
內容簡介
DGXPCO(Digital Guarantees for eXplicitly Permitted Core Operations)是一個概念驗證的加密簽名驗證外掛程式,用於WordPress軟體更新。此外掛程式會提供WordPress核心更新的手動(離線)簽名,並在未驗證更新內容為遠端簽名時,防止應用程式進行更新。
此舉為WordPress更新的完整性提供了第二個真實性源,超越了WordPress更新伺服器標頭中提供的MD5內容雜湊值。如果更新伺服器遭到入侵,也不太可能入侵存儲文件簽名的伺服器。如果簽名無法驗證,您就可以知道您的網站得到了保護,不會受到攻擊的影響。
外掛標籤
開發者團隊
原文外掛簡介
DGXPCO (Digital Guarantees for eXplicitly Permitted Core Operations) is a proof-of-concept cryptographic signature verification utility for WordPress software updates. The plugin will source manual (offline) signatures for WordPress core updates and prevent the application from updating unless the contents of the update payload are verified with a remote signature.
This provides a second source of truth for the integrity of WordPress updates beyond the MD5 content hash supplied in the header from the WordPress update server. If that server were ever breached, it’s unlikely the server hosting the signatures of the files was also breached. If the signatures ever fail to validate, you can know your site was protected from an attack.
