首页> 外文会议>International Conference on Data and Software Engineering >A novel countermeasure to prevent XMLRPC WordPress attack
【24h】

A novel countermeasure to prevent XMLRPC WordPress attack

机译:预防XMLRPC WordPress攻击的新型对策

获取原文

摘要

WordPress (WP) is one of the most popular PHP-based content management system (CMS) used for creating websites. WP became popular due to its many dynamic content management features including Pingback through XMLRPC, which sends a notification when other websites link to any one of the WP contents. However, WP XMLRPC Pingback does not have a mechanism to limit and validate whether any Pingback request actually originated from a linked post. Our experiment demonstrated that an attack with as few as 5 online WP websites is sufficient to take down a victim's WP-based website. The proposed countermeasure for this type of attack has then been shown to successfully prevent HTTP-GET attacks at the source.
机译:WordPress(WP)是用于创建网站的最受欢迎的基于PHP的内容管理系统(CMS)之一。由于其许多动态内容管理功能,WP变得流行,包括通过XMLRPC Pingback,它在其他网站链接到任何WP内容时发送通知。但是,WP XMLRPC pingback没有限制和验证是否源自链接帖子的任何Pingback请求的机制。我们的实验表明,与5个在线WP网站的攻击足以取下受害者的基于WP的网站。此类攻击的提出对策已经显示成功阻止HTTP-GET攻击源。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号