Home Messages Index
[Date Prev][Date Next][Thread Prev][Thread Next]
Author IndexDate IndexThread Index

Re: [wp-testers] WordPress 2.0.1 Remote DoS Exploit?

  • To: wp-testers@xxxxxxxxxxxxxxxxxxxx
  • Subject: Re: [wp-testers] WordPress 2.0.1 Remote DoS Exploit?
  • From: Roy Schestowitz <wp-lowtraffic@xxxxxxxxxxxxxxx>
  • Date: Fri, 10 Mar 2006 13:08:18 +0000
  • Delivery-date: Fri, 10 Mar 2006 13:08:19 +0000
  • Envelope-to: wp-lowtraffic@schestowitz.com
  • In-reply-to: <5aa3aa0603092236o5411d2a5yf827eb2265772186@mail.gmail.com>
  • References: <3DAED5F8-68A9-4819-9D62-481D2141B17C@calpoly.edu> <058d01c643ab$85644f10$6432a8c0@marvin> <5aa3aa0603091110vd197398j2c905dbc6c8ac063@mail.gmail.com> <44107EFA.7060109@negimaki.com> <a491f91d0603091703i2de3fea0he29eb5da8ebd3acc@mail.gmail.com> <d9b7394f0603092154t3b253446q688e50c16edcd423@mail.gmail.com> <a491f91d0603092226x7865e0ect90f20bca56b6638d@mail.gmail.com> <5aa3aa0603092232o40eb55fkce3b634fdc655682@mail.gmail.com> <a491f91d0603092234s6d9bf241q30b48caa41ab56b1@mail.gmail.com> <5aa3aa0603092236o5411d2a5yf827eb2265772186@mail.gmail.com>
  • Reply-to: r@xxxxxxxxxxxxxxx
  • User-agent: Internet Messaging Program (IMP) H3 (4.0.3)
___/ On Fri 10 Mar 2006 06:34:55 GMT, [ Robert Deaton ] wrote : \___

On 3/10/06, Craig <nuclearmoose@xxxxxxxxx> wrote:
So, you're saying this isn't a vulnerability?

No more of a vulnerability than the fact that I can visit your front page a kajillion times in rapid succession from more than one computer all at the same time.


As I said in wp-hackers, if brute-force attacks finally count as
vulnerabilities, expect more of the same after the release of 2.0.2. To
quote:

,----[ Snippet ]
| 2) "Compromise by an extended Brute Force attack is not a CVE
| vulnerability."  (Brute Force Exception)
|
| [...]
|
| 3) "A denial of service in a client that is easy to recover from, is
| not a CVE vulnerability." (Client-Side Denial of Service Exception)
`----

Source: http://www.cve.mitre.org/board/archives/1999-07/msg00146.html


___/ On Fri 10 Mar 2006 06:36:31 GMT, [ Craig ] wrote : \___

So if you did that, and I had AdSense, I'd be rich, right? :^)


That is yet another growing concern:

http://news.bbc.co.uk/1/hi/technology/4787474.stm

which, among other malice, leads to:

http://www.whatistheword.com/story/Money_722.html

Don't expect attackers to make *you* richer. However, some of them can drain
the competition out of money, which benefits Webmasters in the process.


[Date Prev][Date Next][Thread Prev][Thread Next]
Author IndexDate IndexThread Index