Page 1 of 2 12 LastLast
Results 1 to 10 of 19

Thread: Possible Security Threat?

  1. #1
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,359

    Default Possible Security Threat?

    Received this from Badcat today on Twitter and from the looks of it, seems like a serious flaw. Can anyone else confirm the validity or severity of it?

    http://perishablepress.com/press/200...for-wordpress/

    I'm in the IRC Dev chat to see what they say.

  2. #2
    andrea_r's Avatar
    andrea_r is offline WordPress Rockstar
    Join Date
    Jan 2009
    Location
    Eastern Canada
    Posts
    1,325

    Default

    This has actually been present for a long, long time. remember Root? And pre-Habari days? This came up then.

    In many other CMS installs, removed index-install.php is pretty much standard.

  3. #3
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,359

    Default

    So are you saying that if install.php was removed, this probably would have kept anyone from reinstalling WordPress? If this is the case, how come WordPress does not warn people upon the end of installation to remove this file? I know Vbulltin does this and I think PHPbb does this as well. In fact, they won't let you into the administration area unless that file is deleted.

  4. #4
    itsananderson's Avatar
    itsananderson is offline Big Tipper
    Join Date
    Jan 2009
    Location
    Terre Haute, IN
    Posts
    354

    Default

    If you've already installed WordPress though, the install.php file won't let you install it again, so I don't see this as a huge security threat. Obviously it would be more secure if you removed the install.php file, but I suspect the instructions don't have you do this because it might make the install process too confusing or difficult for some people.

  5. #5
    Leland's Avatar
    Leland is offline Hello World
    Join Date
    Mar 2009
    Location
    US
    Posts
    60

    Default

    Well, I said this on Twitter too...but I know that Joomla pretty much cuts off access to everything (front-end and administration) until you've deleted the install directory, after the installation is over.

    Can't really see how it could hurt to at least recommend deleting the install.php file after installing WordPress? Like it said in that Perishable Press post, it's not really needed after installation so I can't think of any reason why you'd still want it there.

  6. #6
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,359

    Default

    but what if the database server crashed and when it came back online, your database was empty meaning you could install WordPress right away again. I think this is a fringe case but it shows that it's possible. So wouldn't removing install.php simply prevent this fringe case from happening?

  7. #7
    Brad is offline Here For The Peanuts
    Join Date
    Jan 2009
    Location
    USA
    Posts
    142

    Default

    At minimum, the instructions here should be updated.
    http://codex.wordpress.org/Installin...Minute_Install

    Deleting the file as a part of the install (similar to Joomla) would be best.

  8. #8
    chipbennett's Avatar
    chipbennett is offline WordPress Legend
    Join Date
    Feb 2009
    Location
    St. Louis, MO
    Posts
    1,997

    Default

    Quote Originally Posted by Jeffro View Post
    but what if the database server crashed and when it came back online, your database was empty meaning you could install WordPress right away again. I think this is a fringe case but it shows that it's possible. So wouldn't removing install.php simply prevent this fringe case from happening?
    But since everyone follows good practice, and maintains regular backups, wouldn't the best course of action be to restore the database from backup? ;)
    WP TurnKey - Turn-Key WordPress installation and maintenance services
    WordPress user since 2005 | @chip_bennett | chipbennett.net | cbnet Plugins

  9. #9
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,359

    Default

    Yes, but what if this happens at night and you don't get the chance to restore until a few hours after the site has been compromised. I know I'm bringing in quite a few What Ifs. I've been in the IRC room all day today and even some of the WordPress guys are stumped. I can't get a straight answer on whether removal of install.php would prevent this from happening, I also can't figure out if this is a security hazard or an obscure bug.

  10. #10
    Ryan's Avatar
    Ryan is offline WordPress Legend
    Join Date
    Jan 2009
    Location
    New Zealand
    Posts
    2,801

    Default

    It looks like a security hazard they've chosen to ignore since it is so unlikely to actually occur.

    Mark Jaquith said in that post that he's never seen this happen before.

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •