<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Holy Plugins Batman!</title>
	<atom:link href="http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/feed/" rel="self" type="application/rss+xml" />
	<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/</link>
	<description>Weblog Tools Blogging Tools Blog</description>
	<pubDate>Thu, 08 Jan 2009 18:59:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: mike</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1165748</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Mon, 06 Aug 2007 16:40:46 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1165748</guid>
		<description>I looked at your robots.txt file and apparently you dont follow your own advice?, you have nothing blocked</description>
		<content:encoded><![CDATA[<p>I looked at your robots.txt file and apparently you dont follow your own advice?, you have nothing blocked</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: plugins</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1164521</link>
		<dc:creator>plugins</dc:creator>
		<pubDate>Sun, 22 Jul 2007 21:10:10 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1164521</guid>
		<description>[...] gelezen op Weblog Tools Collection dat er heel wat plugin directories van WordPress zo goed als helemaal openstaan. Openstaan is [...]</description>
		<content:encoded><![CDATA[<p>[...] gelezen op Weblog Tools Collection dat er heel wat plugin directories van WordPress zo goed als helemaal openstaan. Openstaan is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How To Secure Your WordPress Blog Folder?</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163964</link>
		<dc:creator>How To Secure Your WordPress Blog Folder?</dc:creator>
		<pubDate>Thu, 12 Jul 2007 16:46:19 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163964</guid>
		<description>[...] you&#8217;re using WordPress for your blog, there is one security issue mentioned in WeblogToolsCollection &#38; [...]</description>
		<content:encoded><![CDATA[<p>[...] you&#8217;re using WordPress for your blog, there is one security issue mentioned in WeblogToolsCollection &amp; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How Secure Is Your WordPress Blog? : Cornell Finch</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163641</link>
		<dc:creator>How Secure Is Your WordPress Blog? : Cornell Finch</dc:creator>
		<pubDate>Sun, 08 Jul 2007 08:52:09 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163641</guid>
		<description>[...] a post on Mark&#8217;s website at Weblog Tools Collection1 I found the Blog Security [...]</description>
		<content:encoded><![CDATA[<p>[...] a post on Mark&#8217;s website at Weblog Tools Collection1 I found the Blog Security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wally Wilson</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163630</link>
		<dc:creator>Wally Wilson</dc:creator>
		<pubDate>Sat, 07 Jul 2007 22:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163630</guid>
		<description>Mark,
 
Thanks for the heads-up.  I had blank index.html files every place _except_ my plugins folder.  ::slaps palm to forehead::</description>
		<content:encoded><![CDATA[<p>Mark,</p>
<p>Thanks for the heads-up.  I had blank index.html files every place _except_ my plugins folder.  ::slaps palm to forehead::</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spammers e vulnerabilidades no wordpress - Marketing de busca</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163566</link>
		<dc:creator>Spammers e vulnerabilidades no wordpress - Marketing de busca</dc:creator>
		<pubDate>Thu, 05 Jul 2007 22:42:05 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163566</guid>
		<description>[...] artigo no weblog tools colection lista outras formas mais elaboradas para obter o mesmo efeito. Para mais informação sobre o [...]</description>
		<content:encoded><![CDATA[<p>[...] artigo no weblog tools colection lista outras formas mais elaboradas para obter o mesmo efeito. Para mais informação sobre o [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163556</link>
		<dc:creator>Otto</dc:creator>
		<pubDate>Thu, 05 Jul 2007 14:31:38 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163556</guid>
		<description>The best way is actually to just put &lt;code&gt;Options -Indexes&lt;/code&gt; into the main root .htaccess file. That is enough, you don't need it in every directory, just the main one. You also don't need the "All" in the line of code, just turning off indexes will suffice.

As for people not understanding why it's bad: Consider that plugins are code and can have security flaws. If somebody can see the content of your plugins directory, they can find out the names of your plugins and execute them directly. Then they can go search for exploits for those specific plugins and hack your site that way. Without indexes, they can't see what plugins you have and don't know their filenames. So they have to try more generic methods to get in. Plugins, like any code you run on the site, can be a security risk, so hiding them even a little bit is helpful.</description>
		<content:encoded><![CDATA[<p>The best way is actually to just put <code>Options -Indexes</code> into the main root .htaccess file. That is enough, you don&#8217;t need it in every directory, just the main one. You also don&#8217;t need the &#8220;All&#8221; in the line of code, just turning off indexes will suffice.</p>
<p>As for people not understanding why it&#8217;s bad: Consider that plugins are code and can have security flaws. If somebody can see the content of your plugins directory, they can find out the names of your plugins and execute them directly. Then they can go search for exploits for those specific plugins and hack your site that way. Without indexes, they can&#8217;t see what plugins you have and don&#8217;t know their filenames. So they have to try more generic methods to get in. Plugins, like any code you run on the site, can be a security risk, so hiding them even a little bit is helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lorna</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163544</link>
		<dc:creator>Lorna</dc:creator>
		<pubDate>Thu, 05 Jul 2007 08:48:07 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163544</guid>
		<description>May I request that future WordPress distributions have the .htaccess or index.html files built into each folder that needs to be locked down, especially the themes and plugins folders?</description>
		<content:encoded><![CDATA[<p>May I request that future WordPress distributions have the .htaccess or index.html files built into each folder that needs to be locked down, especially the themes and plugins folders?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bad Bad Bad</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163536</link>
		<dc:creator>Bad Bad Bad</dc:creator>
		<pubDate>Thu, 05 Jul 2007 05:37:52 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163536</guid>
		<description>Baris:

