6 ms·
Wordpress is one of the most insecure platforms out there. Avoid using it if you care about security.
by Apofis 5y ago
Wordpress is one of the most insecure platforms out there. Avoid using it if you care about security.
- Tomte 5y agoAs I said: with this setup, all the readers (everyone but me) do not even hit any Wordpress code anymore. It truly is a static site generator. You can look at the generated HTML files in the file system. That's what the web server serves.
- speedgoose 5y agoIf you can login or comment, you do hit Wordpress code right? It could be fine if you put the admin portal behind a firewall but I would also recommend moving forward and stop developing new websites using Wordpress if you care about security. And you should probably care about security.
- KarlKemp 5y agoIf it generates something, it can still do whatever it wants with the generated files if the purpose is to, for example, embed spam links. If the server is the target, it either still has access to it, or to some alternative computer which, for a private individual writing a blog, will be their much more valuable personal device. Yes, you can spin up a VM, generate html, run it through all sorts of tests and only then upload it. The victims of this hack aren’t going to do that.
- Tomte 5y agoThat's a threat model that is wildly imaginative. Tell your web server to only serve the login stuff to you (certificates, HTTP Basic Auth, whatever). Problem solved. And what is your solution? A SSG also generates something and could embed bad stuff. Something has to upload your SSG generated files and thus needs access to your web server. If you're running it on your personal device it could compromise it. Really, stop trying so hard to invent Wordpress problems. If you don't like it, nobody forces you to use it.
- ifdefdebug 5y agoDid you remove all the code pages? Otherwise, an attacker is not restricted to following links on your site, they can access the code urls directly?
- Tomte 5y agoNo, they can't. As I said, the nginx or Apache configuration makes sure. Look it up, you're routing everything to static files in file system directories. Only if you are requesting an URL (however "you" are identified) the webserver even contemplates serving something else. It's an explicit rule for the special case. Everyone else doesn't see a PHP-FPM execution path at all.
- apatters 5y agoThis comment is a lame hit job. WordPress is the most widely used publishing platform in the world and highly extensible, so there are always going to be third party plugins and themes which get compromised. If security is a concern you can simply avoid third party plugins and themes, or limit your use of them to reputable vendors who have good track records. The code of WordPress itself is pretty robust and the Core team has a great history of fixing vulnerabilities quickly.
- javchz 5y agoIn my experience it's quite the opposite. It's not perfect, but it's safe enough for most users. As long as you have WP updated, and a good configuration with your stack (PHP, MySQL, Nginx) it's hard to hack. The main vulnerabilities come from 3rd party plugins and themes, and shared hosting with older versions of the stack. It's like faulting windows for vulnerabilities in an external .exe app. If you use the default setup, and follow security guidelines, you should be ok.
- jbverschoor 5y agoIt is windows' fault. Its their platform, architecture, their default configurations, sandbox, UX for security, etc
- withinboredom 5y agoBy this extension, you should be saying it is the Linux kernel’s fault all these sites were hacked.
- Apofis 5y ago90% of installations don't do this.
- KarlKemp 5y agoThe issue here was plugins from compromised third-party repository. This has little to do with WordPress. It’s the mechanism Apple refers to as justification for the App Store monopoly which, I guesss, is hated on alternative days to supply chain hacks.
- anakaine 5y agoThis comment is a load of nonsense. Wordpress core has regular and comprehensive security reviews. Wordpress is the most deployed publishing platform globally. Like with any web application you should be deploying it behind a Web application firewall with a fit for purpose ruleset, and additionally with wordpress you can integrate one of several application firewalls into the application - several of which have decent full time security and development teams that actively discover, patch and mitigate zero days and new exploits. Anything you add beyond that is on you, and you should be vetting your vendors or own code properly. I have to wonder what your purpose for attack here is. Are you developing a competing product?
- kevincox 5y agoI don't know enough to comment about WordPress. But a secure applications don't need a WAF to be secure. WAFs in the steady-state are really just fuzzy bug injectors that hope to inject bugs over top of exploitable code. The main use for WAFs that I consider valid is emergency response to recently discovered vulnerabilities while a patch is being discovered and applied. The other use case is external rate limiting and DoS protection. But most often it is better to do that in the app anyways.
- anakaine 5y agoThey do plenty more than that: - Can section off certain requests - Can rate limit - Can catch basic injection attacks With the wafs that integrate with WP such as wordfence they can also do things like: - Check for bad file permissions - Check for bad web server configuration - Recieve ruleset updates for zero days that are actually threat surface specific Having a WAF in place that is threat surface specific isn't as much about saying "its not needed if the code is good" as much as it is saying "the code might not always be good. We are not perfect. I'm at least going to have an extra layer or two of defence to try and stay safe(r) and give me some breathing room between an exploit and a patch".
