Earlier quoted context omitted.
Yeah; the common idea of dignity and self-respect is to replace the duct tape with proper engineering once you're successful though, instead of just taping ever more of it on top and pretending SQL injections aren't really a problem.
...but do they truly pretend SQL injections aren't really a problem, or do they in fact promote practices and provide pathways to reduce that risk?
I found a WordPress RCEs with GPT5.6 and $25
131–140 of 247 posts
Re: I found a WordPress RCEs with GPT5.6 and $25
#132Re: I found a WordPress RCEs with GPT5.6 and $25
#133Earlier quoted context omitted.
Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…
[flagged]
I’m just baffled.
Re: I found a WordPress RCEs with GPT5.6 and $25
#134Re: I found a WordPress RCEs with GPT5.6 and $25
#135Earlier quoted context omitted.
The great irony is they still sport their "Code is Poetry" mantra on their website [0]. If code is poetry, Wordpress is a new genre of it, probably? [0]: https://codex.wordpress.org/WordPress_Philosophy
Vogon Poetry [1]? [1] https://hitchhikers.fandom.com/wiki/Vogon_poetry
Re: I found a WordPress RCEs with GPT5.6 and $25
#136There is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k. The author works for https://www.assetnote.io/ , which has AI products for automated scanning.
So never modified at all, even if plainly contradictory and/or ethically and morally compromised?
Re: I found a WordPress RCEs with GPT5.6 and $25
#137Earlier quoted context omitted.
Why would anybody trust criminals to pay them over time?
Because if they don't other people will hear they don't pay and won't sell them 0days
Re: I found a WordPress RCEs with GPT5.6 and $25
#138Earlier quoted context omitted.
Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…
I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far m…
Re: I found a WordPress RCEs with GPT5.6 and $25
#139Earlier quoted context omitted.
The WordPress codebase is a disgrace. PHP is a beautiful language by now, but they absolutely butcher it and refuse to do anything about that.
It's just because they don't want to break anything in existing sites, sorta like how Microsoft doesn't generally want to break programs on Windows. So, changes are fairly incremental, and the quality is about what you'd expect from a piece of software that's decades old with no plan for what happens if it got this far. But what do you do in that situation? If they change the structure too much, then either they make…