WordPress 4.8.1 still vulnerable to Host Header Attack
learnwebdevelopment.review
learnwebdevelopment.review
"Note: Under Apache 2, you must set UseCanonicalName = On and ServerName. Otherwise, this value reflects the hostname supplied by the client, which can be spoofed. It is not safe to rely on this value in security-dependent contexts."
So it seems to be clearly a Word Press issue.
server {
listen 80 default_server;
return 444;
}
Is something like this necessary for Apache as well? If yes, what are others using? (ignoring the non-standard but effective 444 return code)