[wp-hackers] wpau-backup being exploited?

Jorge Peña jorgepblank at gmail.com
Sun May 25 20:02:29 GMT 2008


So...is it being exploited or not?

On Sun, May 25, 2008 at 6:04 AM, Charles E. Frees-Melvin <
charles.freesmelvin at gmail.com> wrote:

> wpau-backup is the backup directory of people with the WordPress
> Automatic Update plugin.
>
> 2008/5/25 Jeremy Visser <jeremy.visser at gmail.com>:
> > Been getting a lot of spam in Akismet lately that contain URLs like the
> > following:
> >
> >
> http://conexions.org/wordpress/wpau-backup/wordpress/wp-content/themes/classic/css/fence/fencing-tools.html
> >
> > It seems spammers are storing link farm files in these wpau-backup
> > directories.
> >
> > A Google for wpau-backup reveals that a lot of these directories have
> > been indexed:
> >
> > http://www.google.com/search?q=wpau-backup
> >
> > Some of the results returned in that search query were actually linked
> > to in some of the spam I got.
> >
> > What is wpau-backup used for? Does it have any known exploits?
> >
> > --
> > Jeremy Visser                                 http://jeremy.visser.name/
> >
> > ()                           ascii ribbon campaign — against HTML e-mail
> > /\                                               http://asciiribbon.org/
> >
> > _______________________________________________
> > wp-hackers mailing list
> > wp-hackers at lists.automattic.com
> > http://lists.automattic.com/mailman/listinfo/wp-hackers
> >
>
>
>
> --
> --------------------------------
> Charles E. Frees-Melvin
> charles.freesmelvin at gmail.com
> www.cefm.ca
> _______________________________________________
> wp-hackers mailing list
> wp-hackers at lists.automattic.com
> http://lists.automattic.com/mailman/listinfo/wp-hackers
>


More information about the wp-hackers mailing list