Live data from Hacker News

I found a WordPress RCEs with GPT5.6 and $25

slcyber.io

131–140 of 247 posts

Re: I found a WordPress RCEs with GPT5.6 and $25

#131
post #74

Earlier quoted context omitted.

Yeah; the common idea of dignity and self-respect is to replace the duct tape with proper engineering once you're successful though, instead of just taping ever more of it on top and pretending SQL injections aren't really a problem.

...but do they truly pretend SQL injections aren't really a problem, or do they in fact promote practices and provide pathways to reduce that risk?

What they do is put lipstick on a pig! There is no need to "reduce" the risk of SQL injections when you can use a safe API that eliminates the entire error class. This is a solved problem for the rest of the world!

Re: I found a WordPress RCEs with GPT5.6 and $25

#133

Earlier quoted context omitted.

Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…

[flagged]

Why would you reply with something completely unsubstantiated that anyone in security at that time worth their salt would be able to call you out on and then in subsequent comments call people liars for insisting it did, in fact, exist?

I’m just baffled.

Re: I found a WordPress RCEs with GPT5.6 and $25

#134
post #58

Earlier quoted context omitted.

Thanks! I wonder if Claude has something similar?

They do: https://portal.anthropic.com/programs/cvp

Though this program does not apply to Fable. Which is why most security researchers have started flocking to Sol.

Re: I found a WordPress RCEs with GPT5.6 and $25

#135

Earlier quoted context omitted.

The great irony is they still sport their "Code is Poetry" mantra on their website [0]. If code is poetry, Wordpress is a new genre of it, probably? [0]: https://codex.wordpress.org/WordPress_Philosophy

Vogon Poetry [1]? [1] https://hitchhikers.fandom.com/wiki/Vogon_poetry

Let's not insult Vogons, shall we?

Re: I found a WordPress RCEs with GPT5.6 and $25

#136

There is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k. The author works for https://www.assetnote.io/ , which has AI products for automated scanning.

> modified like they are holy scripture

So never modified at all, even if plainly contradictory and/or ethically and morally compromised?

Re: I found a WordPress RCEs with GPT5.6 and $25

#137

Earlier quoted context omitted.

Why would anybody trust criminals to pay them over time?

Because if they don't other people will hear they don't pay and won't sell them 0days

How long do you figure a criminal reputation typically needs/wants to last? I have always been skeptical of “black market credit ratings”. If you happen to build one up, it’s likely only in order to rip someone off at a higher price and cash in the value of it. It’s not like you’ll need that good rep for your retirement.

Re: I found a WordPress RCEs with GPT5.6 and $25

#138
post #121

Earlier quoted context omitted.

Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…

I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far m…

I currently work for a federal contractor including the DoD as their customer, using Wordpress as their main website. You would think there’s no sensitive information there, but some times all it takes is enough information about someone and their team to impersonate that person and gain access to an email thread, file sharing system or even an access card to a building. Never underestimate incompetence.

Re: I found a WordPress RCEs with GPT5.6 and $25

#139
post #59
post #18

Earlier quoted context omitted.

The WordPress codebase is a disgrace. PHP is a beautiful language by now, but they absolutely butcher it and refuse to do anything about that.

It's just because they don't want to break anything in existing sites, sorta like how Microsoft doesn't generally want to break programs on Windows. So, changes are fairly incremental, and the quality is about what you'd expect from a piece of software that's decades old with no plan for what happens if it got this far. But what do you do in that situation? If they change the structure too much, then either they make…

[deleted]
Post reply on HN