Critical Announcement affecting ALL Wordpress users
July 26th, 2006 | Filed under WordPressIf you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked).
Additionally, delete or disable ANY guest account already created by people you are not sure about.
Leaving it open and letting people sign-up for guest accounts on your Wordpress blog could lead to incredibly nasty stuff happening if anybody so desired. And trust me I am not exaggerating this. So don’t wait a second to disable this option and please relay the message.
Wordpress dev team has been notified a while back and I dare hope they will soon start acting on it, if only by relaying a similar announcement through the official channel (as well as, of course, releasing a proper patch).
Sorry for the shrill hysterical tone, but this is a big deal. However, disable that one option and you are fine, no need to panic further
[cheers go to Geoff Eby for discovering and bringing this insane security exploit to my attention]
Update: a small follow-up addressing comments and concerns I have received ever since this last warning, is posted here. Feel free to ignore completely unless you really care about inner Wordpress politics (yawn).
Update 2: Wordpress upgrade 2.0.4 should now patch this bug. If your version of Wordpress is equal to or higher than 2.0.4, feel free to ignore the warning above. If not, then you should/MUST upgrade (more details in the comments).
2006-07-26 at 6.08 pm
What exactly do oyu mean by “guest?” It isn’t listed as a subscriber type. Do you mean “subscriber,” which is the lowest level of user? Also, to disable it, would I uncheck the “Allow anyone to register” option in the “General” options tab? Sorry, but I’m just a little confused about this problem…
2006-07-26 at 6.11 pm
what exactly happens? The reason I ask is that two of my sites (techiecity.net and clearout.info) were hacked just today by some wierd dude. The whole server is down for the count.
2006-07-26 at 6.20 pm
[...] more details [...]
2006-07-26 at 6.56 pm
WP Users : Disable Guest Account Registration immediately
I’ve been informed through the automated annotation service that’s integrated in the popular Spamkarma 2 plugin for WordPress that everybody, regardless of the WordPress version used, should deactivate the “everyone can register”…
2006-07-26 at 7.03 pm
I don’t remembering touching that setting in my blog and I don’t have it enabled so I don’t think it’s turned on by default. But thanks for the warning.
2006-07-26 at 7.21 pm
[...] Hier ist eine wichtige Meldung von Dr. Dave (SpamKarma2). Anscheinend geht jetzt langsam aber sicher die Post ab. Abgelegt am: 26.07.2006 in Aufgeschnappt, Wussten Sie schon und 1 mal gelesen | [...]
2006-07-26 at 7.43 pm
[...] som helst kan regga sig) bör slå av den omeddelbart enligt Dr. Dave, läs mer här. [fast länk][trackback] [...]
2006-07-26 at 8.00 pm
If anyone has more details about the vulnerability and what newly registered users can do, please e-mail me privately at [censored]
Note from drD: Removed your email address as it was both seemingly invalid and not likely to get you any helpful info anyway. As I said below, you will have to trust us for now and take the really tiny leap of disabling that option for the time being, until more can be said safely…
2006-07-26 at 8.01 pm
@Matthew, you are correct in both cases.
@Patrick, it is disabled by default in newer versions of WP.
Also, this affects 1.5.x users as well.
2006-07-26 at 8.28 pm
Great .. finally a life sign of the love-lorn drdave … and it is a message of doom !!!!
2006-07-26 at 8.56 pm
[...] Dr Dave » Blog Archive » Critical Announcement affecting ALL Wordpress users [...]
2006-07-26 at 9.26 pm
[...] Public Service Announcement (IMPORTANT) Filed under: Public Announcements window.document.getElementById(’post-1116′).parentNode.className += ‘ adhesive_post’;We’ve just learned that, due to unspecified security issues (it wouldn’t be smart to hand out the details since it would only help the wrong kind of people), having WordPress sites open to registration by anyone can lead to all manner of nasty things happening. [...]
2006-07-26 at 9.53 pm
[...] From Dr. Dave; (permalink) If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). [...]
2006-07-26 at 10.01 pm
[...] [thanks go to geoff_e for discovering and bringing this insane security exploit to my attention] Quelle [...]
2006-07-26 at 10.11 pm
[...] Currently I’ve disabled registration for new users after being notified of a critical security problem. I don’t know what the flaw is (unlike Microsoft, Wordpress is choosing not to reveal how their flaws can be exploited before a fix is created), but since I don’t get many guest registrations I figured it couldn’t hurt. I’ll let you know when that feature is turned back on. [...]
2006-07-26 at 10.11 pm
[...] Le billet original de Dave sur le sujet. [...]
2006-07-26 at 10.12 pm
So…are you going to update us all via comments here when this flaw has been patched?
2006-07-26 at 10.23 pm
[...] Nähres erfahrt ihr hier auf der Seite des Autors [...]
