<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Security Predictions in 2009</title>
	<atom:link href="http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Abel Cheung</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15113</link>
		<dc:creator>Abel Cheung</dc:creator>
		<pubDate>Sun, 18 Jan 2009 00:22:56 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15113</guid>
		<description>Let&#039;s make sure many peoples&#039; heads are run over by cars before deciding whether to build traffic lights or not.</description>
		<content:encoded><![CDATA[<p>Let&#8217;s make sure many peoples&#8217; heads are run over by cars before deciding whether to build traffic lights or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15112</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Sat, 17 Jan 2009 23:31:29 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15112</guid>
		<description>DNS-reliance is a known factor in password resets, core upgrade, plugin installation, plugin browsing, pingbacks, update notification, pingomatic, and RSS/dashboard feeds.

If you have any examples of distributed PHP web applications that deal with DNS in an elegant, secure way I would love to learn more about them.</description>
		<content:encoded><![CDATA[<p>DNS-reliance is a known factor in password resets, core upgrade, plugin installation, plugin browsing, pingbacks, update notification, pingomatic, and RSS/dashboard feeds.</p>
<p>If you have any examples of distributed PHP web applications that deal with DNS in an elegant, secure way I would love to learn more about them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15111</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Sat, 17 Jan 2009 03:18:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15111</guid>
		<description>I try to wherever I come across it, like above.</description>
		<content:encoded><![CDATA[<p>I try to wherever I come across it, like above.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zonknz</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15110</link>
		<dc:creator>zonknz</dc:creator>
		<pubDate>Sat, 17 Jan 2009 02:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15110</guid>
		<description>Matt, can you enlighten us then what protections exist in wordpress to ensure valid code is being applied and you&#039;re not being MITM/dns poisoned and redirected in the wordpress core upgrade feature?

Code signing? https against a know cert? Or as i assert, are you relying on dns to assert validity of code?</description>
		<content:encoded><![CDATA[<p>Matt, can you enlighten us then what protections exist in wordpress to ensure valid code is being applied and you&#8217;re not being MITM/dns poisoned and redirected in the wordpress core upgrade feature?</p>
<p>Code signing? https against a know cert? Or as i assert, are you relying on dns to assert validity of code?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15109</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Sat, 17 Jan 2009 01:01:48 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15109</guid>
		<description>Matt, I have no problem with this but it would be nice seeing the door swing in both directions.</description>
		<content:encoded><![CDATA[<p>Matt, I have no problem with this but it would be nice seeing the door swing in both directions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15108</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Fri, 16 Jan 2009 21:49:48 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15108</guid>
		<description>It would be nice if Blogsecurity contributed to debunking common WP security myths or misconceptions like the above or in the Codex:

http://codex.wordpress.org/CVEs</description>
		<content:encoded><![CDATA[<p>It would be nice if Blogsecurity contributed to debunking common WP security myths or misconceptions like the above or in the Codex:</p>
<p><a href="http://codex.wordpress.org/CVEs" rel="nofollow">http://codex.wordpress.org/CVEs</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15107</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Fri, 16 Jan 2009 21:42:10 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15107</guid>
		<description>Zonknz, that&#039;s a DB upgrade, which is completely separate from the core upgrade feature which downloads and installs new files. You conflated the two. &quot;[Y]ou can run [whatever] code on the [targeted] blog&quot; is completely wrong.</description>
		<content:encoded><![CDATA[<p>Zonknz, that&#8217;s a DB upgrade, which is completely separate from the core upgrade feature which downloads and installs new files. You conflated the two. &#8220;[Y]ou can run [whatever] code on the [targeted] blog&#8221; is completely wrong.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15101</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Thu, 15 Jan 2009 21:17:29 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15101</guid>
		<description>zonknz, I completely missed this, thanks for bringing it to my attention. I&#039;ll write something up on this.</description>
		<content:encoded><![CDATA[<p>zonknz, I completely missed this, thanks for bringing it to my attention. I&#8217;ll write something up on this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zonknz</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15100</link>
		<dc:creator>zonknz</dc:creator>
		<pubDate>Thu, 15 Jan 2009 19:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15100</guid>
		<description>Maybe you&#039;ve seen this, maybe not.

http://www.securityfocus.com/archive/1/499505/30/0/threaded

Anyone can force an upgrade of wordpress from any location,  unathenticated. 

Suppose you can dns poison, MITM , the download itself = you can run what ever code on the targetted blog.

Doesn&#039;t appear to be any signing, or reliable way to tell that the automatic d/l you&#039;re applying has actually come from wordpress.org - the real one, that is. They appear to be relying on DNS! for security!

Crazy, Crazy.</description>
		<content:encoded><![CDATA[<p>Maybe you&#8217;ve seen this, maybe not.</p>
<p><a href="http://www.securityfocus.com/archive/1/499505/30/0/threaded" rel="nofollow">http://www.securityfocus.com/archive/1/499505/30/0/threaded</a></p>
<p>Anyone can force an upgrade of wordpress from any location,  unathenticated. </p>
<p>Suppose you can dns poison, MITM , the download itself = you can run what ever code on the targetted blog.</p>
<p>Doesn&#8217;t appear to be any signing, or reliable way to tell that the automatic d/l you&#8217;re applying has actually come from wordpress.org &#8211; the real one, that is. They appear to be relying on DNS! for security!</p>
<p>Crazy, Crazy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wordpress-security-predictions-in-2009/comment-page-1#comment-15099</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Thu, 15 Jan 2009 12:13:17 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/?p=306#comment-15099</guid>
		<description>Peter, it looks interesting, I&#039;ll check it out over the weekend, thanks for the link.</description>
		<content:encoded><![CDATA[<p>Peter, it looks interesting, I&#8217;ll check it out over the weekend, thanks for the link.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

