• 07-09-2012, 17:23:50
    #1
    Bu sabah güvenlik eklentim, çok sayıda 404 hatası olduğuna dair mail gönderdi. Bir bakayım dedim. Siteme bir bot girmiş ve aşağıda liste halinde gösterdiğim adresleri kontrol etmiş.

    Alıntı
    wp-content/plugins/abrakadabra_and_notvalid.php
    wp-content/plugins/mm-forms-community/includes/doajaxfileupload.php
    wp-content/plugins/font-uploader/font-upload.php
    wp-content/plugins/front-end-upload/front-end-upload.php
    wp-content/plugins/wp-property/third-party/uploadify/uploadify.php
    wp-content/plugins/user-meta/framework/helper/uploader.php
    wp-content/plugins/radykal-fancy-gallery/admin/image-upload.php
    wp-content/plugins/count-per-day/notes.php
    wp-content/plugins/wp-gpx-maps/wp-gpx-maps_admin_tracks.php
    wp-content/plugins/mac-dock-gallery/upload-file.php
    wp-content/plugins/wp-automatic/inc/csv.php
    wp-content/plugins/foxypress/uploadify/uploadify.php
    wp-content/plugins/rbxgallery/uploader.php
    wp-content/plugins/sfbrowser/connectors/php/sfbrowser.php
    wp-content/plugins/wpmarketplace/uploadify/uploadify.php
    wp-content/plugins/omni-secure-files/plupload/examples/upload.php
    wp-content/plugins/topquark/lib/js/fancyupload/showcase/batch/script.php
    wp-content/plugins/front-file-manager/upload.php
    wp-content/plugins/pica-photo-gallery/picaPhotosResize.php
    wp-content/plugins/drag-drop-file-uploader/dnd-upload.php
    Muhtemelen bu eklentilerde güvenlik açığı var. Bu eklentilerden en az birini kullananlar, eklentinin güncel sürümü çıkana kadar pasif kale getirmesini öneriyorum.
  • 07-09-2012, 17:29:05
    #2
    eklenti değilde "uploadify" script kullanan eklentilerde ve temalarda açık var baya zaman geçti konu açmıştım ama malum sorun sonrasında silinmişti geçen zaman içinde "uploadify" ve kullanan eklentiler güncellenmiştir ama dikkatli olmak lazım eklentilerin sürüm notlarına bakıp kullanmalı fakat temalar daha sakat kullanıcılar genelde kendilerine göre düzenledikleri için tema güncellemesi pek yapılmaz

    benim liste:

    wp-content/themes/famous/megaframe/megapanel/inc/upload.php
    wp-content/themes/fresh_trailers_v2/uploadify.php
    wp-content/themes/fresh_trailers/uploadify.php
    wp-content/plugins/gpress/gpress-admin/fieldtypes/image_upload/scripts/uploadify.php
    wp-content/plugins/html5avmanager/lib/uploadify/custom.php
    /wp-content/plugins/image-symlinks/uploadify/uploadify.php
    wp-content/plugins/kish-multi/uploadify/scripts/uploadify.php
    wp-content/plugins/lbg-vp2-html5-bottom/js/uploadify/uploadify.php
    wp-content/plugins/wpmarketplace/uploadify/uploadify.php
    wp-content/plugins/wordpress-member-private-conversation/js/uploadify/uploadify.php
    wp-content/plugins/motorcycle-inventory/uploadify/uploadify.php
    wp-content/themes/wpnavigator/scripts/uploadify.php
    wp-content/plugins/nmedia-user-file-uploader/js/uploadify/uploadify.php
    wp-content/plugins/pods/js/uploadify.php
    wp-content/themes/pronto/cjl/pronto/uploadify/uploadify.php
    wp-content/plugins/wp-property/third-party/uploadify/uploadify.php
    wp-content/plugins/qr-color-code-generator-basic/QR-Color-Code-Generator/uploadify/uploadify.php
    wp-content/plugins/wp-symposium/uploadify/uploadify.php
    wp-content/plugins/uploader/uploadify.php
    wp-content/plugins/uploadify/includes/process_upload.php
    wp-content/plugins/very-simple-post-images/uploadify/uploadify.php
    wp-content/themes/zcool-like/uploadify.php
    wp-content/plugins/squace-mobile-publishing-plugin-for-wordpress/uploadify.php
    wp-content/plugins/1-flash-gallery/js/uploadify/uploadify.php
    wp-content/themes/aim-theme/lib/js/old/uploadify.php
    wp-content/plugins/annonces/includes/lib/uploadify/uploadify.php
    wp-content/plugins/apptivo-business-site/inc/jobs/files/uploadify/uploadify.php
    wp-content/plugins/bulletproof-security/admin/uploadify/uploadify.php
    wp-content/plugins/chillybin-competition/js/uploadify/uploadify.php
    wp-content/plugins/comments_plugin/uploadify/uploadify.php
    wp-content/plugins/wp-crm/third-party/uploadify/uploadify.php
    wp-content/themes/deep-blue/megaframe/megapanel/inc/upload.php
    wp-content/plugins/wp-property/third-party/uploadify/uploadify.php?path=../../
    wp-content/plugins/doptg/libraries/php/uploadify.php?path=../../
    wp-content/themes/wp-eden/admin/uploadify/uploadify.php