<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Ferruh WordPress CSRF Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: WordPress Wednesday News: WordPress 2.5 News, Colleges and Schools Love WordPressMU, Viddler Meets WordPress, Theme Buyers Beware, Columns in Blog Posts, Feeds Without Plugins : The Blog Herald</title>
		<link>http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/comment-page-1#comment-7429</link>
		<dc:creator>WordPress Wednesday News: WordPress 2.5 News, Colleges and Schools Love WordPressMU, Viddler Meets WordPress, Theme Buyers Beware, Columns in Blog Posts, Feeds Without Plugins : The Blog Herald</dc:creator>
		<pubDate>Thu, 21 Feb 2008 04:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/#comment-7429</guid>
		<description>[...] Blog Security reports on a WordPress CSRF vulnerability described as a Cross Site Request Forgery. Investigations are ongoing. [...]</description>
		<content:encoded><![CDATA[<p>[...] Blog Security reports on a WordPress CSRF vulnerability described as a Cross Site Request Forgery. Investigations are ongoing. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/comment-page-1#comment-7274</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Fri, 15 Feb 2008 09:14:08 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/#comment-7274</guid>
		<description>Gareth, just informed me that WPIDS and WP Lockdown will prevent these attacks:

&lt;blockquote&gt;
Lockdown and WPIDS protects against these sorts of CSRF
attacks by employing a framebreaker in the admin area. This
effectively eliminates this attack on every browser apart from IE.
&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>Gareth, just informed me that WPIDS and WP Lockdown will prevent these attacks:</p>
<blockquote><p>
Lockdown and WPIDS protects against these sorts of CSRF<br />
attacks by employing a framebreaker in the admin area. This<br />
effectively eliminates this attack on every browser apart from IE.
</p></blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Wednesday News: WordPress 2.5 Live Reports, WWW or Not to WWW, 16,000 Post Migration, MT Does WP, WP Does Kazakhstan, and Gets Mugged : The Blog Herald</title>
		<link>http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/comment-page-1#comment-7165</link>
		<dc:creator>WordPress Wednesday News: WordPress 2.5 Live Reports, WWW or Not to WWW, 16,000 Post Migration, MT Does WP, WP Does Kazakhstan, and Gets Mugged : The Blog Herald</dc:creator>
		<pubDate>Thu, 14 Feb 2008 06:14:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/#comment-7165</guid>
		<description>[...] Blog Security reports on a WordPress CSRF vulnerability described as a Cross Site Request Forgery. Investigations are ongoing. [...]</description>
		<content:encoded><![CDATA[<p>[...] Blog Security reports on a WordPress CSRF vulnerability described as a Cross Site Request Forgery. Investigations are ongoing. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/comment-page-1#comment-7110</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Wed, 13 Feb 2008 18:03:37 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/#comment-7110</guid>
		<description>Rasheed, Ferruh provided a patch as part of his advisory. The patch basically prevents any requests without a valid nonce present.</description>
		<content:encoded><![CDATA[<p>Rasheed, Ferruh provided a patch as part of his advisory. The patch basically prevents any requests without a valid nonce present.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CSRF Attack on WordPress &#183; Pressed Words</title>
		<link>http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/comment-page-1#comment-7104</link>
		<dc:creator>CSRF Attack on WordPress &#183; Pressed Words</dc:creator>
		<pubDate>Wed, 13 Feb 2008 16:47:20 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/#comment-7104</guid>
		<description>[...] named Ferruh has a proof-of-concept cross-site request forgery (CSRF) attack against WordPress (HT: DK at BlogSecurity). I&#8217;ve tried it out successfully on my own version of WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] named Ferruh has a proof-of-concept cross-site request forgery (CSRF) attack against WordPress (HT: DK at BlogSecurity). I&#8217;ve tried it out successfully on my own version of WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rasheed</title>
		<link>http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/comment-page-1#comment-7088</link>
		<dc:creator>Rasheed</dc:creator>
		<pubDate>Wed, 13 Feb 2008 13:18:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/ferruh-wordpress-csrf-vulnerability/#comment-7088</guid>
		<description>So what should we do ?

Can you give us more details ?

Thanks.</description>
		<content:encoded><![CDATA[<p>So what should we do ?</p>
<p>Can you give us more details ?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
