4 ms·
That's really pathetic, to put it mildly. Three weeks between initial contact and removal of compromised themes. Four months until public disclosure.
by zzleeper 5y ago
That's really pathetic, to put it mildly. Three weeks between initial contact and removal of compromised themes. Four months until public disclosure.
- smoe 5y agoPublic disclosure by the people that found the backdoor. I couldn't find any disclosure about it by AccessPress themselves between 15. October when they pulled the compromised themes and plugins to now.
- freebreakfast 5y agoThriveThemes still hasn't released a disclosure on an attack from March 2021.[0] This seems to be par for the course among theme developers. 0. https://www.wordfence.com/blog/2021/03/recently-patched-vulnerability-in-thrive-themes-actively-exploited-in-the-wild/ https://www.wordfence.com/blog/2021/03/recently-patched-vuln...
- benatkin 5y agoI never download from anywhere but wordpress.org and a lot of others don't, and that wasn't attacked, so I disagree that it's "pathetic".
- IncRnd 5y agoThat's not the timeline. It was a single day from contact to removal of compromised plugins. According to the article, the issue was that the vendor's contact form didn't work, not that the vendor didn't quickly remove the plugins. You are also confusing plugins with themes. They are not exactly the same.
- jcun4128 5y ago> vendor's contact form didn't work Had this happen recently to a site. The SMTP password was set wrong and I don't know how many months/years this form just failed to submit but no one was aware of it... was for a landing page type site.
- john-doe 5y ago> The attack was discovered by researchers at Jetpack, the creators of a security and optimization tool for WordPress sites. It’s a deceitful way to present it. Jetpack and WordPress are the same company.
- monkey_monkey 5y agoIt's not deceitful at all. Anyone who's in the WP ecosystem understands this. Jetpack is part of Automattic. Automattic's main thing is wordpress.com (the hosted platform). Automattic and WP.org are not the same thing even though ( as with many open source projects that have commercial implications) the lines are somewhat blurred. Presenting this as "deceitful" is really quite the over-reaction.
- john-doe 5y agoIf the lines are somewhat blurred, you can understand my initial confusion, not being “in the WP ecosystem” myself.
- monkey_monkey 5y agoSure. but perhaps think about the use of emotive words like "deceitful" when you don't fully understand what's going on?
- john-doe 5y agoEnglish as third language, so let’s say I didn’t realise it was such a strong word.
- Kye 5y agoEnglish is a mess. Deceitful implies intention. Qualifiers help. "Unintentionally misleading" fits better. It's like the difference between manslaughter (whoopsiedeath) and murder (intentional).
- 5y ago