Hannes Johnson dot Com

Hannes Johnson dot Com header image 2

JohnChow.com Got Hacked - WordPress Security Hole?

January 11th, 2007 · 9 Comments · 2,636 views

One blog that I frequently visit is JohnChow.com. Today when I was going to check his RSS feed through Live Bookmarks in Firefox I got the message “Live Bookmark feed failed to load.” So I typed johnchow.com into the location bar and then I saw this:

JohnChow.com hacked

I filtered out the text because I don’t want to give the hacker credit - that’s often their only goal, to impress their buddies. But the message on the page was rather disturbing - looks like somebody doesn’t like George W. Bush and USA. Which is pretty funny because John Chow is Canadian ;) When the page loaded it also started playing a MIDI version of The House of the Rising Sun - not sure what that’s all about.


It looks like John’s buddy Stephen Fung was also hit by the same hacker. John and Stephen are both running WordPress so it might be a security hole in WordPress that the hacker exploited. But they’re both running version 2.0.6 of WordPress which did have some security updates… It might also be a plug-in they’re using that’s not 100% secure.

But both blogs are up and running again and everything looks like it’s back to normal - no major damage done. I would be interested in knowing what security hole the hacker exploited so I can close it.

It’s always annoying when your site gets hacked. A few months ago my article directory got hacked by some Nigerian spammers. They exploited a security hole in the system I was using to run my site and sent thousands of spam e-mails through my domain so my host was forced to suspend my domain. I had to start all over again with a new article directory system…

So, be careful and make sure you’re not leaving any doors open for hackers.

Technorati tags: , , , ,

Did you enjoy this post? Why not subscribe to my RSS feed. That way you'll never miss out on new blog posts. Click here for the feed.

Tags: Web Development

A few related posts you might enjoy:

9 responses so far ↓

  • Magadalene Ngina // Jan 11, 2007 at 5:46 am

    Thanks alot for this information. I shall be more careful on my web site

  • Felista K. // Jan 11, 2007 at 5:51 am

    I am too knowledable on blogging but i shall keep off WordPress when i start my blog

  • Felista K. // Jan 11, 2007 at 5:58 am

    I shall be careful when i establish my blog

  • WesleyTech.com // Jan 12, 2007 at 9:52 pm

    My Postnuke website was hacked awhile back and my bandwidth was all sucked up by a spammer / hacker. boo to spammers. I’d also like to know what specific security vulnerability was exploited…

  • Tyler // Jan 12, 2007 at 10:02 pm

    Stephen told me it wasn’t through Wordpress but through it Joomla that had an explot they used to do their nasty.

    Let’s just say Joomla lost a customer with that issue ;)

  • New WordPress Upgrade - Version 2.0.7 | Hannes Johnson dot Com // Jan 18, 2007 at 10:11 pm

    [...] WordPress released a new upgrade - version 2.0.7. This is an important upgrade because it fixes a PHP security problem and a FeedBurner issue that was in 2.0.6. I had noticed the FeedBurner problem - often when I checked the RSS feed for this blog (and other WordPress blogs) I often got the error message “Live Bookmark feed failed to load.”. The security problem might be why John Chow got hacked a few days ago. At least he hints to that on his blog. [...]

  • John Chow dot Com - You Can Learn A Thing Or Two From A Dot Com Mogul | Hannes Johnson dot Com // Jan 19, 2007 at 2:14 am

    [...] I mentioned John Chow in an earlier post. Well, John is a real up-and-comer in the blogosphere and is on his way to become an internet celebrity ;) His blog is already in the Technorati Top 1000 and he’s set on reaching the Top 100 before the end of this year. You might say that John Chow is the reason I decided to put this domain to good use and not just let it collect digital dust. I’ve been reading his blog for a while and I discovered that it doesn’t have to be that hard making a full-time income from a single blog - and it can be quite fun too. [...]

  • Nirmal // Feb 22, 2007 at 3:33 pm

    That was gud info…..

  • Gary // Feb 23, 2007 at 12:42 am

    So, what’s a regular (non-tech) blogger like me suppose to do if my site does get hacked? I have everything saved on my hard drives, but other than reloading the same files for the hacker to hack, I wouldn’t know what to do to protect myself.

Leave a Comment

(required)

(required, never displayed)