<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Serious Wordpress Vulnerability/Exploit Verion 2.0.3 and Below</title>
	<atom:link href="http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Fri, 25 Jul 2008 11:12:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: ÃÃŠÂ£Fâ€¡Ã‘Â§ &#187; Blog Archive &#187; Registrazioni disattivate</title>
		<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-6497</link>
		<dc:creator>ÃÃŠÂ£Fâ€¡Ã‘Â§ &#187; Blog Archive &#187; Registrazioni disattivate</dc:creator>
		<pubDate>Sun, 20 Aug 2006 23:25:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-6497</guid>
		<description>[...] A causa di una pericolosa falla in Wordpress sono costretto a dover disabilitare temporanbeamente 8in attesa di una fix per tale bug) le registrazioni. pertanto,non sarÃ  piÃ¹ possibile registrarsi. Maggiori info sul bug QUI [...]</description>
		<content:encoded><![CDATA[<p>[...] A causa di una pericolosa falla in Wordpress sono costretto a dover disabilitare temporanbeamente 8in attesa di una fix per tale bug) le registrazioni. pertanto,non sarÃ  piÃ¹ possibile registrarsi. Maggiori info sul bug QUI [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress 2.0.4 Released - Fixes Security Issues &#187;</title>
		<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-4072</link>
		<dc:creator>Wordpress 2.0.4 Released - Fixes Security Issues &#187;</dc:creator>
		<pubDate>Mon, 31 Jul 2006 05:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-4072</guid>
		<description>[...] Secure?- WebScarab - Web Application Analysis - New Version   &#124; 1 Views &#124;            no comments   trackback this article      comment on thisarticle [...]</description>
		<content:encoded><![CDATA[<p>[...] Secure?- WebScarab - Web Application Analysis - New Version   | 1 Views |            no comments   trackback this article      comment on thisarticle [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Ripcord &#187; Blog Archive &#187; Site Taken Down For Wordpress Security Problem</title>
		<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-4069</link>
		<dc:creator>Security Ripcord &#187; Blog Archive &#187; Site Taken Down For Wordpress Security Problem</dc:creator>
		<pubDate>Mon, 31 Jul 2006 01:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-4069</guid>
		<description>[...] Some of you may have noticed that the site was down for a couple of days. This was because of an apparent flaw with Wordpress. While I was attending the ACUTA conference in San Diego I decided to catch up on the news. I am glad that I did because I noticed that Darknet had an entry about a newly discovered security vulnerability with all versions of Wordpress below 2.0.4 . Unfortunately his actual site was down and I was not able to read the full article. So I made a quick judgment call and decided to take the site down until I understood more about what was actually happening. [...]</description>
		<content:encoded><![CDATA[<p>[...] Some of you may have noticed that the site was down for a couple of days. This was because of an apparent flaw with Wordpress. While I was attending the ACUTA conference in San Diego I decided to catch up on the news. I am glad that I did because I noticed that Darknet had an entry about a newly discovered security vulnerability with all versions of Wordpress below 2.0.4 . Unfortunately his actual site was down and I was not able to read the full article. So I made a quick judgment call and decided to take the site down until I understood more about what was actually happening. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Code Cave</title>
		<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3779</link>
		<dc:creator>The Code Cave</dc:creator>
		<pubDate>Fri, 28 Jul 2006 04:35:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3779</guid>
		<description>[...] Thanks to some drastic and controversial actions taken by SpamKarma creator Dr. Dave, a large percentage of the blogging populace has been alerted to a security hole in WordPress. He even went to the effort of activating a warning message that was sent out to everyone who uses his SK2 plugin. This has resulted in a lot of fear spreading amoung a huge number of bloggers. This sort of thing just spreads exponentialy. Here&#8217;s a quasi random sampling of two dozen of the first posts on it: ....................... And these were just from the English blogs that post about this on the same day as the notice going out. The neat thing is that these are some of the most on-top-of-things bloggers out there. Those 24 blogs have some great content and gread visual