6 ms·
PHPMailer is also used by wordpress: https://www.wordfence.com/blog/2016/12/phpmailer-vulnerability/ https://www.wordfence.com/blog/2016/12/phpmailer-vulnerabil
by rompic 10y ago
PHPMailer is also used by wordpress: https://www.wordfence.com/blog/2016/12/phpmailer-vulnerability/ https://www.wordfence.com/blog/2016/12/phpmailer-vulnerabili...
- koheripbal 10y agoIt's times like this I'm glad I have a country block setup through ipdeny. Reducing the likelihood of attack by two orders of magnitude is a big help until there's a patch.
- diegoperini 10y agoNo it is unfortunately not if there exists at least one company that provides a VPN service from your country. :)
- koheripbal 10y agoYou don't think there's any value in reducing penetration attempts by 2-3 orders of magnitude? I went from seeing an attack every few seconds to one per day/week.
- nkkollaw 10y agoHow do you monitor attacks?
- nkkollaw 10y agoNice. What countries do you block..?
- exratione 10y agoLooks like recent versions of WordPress may or may not reject emails with the quoted name format of "bad stuff"@example.com. Might depend on your plugins. My experimentation produced varied results for my sites and testbeds. filter_var($email, FILTER_SANITIZE_EMAIL) works for this exploit, as it removes spaces and double quotes. The SMTP plugins I surveyed still use PHPMailer. You'd want to try something like: /** * Block the PHPMailer vulnerability: * https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html */ function example_wp_mail_filter($args) { $new_wp_mail = array( # Get rid of quotes in quoted emails: "bad stuff"@example.com. Should be # sufficient sabotage. 'to' => preg_replace('[\'"]/u', "", $args['to']), 'subject' => $args['subject'], 'message' => $args['message'], 'headers' => $args['headers'], 'attachments' => $args['attachments'], ); return $new_wp_mail; } add_filter('wp_mail', 'example_wp_mail_filter');
- Piskvorrr 10y agoOh geez. That does block the exploit, but breaks the functionality. `"Random A. Person" <someone@example.com>` (Also, if the SMTP plugin uses PhpMailer, but actually is configured to talk to SMTP, there is no mail() and the issue is moot)
- tyingq 10y agoStock wordpress shouldn't be remotely exploitable with this. The exploit relies on the end user being able to specify the "From" address. That is passed to sendmail via the -f parameter on the command line, which is why the vulnerability exists. Other addresses, like To:, are passed via the headers/piped, so they don't create issues. Wordpress is adding a fix, but I assume that's to cover plugins that allow end users to set the From: address, like perhaps "Share this with a friend" type functionality where the email is meant to look like it's from a different domain. In short, I don't think most wordpress installations are remotely exploitable via this bug.