Skip to content

Comment on GoDaddy apparently uninterested in fixing their security hole

Comments

So you found the exploit code, nice work. But you can't actually say how it got there? Prove it's not a WordPress 0day vulnerability allowing the file to be created.

I understand your frustration with being stonewalled by GoDaddy support, but look at it from their end. Unless you can prove it's a vulnerability in their service, why should they take action?

In order for it to be a Wordpress vulnerability there would need to be a corresponding entry in the http logs showing the request, either a GET or a POST, hitting whichever exploitable file it was within Wordpress itself. There is no such server request.

This is something that they could have seen in about 2 minutes of opening the http file and visually scanning the few hundred requests prior to the file in question being created.

Why should they take action? Really? Your replying as if "taking action" means something more than not ignoring potentially actionable information.

Btw... they do not make any of the other logs available to their tech support, let alone their customers. They should look into it because only they can look into it. To suggest that they were in the right in not at least checking it out seems an odd stance to take, tbh.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.