WordPress 2.1.1 Critical Security Alert - Download Upgrade to 2.1.2 WordPress的2.1.1臨界安全警報-下載升級到2 .1.2

WordPress WordPress的 developer community has labeled and classified the entire version 2.1.1 of WordPress release dangerous with serious security threat and unsafe to use in production environment.開發者社區已標記和分類整個版本2.1.1發布WordPress的危險與嚴重的安全威脅和不安全的使用在生產環境。 WordPress users who are using WordPress v2.1.1, especially those who just downloaded it over the last 4 or 5 days, should immediately download the latest version 2.1.2 of WordPress and upgrade their installation by overwriting all old files fully. WordPress的用戶誰使用WordPress的v2.1.1 ,尤其是那些誰剛剛下載它在過去的4年或5天,應立即下載最新版本2.1.2的WordPress的升級安裝覆蓋所有的舊檔案完全。 Apparently, a hacker or cracker had managed to hack into a server hosting wordpress.org, and gained user-level access to modify the download file of WordPress to include security-comprised exploitable code.顯然,黑客或黑客已設法侵入一台服務器託管wordpress.org ,並獲得用戶級訪問修改下載文件的WordPress的,包括安全包括利用代碼。

According to WordPress blog WordPress的博客 :

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file.這是確定一個裂解裝置獲得了用戶級訪問的一個服務器上,權力wordpress.org ,並利用這個機會來修改下載文件。 We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack.我們已鎖定該服務器為進一步取證,但在這個時候看來2.1.1下載是唯一的事情所感動攻擊。 They modified two files in WP (theme.php and feed.php) to include code that would allow for remote PHP execution.他們修改兩個文件中可濕性粉劑( theme.php和feed.php ) ,包括代碼,將允許遠程PHP的執行。

If you have any questions on this security hole, you can email如果您有任何問題關於這個安全漏洞,你可以通過電子郵件 21securityfaq@wordpress.org .

Download and install the latest version of Wordpress (version 2.1.2) from下載並安裝最新版本的WordPress的( 2.1.2版)由 Download page下載頁面 to patch the security hole.修補了安全漏洞。 Or download from或下載 direct download link for ZIP file直接下載鏈接為ZIP文件 .

Update:更新: WordPress 2.2 WordPress的2.2 released for download.發布供下載。

IMPORTANT : This is a machine translated page which is provided "as is" without warranty. 重要說明:這是一台機器翻譯網頁這是“原樣”提供,無保修。 Machine translation may be difficult to understand.機器翻譯可能很難理解。 Please refer to請參閱 original English article英文原文的文章 whenever possible.只要有可能。

Share and contribute or get technical support and help at共享和貢獻或獲得技術支持和幫助 My Digital Life Forums 我的數字生活論壇 .



One Response to “WordPress 2.1.1 Critical Security Alert - Download Upgrade to 2.1.2”一對“ WordPress的2.1.1臨界安全警報-下載升級到2 .1.2”

  1. sweetjessyfc
    July 5th, 2007 19:37 07年七月5日19:37
    1

    Hi,嗨,
    I’ma 35 years old woman, divorced and with children.我是一名35歲女子,離婚和兒童。 I work as bar tender, part-time, so I can use the time to take care of the house and kids and and I’ve found my equilibrium doing like this.我工作的酒吧招標,部分時間,這樣我就可以利用這些時間照顧家和孩子,和我發現我的平衡這樣做。 During the endless spent in my house i like to do something, in particular that is watching movies on my在無休止的花費在我的房子我想做些什麼,尤其是看電影是我的 satellite衛星 . I also adore to see classic movies.我也喜歡看經典電影。 I don’t dislikenot at every hour but often to see the wheater forecast either.我不dislikenot在每一個小時,但往往看到惠特預測的。
    I am enough sadisfied with my life and overall about my children.我有足夠的sadisfied我的生活和整體約我的孩子。 I just hope to stay health, so just an normal happy life.我只希望保持健康,所以只是一個正常幸福的生活。
    Bye附屬的
    Jessica傑西卡

Leave a Reply留下一個回复

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> 您可以使用這些標籤: href="" title="">的<a <abbr title=""> <acronym title="">的<b> <blockquote cite=""> <cite>的<code> “刪除日期時間= “ ” “的<em> <i> <q cite=""> <strike>的<strong>

Subscribe without commenting訂閱沒有評論


Custom Search

New Articles新文章

Incoming Search Terms for the Article收到的搜索字詞的文章

upgrade red alert 2 升級紅色警報2 - - red alert 2 upgrade 紅色警戒2升級 - - ReCycle 2.1.2 update 回收站2.1.2更新 - - security alert, not allow file, downloaded 安全警戒,不允許文件,下載 - - Printer Status and Alerts:download 打印機狀態和快訊:下載 - - ReCycle 2.1.2 upgrade 回收站2.1.2升級 - - ReCycle 2.1.2 free download 回收站2.1.2免費下載 - - SECURITY ALERT DOWNLOAD 安全警報下載 - - red alert download upgreat 紅色警報下載upgreat - - download files which need to upgrade in red alert 2 in internet 下載文件需要升級紅色警報2互聯網 - - downlowd upgrade downlowd升級 - - Recycle+2.1.2+Patch+Vista 回收站+2.1.2 +補丁+ Vista的 - - Review of BurnAware Professional v2.1.1 審查BurnAware專業v2.1.1 - - wordpress 2.1 hacked WordPress的2.1砍死 - - ReCycle 2.1.2 update patch 回收站2.1.2更新補丁 - - update wordpress 2.1 to 2.7 更新WordPress的2月1日至二月七日 - - windows upgrade to 2.1 窗戶升級到2.1 - - Red Alert 2 + Upgrade 紅色警報2 +升級 - - Crit Alert download 危重快訊下載 - - sequrity alert download 安全性警報下載 - - red alert upgrade 紅色警報升級 - - download red alert 2 arabic 下載紅色警報2阿拉伯語 - - Download movies free sex strong French women 電影免費下載色情強大的法國婦女 - - Red Alert-Download 紅色警報下載 - - recycle 2.1.2 megaupload 回收2.1.2 megaupload - - download update auto B+2.1.2 自動下載更新乙+2.1.2 - - wordpress 2.1 google reader security WordPress的2.1谷歌閱讀器安全 - - auto B+2.1. 汽車乙2.1 。 - - free critical upgrades 免費升級的關鍵 - -