<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Permalinks Migration Vulnerability</title>
	<atom:link href="http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/</link>
	<description>Weblog Tools Blogging Tools Blog</description>
	<pubDate>Tue, 02 Dec 2008 12:51:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: How to Update Your WordPress Permalinks Without Causing Link Rot &#8212; Kingdom Front</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1225437</link>
		<dc:creator>How to Update Your WordPress Permalinks Without Causing Link Rot &#8212; Kingdom Front</dc:creator>
		<pubDate>Sun, 04 May 2008 07:24:02 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1225437</guid>
		<description>[...] below (e.g., going from name-based permalinks back to name and date-based permalinks), there is a WordPress plugin that can take care of you. If all you want to do is change from name and date-based permalinks to [...]</description>
		<content:encoded><![CDATA[<p>[...] below (e.g., going from name-based permalinks back to name and date-based permalinks), there is a WordPress plugin that can take care of you. If all you want to do is change from name and date-based permalinks to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Permalink Structure Change</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1224660</link>
		<dc:creator>Permalink Structure Change</dc:creator>
		<pubDate>Wed, 30 Apr 2008 11:50:23 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1224660</guid>
		<description>[...] Migration Plugin Version 1.0. However, it&#8217;s got a bug apparently so the fix is here in this Weblog Tools Collection post, or download here from g30rg3 Blog or from WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] Migration Plugin Version 1.0. However, it&#8217;s got a bug apparently so the fix is here in this Weblog Tools Collection post, or download here from g30rg3 Blog or from WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Weekly Episode 3 &#124; Jeffro2pt0</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1224091</link>
		<dc:creator>WordPress Weekly Episode 3 &#124; Jeffro2pt0</dc:creator>
		<pubDate>Fri, 25 Apr 2008 08:04:42 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1224091</guid>
		<description>[...] Dean&#8217;s Migration Plugin Vulnerability - According to an advisory released by Packetstorm, a fellow by the name of g30rg3_x has discovered two bugs within Dean’s Permalinks Migration Plugin version 1.0. The first bug relates to XSRF and can allow an attacker to force a user to perform an unsolicited action that when combined with an XSS bug that has also been discovered, allows the attacker to gain valid credentials. [...]</description>
		<content:encoded><![CDATA[<p>[...] Dean&#8217;s Migration Plugin Vulnerability - According to an advisory released by Packetstorm, a fellow by the name of g30rg3_x has discovered two bugs within Dean’s Permalinks Migration Plugin version 1.0. The first bug relates to XSRF and can allow an attacker to force a user to perform an unsolicited action that when combined with an XSS bug that has also been discovered, allows the attacker to gain valid credentials. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Permalinks Migration Plugin Vulnerability &#187; JaypeeOnline // Blogging News &#38; Reviews</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1211673</link>
		<dc:creator>Permalinks Migration Plugin Vulnerability &#187; JaypeeOnline // Blogging News &#38; Reviews</dc:creator>
		<pubDate>Sun, 03 Feb 2008 12:22:25 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1211673</guid>
		<description>[...] Collection, an article was posted earlier today regarding a vulnerability in version 1.0 of the Deans Permalinks Migration Plugin. The said vulnerability involves XSRF or Cross-site request forgery and allow the attacker to steal [...]</description>
		<content:encoded><![CDATA[<p>[...] Collection, an article was posted earlier today regarding a vulnerability in version 1.0 of the Deans Permalinks Migration Plugin. The said vulnerability involves XSRF or Cross-site request forgery and allow the attacker to steal [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Connie</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1211649</link>
		<dc:creator>Connie</dc:creator>
		<pubDate>Sun, 03 Feb 2008 09:10:46 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1211649</guid>
		<description>So where's the link to the packetstorm advisory? I checked the list of January 2008 advisories and found nothing. I might have missed it -- here's the link for anyone who cares to check http://packetstormsecurity.org/0801-advisories/.</description>
		<content:encoded><![CDATA[<p>So where&#8217;s the link to the packetstorm advisory? I checked the list of January 2008 advisories and found nothing. I might have missed it &#8212; here&#8217;s the link for anyone who cares to check <a href="http://packetstormsecurity.org/0801-advisories/">http://packetstormsecurity.org/0801-advisories/</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick Beckman</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210488</link>
		<dc:creator>Rick Beckman</dc:creator>
		<pubDate>Fri, 25 Jan 2008 18:07:18 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210488</guid>
		<description>Ashish: You'll likely need it for as long as websites have links to any of your old-style permalinks, unless you are okay with serving up a Content Not Found page to visitors from those older sources.

Search engines should eventually update. If you're able, definitely keep a watch on your server access logs; over time, requests for old-style permalinks should become fewer. When they reach a level you're happy with, you'll be safe disabling the plugin.

