{"id":874,"date":"2008-11-03T21:58:23","date_gmt":"2008-11-03T20:58:23","guid":{"rendered":"http:\/\/www.craigmurphy.com\/blog\/?p=874"},"modified":"2010-02-27T12:10:12","modified_gmt":"2010-02-27T11:10:12","slug":"wordpresz-264-fake","status":"publish","type":"post","link":"http:\/\/www.craigmurphy.com\/blog\/?p=874","title":{"rendered":"WordPresz 2.6.4 &#8211; fake?"},"content":{"rendered":"<p>When I logged into my admin account for my WordPress blog, I was surprised to find this waiting for me in the dashboard:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.craigmurphy.com\/blog\/wp-content\/uploads\/2008\/11\/wordpresz264.jpg\" style=\"border:none\" \/><\/p>\n<p><strong>UPDATE 07\/11\/2008:<\/strong> <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=887\">Watch<\/a> a short (less than 60 seconds) video demonstrating the dashboard hijack.<\/p>\n<p><strong>UPDATE 08\/11\/2008:<\/strong> <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=896\">Cleaning up after the WordPress 2.6.4 incident<\/a>.  Note that I did not install the fake 2.6.4, so it&#8217;s not a clean up for that scenario.  <\/p>\n<p><strong>Wordpresz.org<\/strong> appears to be a spoof of wordpress.org.  With the exception of the download link and one or two others (Facebook link, etc.) all the pages lead back to the front\/home page.<\/p>\n<p>I&#8217;ve just downloaded the wordpresz 2.6.4 offering to see what&#8217;s different.  If I find anything, and if time permits, I&#8217;ll update this post.  <\/p>\n<p><strong>22:26 UPDATE<\/strong><br \/>\nJust looking at the respective home pages for WordPresz.org vs WordPress.org, a few differences jump out &#8211; check out items 1, 2 and 3 below.  <\/p>\n<p>Item 1 &#8211; the download size is too round and is incorrect, it should be about 1.4mb in this case.  <\/p>\n<p>Item 2 &#8211; these are randomised over at WordPress.org, but are static at WordPresz.org.  <\/p>\n<p>Item 3 &#8211; The real WordPress.org has a &#8220;Showcase&#8221; link included.<\/p>\n<p>Indeed, the source for both home pages reveals that WordPresz.org is simply an earlier snapshot of WordPress.org.  <\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.craigmurphy.com\/blog\/wp-content\/uploads\/2008\/11\/wordpresz264_1.jpg\" style=\"border:none\" \/><\/p>\n<p>Looking at domain data for WordPresz.org, there are a few holes here.  Google hasn&#8217;t indexed this site?  What about the Alexa ranking?<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.craigmurphy.com\/blog\/wp-content\/uploads\/2008\/11\/wordpresz_dom.jpg\" style=\"border:none\" \/><\/p>\n<p>Whereas, WordPress.org is pretty popular with Google and has an Alexa ranking.<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.craigmurphy.com\/blog\/wp-content\/uploads\/2008\/11\/wordpress_dom.jpg\" style=\"border:none\" \/><\/p>\n<p>23:59 UPDATE<br \/>\nVia <a href=\"http:\/\/wordpress.org\/support\/profile\/210942\">Clayton<\/a>, <a href=\"http:\/\/www.securityfocus.com\/archive\/1\/490887\/30\/0\/threaded\">this<\/a> may well be part of the problem.  There&#8217;s further <a href=\"http:\/\/wordpress.org\/support\/topic\/214908\">comment<\/a> on the WordPress support forum too.  I&#8217;ve since upgraded to 2.6.3 via the WordPress.org download.  <\/p>\n<p>The moral of this story: keep on top of WordPress updates and security fixes.<\/p>\n<p>**<\/p>\n<p><em>Images grabbed using <a href=\"http:\/\/www.techsmith.com\/\">TechSmith<\/a>&#8216;s <a href=\"http:\/\/www.techsmith.com\/screen-capture.asp\">SnagIt<\/a> &#8211; an essential tool for developers and bloggers alike.  With thanks to <a href=\"http:\/\/twitter.com\/betsyweber\">Betsy Weber<\/a><\/em><\/p>\n<p>Technorati Tags: <a href=\"http:\/\/technorati.com\/tag\/WordPress\" rel=\"tag\">WordPress<\/a>, <a href=\"http:\/\/technorati.com\/tag\/WordPresz\" rel=\"tag\">WordPresz<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When I logged into my admin account for my WordPress blog, I was surprised to find this waiting for me in the dashboard: UPDATE 07\/11\/2008: Watch a short (less than 60 seconds) video demonstrating the dashboard hijack. UPDATE 08\/11\/2008: Cleaning up after the WordPress 2.6.4 incident. Note that I did not install the fake 2.6.4, &hellip; <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=874\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">WordPresz 2.6.4 &#8211; fake?<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[168,34,167,166],"class_list":["post-874","post","type-post","status-publish","format-standard","hentry","category-security","tag-hack","tag-wordpress","tag-wordpress-hack","tag-wordpresz"],"_links":{"self":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=874"}],"version-history":[{"count":7,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/874\/revisions"}],"predecessor-version":[{"id":1656,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/874\/revisions\/1656"}],"wp:attachment":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=874"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}