0-Day Wordpress DoS/exploit

Discussion in 'Security' started by nux, Oct 19, 2009.

  1. #1
    There's a wordpress DoS out that affects the latest version of Wordpress. It's in the wp-trackback.php file. The exploit essentially tells the server to process a trackback in thousands of charsets.

    You can find more details here:

    http://www.stevefortuna.com/new-0-day-wordpress-exploit/
     
    nux, Oct 19, 2009 IP
  2. nux

    nux Active Member

    Messages:
    265
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    55
    #2
    nux, Oct 20, 2009 IP
  3. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #3
    The blog is hosted at Theplanet.com. Send them an abuse/DMCA complaint although don't expect a reply.

    Feel free to use the Report Post icon at the upper right as well.

    edit: Oh, and there's no such thing as the 'latest version' of any software. They have version numbers for a reason. Please use them. Latest version is 2.9. Is that what you're running?
     
    Last edited: Oct 20, 2009
    theapparatus, Oct 20, 2009 IP
  4. nux

    nux Active Member

    Messages:
    265
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    55
    #4
    Yes, it was 2.8.4. Latest as of yesterday. I noticed they're hosted at HostGator and I've already sent them a letter.

    Thanks for the suggestion.
     
    nux, Oct 20, 2009 IP
  5. nux

    nux Active Member

    Messages:
    265
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    55
    #5
    I still see 2.8.4 on wordpress.org, along with no mentions to upgrade within the control panel. How are you determining that 2.9 is the latest version. Is this version still in development, and not publicly released?
     
    nux, Oct 20, 2009 IP
  6. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #6
    They're working on 2.9 right here:

    http://core.trac.wordpress.org/browser/trunk

    Feel free to download a copy.

    You're missing the point of what I was saying. Latest release for you is 2.8.4. Latest release for others is 2.9 or the development version. Had a client last week for the latest version for them was 2.6.something and they swore it was the latest version. The download is actually 2.8.4a I believe. That's why you should the specific version numbers as what you're running may not be the 'latest'.

    edit: In fact actually there's 4 different 2.8.4's now:

    http://wordpress.org/download/release-archive/

    reedit: Oh and they're not hosted on Hostgator, that's where the domain is registered. They're hosted at 174.132.114.6 which is a theplanet.com IP address.
     
    theapparatus, Oct 20, 2009 IP
  7. nux

    nux Active Member

    Messages:
    265
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    55
    #7
    I fully understand why I should have mentioned 2.8.4 along with latest version. But you can't argue that the latest version and trunk/beta/development are any way related.

    The latest release is still 2.8.4.

    And Hostgator is hosted at theplanet. If you lookup a hostgator IP, you will see similar response as the other theplanet IP. The reverse DNS on Hostgator's main IPs are theplanet.com
     
    nux, Oct 20, 2009 IP
  8. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Bloody hell. No wonder why you're getting your content ripped off.

    Have fun dealing with your issue. I don;t have the time to beat you over the head with basic internet and computer knowledge.
     
    theapparatus, Oct 20, 2009 IP
  9. nux

    nux Active Member

    Messages:
    265
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    55
    #9
    Are you kidding me? Basic internet and computer knowledge? Hah...Don't be silly.

    Explain to my why some guy stole my content, please.

    And you're telling me this server: gator637.hostgator.com doesn't belong to hostgator...Thanks for being so much help...
     
    Last edited: Oct 20, 2009
    nux, Oct 20, 2009 IP
  10. SecureCP

    SecureCP Guest

    Messages:
    226
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Don't be an e-snob. hostgator is hosted on the planet's servers.

    12 65 ms 67 ms 66 ms po1.car01.dllstx6.theplanet.com [70.87.254.138]
    13 65 ms 67 ms 67 ms gator637.hostgator.com [174.132.114.2]

    And someone stole your content because it is exactly that.
     
    SecureCP, Oct 21, 2009 IP
  11. sydzapp

    sydzapp Well-Known Member

    Messages:
    703
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    100
    #11
    Noob, what the hell is nux saying here then : http://forums.digitalpoint.com/showpost.php?p=12719225&postcount=8

    Read all posts before you make a stupid comment.
     
    sydzapp, Oct 22, 2009 IP