首页> 外文会议>International Conference on Data and Software Engineering >A novel countermeasure to prevent XMLRPC WordPress attack
【24h】

A novel countermeasure to prevent XMLRPC WordPress attack

机译:一种防止XMLRPC WordPress攻击的新颖对策

获取原文

摘要

WordPress (WP) is one of the most popular PHP-based content management system (CMS) used for creating websites. WP became popular due to its many dynamic content management features including Pingback through XMLRPC, which sends a notification when other websites link to any one of the WP contents. However, WP XMLRPC Pingback does not have a mechanism to limit and validate whether any Pingback request actually originated from a linked post. Our experiment demonstrated that an attack with as few as 5 online WP websites is sufficient to take down a victim's WP-based website. The proposed countermeasure for this type of attack has then been shown to successfully prevent HTTP-GET attacks at the source.
机译:WordPress(WP)是用于创建网站的最流行的基于PHP的内容管理系统(CMS)之一。 WP由于其许多动态内容管理功能而变得流行,包括通过XMLRPC进行Pingback,当其他网站链接到任何WP内容时,该功能都会发送通知。但是,WP XMLRPC Pingback没有机制来限制和验证任何Pingback请求是否实际上源自链接的帖子。我们的实验表明,仅用5个在线WP网站进行攻击就足以摧毁受害者基于WP的网站。事实证明,针对这种类型的攻击提出的对策可以成功地从源头阻止HTTP-GET攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号