An attacker gained access to the provisioning system for GoDaddy’s managed WordPress service

  • @AgreeableLandscape
    link
    102 years ago

    Wait, doesn’t Wordpress itself hash passwords? How the hell did they fuck this up?

    • KelsonV Old AccountOP
      link
      42 years ago

      Apparently it was the database and sFTP passwords that were exposed.

        • KelsonV Old AccountOP
          link
          52 years ago

          Yeah…but it looks like they were storing the passwords to connect to the sFTP service!!

          • @AgreeableLandscape
            link
            42 years ago

            Sigh. And the worst part is that nearly ever major web framework has a well known library for securely storing passwords.