That's not a very good robots.txt

Why in the world would I want to do this?:
Disallow: /*.js$
Disallow: /*.css$
Disallow: /wp-content/
Disallow: /feed/
Disallow: /archives/
Disallow: /sitemap.xml
Disallow: */feed/
Disallow: */trackback/
Disallow: /page/
Disallow: /tag/
Disallow: /category/

That's not good at all! It blocks about half your blog! Google is able to tell what content is on my site and knows it's not copied like the guy worries about on his site.</description>
		<content:encoded><![CDATA[<p>Baris:</p>
<p>That&#8217;s not a very good robots.txt</p>
<p>Why in the world would I want to do this?:<br />
Disallow: /*.js$<br />
Disallow: /*.css$<br />
Disallow: /wp-content/<br />
Disallow: /feed/<br />
Disallow: /archives/<br />
Disallow: /sitemap.xml<br />
Disallow: */feed/<br />
Disallow: */trackback/<br />
Disallow: /page/<br />
Disallow: /tag/<br />
Disallow: /category/</p>
<p>That&#8217;s not good at all! It blocks about half your blog! Google is able to tell what content is on my site and knows it&#8217;s not copied like the guy worries about on his site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: What plugins are you using? &#124; Nerdal Network</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163530</link>
		<dc:creator>What plugins are you using? &#124; Nerdal Network</dc:creator>
		<pubDate>Thu, 05 Jul 2007 02:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163530</guid>
		<description>[...] bit about how it seems to be possible to search through Google and view the contents of most WordPress blogs&#8217; plugins directory. The jury is still out on this being a security hole but he offers a few solutions.  Missing from [...]</description>
		<content:encoded><![CDATA[<p>[...] bit about how it seems to be possible to search through Google and view the contents of most WordPress blogs&#8217; plugins directory. The jury is still out on this being a security hole but he offers a few solutions.  Missing from [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Wednesday News: WordCamp Filling Up Fast, WordPress 2.2.1 Mandatory Upgrade, Hot WordPress Themes and Plugins, WordPress Security, and WordPress Nerds Blog Naked : The Blog Herald</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163524</link>
		<dc:creator>WordPress Wednesday News: WordCamp Filling Up Fast, WordPress 2.2.1 Mandatory Upgrade, Hot WordPress Themes and Plugins, WordPress Security, and WordPress Nerds Blog Naked : The Blog Herald</dc:creator>
		<pubDate>Thu, 05 Jul 2007 00:55:27 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163524</guid>
		<description>[...] Anyone See Your WordPress Plugin&#8217;s Underwear? I&#8217;ve talked about this before, but Mark Ghosh of Weblog Tools Collection makes the point even more valid and asks if you are showing off your WordPress Plugins when you [...]</description>
		<content:encoded><![CDATA[<p>[...] Anyone See Your WordPress Plugin&#8217;s Underwear? I&#8217;ve talked about this before, but Mark Ghosh of Weblog Tools Collection makes the point even more valid and asks if you are showing off your WordPress Plugins when you [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuff by Sarah &#187; WordPress Site Security</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163513</link>
		<dc:creator>Stuff by Sarah &#187; WordPress Site Security</dc:creator>
		<pubDate>Wed, 04 Jul 2007 20:03:46 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163513</guid>
		<description>[...] Wednesday, 4 of July , 2007 at 8:42 pm.  No this isn&#8217;t a post about a security issue with WordPress but more the naivety of hosting your own WordPress site (or potentially other sites/CMSs) and allowing visible listings of directory contents. The post that explains this further can be found at Web Log Tools Collection. [...]</description>
		<content:encoded><![CDATA[<p>[...] Wednesday, 4 of July , 2007 at 8:42 pm.  No this isn&#8217;t a post about a security issue with WordPress but more the naivety of hosting your own WordPress site (or potentially other sites/CMSs) and allowing visible listings of directory contents. The post that explains this further can be found at Web Log Tools Collection. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A.J.</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163504</link>
		<dc:creator>A.J.</dc:creator>
		<pubDate>Wed, 04 Jul 2007 16:03:17 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163504</guid>
		<description>All I can say is that I was absolutely shocked at the search results.  I shouldn't be because I remember searching for social security numbers and credit card numbers in Google back around 2000 or 2001 just to see what came up and you'd be amazed how many comma delimited files or text files were out there publicly available with all customer and order data from poorly written shopping carts.</description>
