<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>What I Think &#187; remote_shell</title>
	<atom:link href="http://www.paulmc.org/whatithink/tag/remote_shell/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.paulmc.org/whatithink</link>
	<description>Yes. I&#039;m back.</description>
	<lastBuildDate>Sat, 24 Jul 2010 20:23:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>BackUpWordPress Plugin Security Issue</title>
		<link>http://www.paulmc.org/whatithink/2007/11/11/backupwordpress-plugin-security-issue/</link>
		<comments>http://www.paulmc.org/whatithink/2007/11/11/backupwordpress-plugin-security-issue/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 14:40:07 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[backupwordpress]]></category>
		<category><![CDATA[plugins]]></category>
		<category><![CDATA[remote_access]]></category>
		<category><![CDATA[remote_shell]]></category>

		<guid isPermaLink="false">http://www.paulmc.org/whatithink/2007/11/11/backupwordpress-plugin-security-issue/</guid>
		<description><![CDATA[
Over the last few days I&#8217;ve been noticing quite a few hits on my blog for various, non-existant pages. Each of these hits takes the form of:


bkpwp_plugin_path=URL of a text file on an another website


Checking the URL in the page request returns a text file containing PHP code that attempts to launch a remote shell.


The [...]]]></description>
			<content:encoded><![CDATA[<p>
Over the last few days I&#8217;ve been noticing quite a few hits on my blog for various, non-existant pages. Each of these hits takes the form of:
</p>
<p>
<b>bkpwp_plugin_path=<i>URL of a text file on an another website</i></b>
</p>
<p>
Checking the URL in the page request returns a text file containing PHP code that attempts to launch a remote shell.
</p>
<p>
The first part of the page request is a reference to a plugin for WordPress called <a href="http://wordpress.designpraxis.at/plugins/backupwordpress/">BackUpWordPress</a> This plugin automatically backs up your WordPress database and files. According to <a href="http://www.securityfocus.com/bid/26290/info">Security Focus</a>, the plugin does not properly check user provided input, thereby allowing remote users to possibly access your hosting providers server.
</p>
<p>
At this point in time there is no update available to resolve this issue. If you&#8217;re using this plugin, then until a fix is made available, the safest option is to deactivate and remove the plugin.
</p>
<p>
<b>Update:</b> Since I wrote this piece, the BackUpWordPress plugin has been updated to fix this issue. Kudos to the developer for releasing a fix so quickly. More details in this <a href="http://www.paulmc.org/whatithink/2007/11/11/backupwordpress-plugin-security-issue/#comment-1107">comment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.paulmc.org/whatithink/2007/11/11/backupwordpress-plugin-security-issue/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
