Wordpress ALERT!

Discussion in 'WordPress' started by tech86, May 25, 2006.

  1. DomainMagnate

    DomainMagnate Illustrious Member

    Messages:
    10,932
    Likes Received:
    1,022
    Best Answers:
    0
    Trophy Points:
    455
    #21
    yeah, that's what we all like to think.. :D
     
    DomainMagnate, May 26, 2006 IP
  2. -Abhishek-

    -Abhishek- Regaining my Momentum!

    Messages:
    2,109
    Likes Received:
    302
    Best Answers:
    0
    Trophy Points:
    0
    #22
    Check the codex at http://codex.wordpress.org/Enable_Sending_Referrers for information. The "sending referrers" problem is pretty common, and can happen for about a thousand different reasons. All of the common causes and solutions are in the codex link above :) If you check that, then try installing a different browser (like Firefox or Opera) and see if that makes a difference. If it's still broken, then hit this thread again and let me know.
    Abhishek

    @tech86 ... Thanks for the alert bro ...
    But I'd suggest providing a link to the release page or fix whitepaper of the exploit rather than the exploit itselves, coz there are many craptards roaming around here!
    Abhishek
     
    -Abhishek-, May 26, 2006 IP
  3. tech86

    tech86 Peon

    Messages:
    83
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #23

    Ok, you know what.. **** you.

    Honestly, you need to learn to accept a favour and not bitch about it.

    You might not know much about the security world but what you need to realize is that the security world is not "synchronized". Just cause someone posted a dangerous exploit online, doesn't mean that there is a nice innocent upgrade on the official website. This also doesn't mean that there is a nice innocent advisory posted somewhere with exploit.

    At the time when I saw this vulnerability, this was the only form of documentation available online in regards to this vulnerability.

    As I read about this I remembered that a LOT of webmasters on these forums use Wordpress and so I decided to post it here with a simple temporary fix.

    That to me seemed like a good idea so that the other people on here do not end up with thier entire websites deleted.

    So you know what, this was for the webmasters that needed this information and found it usefull. If you didn't there is a [x] button to the right hand top site of the corner USE it and don't make a worthless post discouraging people from helping out.
     
    tech86, May 26, 2006 IP
    DomainMagnate likes this.
  4. tech86

    tech86 Peon

    Messages:
    83
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #24
    One more thing, if you bothered to read the simple english explanation on there, you will read that it's possible to inject a php shell / backdoor into the wordpress install. This means that a weak mysql password is not required. However that is a secondary form of attack.
     
    tech86, May 26, 2006 IP
  5. tech86

    tech86 Peon

    Messages:
    83
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #25
    In this case as far as I am aware at the time I made the post the whitepapar was not available and by the time it is a lot of the webmasters here could be victims.
     
    tech86, May 26, 2006 IP
  6. jackburton2006

    jackburton2006 Peon

    Messages:
    5,296
    Likes Received:
    282
    Best Answers:
    0
    Trophy Points:
    0
    #26
    Do the Wordpress guys know about this? I went to their site after seeing this and didn't find any discussions about it...
     
    jackburton2006, May 26, 2006 IP
  7. -Abhishek-

    -Abhishek- Regaining my Momentum!

    Messages:
    2,109
    Likes Received:
    302
    Best Answers:
    0
    Trophy Points:
    0
    #27
    Understood and agreed! User Signups disabled on two of my blogs :) Thanks dude!
    Abhishek
     
    -Abhishek-, May 26, 2006 IP
  8. tech86

    tech86 Peon

    Messages:
    83
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #28

    I believe they do and they will probably release a fix as soon as they can.

    Abhishek, you're blog was actually the first one that popped in my head :p and then I was like, hmm a lot of dP users use wordpress.
     
    tech86, May 26, 2006 IP
  9. mdvaldosta

    mdvaldosta Peon

    Messages:
    4,079
    Likes Received:
    362
    Best Answers:
    0
    Trophy Points:
    0
    #29
    Theirs no need to make any drama out of my post, that wasn't my intent. I said thanks for the heads up, you did a great thing for for making the public aware of the exploit, my only gripe ws that you posted the actual code to execute this rather than just a heads up.
     
    mdvaldosta, May 26, 2006 IP
  10. tech86

    tech86 Peon

    Messages:
    83
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #30
    I apoligize I get riled up when I get crap for trying to do a nice thing.

    Also one more time, I would've posted a harmless advisory if there was on out there at the time.
     
    tech86, May 26, 2006 IP
  11. minstrel

    minstrel Illustrious Member

    Messages:
    15,082
    Likes Received:
    1,243
    Best Answers:
    0
    Trophy Points:
    480
    #31
    That's a firewall problem, Boydy.

    Are you by any chance using Norton Personal Firewall?
     
    minstrel, May 26, 2006 IP
  12. Dreamchaser

    Dreamchaser Well-Known Member

    Messages:
    745
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    110
    #32
    Dreamchaser, May 31, 2006 IP
  13. Emperor

    Emperor Guest

    Messages:
    4,821
    Likes Received:
    180
    Best Answers:
    0
    Trophy Points:
    0
    #33
    The security fix has been officially released.
     
    Emperor, Jun 1, 2006 IP
  14. forkqueue

    forkqueue Guest

    Messages:
    401
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #34
    You think the script kiddies don't already have access to this exploit?

    By publishing the exploit you're giving knowledgable people a way to easily see what is being done and how best to fix the issue. By keeping it secret, you're only giving the crackers an opportunity to create further exploits.
     
    forkqueue, Jun 1, 2006 IP
  15. Dreamchaser

    Dreamchaser Well-Known Member

    Messages:
    745
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    110
    #35
    Dreamchaser, Jun 1, 2006 IP
  16. websys

    websys Active Member

    Messages:
    841
    Likes Received:
    23
    Best Answers:
    0
    Trophy Points:
    78
    #36
    thx ... turned reg off now :D
     
    websys, Jun 1, 2006 IP