<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: 2in1 Security Bulletin</title>
	<atom:link href="http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/feed/" rel="self" type="application/rss+xml" />
	<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/</link>
	<description>Weblog Tools Blogging Tools Blog</description>
	<pubDate>Tue, 02 Dec 2008 13:43:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: ???????? &#187; ??????????????????????????????????</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1212631</link>
		<dc:creator>???????? &#187; ??????????????????????????????????</dc:creator>
		<pubDate>Fri, 08 Feb 2008 14:25:30 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1212631</guid>
		<description>[...] WP-Cal (Weblog Tools Collection » Blog Archive » 2in1 Security Bulletin??) [...]</description>
		<content:encoded><![CDATA[<p>[...] WP-Cal (Weblog Tools Collection » Blog Archive » 2in1 Security Bulletin??) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Wednesday News: WordPress 2.3.3 Security Must Upgrade, Plugins Vulnerable, Automatic Upgrades, and More : The Blog Herald</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1212289</link>
		<dc:creator>WordPress Wednesday News: WordPress 2.3.3 Security Must Upgrade, Plugins Vulnerable, Automatic Upgrades, and More : The Blog Herald</dc:creator>
		<pubDate>Thu, 07 Feb 2008 02:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1212289</guid>
		<description>[...] Weblog Tools Collection reports vulnerabilities in Adserve WordPress Plugin v0.2 and WP-Cal WordPress Plugin. [...]</description>
		<content:encoded><![CDATA[<p>[...] Weblog Tools Collection reports vulnerabilities in Adserve WordPress Plugin v0.2 and WP-Cal WordPress Plugin. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ?????????? ? ???????? wp-calc ? wp-adserv &#8212; ???????????? WordPress ??????</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211872</link>
		<dc:creator>?????????? ? ???????? wp-calc ? wp-adserv &#8212; ???????????? WordPress ??????</dc:creator>
		<pubDate>Mon, 04 Feb 2008 22:51:08 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211872</guid>
		<description>[...] WebLogTools ???????? ? ???? ????? ???????????, ????????? ? WordPress ????????: ??????? ??????? ?????????? SQL ???????? ? WordPress ??????? WP-Cal ?????? 0.? ??????? ??????? ???????? ???? &#8220;enter_the_dragon&#8221; ??????? ?? ?????????? ? WordPress ??????? Adserve Plugin version 0.2. [...]</description>
		<content:encoded><![CDATA[<p>[...] WebLogTools ???????? ? ???? ????? ???????????, ????????? ? WordPress ????????: ??????? ??????? ?????????? SQL ???????? ? WordPress ??????? WP-Cal ?????? 0.? ??????? ??????? ???????? ???? &#8220;enter_the_dragon&#8221; ??????? ?? ?????????? ? WordPress ??????? Adserve Plugin version 0.2. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; wp-calc &#38; wp adserv plugin vulnerabilities</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211858</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; wp-calc &#38; wp adserv plugin vulnerabilities</dc:creator>
		<pubDate>Mon, 04 Feb 2008 20:34:23 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211858</guid>
		<description>[...] at WeblogToolsCollection  has reported two new vulnerabilities that have recently been found in WordPress plugins:  Today, we [...]</description>
		<content:encoded><![CDATA[<p>[...] at WeblogToolsCollection  has reported two new vulnerabilities that have recently been found in WordPress plugins:  Today, we [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tadd</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211433</link>
		<dc:creator>Tadd</dc:creator>
		<pubDate>Fri, 01 Feb 2008 16:01:26 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211433</guid>
		<description>Jeff - yeah I do enjoy these posts ... not, like enjoy in as in a novel or movie ... but I'm grateful that there are people who are helpful and point out problems with plugins that could bring your whole website down.</description>
		<content:encoded><![CDATA[<p>Jeff - yeah I do enjoy these posts &#8230; not, like enjoy in as in a novel or movie &#8230; but I&#8217;m grateful that there are people who are helpful and point out problems with plugins that could bring your whole website down.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeffro2pt0</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211415</link>
		<dc:creator>Jeffro2pt0</dc:creator>
		<pubDate>Fri, 01 Feb 2008 12:18:05 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211415</guid>
		<description>&lt;strong&gt;@Alex&lt;/strong&gt; Thanks for letting me know regardless. I was thinking of adding the prefix stuff to the codex article about hardening  WordPress but because of the point you brought up, It's better that I didn't.</description>
		<content:encoded><![CDATA[<p><strong>@Alex</strong> Thanks for letting me know regardless. I was thinking of adding the prefix stuff to the codex article about hardening  WordPress but because of the point you brought up, It&#8217;s better that I didn&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211411</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Fri, 01 Feb 2008 11:13:03 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211411</guid>
		<description>Jeffro: Er, that was meant ironic. I wrote that because the sentence "However, the malicious user must have knowledge of the database table prefix." sounds like guessing the table prefix of a WordPress installation would be a substential blocker for an attacker. Btw, I also wouldn't suggest changing the prefix, simply because there might be a bug in a plugin where wp_ is hardcoded. Unless you really have the necessity to change the prefix and you are ready to debug plugins, you should leave it.</description>
		<content:encoded><![CDATA[<p>Jeffro: Er, that was meant ironic. I wrote that because the sentence &#8220;However, the malicious user must have knowledge of the database table prefix.&#8221; sounds like guessing the table prefix of a WordPress installation would be a substential blocker for an attacker. Btw, I also wouldn&#8217;t suggest changing the prefix, simply because there might be a bug in a plugin where wp_ is hardcoded. Unless you really have the necessity to change the prefix and you are ready to debug plugins, you should leave it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dhruva Sagar</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211380</link>
		<dc:creator>Dhruva Sagar</dc:creator>
		<pubDate>Fri, 01 Feb 2008 05:46:05 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211380</guid>
		<description>This is really interesting, and nice information.
Very nice work done guys. By the way, do we have any workarounds around them from our side? any code changes you or anyone can suggest?

