Fake WordPress site distributing backdoored release | Zero Day
Fake WordPress site distributing backdoored release | Zero Day (flag)
blogs.zdnet.com — November 6th, 2008 Fake WordPress site distributing backdoored release Posted by Dancho Danchev @ 6:29 am Categories: Hackers , Browsers , Open source , Pen testing , Passwords , Malware , Web 2.0 Tags: Security , EstDomains , Wordprezs , WordPress , Typosquatting , Dancho Danchev Wordprezs Fake ...
Comments
4 Blogs Link to this Story

Fake Wordpress Site Releasing Backdoored Code
TechCrunch — Don't mistype "wordpress.org" because you could end up downloading compromised code. Some hackers have set up www.wordpresz.org. The code sends cookie contents to a hacked program hosted on wordpresz.org and could expose passwords and other identifying information. ...

links for 2008-11-06
Jarrett House North — ... So this is what the campaign web staff were cooking up in their spare time. (tags: 2008 election obama) Fake WordPress site distributing backdoored release | Zero Day | ZDNet.com Social engineering, fake domain, and ...

I hereby urge all to read the article "Obama's world" in this week's edition of The Economist. Superb journalism! I hope Obama reads it too.
Politweets — ... :-) 1:37 AM yesterday from TwitterFox in reply to marks Wow. Facebook launches their enterprise cloud named Force.com: http://tinyurl.com/6bqglj 8:43 AM Nov 6th from TwitterFox @ tveskov : Wow, it can even use your FriendFeed info to import the services you've already imported into FriendFeed. That's nice! 8:17 AM Nov 6th from TwitterFox in reply to tveskov Don't download your WordPress from wordpresz.org: http://blogs.zdnet.com/secu... 8:13 AM Nov 6th from TwitterFox I won't make it ...

Fake WordPress site distributing 2.6.4 backdoored release
D' Technology Weblog — ... The backdoored pluggable.php file attempts to send the stolen data to wordpresz.org/tuk.php which is still accepting cookies if the requests are properly formatted. The spoof is a nearly perfect combination of social engineering, typosquatting and the natural EstDomains connection as the domain registrar, nearly perfect in the sense that they couldn’t duplicate the whole WordPress.org potentially raising suspicion at the end user’s end. Full Article ...

Related Content
WordPress 2.7 - 20 Must See Features
mashable.com 12/8/2008 — WordPress is quickly becoming the standard software for the majority of blogs. This fact makes every major release of the software seem like a huge event, but the thing is that this time it is. WordPress 2.7 comes with a huge number of changes, a ...
WordPress is quickly becoming the standard software for the majority of blogs. This fact makes every major release of the software seem like a huge event, but the thing is that this time it is. WordPress 2.7 comes with a huge number of changes, a ...
WordPress 2.7: If You Don't Like It, Change It
www.readwriteweb.com 12/11/2008 — The last time WordPress - the popular open source blogging platform - changed their user interface, they got a reaction. And it wasn't positive. Even diehard fans were questioning the reasoning behind the changes, trying to figure out ways to work ...
The last time WordPress - the popular open source blogging platform - changed their user interface, they got a reaction. And it wasn't positive. Even diehard fans were questioning the reasoning behind the changes, trying to figure out ways to work ...
New WordPress 2.7 Paves the Way for WordPress Social Networks
blog.wired.com 12/11/2008 — The popular open source blogging software WordPress has officially released version 2.7, a significant upgrade that makes huge improvements to the user interface, and, more importantly, according to founder Matt Mullenweg, the new code lays the ...
The popular open source blogging software WordPress has officially released version 2.7, a significant upgrade that makes huge improvements to the user interface, and, more importantly, according to founder Matt Mullenweg, the new code lays the ...
WordPress 2.7 Sees The Light Of Day
performancing.com 12/11/2008 — WordPress logo It didn't take long for the team to release WordPress 2.7 after RC2 was released just a few hours prior. Despite any confusion that may arise from two versions being released in the same day, I highly encourage anyone that is using ...
WordPress logo It didn't take long for the team to release WordPress 2.7 after RC2 was released just a few hours prior. Despite any confusion that may arise from two versions being released in the same day, I highly encourage anyone that is using ...
A Journey Through Five Years of WordPress Interface.
planetozh.com 12/17/2008 — With the recently launched WordPress 2.7, bloggers now marvel at how clean, beautiful and usable is the new interface. But do you remember what it used to be a couple of months ago? For those who started using WordPress years ago, can you remember ...
With the recently launched WordPress 2.7, bloggers now marvel at how clean, beautiful and usable is the new interface. But do you remember what it used to be a couple of months ago? For those who started using WordPress years ago, can you remember ...
WordPress
www.linkedin.com 10/29/2008 — Developed By WordPress Category Utility Display Settings When you add an Application, you are allowing it to access profile information about you and your connections which the Application uses to provide the service. This and other information you ...
Developed By WordPress Category Utility Display Settings When you add an Application, you are allowing it to access profile information about you and your connections which the Application uses to provide the service. This and other information you ...
Wordpress 2.7: Faster, Customizable, With Automatic Updates
mashable.com 12/11/2008 — The new version of Wordpress - version 2.7, codenamed “Coltrane” - is now available, and I’ll skip to the part I think users will like the most: no more manual updates. That’s right, the new Wordpress now has an automatic ...
The new version of Wordpress - version 2.7, codenamed “Coltrane” - is now available, and I’ll skip to the part I think users will like the most: no more manual updates. That’s right, the new Wordpress now has an automatic ...
WordPress Downloads Cross the 3 Million Mark
www.labnol.org 11/14/2008 — At exactly 9:25 PM PST today, the download counter at WordPress touched the 3 million mark . That mean WordPress 2.6 self-hosted software has been downloaded more than 3 million times from wordpress.org. Congrats Matt and WordPress team . I was ...
At exactly 9:25 PM PST today, the download counter at WordPress touched the 3 million mark . That mean WordPress 2.6 self-hosted software has been downloaded more than 3 million times from wordpress.org. Congrats Matt and WordPress team . I was ...
WordPress 2.7 upgrade in one line
hackaday.com 12/11/2008 — BadPoetry WordPress 2.7 has just been released and features a complete interface overhaul. Hack a Day runs on WordPress MU hosted by WordPress.com , so we got this update last week. We run standard WordPress.org on all of our personal blogs ...
BadPoetry WordPress 2.7 has just been released and features a complete interface overhaul. Hack a Day runs on WordPress MU hosted by WordPress.com , so we got this update last week. We run standard WordPress.org on all of our personal blogs ...
If WordPress 2.7 Was A Movie…
en.blog.wordpress.com 11/7/2008 — This would be our trailer. Check out some of the upcoming new features and design changes in this sneak preview video, including how to customize your dashboard, the new comment reply feature, the new navigation system, and the customizable posting ...
This would be our trailer. Check out some of the upcoming new features and design changes in this sneak preview video, including how to customize your dashboard, the new comment reply feature, the new navigation system, and the customizable posting ...
WordPress 2.7 Simplifies Administration, Content CreationInformationWeek - All Stories And Blogs 11/5/2008
WordPress 2.7 Beta 1 was released this past weekend , and although it's always tough to make a full assessment based on beta software, its improvements to the administrative functions are making it look like a compelling upgrade.
Fake site punts Trojanised WordPressThe Register 11/6/2008
Backdoored blogging code blag Fraudsters have set up a fake site featuring a backdoored version of the WordPress blogging application as part of a sophisticated malware-based attack.…