10 ms·
Multiple vulnerabilities in WP Fastest Cache plugin
- deleted 5y ago[deleted]
- andris9 5y agoHow come it is still not illegal to concatenate values into SQL queries instead of doing prepared statements
- tyingq 5y agoIt's worse...the call doesn't even support bind params. There is a "$wpdb->prepare()", but it's not real bind params, but rather a bunch of php quoting, escaping, and stripping. And in this case, they didn't even do that.
- antihero 5y agoSo basically, by lowering the barrier to entry and making it easy, they've actually made it difficult/impossible to write even slightly secure code whilst simulataneously encouraging the level of developer who has no idea what they are doing.
- latch 5y agoThe problem isn't so much concatenation, as it is, concatenation based on dynamic (e.g user-submitted) input. In some (admittedly rare cases), it's hard to avoid concatenation since not every part of an SQL query can be parameterized, such as table names. (Fun "fact", I vaguely remember that, once upon a time, even things like parameters in limit/offsets weren't universally supported. Also, and correct me if I'm wrong, first class support for arrays (e.g., via any($1)) is relatively new).
- deepstack 5y agoAll user input need to sanitised or check agains a data structure validating that is a valid input. Especially something like table names.
- sumtechguy 5y agoLegacy. Plus the ODBC layer is sort of 'broken' then add on nearly 25 years of examples on the internet. We have 2 modes of using ODBC/SQL. Almost tightly bound. Basically you have a bit of query string with question marks in it and you bind out your data points. Either for sending/receiving. Even passing in prepared strings could be an attack vector if you know what you are doing. As it breaks one of the 'rules' of secure programing trusting the client to tell you the correct thing. This however is the currently the only best way to do it, unless you go full on with the stored procedure pattern (which can still have injection attacks). Loosely bound. Here is a totally composed string ready to go just run it. Also a good way to make easy SQL injection attacks. Both involve string manipulation. Then a requirement of that interface is it has to sort of kind of work with at least 4 different SQL systems. Anyone who has had to port stored procs between some of these different SQL systems, can attest to, that they are not the same, except in some very basic ways. On top of that there are a lot of bad examples out there. But also once someone finally kind of gets something to work they may cut and paste that method. Which may or may not be good. Plus SQL has this stigma for many years of 'being hard'. I know I ended up as the 'SQL guy' for awhile because many in some of my orgs would not touch it. That is what the runtime environments have to deal with. Some paper over it with an API abstraction, some are better than others.
- hluska 5y agoThis is not the first time that WP Fastest Cache has had a SQL injection vulnerability discovered. Here’s a report on 0.8.4.8: https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-wp-fastest-cache-sql-injection-0-8-4-8/ https://www.acunetix.com/vulnerabilities/web/wordpress-plugi... Here’s a report on 0.8.7.4: https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-wp-fastest-cache-sql-injection-0-8-7-4/ https://www.acunetix.com/vulnerabilities/web/wordpress-plugi... I could go on (all night) but I trust you all get the point. I have two questions. First, at what point can we say “Emre, you’re really bad at writing code. There are lots of other jobs. Find another.” Second and more importantly for the future of the web, how can we as an industry protect innocent users from projects like this?? This monstrosity has over 1 million active installs and the chuckle head doesn’t have a fucking clue how to write SQL.
- loyukfai 5y agoAny similar caching plugin would you recommend instead?
- spurgu 5y agoPersonally I always go with Cache Enabler (by KeyCDN) with nginx. Simple and rock solid. Creates static HTML. For optimum performance (bypassing PHP altogether) configure nginx to try_files (or equivalent in Apache) in the wp-content/cache directory. Edit: I've also used WP Super Cache and W3 Total Cache quite extensively, both both of these have on some sites had a tendency to randomly clear the cache and I've never managed to figure out why. Cache Enabler has never done this.
- BarryMilo 5y agoI don't understand why people are trusting random WP contrib developers with cache anyhow? Is nginx no longer a thing?
- judge2020 5y agoConfigurablity and ease of use. Many people run Wordpress on cheap, shared hosting and would only have the option of a cache plugin. A lot of WP admins likewise have no command-line experience and couldn’t install nginx without resorting to Google.
