Posts Tagged ‘Security’

Sql injection exploit for WordPress

January 10th, 2007 by Martin

There is an new exploit for WordPress. It was reported here. I did couple of tests and have to say that it works for me only on versions previous to current 2.0.6. But according to source:

WordPress < = 2.0.6 wp-trackback.php Zend_Hash_Del_Key_Or_Index /
/ SQL injection admin hash disclosure exploit
(needs register_globals=on, 4 <= PHP < 4.4.3,< 5.1.4)

Under 2.0.6 I was unable to run it… But if you have any previous version I can only recommend you upgrade!

 Tags

WordPress Bug Hunt started

August 30th, 2006 by Martin

On Wednesday, August 30, 2006 at 01:00:00 UTC time , the latest WordPress Bug Hunt will commence. The fun starts when you show up, so please be prompt ;-) The goal of a Bug Hunt is to find, confirm, and fix bugs, then submit and test patches for those bugs. A WordPress Bug Hunt normally commences with a session on the #wordpress-bugs IRC channel on IRC.freenode.net. There are always numerous bug hunting opportunities available for Bug Hunters. PHP coding experience is not necessary — all participants are welcome to join!

 Tags

BlackHat looks at Ajax security design issues

August 7th, 2006 by Martin

AJAX is pretty cool stuff. But at Black Hat USA 2006 in Las Vegas and other events, the downside of AJAX is getting its due. ''We are seeing bad design choices,'' says SPI research engineer Billy Hoffman.Full article is available at SearchSecurity.com.

 Tags

Hackers Clone E-Passports

August 4th, 2006 by Martin

Wired – A German computer security consultant has shown that he can clone the
electronic passports that the United States and other countries are
beginning to distribute this year. To read full article about this issu click here.

 Tags
Text size: A A