WordPress Security Problem

This is from the WordPress development blog and worth noting if you run WordPress as your blog software:

Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation: This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.

This is the kind of thing you pray never happens, but it did and now we’re dealing with it as best we can. Although not all downloads of 2.1.1 were affected, we’re declaring the entire version dangerous and have released a new version 2.1.2 that includes minor updates and entirely verified files. We are also taking lots of measures to ensure something like this can’t happen again, not the least of which is minutely external verification of the download package so we’ll know immediately if something goes wrong for any reason.

Finally, we reset passwords for a number of users with SVN and other access, so you may need to reset your password on the forums before you can login again.


Deprecated: Creation of dynamic property WP_Term::$cat_ID is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 378

Deprecated: Creation of dynamic property WP_Term::$category_count is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 379

Deprecated: Creation of dynamic property WP_Term::$category_description is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 380

Deprecated: Creation of dynamic property WP_Term::$cat_name is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 381

Deprecated: Creation of dynamic property WP_Term::$category_nicename is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 382

Deprecated: Creation of dynamic property WP_Term::$category_parent is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 383
Posted in Technology | Tagged , ,

Random Virgin broadband service

Bah. After years with Telewest, during which the broadband Internet service was pretty damn good, a few days of Virgin being in full control and I’m tearing my hair out.

An outage yesterday – when I actually had a free day to go on the net in the hours of daylight – had me disassembling my PC and mixing up the network connection to my switch because I first assumed my PC was at fault. Then I thought that I had stopped ithe connection working by changing the network cards’ connections to the switch so I randomised these again, then forgot what was connected to what when I started .

Someone phoned up Virgin for me and found that there was an official outage with another 4 hours to go. So my PC had been fine till I started trying to fix it…..

When I phoned up after the official four hours I got an unremittingly chirpy recording that suggested that I reboot my PC and the cable box. Obviously I had tried this about 8 hours earlier, and several times since. But I tried again. Nothing.

This morning, there was still nothing. I came back at 7:30 pm and still had nothing but this time I made my PC reconfigure its network settings and drop its IP & gateway etc. and I connected the PC directly to the cable modem box. (Goodbye, switch. It looks like one PC at a time from now on.) It worked.

Elated, I got online for at least 40 minutes, before the service decided it was too much trouble to keep connected to the Internet and switched off again for five minutes. I have no idea how long it will stay on now.

Losing Sky One is one thing, there are always other alternatives.. (Thanks to Nullfidian for the link to Virgin’s page that explains what TV there will be.) A crappy broadband service would be completely different. It might be a pure coincidence that there happened to be a local service failure in this area at the start of Virgin’s control. I will give them the benfit of the doubt but will be sure to watch the service closely for a while to see if it gets back to Telewest standards.


Deprecated: Creation of dynamic property WP_Term::$cat_ID is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 378

Deprecated: Creation of dynamic property WP_Term::$category_count is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 379

Deprecated: Creation of dynamic property WP_Term::$category_description is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 380

Deprecated: Creation of dynamic property WP_Term::$cat_name is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 381

Deprecated: Creation of dynamic property WP_Term::$category_nicename is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 382

Deprecated: Creation of dynamic property WP_Term::$category_parent is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 383

Deprecated: Creation of dynamic property WP_Term::$cat_ID is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 378

Deprecated: Creation of dynamic property WP_Term::$category_count is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 379

Deprecated: Creation of dynamic property WP_Term::$category_description is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 380

Deprecated: Creation of dynamic property WP_Term::$cat_name is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 381

Deprecated: Creation of dynamic property WP_Term::$category_nicename is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 382

Deprecated: Creation of dynamic property WP_Term::$category_parent is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 383

Deprecated: Creation of dynamic property WP_Term::$cat_ID is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 378

Deprecated: Creation of dynamic property WP_Term::$category_count is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 379

Deprecated: Creation of dynamic property WP_Term::$category_description is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 380

Deprecated: Creation of dynamic property WP_Term::$cat_name is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 381

Deprecated: Creation of dynamic property WP_Term::$category_nicename is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 382

Deprecated: Creation of dynamic property WP_Term::$category_parent is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 383

Deprecated: Creation of dynamic property WP_Term::$cat_ID is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 378

Deprecated: Creation of dynamic property WP_Term::$category_count is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 379

Deprecated: Creation of dynamic property WP_Term::$category_description is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 380

Deprecated: Creation of dynamic property WP_Term::$cat_name is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 381

Deprecated: Creation of dynamic property WP_Term::$category_nicename is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 382

Deprecated: Creation of dynamic property WP_Term::$category_parent is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 383
Posted in Bad Shops, Rants, Technology, Television | Tagged , , , ,

Supplemental Woe

Following on from the expose about McKeith and her crackpottery it is interesting that the news of late has been trumpeting the “dangers” of using vitamin and herbal supplements. Remember one of the main claims of the woo-ers supporting McKeith is that modern medicine kills and all these herbal supplements dont.

It seems (JAMA, vol 297, p842) that this is not the case. The report comes to the following conclusions:

Treatment with beta carotene, vitamin A, and vitamin E may increase mortality. The potential roles of vitamin C and selenium on mortality need further study.

The study found that people taking beta carotene supplements were at 7% greater risk of death than those who were not taking the supplements, and with Vit E it was 4% greater risk. More worryingly, Vitamin A supplementation appeared to increase the risk of mortality by 16%.

Now, there is a bit of a cautionary comment to go with this – this is a “meta analysis” study not a direct study, so there is the possibility that the people being given the supplements were at a greater risk of dying than the general public anyway, however one of the study group has commented “seventy percent of the participants were healthy.” (New Scientist)

Assuming this study is an accurate reflection, it is a nice slap in the face of those who push this woo in the place of retrovirals, immunisation and other “real” medicine 🙂


Deprecated: Creation of dynamic property WP_Term::$cat_ID is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 378

Deprecated: Creation of dynamic property WP_Term::$category_count is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 379

Deprecated: Creation of dynamic property WP_Term::$category_description is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 380

Deprecated: Creation of dynamic property WP_Term::$cat_name is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 381

Deprecated: Creation of dynamic property WP_Term::$category_nicename is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 382

Deprecated: Creation of dynamic property WP_Term::$category_parent is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 383

Deprecated: Creation of dynamic property WP_Term::$cat_ID is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 378

Deprecated: Creation of dynamic property WP_Term::$category_count is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 379

Deprecated: Creation of dynamic property WP_Term::$category_description is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 380

Deprecated: Creation of dynamic property WP_Term::$cat_name is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 381

Deprecated: Creation of dynamic property WP_Term::$category_nicename is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 382

Deprecated: Creation of dynamic property WP_Term::$category_parent is deprecated in /homepages/34/d43362328/htdocs/ydontu/blog/wp-includes/category.php on line 383
Posted in Science, Society | Tagged , , , , , , , ,