‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. toyg · · focus · HN ↗
      TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
      1. teunispeters · · focus · HN ↗
        That's bad designs for you. Assume that just because it's widely visible, must mean it has exploits. (this is the only point on that list I'll call "that's bad logic" on).
        1. ASalazarMX · · focus · HN ↗
          Everything complex enough has exploits, you can't make exploits impossible with design, just less likely.
          1. teunispeters · · focus · HN ↗
            The point of engineering is measuring and confirming errors, and designing to mitigate them. Exploits are errors.

            Complexity does not lead directly to exploits, letting errors be ignored does. At what level an error can be ignored - that's quality control. And one can tell poor quality software by how exploitable it is.

            1. ASalazarMX · · focus · HN ↗
              > Complexity does not lead directly to exploits

              Indirectly then? More complexity means more interacting parts, more complex interaction might hide flaws in ways it's hard to predict without looking at the big picture, which might be too big for a single person to picture (he).

              I don't advocate for oversimplified systems, the same way I don't advocate for overcomplicated systems. I advocate for finding an equilibrium.

              1. teunispeters · · focus · HN ↗
                Well, one can design in ways to reduce attack surfaces. But then it also helps if your tools and infrastructure support that. PHP for instance, is famously unhelpful and often hostile to this, though.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.