back to article FBI to WordPress users: patch now before ISIL defaces you

The United States Federal Bureau of Investigation (FBI) has issued a warning to WordPress users: hurry up and patch your content management system before web site is defaced by ISIL sympathisers. The Bureau has issued a notice titled "ISIL defacements exploiting WordPress vulnerabilities" in which it warns that "Continuous Web …

  1. Destroy All Monsters Silver badge
    Windows

    If the FBI warns that they "noticed something", there is probably not much up

    Still, being defaced by ISIS is probably something that has to be taken more literally than would otherwise be done.

    1. Anonymous Coward
      Anonymous Coward

      Re: If the FBI warns that they "noticed something", there is probably not much up

      If the FBI warns that they "noticed something", there is probably not much up

      Au contraire, I'd say that if even they noticed it must be baaad :).

      Can't say I notice much - I have a public WP site but I keep it to the same rules as I have been building firewalls since before the idea of the URL: do not run anything unless it is absolutely required. That means limiting plugins and themes to what makes the site work, good security including login name and login URL changes (automated by some security plugins) and the use of free OTP (Google Authenticator is your friend), keeping up to date with patching and review 404 logfiles.

      So far, so good :)

  2. AMBxx Silver badge
    Stop

    One to avoid?

    Looking through the changelog, there are XSS bugs fixed in half the updates.

    One classic bugfix is '•Maybe fixed "304 not modified" problem for some users.' I'd like something a bit more definite than that!

  3. Ole Juul

    Automatic Updates

    WordPress has had automatic updates for a long time now and I've been very happy with that on two sites where I use WP. It's been trouble free and nothing has ever broken. I do update plugins by hand though.

    1. Anonymous Coward
      Anonymous Coward

      Re: Automatic Updates

      Automatic updates are a tradeoff as it requires the WP directories to be writeable by Apache.

  4. Robert Ramsay

    Requires a valid nonce?

    I hope it's just my out of date terminology knowledge...

    1. Destroy All Monsters Silver badge
      Childcatcher

      Re: Requires a valid nonce?

      Stop watching BBC.

      Definition - What does Nonce mean?

      A nonce is a type of data bit identification in IT security and other types of technical systems. It is a number or other data variable that is used only once.

      1. Simon Harris
        Coat

        Re: Requires a valid nonce?

        You're talking Nonce Sense.

        (I may have been watching too much Channel 4).

    2. Anonymous Coward
      Anonymous Coward

      Re: Requires a valid nonce?

      @Robert, unfortunately your outdated knowledge is closer to the truth. I recently had a look at WP's perverted nonce code, and... it's NOT a cryptographic nonce (number used once). You can use it as many times as you want for 12-24 hours. Seems near worthless for security purposes.

  5. Stevie

    Bah!

    Frankly, my blog could use the traffic.

  6. Colin Miller

    1.4.3? The 1.4 series of WordPress was released around 2004/2005. The current version is 4.1.1, which was released around the start of this year.

    https://wordpress.org/about/roadmap/ doesn't list all the releases ,

    1. Anonymous Coward
      Anonymous Coward

      It's referring to the version of the WordPress Super Cache plugin, not WP.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like