2006-07-26 at 11.26 pm
[...] halten, was die Kommentare angeht. Man kann aber auch selbst einen Kommentar verfassen, oder ein Trackback von der eigenen Seite ausmachen. [...]
2006-07-27 at 1.33 am
It would be nice to have some details on this exploit. My new user default role is “subscriber.” I’m not sure what difference a “subscriber” can make other than to leave comments, which BTW can be done at my site without registration.
2006-07-27 at 1.39 am
[...] Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable ‘guest user registration’ on your blog if it’s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke. [...]
2006-07-27 at 1.53 am
Um, great! I dont see anything about this on wordpress.org anywhere ?
2006-07-27 at 2.34 am
Hello all… In a nutshell:
1) what geoff_e said.
2) no, obviously I cannot give you the slightest amount of detail on the exploit. You’ll have to take my word for it (but don’t feel like you have to). It’s been tested and shown to exist with varying levels of danger on *all* versions of WP up to the very last one.
3) wp devs have been notified. I am *not* an official WP dev. Both this announcement and any technical opinion I may have about it are my very own and not in any way representative of the official WP position, response to it or lack thereof (thanks Cthulhu).
4) it is fairly easy to patch, though Lead seem to have had more important priorities at the moment. However, merely releasing the patch is akin to publicly disclose the exploit. Which *must* be done at some point, but hopefully not before as many regular users as possible have heard the message and protected their blog (I trust the simple act of disabling this option is more likely to be done promptly than an actual upgrade).
5) if looking for any official answer, emergency response deployment, reassurance, dismissal or otherwise Party-sanctionned advices, contact WP officials, not me.
Thanks and happy blogging nonetheless…
2006-07-27 at 3.03 am
[...] Got this off Lorelle who got this of the creator of Spam Karma, Dr. Dave. It’s a massive security flaw that affects any and all users of the standalone version of wordpress both 1.5.X and 2.0.X and not Wordpress.com or any Wordpress Multi User versions. In Dr. Dave’s words from his post: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). [...]
2006-07-27 at 3.14 am
[...] More details here . Technorati Tags: WordPress Bookmark Important security announcement affecting ALL WordPress users! at: [...]
2006-07-27 at 3.17 am
Wordpress Exploit
Critical Announcement affecting ALL Wordpress users! Disable User Registration Now!…
2006-07-27 at 3.18 am
[...] According to Dr Dave there is a serious security flaw in all versions of WordPress. His advice is to immediately disable the “anyone can register option” (Go to the admin panel, under Options->General, about half way down the page) to protect yourself in the meantime. [...]
2006-07-27 at 3.33 am
[...] Dr Dave has announced that there is a security exploit affecting WordPress 1.5 and WordPress 2.0. [...]
2006-07-27 at 3.51 am
[...] Due to a security exploit found in ALL versions of WordPress, open registration for new accounts has been temporarily suspended until WordPress can come out with a patch. [...]
2006-07-27 at 4.00 am
[...] Read more at Dr Dave -thanks to Patrick for the email heads up If you enjoyed this post Subscribe to the Free ProBlogger Newsletter [...]
2006-07-27 at 4.30 am
Where did you get this information?? How do you know about this??
I disabled it in my 4 blogs and deleted a bunch of users that signed up but never left comments.
I’m confused though….
What’s weird is that I actually thought that someone hacked one of my sites yesterday because all of a sudden the comment section stopped working. I had to make a whole new theme for my site because the comments just wouldn’t work! I couldn’t figure out how to fix it. The new theme works fine now, but I thought it was strange. Do you think someone actually hacked my site?!
I am anxious for more information…
2006-07-27 at 4.32 am
drDave, if you think you have found a vulnerability the best thing to do is email security@wordpress.org, not cause a panic with a cryptic blog post. We’re about to put out a release and I haven’t received anything from you so I need to know if this is already fixed in 2.0.4 or not.
2006-07-27 at 5.14 am
Seguridad, WordPress, registro de usuarios y preocupación
ProBlogger se despacha hace menos de una hora con una entrada títulada “Possible WordPress Security Problem” donde Dr Dave hace un anuncio (en mi opinión quizá algo alarmista) llamado “Critical Announcement affecting ALL Wordpress …
2006-07-27 at 5.20 am
[...] navigation coming soon! WP Exploit Thursday, 7.27.06 Wordpress has a bug! An exploit has been found and if you run any versionof WP, make sure you unckeck “Anyone can register” in your Options menu. Also delete any guest accounts already created on your blog. For more info, check out Dr Dave. [...]
2006-07-27 at 6.16 am
[...] You are also advised to delete all Guest users or any users that you do not know personally, details about this exploit can be read at Dr Dave blog. [...]
