Wordpress 1.5.1.3 now available.

Listen to article

たった3時間前に、WordpressがStrayHorn v1.5.1.3の最新セキュリティアップデートをリリースしました。ぜひブログをアップグレードしてください。

After the recent security breach of PCIJ's blog, I believe that bloggers will be more aware of the importance of regularly updating their web softwares. Along with WP, PHPNuke and PhpBB are two of the most widely exploited web apps. WP is quick in releasing patches and updates, while phpBB (now v2.0.16) regularly releases new updates as well.

脆弱性を知っている人なら誰でも簡単に悪用でき、あなたのサイトが不運な標的になる可能性があります。PCIJはまだ幸運です。スクリプトキディ(一般的に呼ばれるハッカーではなく)はホスティングアカウントへのアクセスが限定的で、WPの穴からログインしただけなので、そうでなければすべてのファイルを消去されていたでしょう。

React to this article:
Written by
Abe Olandres

Abe Olandres

Editor-in-chief

Abe is the founder and Editor-in-Chief of YugaTech with over 20 years of experience in the technology industry. He is one of the pioneers of blogging in the country and is considered by many as the Father of Tech Blogging in the Philippines.

View all posts by Abe Olandres →

24 Comments

PO
Porn Search Engine · 20 years ago

Please visit this Porn Search Engine to search for movies and pictures.

Reply
AB
Abe Olandres Editor-in-chief · 21 years ago

Here’s an in-depth dissection of the changes in WP 1.5.1.3: http://elliottback.com/wp/archives/2005/06/29/wordpress-153-security-fixes/

Reply
MA
markku · 21 years ago

Only 4 core files were changed:

xmlrpc.php
wp-admin/post.php
wp-includes/functions-post.php
wp-includes/version.php

Reply
FL
Fleeb · 21 years ago

How about asking the WP guys to allow placing of their WP includes outside of public_html? Hmm…

Reply
MI
Migs · 21 years ago

install Apache mod_security if you can.

Reply
AN
AnP · 21 years ago

i upgraded pero I can’t see the diff.

Reply
AB
Abe Olandres Editor-in-chief · 21 years ago

@ hoop

Now that you mentioned it… ;) :D

Reply
MR
mr nice ash · 21 years ago

probably. but it can be helped always.

Reply
HO
hoop · 21 years ago

I think it would be best practice to add a web directory password for the wp-admin folder. Would in effect add another security layer to the site.

Reply
AB
Abe Olandres Editor-in-chief · 21 years ago

Just upgraded myself… :D

@Jaypee, someone got a user level to enable them to post an entry. That’s all that was done actually.

Reply
HO
hoop · 21 years ago

Thanks Yuga!

Just updated my blog.

Followed this link to upgrade from 1.5.1.2 to 1.5.1.3

Reply
JA
Jaypee · 21 years ago

Salamat sa update. Ano nangyari sa blog ng PCIJ? nadelete ang ibang files? na vandalize ba? :D

Reply

Leave a Reply

Loading next article...