<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 98% of WordPress Blogs Vulnerable</title>
	<atom:link href="http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/feed/" rel="self" type="application/rss+xml" />
	<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/</link>
	<description>Business and Technology with Common Sense</description>
	<lastBuildDate>Thu, 24 May 2012 21:21:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-beta4-20883</generator>
	<item>
		<title>By: Ness</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42551</link>
		<dc:creator>Ness</dc:creator>
		<pubDate>Sat, 16 Feb 2008 14:54:27 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42551</guid>
		<description>It crashed when I tried to update from an earlier version to latest one. Didn&#039;t work.</description>
		<content:encoded><![CDATA[<p>It crashed when I tried to update from an earlier version to latest one. Didn&#8217;t work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Zatz</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42550</link>
		<dc:creator>Dave Zatz</dc:creator>
		<pubDate>Sat, 09 Jun 2007 12:53:21 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42550</guid>
		<description>Er make that &quot;Subscribe&quot; to Comments. I need my coffee.</description>
		<content:encoded><![CDATA[<p>Er make that &#8220;Subscribe&#8221; to Comments. I need my coffee.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Zatz</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42549</link>
		<dc:creator>Dave Zatz</dc:creator>
		<pubDate>Sat, 09 Jun 2007 12:52:13 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42549</guid>
		<description>2.2 broke my Respond to Comments plugin. Wonder if B5&#039;s new talent knows anything about that. ;)</description>
		<content:encoded><![CDATA[<p>2.2 broke my Respond to Comments plugin. Wonder if B5&#8242;s new talent knows anything about that. ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jermayn Parker</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42548</link>
		<dc:creator>Jermayn Parker</dc:creator>
		<pubDate>Wed, 30 May 2007 03:57:17 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42548</guid>
		<description>yeah I must upgrade, thanks the timely reminder..

Only surveying 50 is not much though</description>
		<content:encoded><![CDATA[<p>yeah I must upgrade, thanks the timely reminder..</p>
<p>Only surveying 50 is not much though</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: docwhat</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42547</link>
		<dc:creator>docwhat</dc:creator>
		<pubDate>Tue, 29 May 2007 20:14:37 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42547</guid>
		<description>So how did you detect the version of the blog in your survey?  The header in the template?  Oooh... or the css href on wp-admin works, too...

I&#039;m not very happy that the software and version is broadcast in wordpress.  It&#039;s not so much security by obscurity than hiding from the fricking spammers.  When I took out the header, my comment spam decreased over the next 3-4 weeks.

Ciao!</description>
		<content:encoded><![CDATA[<p>So how did you detect the version of the blog in your survey?  The header in the template?  Oooh&#8230; or the css href on wp-admin works, too&#8230;</p>
<p>I&#8217;m not very happy that the software and version is broadcast in wordpress.  It&#8217;s not so much security by obscurity than hiding from the fricking spammers.  When I took out the header, my comment spam decreased over the next 3-4 weeks.</p>
<p>Ciao!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashish Mohta</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42546</link>
		<dc:creator>Ashish Mohta</dc:creator>
		<pubDate>Mon, 28 May 2007 05:21:24 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42546</guid>
		<description>Lol that was funny, 1.5 o boy. But your right. people are so happy with what is running so smooth they never want to take a chance. In the era where taking backup is so easy and to get back to previous state is easier than that...I wonder why ppl don&#039;t upgrade.</description>
		<content:encoded><![CDATA[<p>Lol that was funny, 1.5 o boy. But your right. people are so happy with what is running so smooth they never want to take a chance. In the era where taking backup is so easy and to get back to previous state is easier than that&#8230;I wonder why ppl don&#8217;t upgrade.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carol</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42545</link>
		<dc:creator>Carol</dc:creator>
		<pubDate>Sat, 26 May 2007 23:57:28 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42545</guid>
		<description>I know, I know...I should upgrade both blogs.  Honestly when I read the instructions my eyes go all googly and I get a piercing pain in my head.