2006-07-27 at 8.13 am
[...] Relaunch of Darknet- An Introduction to AJAX- About Darknet | 2 Views | no comments trackback this article comment on thisarticle [...]
2006-07-27 at 8.23 am
如果用WordPress,那么要小心了
如果你用了wordpress,请马上禁用掉任何人可注册选项(管理后台->Options->去掉Anyone can register选项前面的勾).然后检查一下已注册的用户是否有可疑,如果可疑请删除.Leaving it open and letting people s…
2006-07-27 at 8.57 am
[...] Through Darknet I discovered that apparently a vulnerability has been found in WordPress that could allow evil people to do nasty stuff. Details remain vague though, but according to Dr Dave, one should disable the Anyone can register thingy in the Options of their weblog to prevent the vulnerability being exploited. [...]
2006-07-27 at 9.07 am
Sicherheitslücke?
Offenbar gibt’s ein über-böses Sicherheitsloch in Wordpress, wenn die Benutzerregistrierung aktiviert ist, wie ich von Dr Dave gelernt habe. Da ich ihm glaube, ist also bis auf weiteres keine Registrierung mehr möglich. Dies ist aber kein Pr…
2006-07-27 at 9.39 am
[...] Der Schöpfer des Anti-Spam-Plugins “Spam Karma 2″ (unknowngenius.com/blog[1]), Dr. Dave, hat gestern vor einer generellen Sicherheitslücke in Wordpress gewarnt, die mit der Benutzerverwaltung zusammenhängt (siehe auch unknowngenius.com/blog[2], englisch): If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). Additionally, delete or disable ANY guest account already created by people you are not sure about. [...]
2006-07-27 at 9.44 am
[...] can swallow a pint of blood before you get sick. « Le Grand bleu WP Probs Dr Dave mentioned the wp users should immediately disable the “anyone can register” ,due to his point, it could cause “your wp blog could lead to incredibly nasty stuff happening if anybody so desired”. read more at dr dave. blog, dr dave, incredibly, lead, nasty, register, stuff, updates and news [...]
2006-07-27 at 9.47 am
WP Sicherheitslücke
Wie Dr Dave (der Autor des bekannten PlugIns “SpamKarma”) gestern eindringlich warnte, befindet sich in der Benutzerverwaltung von WP ein kritischer Bug. Dr Dave empfielt allen Usern die Benutzerregistrierung zu deaktivieren und “verd…
2006-07-27 at 10.23 am
[...] I have disabled new guest accounts due to this security problem. I don’t have many guest accounts so I’m not going to delete them for now. [...]
2006-07-27 at 10.44 am
[...] Anscheinend gibt es beim Wordpress Plugin “Spam Karma 2” von Dr. Dave eine Sicherheitslücke, sofern man es erlaubt, dass sich fremde User selbstständig innerhalb von Wordpress registrieren. Deswegen gibt es hier den Lesebefehl für alle betroffenen Administratoren – und bitte weitersagen! Ob etwas wahres dran ist, kann ich jedenfalls zur Zeit nicht beurteilen. [...]
2006-07-27 at 10.50 am
[...] The details of the exploit have not been publicly released yet to give people time to defend against the exploit before a patch is released. I highly recommend you read the details. [...]
2006-07-27 at 10.51 am
[...] unknowngenius.com/blog/ [...]
2006-07-27 at 11.03 am
[...] Notre bon docteur Dave, entre autres choses responsables de l’excellent et indispensable plug-in Spam Karma (que votre serviteur préfère à Akismet, en passant) signale une faille de sécurité assez importante pour toutes les versions de WordPress. [...]
2006-07-27 at 11.20 am
[...] Secondly, this is very important for all WordPress users: WP Users : Disable Guest Account Registration immediately [...]
2006-07-27 at 11.21 am
[...] See Dr Dave » Blog Archive » Critical Announcement affecting ALL Wordpress users [...]
2006-07-27 at 11.35 am
[...] Über die Notification Function von SpamKaram habe ich, die dringende Mitteilung bekommen, alle meine Guest Accounts zu sperren bzw. die Anmeldefunktion dafür abzuschalten, da in diesem Zusammenhang ein Sicherheitsleck entdeckt wurde. Betroffen sind alle Versionen von Wordpress. Nähere Informationen hier. [...]
2006-07-27 at 11.43 am
[...] slått av – sikkerhetsfeil ved WordPress (0) Kommentarer – TrackBack Det har blitt oppdaget en større sikkerhetsrisiko i WordPress, – dette gjelder alle blogger somlar brukerne registrere seg selv. [...]
2006-07-27 at 11.57 am
[...] Ursprungsquelle: unknowngenius.com trackback [...]
2006-07-27 at 12.09 pm
Is this a hoax? Who knows.
