<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: wp-pass Redirect Vulnerability</title>
	<atom:link href="http://blogsecurity.net/news/news-050707/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/news/news-050707</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: How many times do I have to tell you? My wp-pass.php is patched!! &#124; mou.me.uk</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-7036</link>
		<dc:creator>How many times do I have to tell you? My wp-pass.php is patched!! &#124; mou.me.uk</dc:creator>
		<pubDate>Wed, 13 Feb 2008 00:18:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-7036</guid>
		<description>[...] been stopped by the fact I update my WordPress install regularly. The common trick is using the wp-pass.php vulnerability, which was apparently fixed in wp 2.2.2. Basically, my logs show a 404 from this [...]</description>
		<content:encoded><![CDATA[<p>[...] been stopped by the fact I update my WordPress install regularly. The common trick is using the wp-pass.php vulnerability, which was apparently fixed in wp 2.2.2. Basically, my logs show a 404 from this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SEO Cybernautix</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-1898</link>
		<dc:creator>SEO Cybernautix</dc:creator>
		<pubDate>Wed, 10 Oct 2007 16:35:35 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-1898</guid>
		<description>Checking the server logs recently on one of my blogs showed me that this kind of attack is happening occasionally. I keep up to date and now running WP 2.2.3 and it gets declined and just get a 406 error.</description>
		<content:encoded><![CDATA[<p>Checking the server logs recently on one of my blogs showed me that this kind of attack is happening occasionally. I keep up to date and now running WP 2.2.3 and it gets declined and just get a 406 error.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Recommended site for WordPress security</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-281</link>
		<dc:creator>Recommended site for WordPress security</dc:creator>
		<pubDate>Thu, 19 Jul 2007 12:17:16 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-281</guid>
		<description>[...] wp-pass.php redirection [...]</description>
		<content:encoded><![CDATA[<p>[...] wp-pass.php redirection [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abel Cheung</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-280</link>
		<dc:creator>Abel Cheung</dc:creator>
		<pubDate>Wed, 18 Jul 2007 17:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-280</guid>
		<description>2 weeks are over, and no sign of any sort of fix landing in the repository. All WordPress people did for 2.2 branch is to bump PHP requirement from 4.1 to 4,2, fix glitch when removing link and adding new configuration option, and add some check of post content type.

Some preliminary check shows that not only the freely downloadable code base is vulnerable, but http://*.wordpress.com/ as well. Uhh.... this can be either good or bad depending on POV.</description>
		<content:encoded><![CDATA[<p>2 weeks are over, and no sign of any sort of fix landing in the repository. All WordPress people did for 2.2 branch is to bump PHP requirement from 4.1 to 4,2, fix glitch when removing link and adding new configuration option, and add some check of post content type.</p>
<p>Some preliminary check shows that not only the freely downloadable code base is vulnerable, but http://*.wordpress.com/ as well. Uhh&#8230;. this can be either good or bad depending on POV.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress: Más vulnerabilidades de inyección de SQL en Buayacorp - Diseño y Programación</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-279</link>
		<dc:creator>WordPress: Más vulnerabilidades de inyección de SQL en Buayacorp - Diseño y Programación</dc:creator>
		<pubDate>Fri, 13 Jul 2007 04:42:57 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-279</guid>
		<description>[...] que en estos días ando algo ocupado y sin muchas ideas para publicar, aprovecharé la oleada de reportes de seguridad en WordPress para comentar algunos bugs que todavía no están corregidos en la [...]</description>
		<content:encoded><![CDATA[<p>[...] que en estos días ando algo ocupado y sin muchas ideas para publicar, aprovecharé la oleada de reportes de seguridad en WordPress para comentar algunos bugs que todavía no están corregidos en la [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Start the Clock on WP 2.2.2 &#171; Geof&#8217;s Relentless Kvetching About WordPress</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-278</link>
		<dc:creator>Start the Clock on WP 2.2.2 &#171; Geof&#8217;s Relentless Kvetching About WordPress</dc:creator>
		<pubDate>Tue, 10 Jul 2007 14:05:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-278</guid>
		<description>[...] the Clock on WP&#160;2.2.2 July 9th, 2007   There&#8217;s a vulnerability in WP 2.2.1. BlogSecurity is who brought it to my attention. After being burned by vulnerabilities before&#8212;and having gotten absolutely slammed over the [...]</description>
		<content:encoded><![CDATA[<p>[...] the Clock on WP&nbsp;2.2.2 July 9th, 2007   There&#8217;s a vulnerability in WP 2.2.1. BlogSecurity is who brought it to my attention. After being burned by vulnerabilities before&#8212;and having gotten absolutely slammed over the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Monoclipsian &#187; Blog Archive &#187; wp-pass Redirect Vulnerability: Possible Fix</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-277</link>
		<dc:creator>Monoclipsian &#187; Blog Archive &#187; wp-pass Redirect Vulnerability: Possible Fix</dc:creator>
		<pubDate>Sun, 08 Jul 2007 05:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-277</guid>
		<description>[...] If you read about Wordpress bugs, you have probably seen the alert about wp-pass. In this post we&#8217;ll discuss a possible fix, that may help some people out. The vulnerability is present in version 2.2.1, so this fix will probably hold you over until 2.2.2 is released. You can read more on this over at BlogSecurity. [...]</description>
		<content:encoded><![CDATA[<p>[...] If you read about Wordpress bugs, you have probably seen the alert about wp-pass. In this post we&#8217;ll discuss a possible fix, that may help some people out. The vulnerability is present in version 2.2.1, so this fix will probably hold you over until 2.2.2 is released. You can read more on this over at BlogSecurity. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-268</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Sat, 07 Jul 2007 12:41:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-268</guid>
		<description>There is also a very nasty cross-domain redirect on the latest version of Wordpress. I contacted security [ at ] wordpress.org about a week ago but no response yet :(

I will pass the details to David Kierznowski so we can post them @ blogsecurity.net</description>
		<content:encoded><![CDATA[<p>There is also a very nasty cross-domain redirect on the latest version of Wordpress. I contacted security [ at ] wordpress.org about a week ago but no response yet :(</p>
<p>I will pass the details to David Kierznowski so we can post them @ blogsecurity.net</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Del.icio.us bookmarks: Juni 30th - Juli 6th &#124; Bloganbieter.de Blog</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-267</link>
		<dc:creator>Del.icio.us bookmarks: Juni 30th - Juli 6th &#124; Bloganbieter.de Blog</dc:creator>
		<pubDate>Sat, 07 Jul 2007 11:15:53 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-267</guid>
		<description>[...] BlogSecurity » wp-pass Redirect Vulnerability - [...]</description>
		<content:encoded><![CDATA[<p>[...] BlogSecurity » wp-pass Redirect Vulnerability &#8211; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://blogsecurity.net/news/news-050707/comment-page-1#comment-276</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Fri, 06 Jul 2007 11:10:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=38#comment-276</guid>
		<description>Exciting times ahead maybe?</description>
		<content:encoded><![CDATA[<p>Exciting times ahead maybe?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
