SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    One Computer Can Knock Almost Any WordPress Site Offline
Date    Wednesday February 07 2018, @03:07PM
Author    Fnord666
Topic   
from the control-your-scripts dept.
https://soylentnews.org/article.pl?sid=18/02/07/0558228

MrPlow writes:

Submitted via IRC for TheMightyBuzzard

As if there aren't enough ways to attack a WordPress site, an Israeli researcher has published details of how almost anyone can launch a denial of service (DoS) attack against almost any WordPress with just one computer. That, he suggests, is almost 30% of all websites on the internet.

The attack uses the vulnerability associated with CVE-2018-6389. The CVE database, at the time of writing, has no details, marking it only as 'reserved' for future use. Details, however, can be found in a Barak Tawily blog post published Monday. It is an abuse of the WordPress load-scripts.php function, which exists to allow administrators/web designers to improve website performance by combining multiple JavaScript files into a single request at the server end.

[...] Tawily goes on to show that mitigation isn't really that difficult if you know what to do (which many WordPress users do not). He "forked WordPress project and patched it so no one but authenticated users can access the load-*.php files, without actually harming the wp-login.php file functionality." He goes further to provide a bash script that modifies the relevant files to mitigate the vulnerability.

Source: http://www.securityweek.com/one-computer-can-knock-almost-any-wordpress-site-offline


Original Submission

Links

  1. "MrPlow" - https://soylentnews.org/~MrPlow/
  2. "blog post" - https://baraktawily.blogspot.co.uk/2018/02/how-to-dos-29-of-world-wide-websites.html
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=24707

© Copyright 2026 - SoylentNews, All Rights Reserved

printed from SoylentNews, One Computer Can Knock Almost Any WordPress Site Offline on 2026-01-24 20:37:18