‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. nom · · focus · HN ↗
      The access log of public http servers is truly interesting to watch.

      You know that the scripts doing it are optimized for success rate, so the types of requests they send give you an impression of what's actually out there.

      It's clear to me that once we finally achieve rogue AGI, it is going to propagate through unpatched WordPress WooCommerce instances.

      1. mitxela · · focus · HN ↗
        Not success rate per request though.
      2. lyu07282 · · focus · HN ↗
        It seems the most common issue of them all is an exposed .env file by that measure.
        1. graemep · · focus · HN ↗
          I think that is very likely to be common. It is an easy mistake to make if your code is in a directory the web server can read, which is common, and is usual with PHP.
      3. jamesfinlayson · · focus · HN ↗
        Yep I see this at work pretty regularly - a SpringBoot log file full of requests for all sorts of things (mostly WordPress but I think some IIS as well).
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.