I think a work around, resolution should always be posted alongside such a vulnerability disclosure.</description>
		<content:encoded><![CDATA[<p>This is really interesting, and nice information.<br />
Very nice work done guys. By the way, do we have any workarounds around them from our side? any code changes you or anyone can suggest?</p>
<p>I think a work around, resolution should always be posted alongside such a vulnerability disclosure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeffro2pt0</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211338</link>
		<dc:creator>Jeffro2pt0</dc:creator>
		<pubDate>Thu, 31 Jan 2008 22:30:13 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211338</guid>
		<description>&lt;strong&gt;@Alex&lt;/strong&gt; I was checking out the Codex article for hardening WordPress and it is not suggested anywhere within the document to change the default database prefix. 

&lt;strong&gt;@Tadd&lt;/strong&gt; Do you enjoy these types of posts? Unfortunately, I see too many security related news posts for plugins but I can continue to write about the bulletins of you guys feel this is necessary.</description>
		<content:encoded><![CDATA[<p><strong>@Alex</strong> I was checking out the Codex article for hardening WordPress and it is not suggested anywhere within the document to change the default database prefix. </p>
<p><strong>@Tadd</strong> Do you enjoy these types of posts? Unfortunately, I see too many security related news posts for plugins but I can continue to write about the bulletins of you guys feel this is necessary.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tadd</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211290</link>
		<dc:creator>Tadd</dc:creator>
		<pubDate>Thu, 31 Jan 2008 15:17:32 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211290</guid>
		<description>See, this is why I love WordPress. The open community who would rather spread the information regarding the problem than exploit it. I remember working with a now defunct CMS that has a slew of holes. Rather than people letting everyone know, they would go around to any site they  knew and would use the exploits - ruining all sites they found. Not very helpful.

BUT I'm glad WordPress community is good. Kudos.</description>
		<content:encoded><![CDATA[<p>See, this is why I love WordPress. The open community who would rather spread the information regarding the problem than exploit it. I remember working with a now defunct CMS that has a slew of holes. Rather than people letting everyone know, they would go around to any site they  knew and would use the exploits - ruining all sites they found. Not very helpful.</p>
<p>BUT I&#8217;m glad WordPress community is good. Kudos.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211288</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Thu, 31 Jan 2008 14:30:34 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2008/01/31/2in1-security-bulletin/#comment-1211288</guid>
		<description>&lt;blockquote&gt;However, the malicious user must have knowledge of the database table prefix.&lt;/blockquote&gt;

What a good thing that the table prefix is not &lt;code&gt;wp_&lt;/code&gt; on 99% of the WordPress installations out there. ;)</description>
		<content:encoded><![CDATA[<blockquote><p>However, the malicious user must have knowledge of the database table prefix.</p></blockquote>
<p>What a good thing that the table prefix is not <code>wp_</code> on 99% of the WordPress installations out there. <img src='http://weblogtoolscollection.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