Sigh.  I&#039;m a bad, bad blogger.</description>
		<content:encoded><![CDATA[<p>I know, I know&#8230;I should upgrade both blogs.  Honestly when I read the instructions my eyes go all googly and I get a piercing pain in my head.</p>
<p>Sigh.  I&#8217;m a bad, bad blogger.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jenny</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42544</link>
		<dc:creator>Jenny</dc:creator>
		<pubDate>Sat, 26 May 2007 17:55:24 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42544</guid>
		<description>I&#039;m waiting for FANTASTICO to let me upgrade. I fear the possibility of screwing up my site. At least this way, it&#039;s backed up from head to toe and I can easily reinstall it.</description>
		<content:encoded><![CDATA[<p>I&#8217;m waiting for FANTASTICO to let me upgrade. I fear the possibility of screwing up my site. At least this way, it&#8217;s backed up from head to toe and I can easily reinstall it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: that girl again</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42543</link>
		<dc:creator>that girl again</dc:creator>
		<pubDate>Sat, 26 May 2007 13:27:11 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42543</guid>
		<description>Why does the wordpress default theme include the version number in the header and order us to &#039;leave this for stats&#039;? I know security by obscurity is no substitute for keeping up to date, but, realistically, not everyone is going to upgrade on a monthly basis and broadcasting your vulnerability in metatags doesn&#039;t seem the smartest move. Theme designers really need to start thinking about the code they&#039;re using and quit blindly copy-pasting from Kubrick.</description>
		<content:encoded><![CDATA[<p>Why does the wordpress default theme include the version number in the header and order us to &#8216;leave this for stats&#8217;? I know security by obscurity is no substitute for keeping up to date, but, realistically, not everyone is going to upgrade on a monthly basis and broadcasting your vulnerability in metatags doesn&#8217;t seem the smartest move. Theme designers really need to start thinking about the code they&#8217;re using and quit blindly copy-pasting from Kubrick.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brem</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42542</link>
		<dc:creator>brem</dc:creator>
		<pubDate>Fri, 25 May 2007 18:02:44 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42542</guid>
		<description>The thing is, you never know if the new version will work with all the plug-ins. And to backup the DB and files before every update is kind of a pain...

I update... but I tend to be one version behind...:)</description>
		<content:encoded><![CDATA[<p>The thing is, you never know if the new version will work with all the plug-ins. And to backup the DB and files before every update is kind of a pain&#8230;</p>
<p>I update&#8230; but I tend to be one version behind&#8230;:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42541</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Fri, 25 May 2007 16:39:34 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42541</guid>
		<description>Well all the devs blogs have it. In addition, you should subscribe to &lt;a href=&quot;http://blogsearch.google.com/blogsearch_feeds?hl=en&amp;q=wordpress+security&amp;ie=utf-8&amp;num=10&amp;output=rss&quot;&gt;this&lt;/a&gt; or setup a google alert.</description>
		<content:encoded><![CDATA[<p>Well all the devs blogs have it. In addition, you should subscribe to <a href="http://blogsearch.google.com/blogsearch_feeds?hl=en&amp;q=wordpress+security&amp;ie=utf-8&amp;num=10&amp;output=rss">this</a> or setup a google alert.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Zatz</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42540</link>
		<dc:creator>Dave Zatz</dc:creator>
		<pubDate>Fri, 25 May 2007 16:35:39 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42540</guid>
		<description>Adam is on target...

If WordPress x.x.x has a vulnerability WordPress the organization should be more active in communicating that to folks running the software. The only reason I knew 2.1.13 had a problem is because I read it here. My Dashboard says 2.2 is available, but it doesn&#039;t say I should upgrade ASAP because there&#039;s a security flaw. Security through obscurity?

Also upgrading can be stressful and a PITA for the less tech savvy. Again without learning abut upgrade scripts here, I&#039;d still be putting it off.</description>
		<content:encoded><![CDATA[<p>Adam is on target&#8230;</p>
<p>If WordPress x.x.x has a vulnerability WordPress the organization should be more active in communicating that to folks running the software. The only reason I knew 2.1.13 had a problem is because I read it here. My Dashboard says 2.2 is available, but it doesn&#8217;t say I should upgrade ASAP because there&#8217;s a security flaw. Security through obscurity?</p>
<p>Also upgrading can be stressful and a PITA for the less tech savvy. Again without learning abut upgrade scripts here, I&#8217;d still be putting it off.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wendy Piersall</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42539</link>
		<dc:creator>Wendy Piersall</dc:creator>
		<pubDate>Fri, 25 May 2007 16:34:06 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42539</guid>
		<description>Aaron, you can take partial credit for the fact that I am running 2.2 thanks to your post a couple of weeks ago. :)</description>
		<content:encoded><![CDATA[<p>Aaron, you can take partial credit for the fact that I am running 2.2 thanks to your post a couple of weeks ago. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42538</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Fri, 25 May 2007 14:07:21 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42538</guid>
		<description>just for clarity-
if 2.1.3 is that eminently hackable, why is there no 2.0.11?  was the vulnerability only in the 2.1 branch?</description>
		<content:encoded><![CDATA[<p>just for clarity-<br />
if 2.1.3 is that eminently hackable, why is there no 2.0.11?  was the vulnerability only in the 2.1 branch?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42537</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Fri, 25 May 2007 13:32:56 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42537</guid>
		<description>adam: It&#039;s on Digg now - and yes you can &lt;A href=&quot;http://digg.com/software/98_of_WordPress_Blogs_Vulnerable&quot;&gt;feel free to Digg it&lt;/a&gt;. On the other hand, Digg&#039;s got a big bullhorn so thats another way to make lots of people hear about it.