There are proceedures when you find a security issue. Contacting the upstream author and vendor sec, obtaining CVE ids from Mitre, contacting relevent distribution channels, etc.
Posting scare stories on a blog, no matter how true they may be is not a way to deal with a security issue.
2006-07-27 at 12.43 pm
Considering the source .. i have no doubt in trusting this ‘minor panic’ … it is not like drdave is asking to shut down the blog or delete all my porn pics from my hard drive …
The alternative? He informs the proper channels (which I believe he did) and waits for them to act … in the meantime some script happy hacker has deleted my blog … er.. ok .. i go with mild panic if I may …
ta ta
2006-07-27 at 1.20 pm
[...] Coming direct from the blog of Dr Dave (the evil genius behind anti spam plugin Spam Karma), he reports on a critical flaw that has been discovered in WordPress that can allow very bad things to happen: [...]
2006-07-27 at 1.34 pm
[...] [Thanks to Tobi for pointing me to this & Dr. Dave for posting it] [...]
2006-07-27 at 1.54 pm
Hello all,
Response to the above comments (and more): here.
2006-07-27 at 2.02 pm
Leck in Wordpress
Falls jemand selbst Wordpress als Blogsoftware benutzt sollte er die Benutzerregistrierung abschalten. Anscheinend gibt es ein ernst zu nehmendes Leck. Es gibt allerdings noch keine Details zu einem Exploit und auch keine zum Leck selbst…
Gefunde…
2006-07-27 at 2.08 pm
[...] Dr Dave is warning of a recently discovered security risk affecting ALL users on ALL VERSIONS of Wordpress If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). [...]
2006-07-27 at 2.48 pm
[...] By DrDave: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). [...]
2006-07-27 at 3.09 pm
[...] Article Link [...]
2006-07-27 at 3.21 pm
[...] Sicherheitsalarm. Gerade schneite hier über die Benachrichtigungsfunktion von SpamKarma2 eine Sicherheitswarnung herein. Dr. Dave warnt hier sehr deutlich vor einer allzu offenen Benutzerregistrierung: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). [...]
2006-07-27 at 3.28 pm
[...] Sicherheitsalarm. Gerade schneite hier über die Benachrichtigungsfunktion von SpamKarma2 eine Sicherheitswarnung herein. Dr. Dave warnt hier sehr deutlich vor einer allzu offenen Benutzerregistrierung: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). [...]
2006-07-27 at 4.25 pm
Vulnerabilidade Crítica atinge o WordPress
Hoje tomei um susto, quando eu fui dar uma olhada geral nas opções do WordPress, quando eu cheguei no Spam Karma, e ví uma mensagem gigante em vermelho, dizendo haver uma vulnerabilidade crítica atingindo o WordPress, fui lá ver, achei meio estran…
2006-07-27 at 4.27 pm
[...] If you use Wordpress and have checked “permit guest users” under options, uncheck that option now. Why do this? Because Dr. Dave “The Unknown Genius” who wrote SpamKarma is suggesting all Wordpress useres do this as a precautionary measure while the real Wordpress gurus patch a security bug. [...]
2006-07-27 at 5.23 pm
Thanx for the heads up.
But why is there nothing on the Wordpress web site? Not even in the forums?
And, I don’t seem to have a guest user on my site… (scratches head)….
2006-07-27 at 5.53 pm
[...] Genauere Details über den Exploit gibts (noch) nicht. Hier klicken für den ganzen Artikel. [...]
2006-07-27 at 6.08 pm
[...] die Möglichkeit, dass sich User auf dem Wordress-Blog selbst registrieren können, sollte ausgeschaltet werden (Options -> General -> Membership: Anyone can register). So die Meldung, die momentan herumgeht. Das angebliche Sicherheitsrisiko hat der Spamkarma-Developer veröffentlicht. Und beim Gerald lese ich, dass doch etwas dran sein könnte. Also, bis sich das aufgeklärt hat, sicherheitshalber User-Registrierungen ausschalten und bestehende User, bei denen man sich unsicher ist, deleten. [...]
2006-07-27 at 6.18 pm
[...] WordPress Guest Registration Security Concern I was reading through my RSS Feeds today, and Darren Rowse mentioned that there was a security concern pointed out to him from Dr Dave regarding a feature of WordPress that allows guests to the site to register as users on the site. [...]
2006-07-27 at 6.34 pm
[...] 这件事到底有没有根据?Dr Dave只是在Blog上简短的提到他所认为的安全问题却没有列出任何详细的相关资料。但是,Wordpress官方对此的态度也很暧昧,即不承认也不否认是否属实。Darren就这个问题向wordpress的Matt询问时,他表示自己并不清楚具体情况,现在也不好说是否有什么值得担心的。不过,他同时提到2.0.4版wordpress不久后即将释出,如果有真的有什么问题的话届时也会在新一轮升级中得到解决。 [...]
