11/1/2007 ↓

ModSecurity and Wordpress

Thanks for visiting! If you're new here, you may want to subscribe to our RSS feed. This blog posts regular Wordpress news, updates of themes, plugins, ideas, hacks, quick fixes and everything about blogging, especially about Wordpress. Go ahead, subscribe to our feed! You can also receive updates from this blog via email.

Daniel Cuthbert has written a paper on ModSecurity and Wordpress. While I praise the work and the effort, I am not sure why they did not find it in themselves to protect the PDF document that they are distributing using some sort of an SHA1 checksum or the like to ensure the integrity of the download. Now I know that these guys know what they are doing but I have a problem with security related papers, help documents, scripts and other items when they cannot be verified with the source and the source itself cannot be verified with the original author of the product.

I have always been a big proponent of mod_security and I think it provides a comprehensive layer of web security without as much overhead. Although I have never thought of WordPress’ security to be as weak as the BlogSecurity folks have claimed it to be. mod_security requires various rules to be put in place for it to filter out malicious activity. This paper goes through some of those generic PHP rules and some specific WordPress based rules for webmasters to add to their mod_security filters.

1 Star2 Stars3 Stars4 Stars5 Stars (6 votes, average: 4.33 out of 5)
Loading ... Loading ...
Sphere: Related Content | stumbleit |
Translate to German Translate to Spanish Translate to French Translate to Italian Translate to Portuguese Translate to Japanese Translate to Korean Translate to Russian Translate to Chinese

Latest Videos

Latest WordPress Jobs

6 Comments | Leave a comment | Comments RSS

  1. Although I have never thought of WordPress’ security to be as weak as the BlogSecurity folks have claimed it to be.

    Your kidding me right? :)

    David Kierznowski (2 comments.) — 11/1/2007 @ 7:48 am
  2. With regards to the security of the pdf, i’m a little confused here. If it was source code we could have offered the usual methods of signing, but I have written many papers in my lifetime and never come across this request. If you want I can add a md5sum of the paper?

    Wordpress isn’t secure. The developers have constantly shown a lack of regard, and understanding, of the Secure Development Life Cycle, which is why every new release includes various security issues.

    Daniel (1 comments.) — 11/1/2007 @ 9:07 am
  3. Daniel: You are offering up code inside the PDF for people to use. If that PDF is copied to another blog/server and the contents modified to suit nefarious purposes, or if the transmission is modified in transit, it could prove to be a security risk on its own since your goodwill will still be associated with it. Your confusion concerns me.

    As for your concern about the WordPress developers’ lack of regard, I whole heartedly disagree. I cannot speak for them but my observation is that the best possible solution(s) is(are) chosen from the list of available resources and options for code. Security is one of the major concerns of the developers and it is taken as seriously as possible. I have always encouraged people with an interest in WordPress to roll up their sleeves and dive into the code as and when they can help. It is not a one way street. If there was one point of code development and only one source control (such as Wordpress.com) then security could be better cordoned off. If a whole bunch of people can inject code into the source (such as freely available plugins and themes), controlling their outcome becomes even more difficult. However, this is not an excuse but a predictor of further work that needs to be done.

    Also, assailing the developers of being callous is probably not very productive nor is it very effective in getting results since complaining only makes people ignore you and real code and real solutions are more welcomed. You are doing good work with good intentions. I suggest that you do not taint it with negativity.

    Mark Ghosh (198 comments.) — 11/1/2007 @ 9:35 am
  4. Mark, as Daniel mentioned we could offer an MD5 or SHA1 checksum with the PDF its fairly easy to do. I guess this is only really useful if the PDF is distributed and accessed on other web sites - this often applies to tools rather then papers.

    Getting back to the to avoid ambiguity: implementing these rules will definitely add an awesome layer of security to a WordPress blog! Daniel, as I have said before, kick ass work my man!

    David Kierznowski (2 comments.) — 11/1/2007 @ 10:40 am
  5. David/Daniel: SHA1 checksum should work just fine. Thank you!
    Mark Ghosh (198 comments.) — 11/1/2007 @ 11:49 am
  6. [...] read a paper on Blogsecurity, posted also on wordpress planet a few minutes ago about excellent way to securing the Wordpress blog with Modsecurity. The writer [...]

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required, will not be published)


S2