<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>KodeeXII.Net &#187; wordpress vulnerability</title>
	<atom:link href="http://kodeexii.net/tag/wordpress-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://kodeexii.net</link>
	<description>Hadee Roslan’s Ramblings on Technology, Mindset and Methodology to Build A Successful Online Business.</description>
	<lastBuildDate>Tue, 29 Nov 2011 10:47:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<atom:link rel='hub' href='http://kodeexii.net/?pushpress=hub'/>
<cloud domain='kodeexii.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
	<!-- google_ad_section_end --><!-- google_ad_section_start -->	<item>
		<title>Prevent a WordPress Vulnerability Exploit &#8211; Upgrade to 2.6.2</title>
		<link>http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html</link>
		<comments>http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html#comments</comments>
		<pubDate>Tue, 09 Sep 2008 20:33:58 +0000</pubDate>
		<dc:creator>kodeexii</dc:creator>
				<category><![CDATA[Computer Technology]]></category>
		<category><![CDATA[sql column truncation]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.6.2]]></category>
		<category><![CDATA[wordpress release]]></category>
		<category><![CDATA[wordpress vulnerability]]></category>

		<guid isPermaLink="false">http://kodeexii.net/blog/?p=537</guid>
		<description><![CDATA[Wordpress just released their 2.6.2 version. This update include a vulnerability patch. Existing Wordpress users who allow registrations on their sites should update to this release. Your users' password can be modified by the bad guys if you don't upgrade. You wouldn't want your users annoyed by having their passwords modified randomly for them do you?]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="float: right;" src="http://kodeexii.net/blog/wp-content/uploads/2007/12/wpicon.jpg" alt="Wordpress Icon" width="51" height="51" />Are you running a WordPress site? Do you allow user registration on your WordPress site? If you do, you might want to upgrade your site or sites to the latest WordPress release, which is 2.6.2.  There is a <a  target="_blank" title="Wordpress 2.6.2 Vulnerability" href="http://wordpress.org/development/2008/09/wordpress-262/">vulnerability in WordPress versions prior to 2.6.2</a>. This, however, affects you only if you allow user registrations into your WordPress site.</p>
<p>What vulnerability? Well, the person who disclosed the vulnerability, <a  target="_blank" href="http://www.suspekt.org/">Stefan Esser</a>, calls it the <a  target="_blank" title="Steffan Esser's MySQL and SQL Column Truncation Vulnerabilities" href="http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/"><strong>SQL Column Truncation Vulnerabilities</strong></a>. What is it? In plain English, it allows them bad people to sort of modify passwords of other existing users in the system.</p>
<p>Them bad people will still not be able to get into the system as other users, though. The new password is still unknown to them as it was randomly generated. However, it is still breakable with a little more effort since there is also a weakness in how the random password was generated.</p>
<p>What this does is basically annoy your users as they will then have to reset their passwords since it&#8217;s been changed by the bad people. Thus, if you don&#8217;t want your registered users and customers to be annoyed silly by these bad people who go around changing user passwords, I recommend that you <a  target="_blank" title="Download WordPress 2.6.2" href="http://wordpress.org/download/">upgrade your WordPress installation to 2.6.2</a></p>
<p>Do note that the SQL Column Truncation Vulnerability affects all application using MySQL as the backend database. Verify with your app vendor about this.</p>
<div class="evernoteSiteMemory"><a href="javascript:" onclick="Evernote.doClip({title: 'Prevent a WordPress Vulnerability Exploit &amp;#8211; Upgrade to 2.6.2 on KodeeXII.Net',url: 'http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html',contentID: 'post',code: 'Hade2895',suggestTags: 'sql column truncation,wordpress,wordpress 2.6.2,wordpress release,wordpress vulnerability',providerName: 'KodeeXII.Net',styling: 'text' });return false" class="evernoteSiteMemoryLink"><img src="http://kodeexii.net/wp/wp-content/plugins/wp-evernote-site-memory/img/smallclip.png" class="evernoteSiteMemoryButton" /></a>
				<p class="evernoteSiteMemoryDescription">
					<strong>Evernote</strong> lets you save all the interesting things you see online into a single place. Access all those saved pages from your computer, phone or the web.  <a  href="https://www.evernote.com/Registration.action" title="Sign up for Evernote" target="_blank">Sign up now</a> or <a  href="https://www.evernote.com/about/learn_more/" title="Learn more about Evernote" target="_blank">learn more</a>. It's free!
				</p>
				
				<div class="evernoteSiteMemoryClear">&nbsp;</div>
			</div>]]></content:encoded>
			<wfw:commentRss>http://kodeexii.net/prevent-a-wordpress-vulnerability-exploit-upgrade-to-262.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<!-- google_ad_section_end --></channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 74/90 queries in 0.023 seconds using disk: basic
Object Caching 941/964 objects using disk: basic

Served from: kodeexii.net @ 2012-02-10 18:06:15 -->
