August 18, 2005

Blogging > For Security Reasons, Don't Post Your Blog Software Version

There's been a rash of blogs running Word Press getting hacked lately. Software has bugs and that sort of thing happens. One way to avoid some of the problems: don't post your blog software's version number.

For instance, I noticed that Politburo Diktat is running a recent Word Press release - 1.5.1.3. If someone discovers a security flaw in that release all they have to do is Google "powered by WordPress, version 1.5.1.3" to they'll find vulnerable blogs. No one but you needs to know what version you're running.

Posted by lesjones



Comments

My site was hacked and I didn't display the version. It was actaully a security hole in the old wordpress (v 1.2XX).

Posted by: SayUncle at August 18, 2005

Not displaying the version doesn't keep you from getting hacked. It just protects you from being the victom of a Google-by hacking.

Posted by: Les Jones at August 18, 2005

Either way - good tip. Thanks!

Posted by: Preston Taylor Holmes at August 18, 2005
Post a comment










Remember personal info?







Terms of Use