Watch Out for Recent WordPress Gumblar PHP Exploit

Kristi wrote a guest blog post at TechJaws about the attack last weekend on her well known Kikolani Blog by the PHP Script Injection Exploit in WordPress 2.7.1.  Kristi explains how she restored her blog and dealt with the issue. The UnMask Parasites blog provides additional details on what is known about this particular malware which has been dubbed the Gumblar .cn Exploit.

Gumblar exploit does NOT affect only WordPress. It can target any site using .php including Drupal, PhotoPost and even the Bangalore Telecom Web site.

The resources below will assist you in assessing your risk, increasing security for your WordPress blog and removing this exploit if you are already affected.

WordPress Security Resources:

Security Monitoring Tools for WordPress:

WordPress Security Audit Services:

WordPress Security Plugins:

Comments

  1. Janis who writes about Subnet calculator says:

    Thank you ver much for the warning

  2. digit who writes about seattle seo company says:

    I love WordPress Blog! I am regular visitor of your blog.and getting quite informative posts.i have already learn more than enough from this blog.so thanks for sharing. Known the adjuration of mate ship can never be bound by bounded distance.
    digit would love you to read ..Contact UsMy Profile

  3. Danny who writes about Pole chain saw says:

    Didn’t even know that this could happen.
    Is this exploit fixed in the newer versions of wp?
    And are there new exploits? (probably)
    Danny would love you to read ..Remington RM1015P 10-Inch 8 Amp Electric Pole chain SawMy Profile

  4. I only just recently heard of this gumblar nastiness, seemed to be a big deal about the time of this post though. Glad I wasn’t a fan of Kristi’s blog back then. To my knowledge I’ve never had anything like that, hopefully I never will.
    Anthony would love you to read ..Acne Diets-Let’s Get RealMy Profile

  5. Brian Kinkade who writes about denver relocation says:

    I’ve visited Kikolani blog, its brilliant and Kristi is doing great work. I found the post very interesting and I’ll certainly check the links. Also, I’m really glad that I came across this blog because everything about this blog is enriching and very helpful.

  6. fortunately our blog was sparred but a co league of mine was victimize..this happened a few years back still..changes were made and bloggers like Kristi helped a lot in solving the problem
    Buffalo Tees would love you to read ..Buffalo Cool Place T-ShirtMy Profile

  7. Never even heard of this, thanks for the tip. Ill follow more posts so I don’t miss things like this.
    Trailers and Reviews would love you to read ..Source Code TrailerMy Profile

  8. I glad Gumblar didn’t affect my blog. As a relatively new blogger, I’m not sure what I’m going to do if I’m affected by a virus. It’s great that people with more tech experience share!

  9. Well this is strange and I got to be conscious about this.

Trackbacks

  1. Securing WordPress « Elijah Mills says:

    [...] Changing File Permissions Editing wp-config.php htaccess for subdirectories 13 Vital Tips… WordPress Exploits Firewalling and Hack Proofing How to stop… 18 WordPress Security Plugins 10 Easy Ways… [...]

  2. Watch Out for Recent WordPress Gumblar PHP Exploit | GROWMAP.COM says:

    [...] Continued here: Watch Out for Recent WordPress Gumblar PHP Exploit | GROWMAP.COM [...]

Speak Your Mind

*

CommentLuv badge
This blog uses premium CommentLuv which allows you to put your keywords with your name if you have had 1 approved comments. Use your real name and then @ your keywords (maximum of 5) WARNING: Comments that contain ONLY keywords are likely to be deleted. Please use a name followed by @ your keywords.