WP 2.3.3 does not close injection spam loophole

by Aziz Poonawalla on March 16, 2008

Over a month ago, I’d upgraded to WordPress v2.3.3 which addressed a security hole that was permitting spammers to “inject” spammy links directly into posts via xmlrpc.php, and thereby avoid the “nofollow” attribute that is automatically applied to links in comments (to deprive comment spammers of the PageRank mojo they seek). The spam was surrounded by “noscript” HTML tags, which meant that they were invisible in the browser, thus hiding the links from detection and removal. However, subscribers to the blog feed can see the spam since RSS readers ignore javascript markup.

However, on my latest post at my geekblog, I was hit by the injection spam again. I have sent the following email to wordpress security (security @ wordpress.org)

Hello,

I have a WordPress blog at domain http://haibane.info which was upgraded to 2.3.3 as soon as the security release came out last month. I had experienced the injection spam attack detailed here:

http://wordpress.org/support/topic/151368

and upgraded to 2.3.3, but on my most recent post I have seen the same spam attack occur. The post is here:

http://www.haibane.info/2008/03/16/google-42/

and I have already removed the injection spam, but am reprinting it below :

<noscript><a href="http://www.casinomejor. es/casino-online- basico.html">casino online</a> mirar sus oponentes h�bitos.</noscript>

<noscript>Il <a href="http://www.qualitapoker .com/neteller-game-poker.html">http://www.qualitapoker .com/neteller-game- poker.html</a> � un gioco di carte.</noscript>

(there were two separate injections into the same post)

I am disabling user registration as a precautionary measure but it is clear that the 2.3.3 release did not solve the problem.

I recommend closing user registration on all WP blogs for the time being. Peter’s captcha plugins make user registration obsolete for commenting, anyway.

{ 3 comments… read them below or add one }

1 Donncha O Caoimh March 17, 2008 at 3:48 am

I think your blog was probably attacked before you upgraded and the hackers got your login cookie using some Javascript. Best thing to do is change your password!

2 Aziz Poonawalla March 17, 2008 at 5:31 am

I upgraded that blog the day of the 2.3.3 release, because I’d been hit before. So merely upgrading the blog doesn’t remove the vulnerability?

I am going ahead and changing the passwords. Thats probably best practice anyway.

3 ScottS-M March 17, 2008 at 10:07 am

Cookie hijacking is different than they were using before wasn’t it? Funny they’d go through the trouble of getting that and then fall back to the same sort of spam as before.

Leave a Comment

*
To prove you're a person (not a spam script), type the answer to the math equation shown in the picture. Click on the picture to hear an audio file of the equation.
Click to hear an audio file of the anti-spam equation

Previous post:

Next post:

viagra 100mg england
best price for propecia online
canada viagra generic
get cialis
viagra prescriptions
cost of cialis
generic cialis sale
cialis canada
buy online propecia
bleak house movie
lowest propecia prices
real cialis
buy cialis us
cialis next day
levitra viagra online
cialis and ketoconazole
buy viagra cialis levitra
cialis endurance
best price generic propecia
levitra vs cialis
viagra cialis online sales
buy cialis fedex shipping
cialis express delivery
viagra online
monster ark download
viagra pills
order propecia
viagra lawyers
buy propecia online cheap pharmacy
viagra non prescription
diamonds are forever trailer
baldness male propecia
purchase cialis us
combine cialis and levitra
info viagra
viagra fast delivery
cialis 30 mg
get viagra fast
viagra and cialis for sale
buying cialis online
brand name cialis overnight
indian cialis
viagra blister 4
viagra tablet weight
cialis soft tablets
buy propecia uk
online propecia sales
generic cialis canadian
cialis philippines
ordering viagra overnight delivery
viagra canadian pharmacy dosage
online pharmacy propecia
cialis levitra
cialis fast delivery
cialis mastercard
china viagra
buy mg propecia
viagra canada
brand viagra professional
next day viagra
lowest price for propecia
usa cialis
real viagra without prescription
discount propecia propecia
cialis soft
viagra gel
buy cialis canada
viagra costs
get propecia online pharmacy
viagra for cheap
buy cheap online propecia
cialis sales uk
buy cialis once daily
cialis price 100 mg
cialis arterial fibrillation
cialis herbal
real viagra online
viagra samples
cialis professional no prescription
propecia for hair loss
cialis price in canada
cialis low price
canada viagra
mail order propecia
viagra for women
cialis no prescription
what is cialis
best price for propecia
canadian generic viagra online
viagra discount sale
viagra label
effects of cialis
canadian propecia rx
viagra perscription
online prescription propecia
viagra free
cialis levitra sale viagra
liquid propecia
order cheapest propecia online
low cost propecia
buy cheap uk viagra
cialis usa
canadian drugs propecia
pfizer soft viagra
woman and cialis
cialis no rx
generic propecia sale
mexico viagra
viagra mexico
cialis daily
viagra in india
viagra in spain
generic viagra online
real viagra pharmacy prescription
how does viagra work
beethoven music video
buy viagra
ordering propecia
how much is viagra
best price on propecia
best price propecia
us cialis
order viagra
professional cialis
cialis headaches
cialis buy on line
viagra prescription
how to get viagra
buy viagra line
cheap viagra online
low price cialis
cialis strenght mg
price check 50mg viagra
viagra buy
usa cialis sales
uk propecia sales
cialis for women
order propecia pill
canada online pharmacy propecia
viagra next day delivery
purchase cialis cheap
buy discount viagra
should i chew cialis
discount drug propecia
generic propecia viagra
purchase propecia
buy levitra online viagra
viagra dose
canadian pharmacy viagra legal
online propecia prescription
cialis 20 mg
cialis order
purchase cialis
pat garrett creative
canada viagra pharmacies scam