If a few websites are consistently sending content to an older style permalink, it might be worth it to add a simple redirect in an .htaccess file, if you're able, such as this:

Redirect /2006/04/01/some-old-post/ /some-old-post/

Adjust that accordingly, of course. :)</description>
		<content:encoded><![CDATA[<p>Ashish: You&#8217;ll likely need it for as long as websites have links to any of your old-style permalinks, unless you are okay with serving up a Content Not Found page to visitors from those older sources.</p>
<p>Search engines should eventually update. If you&#8217;re able, definitely keep a watch on your server access logs; over time, requests for old-style permalinks should become fewer. When they reach a level you&#8217;re happy with, you&#8217;ll be safe disabling the plugin.</p>
<p>If a few websites are consistently sending content to an older style permalink, it might be worth it to add a simple redirect in an .htaccess file, if you&#8217;re able, such as this:</p>
<p>Redirect /2006/04/01/some-old-post/ /some-old-post/</p>
<p>Adjust that accordingly, of course. <img src='http://weblogtoolscollection.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashish Mohta</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210487</link>
		<dc:creator>Ashish Mohta</dc:creator>
		<pubDate>Fri, 25 Jan 2008 18:02:54 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210487</guid>
		<description>Do you need this plugin to be activated forever in the blog or you can just quit using it after some months when the migration is over</description>
		<content:encoded><![CDATA[<p>Do you need this plugin to be activated forever in the blog or you can just quit using it after some months when the migration is over</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick Beckman</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210479</link>
		<dc:creator>Rick Beckman</dc:creator>
		<pubDate>Fri, 25 Jan 2008 17:16:36 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210479</guid>
		<description>I wish I knew about this plugin before I spent hours &lt;a href="http://rickbeckman.org/how-to-update-your-wordpress-permalinks-without-causing-link-rot/" rel="nofollow"&gt;coming up with an .htaccess solution&lt;/a&gt;! Dealing with the redirect at the server level is probably a bit faster and more secure anyway. There are certain permalink changes which won't be able to be dealt with at the server level -- such as going from plain name-based permalinks to something with more information, such as year/name-based.</description>
		<content:encoded><![CDATA[<p>I wish I knew about this plugin before I spent hours <a href="http://rickbeckman.org/how-to-update-your-wordpress-permalinks-without-causing-link-rot/">coming up with an .htaccess solution</a>! Dealing with the redirect at the server level is probably a bit faster and more secure anyway. There are certain permalink changes which won&#8217;t be able to be dealt with at the server level &#8212; such as going from plain name-based permalinks to something with more information, such as year/name-based.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ted Clayton</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210469</link>
		<dc:creator>Ted Clayton</dc:creator>
		<pubDate>Fri, 25 Jan 2008 16:24:21 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210469</guid>
		<description>Site working!  Actually, I think I noticed the laborious install/activate-action, when installing Top Level Cats, and Redirection.  Following those, I also activated Dean's Permalinks, but I think noticed nothing.</description>
		<content:encoded><![CDATA[<p>Site working!  Actually, I think I noticed the laborious install/activate-action, when installing Top Level Cats, and Redirection.  Following those, I also activated Dean&#8217;s Permalinks, but I think noticed nothing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ted Clayton</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210462</link>
		<dc:creator>Ted Clayton</dc:creator>
		<pubDate>Fri, 25 Jan 2008 15:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210462</guid>
		<description>I very recently installed this plugin, along with a number of other, and yesterday suddenly could not bring up my homepage at all.  This morning, the page partially renders, then stops at the same place with an error message:  "... exceeded the 'max_questions' resource ... ".  

I did notice some laborious action, while installing Dean's and another Permalinks-related plugin.  I have FTPed all my recently installed plugins out of /wp-content/plugins, will wait an hour for the 'resource' error to time out (correct?) and try my site again.  Unless you guys know different, my understanding is we should leave my host alone so the error times out.

Will update.  Any insight appreciated.</description>
		<content:encoded><![CDATA[<p>I very recently installed this plugin, along with a number of other, and yesterday suddenly could not bring up my homepage at all.  This morning, the page partially renders, then stops at the same place with an error message:  &#8220;&#8230; exceeded the &#8216;max_questions&#8217; resource &#8230; &#8220;.  </p>
<p>I did notice some laborious action, while installing Dean&#8217;s and another Permalinks-related plugin.  I have FTPed all my recently installed plugins out of /wp-content/plugins, will wait an hour for the &#8216;resource&#8217; error to time out (correct?) and try my site again.  Unless you guys know different, my understanding is we should leave my host alone so the error times out.</p>
<p>Will update.  Any insight appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tadd</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210458</link>
		<dc:creator>Tadd</dc:creator>
		<pubDate>Fri, 25 Jan 2008 14:06:05 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/25/permalinks-migration-vulnerability/#comment-1210458</guid>
		<description>Ah, good catch ... I better grab that change and replace the plug I installed!

Nothing like sql injections to make a day go bad.</description>
		<content:encoded><![CDATA[<p>Ah, good catch &#8230; I better grab that change and replace the plug I installed!</p>
<p>Nothing like sql injections to make a day go bad.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
