Ah it’s WordPress again, sometimes I wonder how many holes there are in WordPress. I guess a dedicated attacker could find some serious ones with the complexity of the code base.
It’s suspected some of the recent high profile breaches have come from WordPress exploits.
The latest one to become public is a simple but effective flaw, it doesn’t enable take-over but it does allow a prankster to lock an admin out of their blog by resetting the password.
I actually saw the alert as it was published on Full-Disclosure, obviously anything to do with WordPress catches my attention.
The exploit can be executed by running the following code on a WordPress 2.8.3 blog:
http://www.namadomain.com/wp-login.php?action=rp&key
WordPress 2.8.4 has already been released so if you’re running WordPress do update ASAP to ensure you are safe from this bug.
With the core updates now available on auto-update there’s no excuse for not updating (no more download, extract, upload via FTP).
Of course with its history, this doesn’t mean you are safe from any of the other exploits that haven’t been made public.
Kalau kurang jelas, silahkan di translate di google…
Tutorial ini udah lama tersimpang di FD kesayanganku, sebelum dihapus mendingan ane share dulu…. Bruakakaakakaa…
Source : F1car | Personal Site