Questioning WordPress Security - Roundup

Back in April news broke of a num­ber of Word­Press powered sites being com­prom­ised and redir­ect­ing vis­it­ors to mali­cious sites. At that time the prob­lem seemed to be lim­ited to Net­work Solu­tions shared host­ing cus­tom­ers but more recently sim­ilar exploits have been encountered by GoDaddy cus­tom­ers. At this point it seems that not only Word­Press but other PHP based soft­ware, such as Zen­Cart and Joomla, and static HTML web­sites have also been compromised.

Imprisonment
Photo From Daz­zie D

I’ve been keep­ing an eye on this story and when I saw that the Explict­Web Pod­cast were inter­view­ing Word­Press con­trib­ut­ing developer Andrew Nacin I asked, via twit­ter, if they could get his com­ments on the issue. Sadly there was not enough time to get his response on the show, but he kindly replied to my ques­tion on his blog.

Andrew points out that Net­work Solu­tions have already owned up to the fact that it was their fault and noth­ing to do with Word­Press, cit­ing the prob­lem was due to a ‘com­plex com­bin­a­tion of factors’. In a later post they explain more fully what the attack­ers did and I hope we also see the res­ults of secur­ity ana­lysts work­ing on the prob­lem as to what mis-configurations or weak­nesses were exploited.

For those who run web­sites, it might be time to think about the qual­ity of your host­ing. Shared host­ing solu­tions are cheap but it is hard to bal­ance low-cost with secur­ity and performance.

Pos­sibly Related Posts

3 thoughts on “Questioning WordPress Security - Roundup

  1. Pingback: Tweets that mention Questioning WordPress Security – Roundup | steveblamey.co.uk -- Topsy.com

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>