• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / WordPress 5.2 comes today with offline digital signatures

WordPress 5.2 comes today with offline digital signatures

07/05/2019 17:44 by giorgos

The new WordPress 5.2 that will be released today will bring a new technology for automatic updates, as a new defense measure against possible attacks on the servers that distribute the updates. The new version along with everything else we have already mentioned, will also carry offline digital signatures for all key updates, themes, plugins and translations.

Wordpress Splash Image - WordPress 5.2 comes today with offline digital signatures

This new feature complements WordPress Automatic Update, first introduced with version 3.7 on October 24, 2013. The new security feature prevents any potential intruder from making malicious versions of the CMS even if it has gained control. in all WordPress installations and infrastructures.

Prior to the release of WordPress 5.2, this was possible because there was no signature verification mechanism for packages promoted by the update server.

So since automatic updates will now be enabled "by default, for kernel versions and translation files" according to the WordPress documentation site, such an attack could lead to the immediate infection of approximately 33,8% of all websites on the Internet.

"A failure of this magnitude would be catastrophic for the World Wide Web and provide a huge attack platform for the attacker, who could control millions of web hosting accounts from which new attacks could be launched," WordFence said.

api normal - WordPress 5.2 comes today with offline digital signatures

The offline digital signature feature that will be released today with the new WordPress 5.2 adds a real level of defense to an attack from a compromised infrastructure (server servers) api.wordpress.org).

Paragon Initiative Enterprises first put forward the proposal to shield WordPress from the attacks we described above, and many of its proposals were included in the WordPress 5.2 database.

Such as he explains Arciszewski of Paragon Initiative Enterprises:

Before WordPress 5.2, if you wanted to infect every WordPress website on the Internet (about 33,8% of websites at the moment), you just had to hit the update server. This way, you could use the auto-update feature to install malicious code that allowed you to do everything (eg create the largest DDoS botnet in the world).

From WordPress 5.2 onwards, you should perform the same attack but you should also have the digital signatures from the WordPress core. After WordPress 5.2 only the basic CMS updates will be digitally signed. Plugins and themes will be signed later.

WordPress 5.2 comes today with offline digital signatures was last modified: 7 May, 2019, 5: 44 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: 2013, botnet, CMS, core, wordpress

You May Also Like

WordPress 5.6.2 maintenance and security update
WordPress Hosting (managed): Rocket net
How can WordPress run faster?

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Frontier SuperComputer 1,5 exaflops the second with AMD
Next Post: Red Hat Enterprise Linux 8: Kernel 4.18 & GNOME 3.28 in Wayland »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.