Wordpress Version 2.0.3 Review - What's Up With...
(Page 3 of 6 )
What's Up With The Security Problem?
The security problem seems minor, but the WordPress team is fixing it before it grows into something major. It's a bug that takes advantage of the cookie you download when you sign into WordPress. The cookie in question prevents anyone unauthorized from accessing your admin panel. It's tied to your user account, and verifies that you are the authorized administrator of the account you're working on.
The bug that's being fixed is one that takes advantage of a sociological trick. If someone created a link or a form pointing to your WordPress admin account, they might possibly be able to trick you into clicking the link. In the case of the one here, you delete a post. This sounds both minor and highly unlikely; but a small crack in the door can be exploited later by a dedicated hacker. And this is also the kind of bug that, a few years ago, allowed a hacker access to the Microsoft databases, from which he stole portions of the Longhorn and other codes. So yes, you do need to take it seriously.
Next: WordPress had ensured... >>
More Blog Help Articles
More By Jase Dow