<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wordpress 2.2 Security Hole: Identity Theft</title>
	<atom:link href="http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/feed/" rel="self" type="application/rss+xml" />
	<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/</link>
	<description>Free Softwares, Computers &#38; Linux</description>
	<lastBuildDate>Tue, 09 Mar 2010 13:14:55 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: UeberTs Thoughts &#187; strange accesses to Wordpress register page</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-4394</link>
		<dc:creator>UeberTs Thoughts &#187; strange accesses to Wordpress register page</dc:creator>
		<pubDate>Thu, 11 Sep 2008 09:24:13 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-4394</guid>
		<description>[...] wonder if it has to do with the current security hole (is there already an exploit ?), an earlier for Wordpress 2.2 or simply spam [...]</description>
		<content:encoded><![CDATA[<p>[...] wonder if it has to do with the current security hole (is there already an exploit ?), an earlier for Wordpress 2.2 or simply spam [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hindsight&#8230; It&#8217;s is a wonderful thing! &#171; Lee Kelleher&#8217;s Weblog</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-4061</link>
		<dc:creator>Hindsight&#8230; It&#8217;s is a wonderful thing! &#171; Lee Kelleher&#8217;s Weblog</dc:creator>
		<pubDate>Fri, 18 Jul 2008 23:03:16 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-4061</guid>
		<description>[...] to say, WordPress 2.2 has an ugly security hole which allows hackers to remotely inject SQL statements into the database.  I&#8217;d heard about [...]</description>
		<content:encoded><![CDATA[<p>[...] to say, WordPress 2.2 has an ugly security hole which allows hackers to remotely inject SQL statements into the database.  I&#8217;d heard about [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kev</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-3192</link>
		<dc:creator>kev</dc:creator>
		<pubDate>Sun, 07 Oct 2007 23:35:07 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-3192</guid>
		<description>&lt;blockquote&gt;Do yourself a huge favor and take the version number out of your templates&lt;/blockquote&gt;

I totally agree with you Tyler. This should be a strong recommandation to any template maker.

BTW, starting from &lt;a href=&quot;http://getk2.com/2007/09/k2-release-candidate-1/&quot; rel=&quot;nofollow&quot;&gt;RC1&lt;/a&gt;, &lt;a href=&quot;http://getk2.com&quot; rel=&quot;nofollow&quot;&gt;K2&lt;/a&gt; (the theme I use on this blog) will &lt;a href=&quot;http://code.google.com/p/kaytwo/source/detail?path=/trunk/footer.php&amp;r=432&quot; rel=&quot;nofollow&quot;&gt;no longer show the Wordpress version number&lt;/a&gt; to the user. Sadly, it will be still there in the html code. So it&#039;s a good start but not a solution at all... :(</description>
		<content:encoded><![CDATA[<blockquote><p>Do yourself a huge favor and take the version number out of your templates</p></blockquote>
<p>I totally agree with you Tyler. This should be a strong recommandation to any template maker.</p>
<p>BTW, starting from <a  href="http://getk2.com/2007/09/k2-release-candidate-1/" rel="nofollow">RC1</a>, <a  href="http://getk2.com" rel="nofollow">K2</a> (the theme I use on this blog) will <a  href="http://code.google.com/p/kaytwo/source/detail?path=/trunk/footer.php&#038;r=432" rel="nofollow">no longer show the Wordpress version number</a> to the user. Sadly, it will be still there in the html code. So it&#8217;s a good start but not a solution at all&#8230; <img src='http://kevin.deldycke.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-3117</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Thu, 23 Aug 2007 23:54:18 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-3117</guid>
		<description>Do yourself a huge favor and take the version number out of your templates, no one really needs to know what you&#039;re running. People will just google for vulnerable versions, and can even automate the attack.</description>
		<content:encoded><![CDATA[<p>Do yourself a huge favor and take the version number out of your templates, no one really needs to know what you&#8217;re running. People will just google for vulnerable versions, and can even automate the attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mhm</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-3046</link>
		<dc:creator>mhm</dc:creator>
		<pubDate>Tue, 17 Jul 2007 13:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-3046</guid>
		<description>very interesting</description>
		<content:encoded><![CDATA[<p>very interesting</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prevent Wordpress hacking &#187; Sha dot Com Anak Melayu boleh blog! Mana gadis manis melayu aku?</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-2992</link>
		<dc:creator>Prevent Wordpress hacking &#187; Sha dot Com Anak Melayu boleh blog! Mana gadis manis melayu aku?</dc:creator>
		<pubDate>Wed, 27 Jun 2007 01:47:29 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-2992</guid>
		<description>[...] to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their worse. You [...]</description>
		<content:encoded><![CDATA[<p>[...] to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their worse. You [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don&#8217;t get hacked! &#187; Sha Money Maker dot com</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-2990</link>
		<dc:creator>Don&#8217;t get hacked! &#187; Sha Money Maker dot com</dc:creator>
		<pubDate>Wed, 27 Jun 2007 00:05:36 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-2990</guid>
		<description>[...] to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their worse. You [...]</description>
		<content:encoded><![CDATA[<p>[...] to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their worse. You [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PsychoPhil - Drink More Beer</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-2973</link>
		<dc:creator>PsychoPhil - Drink More Beer</dc:creator>
		<pubDate>Fri, 22 Jun 2007 21:18:07 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-2973</guid>
		<description>[...] Wordpress 2.2 Security Hole: Identity Theft (tags: security wordpress software internet)    - Posted in del.icio.us by del.icio.us &#160;   trackback [...]</description>
		<content:encoded><![CDATA[<p>[...] Wordpress 2.2 Security Hole: Identity Theft (tags: security wordpress software internet)    &#8211; Posted in del.icio.us by del.icio.us &nbsp;   trackback [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kev</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-2971</link>
		<dc:creator>kev</dc:creator>
		<pubDate>Fri, 22 Jun 2007 15:35:56 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-2971</guid>
		<description>&lt;blockquote&gt;Would it be correct to think that this hack only affects WordPress installs that are open to registration?&lt;/blockquote&gt;

