Showing posts with label WordPress. Show all posts
Showing posts with label WordPress. Show all posts

Wednesday, April 29, 2015

Wordpress - Zero Day Vulnerability Discovered


http://hackingdude.com/2015/04/29/wordpress-zero-day-vulnerability/

Most of the time, we have reported about WordPress vulnerabilities involving vulnerable plugins, but this time a Finnish security researcher has discovered a critical zero-day vulnerability in the core engine of the WordPress content management system.
I thought I'd post about this since the vulnerability is a bit unusual.  I also though it was a bit unusual that Wordpress reportedly ignored a previous vulnerability that the researcher reported to them.  Wordpress has a responsibility to it's users and for them to purposefully ignore such a discovery is wrong, in my opinion.

So, if you've Wordpress CMSs that you administer, I'd advise you to upgrade to v4.2.1 (I did a few days ago).


Wednesday, May 01, 2013

Millions of WordPress sites exploitable for DDoS Attacks using Pingback mechanism

http://thehackernews.com/2013/05/millions-of-wordpress-sites-exploitable.html

Over the weekend, Incapsula mitigated a unique DDoS attack against a large gaming website, in which they have discovered a DDoS attack using thousands of legitimate WordPress blogs without the need for them to be compromised.

This article also mentions another recent report, released by them (The Hacker News), involving another method of DDoS attack using DNS amplification as a method of attack.

I've been testing out WordPress on my 1and1.com virtual server and it is pretty locked down...I've still had at least one compromise (someone uploaded php-based exploit code onto the server via a plugin, which I've since removed).  WordPress constantly gets attacked and even though I'm running extra layers of security, it's taking 100% of my attention to ensure that nothing is amiss...it takes the fun out of administrating a CMS, IMO.  :/