EvilZone

Hacking and Security => Hacking and Security => : hacker@sr.gov.yu May 07, 2013, 11:20:35 AM

: WordPress Default Leaves Millions of Sites Exploitable for DDoS Attacks
: hacker@sr.gov.yu May 07, 2013, 11:20:35 AM
http://www.incapsula.com/the-incapsula-blog/item/715-wordpress-security-alert-pingback-ddos (http://www.incapsula.com/the-incapsula-blog/item/715-wordpress-security-alert-pingback-ddos)


 :o
: Re: WordPress Default Leaves Millions of Sites Exploitable for DDoS Attacks
: Stackprotector May 07, 2013, 12:06:02 PM
http://www.incapsula.com/the-incapsula-blog/item/715-wordpress-security-alert-pingback-ddos (http://www.incapsula.com/the-incapsula-blog/item/715-wordpress-security-alert-pingback-ddos)


 :o
Stupid right? :)
: Re: WordPress Default Leaves Millions of Sites Exploitable for DDoS Attacks
: hacker@sr.gov.yu May 07, 2013, 01:25:35 PM
http://core.trac.wordpress.org/ticket/4137 (http://core.trac.wordpress.org/ticket/4137)


6 year old bug, really?  :)
: Re: WordPress Default Leaves Millions of Sites Exploitable for DDoS Attacks
: Stackprotector May 07, 2013, 01:29:51 PM
http://core.trac.wordpress.org/ticket/4137 (http://core.trac.wordpress.org/ticket/4137)


6 year old bug, really?  :)
I just installed a wordpress blog. But i will always advice to keep the basics and throw away any shit you don't need. Also just enabled cloudflare free on it :)
: Re: WordPress Default Leaves Millions of Sites Exploitable for DDoS Attacks
: hacker@sr.gov.yu May 07, 2013, 01:44:42 PM
Better WP Security + Cloud Flare + Mod_Secuity(with OWASP rules) is quite good :)
: Re: WordPress Default Leaves Millions of Sites Exploitable for DDoS Attacks
: Stackprotector May 07, 2013, 01:50:28 PM
Better WP Security + Cloud Flare + Mod_Secuity(with OWASP rules) is quite good :)
And the biggest problem are the themes. So don't use a leaked old premium theme, or be sure it's clean and every addon included (timthumb) is updated :D
: Re: WordPress Default Leaves Millions of Sites Exploitable for DDoS Attacks
: hacker@sr.gov.yu May 07, 2013, 03:24:51 PM
And the biggest problem are the themes. So don't use a leaked old premium theme, or be sure it's clean and every addon included (timthumb) is updated :D
Yep, plugins are also a big threat.