Top Banner
Duncan Stuart @dgmstuart
17
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Snakes in a plugin - WordPress plugin security

Duncan Stuart@dgmstuart

Page 2: Snakes in a plugin - WordPress plugin security

@dgmstuart

“You can't defend. You can't prevent. The only thing you can do is detect and respond.”Bruce Schneier

Page 3: Snakes in a plugin - WordPress plugin security

@dgmstuart

WordPress dev for the public sector

Secure hosting

Plugin security reviews

www.dxw.com

Page 4: Snakes in a plugin - WordPress plugin security

@dgmstuart

The internet is a terrifying place

Page 5: Snakes in a plugin - WordPress plugin security

Demo

Page 6: Snakes in a plugin - WordPress plugin security

@dgmstuart

You can’t trust the ‘from’ field

You can’t trust the address bar

The internet is a terrifying place

What did we learn?

Page 7: Snakes in a plugin - WordPress plugin security

@dgmstuart

It’s much, much worse

@dgmstuart

Page 8: Snakes in a plugin - WordPress plugin security
Page 9: Snakes in a plugin - WordPress plugin security

@dgmstuart

Page 10: Snakes in a plugin - WordPress plugin security

@dgmstuart

It’s not unusual...

It’s the most common vulnerability

25% of plugins we review are unsafe

over 25% are conditionally safe

Page 11: Snakes in a plugin - WordPress plugin security

@dgmstuart

“I am regularly asked what the average Internet user can do to ensure his security.

Bruce Schneier

Page 12: Snakes in a plugin - WordPress plugin security

@dgmstuart

“I am regularly asked what the average Internet user can do to ensure his security. My first answer is usually 'Nothing; you're screwed'”Bruce Schneier

Page 13: Snakes in a plugin - WordPress plugin security

@dgmstuart

Page 14: Snakes in a plugin - WordPress plugin security

@dgmstuart

What can you do?

1. Update!

2. Pen test!

3. Mongoose!

Page 15: Snakes in a plugin - WordPress plugin security

@dgmstuart

Security alerts for WordPress plugins

www.mongoosewp.com

Page 16: Snakes in a plugin - WordPress plugin security

@dgmstuart @thedxw

www.dxw.com

Thank You

Page 17: Snakes in a plugin - WordPress plugin security

Questions?@dgmstuart