#1 (permalink)  
Old 04-13-2008, 02:15 PM
cobwab cobwab is offline
Senior Member
 
Join Date: Nov 2007
Location: Wareham,Swifts Beach,MA USA
Posts: 405
Send a message via Skype™ to cobwab
Default Secuity Breach/hole in WP

Hey,

This looks bad. I googled using keyword "asc" and it gave a reference to my blog, bad-breath-advisor.com. I clicked on it and up came my blog without ever having to go through admin/password. Here th3e google ref:
"
197 results stored on your computer - Hide - About

Bad Breath Advisor › Edit.. - GetWeightedTags(tag" asc" limit) format

SBI Tips and Tricks #031.. - ays=0&postorder=asc&start=0 http:forums
"
I end up in the Plugins:

"Editing UltimateTagWarrior/ultimate-tag-warrior.php"

From here, I gain access to everything concerning my blog without ever having to login.

Is this fixed in 2.5?

If so, we should immediately install 2.5 or risk destruction at the hand of some malevolent hacker.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 04-13-2008, 02:26 PM
Kangaroo Jack Kangaroo Jack is offline
Senior Member
 
Join Date: Jun 2007
Location: MA
Posts: 156
Default

If you feel that has happened you should immediately change your username and password.

Out of curiosity did you give access to your admin to some else?
__________________
Cheers

David
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 04-13-2008, 02:30 PM
Marc Marc is offline
Administrator
Site Admin
 
Join Date: Jan 2007
Posts: 388
Default

hhmm.

I'm going to ask a really silly question here.

Are you using a desktop search and searching your desktop not the web?

This makes me think you may be.

197 results stored on your computer

Its referencing files on your computer.

Unless you didnt copy corectly into here?

Please clarify.

thanks
Marc
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 04-13-2008, 02:35 PM
Kangaroo Jack Kangaroo Jack is offline
Senior Member
 
Join Date: Jun 2007
Location: MA
Posts: 156
Default

Ok I jumped the gun a bit here. I had assumed that what you mentioned was correct. In a sense it is.

Correct me if I'm wrong but like most of us we save the login details on our PC. When we revisit that site/page we are automatically logged in. My guess is that is what happened to you.

I tried the admin and had no luck.

EDIT: I missed that part about being stored on the computer. Thanks Marc.
__________________
Cheers

David

Last edited by Kangaroo Jack : 04-13-2008 at 02:38 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 04-13-2008, 04:59 PM
cobwab cobwab is offline
Senior Member
 
Join Date: Nov 2007
Location: Wareham,Swifts Beach,MA USA
Posts: 405
Send a message via Skype™ to cobwab
Default

I can't reproduce it so I must have been off the web.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 04-14-2008, 11:45 AM
Boris_yo Boris_yo is offline
Senior Member
 
Join Date: Jan 2008
Posts: 225
Post robots.txt

When putting site up, what you should not forget to do is create robots.txt file on top level of your domain.

Edit it and include the following:

Disallow: /wp-content/cache/
Disallow: /wp-content/themes/
Disallow: /wp-content/plugins/
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-login.php
Disallow: /wp-register.php

Disallow: add whatever you don't want to be indexed by search engines
__________________
Proud Member Of AdSense Excellence
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


All times are GMT. The time now is 04:11 PM.


vBulletin style developed by Transverse Styles

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0