Skip to content

Gossamer Web Design

Websites That Work (530) 583-7989

  • Tahoe Reno Web Design
    • Divi
    • Elementor
    • Open Source
    • WordPress
  • Search Engine Optimization
  • Web Design Services
    • Advertising
    • Google Apps
  • System Administration
    • Postfix + Amavis + OpenDKIM + SPF
    • Postfix Service Matrix
  • Contact
    • Cart
    • Checkout
    • My account
    • Shop
  • Resume

WordPress 2.8.4,1 Upgrade

August 13, 2009August 13, 2009 adminAdmin, WordPress

Today we received a security notice:

Affected package: wordpress-2.8.2,1
Type of problem: wordpress — remote admin password reset vulnerability.
Description:
WordPress reports:

A specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner.

References:

  • URL: <http://wordpress.org/development/2009/08/2-8-4-security-release/>
  • URL: <http://www.milw0rm.com/exploits/9410>

Affects:

  • wordpress <2.8.4,1
  • de-wordpress <2.8.4
  • wordpress-mu <2.8.4a

Our installations of WordPress and WordPress-MU have been updated.

In addition, a review of our logs revealed several hack attempts using admin_topic_action_logging.php. Apparently some IBM systems are vulnerable to this exploit. The offending IPs have been banned from our server.

Admin AccountAttackerHackIpsLogsLt 2Milw0rmPassword ResetRemote AdminSecurity CheckSecurity NoticeSecurity ReleaseUrlVulnerability Description
  • Pages

    • Tahoe Reno Web Design
      • Divi
      • Elementor
      • Open Source
      • WordPress
    • Search Engine Optimization
    • Web Design Services
      • Advertising
      • Google Apps
    • System Administration
      • Postfix + Amavis + OpenDKIM + SPF
      • Postfix Service Matrix
    • Contact
      • Cart
      • Checkout
      • My account
      • Shop
    • Resume
  • Archives

    • November 2025
    • October 2025
    • September 2025
    • April 2025
    • March 2020
    • February 2020
    • February 2017
    • December 2016
    • November 2016
    • October 2016
    • September 2016
    • June 2012
    • March 2012
    • February 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • April 2011
    • March 2011
    • December 2010
    • August 2010
    • June 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
  • Categories

    • Admin (84)
    • Email (12)
    • Flash (2)
    • google (3)
    • Hp (1)
    • Perl (18)
    • PHP (18)
    • Press Releases (4)
    • Resume (20)
    • Security (1)
    • SEO (4)
    • Specials (1)
    • Uncategorized (8)
    • Unix (36)
    • Web Design (9)
    • Windows (9)
    • WordPress (39)
    • Yoder Group (1)

Gossamer Web Design

Tahoe Reno, NV
530 583-7989
  • Tahoe Reno Web Design
  • Search Engine Optimization
  • Web Design Services
  • System Administration
  • Contact
  • Resume
Powered by WordPress | Theme: Astrid by aThemes.

Web Design by Gossamer

All Rights Reserved © Gossamer Computer Services