Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added Wordpress XMLRPC DoS #3624

Merged
merged 2 commits into from
Aug 7, 2014
Merged

Added Wordpress XMLRPC DoS #3624

merged 2 commits into from
Aug 7, 2014

Conversation

firefart
Copy link
Contributor

@firefart firefart commented Aug 7, 2014

This abuses the currently XMLRPC DoS vulnerability in Wordpress.

Verification steps

  • Install Wordpress (I used 3.9.1) and disable automatic updates so it will not update to 3.9.2 during your tests https://www.firefart.at/how-to-install-wordpress/
  • Run the exploit against the installation
  • Watch CPU consumption and MySQL connections running out

apache

@firefart
Copy link
Contributor Author

firefart commented Aug 7, 2014

Based on Nir's feedback I will also implement some basic memory size fingerprinting later on

@firefart
Copy link
Contributor Author

firefart commented Aug 7, 2014

Fingerprinting added

@wchen-r7 wchen-r7 self-assigned this Aug 7, 2014
@wchen-r7
Copy link
Contributor

wchen-r7 commented Aug 7, 2014

Will take a look today.

@wchen-r7
Copy link
Contributor

wchen-r7 commented Aug 7, 2014

Works as advertised. Landing.

@wchen-r7 wchen-r7 merged commit a7be5b5 into rapid7:master Aug 7, 2014
wchen-r7 added a commit that referenced this pull request Aug 7, 2014
@firefart firefart deleted the wordpress_dos branch August 8, 2014 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants