‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. reaperducer · · focus · HN ↗
      If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates.

      People on HN love to talk smack about WordPress. After all these years, it's as much a reflex as shouting "walled garden!" every time there's an Apple story.

      Yet some of the biggest web sites on the internet run WordPress, and more importantly, some of the biggest hacking targets on the internet run WordPress.

      Prime example: whitehouse.gov.

      If you know what you're doing, WordPress fine. The same is true with every other piece of technology out there.

      But people on HN like to lump the good in with the bad because everything is binary.

      1. chrismorgan · · focus · HN ↗
        WordPress’s security model is distilled insanity, concentrated vulnerability. You’re supposed to give your site write access to its code, which turns almost any vulnerability into complete and persistent site takeover. Not to mention how many things will store code in the database and execute it from there, and how much of its design is fragile as anything, and how many plugins, often popular ones, do obviously dumb things that would not have been possible in most ecosystems.

        Drupal (also popular in governments and such), by contrast, will check that it can’t write to anything but its designated file uploads directory, and complain if it can, and has careful guidance around avoiding letting uploads be accidentally executable too. The blast radius of the typical vulnerability, and the possibility of persistent takeover, is drastically reduced.

        It’s possible to use C correctly, but in practice using it invites security problems, because it’s frightfully easy to make subtle but disastrous mistakes, even for experts, so there are reasons why people are moving to safe languages.

        WordPress is that kind of bad. It has always been bad, though it’s somewhat less bad than it used to be. Some of its badness is a part of how it got popular.

        1. graemep · · focus · HN ↗
          > You’re supposed to give your site write access to its code

          You do not need to. Its to help people who cannot manage an ssh login update. You can use the cli to update if you can. I am pretty sure big sites will not be doing their updates from the big site.

          The problem with plugins is lack of a proper framework. Its very easy to do things like pass user inputs into a query by strong concatenation because you have to make in extra effort to not do so.

          That said, its no guarantee. I have seen people do things like call exec on user inputs in Django.

          > has careful guidance around avoiding letting uploads be accidentally executable too.

          That should be the default, not something you need to take extra care over.

          1. trollbridge · · focus · HN ↗
            I support plugins for a client that require write access to their homedir that contains their code. They use it to hold temp files!

            I can mitigate the damage a little bit with some chattr +i, but overall, every plugin is another gigantic attack surface.

          2. chrismorgan · · focus · HN ↗
            > That should be the default, not something you need to take extra care over.

            I agree. That’s one of the problems of PHP’s file-based execution model, and how the likes of Apache and nginx work. Drupal is no paragon of security, but it’s far closer than WordPress. For all its faults, even Node.js avoids this class of problem.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.