Hacker Gains Access To WordPress.com Servers
techcrunch.com
techcrunch.com
[1] - https://www.owasp.org/index.php/London#Next_Meeting.2FEvent
If so I would very much like to see it.
I will take you up on your offer of slides though, I only asked about the recording because I remembered seeing that Samy Kamkar talk online (though it might not have been at OWASP).
Big trust betrayal - happy to set up an equivalent webex for the HN group. I understand that Wordpress is particularly useful for landing pages though, so I'm happy to do something and actually spend more time on it making it better for the wider HN community.
I guess that's not so important for wordpress, but I'm talking at DC4420[1] next week on evading antimalware defences and that's not something I'd really want to see put up on youtube for obvious reasons.
Damnit, forgot to put the link in!
If you run a site that has valuable information you will end up being a target. That's just a fact. How you respond to these types of security incidents is what will set you apart from the pack. Sadly most breaches are covered up. They are bad for PR and most people don't understand them.
Always make sure you have a plan in place. Even if it is just shutting down a list of servers incident response can go a long way.
Does anybody know how WordPress.com saves MySQL passwords? Does it differ from Wordpress installations? Vanilla Wordpress installations have them among the rest of the code and thus those might have leaked too.
I wouldn't worry about MySQL passwords though: Automattic controls their database servers, so they can generate new credentials very easily.
<?php
$pwnd = mysql_select_or_whatever_it_is('select * from sensitive_tables');
?>
Like most LAMP applications Wordpress uses only one connection with total access to all tables. It's the same unavoidable design issue that causes plugins and themes to be a security issue.I can then use LOAD_FILE and SELECT INTO to read and write to files, but I won't be able to execute arbitrary code.
If the application user has access to mysql.user though I can then SELECT host, user, password FROM mysql.user; to get the credential details and password hashes, which can then be fed through a password cracker of my choice. Once I've done that I can reconfigure the worker to use the root mysql account, restart the PHP worker process and start sucking the database down or modifying it.
Of course, in theory you'd have some access to the database server beyond port 3306 such as SSH, in which case I'd look at grabbing mysql account info from /etc/passwd, then dropping ssh keys into that user's home directory so I can use key-based auth to get onto the box. This may or may not work (there's many variables) but I'm just writing that here to illustrate that breaking in as is with perl, there's more than one way to do it.
I suggest a failure plan to prepare for security failures including several PR messages depending on severity of failure even if you do not know if you're compromised.
It's highly unlikely that you will be able to avoid potential leaks.
I guess, as always, there is no silver bullet.
Maybe you want decentralised permissions of multiple database users? They can't quite get or do most things.
Or centralised and/or put into a locked down file that can only be accessed by the OS user for parsing scripts eg www-data.
More references:
http://technet.microsoft.com/en-us/library/cc722487.aspx#EIA...
http://us.php.net/manual/en/security.php (Or check your relevant manual)
http://blogs.forbes.com/firewall/2010/12/13/the-lessons-of-g...
http://stackoverflow.com/questions/3173698/how-safe-is-code-...
I can understand techcrunch getting it wrong, but we on HN should at least set the record straight.
how is root access 'low-level' ?
bah - who cares, they have bigger problems than PR message wording
EDIT: I'd assume other architectures as well, Intels are the only ones I know about, however.
A dinky example say is for instance you may need a password for X, but if you have access to disable the need for the password in X, you have lower level access. In the case at hand, with root level access you can read all the keys, passwords, settings in all the WP config files, otherwise you wouldn't be able to. You could also quietly add an additional password to the database allowing a bad application to run behind the scenes doing bad things with the data.
This makes for a very good simple CS test question.