<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Insecure by Design?</title>
	<atom:link href="http://blogsecurity.net/wordpress/wordpress-insecure-by-design/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-16112</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Thu, 12 Feb 2009 12:07:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-16112</guid>
		<description>Milan, WordPress has come a far way since Jan/08 (when this post was released). They still have a fair way to go but they have implemented some great security features in recent version.

I like to think BlogSecurity had something to do with this.</description>
		<content:encoded><![CDATA[<p>Milan, WordPress has come a far way since Jan/08 (when this post was released). They still have a fair way to go but they have implemented some great security features in recent version.</p>
<p>I like to think BlogSecurity had something to do with this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Milan</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-16096</link>
		<dc:creator>Milan</dc:creator>
		<pubDate>Tue, 10 Feb 2009 21:50:02 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-16096</guid>
		<description>As a relatively unsophisticated WordPress user, I find this worrisome. Hopefully, it is something they will prioritize for the next version, rather than tinkering with the look of admin pages again.

Is this the kind of thing where a good fix could be &#039;dropped in,&#039; or would it require a great deal of coding and testing?</description>
		<content:encoded><![CDATA[<p>As a relatively unsophisticated WordPress user, I find this worrisome. Hopefully, it is something they will prioritize for the next version, rather than tinkering with the look of admin pages again.</p>
<p>Is this the kind of thing where a good fix could be &#8216;dropped in,&#8217; or would it require a great deal of coding and testing?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: I want my WordPress! &#171;</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-16029</link>
		<dc:creator>I want my WordPress! &#171;</dc:creator>
		<pubDate>Wed, 04 Feb 2009 01:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-16029</guid>
		<description>[...] this a technical impossibility? Are there good reasons (security reasons, maybe?) For anyone who has been blogging for the Observer, are you okay with the current [...]</description>
		<content:encoded><![CDATA[<p>[...] this a technical impossibility? Are there good reasons (security reasons, maybe?) For anyone who has been blogging for the Observer, are you okay with the current [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-8434</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Sun, 16 Mar 2008 22:56:53 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-8434</guid>
		<description>We&#039;ll take your &#039;objective blog&#039; as a compliment, thanks.

If you want something more detailed, attend my OWASP presentation in London, planned in April :)</description>
		<content:encoded><![CDATA[<p>We&#8217;ll take your &#8216;objective blog&#8217; as a compliment, thanks.</p>
<p>If you want something more detailed, attend my OWASP presentation in London, planned in April :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xentek</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-8395</link>
		<dc:creator>xentek</dc:creator>
		<pubDate>Thu, 13 Mar 2008 14:23:32 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-8395</guid>
		<description>mysql_escape_string()? Is that it? I figured an objective blog like this could spend a little more time going deeper than that.

And I would argue, having done multiple projects with both platforms, that Drupal is not more secure. It has more published exploits than WP, and some of its most popular modules don&#039;t conform to either their published coding standards or security practices. Some of them don&#039;t even use the published API and are littered with plain SQL through out the source.

Also its interesting that you say this, yet are using WP to publish this very blog.</description>
		<content:encoded><![CDATA[<p>mysql_escape_string()? Is that it? I figured an objective blog like this could spend a little more time going deeper than that.</p>
<p>And I would argue, having done multiple projects with both platforms, that Drupal is not more secure. It has more published exploits than WP, and some of its most popular modules don&#8217;t conform to either their published coding standards or security practices. Some of them don&#8217;t even use the published API and are littered with plain SQL through out the source.</p>
<p>Also its interesting that you say this, yet are using WP to publish this very blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Halil</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-7732</link>
		<dc:creator>Halil</dc:creator>
		<pubDate>Tue, 26 Feb 2008 14:28:58 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-7732</guid>
		<description>@Ryan Boren

I dont wanna be rude but I really find the excuse to be funny.

Drop the very old version support of mySQL and PHP, raise the minumum required versions if it is needed.

