<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SplitMango Media Inc.&#187; blogging software</title>
	<atom:link href="http://www.splitmango.com/tag/blogging-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.splitmango.com</link>
	<description>1800-771-9879</description>
	<lastBuildDate>Mon, 26 Jul 2010 19:19:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Old Versions of WordPress Under Attack</title>
		<link>http://www.splitmango.com/blog/wordpress/old-versions-of-wordpress-under-attack/</link>
		<comments>http://www.splitmango.com/blog/wordpress/old-versions-of-wordpress-under-attack/#comments</comments>
		<pubDate>Sat, 05 Sep 2009 19:04:47 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[blogging software]]></category>
		<category><![CDATA[lorelle]]></category>

		<guid isPermaLink="false">http://www.splitmango.com/?p=500</guid>
		<description><![CDATA[Do you run an older version of WordPress?? You may be vulnerable to an attack! Lorelle on WordPress discovered that a nasty attack is exploiting security holes in previous versions of the blogging software, creating a new “hidden” Administrator account and getting right down to the database level. These attacks are said to be “growing [...]]]></description>
			<content:encoded><![CDATA[<p>Do you run an older version of WordPress?? You may be vulnerable to an attack!</p>
<p><a href="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/" target="_blank">Lorelle on WordPress</a> discovered that a nasty attack is exploiting security holes in previous versions of the blogging software, creating a new “hidden” Administrator account and getting right down to the database level. These attacks are said to be “growing by the hour”. Lorelle writes:</p>
<p><strong>There are two clues that your WordPress site has been attacked.</strong></p>
<ul>
<li>There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&amp;(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFER ER%5D))%7D%7D|.+)&amp;%/. The keywords are &#8220;eval&#8221; and &#8220;base64_decode.&#8221;</li>
<li>The second clue is that a &#8220;back door&#8221; was created by a &#8220;hidden&#8221; Administrator. Check your site users for &#8220;Administrator (2)&#8221; or a name you do not recognize. You will probably be unable to access that account.</li>
</ul>
<p>All users are advised to upgrade to the latest version of WordPress immediately. Let us know if we can help with your upgrade.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.splitmango.com/blog/wordpress/old-versions-of-wordpress-under-attack/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
