Balkhis - Vision For Success

Wordpress 2.6.2 – Important Security Fix

Dear Readers, I would like to thank you for reading this post. I highly value your feedback and would like to know more about my readers. Follow me on Twitter

Upgrade to wordpress 2.6.2Well What do you know, there is another release of Wordpress. And a crucial one that should upgrade to as soon as possible. I have already upgraded my site, and I recommend you guys to do the same. Recently, Stefan Esser warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().

It is mainly geared towards users who have open registration enabled because WP 2.6.1 and earlier versions allow you to craft a username so it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, but it is still annoying to know that someone can do this, so it was more of annoyance rather than a security exploit.

Even though it wasn’t a security exploit, it can lead to many breakthroughs. So simply by seeding random numbers mt_rand(), attacker could predict the randomly generated password (so the formula how random number generates). While the attack is difficult to accomplish, and most people don’t know how to do it. But there is a possibility. And when there is, you know not to take risks. So upgrade to wordpress 2.6.2. Thanks to Stefan because with his help Wordpress team was able to fix the issue. He will be releasing the complete attack details soon.

Other PHP applications are also susceptible to this class of attack. To protect all of your applications, get the latest version of Suhosin. If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit. You should still upgrade to 2.6.2 if you allow open user registration so you can prevent the possibility of passwords being guessed by the attacker.

2.6.2 also contains a handful of bug fixes. Check out the full changeset and list of changed files.



To stay updated with the blog, please consider subscribing to my full feed RSS. You can also subscribe by Email and have new posts sent directly to your inbox. I hate spam as well, so I promise you that you will not be spammed.
Add to Social Bookmarks:
Add this Article to Digg Add this Article to Stumbleupon Add this Article to Del.icio.us Add this Article to Reddit Add this Article to Newsvine Add this Article to Technorati

RSS feed

14 Comments

Comment by Hugo Santos
2008-09-09 09:17:39

Going to upgrade ASAP. I just hope the plugins stay compatible….


 
2008-09-09 12:47:30

Thanks for that timely reminder about Wordpress’s 2.6.2 update I keep meaning to get around to it and by all accounts it is an important one from the security angle.


 
Comment by Melvin
2008-09-09 18:55:09

Thanks Balkhis, I have understood that all too well…


 
Comment by Otooo
2008-09-10 03:53:40

Argh – I am getting sick of all these upgrades – it seems like there’s a new one every week
I guess it’s for the better though – just gotta motivate myself to sit down and do it :)


Comment by Syed Balkhi
2008-09-10 05:20:42

hehe yeah it is annoying. I am already on wp 2.7 :P


 
 
Comment by Danny
2008-09-10 12:16:07

I’ve got remember to upgrade my blogs! I haven’t even upgraded to 2.6.1!

Eeek. Thanks for explaining the features of it so well :)


 
Comment by Normal Joe Subscribed to comments via email
2008-09-10 18:29:58

I upgraded, when I saw it in the admin panel, that’s a crazy exploit though, glad we have folks out here looking for them.


Comment by Syed Balkhi
2008-09-10 18:55:06

hehe yeah I am on 2.7 will show you sneak peaks sometime.


Comment by Normal Joe Subscribed to comments via email
2008-09-10 22:00:08

What the crap! You on the development team or something? What did they change? I need that private session man!

(Comments wont nest below this level)

Comment by Syed Balkhi
2008-09-11 05:14:05

They revamped the look of the admin panel again…


 
Comment by Normal Joe Subscribed to comments via email
2008-09-11 08:15:32

Ahh man, did they add drop down menus? I’m not sure what else they could change…but…I need that exclusive peek man ;)


 
 
 
 
 
2008-09-11 07:31:06

[...] is wrong with you Balkhis, two wordpress posts in a week? Well, I wrote to inform my readers about wordpress 2.6.2 because I know a lot of you were using that version. Because that is the most stable release at [...]


 
Comment by Authority Directory
2008-09-11 19:17:51

yep – upgraded to this one as soon as I saw its release. :)


 

Sorry, the comment form is closed at this time.

Subscribe to Balkhis via RSS
Subscribe to Balkhis via Email