Yes, that&#039;s right !

But it&#039;s not a good idea to skip this update simply because your Wordpress is not open to registration. As you can see in the &lt;a href=&quot;http://wordpress.org/development/2007/06/wordpress-221/&quot; rel=&quot;nofollow&quot;&gt;v2.2.1 press release&lt;/a&gt;, this version also fix several bugs and vulnerabilities...</description>
		<content:encoded><![CDATA[<blockquote><p>Would it be correct to think that this hack only affects WordPress installs that are open to registration?</p></blockquote>
<p>Yes, that&#8217;s right !</p>
<p>But it&#8217;s not a good idea to skip this update simply because your Wordpress is not open to registration. As you can see in the <a  href="http://wordpress.org/development/2007/06/wordpress-221/" rel="nofollow">v2.2.1 press release</a>, this version also fix several bugs and vulnerabilities&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dalton</title>
		<link>http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/comment-page-1/#comment-2969</link>
		<dc:creator>dalton</dc:creator>
		<pubDate>Fri, 22 Jun 2007 01:58:41 +0000</pubDate>
		<guid isPermaLink="false">http://kevin.deldycke.com/2007/06/wordpress-22-security-hole-identity-theft/#comment-2969</guid>
		<description>Would it be correct to think that this hack only affects WordPress installs that are open to registration? None of my blogs are. One of my main issues with WordPress at this point is the upgrade process...it would be really nice if they instituted some sort of upgrade system to make the whole process easier. I have four or five blogs to upgrade now, and it kind of ticks me off.

Though, I&#039;ve been using WP for at least 3 years now, it&#039;s become second nature, it sure would be hard to leave.</description>
		<content:encoded><![CDATA[<p>Would it be correct to think that this hack only affects WordPress installs that are open to registration? None of my blogs are. One of my main issues with WordPress at this point is the upgrade process&#8230;it would be really nice if they instituted some sort of upgrade system to make the whole process easier. I have four or five blogs to upgrade now, and it kind of ticks me off.</p>
<p>Though, I&#8217;ve been using WP for at least 3 years now, it&#8217;s become second nature, it sure would be hard to leave.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
