Filtered By: Scitech
SciTech

Wordpress catches hackers red-handed


Open-source blog and publishing platform WordPress intercepted this week what could have been an attempt by hackers to break in to it by placing backdoors on three of its popular plug-ins. In a blog post, WordPress said it has temporarily shut down access to the plug-in repository and forced users to reset their passwords as a security precaution. "We’re still investigating what happened, but as a prophylactic measure we’ve decided to force-reset all passwords on WordPress.org. To use the forums, trac, or commit to a plugin or theme, you’ll need to reset your password to a new one. (Same for bbPress.org and BuddyPress.org.)," WordPress founder Matt Mullenweg said. He said that the WordPress team noticed suspicious commits to popular plugins such as AddThis, WPtouch, and W3 Total Cache. These plugins were found to contain "cleverly disguised backdoors," he said. "We determined the commits were not from the authors, rolled them back, pushed updates to the plugins, and shut down access to the plugin repository while we looked for anything else unsavory," Mullenweg said. He advised users to make sure to never use the same password for two different services, and encouraged them not to reset your passwords to be the same as their old ones. "If you use AddThis, WPtouch, or W3 Total Cache and there’s a possibility you could have updated in the past day, make sure to visit your updates page and upgrade each to the latest version," he added. Computer security firm Sophos said Web-based backdoors can be extremely dangerous. "If you're a WordPress user, you'll know that the WordPress platform includes a complete and powerful administration interface, password-protected, via a URL such as 'site.example/wp-admin.' A WordPress backdoor might offer something with similar functionality, but using a different, unexpected, URL, and using a password known to the hacker, instead of to you," Sophos Asia Pacific head of technology in Asia PAcific Paul Ducklin said. — TJD, GMA News