		<content:encoded><![CDATA[<p>All I can say is that I was absolutely shocked at the search results.  I shouldn&#8217;t be because I remember searching for social security numbers and credit card numbers in Google back around 2000 or 2001 just to see what came up and you&#8217;d be amazed how many comma delimited files or text files were out there publicly available with all customer and order data from poorly written shopping carts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jenny</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163496</link>
		<dc:creator>Jenny</dc:creator>
		<pubDate>Wed, 04 Jul 2007 14:06:01 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163496</guid>
		<description>I did the index.php thing, but it looks like it's bad, so...I'ma go ahead and change it to html i guess.</description>
		<content:encoded><![CDATA[<p>I did the index.php thing, but it looks like it&#8217;s bad, so&#8230;I&#8217;ma go ahead and change it to html i guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lista dei plugin di Wordpress e spider &#124; ShinRa House</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163492</link>
		<dc:creator>Lista dei plugin di Wordpress e spider &#124; ShinRa House</dc:creator>
		<pubDate>Wed, 04 Jul 2007 11:44:40 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163492</guid>
		<description>[...] Weblog Tools Collection segnala un interessante ricerca su Google potenzialmente pericolosa per Wordpress e propone alcune soluzioni al problema. [...]</description>
		<content:encoded><![CDATA[<p>[...] Weblog Tools Collection segnala un interessante ricerca su Google potenzialmente pericolosa per Wordpress e propone alcune soluzioni al problema. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BLOGoree.ro blog &#187; Protejeaza-ti directorul cu pluginuri</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163491</link>
		<dc:creator>BLOGoree.ro blog &#187; Protejeaza-ti directorul cu pluginuri</dc:creator>
		<pubDate>Wed, 04 Jul 2007 11:11:04 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163491</guid>
		<description>[...] oamenii din blogosfera, e suficient sa cauti pe Google. Baietii de la Weblog Tools Collection au scris despre acest aspect   Ok - toate bune si frumoase, dar de asemenea oricine poate vedea ce pluginuri aveti instalate, [...]</description>
		<content:encoded><![CDATA[<p>[...] oamenii din blogosfera, e suficient sa cauti pe Google. Baietii de la Weblog Tools Collection au scris despre acest aspect   Ok - toate bune si frumoase, dar de asemenea oricine poate vedea ce pluginuri aveti instalate, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress - protejeaza-ti directorul cu pluginuri &#124; Technology Blog @ Cristian Ciofu</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163490</link>
		<dc:creator>WordPress - protejeaza-ti directorul cu pluginuri &#124; Technology Blog @ Cristian Ciofu</dc:creator>
		<pubDate>Wed, 04 Jul 2007 10:46:41 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163490</guid>
		<description>[...] baietii de la Weblog Tools Collection au scris despre acest aspect [...]</description>
		<content:encoded><![CDATA[<p>[...] baietii de la Weblog Tools Collection au scris despre acest aspect [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cody</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163483</link>
		<dc:creator>Cody</dc:creator>
		<pubDate>Wed, 04 Jul 2007 09:00:13 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163483</guid>
		<description>Word to the wise: putting an empty index.php file in your /wp-content/plugins folder will mess with your dashboard (see &lt;a href="http://wordpress.org/support/topic/65565" title="Slim dashboard indeed" rel="nofollow"&gt;here&lt;/a&gt;. Try an index.html file instead, or just do the .htaccess bit.</description>
		<content:encoded><![CDATA[<p>Word to the wise: putting an empty index.php file in your /wp-content/plugins folder will mess with your dashboard (see <a href="http://wordpress.org/support/topic/65565" title="Slim dashboard indeed">here</a>. Try an index.html file instead, or just do the .htaccess bit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163463</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Wed, 04 Jul 2007 05:42:53 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163463</guid>
		<description>*phew* good catch!  Mine was unsecure as well.. *patches it up*</description>
		<content:encoded><![CDATA[<p>*phew* good catch!  Mine was unsecure as well.. *patches it up*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: efrasiyab</title>
		<link>http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163459</link>
		<dc:creator>efrasiyab</dc:creator>
		<pubDate>Wed, 04 Jul 2007 05:08:23 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/07/03/holy-plugins-batman/#comment-1163459</guid>
		<description>&lt;a href="http://www.billhartzer.com/pages/one-simple-way-to-protect-your-wordpress-plugins/" rel="nofollow"&gt;Here&lt;/a&gt;'s a another simple solution.</description>
		<content:encoded><![CDATA[<p><a href="http://www.billhartzer.com/pages/one-simple-way-to-protect-your-wordpress-plugins/">Here</a>&#8217;s a another simple solution.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
