3 ms·
Well, the blog post presupposes you can get remote code execution on the WordPress server. There's very little you can do to secure yourself if the opponent alr
by mediumdeviation 10y ago
Well, the blog post presupposes you can get remote code execution on the WordPress server. There's very little you can do to secure yourself if the opponent already has RCE, because at that point the attacker has at least as much privilege as the application itself. In that case you have to fall back on limiting the amount of damage that can be done by respecting the principle of least privilege.