- kichimi 5y agoIt's just the oft touted "WordPress is insecure" meme.
- simion314 5y agoYour Favorite platform will be exactly the same if a bad guy has access and inserts it;s code or if you are dumb enough to install a random third party code from a random website. My personal blog uses one of the default themes, I hosted extremely cheap, I NEVER touch it because it is autoupdated and it just works. I did not review WordPress code so I can't tell how secure it is, but using this article to do a lazzy hit on WordPress is pathetic, this issue is as related with WordPress as you installing an .exe fom a random website is a Windows issue.
- sshine 5y agoWordPress is insecure by design. tl;dr: Use a static site generator. The biggest reason is that its pages are not statically generated and allows for code execution when they contain no dynamic content. The second biggest reason is the marketplace for plugins and themes; even if WordPress security audited their entire standard release, every single theme or plugin you install could compromise your installation. You’d think of a theme as something that provides colors and spacing, but they’re fully executable programs. WordPress is conveniently written in PHP, which attracts inexperienced programmers with no understanding of web security. The attack that OP links to is a supply-chain attack made possible by WordPress’es software architecture, but it could have happened on most more secure alternatives if they were equally popular. So while it’s easy to ridicule WordPress for having no security and a poor architecture to withstand most attacks, we mustn’t forget that it’s a combination of its huge popularity and the ease of use caused by its simplistic choices that has lead to this breach.
- sdze 5y ago> WordPress is insecure by design. Is there a proof for that?
- blowski 5y agoIf the critics spent as much time building and selling what they see as the “better option” to WordPress, perhaps we wouldn’t be in this place. As it is, they just do the easy thing, playing “pigeon chess” by making these hackneyed, unsupported assertions. A better assessment is that WordPress has made trade-offs regarding security, as anybody in the real world must. Individuals must also make their own trade-offs, including whether to run WordPress at all, then how to configure it and which third-party code to use. Sometimes we get the trade-offs wrong, and that should affect how people make future decisions.
- xorcist 5y agoPHP has a pretty good deployment story in FPM since 10+ years. Every worker can run in a read-only chroot, or with separate uids. Wordpress has only one entrypoint and only needs to write to its data directory, so it's quite decent. The big issue with wordpress is with the vast plugin system, where all bets may be off depending on what you run.
- cyptus 5y agojust don’t install tons of untrusted plugins and themes like you would also not do on any other platform you host. even whitehouse.gov uses WordPress: https://wordpress.org/showcase/the-white-house/ https://wordpress.org/showcase/the-white-house/
- Apofis 5y agohttps://www.searchenginejournal.com/wordpress-core-vulnerabilities/432042/ https://www.searchenginejournal.com/wordpress-core-vulnerabi...
- ChrisMarshallNY 5y agoI have had a different experience. I’ve been using WP since it was a wee bairn, and have written a number of plugins and themes, over the years. It is not for every use case. I think some of the new static site generators are great, but WP fits the bill, when we need a fairly dynamic, configurable, maintainable, site. The “security issues” are, IMNSHO, a reflection of the much wider “depenecapocalypse,” that is plaguing the entire software development industry, where lightly-trained, and inexperienced, devs, slap all kinds of executables into their projects, with hardly a glance at the bona fides of said executables, which, in my experience, can be … questionable. I admit that I have created “Frankensites,” by using too many plugins (in fact, today, I am about to rewrite one, using as "bare bones" an architecture, as possible). Even good plugins can have a limited shelf life, and I have learned (the hard way) that paying for extensions and themes buys me almost nothing. I have been aghast, when examining the code, in some of these. There’s a lot of crap WP code, out there, but I have been fairly impressed with the quality of the code and architecture of the core system. The one thing that I think needs improvement, is the WordPress Codex. It’s a mess. I’m often better served, examining the code directly, than relying on that. I don't do Web sites as a living. There's millions of better Web developers than me. I like to be able to walk away from a site, and let it stand on its own. WP has served me well, for that.
- marc_io 5y ago> The one thing that I think needs improvement, is the WordPress Codex. The original Codex can be considered obsolete as it has been replaced by developers.wordpress.org which is much more informative and up to date.
- sdze 5y agoI personally love the WordPress Hook system. You really can manipulate everything with plugins.
- herbst 5y agoAll my logs, if wordpress or not, get constantly hammered with random wordpress backdoor requests. Even if it were generally secure, the one day it's not can break everything.
- goatherders 5y agoSimply not true. WP core is very secure.