I dont understand how this can be an excuse of bad/in-efficient/in-secure etc. design.</description>
		<content:encoded><![CDATA[<p>@Ryan Boren</p>
<p>I dont wanna be rude but I really find the excuse to be funny.</p>
<p>Drop the very old version support of mySQL and PHP, raise the minumum required versions if it is needed.</p>
<p>I dont understand how this can be an excuse of bad/in-efficient/in-secure etc. design.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fredrik Wärnsberg</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-7346</link>
		<dc:creator>Fredrik Wärnsberg</dc:creator>
		<pubDate>Mon, 18 Feb 2008 20:54:33 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-7346</guid>
		<description>I dug through the WP source code briefly a couple of days ago and I was also left puzzled as to why they weren&#039;t using mysql_real_escape string. In my experience that&#039;s standard practice.

On the other hand, that shouldn&#039;t be too hard for them to fix.

I also have to agree with Leonid&#039;s point on PHP ;)</description>
		<content:encoded><![CDATA[<p>I dug through the WP source code briefly a couple of days ago and I was also left puzzled as to why they weren&#8217;t using mysql_real_escape string. In my experience that&#8217;s standard practice.</p>
<p>On the other hand, that shouldn&#8217;t be too hard for them to fix.</p>
<p>I also have to agree with Leonid&#8217;s point on PHP ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Tăng cường bảo mật cho wordpress VNIT™ - VNITWEB &#187; Tăng cường bảo mật cho wordpress: Chuyên Trang Chia Sẻ, Công Nghệ Thông Tin Và Giải Trí Tổng Hợp VN</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-6904</link>
		<dc:creator>&#187; Tăng cường bảo mật cho wordpress VNIT™ - VNITWEB &#187; Tăng cường bảo mật cho wordpress: Chuyên Trang Chia Sẻ, Công Nghệ Thông Tin Và Giải Trí Tổng Hợp VN</dc:creator>
		<pubDate>Thu, 07 Feb 2008 17:05:54 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-6904</guid>
		<description>[...] http://blogsecurity.net/wordpress/wordpress-insecure-by-design/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blogsecurity.net/wordpress/wordpress-insecure-by-design/" rel="nofollow">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Boren</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-6859</link>
		<dc:creator>Ryan Boren</dc:creator>
		<pubDate>Wed, 06 Feb 2008 17:45:38 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-6859</guid>
		<description>Given the old versions of PHP and MySQL we support and the peculiar DB setups we encounter, we&#039;ve had troubles with simply using mysql_real_escape_string().  The Drupal method of enforcing UTF-8 is appealing, but we&#039;re stuck with what we have for now.  If anyone has insight on how to get mysql_real_escape_string() and friends to behave across all of the environments WP supports, please share on &lt;a href=&quot;http://trac.wordpress.org/ticket/5455#comment:18&quot; rel=&quot;nofollow&quot;&gt;this bug report&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>Given the old versions of PHP and MySQL we support and the peculiar DB setups we encounter, we&#8217;ve had troubles with simply using mysql_real_escape_string().  The Drupal method of enforcing UTF-8 is appealing, but we&#8217;re stuck with what we have for now.  If anyone has insight on how to get mysql_real_escape_string() and friends to behave across all of the environments WP supports, please share on <a href="http://trac.wordpress.org/ticket/5455#comment:18" rel="nofollow">this bug report</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Is WordPress&#8217; security vulnerable at its core? &#124; WordPressGarage.com</title>
		<link>http://blogsecurity.net/wordpress/wordpress-insecure-by-design/comment-page-1#comment-6847</link>
		<dc:creator>Is WordPress&#8217; security vulnerable at its core? &#124; WordPressGarage.com</dc:creator>
		<pubDate>Wed, 06 Feb 2008 09:04:39 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-insecure-by-design/#comment-6847</guid>
		<description>[...] seems to be the latter, and BlogSecurity.net addressed the general issue of WordPress security recently: We have seen alot of critical vulnerabilities being discovered in WordPress core and its [...]</description>
		<content:encoded><![CDATA[<p>[...] seems to be the latter, and BlogSecurity.net addressed the general issue of WordPress security recently: We have seen alot of critical vulnerabilities being discovered in WordPress core and its [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
