On TV.com: Why Is Everyone in TV High School SO OLD
BNET Business Network:
BNET
TechRepublic
ZDNet

September 8th, 2008

WordPress shuts door on new PHP attack vector

Posted by Ryan Naraine @ 8:09 pm

Categories: Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Exploit code, Open source, Passwords, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: Password, PHP, Attack Vector, Wordpress, Scripting Languages, Security, Software/Web Development, Web Development, Ryan Naraine

WordPress shuts door on new PHP attack vectorThe WordPress patching hamster wheel keeps on rolling and rolling.

According to an advisory from maintainers of the open-source blog software, WordPress 2.6.2 was released on September 8 to mitigate a new attack vector discovered by PHP security guru Stefan Esser.

From the announcement:

  • Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.

[ SEE: Flaw trifecta kicks off Month of PHP bugs ]

WordPress developers said the attack is difficult to accomplish but, because of the associated risk, the patch is being released.

It’s important to note that other PHP applications are vulnerable to this class of attack.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 3 Talkback(s)
RE: WordPress shuts door on new PHP attack vector
We run a heavily modified version (for instance this comment system is not from Wordpress), so version in our case is not really meaningful.... (Read the rest)
Posted by: JP_999 Posted on: 09/09/08 You are currently: a Guest | | Terms of Use
Hopefully this fixes the the problems we've seen with hacked WP sites  faseidl | 09/09/08
What wordpress version is ZDNet on Ryan?  D. T. Schmitz | 09/09/08
RE: WordPress shuts door on new PHP attack vector  JP_999ZDNet Moderator | 09/09/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More