Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-07-2015, 09:10 AM   #1
MrGusMuller
Confirmed User
 
MrGusMuller's Avatar
 
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
[!] - Wordpress - JetPack, TwentyFifteen and others

Quote:
Any WordPress Plugin or theme that leverages the genericons package is vulnerable to a DOM-based Cross-Site Scripting (XSS) vulnerability due to an insecure file included with genericons. So far, the JetPack plugin (reported to have over 1 million active installs) and the TwentyFifteen theme (installed by default) are found to be vulnerable.
...

Quote:
but if you do not have a WAF or IPS protecting your site, we highly recommend removing the example.html from inside the genericons directory.
https://blog.sucuri.net/2015/05/jetp...based-xss.html
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections
ICQ: 63*23*43*113

MrGusMuller is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-07-2015, 09:10 AM   #2
cybermike
Confirmed User
 
Join Date: Jan 2002
Location: Ny
Posts: 4,108
Getting annoying wordpress!
__________________
Hey surfers how about some The Best Porn Sites
cybermike is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-07-2015, 09:16 AM   #3
MrBottomTooth
Confirmed User
 
MrBottomTooth's Avatar
 
Join Date: Sep 2009
Posts: 5,795
So was this something fixed in the last update or something new?
MrBottomTooth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-07-2015, 09:18 AM   #4
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
Quote:
Originally Posted by MrBottomTooth View Post
So was this something fixed in the last update or something new?
I assume it's new because WP auto updated last night to 4.2.2
Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-07-2015, 10:17 AM   #5
MrGusMuller
Confirmed User
 
MrGusMuller's Avatar
 
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
If you have the following files on ur WP you aren't safe.
wp-content/themes/twentyfifteen/genericons/example.html
wp-content/plugins/jetpack/_inc/genericons/genericons/example.html

EVEN if twentyfifteen and jetpack are disable you are compromised.

If you've updated WP core to 4.2.2, it should have removed these files for you automatically.


Peace
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections
ICQ: 63*23*43*113

MrGusMuller is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
genericons, theme, vulnerable, plugin, twentyfifteen, wordpress, jetpack, waf, found, default, ips, site, example.html, removing, inside, installed, recommend, directory, highly, protecting, cross-site, dom-based, scripting, xss, vulnerability



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.