TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Details on the Network Solutions / Wordpress mass hack - How it happened

13 pointsby fseekabout 15 years ago

4 comments

jbmabout 15 years ago
Out of curiosity, how could one program something to access the DB without storing the password somewhere on the server? That seems to be the main weakness they are discussing, but it doesn't seem to be easy to store the password on the server without a trivial way to exploit it.
评论 #1255375 未加载
charliesomeabout 15 years ago
Awesome, this never occurred to me. Even though it was a very simply hack, you've got to applaud the hackers for thinking outside the box in the first place and going "Hrmm... I wonder if anyone has left their wordpress config as 755? And how can I use that to my advantage?"
sucuri2about 15 years ago
The attack was very simple, basically scanned all sites hosted there for wp-config.php with the wrong permissions. If it found, got the db information and modified it.
dale-cooperabout 15 years ago
Why weren't their users chrooted to their own directory?