![]() |
wordpress security: *must read* exploit not fixed in 2.8.4
Theirs currently an exploit out for 2.8.4 which isnt patched, that will allow someone to exhause your site using a DoS against certain file(s).
Here is the POC (proof of concept) Code:
<?php add this to your themes functions.php file Code:
<?php |
Damn, just went and updated all of my sites recently too.
Thanks, Fris. |
Thanks mate, cheerio.
|
Thanks for the info. I'll update everything now.
|
what are you upgrading to? He said exploit still exists in 2.8.4 (current version)
|
Quote:
|
Thx for the info!
|
Thanks. What's the fix for people running an old theme that doesn't have a functions.php? ;)
Can the default functions.php just be copied over to the theme folder? What else needs to be done? |
bumping up some good info, thanks fris
|
Quote:
|
this is no where near the risk of the vulnerability that was recently patched by wordpress.
|
Quote:
You can add that code to your themes functions.php file which overrides any core functions that you have applied in functions.php |
Thanks man, updating the most important one snow, will wait for new release for the smaller blogs.
|
Shit....this may help some people...Its a plugin
http://fullthrottledevelopment.com/w...ck-dos-attacks I turned off my trackbacks years ago but I think it is still there to exploit. |
Quote:
I don't need to do anything else to call the functions.php or anything from any other files? |
If you have pingbacks/trackbacks turned off, can you just dev/null it via .htaccess?
<Files wp-trackback.php> Order Deny,Allow Deny from all </Files> |
Quote:
|
Quote:
|
Awesome, thanks guys!
|
Exploit not fixed? Thanks for posting. Interesting read.
|
thanks for the info...
fuck wordpress is a pain in the ass |
...good looking out Fris
|
the exploit is FIXED..
the problem you are referring to has to do with some permissions that a user can set. the problem you are referring to, can be more possible on mu if the admin doesn't know how to configure it. If you are really secure, you should post it in the wp trac and not in GFY. However, again, this was fixed long ago. |
Thanks for the info.
|
Quote:
|
nevermind 2.8.5 has been released with the fix
|
Quote:
|
Quote:
|
Quote:
|
All times are GMT -7. The time now is 04:26 PM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123