Don’t let this happen to you
July 16th, 2008Upgrade your version of WordPress to the latest release (currently 2.6 as of 7/16/08) right away. And keep it up to date.
Tonight I’ve spent some trying to help someone whose WordPress blog got hacked. It’s not a pretty site. His blog is downloading viruses and trojan horses to anyone who visits it, and Google has banned the site and most modern browsers are throwing up huge warning pages before they let anyone through.
Not good for business. Don’t let this happen to you. Keep your version of WordPress up to date.
This person was still running version 2.2 which is over a year out of date and has a number of documented security problems. If your blog is still running 2.2 — run don’t walk to your computer and upgrade. If you’re at 2.3.3, you’re in slightly better shape, but you should still upgrade. In fact, just upgrade everytime WordPress releases a new version and you’ll be safe.
The latest release 2.6, is the most secure ever, and has some core security improvements that make it harder to hack than ever.
Why does this happen?
It happens becaused WordPress is the world’s most powerful and popular blogging software, and so there are literally thousands of people working day and night trying to find the slightest security breach in the WordPress core files. Why? Because they know if they can find a security breach, they can write software that will troll the internet injecting links to their spammy sites and viruses into hundreds of thousands of WordPress blogs.
That’s the bad news. The good news is that the heroic folks at WordPress are constantly plugging these holes and making WordPress more and more secure all the time.
So, please upgrade. I know it can seem scary at first — but it’s really as easy as
- Backup your blog (never skip this)
- using FTP, delete the old core files (don’t delete “wp-config.php” or “wp-content” folder)
- using FTP, upload new files from http://www.wordpress.org/download (but don’t upload “wp-content” folder).
If you’ve never done it before, please read and watch this post on backing up your blog, and this post on upgrading wordpress.
Don’t say I didn’t warn you!
Oh, and another tip: if you’ve let your blog stay out of date for a long time, change all your login passwords. Sometimes if your blog get’s hacked, the hackers can keep your password and then it won’t even help if you upgrade because they still have your password.









