Archive for March, 2007

CN域名明天降价 渠道出现1元域名

Tuesday, March 6th, 2007

据消息人士透露,多家域名注册商将从7日开始把.cn域名价格降至1元人民币,目前该消息尚未得到CNNIC和各代理商官方证实。3月6日,有消息人士透露,.cn域名的价格将从3月7日中午12点开始降至第一年1元人民币1个。该人士表示,“这个价格比CNNIC给我们的还要高,上面要数量,我们要业绩”。

另据业内人士透露,目前万网、中资源、中国频道、商务中国的价格都已经确定为1元,新网还在开会研究。

对此,中国万网相关负责人在接受DoNews采访时表示,“外面传出的价格毫无根据,我们正在制定方案,等明天CNNIC大会,将会真相大白。”

佛山一注册商则认为,现在大多注册商的价格还是88元1个,CNNIC公布价格后大家才会调节。该注册商认为万网等以1元销售目的在于增加注册量,至于“续费时是不是这个价格还难说。”

目前.cn域名降价一事并未得到CNNIC的确认,该公司有关负责人表示“相信很快就会有答案”。据悉,CNNIC将于3月7日召开有关.cn域名的发布会。(完)

附:万网内部通知

CN域名政策如下:执行时间:3月7日中午12点本活动只针对英文CN域名新增第一年

渠道:所有代理级别,新增第一年每个1元,续费、转入和多年(除第一年)价格不变,维持现有价格。

持续3个月

wordpress 2.1.1可能包含黑客代码

Tuesday, March 6th, 2007

刚刚看到wordpress 网站的通知,黑客入侵了他们的一个服务器,篡改了wordpress 2.1.1的源代码,要求下载了wordpress 2.1.1的用户尽快升级到2.1.2.下面是原文:
Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Longer explanation: This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.

It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.

This is the kind of thing you pray never happens, but it did and now we’re dealing with it as best we can. Although not all downloads of 2.1.1 were affected, we’re declaring the entire version dangerous and have released a new version 2.1.2 that includes minor updates and entirely verified files. We are also taking lots of measures to ensure something like this can’t happen again, not the least of which is minutely external verification of the download package so we’ll know immediately if something goes wrong for any reason.

Finally, we reset passwords for a number of users with SVN and other access, so you may need to reset your password on the forums before you can login again.

What You Can Do to Help

If your blog is running 2.1.1, please upgrade immediately and do a full overwrite of your old files, especially those in wp-includes. Check out your friends blogs and if any of them are running 2.1.1 drop them a note and, if you can, pitch in and help them with the upgrade.

If you are a web host or network administrator, block access to “theme.php” and “feed.php”, and any query string with “ix=” or “iz=” in it. If you’re a customer at a web host, you may want to send them a note to let them know about this release and the above information.

Thanks to Ryan, Barry, Donncha, Mark, Michael, and Dougal for working through the night to figure out and address this problem, and thanks to Ivan Fratric for reporting it in the first place.