FireStats error : FireStats database needs to be upgraded
WordCamp Philippines

WordCamp Philippines

If you’re a Pinoy blogger or a WordPress user/fan then most likely you’ve heard or read of this already. But in case you haven’t, I have good news for you. There will be a WordCamp held in the Philippines this coming September 6, 2008. If you don’t know what I’m talking about here’s a little info.

What is WordCamp?

WordCamp is a conference type of event that focuses squarely on everything WordPress. Everyone from casual end users all the way up to core developers show up to these events. These events are usually highlighted by speeches or keynotes by various people. WordCamp is a spin off from the popular BarCamp which was a spin off of FooCamp. - Weblog Tools Collection

WordCamp Philippines will be the first ever WordCamp organized and held in Asia. WordCamp Philippines is being organized by a group of Filipino bloggers based in Mindanao who were also responsible for organizing the successful 1st Mindanao Bloggers Summit held last year.

What are the objectives of WordCamp Philippines?

…to encourage more developers to use and deploy WordPress, not only as a blogging engine but also as a full-featured content management system for Web sites. Another is to increase the number of WordPress users and developers in the country. By developers, we mean programmers of WordPress plugins and designers of themes & templates.



Wordpress 2.1.1 - Dangerous Download
14 Comments 3477 Views

« Free Video Editing Software for Windows Pimp My WP Dashboard Part I »



A week ago, I read about the release of Wordpress 2.1.1 and 2.0.9. Since it only required a few files to be upgraded or overwritten, I immediately upgraded my Wordpress installation. Now, if you were like me who upgraded to Wordpress 2.1.1, please read this:

Short explanation:

If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation:

This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.

This is the kind of thing you pray never happens, but it did and now we’re dealing with it as best we can. Although not all downloads of 2.1.1 were affected, we’re declaring the entire version dangerous and have released a new version 2.1.2 that includes minor updates and entirely verified files. We are also taking lots of measures to ensure something like this can’t happen again, not the least of which is minutely external verification of the download package so we’ll know immediately if something goes wrong for any reason.

Read full story

After I read this, I immediately upgraded my Wordpress installation to 2.1.2. I’m posting about this to warn those who have their blogs running Wordpress 2.1.1 about the security exploit and I strongly suggest that you spend time to upgrade ASAP.

Download Wordpress 2.1.2

(2 votes, average: 5 out of 5)
If you enjoyed the article, why not subscribe?

Related Ads

Related Posts



14 Responses to “Wordpress 2.1.1 - Dangerous Download”

  1. MyAvatars 0.2   Riz PHILIPPINES Windows XP Mozilla Firefox 1.5.0.10 on Mar 2, 2007 | 4:47 pm | Reply

    Hi JP, nice of you to drop by my site :)

    I haven’t upgraded mine yet, but was thinking about it. Would you know if this apply to one-click installs that Dreamhost provides?

    Haha, oh well, nde ko nalang muna upgrade to be sure. Hehe.

  2. MyAvatars 0.2   christian PHILIPPINES Windows XP Mozilla Firefox 2.0.0.2 on Mar 2, 2007 | 7:03 pm | Reply

    It’s so annoying that I have to upgrade my three plus one WP installations every now and then. But I don’t have a choice but to upgrade them as I don’t want somebody to hack my site.

  3. MyAvatars 0.2   benj PHILIPPINES Windows XP Mozilla Firefox 2.0.0.2 on Mar 2, 2007 | 11:22 pm | Reply

    Does a gargantuan increase in hits relate to “hacking”? My hits jumped ten-fold in the past 24 hours. o_0

    I just saw the upgrade instructions and I got intimidated. haha

  4. MyAvatars 0.2   K HONG KONG Mac OS X Safari 419.3 on Mar 2, 2007 | 11:49 pm | Reply

    I heard the new wp upgrade is not stable yet?

    That’s the thing with having your own domain, the “upgrading” stuff & security issues. But does this mean, the new upgrade comes handy with an autoinstaller that you don’t need to use copy and paste option in your css? I’m using a free wp.com account and can’t even tell if it’s upgraded or that changing a simple header image can make it look a little nicer.

    See, I’m a cut and paste person so as much as possible leave that up to the tech guys like yourself. Your site always looks good, Jaypee.

  5. MyAvatars 0.2   benj PHILIPPINES Windows XP Mozilla Firefox 2.0.0.2 on Mar 3, 2007 | 1:38 am | Reply

    I did it! woohooo! Piece of cake! hah!

