https://github.com/Icex0/wp2shell-poc 🏫 MY COURSES Sign-up for my FREE 3-Day C Course: https://lowlevel.academy 🧙♂️ HACK YOUR CAREER Wanna learn to hack? Join my new CTF platform: https://labs.lowlevel.tv ⌨️ KEYBOARD Like what you hear? Grab a Q5 at https://go.lowlevel.tv/keyboard 🔥COME HANG OUT Check out my other stuff: https://lowlevel.tv
ADVERTISEMENT
In the vein of t-shirts that say “It’s always DNS”, perhaps you need to make “No, Rust wouldn’t fix it” merch
I run a website, and I frequently get bots attempting to access the non-existent WordPress setup files
Wordpress hackable? I'm shocked. Shocked I say!
ahh please, when has WP not been vulnerable as hell?
SQL injection?? I see Bobby Tables has been busy.
2025: ai will save humanity 2026: we can't have websites anymore
I wish I could be surprised by "crap code in wordpress" but it's a "crap code in wordpress" situation xD
i run a website and i regularly get bots trying to access the non-existent wordpress setup files
I'm so glad you mentioned that this issue wouldn't be fixed by rust, I was about to rewrite the whole of wordpress in rust.
bro you are like chubby emu of the software universe
Claude, how many Thai restaurants use WordPress?
As a Wordpress developer for around 15 years, I can say wordpress situation was always absolutely insane. I'm not kidding, first thing we do is to forbid all access to crazy rpc routes and then moving wp-admin to another place, because we never know what will be the next vulnerability on this. I think their methodology is Backdoor Driven Development. Vulnerability bots sees a wordpress server: "I just hit the jackpooooot". It will try to nuke you with million known ways to exploit this flawed API.
No mention of being a meme in Fireship? Congrats.
It is 2006. Wordpress runs the internet and is vulnerable to sql injection. It’s is 2026. Wordpress runs the internet and is vulnerable to sql injection.
come hang out @ (newsletter, livestream, podcast) or don't im not a cop
Glad you noted at the end that rust wouldn't have fixed it, was worried for a sec
Yea, As a IT guy. Almost EVERYONE is on wordpress in South Africa atleast.
Wordpress hacked? wooow~ that's definitely never happened before 😂
If you didn't do it a week ago, also trigger a bit of forensics because you probably are pwned.
Everyone thinks they are the perfect engineer until its their server