WordPress Search Based DOS Attack

Posted by admin in WordPress, WordPress... | 01.02.2010 - 4:23 am

I was notified on Twitter the other day that there was a new 0 Day denial of service exploit for WordPress. When asking on Twitter if it worked, numerous people replied that the published code did work and was taking down their sites. This raised some red flags for me so I jumped into the WordPress-Dev IRC channel to figure out what was going on.
The way this denial of service attack works is that a random search string is sent to the search form of a WordPress based website. Caching plugins do not work against this because the search string is randomized. It’s quite simple but what I’ve been told is that this is not an issue for WordPress to handle. Instead, this attack should be dealt with by the webhost on a firewall level. At one point, a ticket was created by Scribu but has since been closed as […]

Original post by Jeff Chandler

    Technorati Tags:

    Related Posts:
  1. Old WordPress version? Attack warning. Please upgrade!
  2. ...
  3. New WordPress Plugin: Better Search
  4. ...
  5. Best Of WLTC 2010 – Part 1
  6. ...
  7. WordPress Plugin Releases for 06/13
  8. ...
  9. Add WP Search Engines To FF
  10. ...
  11. Comment Rating Plugin Fixes Security Vulnerability
  12. ...
  13. WordPress on every Google Search?
  14. ...
  15. Add Voice Search to WordPress
  16. ...
  17. Why You Should Never Search For Free WordPress Themes in Google or Anywhere Else
  18. ...
  19. Beautiful CSS3 Search Form
  20. ...
  21. How to show ads to only search engine visitors using Who Sees Ads
  22. ...
  23. WordPress 2.7 UI Survey #2: Search box, Favorites menu, Future Publish
  24. ...
  25. WP Plugin: Magnify.net Multimedia Search and Embed
  26. ...
  27. How to Highlight Search Terms with jQuery
  28. ...
  29. WordPress Plugin Releases for 4/9
  30. ...

  31. No Comments on "WordPress Search Based DOS Attack" »

    No comments yet.

    Leave a comment