Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

WordPress auth cookie forgery

$
0
0
The use of non-strict comparison in WordPress’s cookie validation code could allow an attacker to forge authentication cookies by exploiting PHP’s type juggling system or by measuring timing differences between requests. Both attacks are a bit impractical, but rather fun.

read more......https://labs.mwrinfosecurity.com/blog/2014/04/11/wordpress-auth-cookie-forgery/

Viewing all articles
Browse latest Browse all 8064

Trending Articles