Researchers find serious flaws in WordPress plugins used on 400k sites

https://arstechnica.com/?p=1645061

The word

Serious vulnerabilities have recently come to light in three WordPress plugins that have been installed on a combined 400,000 websites, researchers said. InfiniteWP, WP Time Capsule, and WP Database Reset are all affected.

The highest-impact flaw is an authentication bypass vulnerability in the InfiniteWP Client, a plugin installed on more than 300,000 websites. It allows administrators to manage multiple websites from a single server. The flaw lets anyone log in to an administrative account with no credentials at all. From there, attackers can delete contents, add new accounts, and carry out a wide range of other malicious tasks.

People exploiting the vulnerability need only know the user name of a valid account and include a malicious payload in a POST request that’s sent to a vulnerable site. According to Web application firewall provider Wordfence, the vulnerability stems from a feature that allows legitimate users to automatically log in as an administrator without providing a password.

“Logical vulnerabilities like the ones seen in this recent disclosure can result in severe issues for Web applications and components,” Marc-Alexandre Montpas, a researcher at Web security firm Sucuri, wrote in a post. “These flaws can be exploited to bypass authentication controls—and in this case, log in to an administrator account without a password.”

Anyone running InfiniteWP Client version 1.9.4.4 or earlier should update to 1.9.4.5 immediately.

The critical flaw in WP Time Capsule also leads to an authentication bypass that allows unauthenticated attackers to log in as an administrator. WP Time Capsule, which runs on about 20,000 sites, is designed to make backing up website data easier. By including a string in a POST request, attackers can obtain a list of all administrative accounts and automatically log into the first one. The bug has been fixed in version 1.21.16. Sites running earlier versions should update right away. Web security firm WebARX has more details.

The last vulnerable plugin is WP Database Reset, which is installed on about 80,000 sites. One flaw allows any unauthenticated person to reset any table in the database to its original WordPress state. The bug is caused by reset functions that aren’t secured by the standard capability checks or security nonces. Exploits can result in the complete loss of data or a site reset to the default WordPress settings.

A second security flaw in WP Database Reset causes a privilege-escalation vulnerability that allows any authenticated user—even those with minimal system rights—to gain administrative rights and lock out all other users. All site administrators using this plugin should update to version 3.15, which patches both vulnerabilities. Wordfence has more details about both flaws here.

There’s no evidence that any of the three vulnerable plugins are being actively exploited in the wild.

via Ars Technica https://arstechnica.com

January 17, 2020 at 05:47AM

Xbox One Console Streaming Now Available Everywhere, Here’s How To Sign Up

https://www.gamespot.com/articles/xbox-one-console-streaming-now-available-everywher/1100-6472830/

While Microsoft’s xCloud game-streaming service remains only available as part of a limited test, the company is expanding its other new streaming offering. Microsoft announced today that Xbox Insiders in every country where Xbox Live is available can now test the console-streaming program that begun its limited beta rollout last year.

Console streaming allows players to stream the Xbox One games they already own to their Android phone or tablet from their console. This is done over Wi-Fi while at home and through your mobile data plan if you’re playing on the go.

The service requires a strong connection of 5 GHz Wi-Fi or mobile data connection at 10 Mbps down / 4.75 Mbps up. Since it’s a beta, only three titles are available to stream: Forza Horizon 4, Gears 5, and Sea of Thieves.

More details about console streaming can be found on Microsoft’s website.

“We view the public preview as an important step in our journey to deliver game streaming to Xbox players around the world! We are learning from Xbox Insiders like you whenever you participate in these new technologies,” Microsoft said.

The Xbox Insider program is free and available to everyone–you can sign up here. Once you’re accepted into the program, you can get started with the console streaming preview by following the instructions posted below, as written by Microsoft.

As for the Xcloud game-streaming service, this is a Netflix-style streaming service that allows users to stream games wherever they are over the internet. Microsoft is currently testing this in the US, UK, and Korea, with support for other parts of the world to come later.

Xbox Console Streaming Startup Guide:

  • You must be an Xbox Insider, in a supported region, with an Xbox One console enrolled in an Xbox One Update Preview ring to participate in the preview. Additional requirements:
    • A phone or tablet running Android 6.0 or higher, with Bluetooth 4.0 (mobile data charges may apply)
    • A Bluetooth-enabled Xbox One Wireless Controller
    • A Microsoft Account with Xbox profile, and high-speed Internet (ISP fees may apply)
    • While not required, we recommend a controller mount for those gamers testing on a phone
  • Download the Xbox Game Streaming (Preview) app from the Google Play Store.
  • The app will guide you through setup on your enrolled Xbox One. This includes a test to ensure your home network, console and controller are ready for Xbox Console Streaming:
    • The network test ensures your console’s network connection and setup meet the minimum requirements:
      • NAT type: Open or Moderate
      • Upstream bandwidth: At least 4.75 Mbps required, 9 Mbps preferred
      • Network latency: 125 ms or less required, 60 ms or less preferred
      • Console settings: Power setting must be Instant-on
    • For help improving your console’s setup, visit the Xbox Support website
    • For additional support, check out the Game Streaming Support Hub, or visit the Xbox Insiders Subreddit

Got a news tip or want to contact us directly? Email news@gamespot.com

via GameSpot’s PC Reviews https://ift.tt/2mVXxXH

January 16, 2020 at 04:52PM

Hyundai and Kia invest $110 million in UK electric van startup Arrival

https://www.autoblog.com/2020/01/16/hyundai-kia-invest-arrival-electri-delivery-vans/

Korea’s Hyundai Group is backing a UK electric vehicle startup that plans to begin selling battery-powered delivery vans in 2021, the companies said on Thursday. Hyundai and sister firm Kia are making the investment of $110 million (100 million euros or 84.34 million pounds) in Arrival.

Founded in 2015 and based in London, Arrival has developed a boxy, futuristic-looking shuttle bus aimed at the commercial delivery market. The company said its van will have a range between charges of 300 miles.

In a statement, Arrival said it will work with Hyundai and Kia to develop a variety of electric vehicles, initially for the commercial market. Those vehicles will be built on Arrival’s modular vehicle platform or “skateboard” that bundles motor, batteries and chassis components, similar to the skateboard developed by U.S. startup Rivian.

Rivian is backed by Ford and Amazon, and has a contract to build 100,000 electric delivery vans for the e-commerce giant, starting in 2021.

Hyundai and Kia last year invested $89 million in Rimac Automobili, a nine-year-old Croatian company aspiring to build electric supercars that is also backed by Porsche.

Arrival said its vehicles will be equipped with advanced driver assist features and can be upgraded with self-driving systems.

The vehicles are designed to sell for the same price as similar models powered by internal combustion engines and to be built in small “microfactories.” That strategy is the opposite of U.S. electric vehicle rival Tesla which uses massive “gigafactories.”

Last fall, Arrival, which until now has operated largely in stealth mode, hired General Motors veteran Michael Ableson to head its new North American operations.

With a small factory in Banbury, England, Arrival said it now has 800 employees in five countries, including Germany, Russia and Israel.

Arrival previously said it would use BlackBerry’s QNX operating system to connect safety features in its electric vehicles.

Arrival said its prototype delivery vans are being tested by the Royal Mail, DHL and UPS.

Related Video:

via Autoblog https://ift.tt/1afPJWx

January 16, 2020 at 04:42PM