<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BlogSecurity &#187; Articles</title>
	<atom:link href="http://blogsecurity.net/category/wordpress/articles/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Mon, 22 Feb 2010 21:41:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Distributed WordPress Password Guessing</title>
		<link>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing</link>
		<comments>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing#comments</comments>
		<pubDate>Tue, 08 Dec 2009 23:00:22 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=589</guid>
		<description><![CDATA[One of The Internet Storm Center readers recently discovered a malicious WordPress hacking script.
The script is nothing more then a password guessing tool. However, what makes it unique &#8212; as pointed out by ISC, is the fact that it uses a MySQL database backend to store password attempts. This means the script could be executed [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>How to Firewall Your WordPress Blog</title>
		<link>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog</link>
		<comments>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog#comments</comments>
		<pubDate>Thu, 05 Mar 2009 10:22:56 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[blog security]]></category>
		<category><![CDATA[wordpress security]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=471</guid>
		<description><![CDATA[You already know to use a decent password for your blog, but brute-force or dictionary attacks aren&#8217;t the only attacks used against bloggers.  It&#8217;s much cheaper and faster to exploit software flaws, and that the hackers do.  A programmer&#8217;s oversight may allow a hacker to gain access to your blog to insert spyware, [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog/feed</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>3 Tips to Avoid Dangerous Themes and Plugins</title>
		<link>http://blogsecurity.net/wordpress/3-tips-to-avoid-dangerous-themes-and-plugins</link>
		<comments>http://blogsecurity.net/wordpress/3-tips-to-avoid-dangerous-themes-and-plugins#comments</comments>
		<pubDate>Tue, 10 Feb 2009 02:10:19 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Reflections]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=413</guid>
		<description><![CDATA[We all love how easy it is to install plugins and themes but how do we know there is no hidden jack in the box waiting to pop out? Viruses, worms and backdoors could be embedded into any theme or plugin and uploaded to the Internet for public consumption.
Here are three easy to use ideas [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/3-tips-to-avoid-dangerous-themes-and-plugins/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>WordPress Developer Notes</title>
		<link>http://blogsecurity.net/wordpress/wordpress-developer-notes</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-developer-notes#comments</comments>
		<pubDate>Thu, 05 Feb 2009 22:44:39 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[wp-scanner]]></category>
		<category><![CDATA[wpscanner]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=401</guid>
		<description><![CDATA[Introduction
WordPress scanner is a free online resource that blog administrators can use to provide a measure of their wordpress security level. It is BETA software and is continually being developed.
If you have landed here directly we suggest starting at the wp-scanner launch page.
This page is part of a group of pages discussing various aspects of [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-developer-notes/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WordPress Scanner FAQ</title>
		<link>http://blogsecurity.net/wordpress/wpscanner-faq</link>
		<comments>http://blogsecurity.net/wordpress/wpscanner-faq#comments</comments>
		<pubDate>Thu, 05 Feb 2009 22:12:57 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=392</guid>
		<description><![CDATA[Introduction
WordPress scanner is a free online resource that blog administrators can use to provide a measure of their wordpress security level. It is BETA software and is continually being developed.
If you have landed here directly we suggest starting at the wp-scanner launch page.
This page is part of a group of pages discussing various aspects of [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wpscanner-faq/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress Insecure by Design?</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-insecure-by-design#comments</comments>
		<pubDate>Tue, 22 Jan 2008 20:47:12 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/</guid>
		<description><![CDATA[
We have seen alot of critical vulnerabilities being discovered in WordPress core and its plugins of late, who&#8217;s to blame? This article will take a brief look into WordPress design and its core security functions.


One of the major problems I see with WordPress is that it provides little (if any) protection against input validation attacks. [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/feed</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
		<item>
		<title>ModSecurity and Wordpress: Defense in Depth</title>
		<link>http://blogsecurity.net/wordpress/modsecurity-and-wordpress-defense-in-depth</link>
		<comments>http://blogsecurity.net/wordpress/modsecurity-and-wordpress-defense-in-depth#comments</comments>
		<pubDate>Thu, 01 Nov 2007 08:19:17 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/modsecurity-and-wordpress-defense-in-depth/</guid>
		<description><![CDATA[
Daniel Cuthbert writes an excellent paper for BlogSec on securing your blog with ModSecurity.


Here&#8217;s a snippet:


Wordpress is a state-of-the-art semantic personal publishing platform with a focus on aesthetics, web standards, and usability. Unfortunately it is also missing the vital security functions that protect the application from malicious attacks. A default install of Wordpress is not [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/modsecurity-and-wordpress-defense-in-depth/feed</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>Which is more secure: WordPress vs WordPress MU</title>
		<link>http://blogsecurity.net/wordpress/which-is-more-secure-wordpress-vs-wordpress-mu</link>
		<comments>http://blogsecurity.net/wordpress/which-is-more-secure-wordpress-vs-wordpress-mu#comments</comments>
		<pubDate>Tue, 23 Oct 2007 23:56:44 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/which-is-more-secure-wordpress-vs-wordpress-mu/</guid>
		<description><![CDATA[
A couple of weeks ago Adam Warner suggested we have do a security comparison between WordPress and WordPress MU. In particular, he was interested to know which was more likely to pass PCI accreditation.


I contacted Doncha, lead developer of WordPress MU for some feedback. Interestingly, we both shared similar sentiments and it made this question [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/which-is-more-secure-wordpress-vs-wordpress-mu/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>WordPress Security Whitepaper</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-whitepaper</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-security-whitepaper#comments</comments>
		<pubDate>Thu, 04 Oct 2007 07:52:22 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-security-whitepaper/</guid>
		<description><![CDATA[***PLEASE BE VERY CAUTIOUS USING ANY PLUGINS/TOOLS IN THIS WHITEPAPER. SOME OF THEM ARE BETA TOOLS AND HAVE NOT BEEN UPDATED FOR SOME TIME. SOME OF THE PLUGINS ARE KNOWN TO CAUSE PROBLEMS. FOLLOW THE PRINCIPLES BUT IT IS NOT RECOMMENDED THAT YOU RUN ANY OUTDATED OR BETA PLUGINS. IF IN DOUBT, PLEASE ASK!***
This document [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-security-whitepaper/feed</wfw:commentRss>
		<slash:comments>163</slash:comments>
		</item>
		<item>
		<title>5 Step Failsafe upgrade for WordPress</title>
		<link>http://blogsecurity.net/wordpress/5-step-failsafe-upgrade-for-wordpress</link>
		<comments>http://blogsecurity.net/wordpress/5-step-failsafe-upgrade-for-wordpress#comments</comments>
		<pubDate>Tue, 25 Sep 2007 06:23:13 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/uncategorized/5-step-failsafe-upgrade-for-wordpress/</guid>
		<description><![CDATA[
Roland Rust runs http://wordpress.designpraxis.at and we are pleased to introduce him as our guest blogger today! In this post he discusses WordPress backups with one of his excellent plugins, &#34;BackupWordPress&#34;. This plugin really makes it easy not only to backup your entire blog (including files) but also to restore it with the click of a [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/5-step-failsafe-upgrade-for-wordpress/feed</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
	</channel>
</rss>