YTour point about ongoing notifications though is well recieved.</description>
		<content:encoded><![CDATA[<p>adam: It&#8217;s on Digg now &#8211; and yes you can <a href="http://digg.com/software/98_of_WordPress_Blogs_Vulnerable">feel free to Digg it</a>. On the other hand, Digg&#8217;s got a big bullhorn so thats another way to make lots of people hear about it.</p>
<p>YTour point about ongoing notifications though is well recieved.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42536</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Fri, 25 May 2007 13:05:59 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42536</guid>
		<description>So you&#039;re saying you&#039;d like me to demonstrate on your blog how 2.1.3 is vulnerable? Trust me when I say that I can gain admin access to your blog in 5 minutes.</description>
		<content:encoded><![CDATA[<p>So you&#8217;re saying you&#8217;d like me to demonstrate on your blog how 2.1.3 is vulnerable? Trust me when I say that I can gain admin access to your blog in 5 minutes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42535</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Fri, 25 May 2007 13:05:53 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42535</guid>
		<description>this might be something that should be broadcast from the dashboard.  i doubt that any of the people whose blogs are insecure are reading slashdot, or your blog, or the hackers list.

it&#039;s the people who spend more time actually blogging, than reading about blogging.  and it&#039;s the reason that it&#039;s &lt;strong&gt;so important&lt;/strong&gt; that &quot;easy upgrading&quot; gets finished before any more versions of wordpress ship.</description>
		<content:encoded><![CDATA[<p>this might be something that should be broadcast from the dashboard.  i doubt that any of the people whose blogs are insecure are reading slashdot, or your blog, or the hackers list.</p>
<p>it&#8217;s the people who spend more time actually blogging, than reading about blogging.  and it&#8217;s the reason that it&#8217;s <strong>so important</strong> that &#8220;easy upgrading&#8221; gets finished before any more versions of wordpress ship.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: docwhat</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42534</link>
		<dc:creator>docwhat</dc:creator>
		<pubDate>Fri, 25 May 2007 12:59:15 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42534</guid>
		<description>2.2 only came out 10 days ago.  People running 2.1.3 are reasonably with-it.

It would be interesting if you check the same sites in a couple weeks to see how they change.

Ciao!</description>
		<content:encoded><![CDATA[<p>2.2 only came out 10 days ago.  People running 2.1.3 are reasonably with-it.</p>
<p>It would be interesting if you check the same sites in a couple weeks to see how they change.</p>
<p>Ciao!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Beard</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42533</link>
		<dc:creator>Andy Beard</dc:creator>
		<pubDate>Fri, 25 May 2007 11:07:45 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42533</guid>
		<description>Running 2.2 on primary blogs, I have been slacking on a few niche ones and &quot;marketing platforms&quot;

At least I beat your statistics, but most don&#039;t</description>
		<content:encoded><![CDATA[<p>Running 2.2 on primary blogs, I have been slacking on a few niche ones and &#8220;marketing platforms&#8221;</p>
<p>At least I beat your statistics, but most don&#8217;t</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Hampton</title>
		<link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/comment-page-1/#comment-42532</link>
		<dc:creator>Michael Hampton</dc:creator>
		<pubDate>Fri, 25 May 2007 10:57:53 +0000</pubDate>
		<guid isPermaLink="false">http://technosailor.com/98-of-wordpress-blogs-vulnerable/#comment-42532</guid>
		<description>Odd, that. Nine out of 10 of my blogs are up to date. The tenth is getting upgraded in a few minutes.</description>
		<content:encoded><![CDATA[<p>Odd, that. Nine out of 10 of my blogs are up to date. The tenth is getting upgraded in a few minutes.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