styles. The are well worth perusing&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Thanks to some drastic and controversial actions taken by SpamKarma creator Dr. Dave, a large percentage of the blogging populace has been alerted to a security hole in WordPress. He even went to the effort of activating a warning message that was sent out to everyone who uses his SK2 plugin. This has resulted in a lot of fear spreading amoung a huge number of bloggers. This sort of thing just spreads exponentialy. Here&#8217;s a quasi random sampling of two dozen of the first posts on it: &#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.. And these were just from the English blogs that post about this on the same day as the notice going out. The neat thing is that these are some of the most on-top-of-things bloggers out there. Those 24 blogs have some great content and gread visual styles. The are well worth perusing&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kritikus hiba a wordpress 2.0.3 Ã©s rÃ©gebbi verziÃ³iban - kobak pont org</title>
		<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3738</link>
		<dc:creator>kritikus hiba a wordpress 2.0.3 Ã©s rÃ©gebbi verziÃ³iban - kobak pont org</dc:creator>
		<pubDate>Thu, 27 Jul 2006 18:43:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3738</guid>
		<description>[...] forrÃ¡s: darknet, dr dave  Ezekre klikk, ha menteni akarod a posztot. [...]</description>
		<content:encoded><![CDATA[<p>[...] forrÃ¡s: darknet, dr dave  Ezekre klikk, ha menteni akarod a posztot. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: An Information Security Place &#187; Blog Archive &#187; Serious flaw in Wordpress 2.0.3 and below</title>
		<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3724</link>
		<dc:creator>An Information Security Place &#187; Blog Archive &#187; Serious flaw in Wordpress 2.0.3 and below</dc:creator>
		<pubDate>Thu, 27 Jul 2006 13:48:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3724</guid>
		<description>[...] For my blogging friends out there using Wordpress, take serious note of this post from Darknet.Â  Seems like all versions of Wordpress below 2.0.3 are vulnerable (2.0.4 should be coming out very soon) to a flaw in the Subscriber functionality.Â  If you require people to register before they can comment, then you need to make sure you turn off the &#8220;anyone can register&#8221; option and delete any subscribers you do not not know personally or who have never posted or have not posted for a long time (personally, I don&#8217;t require people to subscribe to comment - you might consider either turning off comments or not requiring membership untiol 2.0.4 comes out). [...]</description>
		<content:encoded><![CDATA[<p>[...] For my blogging friends out there using Wordpress, take serious note of this post from Darknet.Â  Seems like all versions of Wordpress below 2.0.3 are vulnerable (2.0.4 should be coming out very soon) to a flaw in the Subscriber functionality.Â  If you require people to register before they can comment, then you need to make sure you turn off the &#8220;anyone can register&#8221; option and delete any subscribers you do not not know personally or who have never posted or have not posted for a long time (personally, I don&#8217;t require people to subscribe to comment - you might consider either turning off comments or not requiring membership untiol 2.0.4 comes out). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Navaho Gunleg &#187; WordPress users: Disable &#8216;Anyone can register&#8217;!</title>
		<link>http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3692</link>
		<dc:creator>Navaho Gunleg &#187; WordPress users: Disable &#8216;Anyone can register&#8217;!</dc:creator>
		<pubDate>Thu, 27 Jul 2006 06:57:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/#comment-3692</guid>
		<description>[...] Through Darknet I discovered that apparently a vulnerability has been found in WordPress that could allow evil people to do nasty stuff. Details remain vague though, but according to Dr Dave, one should disable the Anyone can register thingy in the Options of their weblog to prevent the vulnerability being exploited. [...]</description>
		<content:encoded><![CDATA[<p>[...] Through Darknet I discovered that apparently a vulnerability has been found in WordPress that could allow evil people to do nasty stuff. Details remain vague though, but according to Dr Dave, one should disable the Anyone can register thingy in the Options of their weblog to prevent the vulnerability being exploited. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
