<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>KodeeXII.Net &#187; wordpress vulnerability</title>
	<atom:link href="http://kodeexii.net/tag/wordpress-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://kodeexii.net</link>
	<description>Miami Hurricanes, Tottenham Hotspurs, Computer Technology..</description>
	<lastBuildDate>Tue, 22 Jun 2010 08:18:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Prevent a WordPress Vulnerability Exploit &#8211; Upgrade to 2.6.2</title>
		<link>http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html</link>
		<comments>http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html#comments</comments>
		<pubDate>Tue, 09 Sep 2008 20:33:58 +0000</pubDate>
		<dc:creator>kodeexii</dc:creator>
				<category><![CDATA[Computer Technology]]></category>
		<category><![CDATA[sql column truncation]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.6.2]]></category>
		<category><![CDATA[wordpress release]]></category>
		<category><![CDATA[wordpress vulnerability]]></category>

		<guid isPermaLink="false">http://kodeexii.net/blog/?p=537</guid>
		<description><![CDATA[Wordpress just released their 2.6.2 version. This update include a vulnerability patch. Existing Wordpress users who allow registrations on their sites should update to this release. Your users' password can be modified by the bad guys if you don't upgrade. You wouldn't want your users annoyed by having their passwords modified randomly for them do you? <a href="http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="float: right;" src="http://kodeexii.net/blog/wp-content/uploads/2007/12/wpicon.jpg" alt="WordPress Icon" width="51" height="51" />Are you running a WordPress site? Do you allow user registration on your WordPress site? If you do, you might want to upgrade your site or sites to the latest WordPress release, which is 2.6.2.  There is a <a  title="WordPress 2.6.2 Vulnerability" href="http://wordpress.org/development/2008/09/wordpress-262/" target="_blank">vulnerability in WordPress versions prior to 2.6.2</a>. This, however, affects you only if you allow user registrations into your WordPress site.</p>
<p>What vulnerability? Well, the person who disclosed the vulnerability, <a  href="http://www.suspekt.org/">Stefan Esser</a>, calls it the <a  title="Steffan Esser's MySQL and SQL Column Truncation Vulnerabilities" href="http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/" target="_blank"><strong>SQL Column Truncation Vulnerabilities</strong></a>. What is it? In plain English, it allows them bad people to sort of modify passwords of other existing users in the system.</p>
<p>Them bad people will still not be able to get into the system as other users, though. The new password is still unknown to them as it was randomly generated. However, it is still breakable with a little more effort since there is also a weakness in how the random password was generated.</p>
<p>What this does is basically annoy your users as they will then have to reset their passwords since it&#8217;s been changed by the bad people. Thus, if you don&#8217;t want your registered users and customers to be annoyed silly by these bad people who go around changing user passwords, I recommend that you <a  title="Download WordPress 2.6.2" href="http://wordpress.org/download/" target="_blank">upgrade your WordPress installation to 2.6.2</a></p>
<p>Do note that the SQL Column Truncation Vulnerability affects all application using MySQL as the backend database. Verify with your app vendor about this.</p>
]]></content:encoded>
			<wfw:commentRss>http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
