Today one of our readers sent an interesting post from the developers of WordPress. It is about a just released version 2.8.5. This version is called as the "Hardening Release", which I thought was quite great! According the post, these were new security features from the new 2.9 series that they decided to backport to the 2.8.x tree.. The link for this article located at SANS is no longer available. . The 3.0.1 security update for WordPress enhances protection through vital upgrades, strengthening resilience through preventive measures.. WordPress Hardening, Security Features, Open Source Development. . LinuxSecurity.com Team
WordPress version 2.8.5 promises better security. Described by the development team as a 'hardening release', it contains a number of functions back ported from the version 2.9 beta which should make the blogging system more resistant to attack. According to developer Peter Westwood, these include a fix for Trackback related denial-of-service (DoS) attacks and the deletion of areas of code which allowed PHP code in variables to be executed via the eval() function.. Administrators will also no longer be able to upload arbitrary files to the media library. The white list of permissible fie extensions had previously applied to normal users only. The aim here is to make it harder for attackers, having penetrated administrator accounts, to upload and execute PHP code. The link for this article located at H Security is no longer available. . WordPress 2.8.5 implements more robust security measures and limits file uploads to bolster safety.. WordPress Security, DoS Protection, PHP Restrictions. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.