wordpress

Vulnerability Zero Day on WordPress sites

An attacker may be able to take complete control of a websites who uses it WordPress due to the lack of the cryptographically secure pseudorandom number generator (CSPRNG).Wordpress

CSPRNG is a mechanism that produces random numbers on a computer, which can be applied for cryptographic purposes, such as the production of keys or salts. The numbers are pseudo-random because a really random series can only be produced on a theoretical level.

The WrongPress error was discovered by Scott Arciszewski, a Web developer from Orlando, Florida. He has already advised WorPress technicians about the need to implement a CSPRNG mechanism on the platform in order to eliminate even the slightest chance of anyone predicting the link used to reset the passwords.

Anyone who succeeds will be able to violate all WorrdPress that exist on the web. However, there is currently no available method.

Arciszewski reports that he tried several times to bring the issue to the των τεχνικών της WοrdPress. Πρώτη φορά στις 25 του Ιούνη του 2014, ανοίγοντας ένα ticket για το θέμα στον της πλατφόρμας. Η επόμενη φορά ήταν κατά τη διάρκεια του in Orlando, a conference focused on the WordPress platform.

A published by the researcher which completely reveals the vulnerability, also has a patch created by itself, which has not yet been integrated into WordPress.

Patch available with unit tests and PHP 5.2 on Windows support at
https://core.trac.wordpress.org/attachment/ticket/28633/28633.3.patch

Remember that WordPress is used by 75 million websites on the internet. Nevertheless, this vulnerability requires a lot of knowledge and skills, which discourages many would-be hackers.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).