Hundreds of WordPress blogs were hacked during the past few days by attackers who pilfered blogger credentials stored in plain text in the database. The researchers who discovered the attacks say a design flaw in the WordPress blogging platform was the underlying problem because by default it allows users to set up permissions that let anyone read their blog's wp-config.php file configuration files, and because WordPress stores the bloggers' credentials in plain text.. The attackers injected malicious iFrames into the blogs so that any visitors would automatically be infected with malware, including code that spreads fake antivirus software. "A few people got hacked last week and asked us to help," says David Dede, founder of Sucuri Security, which also uses WordPress for its own blog. "We fixed them and in one site, just after we fixed it, it got hacked again. Looking at the logs, we didn't see any access in there at all, so the attack didn't come from the Web." Dede says after further analysis and more complaints of hacked blogs, he and his team found that the blogs were getting hit with a malicious iFrame, and that the blogs were all hosted on Network Solutions' servers. Most were running the newest version of WordPress, 2.9.2, he says The link for this article located at Dark Reading is no longer available. . The attackers injected malicious iFrames into the blogs so that any visitors would automatically be . hundreds, wordpress, blogs, hacked, during, attackers, pilfered, blogger. . LinuxSecurity.com Team
A hacker was able to break into the database of RockYou and obtain 32 million clear-text passwords through an SQL vulnerability. Researchers at database security firm Imperva discovered the flaw in RockYou.com, which provides applications and services for social networking sites like Facebook and MySpace. . Imperva notified the site then issued a warning about the flaw, Amichai Shulman, CTO of Imperva, told SCMagazineUS.com on Tuesday. But before RockYou could fix the bug, at least one hacker, using the alias The link for this article located at SC Magazine is no longer available. . Imperva notified the site then issued a warning about the flaw, Amichai Shulman, CTO of Imperva, tol. hacker, break, database, rockyou, obtain, million, clear-text, passwords. . LinuxSecurity.com Team
Analyst group Gartner has warned administrators to be "more aggressive" when protecting their Oracle applications because they are not getting enough help from the database giant. Gartner published an advisory on its Web site just days after Oracle's latest quarterly patch cycle, which included a total of 103 fixes with 37 related to flaws in the company's database products. Some of the flaws carry Oracle's most serious rating, which means they're easy to exploit and an attack can have a wide impact. . According to the advisory, which was posted by Gartner analyst Rich Mogull on Monday, "the range and seriousness of the vulnerabilities patched in this update cause us great concern.… Oracle has not yet experienced a mass security exploit, but this does not mean that one will never occur." The link for this article located at ZDNet.co.au is no longer available. . According to the advisory, which was posted by Gartner analyst Rich Mogull on Monday, 'the range and. analyst, group, gartner, warned, administrators, aggressive', protecting, their, oracle. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.