PhotoDune

Why do people use wordpress?

624 posts
  • Bought between 10 and 49 items
  • Exclusive Author
  • Has been a member for 3-4 years
  • Sold between 100 and 1 000 dollars
Thecodingdude says

@thecodingdude actually LOOK at your WP-config file.

You’ll notice ‘DBPASS’ is stored as a one time hash?

Do you know what that means?

/** MySQL database password */
define(‘DB_PASSWORD’, ‘password_here’);

include(”../wp-config.php”);
echo DB_PASSWORD;

Why don’t you try it?

812 posts
  • Bought between 10 and 49 items
  • Exclusive Author
  • Has been a member for 3-4 years
iamthwee says

Since when does anyone have their wp-config file configured with the password stored as plain text such as:

define(‘DB_PASSWORD’, ‘password_here’);

I really don’t know if you’re being serious?

624 posts
  • Bought between 10 and 49 items
  • Exclusive Author
  • Has been a member for 3-4 years
  • Sold between 100 and 1 000 dollars
Thecodingdude says

Since when does anyone have their wp-config file configured with the password stored as plain text such as:
define(‘DB_PASSWORD’, ‘password_here’);
I really don’t know if you’re being serious?

I am being serious and yes people do.

812 posts
  • Bought between 10 and 49 items
  • Exclusive Author
  • Has been a member for 3-4 years
iamthwee says

[Edit] I just got what you meant…

523 posts
  • Author had a File in an Envato Bundle
  • Author had a Free File of the Month
  • Bought between 10 and 49 items
  • Contributed a Blog Post
  • Contributed a Tutorial to a Tuts+ Site
  • Denmark
  • Exclusive Author
  • Has been a member for 2-3 years
+5 more
Zeplix says

Why would you give someone your passwords in the first place? o0

900 posts
  • Bought between 100 and 499 items
  • Elite Author
  • Exclusive Author
  • Has been a member for 5-6 years
  • Referred between 200 and 499 users
  • Sold between 100 000 and 250 000 dollars
  • United States
michaelhejja says

The same reason people eat at McDonalds. Speed and price. Everybody knows it’s garbage, but people use it anyways.

900 posts
  • Bought between 100 and 499 items
  • Elite Author
  • Exclusive Author
  • Has been a member for 5-6 years
  • Referred between 200 and 499 users
  • Sold between 100 000 and 250 000 dollars
  • United States
michaelhejja says

*dupe

3370 posts
  • Australia
  • Bought between 100 and 499 items
  • Exclusive Author
  • Has been a member for 2-3 years
  • Interviewed on the Envato Notes blog
  • Microlancer Beta Tester
  • Sold between 1 000 and 5 000 dollars
Australia says

The same reason people eat at McDonalds. Speed and price. Everybody knows it’s garbage, but people use it anyways.

I hate Wormpress with a passion.

2355 posts
  • Has been a member for 4-5 years
  • Exclusive Author
  • Europe
  • Bought between 10 and 49 items
  • Referred between 100 and 199 users
  • Sold between 100 and 1 000 dollars
  • Microlancer Beta Tester
digitalimpact says

And so it begins…

Up next: iOS vs. Android.

1844 posts
  • Elite Author
  • Sold between 100 000 and 250 000 dollars
  • Author had a File in an Envato Bundle
  • Has been a member for 4-5 years
  • Author had a Free File of the Month
  • Won a Competition
  • Bought between 10 and 49 items
+4 more
bitfade says

include(”../wp-config.php”);
echo DB_PASSWORD;
That’s how all php cms work, you need to set db password somewhere. If somebody has access to your filesystem then you’re just screwed and can’t really blame wordpress for that.

Remote exploits have been found in core files but much less frequently than other popular cms like joomla just to name one. The real problem are themes and plugins coded without any security check.

by
by
by
by
by