Security Threat: WordPress Under Attack
techcrunch.com
techcrunch.com
Wordpress security is a pain in the keister, though. You can reduce your risk by:
1) Making regular backups (I like automysqlbackup.sh.) Comprehensive compromise of a Wordpress installation is only really recoverable by wiping and starting over, unless you want to find that your forgotten posts from 3 years ago are linking to viagra pharmacies.
2) Putting every Wordpress installation in its own DB with its own DB user. Don't use root. I have a script which installs WP for me and creates the new DB, creates the new user, and gives the user an insanely difficult password because it will never actually be typed by a human.
3) Making sure the Wordpress directories can't get written to by the server. I go as far as blocking the uploads, which means I have to do some chmod magic when uploading things.
4) If you can put up with the nuisance, protect the wp-admin directory at the web server level, for example by denying all IPs but your own, or by putting it under HTTP Basic authentication. That will cut down drastically on the number of automated probes that hit you. You don't have to run faster than the tiger, you just have to run faster than the other guy the tiger is chasing...
If you install and set up Wordpress Mu [1], you can run all those blogs off of a single installation, and then not only do you have a contralized install to manage plugins and themes, but it's far easier to keep a single install up to date compared to twelve or more...
Check out: http://designblurb.com/remove-wordpress-generator-meta-tag-h...
It's preferable write a exploit of find a flaw in something so widespread and carpet bomb them all instead of doing the same for a rarely used piece of software.
vBulletin and Mediawiki are also incredibly popular. But they have nothing resembling the rap sheet that WordPress has.
Try another argument.
It could easily be expanded to also look at $_POST data which is another form of attack you'll never see in your logs.
Of course updating is not enough.
That's why the Obama campaign used Movable Type instead of WP.