Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
Get HideMyAss! VPN, PC Mag's Top 10 VPNs of 2016 for 55% off for a Limited Time ×

Submission + - Large DDoS attack brings WordPress pingback abuse back into spotlight (cso.com.au)

angry tapir writes: Attackers have abused the WordPress pingback feature, which allows sites to cross-reference blog posts, to launch a large-scale, distributed denial-of-service (DDoS) attack, according to researchers from Web security firm Sucuri. The attack involved over 162,000 legitimate WordPress websites being forced to send hundreds of requests per second to a popular WordPress site, preventing access to it for many hours. The attack exploited an issue with the XML-RPC (XML remote procedure call) implementation in WordPress that's used for features like pingback, trackback, remote access from mobile devices and others, and brought back into the spotlight the denial-of-service risks associated with this functionality that have been known since 2007.
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Large DDoS attack brings WordPress pingback abuse back into spotlight

Comments Filter:

"When in doubt, print 'em out." -- Karl's Programming Proverb 0x7

Working...