Oct 03

Patch for Host Overflow Application eXception

in Humor

I have crafted a simple Wordpress plugin to patch the Host Overflow Application eXception vulnerability. The vulnerability enabled me to take advantage of an unchecked buffer to post blog entries. It really is a simple fix, but I’ve encrypted the plugin contents so it is harder for people to exploit it.

The patch has been tested on the latest version of Wordpress, but I think it should work in 1.5 as well. Let me know if you believe your blog software is at risk and I will look into it.

Once the plugin is installed and activated you should see a notification box in your Wordpress admin console.

Download the Plugin

Update: Download link updated to work correctly

This was a joke played by myself and Randy. It was harmless and designed to cause people to more carefully check what Wordpress plugins they install.
4 comments

Tags:

RSS If you enjoyed this post, then make sure you subscribe to my RSS Feed.

Related Posts:

  1. Randy Charles Morin Identicon Icon
    October 3rd, 2006 at 12:32 pm

    Jason, the plug-in appears to be 404.

  2. Jason Schramm Identicon Icon
    October 3rd, 2006 at 2:52 pm

    I updated the link and it should now work fine. I was just missing the “http” in the url.

  3. Claudio Identicon Icon
    October 9th, 2006 at 4:51 am

    Host Overflow Application eXception = HOAX? ;)

  4. » Host Overflow Application eXception Makes Symantec’s Radar » InsideGoogle » part of the Blog News Channel Identicon Icon
    October 9th, 2006 at 12:05 pm

    [...] Jason Schramm and Randy Morin ran some funny posts about Host Overflow Application eXception, a supposed vulnerability in blog posting systems that let you hack into a blog and post on it. It wasn’t real, and it wasn’t supposed to fool anyone (read the capitalized letter: H-O-A-X. Do I have to paint a picture?), and quite a few bloggers got into the fun, posting hacked posts on their blog (including me). Jason even posted a “patch” that posted in your blog’s footer: Host Overflow Application eXcepton = HOAX You are gullible, but what if this plugin was malicious? [...]

Leave a Reply

© 2006-2007 Jason Schramm. Site design by Jason Schramm.
Jason Schramm is the man.