Object injection vulnerability enables remote code execution in WordPress 3.6
vagosec.org
vagosec.org
Because of that, I moved off WordPress for personal blogging and onto Pelican [1]. You can't compromise static content.
It would be better for the overall health of the web if more independent publishers moved to static content.
I would also say, WP is not a blogging platform. It's ventured into the "Content Management Framework" realm with blogging "stuff" bolted on at this point. But PHP is still is the most ubiquitous and easiest environment for the novice (for better or for worse) so that's something to keep in mind as well.
A CMS produces static content... Most sites use caching, serving static files... I think you are meaning that only static files should be put on the server because it's safer? I'd like to see that in action on anything other than a simple blog or site with more than a dozen pages.
> I would also say, WP is not a blogging platform
You're the first person I've heard say that, usually it is the opposite ("it's just a blogging platform"). Can you point to any development in the code base that has suddenly made WP less dedicated to blogging? WP is clearly very versatile, otherwise people wouldn't use it for everything. But there's nothing in the code base that has changed that de-emphasizes its blogging capabilities or focus.
The original comment is not quite right. It's not that WordPress is now a "CMS Framework" with blogging bolted onto it. It's actually the other way around: a CMS framework is bolted onto a simplistic and fairly faulty blogging platform.
If you use it as a blogging platform, or to run a mostly static site, sure it works. But try to actually build something on this "framework" and you'll run into all kinds of ugly. Things like BuddyPress, ecommerce plugins, etc. all are a mess because you can't turn a blog into a social network or an online store any easier than a Prius into an 18 wheeler.
And WP is not versatile. It's just that PHP has no rules. Anyone can do anything at any time. Don't want to wire proper plumbing into your framework to pass some variable to the right view? Just declare a global variable! Don't have access to the right set of posts? Query the database directly!
So my argument against WP is not that it's a bad blogging platform. It's that blogging is all that's it's good for, assuming you spend every minute of every day checking for security updates.
For a list of sites/people that are able to turn a Prius into an 18 wheeler, see a previous comment I made: https://news.ycombinator.com/item?id=5412337
WordPress initial purpose was for blogging, later it grew along with demand and real world usage to become a more robust, capable versatile CMS. The blogging architecture is still front and center however. While there are definitely limitations to what WP should responsibly be used for, some folks like to hash out poorly constructed ones.
Take the security updates aspect - it doesn't matter software you use - it will need updating. A vigilant attitude toward security should be the default for serious sites, regardless of the software used.
Same with cars, they can suffer all kinds of problems if not properly maintained. You can't force the car owner to take the car into the shop to perform said maintenance. That doesn't make the car fundamentally bad.
When people say something to the effect 'WP isn't secure', it's often made as a blanket statement to make it sound like WP is fundamentally weak. There have been very little serious problems with WordPress core itself. Security concerns and exploits are the reality of any software that is widely used, WP is no exception, but it's to be expected. If anyone likes to share any powerful software in use that has millions of users and manages to evolve constantly and stay perfectly robust against any imaginable attack - I'd like to hear some examples.
Back in the real world, what counts is building useful products that matter to its end-users.
Wordpress plugins, and the usage they get by (certain kind of) developers, have been my nightmare from the security and performance viewpoints, always I've been involved maintaining wordpress based solutions.
Anyway, wordpress is not the only web application affected by a this kind of bug (serialization, user input, eval, etc) in the late times.
I also like that I can have my content under version control.
I'm not sure there is a single software package that is powerful and popular that doesn't receive post-release updates and patches. If you want to convince a person to get off the software on to an alternative, it would have to at least approximate its capabilities. Moving to Pelican from WordPress is like ditching a computer for a calculator. If all you want to do is add and subtract, that's fine...but come on.
I'm surprised that the fix in Wordpress wasn't explicitly marking fields that need to be serialized/unserialized, instead of second-guessing based on the broken promise by MySQL.
> MySQL replaces characters it doesn’t recognize (for the given character set), with a placeholder. MySQL will sometimes replace byte sequences with “?” or “�” (U+FFFD). Such replacements would not be harmful.
This is so wrong. A database must never change any data that it's asked to stored. Wordpress, and other applications, always make that assumption, and when it isn't true anymore all hell breaks loose.
PS: it blows my mind that it looks like strpos in PHP could return either boolean or integer [1].
[1] http://core.trac.wordpress.org/browser/tags/3.6.1/wp-include...
I would also like to use this moment to go on a tangent with my unwilling audience that, not wasting any remote opportunity to badmouth php, or any other language for that matter, just for its standard library or trying to not break as much legacy code as possible, is bad form. Sure language syntax itself may suck, semantics may suck, I am always up for a good PL flamewar. If you want to bash the library, don't blame the language itself for the poor choices of the library.
cryptbe, I would like to apologise in advance and humbly request you to not take this personally.
Ruby on Rails has such ugliness too, a view helper called "escape_once": http://api.rubyonrails.org/classes/ActionView/Helpers/TagHel...
What's crazy is that I can't even find an "escape" helper. Ho it's called html_escape. Ho and there is a html_escape_once too!
Python Django too: https://docs.djangoproject.com/en/dev/ref/utils/#django.util...
I'll be in the corner.