edited by dravid; 04-07-2008 at 12:30 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 27-06-2008, 10:37 AM
paul's Avatar
ninja SEO
 
Join Date: Dec 2006
Location: .de
Posts: 1,118
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
paul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud of
Default

What number do you dial ?

Is there a charge for this ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 27-06-2008, 11:17 AM
Cormac's Avatar
Cormac Moylan
 
Join Date: Jan 2006
Location: Baile Ath Cliath / Corcaigh
Posts: 1,247
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Cormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to behold
Send a message via AIM to Cormac Send a message via MSN to Cormac Send a message via Yahoo to Cormac Send a message via Skype™ to Cormac
Default

I don't get it. Why would somebody use SMS instead of something like email to two step authenticate their login?

Who pays for the text message?
What if the SMS server is down? - Can I still login?
What does the plugin author do with my mobile number?

There are other ways to get hijacked other than simple username/password breaches. Just use SSL on your login page if you are concerned about u/p sniffing.
__________________
blog | Geansaí Gorm - Written entirely in, awful, Irish! | Me on Blue Jumpers
*
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4 (permalink)  
Old 27-06-2008, 12:41 PM
Forbairt's Avatar
respect my AW-THOR-IT-AYY
Recent Blog: Free CSS book
 
Join Date: Jun 2007
Location: My Office, Dublin
Posts: 2,097
Nominated 2 Times in 1 Post
Nominated TOTW/F/M Award(s): 1
Forbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enough
Send a message via AIM to Forbairt Send a message via MSN to Forbairt Send a message via Yahoo to Forbairt Send a message via Skype™ to Forbairt
Default

safest thing is to never put your wordpress blog online ... don't put it on any computer that is in any way connected to the internet as well ...
__________________
Forbairt Media | Web Design & Development Galway / Dublin, Ireland - coming soon ... ( vague but descriptive isn't it )
Recent Work: Safari Club African Safari Holidays - Malawi Safaris
Other Stuff: FluffyLinkulator Rapid Inclusion Service Tools
Jumper Stuff: Task Drop's Official Geansai Gorm Website
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 27-06-2008, 04:09 PM
gav240z's Avatar
Wannabe Geek
 
Join Date: Dec 2007
Location: Rathmines, Dublin
Posts: 427
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
gav240z is a jewel in the roughgav240z is a jewel in the roughgav240z is a jewel in the rough
Default Wordpress is ok...

Quote:
Originally Posted by Forbairt View Post
safest thing is to never put your wordpress blog online ... don't put it on any computer that is in any way connected to the internet as well ...
LOL. To be fair wordpress is targeted for the same reasons that MS windows and IE are. Because a majority of websites use it.

Safest way to keep your wordpress installation from being exploited is to keep it up to date and run it on a secure hosting service.

I recently failed to keep up to date and paid the price. Albeit a small one.

One thing I hate about WP is that it outputs <meta generator="Wordpress 2.5.1"> its just a red flag to a bull when it comes to scripts / script kiddies. Of course there are other ways to tell its WP but why make it more obvious than need be.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 27-06-2008, 04:17 PM
paul's Avatar
ninja SEO
 
Join Date: Dec 2006
Location: .de
Posts: 1,118
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
paul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud ofpaul has much to be proud of
Default

I am going to run this on all my blogs tonight : WordPress › WordPress Exploit Scanner WordPress Plugins
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #7 (permalink)  
Old 27-06-2008, 04:43 PM
Cormac's Avatar
Cormac Moylan
 
Join Date: Jan 2006
Location: Baile Ath Cliath / Corcaigh
Posts: 1,247
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Cormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to beholdCormac is a splendid one to behold
Send a message via AIM to Cormac Send a message via MSN to Cormac Send a message via Yahoo to Cormac Send a message via Skype™ to Cormac
Default

I installed it earlier, Paul.
It gave me a few alerts about a spell checking plugin I installed for TinyMCE. Handy plugin.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Tags
blog, hijacked, wordpress

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads

Thread Thread Starter Forum Replies Last Post
General Blog questions & BLOG URL SEO question. Help Please? :-) Gman290 Search Engine Optimisation 6 08-11-2008 01:24 AM
My Wordpress Blog... Anouilh Site Reviews / Announcements 13 06-11-2008 03:14 PM
Do you run more than one blog? blacknight Blogs & Blogging 4 15-07-2007 02:57 PM
Irish blog listings which would accept an adult blog? dude Blogs & Blogging 4 04-12-2006 11:40 PM
How often do you blog? blacknight Blogs & Blogging 5 11-11-2006 06:58 PM


Sponsored links

Paid On Results


All times are GMT +1. The time now is 08:19 PM.


Powered by: vBulletin Version 3.7.3, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Hosted in Ireland by Blacknight - Test your ISP |Irish Hosting Directory| Armchair.ie|Logo by Eden Web Design|Avatars by Afterglow |Latest Blog Entries | VPS HostingAd Management by RedTyger

Search Engine Friendly URLs by vBSEO 3.2.0