‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. toyg · · focus · HN ↗
      TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
      1. fragmede · · focus · HN ↗
        How many times has Google been hacked? It's not zero, but just because something is popular doesn't mean it has to get exploited. Repeatedly.
        1. snowwrestler · · focus · HN ↗
          There is only one Google and it is operated by professionals. Who do not need to disclose the vulnerabilities that they find.

          Wordpress is pretty much the exact opposite of that.

          1. ValentineC · · focus · HN ↗
            We can say the same about most of open source.

            It's the WordPress plugin ecosystem that's more often the security nightmare though.

            1. AdrenalinMd · · focus · HN ↗
              Yes, and if you take Linux for example, there are also tons of exploit for it.
              1. zelphirkalt · · focus · HN ↗
                True, but then again WP is a very simple system, in comparison to the Linux kernel, and WP operates on a very different level, at which it should be much easier to get right. Also WP is not written in C. Granted, PHP is not all that great either, but probably still miles ahead, when comparing it to having to write bug-free C code, as one doesn't have to deal with all the manual memory management stuff, which people, even experienced engineers _will_ get wrong at least sometimes (remember the Chromium statistics about vulnerabilities).
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.