2006-07-27 at 6.38 pm
[...] 剛剛整理 blog 時看到 Spam Karma 2的 critical announcement, 說要把 User Registration 的功能關掉, 以免麻煩. [...]
2006-07-27 at 6.46 pm
[...] Slå “Everyone can register” muligheden fra – den indebærer en eller anden slags kritisk sikkerhedsrisiko, ifølge denne side, som bestyres af manden bag Spam Karma; som altså ved et og andet om WP. [...]
2006-07-27 at 7.13 pm
[...] Lord Misha has informed the blogorandomgeometricshape that WordPress sites with open registration. Apparently that leaves sites vulnerable to undisclosed nastiness. By Imperial Decree, kinda, registration is now closed. I also deleted the profiles of people I didn’t recognize. If deleted you by mistake, send me an e-mail, and I will re-register you. Also, if you would like to be registered, send me an e-mail, and I will take care of it. Thanks. [...]
2006-07-27 at 7.48 pm
[...] Aufgrund einer aktuellen Sicherheitswarnung, die der Spam Karma Entwickler Dr. Dave herausgegeben hat, wird die Benutzerregistrierung hier bei Apfelquak bis auf weiteres vorsorglich deaktiviert. Angeblich stelle die Möglichkeit, allen Usern eine Registrierung zu ermöglichen, ein Sicherheitsrisiko dar. Bis sich die Angelegenheit geklärt hat oder ein entsprechendes Bugfix veröffentlicht wurde, bitte ich diejenigen, die gerne als Autor mitmachen wollen, sich per Mail zu melden. Weitere Informationen zur Sicherheitslücke finden die WP-Blogger unter euch bei Basic Thinking. Abgelaicht unter Intern, Web von ad | [...]
2006-07-27 at 8.44 pm
[...] forrás: darknet, dr dave Ezekre klikk, ha menteni akarod a posztot. [...]
2006-07-27 at 11.09 pm
[...] 27. Juli 2006 Der Autor des WordPress-Plugins Spam Karma, Dr Dave, warnt vor einer Sicherheitslücke in WordPress. [...]
2006-07-27 at 11.55 pm
[...] Vse kar vam je storiti je to, da odklikate v admin sekcijo Options > General > Membership, odznačite opcijo “Anyone can register” in tako bo bojda vse v najlepšem redu do popravka. Bom pa zadevo spremljal in vas obvestil kako in kaj… Drugače si pa preberite tole in tole. [...]
2006-07-28 at 1.43 am
[...] Due to a major security issue that effects ALL WordPress websites, new user account registration has been temporarily suspended. [...]
2006-07-28 at 2.14 am
[...] Dr Dave » Critical Announcement affecting ALL Wordpress users [...]
2006-07-28 at 2.36 am
[...] Critical Announcement affecting ALL Wordpress users, but why isn’t it on the Dashboard yet?! If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). (tags: WordPress) [...]
2006-07-28 at 6.33 am
[...] Thanks to some drastic and controversial actions taken by SpamKarma creator Dr. Dave, a large percentage of the blogging populace has been alerted to a security hole in WordPress. He even went to the effort of activating a warning message that was sent out to everyone who uses his SK2 plugin. This has resulted in a lot of fear spreading amoung a huge number of bloggers. This sort of thing just spreads exponentialy. Here’s a quasi random sampling of two dozen of the first posts on it: ………………….. And these were just from the English blogs that post about this on the same day as the notice going out. The neat thing is that these are some of the most on-top-of-things bloggers out there. Those 24 blogs have some great content and gread visual styles. The are well worth perusing… [...]
2006-07-28 at 9.38 am
[...] Daca rulati un blog WordPress si aveti setat pe enable portiunea de user registration pentru guests, ar fi indicat sa ii dati disable (in wp-admin >> options verificati daca Anyone can register este bifat sau nu). Stergeti orice cont guest de care nu sunteti sigur ca apartine unei persoane de incredere. Cei de la WordPress au fost deja anuntati si se asteapta un patch in curand. Sorry for the shrill hysterical tone, but this is a big deal. However, disable that one option and you are fine, no need to panic further Sursa [...]
2006-07-28 at 11.03 am
[...] Looks like according to Dr Dave of Spam Karma an security hole or hack using guest accounts on Wordpress. You’re severely recommended to goto ‘Options’ in your control panel and unclick ‘Anyone can register’ for the moment. [...]
2006-07-28 at 11.08 am
I saw the update within SpamKarma and appreciate very greatly you bringing this security notice to the WP communities attention. Thanks for the information, action on my part has already been taken!
2006-07-28 at 11.36 am
[...] Critical Announcement affecting ALL Wordpress users: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). Additionally, delete or disable ANY guest account already created by people you are not sure about. [...]
