Watch Out for Recent WordPress Gumblar PHP Exploit

May 12, 2009 · 70 comments

Kristi wrote a guest blog post at TechJaws about the attack last weekend on her well known Kikolani Blog by the PHP Script Injection Exploit in WordPress 2.7.1.  Kristi explains how she restored her blog and dealt with the issue. The UnMask Parasites blog provides additional details on what is known about this particular malware which has been dubbed the Gumblar .cn Exploit.

Gumblar exploit does NOT affect only WordPress. It can target any site using .php including Drupal, PhotoPost and even the Bangalore Telecom Web site.

The resources below will assist you in assessing your risk, increasing security for your WordPress blog and removing this exploit if you are already affected.

WordPress Security Resources:

Security Monitoring Tools for WordPress:

WordPress Security Audit Services:

WordPress Security Plugins:

Stay In The Loop!

Subscribe to the GrowMap feed via RSS or Email to receive notifications when new posts are published. Follow GrowMap on Twitter too!

{ 1 trackback }

Watch Out for Recent WordPress Gumblar PHP Exploit | GROWMAP.COM
May 13, 2009 at 2:02 am

{ 69 comments… read them below or add one }

instockphones from best cricket phones January 5, 2010 at 7:54 am

Twitter: @muqtada123

I have noticed that in the recent google PR update, it does not update the PR for most blogs powered by WP and this could be the reason that why google did this.

Reply

Leave a Comment

CommentLuv Enabled

This site uses KeywordLuv. Enter YourName@YourKeywords in the Name field to take advantage.

*
To prove you're a person (not a spam script), type the answer to the math equation shown in the picture. Click on the picture to hear an audio file of the equation.
Click to hear an audio file of the anti-spam equation

Previous post: How to Create a Successful Blog Based Business

Next post: Intelligent Bloggers to Consider Reading