Search This Blog
Popular Posts
-
Elegant Themes has been developing WordPress themes for a long time. It has developed lots of popular themes including Divi, Nexus, Fa...
-
Flickr/Laura D'Alessandro See Also I took Harvard Business School's new pre-MBA course online — and it is definitely w...
-
Hello there! My blog post 'Spikes' was published on Sept. 22nd; however, the post before it called 'Flow' was published on...
-
I will publish an article only when I have something important to say. That's what I reminded myself every time the egocentric ...
-
Hi there! There isn't a true e-commerce solution here at WordPress.com. You can, however get a PayPal button. If you get a PayPal bu...
-
Good news for the secure web: WordPress will now encrypt the traffic for over a million more websites that are hosted on its servers. Wo...
-
How to start a blog or website in 5 minutes with WordPress. After publishing the post on how I started blogging full-time, I'v...
-
KOZHIKODE: E A Jabbar, a retired teacher and an activist of Malappuram based Yukthi vadi Sangham, has filed a complaint before chief minis...
-
At the ripe young age of 32, back in 2009, Uber CEO Travis Kalanick apparently launched a Wordpress blog called Swooshing, and for some ...
-
Wednesday the latest version of WordPress 4.7.1 was released by the WordPress Team, it is classified as a security release for all pre...
Blog Archive
- December (18)
- November (29)
- October (27)
- September (29)
- August (31)
- July (30)
- June (29)
- May (29)
- April (30)
- March (31)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (30)
- August (43)
- July (42)
- June (33)
- May (43)
- April (36)
- March (37)
- February (31)
- January (4)
- December (1)
- November (1)
- October (24)
- September (24)
- August (25)
- July (28)
- June (18)
- September (1)
Total Pageviews
Blogroll
WordPress blogger patch foot-drag nag: You're tempting hackers
Misconfigured and unpatched WordPress sites are causing a rash of problems both to themselves and the wider internet. In fact, this ever-present internet security threat has flared up again over the last week because of several new issues.
The most pressing problem involves a recent brute force amplification attack on WordPress-based website via the XML-RPC API. Researchers at Sucuri discovered a way to carry out the attacks against WordPress' built-in XML-RPC feature.
More details of a proof of concept demo of the flaw can be found here.
The vulnerability allows an attacker to bypass web server rate limits. The practical upshot is instead of limiting websites to one query with a one password at a time, the flaw means a hacker can now send one query with 500 passwords via XML-RPC API.
XML-RPC is a protocol for securely exchanging data across the internet. The technology supports the ability for an application to execute multiple commands within one HTTP request.
Attacks are happening against WordPress sites, so the bug is far from merely theoretical. El Reg has seen evidence that the XML-RPC vulnerability is being actively abused by hackers for all manner of malfeasance, from brute forcing passwords to attempting to take sites down.
Regular sites are getting affected by attack traffic even though the main brunt of the attack is being thrown against sites using the popular CMS platforms.
Separately, WordPress users need to make sure their Akismet anti-spam plugin is up to date following the discovery of an unrelated security bug. The vulnerability might potentially be exploited through cross-site scripting attacks.
Lastly, security researchers at Swiss firm High-Tech Bridge have identified a critical vulnerability in WordPress's Gwolle Guestbook plugin, which has over 10,000 active installations. The vulnerability, a PHP File inclusion, could result in an attacker controlling a filename or reading and writing files, as well as created the potential for hackers to push arbitrary code onto target systems.
WordPress has a bad name when it comes to security but vulnerabilities are normally patched quickly.
Sponsored: Analyzing the economic value of IBM FlashSystem
Source: WordPress blogger patch foot-drag nag: You're tempting hackers
0 comments:
Post a Comment