- rado 5y agoHow is WP still missing built-in cache, CDN, multilingual support…
- partiallypro 5y agoI assume they want you to use JetPack which offers all of that (for free.) I just use WPRocket for caching, it seems to be the best.
- jikbd 5y agoAutomattic, the makers of Wordpress, have a free and very powerful cache plugin.
- danmur 5y agoIt's just not the fastest cache plugin (at least by name)
- robjan 5y agoIt's "good enough", in my experience, and works on nginx and Apache with minimal configuration. Some plugins break it and the object cache leaves a lot to be desired but for a basic wordpress you can pretty much activate it and forget it.
- jillesvangurp 5y agoThere are multiple plugins that do each of those things. There's no need to build it into the core product. I'm not a big fan of wordpress but am running it anyway for our corporate website (I'm the CTO) because it hits the good enough mark and it is just not worth my time trying to come up with something better. The big advantage of the current setup: I don't have to micromanage it beyond making sure we have backups and the site stays up and running. Our sales and marketing people manage the content and I don't have to babysit them. Win, win for me because I have more interesting things to do then maintaining a website. The downside: it's PHP and security vulnerabilities are a constant risk and worry with that. I just checked we are up to date and don't have this caching plugin installed. However, we have a constant stream of opportunistic bot traffic trying to exploit pretty much every vulnerability ever for wordpress, php, and php related tooling that we aren't even running. So, I'm more than a bit paranoid about any hypothetical way in.
- fabian2k 5y agoThat's a very obvious SQL injection, and a completely unnecessary one. I don't actually know how PHP handles this, but usually it's really not any more work to pass parameters as parameters and not concatenate them into the SQL string. And SQL injections are not an obscure or difficult to understand subject, it's probably the most obvious common security issue. There are cases where it's more annoying to do stuff in plain SQL and where you'd have to concatenate strings. But this is not one of them, is a simple parameter that needs to be passed to the query.
- mpol 5y agoIn WordPress there is the `$wpdb` class, that abstracts database access away. It is advised to use `$wpdb->prepare()` with prepared statements. Then you have an array with placeholders and an array with values, which the `$wpdb` class should handle correctly. But looking at this code, simply casting to an int with `(int) $id` in the `set_id()` method would have been enough.
- billpg 5y agoI'm a little surprised there isn't a general purpose option inside Apache. I'd like to go into my .htaccess and say "Any GET request that matches this regex, please cache and serve future requests from the cache for x seconds." (I'd set it to an hour normally and 6 hours if I'm on HN.) That sort of thing would be perfect for WordPress and similar CMSs.
- lixtra 5y agoDid you carefully read [1]? As noted by others many WP users don’t have access to the webserver or lack knowledge to configure it properly. [1] https://httpd.apache.org/docs/2.4/mod/mod_cache.html https://httpd.apache.org/docs/2.4/mod/mod_cache.html
- billpg 5y agoWordPress already has its own htaccess file for rewriting URLs into query string parameters. I wonder why it doesn't include a cache command as normal. The number of times I've gone to a page only to be faced with a MySQL error for too many connections.
- zapt02 5y agoMany plugins add dynamic pages to WordPress - e-commerce carts, membership plugins etc. If WP would just add a cache to everything they would not work. You might say that there could be an API for these plugin to register their uncached routes, but not everyone runs Apache - Nginx is also commonly used and would also need to somehow be supported. As someone who has written their own WP caching plugin, it's actually very convenient to perform the caching in PHP, because you can check for cookies and regex expressions for URLs, and there are many plugins that handle it well. For most sites I use a free one called Cache Enabler.
- mschuster91 5y agoThe people who use wordpress cache plugin are not really technical. They use 5$/month shared hosting crap where you can't configure anything more than mod_rewrite in .htaccess.
- JimWestergren 5y agoAnd that is why I have forbidden third party WP plugins at the company I work for - no exception. There is only 1 plugin and it is the one we write our self which take care of caching and all custom needs. Each line of code in that plugin is double checked and properly tested before going in production.
- webinvest 5y agoAnother solution is to pay a penetration tester or an offensive security expert to audit your website. They’ll probably load up Kali and run SQLMAP and Nikto against it and do some custom penetration testing.