<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress 2.8.3 Admin Reset Exploit</title>
	<atom:link href="http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: dozaaaar</title>
		<link>http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/#comment-158655</link>
		<dc:creator>dozaaaar</dc:creator>
		<pubDate>Thu, 13 Aug 2009 04:46:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2013#comment-158655</guid>
		<description>This attack vector bypasses the empty() checks but does not yeild an empty string as the value in the WHERE clause, rather it yeilds the string &#039;Array&#039;...therefore NOT A PROBLEM.</description>
		<content:encoded><![CDATA[<p>This attack vector bypasses the empty() checks but does not yeild an empty string as the value in the WHERE clause, rather it yeilds the string &#8216;Array&#8217;&#8230;therefore NOT A PROBLEM.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: free</title>
		<link>http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/#comment-158653</link>
		<dc:creator>free</dc:creator>
		<pubDate>Wed, 12 Aug 2009 19:01:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2013#comment-158653</guid>
		<description>rather annoying exploit, especially if you dont have direct access to the db.
good thing they already fixed it .</description>
		<content:encoded><![CDATA[<p>rather annoying exploit, especially if you dont have direct access to the db.<br />
good thing they already fixed it .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Kelley</title>
		<link>http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/#comment-158652</link>
		<dc:creator>Brad Kelley</dc:creator>
		<pubDate>Wed, 12 Aug 2009 18:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2013#comment-158652</guid>
		<description>I&#039;m not tracking. Which account is it resetting the password on? In my blogs I have the default admin account deleted, so just curious. Can&#039;t tell by a cursory inspection of the code.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not tracking. Which account is it resetting the password on? In my blogs I have the default admin account deleted, so just curious. Can&#8217;t tell by a cursory inspection of the code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin Korb</title>
		<link>http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/#comment-158651</link>
		<dc:creator>Kevin Korb</dc:creator>
		<pubDate>Wed, 12 Aug 2009 17:35:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2013#comment-158651</guid>
		<description>@cbrp1r8

I&#039;ll agree and disagree with your comment.  PHP does provide the tools to easily soar indeed.  It DOES provide the means to check for buildings etc, however it doesn&#039;t enforce, or require you to use them.

You can write crappy code in any language and leave yourself open for attack.  Just because PHP lets you get the ball rolling very quickly, doesn&#039;t mean it&#039;s inferior.

I do shutter everytime I have to dive into the wordpress code though.  It&#039;s far from elegant and you&#039;d think with the adoption that it has it would be better.</description>
		<content:encoded><![CDATA[<p>@cbrp1r8</p>
<p>I&#8217;ll agree and disagree with your comment.  PHP does provide the tools to easily soar indeed.  It DOES provide the means to check for buildings etc, however it doesn&#8217;t enforce, or require you to use them.</p>
<p>You can write crappy code in any language and leave yourself open for attack.  Just because PHP lets you get the ball rolling very quickly, doesn&#8217;t mean it&#8217;s inferior.</p>
<p>I do shutter everytime I have to dive into the wordpress code though.  It&#8217;s far from elegant and you&#8217;d think with the adoption that it has it would be better.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cbrp1r8</title>
		<link>http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/#comment-158643</link>
		<dc:creator>cbrp1r8</dc:creator>
		<pubDate>Wed, 12 Aug 2009 15:30:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2013#comment-158643</guid>
		<description>wordpress.....again.....at least this part of the article was mildly humerous....

&quot;The bigger point he and other observers seem to make is that PHP is the coding equivalent of an everyman</description>
		<content:encoded><![CDATA[<p>wordpress&#8230;..again&#8230;..at least this part of the article was mildly humerous&#8230;.</p>
<p>&#8220;The bigger point he and other observers seem to make is that PHP is the coding equivalent of an everyman</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GZero</title>
		<link>http://www.darknet.org.uk/2009/08/wordpress-2-8-3-admin-reset-exploit/#comment-158640</link>
		<dc:creator>GZero</dc:creator>
		<pubDate>Wed, 12 Aug 2009 12:32:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2013#comment-158640</guid>
		<description>Of course, this only effectivly locks the admin out when he doesn&#039;t have access to his e-mail address. Or his DB.

Interesting bug. Clever use of PHP&#039;s get/post array notation, but can&#039;t really be considered exploitable to any serious extend.</description>
		<content:encoded><![CDATA[<p>Of course, this only effectivly locks the admin out when he doesn&#8217;t have access to his e-mail address. Or his DB.</p>
<p>Interesting bug. Clever use of PHP&#8217;s get/post array notation, but can&#8217;t really be considered exploitable to any serious extend.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

