This morning one of my web sites was scanned for all 25 of these WordPress plugins. I’m not exactly sure what they are vulnerable to (looking around the web it looks like they can be used to add programs to your web site), but you should confirm that if your site is using one of these plusings, that you have the most recent version installed.
Equifax Spam
I received spam to an email address that I gave to Equifax when I got my credit report. Selling personal info?
Trivia: Anagram Math
Trivia: Twelve plus one is an anagram of eleven plus two.
More Vulnerability Attack Scans
For the past several hours I’ve been attacked (41,322 times and counting!) by many different IP addresses (95 at last count, including a bunch using Amazon Web Services (amazonaws)) looking for many different URLs. They are searching for the broken timthumb.php script, as well as 5a3c2f91dc7ccef6724e602c0d391659.php or 6c8fd79d31461e644cbf23026ff5d19a.php, which is apparently an app to give the world the ability to execute commands on your web server via the web. I’ll post more details if I can figure out how to present in a useful manner.
Logoworks Sharing of Email
Be careful of using Logoworks – they provide their customers’ email addresses to other companies, such as Brandaver
Quote: Steve Jobs
“Don’t waste the time you’re given living someone else’s life.” – Steve Jobs
Quote: Politics
“Politics is so complicated that only zealots get involved.” – Britt Blaser
TimThumb.php Vulnerability Scans
Earlier today one of my web sites was scanned for the timthumb.php script. timthumb is a web application that allows for the site to gather and resize images. The script is included in a lot of WordPress themes, such as the list of 332 themes listed at the bottom of this post. If you are using one of these themes, upgrade it, and confirm that timthumb has been upgraded to address its security problems.
Domains to Block on August 29, 2011
The spam problem, while much better than it was a year ago, is still a problem. My SpamAssassin has received spam from all of these domains, in the last three weeks. I am not asserting that these domains have always been used for spam, or that they are now. But in August 2011 they were.
Misc Update for 2011-08-26
An aftershock just woke me up. USGS preliminary report says it was 4.5