JasperCoonrod67 attacks not upgraded wordpress
Now is the third blog where I defend myself against intrusion of a certain user JasperCoonrod67. All three were upgraded to wordpress 2.8.3 and therefore vulnerable.
I speak of "intrusion" is because I really do not know what the purpose of this unwelcome guest.
I started the "investigation" when it multiple times on one of the blogs in question, I was suddenly replaced by a custom theme the default.
The first control panel, admin & users of the authors then alarmed me: among administrators, in this case 2, there was a third. This third pear ² is indicated only by a ticket system on top (as shown in picture). But those on the list 2 directors remain with the respective data .
It 'was necessary to access the database, see the table wp_users to be able to peck the only registered user without email address, your name JasperCoonrod67.
Deleted the admin user phantom is immediately necessary to upgrade to the latest version of wordpress 2.8.4.





September 27th, 2009 at 15:37
It is happened to me su'altro blog that I manage, it was a bug in the penultimate version of WordPress, the only way to eliminate the ghost user is accessing the database and delete it from there.
At the moment it seems that cia pear ² ² can be performed with the 2.8.3 and not with the previous ones ...
February 5th, 2010 at 15:01
The intruder is also been my guest. The only damage has been some news of the header, otherwise no trouble. To me it is enough to eliminate it simply remove it from the list users.