• Jump to Content
Loading...
 
Got Root?  Accept no substitutes.
I forgot my password Register
in
Contact Us
Get Help!
Tiki Calendar
Mobile
Downloads >>
Wiki >>
Books >>
Blogs >>
Forums >>

Virtual Patch for Hidden Text Exploit

By: Michael Shinn on: Thu 24 of Apr., 2008 18:00 EDT (7637 Reads)
(0 bytes)
Print

Article image

SANS ISC (external link) (cache) brings us a report (external link) (cache) of a new method spammers are using to put links into blogs using hidden text. We don't consider this a WordPress vuln, but rather a class of problems revolving around hidden test. This is very reminiscent of the iframe attacks using hidden iframes. In the spirit of making the world a nicer place, we're publishing Modsec rules to protect against this problem. You can download the rules from here. Right now its one rule, but as we discover other ways to protect against this we'll update the file. If you are running ASL or have a subscription to the real time rules, this is included in the latest update automatically.


Sidebar

banner

Our Books

banner
RSS feed Wiki RSS feed Blogs RSS feed Articles RSS feed Forums
Theme: Fluid Index by Your Index
Linux Yum Channels      
Security Tools      
Network Management      
Remote Access      
VPN      
System Management      
Patch Management      
Suggest new downloads      
Docs Wiki Home      
Last Changes      
Dump      
Rankings      
List Pages      
Orphan Pages      
Multiple Print      
Articles Home      
List Articles      
Rankings      
Our Books      
Recommended Books      
List Blogs      
Rankings      
List Forums      
Rankings      
List of Donors