2006-07-28 at 11.59 am
[...] Notre bon docteur Dave, entre autres choses responsables de l’excellent et indispensable plug-in Spam Karma (que votre serviteur préfère à Akismet, en passant) signale une faille de sécurité assez importante pour toutes les versions de WordPress. [...]
2006-07-28 at 2.02 pm
[...] Dr Dave of Spam Karma fame warns of a potential security risk: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register†is not checked). [...]
2006-07-28 at 3.40 pm
[...] Dr. Dave, the man behind Spam Karma has this to say: if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY [...]
2006-07-28 at 3.41 pm
[...] July Administrator09:35 amAdd comment I don’t believe there is anything in the wild, but Dr. Dave (of famed Spam Karma – of which I’m a big fan) has seen a proof of concept for it. He said that Geoff Eby, an acquaintance of his, showed him a proof of concept that was “insane.” So, I’m guessing by his word choice that this is very serious. There is probably some way to escalate privilege or something. In any case, here’s what you need to know to make sure you aren’t victimized. [...]
2006-07-28 at 3.50 pm
WordPress Security Issue
Dr. Dave, the dude behind Spam Karma, has issued a warning to all WordPress users. A message popped up on my Spam Karma 2 dashboard warning of a potential security vulnerability in WordPress. Here’s part of the warning:
If you are running Wordp…
2006-07-28 at 5.17 pm
Noted. I have never enable it anyway. Thanks
2006-07-28 at 6.24 pm
[...] siehe Dr. Dave [...]
2006-07-28 at 6.47 pm
User Registration Temporarily Disabled
Due to a security exploit found in ALL versions of WordPress, open registration for new accounts has been temporarily suspended until WordPress can come out with a patch.
In addition, all users that had registered here but never left a comment have bee…
2006-07-28 at 7.55 pm
[...] Dr. Dave, conocido por su spamkarma, anunció el día de ayer un nuevo bug crítico en todas las versiones de wordpress. Aunque no ha dado al detalle del bug, hasta no estar seguro que haya un parche oficial (ojala muchos hicieran eso), si dá la solución momentanea para evitar el bug hasta que salga un nuevo parche de wordpress para actualizar. [...]
2006-07-28 at 9.51 pm
[...] If you use registration (like I do), you should turn it off. More here. [...]
2006-07-29 at 2.44 am
[...] Article here … [...]
2006-07-29 at 4.18 am
Stupid Question Time: In order to get an official fix for my 1.5.x installation(s!!), I’m going to have to upgrade to 2.0.x, aren’t I?
Let me tell you just how absolutely delighted I am at the prospect…
2006-07-29 at 4.43 am
[...] “MAJOR SECURITY ANNOUNCEMENT “Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable ‘guest user registration’ on your blog if it’s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke.” [...]
2006-07-29 at 5.02 am
[...] Texto Original: Critical Announcement Affecting All WordPress Users [...]
2006-07-29 at 5.50 am
[...] A few days ago, Dr. Dave of Spam Karma fame alerted WordPress users to an unspecified security issue. The workaround: disable registration of new users. Today, the WordPress folks have released WordPress 2.0.4. The security fix means it’s time to upgrade ASAP. [...]
2006-07-29 at 9.51 am
[...] SNAKES!!!! Published Luglio 29th, 2006 in E-life Pare ci sia un bug estremamente critico per WP. Almeno secondo DrDave. Per questo mi sono trovata costretta a disabilitare la sottoscrizione automatica per i nuovi utenti. Essendo niubbissima di WP no so esattamente che cosa questo significhi… non credo cambi molto rispetto a prima, ma se per caso ci fossero problemi nel commentare (eventualmente) i miei articoli, fatemelo sapere scrivendo a strixowl (chiocciola) gmail (punto) com. [...]
2006-07-29 at 11.34 am
[...] In direct response to this blog post I have temporarily turned off registration facilities on this site. This will remain in effect until a patch is issued. [...]
2006-07-29 at 3.17 pm
@ GreyDuck:
For users that are not on the latest version, and don’t have any problems muddling through code, it would be possible to find out the changes from 2.0.3 to 2.0.4, and then look to see if the specific change can be applied to your version.
This is assuming that this issue made it into 2.0.4, since it was all but off the shelf when the issue was brought to their attention.
The best bet is to disable registration for a while, and then see what Geoff and Dr. D have to say about whether it is fixed or not. If it is, then proceed. And good luck.
If 2.0.4 does correct the problem, and you are not completely comfortable with PHP, then your option is upgrading your install, or leaving registration off.
2006-07-29 at 3.23 pm
[...] I can’t find any documentation stating the user registration vulnerability has been fixed, but Kelson is reporting it has been taken care of in WordPress 2.0.4. I believe this WordPress release was pushed out quickly due to some information revealed by Dr. Dave earlier in the week. [...]
