<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress 2.6 Security Improvements?</title>
	<atom:link href="http://blogsecurity.net/wordpress/wordpress-26-security-improvements/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; WordPress 2.6 Released</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-12197</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; WordPress 2.6 Released</dc:creator>
		<pubDate>Mon, 21 Jul 2008 21:57:37 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-12197</guid>
		<description>[...] 2.6 is now available. We have mentioned from of the security improvements in an earlier post. The latest version promises a number of security enhancements as [...]</description>
		<content:encoded><![CDATA[<p>[...] 2.6 is now available. We have mentioned from of the security improvements in an earlier post. The latest version promises a number of security enhancements as [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Angry Goe</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-12079</link>
		<dc:creator>Angry Goe</dc:creator>
		<pubDate>Wed, 16 Jul 2008 02:41:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-12079</guid>
		<description>WTF is wordpress and why should I care?</description>
		<content:encoded><![CDATA[<p>WTF is wordpress and why should I care?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ChaosKaizer</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-11731</link>
		<dc:creator>ChaosKaizer</dc:creator>
		<pubDate>Thu, 03 Jul 2008 05:09:35 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-11731</guid>
		<description>switching off some features is not &quot;security improvements&quot;. Why not just separate the whole features from being download in the first place. I think they should improve their code and hardcoded it instead of turning it off. 

anyway there is others alternative like openid &amp; oauth to make it more secure..</description>
		<content:encoded><![CDATA[<p>switching off some features is not &#8220;security improvements&#8221;. Why not just separate the whole features from being download in the first place. I think they should improve their code and hardcoded it instead of turning it off. </p>
<p>anyway there is others alternative like openid &amp; oauth to make it more secure..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress 2.6 B&#234;ta 1 - Emmanuel GEORJON</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-11677</link>
		<dc:creator>WordPress 2.6 B&#234;ta 1 - Emmanuel GEORJON</dc:creator>
		<pubDate>Thu, 26 Jun 2008 18:03:32 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-11677</guid>
		<description>[...] WordPress 2.6 Security Improvements? du site BlogSecurity.net, [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress 2.6 Security Improvements? du site BlogSecurity.net, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bj</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-11669</link>
		<dc:creator>bj</dc:creator>
		<pubDate>Tue, 24 Jun 2008 12:04:21 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-11669</guid>
		<description>Since the xml/rpc stuff is what makes wordpress so kickass in the search engines, turning this stuff off is not exactly going to win friends and influence people. It would be better to find a way to make it secure for those who wish to use the features and develop a method to turn them off for those who don&#039;t need them.

And it is about time that Matt Mullenweig started paying attention to security. I&#039;ve heard backroom rumors that his dev team has been screaming for this for years.</description>
		<content:encoded><![CDATA[<p>Since the xml/rpc stuff is what makes wordpress so kickass in the search engines, turning this stuff off is not exactly going to win friends and influence people. It would be better to find a way to make it secure for those who wish to use the features and develop a method to turn them off for those who don&#8217;t need them.</p>
<p>And it is about time that Matt Mullenweig started paying attention to security. I&#8217;ve heard backroom rumors that his dev team has been screaming for this for years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress Vs Blogger - WebProWorld</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-11668</link>
		<dc:creator>Wordpress Vs Blogger - WebProWorld</dc:creator>
		<pubDate>Tue, 24 Jun 2008 10:11:34 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-11668</guid>
		<description>[...] Re: Wordpress Vs Blogger     On and off topic  I have ran a self hosted Wordpress blog for awhile and I agree with everyone that is rocks. But with reports of security issues with wordpress I&#039;m not sure if I&#039;m going to say with it. Wordpress being open source and as widely used, it has become a hackers magnet. Wordpress also does not have anyone dedicated to security that I know of.  So with this in mind what other blogger software is as good as Wordpress to be honest I&#039;m not sure can anyone help me out there? or give your thoughts on these issues.  Other comments on wordpress issues. [...]</description>
		<content:encoded><![CDATA[<p>[...] Re: Wordpress Vs Blogger     On and off topic  I have ran a self hosted Wordpress blog for awhile and I agree with everyone that is rocks. But with reports of security issues with wordpress I&#8217;m not sure if I&#8217;m going to say with it. Wordpress being open source and as widely used, it has become a hackers magnet. Wordpress also does not have anyone dedicated to security that I know of.  So with this in mind what other blogger software is as good as Wordpress to be honest I&#8217;m not sure can anyone help me out there? or give your thoughts on these issues.  Other comments on wordpress issues. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Terry</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-11649</link>
		<dc:creator>Terry</dc:creator>
		<pubDate>Mon, 23 Jun 2008 14:56:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-11649</guid>
		<description>[quote]A number of XMLRPC features will be deactivated by default. I doubt they will remove functions such as pingbacks and trackbacks, however, it is something to keep an eye on.[quote]

Many users do not need comment, pingbacks and trackbacks so it would be very useful to produce a guide to disabling these features in older versions of WordPress.</description>
		<content:encoded><![CDATA[<p>[quote]A number of XMLRPC features will be deactivated by default. I doubt they will remove functions such as pingbacks and trackbacks, however, it is something to keep an eye on.[quote]</p>
<p>Many users do not need comment, pingbacks and trackbacks so it would be very useful to produce a guide to disabling these features in older versions of WordPress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dot tilde dot</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-11648</link>
		<dc:creator>dot tilde dot</dc:creator>
		<pubDate>Mon, 23 Jun 2008 14:21:40 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-11648</guid>
		<description>i usually disable xmlrpc on my sites where i dont need it, and it has been working alright for me. 

disabling a necessary feature is not an option, thank you for pointing that out... again.

.~.</description>
		<content:encoded><![CDATA[<p>i usually disable xmlrpc on my sites where i dont need it, and it has been working alright for me. </p>
<p>disabling a necessary feature is not an option, thank you for pointing that out&#8230; again.</p>
<p>.~.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://blogsecurity.net/wordpress/wordpress-26-security-improvements/comment-page-1#comment-11644</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Mon, 23 Jun 2008 11:46:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-26-security-improvements/#comment-11644</guid>
		<description>Now, if just anybody would care  to explain how disabling a feature would reduce attack surface for those who need said feature and thus switch it on? 

Is it any safer when all the other blogs don&#039;t use it? Hm, not in my book at least. 

Otherwise, how would you judge the hypothetical attempt of Microsoft to disable internet access in the next release of Windows as it has proved to be a very vulnerable attack surface in the past versions?</description>
		<content:encoded><![CDATA[<p>Now, if just anybody would care  to explain how disabling a feature would reduce attack surface for those who need said feature and thus switch it on? </p>
<p>Is it any safer when all the other blogs don&#8217;t use it? Hm, not in my book at least. </p>
<p>Otherwise, how would you judge the hypothetical attempt of Microsoft to disable internet access in the next release of Windows as it has proved to be a very vulnerable attack surface in the past versions?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
