‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. toyg · · focus · HN ↗
      TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
      1. Retr0id · · focus · HN ↗
        That's not really true.

        Edit: wow that's a lot of downvotes! I'm surprised people can't identify a trivial reasoning failure.

        1. dwattttt · · focus · HN ↗
          You could've included a little more nuance. An interpretation of your response is "being the most popular remotely accessible software" != "the most attacked", which would need defending.
          1. graemep · · focus · HN ↗
            I imagine anyone with any knowledge of the field could see the flaws in the claim that most popular = most attacked.

            Lots of counter examples and definitely no clear relationship. IMO its up to the person making the claim to provide evidence.

            1. dwattttt · · focus · HN ↗
              Just to expand on that nuance then, "attacked" is not restricted to "successful attacks".

              The most popular widely deployed software will be the most valuable to attack. That most fail is a function of other properties of the software.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.