2006-07-29 at 3.33 pm
Update on the security flaw
The exploit has been, as far as I can tell(*), fixed by the latest 2.0.4 release. You are therefore strongly recommended to (read: you MUST) upgrade to this version.
As for the “users can register” option: enabling it back should be OK.
I personally will leave it off on my blogs, as I just don’t feel like entrusting strangers with access to wp-admin in the current state of the code (I insist that the aforementioned exploit has been fixed now, I am only being paranoid here).
(*) Note that this is only my own very superficial testing of the code released: in no way the word of any official developer. You should all be aware that I have barely any more official knowledge of this than you do, considering Matt’s fondness for the stealth&ignore school of crisis management (basically, if i doesn’t make it on Slashdot, you can bet you’ll never read about it on his blog). As you may have noticed, he has been marvellously low-key about the whole thing (you know, don’t want
investorsusers to “panic” or, god forbid, start suspecting that WP might sometimes have security flaws in it). It also bears pointing out that he has neither contacted me nor replied to my emails in any way other than posting his very helpful comment above.And just to definitely close that chapter of WP’s Incredible Security Adventures by saying I have no regrets whatsoever about releasing this warning, given the way it was otherwise handled by WP officials: 1) deny 2) minimize 3) somewhat acknowledge 4) keep shut 5) release an upgrade that likely won’t be installed by more than 50% of the general public with for only communication a tiny confusing “upgrade announcement” message in the dashboard feed, wedged between two inconsequential WP marketoid news.
2006-07-29 at 9.02 pm
[...] Here’s the deal: unless you are currently running version 2.0.4 it is recommended that you take the following action without delay: [...]
2006-07-30 at 6.03 pm
[...] Una nueva versión de Wordpress ha salido para poder ser descargada, en esta versión se corrigen más de 50 bugs de la versión anterior, incluyendo un grave problema de seguridad anunciado hace pocos dÃas. [...]
2006-07-31 at 12.57 pm
[...] Technikecke Tags: Blog, WordpressSchon am 29. Juli veröffentlichte das Wordpress-Team eine neue Version der Blog-Software. Heute findet sich dies auch auf Heise als Newsmeldung wieder. Grund dafür ist, daß mit der aktuellen Version auch ein kritisches Sicherheitsloch behoben worden sein soll: Angreifer könnten sich durch die Lücke in verwundbare Systeme hacken, weitere Details sind bislang jedoch nicht bekannt. Vergangene Woche warnte der ehemalige WordPress-Entwickler mit dem Pseudonym “Dr Dave” in seinem Blog vor der Schwachstelle und riet WordPress-Nutzern, die Benutzerregistrierung für Gäste zu deaktivieren. Allerdings gibt auch er keine Details zu dem Fehler bekannt, nicht einmal in einem F.A.Q. zu seiner Warnung. Auf eine Anfrage von heise Security bezüglich des Fehlers antwortete der Hauptentwickler Matt Mullenweg bislang nicht. Quelle: Heise Online [...]
2006-07-31 at 3.39 pm
[...] Najwyrazniej jakis paskudny bug w kodzie: http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/ Nawet nie uzywajac trzeba uwazac. Skandal. [...]
2006-07-31 at 5.04 pm
[...] Wegen eines kritischen Sicherheitsproblems mit der hier verwendeten Blogsoftware habe ich die Möglichkeit zur offenen Registrierung vorrübergehend abgeschaltet. Da ich im Moment aus verschiedenen Gründen nicht dazu komme, eine neue Version der Software auf dem Server hochzuladen, kann dieser Zustand noch einige Tage bestehen bleiben. Ich werde hier eine kurze Meldung geben, wenn die Registrierung wieder offen ist. [...]
2006-07-31 at 7.03 pm
[...] Se ha deshabilitado temporalmente el registro de usuarios nuevos, hasta que se actualize la instalación de Wordpress. Esto debido a un bug en versiones anteriores del propio Wordpress. [...]
2006-08-01 at 3.44 am
[...] WordPress 2.0.4, the latest stable release their series, is available for download. This release contains several important security fixes, including the unspecified security issue from Dr. Dave of Spam Karma. [...]
2006-08-01 at 4.26 am
[...] Updated to the latest Wordpress (v2.0.4) to take care of some security issues and various other bugs. I figured that with the update of code I’d try to freshen up the site with a new theme. Being me, it doesn’t work completely proper with the initial install and is going to require some tweeking. I’ll be working on that over the next couple days. Also, IE7 Beta3 likes to throwup when trying to connect to the site claiming there’s a DNS error even though Firefox works just fine. Yay beta! [...]
