WordPress 2.8.5: Hardening Release

WordPress 2.8.5: Hardening Release

20 Oct 2009 ·

WordPress


WordPress 2.8.5

Was checking some stuff on my WP Dashboard a few minutes ago when I noticed that there was notification advising me to upgrade to WordPress 2.8.5. Here’s an excerpt from the WordPress blog regarding this recent release:

As you know over the past couple of months we have been working on the new features for WordPress 2.9. We have also been working on trying to make WordPress as secure as possible and during this process we have identified a number of security hardening changes that we thought we worth back-porting to the 2.8 branch so as to get these improvements out there and making all your sites as secure as possible.

WordPress 2.8.5 headline changes:

  • A fix for the Trackback Denial-of-Service attack that is currently being seen.
  • Removal of areas within the code where php code in variables was evaluated.
  • Switched the file upload functionality to be whitelisted for all users including Admins.
  • Retiring of the two importers of Tag data from old plugins.

Recently, there’s been a lot of attacks and exploits on WordPress blogs. Lately, I’ve been receiving a lot of notifications from the WordPress Firewall plugin regarding attacks on my blog. If you think that your blog has been compromised you can use the WordPress Exploit Scanner plugin to check your blog for any traces of exploits.

I’ve just upgraded my WordPress install to version 2.8.5 and I strongly suggest that you do too. It will only take a few minutes of your time and it won’t only make your blog more secure but it will also give you some peace of mind.

If you haven’t upgraded to WordPress 2.8.5, you are advised to do so immediately to avoid the risks of a DDOS attack and prevent future problems and headaches on your blog or website.

Download WordPress 2.8.5 now!


Subscribe to JaypeeOnline's RSS feed  Share this on del.icio.us  Stumble It!  Digg this!  Share this on Facebook  Tweet this!  Share on FriendFeed  Bookmark It!  Submit to Reddit!  Email this story to a friend!
Written by Jaypee Habaradas
Owner and editor of JaypeeOnline. Self-proclaimed geek. New media writer and consultant. WordPress advocate. Loves blogging, gadgets, video games and sports. You can follow him on Twitter @jaypee or Facebook.
Don't miss a single post and receive FREE updates on your email inbox. Subscribe NOW!

Enter your email address:

*Don't forget to verify your subscription by clicking the link on the email that Feedburner will send you.*

Didn't find what you're looking for? Try looking for it again.

Related Posts

Related Ads

























, , , , ,

**Comments posted on JaypeeOnline are moderated. I reserve the right to edit/delete comments that contain words or phrases that are defamatory, abusive, incite hatred and advertise an email address, commercial services or spammy.


7 Responses to “WordPress 2.8.5: Hardening Release”

  1. Jaypee Habaradas UNITED STATES Mozilla Firefox Ubuntu Linux Says:

    @VC – This is just a hardening release that fixed a few bugs to keep your blog more secure and make it more ready for the next stable release – version 2.9.

    WordPress encourages but doesn’t force users to upgrade. If you don’t want to upgrade, its totally up to you. These upgrades are made to help us keep our blogs more stable and secure.

    Reply

  2. V.C NEW ZEALAND Mozilla Firefox Windows Says:

    I don’t understand why they released the new version so quickly after the last update 2 months ago.
    I don’t see any changing in this new version. It’s not really necessary to upgrade.

    Reply

  3. Jaypee Habaradas UNITED STATES Mozilla Firefox Ubuntu Linux Says:

    @Jhay – Really? Its been a while since that happened to me after I upgraded my WordPress install. But anyways, that upgrade.php page is just a confirmation, kinda like a formality. Hehe

    Reply

  4. Jhay PHILIPPINES Google Chrome Windows Says:

    I think this is the first WP upgrade I applied that worked “out-of-the-box” because after I uploaded the files via FTP, it didn’t redirected me to the /wp-admin/upgrade.php page. :D
    .-= Jhay´s last blog ..Blog Action Day 2009: Make Climate Change an important agenda in the 2010 National Elections =-.

    Reply

  5. Jaypee Habaradas UNITED STATES Mozilla Firefox Ubuntu Linux Says:

    @jan – Good job! Now you can sleep better knowing that your blog has the latest version of WordPress. Yes, the WP Firewall plugin is a totally different plugin from the WordPress Exploit Scanner plugin.

    Reply

  6. jan geronimo PHILIPPINES Google Chrome Windows Says:

    Done. I’ve upgraded mine to 2.8.5 already this morning… Is this WordPress Firewall plugin different from WordPress Exploit Scanner?
    .-= jan geronimo´s last blog ..New Twitter Social Proof: Are You on Everyone’s List Yet? =-.

    Reply

Don't Be Shy. Share your thoughts!

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Trackbacks/Pingbacks

  1. [...] This post was mentioned on Twitter by Jhay Gamba, Jaypee Habaradas. Jaypee Habaradas said: WordPress 2.8.5: Hardening Release http://bit.ly/1G1T98 [...]