Cotton Rohrscheib

The Cotton Club Blog & Podcast

  • Home
  • About
    • Entrepreneurial Journey
  • Blog
    • Faith & Family
    • Marketing & Tech
    • Farm & Business
    • Entertainment
    • Health & Wellness
    • Urban Farming
    • Weekend Projects
  • Podcast
  • Newsletter
  • Media
    • Photo Galleries
    • Video Archives
  • Marketplace
    • Buying Gold & Silver
    • Accoutrements
      • Bags & Briefcases
      • Notebooks
      • Personal Carry
      • Wallets
    • Poshmark
    • Artwork
    • Banknotes & Currency
      • Currency
      • Gold Banknotes
      • Silver Certificates
    • Rare Books
    • Rare Coins
      • Coin Sets
      • Individual Coins
    • Signs & Advertising
    • Stock Certificates
    • Trading Cards
      • Trading Cards: Autographs
      • Trading Cards: Base
      • Trading Cards: Graded
      • Trading Cards: Raw
      • Trading Cards: Pokémon
      • Trading Cards: Sets
    • Vintage Toys
      • Buddy L
      • Ertl Farm Toys
      • GI Joe
      • Masters of the Universe
      • Hot Wheels
      • Lionel Trains
      • Lunch Boxes
      • Marx Toys
      • NASCAR Die-Cast
      • Schleich Toys
      • Star Wars
      • Tonka Trucks
  • Connect
You are here: Home / Marketing & Tech / SQL Truncate & mt_rand()

SQL Truncate & mt_rand()

September 18, 2008 by Cotton Rohrscheib Leave a Comment

For anyone that may have wondered why the upgrade to 2.6.2 was so important, here’s a pretty good explanation I found on WordPress Developers Blog tonight.  It has to do with a SQL column truncation issue that could basically alter users login credentials, etc.

Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. 

The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.  Stefan Esser will release details of the complete attack shortly.  The attack is difficult to accomplish,  but its mere possibility means we recommend upgrading to 2.6.2.

Other PHP apps are susceptible to this class of attack.  To protect all of your apps, grab the latest version of Suhosin.  If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit.  You should still upgrade to 2.6.2 if you allow open user registration so as to prevent the possibility of passwords being randomized.

WordPress › Blog » WordPress 2.6.2

Filed Under: Marketing & Tech Tagged With: MySQL, PHP, Wordpress™

About Cotton Rohrscheib

The Cotton Club is a monthly podcast hosted by me, Cotton Rohrscheib. I'm a 52 year old entrepreneur w/ ADHD, OCD (and now AARP) that refuses to grow up as I grow old. I have collaborated and invested in hundreds of projects throughout my career in multiple industries such as; technology, healthcare, and agriculture. I also have 25 years experience in the marketing industry as a co-founder of an award-winning advertising agency. I will undoubtedly cover a wide variety of topics on my podcast while sharing some really crazy stories and situations that I've been fortunate to witness firsthand. I also have a book coming out in 2025 titled, "Mistakes were Made"

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Email
  • Facebook
  • Instagram
  • LinkedIn
  • Twitter

Recent Updates

  • Ep034: Cotton Rohrscheib & Tim Volberding
  • I Stay on Track w/ Reminders & Task Lists
  • It’s a Really Dry Start to the Season…
  • Trading Card Grading Services
  • Products Being Added…

Blog Categories

  • Blog (439)
  • Entertainment (378)
  • Faith & Family (155)
  • Farm & Business (302)
  • Health & Wellness (38)
  • Marketing & Tech (591)
  • Podcasts (33)
  • Urban Farming (24)
  • Weekend Projects (9)

Blog Archives

Join the Cotton Club!

 

Content Copyright © 2000-2026
Cotton Rohrscheib | Rohrscheib Capital
Disclaimer | Privacy Policy | Account Manager | View Cart

All opinions expressed on this website are 100% Cotton (see my disclaimer). All content, including text, images, and media, are the intellectual property of Rohrscheib Capital unless otherwise noted. To learn how we use your private information, checkout our privacy policy.