2006-08-02 at 10.56 am
[...] Pekola.net toimii Wordpress julkaisualustalla ja Wordpressistä löytyy Akismet spam-suodin, joka poistaa automaattisesti kaikki spam-kommentit ja -viitteet. Kävin äsken katsomassa filtterin aikaansaannoksia ja tänä aamuna Akismet on poistanut satoja kommentteja eli aika massiivinen hyökkäys. Spam-kommenttien sisältö on samaa roskaa, kuin spam-emailienkin eli online kasino-, viagra- ja muita mainoksia. Kai noihin joku aina haksahtaa, koska eihän spammin lähettäminen muuten kannattaisi. Päivitin pari päivää sitten Wordpressin uusimpaan 2.0.4 versioon ja tuo päivitys kannattaa kaikkien Wp:n käyttäjien tehdä tietoturva-aukon vuoksi. [...]
2006-08-02 at 12.05 pm
[...] Allegedly there is some kind of problem with open registration on Wordpress blogs. Better safe than sorry – make sure you’ve turned off the anyone can register option. [...]
2006-08-02 at 5.42 pm
[...] Worum es sich genau handelt will der Entdecker der Lücke mit dem Pseudonym “Dr Dave” noch nicht verraten, allerdings gibt er zumindest einen Hinweis: Wer nicht gleich aktualisieren kann, sollte zumindest fürs Erste die Benutzerregistrierung für GästInnen deaktivieren. [...]
2006-08-04 at 5.05 am
[...] WE have reactivated user registration after upgrading to WordPress version 2.0.4 last week. We had to temporarily disable the feature after Dr. Dave, Spam Karma creator, alerted bloggers using WordPress to a potential security issue. The recent upgrade has patched this bug. [...]
2006-08-04 at 12.31 pm
[...] There could be a vulnerability in Wordpress. First I read about it here (via Planet Debian), then on the OP (original poster)’s blog. [...]
2006-08-05 at 7.48 am
[...] Източник
Малко повече информация по въпроса [...]
2006-08-08 at 2.10 am
[...] Critical Announcement affecting ALL Wordpress users [...]
2006-08-11 at 2.42 pm
[...] I’ve been noodling around with the idea of a Free For All Friday on Slacker Manager, just to see what would show up. I was gonna do it tomorrow, but then I noticed that maybe it’s not such a good idea. Guess we’ll stay on lockdown around here for now. You can still comment, though. [...]
2006-08-15 at 12.35 pm
[...] Just passing along some news about WordPress: Critical Announcement to All WordPress Users. I think it only affects users who have open user registration activated. I don’t. Anyway, check it out. [...]
2006-08-18 at 3.05 am
[...] The exploit used was described about three weeks ago (July 27th, 2006) when Dr. Dave published his “Critical Announcement affecting ALL Wordpress Users.” All in all, it was a fairly stern warning. I would have upgraded to a newer version of Wordpress but couldn’t because I was travelling: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin >> options: make sure “Anyone can register” is not checked). [...]
2006-08-18 at 10.56 pm
facilitating hack a vulnerability ?
Ok.. So finally Kim did post about my exploit…. (our communication on the subject has been via email so far). I’m not too sure if it should be termed a “hack” though, just because if the intention was to hack, I could have very …
2006-09-15 at 4.26 am
[...] Security Alert! Filed under: General Info, Tips & Tricks by Maria on July 26, 2006 Dr Dave, developer of the must-have spam prevention tool, Spam Karma, sent out the following alert message to all Spam Karma users as an announcement in the Spam Karma administration panel: MAJOR SECURITY ANNOUNCEMENT Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable ‘guest user registration’ on your blog if it’s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke. [...]
2006-09-18 at 3.41 am
[...] Dr Dave, developer of the must-have spam prevention tool, Spam Karma, sent out the following alert message to all Spam Karma users as an announcement in the Spam Karma administration panel: MAJOR SECURITY ANNOUNCEMENT Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable ‘guest user registration’ on your blog if it’s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke. [...]
2006-09-23 at 9.50 am
[...] Authors of popular plugins for WordPress such as Dr. Dave (Spam Karma) are discontinuing their association with WordPress because of some baby mama drama jamma damma. I didn’t really read through everyones blogs to see what everyones points of views were (the main WordPress developers vs. outside WordPress developers) but it seemed basically like the outside people were not liking the way Matt (co-creator and owner of WP) was handling things or maybe it’s because WP might be doing some evil stuff on the side. I guess everyone has their share of drama – even the nerds. Posted by Eric on Saturday, September 23, 2006 12:50 am (Possibly) Related Posts: [...]
2006-12-14 at 9.26 pm
[...] Notre bon docteur Dave, entre autres choses responsables de l’excellent et indispensable plug-in Spam Karma (que votre serviteur préfère à Akismet, en passant) signale une faille de sécurité assez importante pour toutes les versions de WordPress. [...]