Cookie vulnerability on WordPress.com

If you have a blog that runs with and is hosted on Wordpress.com, you should be very careful when logging in to your website's management panel. What do we mean? When connecting to Wordpress, do not use public Wi-Fi, because you may give them away you to some malicious user. Your account can be hacked, even if you have enabled two-factor authentication.

hacked wordpress

Η Yan Zhu, μια ερευνήτρια ασφαλείας από το Electronic Frontier Foundation (EFF) παρατήρησε ότι τα ιστολόγια που φιλοξενούνται στο WοrdPress.com αποστείλουν τα cookies ταυτότητας του χρήστη σε μορφή απλού κειμένου και όχι κρυπτογραφημένα. Έτσι, ακόμα και ένα Script can intercept login information.

When WordPress users log in to their account, WordPress.com servers distribute a cookie called "wordpress_logged_in" to the user's browser on her blog. The researcher has noticed that this authentication cookie is being sent through HTTP in a very insecure way.

[tweet_embed id = 471186304667881472]

Some malicious user can easily grab the HTTP cookies if they use the same Wi-Fi, using some specialized tools, such as Firesheep, a network sniffing tool. The cookie can be added to any other web browser and will give the hacker illegal access to the victim's WordPress account.

The good news is that if you have a Worrdpress website hosted on a server that supports HTTPS, then your blog is not vulnerable to the re-use of cookies.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).