0

Some WordPress.com Servers were Compromissed

Posted April 14th, 2011 in wordpress and tagged , , , , , , by Dainius

Very important, but silent news in a blogosphere: some of wordpress.com servers were hacked in a bad way:

Tough note to communicate today: Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed.

We have been diligently reviewing logs and records about the break-in to determine the extent of the information exposed, and re-securing avenues used to gain access. We presume our source code was exposed and copied. While much of our code is Open Source, there are sensitive bits of our and our partners’ code. Beyond that, however, it appears information disclosed was limited.

As soon as you read this, change your wordpress passwords (self hosted wordpress.org accounts indirectly influenced also).

The good news: Matt says that practically zero possibility of usernames/passwords leakage. But for security reasons the main recommendations is to change your password. 

Change username for “Site admin” after installing WordPress MU
First thing You should do after WordPress MU (prior to 3.0) install is to change username for SiteAdmin. First thing I've noticed after install was SiteAdmin username is "admin" - extremely ...
READ MORE
Updated: TweetMeme Button WordPress Plugin Update Can Mess Your Site Up [Not Anymore]
If your site is based on WordPress and you using TweetMeme Button plugin - hold on with updates! The problem is, that something wrong with plugin code and after update ...
READ MORE
WordPress JetPack: Fuel Up Your Blog, No Way Back
This week Automattic released new super plugin for self-hosted WordPress which brings power of the cloud to your blog. With this plugin you can see your stats as in any ...
READ MORE
Digging Into WordPress Sold Out, Waiting Release For WP3.1
Jeff Star and Chris Coyier, two amazing, WordPress immersed, guys already sold out their book named "Digging into WordPress" and preparing new version for WordPress 3.1. There are two possibilities: ...
READ MORE
Digging into WordPress 3.1 Finally Released
I already wrote about amazing "Digging into WordPress" and finally it's ready for you. Also you should know that you can save $5 if you order PDF before April 4th. ...
READ MORE
Change username for “Site admin” after installing WordPress
Updated: TweetMeme Button WordPress Plugin Update Can Mess
WordPress JetPack: Fuel Up Your Blog, No Way
Digging Into WordPress Sold Out, Waiting Release For
Digging into WordPress 3.1 Finally Released

Leave a Reply