<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress 2.6.1 Weak Entropy Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jim</title>
		<link>http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/comment-page-1#comment-14175</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Tue, 07 Oct 2008 14:43:53 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/#comment-14175</guid>
		<description>I don&#039;t see why people have open registration on their wordpress blogs anyways. You can install captcha you sway away the comment spammers.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t see why people have open registration on their wordpress blogs anyways. You can install captcha you sway away the comment spammers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/comment-page-1#comment-13612</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Fri, 12 Sep 2008 01:27:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/#comment-13612</guid>
		<description>&lt;strong&gt;DK&lt;/strong&gt;

It&#039;s worth to be mentioned that in case of this vulnerability (in both SQL Column Truncation exploit and Admin Takeover exploit) are affected only sites with open registration. So any WP site with open registration is in risk and needs to be updated to new version of WordPress.</description>
		<content:encoded><![CDATA[<p><strong>DK</strong></p>
<p>It&#8217;s worth to be mentioned that in case of this vulnerability (in both SQL Column Truncation exploit and Admin Takeover exploit) are affected only sites with open registration. So any WP site with open registration is in risk and needs to be updated to new version of WordPress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dt</title>
		<link>http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/comment-page-1#comment-13610</link>
		<dc:creator>dt</dc:creator>
		<pubDate>Thu, 11 Sep 2008 16:08:35 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/#comment-13610</guid>
		<description>Is not about entropy, is just an exploit for &quot;SQL Column Truncation&quot; bug that was fixed in latest wordpress versiorn (2.6.2) See http://wordpress.org/development/2008/09/wordpress-262/</description>
		<content:encoded><![CDATA[<p>Is not about entropy, is just an exploit for &#8220;SQL Column Truncation&#8221; bug that was fixed in latest wordpress versiorn (2.6.2) See <a href="http://wordpress.org/development/2008/09/wordpress-262/" rel="nofollow">http://wordpress.org/development/2008/09/wordpress-262/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph Scott</title>
		<link>http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/comment-page-1#comment-13609</link>
		<dc:creator>Joseph Scott</dc:creator>
		<pubDate>Thu, 11 Sep 2008 14:47:39 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-261-weak-entropy-vulnerability/#comment-13609</guid>
		<description>It&#039;s important to note that this is a general PHP issue, not something that is specific or unique to WordPress:

http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers/</description>
		<content:encoded><![CDATA[<p>It&#8217;s important to note that this is a general PHP issue, not something that is specific or unique to WordPress:</p>
<p><a href="http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers/" rel="nofollow">http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
