Forum Moderators: phranque

Message Too Old, No Replies

Wordpress Vulnerability?

saw this in my error log today

         

old_expat

5:38 am on Apr 20, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



[Wed Apr 19 02:45:34 2006] [error] [client 67.19.5.130] File does not exist: /home/spastay/public_html/wordpress/xmlrpc.php

There were a number of others as well.

It looks like someone might be snooping for a way into my server and possibly Wordpress has a weakness?

encyclo

9:53 am on Apr 20, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



It's a pretty old vulnerability - most installations should be patched by now (I hope!):

[webmasterworld.com...]

BertieB

9:58 am on Apr 20, 2006 (gmt 0)

10+ Year Member



Yep, there was an vulnerability revealed last year concerning certain XML-RPC implementations. New versions of WP (certainly anything > V2) should be fine.

[wordpress.org...]

and also from SANS:

[isc.sans.org...]

Also see the thread encyclo posted.