    *shakes dust off sleeve*

  6. MyAvatars 0.2   Jaypee UNITED STATES Windows XP Mozilla Firefox 2.0.0.2 on Mar 3, 2007 | 7:18 pm | Reply

    @Riz - You’re welcome! I’m not really sure where Dreamhost get’s their files but I’m assuming that all WP 2.1.1 files are infected except for these in the Subversion repository. If you’re not running WP 2.1.1, there’s no need for you to upgrade. :)

    Thanks for dropping by! :D

    @christian - I know. It does get annoying sometimes but then your blog’s security is more important. Just like you said, no choice but to upgrade. Hehe :D

    @benj - You mean unique hits to your blog? What do you use to track your site stats?

    It only looks intimidating but as you have proved, it’s just a piece of cake, right? Hehe :D

    @K - Which version are you talking about? There’s been several versions released in less than 2 months. Yeah, that’s part of the responsibilities and tasks that you have when you have your own domain. I’m not quite sure I understand what you mean bout the cut and paste option in CSS coz I don’t really do much with my Wordpress.com account.

    You’re not alone, I have a Master’s degree in copying & pasting. Hehe :D

    Thanks for the compliment!

  7. MyAvatars 0.2   benj PHILIPPINES Windows XP Mozilla Firefox 2.0.0.2 on Mar 3, 2007 | 8:41 pm | Reply

    Yup, unique hits. I use Fire Stats and Stat Traq. My suspended account at Pinoy Top Blogs also reflected the insane jump.

    Either I’m getting hacked or Chiz Escudero’s paid investigators are watching me… from the States. hehe

    Can’t wait for 2.1.3!!! wahahaha

  8. MyAvatars 0.2   ade PHILIPPINES Windows XP Mozilla Firefox 2.0.0.2 on Mar 3, 2007 | 11:36 pm | Reply

    Am upgrading now. i don’t want my haters to learn hacking overnight. :P

  9. MyAvatars 0.2   Jaypee UNITED STATES Windows XP Mozilla Firefox 2.0.0.2 on Mar 4, 2007 | 12:08 pm | Reply

    @benj - I see. I’m not sure coz I haven’t used Fire Stats and Stat Traq. Is there a way to see the specific details of your recent visitors or referrers? But I don’t think an increase in hits means your site was hacked but then, I could also be wrong. Most probably it’s those investigators who are visiting your blogs. Hehe :D

    @ade - That’s good. Better safe than sorry. So you have many haters? Hehe :D

  10. MyAvatars 0.2   benj PHILIPPINES Windows XP Mozilla Firefox 2.0.0.2 on Mar 4, 2007 | 12:37 pm | Reply

    Firestats tracks IP, country of origin, referrer etc. but it doesn’t store the date. It just keeps the 24 hour tally and running tally (all-time). It peaked at 1100 unique hits in 24 hours. It has since normalized to 150.

    hay. they could’ve at least clicked on you know whats while they were in my site. hehe

  11. MyAvatars 0.2   Jaypee UNITED STATES Windows XP Mozilla Firefox 2.0.0.2 on Mar 4, 2007 | 1:46 pm | Reply

    @benj - Thanks for mentioning about FireStats. I’ve downloaded and installed it here. I’m loving it! I use it together with SlimStats, hopefully there would be no conflicts between the two plugins.

    Bout the sudden increase in hits, could it have been because of spam bots?

    Yeah, atleast their visit could have been more beneficial to you and your blog. Hehe :D

  12. MyAvatars 0.2   benj PHILIPPINES Windows XP Mozilla Firefox 2.0.0.2 on Mar 5, 2007 | 4:47 am | Reply

    Spam bots? Wow, I feel so special!

    You liked my tip? Should I expect your dollars on my paypal account?

    wahahaha.

    Kidding.

  13. MyAvatars 0.2   Jaypee UNITED STATES Windows XP Flock 0.7.9.1 on Mar 5, 2007 | 8:59 am | Reply

    @benj - I’m not really sure but it could be the most likely reason unless you have a recently posted entry that’s popular.

    Yeah, thanks for the tip! :D

Sign up for PayPal and start accepting credit card payments instantly.
  1. 1 Trackback(s) To This Post

  2. May 14, 2007: WPZipper » JaypeeOnline | Blogging News & Reviews UNITED STATES WordPress 2.1.3

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

« Free Video Editing Software for Windows Pimp My WP Dashboard Part I »


 Subscribe in a reader Or, subscribe via email:
Enter your email address: 
 
Feedburner
WooThemes - Premium WordPress Themes Club
Google