<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Powered By &#187; Security</title>
	<atom:link href="http://www.powered-by.org/category/news/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.powered-by.org</link>
	<description>Content Management System News and Updates</description>
	<lastBuildDate>Wed, 22 Dec 2010 03:49:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress 2.6.3 released after vulnerability in the Snoopy library was discovered</title>
		<link>http://www.powered-by.org/wordpress-263-released-after-vulnerability-in-the-snoopy-library-was-discovered/</link>
		<comments>http://www.powered-by.org/wordpress-263-released-after-vulnerability-in-the-snoopy-library-was-discovered/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 03:31:37 +0000</pubDate>
		<dc:creator>CMS News</dc:creator>
				<category><![CDATA[New Release]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[snoopy]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/?p=68</guid>
		<description><![CDATA[Snoopy is a PHP class that simulates a web browser. It automates the task of retrieving web page content and posting forms. A vulnerability in the Snoopy library was announced today. WordPress uses Snoopy to fetch the feeds shown in the Dashboard. Although this seems to be a low risk vulnerability for WordPress users, we [...]]]></description>
			<content:encoded><![CDATA[<p>Snoopy is a PHP class that simulates a web browser. It automates the task of retrieving web page content and posting forms.<span id="more-70"></span></p>
<blockquote><p>A vulnerability in the Snoopy library was announced today.  WordPress uses Snoopy to fetch the feeds shown in the Dashboard.   Although this seems to be a low risk vulnerability for WordPress users, we wanted to get an update out immediately.  2.6.3 is available for download right now.  If you don’t want to download the whole release to get the security fix, you can download the following two files and copy them over your 2.6.2 installation.</p></blockquote>
<p>File affetec:ted</p>
<ol>
<li><a target="_blank" href="http://trac.wordpress.org/export/9310/tags/2.6.3/wp-includes/class-snoopy.php">wp-includes/class-snoopy.php</a></li>
<li><a target="_blank" href="http://trac.wordpress.org/export/9310/tags/2.6.3/wp-includes/version.php">wp-includes/version.php</a></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/wordpress-263-released-after-vulnerability-in-the-snoopy-library-was-discovered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress shuts door on new PHP attack vector</title>
		<link>http://www.powered-by.org/wordpress-shuts-door-on-new-php-attack-vector/</link>
		<comments>http://www.powered-by.org/wordpress-shuts-door-on-new-php-attack-vector/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 17:53:25 +0000</pubDate>
		<dc:creator>powered-by.org</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[Blogs]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/news/security/wordpress-shuts-door-on-new-php-attack-vector/</guid>
		<description><![CDATA[According to an advisory from maintainers of the open-source blog software, WordPress 2.6.2 was released on September 8 to mitigate a new attack vector discovered by PHP security guru Stefan Esser. From the announcement: Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). With his help we [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_6" class="wp-caption alignright" style="width: 288px"><a href="http://www.powered-by.org/wp-content/uploads/2008/09/wordpress-logo.png"><img class="size-medium wp-image-6" title="wordpress-logo" src="http://www.powered-by.org/wp-content/uploads/2008/09/wordpress-logo.png" alt="Wordpress" width="278" height="117" /></a><p class="wp-caption-text">Wordpress</p></div>
<p>According to an advisory from maintainers of the open-source blog software, WordPress 2.6.2 was released on September 8 to mitigate a new attack vector discovered by PHP security guru Stefan Esser.</p>
<p><span id="more-32"></span></p>
<p>From the announcement:</p>
<blockquote><p>Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.</p></blockquote>
<p>WordPress developers said the attack is difficult to accomplish but, because of the associated risk, the patch is being released.</p>
<p>It’s important to note that other PHP applications are vulnerable to this class of attack.</p>
<p><a target="_blank" href="http://blogs.zdnet.com/security/?p=1868">WordPress shuts door on new PHP attack vector | Zero Day | ZDNet.com</a></p>
<h4>Incoming search terms:</h4><ul><li>inurl:Powered by WordPress 2 6 1</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/wordpress-shuts-door-on-new-php-attack-vector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

